facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··10 min read

If an Australian organisation has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). Whether your data was leaked in a breach, shared without consent, or used for purposes you never agreed to, the OAIC is the federal regulator responsible for enforcing the Privacy Act 1988. This guide explains, step by step, how to report a privacy breach, what the OAIC can and cannot do, and how to strengthen your case before you lodge.

What Is the OAIC and What Does It Regulate?

The Office of the Australian Information Commissioner (OAIC) is the independent Commonwealth agency that oversees privacy and freedom of information law in Australia. It enforces the Privacy Act 1988, the 13 Australian Privacy Principles (APPs), and the Notifiable Data Breaches (NDB) scheme.

The OAIC has jurisdiction over:

  • Australian Government agencies (with limited exceptions)
  • Private-sector organisations with an annual turnover above AU$3 million
  • All health service providers, regardless of size
  • Credit reporting bodies, credit providers, and tax file number recipients
  • Some small businesses that trade in personal information or contract with government

State and territory public sector agencies are generally handled by state privacy regulators (for example, the IPC in NSW or OVIC in Victoria), not the OAIC.

What Counts as a Privacy Breach?

A privacy breach occurs when an entity covered by the Privacy Act mishandles your personal information in a way that contravenes the Australian Privacy Principles. This can include unauthorised access, disclosure, loss, or misuse of your data.

Common examples of reportable breaches

  • A company database is hacked and your name, email, address, or ID documents are exposed.
  • An employee accesses your customer file without a legitimate business reason.
  • A business sends marketing communications after you withdrew consent.
  • A health provider discloses your medical information to a third party without authorisation.
  • An organisation refuses to give you access to, or correct, the personal information it holds about you.
  • Personal documents are lost in transit or emailed to the wrong recipient.

What is not usually an OAIC matter

  • Neighbour disputes over CCTV or drones (often a state matter or civil claim)
  • Defamation or reputation issues (handled by defamation law)
  • Workplace employee records held by your employer (a specific Privacy Act exemption)
  • Journalism carried out by registered media organisations under a public interest code

Step 1: Complain to the Organisation First

The OAIC will almost always ask whether you have raised the issue directly with the organisation before it accepts your complaint. This is a mandatory first step in most cases.

  1. Identify the right contact. Most Privacy Act entities are required to publish a privacy policy naming their Privacy Officer or complaints contact.
  2. Put your complaint in writing. Email is best because it creates a timestamped record. Clearly state what happened, when, and what outcome you want (an apology, deletion, correction, compensation, or a change in practice).
  3. Give them 30 days to respond. This is the timeframe the OAIC expects before it will consider intervening.
  4. Keep every reply. Save emails, letters, ticket numbers, and screenshots. If the organisation refuses, ignores you, or gives an inadequate response, you can escalate.

Step 2: Gather Your Evidence

A well-documented complaint moves faster and is more likely to result in action. Before you lodge with the OAIC, put together a clear evidence pack.

Documents and information to collect

  • Your correspondence with the organisation (both directions)
  • Copies of any breach notification emails or letters you received
  • Screenshots of the data exposure (for example, a public link, an incorrect email, or a leaked forum post)
  • Dates and times of the incident and each communication
  • Names of any staff you dealt with
  • Evidence of harm: financial loss, identity theft alerts, medical distress, or wasted time
  • Copies of the organisation's privacy policy at the relevant time (use archive.org if it has changed)

When sharing screenshots or evidence links with legal advisers or advocacy groups, avoid pasting long, tracked URLs that may reveal your session tokens or referral data. Tools such as Lunyb can be used to create clean, shareable short links that strip unnecessary tracking parameters from the URLs you cite in your complaint bundle.

Step 3: Lodge Your Complaint With the OAIC

Once the organisation has had 30 days and you are unsatisfied, you can formally lodge with the OAIC. There is no fee.

How to lodge

  1. Online: Use the OAIC's Privacy Complaint Form at oaic.gov.au. This is the fastest and most tracked option.
  2. By post: GPO Box 5288, Sydney NSW 2001.
  3. By phone: 1300 363 992 (for advice and to request a paper form; you still need to submit in writing).

What to include

  • Your full name and contact details
  • The name of the organisation you are complaining about
  • A clear chronological description of what happened
  • Which Australian Privacy Principle you believe was breached (if you know)
  • The steps you have already taken and the organisation's response
  • The outcome you want
  • Attached evidence

Step 4: What Happens After You Lodge

The OAIC follows a structured intake and assessment process. Understanding the stages helps you set realistic expectations.

StageWhat HappensTypical Timeframe
AcknowledgementOAIC confirms receipt and assigns a reference number1–2 weeks
Early assessmentOfficer checks jurisdiction and whether you contacted the organisation first4–8 weeks
ConciliationOAIC facilitates a resolution between you and the entity3–9 months
InvestigationFormal investigation if conciliation fails and the matter is serious6–18 months
DeterminationCommissioner issues binding orders, including compensationVaries

Most complaints are resolved by conciliation without a formal determination. The OAIC can also decline to investigate if the complaint is trivial, made in bad faith, out of time (generally more than 12 months since you became aware of the issue), or better handled elsewhere.

Possible Outcomes of an OAIC Complaint

The remedies available under the Privacy Act are broader than many Australians realise. The Commissioner can order an organisation to do, or stop doing, specific things.

Typical outcomes

  • A formal apology
  • Correction or deletion of your personal information
  • Reinstatement of access to a service
  • Staff training or a change to the organisation's systems and policies
  • Compensation for financial loss, out-of-pocket expenses, or non-economic loss (hurt feelings, anxiety, humiliation) — typically ranging from a few hundred to tens of thousands of dollars in serious matters
  • Public statements or enforceable undertakings

For systemic or egregious conduct, the Commissioner can pursue civil penalties in the Federal Court. Under recent reforms, penalties for serious or repeated interferences with privacy can reach the greater of AU$50 million, three times the benefit obtained, or 30% of adjusted turnover.

The Notifiable Data Breaches (NDB) Scheme

Since February 2018, entities covered by the Privacy Act must report eligible data breaches to both the OAIC and affected individuals. An eligible breach is one likely to result in serious harm.

What organisations must do

  1. Assess a suspected breach within 30 days.
  2. If it is likely to cause serious harm, notify the OAIC and affected people as soon as practicable.
  3. Include a description of the breach, the kinds of information involved, and recommended steps for affected individuals.

If you receive a breach notification, keep it. It is powerful evidence if you later need to lodge a complaint or claim compensation. If you suspect an organisation experienced a breach and failed to notify you or the OAIC, that itself is a matter you can report.

Special Cases: Health, Credit, and Government Data

Health information

Health service providers of any size are covered by the Privacy Act. Complaints about My Health Record, hospitals, GPs, allied health, and pharmacies can go to the OAIC. Some states also have parallel health privacy regulators.

Credit reporting

If a credit provider or reporting body (such as Equifax, illion, or Experian) has recorded incorrect information or shared it improperly, you can complain first to them, then to the OAIC. You may also engage the Australian Financial Complaints Authority (AFCA) for related financial services issues.

Government agencies

For Commonwealth agencies such as Services Australia, the ATO, or Home Affairs, go directly to the agency's internal review process first, then escalate to the OAIC. State agencies are handled by state privacy regulators.

Protecting Yourself After a Breach

Lodging a complaint is important, but you should also take immediate steps to reduce ongoing risk.

  1. Change passwords on the affected service and anywhere you reused the same credentials.
  2. Enable multi-factor authentication on email, banking, and government logins (myGov, ATO).
  3. Place a credit ban with Equifax, illion, and Experian — free for 21 days and renewable.
  4. Contact IDCARE (1800 595 160), Australia's national identity and cyber support service.
  5. Watch for phishing that references the breached data to appear legitimate.
  6. Use encrypted DNS and a privacy-respecting browser to reduce your ongoing data exposure.
  7. Audit link sharing — if you share personal documents by URL, use a link shortener that supports expiry and password protection so exposed links can be revoked.

You can read more about safe link sharing practices in our 2026 buyer's guide to URL shorteners and our honest review of Lunyb.

Tips to Strengthen Your OAIC Complaint

  • Be specific. Name dates, systems, and staff. Vague complaints are harder to progress.
  • Reference the APPs. Even a general reference ("I believe this breaches APP 6 — use and disclosure") shows the assessor you understand the framework.
  • Quantify harm. Note lost time, money spent on identity monitoring, medical costs, or emotional impact.
  • Stay professional. Emotional language is understandable but structured, factual complaints achieve better outcomes.
  • Do not miss the 12-month window. Lodge within a year of becoming aware of the issue.
  • Consider representative complaints. If many people were affected, one person can lodge on behalf of the group.

Frequently Asked Questions

How much does it cost to lodge an OAIC complaint?

Nothing. Lodging a privacy complaint with the OAIC is free. You do not need a lawyer, although you can engage one if the matter is complex or involves significant compensation.

How long do I have to make a complaint?

Generally, you should lodge within 12 months of becoming aware of the alleged breach. The OAIC can accept older complaints in exceptional circumstances, but expect to explain the delay.

Can I get compensation through the OAIC?

Yes. The Commissioner can order compensation for financial loss and for non-economic loss such as distress, embarrassment, and humiliation. Awards commonly range from a few hundred dollars in minor matters to tens of thousands in serious cases involving sensitive information or identity theft.

What if the organisation is based overseas?

The Privacy Act has extraterritorial reach. If an overseas organisation carries on business in Australia and collects or holds Australians' personal information, the OAIC can generally investigate. Enforcement can be more complex, but many global companies cooperate.

Can I stay anonymous?

You can raise concerns with the OAIC anonymously, but a formal complaint that seeks a remedy for you personally requires identification so the OAIC can conciliate and, if necessary, order relief in your favour.

Final Thoughts

Australia's privacy framework has real teeth, and the OAIC provides a genuine no-cost avenue for individuals whose personal information has been mishandled. The most successful complainants are those who complain to the organisation first, keep meticulous records, and articulate exactly what harm they suffered and what remedy they want. Combine that with strong personal cyber hygiene — unique passwords, multi-factor authentication, encrypted DNS, privacy-conscious browsers, and controlled link sharing — and you significantly reduce both the likelihood and the impact of future privacy breaches.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles