OAIC Complaints: How to Report a Privacy Breach in Australia
If an Australian organisation has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). The OAIC is the national regulator responsible for enforcing the Privacy Act 1988 and the Australian Privacy Principles (APPs). This guide walks you through exactly how to report a privacy breach, what happens after you lodge a complaint, and how to give yourself the best chance of a meaningful outcome.
What Is the OAIC and When Can You Complain?
The Office of the Australian Information Commissioner is an independent Commonwealth agency that oversees privacy and freedom of information law in Australia. You can lodge an OAIC complaint when you believe an entity covered by the Privacy Act has interfered with your personal information in a way that breaches the Australian Privacy Principles or a registered code.
Entities covered by the Privacy Act generally include:
- Australian Government agencies
- Private sector organisations with an annual turnover of more than $3 million
- Health service providers of any size
- Credit reporting bodies and credit providers
- Tax File Number recipients
- Businesses that trade in personal information or are contracted service providers to the Commonwealth
Small businesses under the $3 million threshold are often exempt, though there are important exceptions. If you are unsure whether the organisation you are complaining about is covered, the OAIC website has a coverage tool, or you can call their enquiries line on 1300 363 992.
Examples of Privacy Breaches You Can Report
- An organisation collecting personal information it doesn't need
- Personal data being disclosed to a third party without your consent
- Unauthorised access to your account or records (a data breach)
- Refusal to give you access to your own personal information
- Refusal to correct inaccurate information
- Use of your data for direct marketing you didn't opt in to
- Cross-border disclosure without adequate protections
Step 1: Complain to the Organisation First
Before the OAIC will investigate, you almost always need to have complained directly to the organisation and given them a reasonable opportunity to respond. This is a mandatory first step under section 40(1A) of the Privacy Act.
- Find the privacy contact. Most APP-covered entities must publish a Privacy Policy that names a privacy officer or contact email.
- Put your complaint in writing. Email is best because it creates a timestamped record. State clearly what happened, when, and which Privacy Principles you believe were breached.
- Ask for a specific outcome. Do you want an apology, deletion of your data, correction, compensation, or a change in practice? Say so.
- Give them 30 days to respond. This is the timeframe the OAIC generally expects before it will accept a complaint.
Keep copies of everything: your original complaint, any acknowledgements, and the final response. You'll need to attach these when you escalate to the OAIC.
Step 2: Lodge Your Complaint With the OAIC
If the organisation ignores you, refuses to fix the problem, or gives an unsatisfactory response, you can then lodge a formal complaint with the OAIC. There are three main ways to do this.
Online Form (Recommended)
The OAIC's online Privacy Complaint Form at oaic.gov.au is the fastest and most reliable option. It walks you through the required information, allows you to upload evidence, and gives you a reference number immediately.
By Post or Email
You can download a PDF complaint form and post it to GPO Box 5288, Sydney NSW 2001, or email a completed form to enquiries@oaic.gov.au. Postal complaints take longer to process.
By Phone (Accessibility Assistance)
If you have difficulty using written forms, call 1300 363 992 and an officer can take your complaint verbally or arrange an interpreter or National Relay Service support.
What to Include in Your OAIC Complaint
A well-prepared complaint moves through the OAIC's triage process faster and is taken more seriously. Include the following information in a clear, chronological format.
| Section | What to Provide |
|---|---|
| Your details | Full name, postal address, email, phone number |
| Respondent details | Legal name of the organisation or agency, ABN if known, contact details |
| Description of breach | What happened, when, how you found out |
| Privacy Principles engaged | Which APPs you think were breached (e.g. APP 6, APP 11) |
| Evidence | Emails, screenshots, letters, contracts, breach notification |
| Prior complaint | Copy of your complaint to the organisation and their response |
| Desired outcome | Apology, correction, deletion, compensation, systemic change |
| Harm suffered | Financial loss, distress, identity theft, reputational damage |
Timeframes to Be Aware Of
The OAIC generally expects complaints to be lodged within 12 months of you becoming aware of the alleged breach. Older complaints can still be accepted but you'll need to explain the delay. There is no fee to lodge a privacy complaint.
What Happens After You Lodge
Once your complaint is received, the OAIC follows a structured assessment and resolution process. Understanding each stage helps set realistic expectations.
- Acknowledgement. You receive confirmation and a case reference within a few business days.
- Preliminary assessment. An officer checks whether the complaint is within jurisdiction, whether the respondent is covered, and whether you complained to the organisation first.
- Early resolution. Many complaints are resolved informally through conciliation, where the OAIC facilitates a discussion between you and the organisation.
- Formal investigation. If early resolution fails and the case has merit, the Commissioner may open a section 40 investigation with information-gathering powers.
- Determination. Under section 52, the Commissioner can make a binding determination requiring the organisation to take action, cease conduct, or pay compensation.
- Enforcement. Determinations can be enforced in the Federal Court or Federal Circuit and Family Court.
Realistic timeframes vary from a few weeks for simple conciliation matters to over 12 months for complex investigations. The OAIC publishes performance statistics annually.
Notifiable Data Breaches Scheme
Since February 2018, the Notifiable Data Breaches (NDB) scheme has required covered entities to notify affected individuals and the OAIC when an eligible data breach occurs. An eligible data breach is one where unauthorised access, disclosure or loss of personal information is likely to result in serious harm.
If you receive a data breach notification, keep it. That notification is powerful evidence if you later need to complain about the organisation's response, the adequacy of their security controls, or delays in notifying you.
What Should Be in a Data Breach Notification?
- The organisation's identity and contact details
- A description of the breach
- The kinds of information involved
- Recommendations for steps you should take (e.g. change passwords, monitor credit)
If a notification is missing this information, vague, or arrives months after the breach was discovered, those are grounds for a separate complaint about the entity's compliance with the NDB scheme itself.
Possible Outcomes and Remedies
Unlike some overseas regulators, the OAIC cannot impose criminal penalties directly, but it has a broad toolkit of remedies. A determination under section 52 can include:
- A declaration that the conduct was an interference with privacy
- An order that the organisation not repeat or continue the conduct
- An order to perform a specific act (such as deleting data or issuing an apology)
- An order to redress loss or damage, including compensation for economic loss and injury to feelings
Compensation amounts in Australian privacy determinations have historically ranged from a few thousand dollars for distress to tens of thousands where serious harm is established. In representative complaints affecting many individuals, aggregate outcomes can be significantly larger.
Civil Penalties for Serious or Repeated Breaches
Following amendments in late 2022, maximum civil penalties for serious or repeated privacy interferences by body corporates are now the greater of $50 million, three times the value of any benefit obtained, or 30% of adjusted turnover during the breach period. These penalties are pursued by the Commissioner in the Federal Court, not automatically awarded to complainants.
Reducing Your Exposure Before a Breach Happens
Complaints are a last resort. The best privacy outcome is one where your data was never mishandled in the first place. A few practical habits reduce your exposure to Australian organisations that may not treat personal information carefully:
- Use a separate email alias when signing up for services you don't fully trust
- Provide the minimum information required (many "required" fields are not legally required)
- Review the Privacy Policy for cross-border disclosure and data retention clauses
- Use link shorteners with privacy-respecting analytics rather than click trackers that fingerprint you. Tools like Lunyb let you share links without exposing recipients to invasive third-party tracking
- Enable multi-factor authentication so a data breach at one provider doesn't cascade
- Regularly request access to and correction of your data under APP 12 and APP 13
If you run a business or website and use shortened links in marketing, choosing a privacy-conscious provider also reduces your own obligations under the APPs. Our 2026 buyer's guide to URL shorteners compares the leading options on privacy, retention, and jurisdiction.
When to Get Legal Advice
The OAIC process is designed to be accessible without a lawyer, and most individual complaints proceed without legal representation. However, you should consider getting advice if:
- You have suffered significant financial loss (identity theft, fraud)
- The breach involves sensitive information (health, sexual orientation, criminal record)
- You are considering a representative (class) complaint
- The respondent has retained lawyers and is contesting the facts
- You want to pursue a parallel action, such as breach of confidence or negligence
Community Legal Centres, Legal Aid in your state, and specialist privacy lawyers can provide guidance. LawAccess in NSW, Victoria Legal Aid, and equivalents in other states offer free initial information.
Alternative and Additional Regulators
The OAIC isn't the only avenue. Depending on the nature of the breach, you may also have rights with:
- State privacy regulators for state government agencies (e.g. IPC NSW, OVIC in Victoria)
- ACMA for spam, unsolicited marketing calls, and Do Not Call Register breaches
- Australian Cyber Security Centre for reporting cybercrime and receiving support
- eSafety Commissioner for image-based abuse or serious online harm
- AFCA for privacy issues involving banks, insurers, and financial service providers
- Telecommunications Industry Ombudsman for telco-related privacy matters
Frequently Asked Questions
How much does it cost to lodge an OAIC complaint?
Nothing. Lodging a privacy complaint with the OAIC is free. You do not need a lawyer, and the OAIC provides accessibility support including interpreters and the National Relay Service.
How long do OAIC complaints take to resolve?
Simple matters resolved through conciliation can conclude in weeks to a few months. Complex investigations leading to a formal determination can take 12 months or more. The OAIC publishes annual performance statistics showing median resolution times.
Can I get compensation through an OAIC complaint?
Yes. The Commissioner can order an organisation to pay compensation for economic loss and for non-economic loss such as injury to feelings, humiliation, and distress. Awards vary widely based on the seriousness of the breach and the harm suffered.
What if the organisation is a small business under $3 million turnover?
Many small businesses are exempt from the Privacy Act, but exceptions apply to health service providers, businesses that trade in personal information, contractors to the Commonwealth, and businesses related to a larger APP entity. Check the OAIC's small business tool or call their enquiries line before assuming an exemption applies.
Do I have to complain to the organisation first?
Almost always yes. Section 40(1A) of the Privacy Act generally requires you to raise your complaint with the entity first and give them a reasonable opportunity (usually 30 days) to respond. The OAIC can waive this requirement in exceptional circumstances, such as where complaining directly would cause you further harm.
Can I complain anonymously?
You can raise concerns anonymously, but the OAIC generally cannot investigate an individual complaint or seek a remedy on your behalf without knowing your identity. Anonymous tips can still inform broader compliance and enforcement work.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Singapore PDPA vs GDPR: Key Differences for Businesses in 2026
Singapore's PDPA and the EU's GDPR both protect personal data, but they differ significantly in consent, penalties, breach notification, and cross-border transfers. This guide breaks down the key differences so businesses can build a unified compliance strategy.
GDPR After Brexit: What Changed for UK Businesses and Data Protection
GDPR did not disappear after Brexit—it split into two parallel regimes. This guide explains how UK GDPR differs from EU GDPR, what adequacy decisions mean for data transfers, and the practical compliance steps every British business should take in 2026.
Data Protection Act 2018 Ireland: Complete Guide
Ireland's Data Protection Act 2018 gives effect to the GDPR under Irish law and empowers the Data Protection Commission to enforce it. This complete guide covers scope, individual rights, penalties, breach notification, and a step-by-step compliance roadmap for Irish organisations.
OAIC Complaints: How to Report a Privacy Breach in Australia
If an Australian organisation has mishandled your personal information, you have the right to complain to the OAIC. This step-by-step guide explains what qualifies as a privacy breach, how to gather evidence, and how the complaint process works from lodgement to determination.