OAIC Complaints: How to Report a Privacy Breach in Australia
If an Australian organisation has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). Whether your data was leaked in a breach, shared without consent, or used for purposes you never agreed to, the OAIC is the federal regulator responsible for enforcing the Privacy Act 1988. This guide explains, step by step, how to report a privacy breach, what the OAIC can and cannot do, and how to strengthen your case before you lodge.
What Is the OAIC and What Does It Regulate?
The Office of the Australian Information Commissioner (OAIC) is the independent Commonwealth agency that oversees privacy and freedom of information law in Australia. It enforces the Privacy Act 1988, the 13 Australian Privacy Principles (APPs), and the Notifiable Data Breaches (NDB) scheme.
The OAIC has jurisdiction over:
- Australian Government agencies (with limited exceptions)
- Private-sector organisations with an annual turnover above AU$3 million
- All health service providers, regardless of size
- Credit reporting bodies, credit providers, and tax file number recipients
- Some small businesses that trade in personal information or contract with government
State and territory public sector agencies are generally handled by state privacy regulators (for example, the IPC in NSW or OVIC in Victoria), not the OAIC.
What Counts as a Privacy Breach?
A privacy breach occurs when an entity covered by the Privacy Act mishandles your personal information in a way that contravenes the Australian Privacy Principles. This can include unauthorised access, disclosure, loss, or misuse of your data.
Common examples of reportable breaches
- A company database is hacked and your name, email, address, or ID documents are exposed.
- An employee accesses your customer file without a legitimate business reason.
- A business sends marketing communications after you withdrew consent.
- A health provider discloses your medical information to a third party without authorisation.
- An organisation refuses to give you access to, or correct, the personal information it holds about you.
- Personal documents are lost in transit or emailed to the wrong recipient.
What is not usually an OAIC matter
- Neighbour disputes over CCTV or drones (often a state matter or civil claim)
- Defamation or reputation issues (handled by defamation law)
- Workplace employee records held by your employer (a specific Privacy Act exemption)
- Journalism carried out by registered media organisations under a public interest code
Step 1: Complain to the Organisation First
The OAIC will almost always ask whether you have raised the issue directly with the organisation before it accepts your complaint. This is a mandatory first step in most cases.
- Identify the right contact. Most Privacy Act entities are required to publish a privacy policy naming their Privacy Officer or complaints contact.
- Put your complaint in writing. Email is best because it creates a timestamped record. Clearly state what happened, when, and what outcome you want (an apology, deletion, correction, compensation, or a change in practice).
- Give them 30 days to respond. This is the timeframe the OAIC expects before it will consider intervening.
- Keep every reply. Save emails, letters, ticket numbers, and screenshots. If the organisation refuses, ignores you, or gives an inadequate response, you can escalate.
Step 2: Gather Your Evidence
A well-documented complaint moves faster and is more likely to result in action. Before you lodge with the OAIC, put together a clear evidence pack.
Documents and information to collect
- Your correspondence with the organisation (both directions)
- Copies of any breach notification emails or letters you received
- Screenshots of the data exposure (for example, a public link, an incorrect email, or a leaked forum post)
- Dates and times of the incident and each communication
- Names of any staff you dealt with
- Evidence of harm: financial loss, identity theft alerts, medical distress, or wasted time
- Copies of the organisation's privacy policy at the relevant time (use archive.org if it has changed)
When sharing screenshots or evidence links with legal advisers or advocacy groups, avoid pasting long, tracked URLs that may reveal your session tokens or referral data. Tools such as Lunyb can be used to create clean, shareable short links that strip unnecessary tracking parameters from the URLs you cite in your complaint bundle.
Step 3: Lodge Your Complaint With the OAIC
Once the organisation has had 30 days and you are unsatisfied, you can formally lodge with the OAIC. There is no fee.
How to lodge
- Online: Use the OAIC's Privacy Complaint Form at oaic.gov.au. This is the fastest and most tracked option.
- By post: GPO Box 5288, Sydney NSW 2001.
- By phone: 1300 363 992 (for advice and to request a paper form; you still need to submit in writing).
What to include
- Your full name and contact details
- The name of the organisation you are complaining about
- A clear chronological description of what happened
- Which Australian Privacy Principle you believe was breached (if you know)
- The steps you have already taken and the organisation's response
- The outcome you want
- Attached evidence
Step 4: What Happens After You Lodge
The OAIC follows a structured intake and assessment process. Understanding the stages helps you set realistic expectations.
| Stage | What Happens | Typical Timeframe |
|---|---|---|
| Acknowledgement | OAIC confirms receipt and assigns a reference number | 1–2 weeks |
| Early assessment | Officer checks jurisdiction and whether you contacted the organisation first | 4–8 weeks |
| Conciliation | OAIC facilitates a resolution between you and the entity | 3–9 months |
| Investigation | Formal investigation if conciliation fails and the matter is serious | 6–18 months |
| Determination | Commissioner issues binding orders, including compensation | Varies |
Most complaints are resolved by conciliation without a formal determination. The OAIC can also decline to investigate if the complaint is trivial, made in bad faith, out of time (generally more than 12 months since you became aware of the issue), or better handled elsewhere.
Possible Outcomes of an OAIC Complaint
The remedies available under the Privacy Act are broader than many Australians realise. The Commissioner can order an organisation to do, or stop doing, specific things.
Typical outcomes
- A formal apology
- Correction or deletion of your personal information
- Reinstatement of access to a service
- Staff training or a change to the organisation's systems and policies
- Compensation for financial loss, out-of-pocket expenses, or non-economic loss (hurt feelings, anxiety, humiliation) — typically ranging from a few hundred to tens of thousands of dollars in serious matters
- Public statements or enforceable undertakings
For systemic or egregious conduct, the Commissioner can pursue civil penalties in the Federal Court. Under recent reforms, penalties for serious or repeated interferences with privacy can reach the greater of AU$50 million, three times the benefit obtained, or 30% of adjusted turnover.
The Notifiable Data Breaches (NDB) Scheme
Since February 2018, entities covered by the Privacy Act must report eligible data breaches to both the OAIC and affected individuals. An eligible breach is one likely to result in serious harm.
What organisations must do
- Assess a suspected breach within 30 days.
- If it is likely to cause serious harm, notify the OAIC and affected people as soon as practicable.
- Include a description of the breach, the kinds of information involved, and recommended steps for affected individuals.
If you receive a breach notification, keep it. It is powerful evidence if you later need to lodge a complaint or claim compensation. If you suspect an organisation experienced a breach and failed to notify you or the OAIC, that itself is a matter you can report.
Special Cases: Health, Credit, and Government Data
Health information
Health service providers of any size are covered by the Privacy Act. Complaints about My Health Record, hospitals, GPs, allied health, and pharmacies can go to the OAIC. Some states also have parallel health privacy regulators.
Credit reporting
If a credit provider or reporting body (such as Equifax, illion, or Experian) has recorded incorrect information or shared it improperly, you can complain first to them, then to the OAIC. You may also engage the Australian Financial Complaints Authority (AFCA) for related financial services issues.
Government agencies
For Commonwealth agencies such as Services Australia, the ATO, or Home Affairs, go directly to the agency's internal review process first, then escalate to the OAIC. State agencies are handled by state privacy regulators.
Protecting Yourself After a Breach
Lodging a complaint is important, but you should also take immediate steps to reduce ongoing risk.
- Change passwords on the affected service and anywhere you reused the same credentials.
- Enable multi-factor authentication on email, banking, and government logins (myGov, ATO).
- Place a credit ban with Equifax, illion, and Experian — free for 21 days and renewable.
- Contact IDCARE (1800 595 160), Australia's national identity and cyber support service.
- Watch for phishing that references the breached data to appear legitimate.
- Use encrypted DNS and a privacy-respecting browser to reduce your ongoing data exposure.
- Audit link sharing — if you share personal documents by URL, use a link shortener that supports expiry and password protection so exposed links can be revoked.
You can read more about safe link sharing practices in our 2026 buyer's guide to URL shorteners and our honest review of Lunyb.
Tips to Strengthen Your OAIC Complaint
- Be specific. Name dates, systems, and staff. Vague complaints are harder to progress.
- Reference the APPs. Even a general reference ("I believe this breaches APP 6 — use and disclosure") shows the assessor you understand the framework.
- Quantify harm. Note lost time, money spent on identity monitoring, medical costs, or emotional impact.
- Stay professional. Emotional language is understandable but structured, factual complaints achieve better outcomes.
- Do not miss the 12-month window. Lodge within a year of becoming aware of the issue.
- Consider representative complaints. If many people were affected, one person can lodge on behalf of the group.
Frequently Asked Questions
How much does it cost to lodge an OAIC complaint?
Nothing. Lodging a privacy complaint with the OAIC is free. You do not need a lawyer, although you can engage one if the matter is complex or involves significant compensation.
How long do I have to make a complaint?
Generally, you should lodge within 12 months of becoming aware of the alleged breach. The OAIC can accept older complaints in exceptional circumstances, but expect to explain the delay.
Can I get compensation through the OAIC?
Yes. The Commissioner can order compensation for financial loss and for non-economic loss such as distress, embarrassment, and humiliation. Awards commonly range from a few hundred dollars in minor matters to tens of thousands in serious cases involving sensitive information or identity theft.
What if the organisation is based overseas?
The Privacy Act has extraterritorial reach. If an overseas organisation carries on business in Australia and collects or holds Australians' personal information, the OAIC can generally investigate. Enforcement can be more complex, but many global companies cooperate.
Can I stay anonymous?
You can raise concerns with the OAIC anonymously, but a formal complaint that seeks a remedy for you personally requires identification so the OAIC can conciliate and, if necessary, order relief in your favour.
Final Thoughts
Australia's privacy framework has real teeth, and the OAIC provides a genuine no-cost avenue for individuals whose personal information has been mishandled. The most successful complainants are those who complain to the organisation first, keep meticulous records, and articulate exactly what harm they suffered and what remedy they want. Combine that with strong personal cyber hygiene — unique passwords, multi-factor authentication, encrypted DNS, privacy-conscious browsers, and controlled link sharing — and you significantly reduce both the likelihood and the impact of future privacy breaches.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Data Protection Act 2018 Ireland: Complete Guide for Businesses
A complete, practical guide to the Data Protection Act 2018 in Ireland — covering its scope, principles, individual rights, DPC enforcement, breach notifications, and compliance steps for Irish businesses. Learn how to align your organisation with Ireland's data protection framework and avoid costly penalties.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A complete step-by-step guide to filing a privacy complaint with Ireland's Data Protection Commission. Learn your GDPR rights, prepare strong evidence, and understand what to expect from the DPC investigation process.
Bill C-27 Digital Charter: What Canadian Businesses Need to Know
Bill C-27, the Digital Charter Implementation Act, will reshape Canadian privacy law through the CPPA, a new tribunal, and AIDA — Canada's first federal AI law. Here's what businesses need to know about new rights, penalties up to 5% of global revenue, and practical steps to prepare.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 introduces new rights to access, correct, erase and de-index personal data, plus a statutory tort for serious privacy invasions. Here's a plain-English guide to what's changed, what businesses must do, and how Australians can protect themselves.