facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··10 min read

If an Australian organisation has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). The OAIC is the national regulator responsible for enforcing the Privacy Act 1988 and the Australian Privacy Principles (APPs). This guide walks you through exactly how to report a privacy breach, what happens after you lodge a complaint, and how to give yourself the best chance of a meaningful outcome.

What Is the OAIC and When Can You Complain?

The Office of the Australian Information Commissioner is an independent Commonwealth agency that oversees privacy and freedom of information law in Australia. You can lodge an OAIC complaint when you believe an entity covered by the Privacy Act has interfered with your personal information in a way that breaches the Australian Privacy Principles or a registered code.

Entities covered by the Privacy Act generally include:

  • Australian Government agencies
  • Private sector organisations with an annual turnover of more than $3 million
  • Health service providers of any size
  • Credit reporting bodies and credit providers
  • Tax File Number recipients
  • Businesses that trade in personal information or are contracted service providers to the Commonwealth

Small businesses under the $3 million threshold are often exempt, though there are important exceptions. If you are unsure whether the organisation you are complaining about is covered, the OAIC website has a coverage tool, or you can call their enquiries line on 1300 363 992.

Examples of Privacy Breaches You Can Report

  • An organisation collecting personal information it doesn't need
  • Personal data being disclosed to a third party without your consent
  • Unauthorised access to your account or records (a data breach)
  • Refusal to give you access to your own personal information
  • Refusal to correct inaccurate information
  • Use of your data for direct marketing you didn't opt in to
  • Cross-border disclosure without adequate protections

Step 1: Complain to the Organisation First

Before the OAIC will investigate, you almost always need to have complained directly to the organisation and given them a reasonable opportunity to respond. This is a mandatory first step under section 40(1A) of the Privacy Act.

  1. Find the privacy contact. Most APP-covered entities must publish a Privacy Policy that names a privacy officer or contact email.
  2. Put your complaint in writing. Email is best because it creates a timestamped record. State clearly what happened, when, and which Privacy Principles you believe were breached.
  3. Ask for a specific outcome. Do you want an apology, deletion of your data, correction, compensation, or a change in practice? Say so.
  4. Give them 30 days to respond. This is the timeframe the OAIC generally expects before it will accept a complaint.

Keep copies of everything: your original complaint, any acknowledgements, and the final response. You'll need to attach these when you escalate to the OAIC.

Step 2: Lodge Your Complaint With the OAIC

If the organisation ignores you, refuses to fix the problem, or gives an unsatisfactory response, you can then lodge a formal complaint with the OAIC. There are three main ways to do this.

Online Form (Recommended)

The OAIC's online Privacy Complaint Form at oaic.gov.au is the fastest and most reliable option. It walks you through the required information, allows you to upload evidence, and gives you a reference number immediately.

By Post or Email

You can download a PDF complaint form and post it to GPO Box 5288, Sydney NSW 2001, or email a completed form to enquiries@oaic.gov.au. Postal complaints take longer to process.

By Phone (Accessibility Assistance)

If you have difficulty using written forms, call 1300 363 992 and an officer can take your complaint verbally or arrange an interpreter or National Relay Service support.

What to Include in Your OAIC Complaint

A well-prepared complaint moves through the OAIC's triage process faster and is taken more seriously. Include the following information in a clear, chronological format.

SectionWhat to Provide
Your detailsFull name, postal address, email, phone number
Respondent detailsLegal name of the organisation or agency, ABN if known, contact details
Description of breachWhat happened, when, how you found out
Privacy Principles engagedWhich APPs you think were breached (e.g. APP 6, APP 11)
EvidenceEmails, screenshots, letters, contracts, breach notification
Prior complaintCopy of your complaint to the organisation and their response
Desired outcomeApology, correction, deletion, compensation, systemic change
Harm sufferedFinancial loss, distress, identity theft, reputational damage

Timeframes to Be Aware Of

The OAIC generally expects complaints to be lodged within 12 months of you becoming aware of the alleged breach. Older complaints can still be accepted but you'll need to explain the delay. There is no fee to lodge a privacy complaint.

What Happens After You Lodge

Once your complaint is received, the OAIC follows a structured assessment and resolution process. Understanding each stage helps set realistic expectations.

  1. Acknowledgement. You receive confirmation and a case reference within a few business days.
  2. Preliminary assessment. An officer checks whether the complaint is within jurisdiction, whether the respondent is covered, and whether you complained to the organisation first.
  3. Early resolution. Many complaints are resolved informally through conciliation, where the OAIC facilitates a discussion between you and the organisation.
  4. Formal investigation. If early resolution fails and the case has merit, the Commissioner may open a section 40 investigation with information-gathering powers.
  5. Determination. Under section 52, the Commissioner can make a binding determination requiring the organisation to take action, cease conduct, or pay compensation.
  6. Enforcement. Determinations can be enforced in the Federal Court or Federal Circuit and Family Court.

Realistic timeframes vary from a few weeks for simple conciliation matters to over 12 months for complex investigations. The OAIC publishes performance statistics annually.

Notifiable Data Breaches Scheme

Since February 2018, the Notifiable Data Breaches (NDB) scheme has required covered entities to notify affected individuals and the OAIC when an eligible data breach occurs. An eligible data breach is one where unauthorised access, disclosure or loss of personal information is likely to result in serious harm.

If you receive a data breach notification, keep it. That notification is powerful evidence if you later need to complain about the organisation's response, the adequacy of their security controls, or delays in notifying you.

What Should Be in a Data Breach Notification?

  • The organisation's identity and contact details
  • A description of the breach
  • The kinds of information involved
  • Recommendations for steps you should take (e.g. change passwords, monitor credit)

If a notification is missing this information, vague, or arrives months after the breach was discovered, those are grounds for a separate complaint about the entity's compliance with the NDB scheme itself.

Possible Outcomes and Remedies

Unlike some overseas regulators, the OAIC cannot impose criminal penalties directly, but it has a broad toolkit of remedies. A determination under section 52 can include:

  • A declaration that the conduct was an interference with privacy
  • An order that the organisation not repeat or continue the conduct
  • An order to perform a specific act (such as deleting data or issuing an apology)
  • An order to redress loss or damage, including compensation for economic loss and injury to feelings

Compensation amounts in Australian privacy determinations have historically ranged from a few thousand dollars for distress to tens of thousands where serious harm is established. In representative complaints affecting many individuals, aggregate outcomes can be significantly larger.

Civil Penalties for Serious or Repeated Breaches

Following amendments in late 2022, maximum civil penalties for serious or repeated privacy interferences by body corporates are now the greater of $50 million, three times the value of any benefit obtained, or 30% of adjusted turnover during the breach period. These penalties are pursued by the Commissioner in the Federal Court, not automatically awarded to complainants.

Reducing Your Exposure Before a Breach Happens

Complaints are a last resort. The best privacy outcome is one where your data was never mishandled in the first place. A few practical habits reduce your exposure to Australian organisations that may not treat personal information carefully:

  • Use a separate email alias when signing up for services you don't fully trust
  • Provide the minimum information required (many "required" fields are not legally required)
  • Review the Privacy Policy for cross-border disclosure and data retention clauses
  • Use link shorteners with privacy-respecting analytics rather than click trackers that fingerprint you. Tools like Lunyb let you share links without exposing recipients to invasive third-party tracking
  • Enable multi-factor authentication so a data breach at one provider doesn't cascade
  • Regularly request access to and correction of your data under APP 12 and APP 13

If you run a business or website and use shortened links in marketing, choosing a privacy-conscious provider also reduces your own obligations under the APPs. Our 2026 buyer's guide to URL shorteners compares the leading options on privacy, retention, and jurisdiction.

When to Get Legal Advice

The OAIC process is designed to be accessible without a lawyer, and most individual complaints proceed without legal representation. However, you should consider getting advice if:

  • You have suffered significant financial loss (identity theft, fraud)
  • The breach involves sensitive information (health, sexual orientation, criminal record)
  • You are considering a representative (class) complaint
  • The respondent has retained lawyers and is contesting the facts
  • You want to pursue a parallel action, such as breach of confidence or negligence

Community Legal Centres, Legal Aid in your state, and specialist privacy lawyers can provide guidance. LawAccess in NSW, Victoria Legal Aid, and equivalents in other states offer free initial information.

Alternative and Additional Regulators

The OAIC isn't the only avenue. Depending on the nature of the breach, you may also have rights with:

  • State privacy regulators for state government agencies (e.g. IPC NSW, OVIC in Victoria)
  • ACMA for spam, unsolicited marketing calls, and Do Not Call Register breaches
  • Australian Cyber Security Centre for reporting cybercrime and receiving support
  • eSafety Commissioner for image-based abuse or serious online harm
  • AFCA for privacy issues involving banks, insurers, and financial service providers
  • Telecommunications Industry Ombudsman for telco-related privacy matters

Frequently Asked Questions

How much does it cost to lodge an OAIC complaint?

Nothing. Lodging a privacy complaint with the OAIC is free. You do not need a lawyer, and the OAIC provides accessibility support including interpreters and the National Relay Service.

How long do OAIC complaints take to resolve?

Simple matters resolved through conciliation can conclude in weeks to a few months. Complex investigations leading to a formal determination can take 12 months or more. The OAIC publishes annual performance statistics showing median resolution times.

Can I get compensation through an OAIC complaint?

Yes. The Commissioner can order an organisation to pay compensation for economic loss and for non-economic loss such as injury to feelings, humiliation, and distress. Awards vary widely based on the seriousness of the breach and the harm suffered.

What if the organisation is a small business under $3 million turnover?

Many small businesses are exempt from the Privacy Act, but exceptions apply to health service providers, businesses that trade in personal information, contractors to the Commonwealth, and businesses related to a larger APP entity. Check the OAIC's small business tool or call their enquiries line before assuming an exemption applies.

Do I have to complain to the organisation first?

Almost always yes. Section 40(1A) of the Privacy Act generally requires you to raise your complaint with the entity first and give them a reasonable opportunity (usually 30 days) to respond. The OAIC can waive this requirement in exceptional circumstances, such as where complaining directly would cause you further harm.

Can I complain anonymously?

You can raise concerns anonymously, but the OAIC generally cannot investigate an individual complaint or seek a remedy on your behalf without knowing your identity. Anonymous tips can still inform broader compliance and enforcement work.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles