facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··10 min read

If an Australian organisation has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). Whether your data was leaked in a breach, sold without consent, or accessed by someone who shouldn't have seen it, the OAIC is the national regulator that can investigate and, in serious cases, order compensation or enforcement action.

This guide walks you through exactly how to lodge an OAIC complaint about a privacy breach, what evidence you need, how long the process takes, and what outcomes to realistically expect.

What Is the OAIC?

The Office of the Australian Information Commissioner (OAIC) is the independent Commonwealth agency that regulates privacy and freedom of information in Australia. It enforces the Privacy Act 1988 and the 13 Australian Privacy Principles (APPs), which govern how most Australian Government agencies and private-sector organisations with an annual turnover above $3 million handle personal information.

The OAIC has power to:

  • Investigate privacy complaints from individuals
  • Conduct own-motion investigations into systemic issues
  • Accept enforceable undertakings from organisations
  • Seek civil penalties through the Federal Court (up to $50 million or more for serious breaches)
  • Order organisations to pay compensation to affected individuals

When Can You Complain to the OAIC?

You can lodge a privacy complaint with the OAIC when an APP entity has done something with your personal information that you believe interferes with your privacy. Common situations include:

1. Unauthorised Data Breaches

An organisation lost control of your data — through hacking, a misconfigured database, a stolen laptop, or an employee accessing records they shouldn't have. If you were notified under the Notifiable Data Breaches (NDB) scheme, or you found out another way, you can complain.

2. Collection Without Consent

An organisation collected personal information about you without a lawful basis, or collected more than was reasonably necessary for their functions.

3. Misuse or Improper Disclosure

Your information was used for a purpose you didn't agree to (secondary use), or disclosed to a third party without authority — including overseas disclosures without appropriate safeguards.

4. Refusal of Access or Correction

You requested access to your own personal information or asked for corrections, and the organisation refused without a valid reason.

5. Direct Marketing Breaches

You continued receiving marketing messages after opting out, or the organisation used your data for marketing without allowing you to opt out easily.

The Critical First Step: Complain to the Organisation First

Before the OAIC will consider your complaint, you generally must complain directly to the organisation and give them 30 days to respond. This is a mandatory step under Section 40 of the Privacy Act, and the OAIC will usually refuse to investigate if you skip it.

Here's how to do it properly:

  1. Find the organisation's privacy officer. Most organisations list a Privacy Officer or Data Protection Officer contact in their privacy policy.
  2. Put your complaint in writing. Email is fine. Clearly state what happened, when, what personal information was involved, and what outcome you want (an apology, correction, deletion, compensation).
  3. Keep records. Save the email, note the date sent, and record all responses.
  4. Wait 30 days. If they don't respond, or their response is inadequate, you can escalate to the OAIC.

Skipping this step is the number one reason complaints get bounced back. Even if you're furious and just want the regulator involved, follow the process.

How to Lodge an OAIC Complaint: Step-by-Step

Step 1: Gather Your Evidence

Before you start the form, collect everything you'll need:

  • Your written complaint to the organisation and their response (or evidence of no response)
  • Copies of the privacy policy or terms you agreed to
  • Any breach notifications you received
  • Screenshots, emails, letters, or other proof of the interference
  • A clear timeline of events with dates
  • Notes on any harm you've suffered (financial loss, identity theft, distress, reputational damage)

Step 2: Complete the Privacy Complaint Form

The OAIC accepts complaints through its online form at oaic.gov.au. There's also a downloadable PDF form if you prefer to post or email it. The form asks for:

  • Your contact details
  • The name of the organisation you're complaining about
  • A description of what happened
  • What you've done to try to resolve it
  • The outcome you're seeking
  • Supporting documents (attach as PDFs or images)

Step 3: Submit and Get an Acknowledgement

You'll receive an acknowledgement within a few business days, usually with a reference number. Keep this number for all future correspondence.

Step 4: Preliminary Assessment

An OAIC case officer will review your complaint to decide whether it falls within the Commissioner's jurisdiction and whether it should be investigated. They may contact you for more information at this stage.

Step 5: Conciliation

Most privacy complaints are resolved through conciliation — a facilitated negotiation between you and the organisation. The OAIC officer helps both sides reach an outcome without a formal determination. Common conciliated outcomes include apologies, staff training commitments, changes to systems, deletion of records, and compensation payments ranging from a few hundred to tens of thousands of dollars depending on harm.

Step 6: Formal Investigation or Determination

If conciliation fails, or the matter is serious enough, the Commissioner may make a formal determination. This is a legally enforceable decision that can order the organisation to change its conduct and pay compensation.

Timelines: How Long Does It Take?

Stage Typical Timeframe
Direct complaint to organisation30 days minimum
OAIC acknowledgement5–10 business days
Preliminary assessment4–8 weeks
Conciliation3–9 months
Formal determination12–24+ months

The OAIC has a significant backlog, and complex complaints — especially those involving large data breaches with many affected individuals — can take much longer than the averages above.

The Notifiable Data Breaches (NDB) Scheme

Since February 2018, organisations covered by the Privacy Act must notify the OAIC and affected individuals when an eligible data breach occurs. An eligible data breach is one that is likely to result in serious harm to any individual whose information was involved.

If you receive a data breach notification, it should tell you:

  • What happened and when
  • What kind of information was involved
  • What the organisation is doing about it
  • What steps you should take to protect yourself

Receiving an NDB notification doesn't automatically entitle you to compensation, but it's strong evidence supporting an OAIC complaint if you've suffered harm.

What Compensation Can You Get?

The OAIC can order compensation for both economic and non-economic loss. Categories include:

  • Economic loss: Money spent on credit monitoring, replacing identity documents, legal fees, lost income
  • Non-economic loss: Injury to feelings, humiliation, anxiety, and distress
  • Aggravated damages: Where the organisation's conduct was particularly high-handed or careless

Historical determinations have awarded amounts ranging from $3,000 for minor breaches up to $20,000+ per affected individual in serious cases. Class-action style representative complaints for large breaches can result in significantly higher aggregate outcomes.

Protecting Yourself Before and After a Breach

While regulators like the OAIC can help after something goes wrong, minimising the data you expose in the first place is the best defence. Practical measures include:

  • Use unique, strong passwords stored in a reputable password manager
  • Enable multi-factor authentication on every account that offers it
  • Use encrypted DNS (DoH or DoT) to reduce network-level tracking
  • Prefer privacy-respecting browsers with tracker blocking enabled
  • Use link shorteners with tracking transparency — services like Lunyb let you share links without exposing analytics data to third-party ad networks, which is useful when publishing links tied to your identity
  • Regularly request and review what data organisations hold about you
  • Sign up for HaveIBeenPwned notifications

If you run a business or share links publicly and want to compare tools that balance analytics with user privacy, our 2026 buyer's guide to URL shorteners breaks down which services collect what.

When the OAIC Isn't the Right Body

Not every privacy grievance belongs with the OAIC. Consider these alternatives:

  • State privacy regulators — Complaints about state government agencies in NSW, Victoria, Queensland, WA, Tasmania, ACT and NT go to state-based commissioners
  • Small business exemption — Organisations with turnover under $3 million are usually exempt (with exceptions like health service providers)
  • Employee records exemption — Current employer handling of employee records is generally exempt
  • ACMA — Spam and telemarketing complaints go to the Australian Communications and Media Authority
  • Scamwatch/ACCC — Scams and misleading conduct
  • eSafety Commissioner — Image-based abuse, cyberbullying, and online harms
  • Police — Identity theft, stalking, and criminal offences

Tips to Strengthen Your Complaint

Be Specific and Chronological

Vague complaints get slower attention. Lay out dates, times, communications, and precisely which piece of personal information was affected. A one-page timeline attached as a PDF is powerful.

Quantify the Harm

If you lost money, itemise it. If you suffered distress, describe how it affected your sleep, work, or relationships. If you spent hours dealing with fallout, log those hours. Compensation is proportionate to demonstrated harm.

Cite the APP You Think Was Breached

You don't have to be a lawyer, but referencing a specific Australian Privacy Principle (for example, "APP 11 — Security of Personal Information") signals you understand the framework and helps the case officer categorise the complaint quickly.

Stay Professional

Even if you're angry, keep correspondence factual and respectful. Emotional language can slow the process and undermine credibility.

What Happens After a Determination?

If the Commissioner makes a formal determination in your favour, the organisation must comply. If they don't, the determination can be enforced through the Federal Court or Federal Circuit Court. Determinations are also published (with your name usually anonymised) and become part of the public regulatory record, which encourages compliance across the industry.

Frequently Asked Questions

How much does it cost to lodge an OAIC complaint?

Nothing. Lodging a privacy complaint with the OAIC is free. You don't need a lawyer, though for complex or high-value matters, legal advice can be valuable. Community legal centres often provide free advice on privacy issues.

Can I complain anonymously?

You can raise concerns anonymously, but the OAIC generally cannot investigate a complaint or seek compensation on your behalf without knowing who you are. Your identity is kept confidential from the organisation only in limited circumstances; usually the organisation will be told who is complaining so they can respond.

Is there a time limit for lodging a complaint?

The OAIC may decline to investigate complaints made more than 12 months after you became aware of the interference with your privacy. Lodge as soon as reasonably possible after exhausting the 30-day organisation response period.

What if the organisation is based overseas?

The Privacy Act can apply to overseas organisations that carry on business in Australia and collect information from Australians. The OAIC has jurisdiction, though enforcement against foreign entities is more complex. Recent amendments have strengthened extraterritorial reach.

Can I sue the organisation instead of using the OAIC?

Australia does not currently have a general statutory tort of serious invasion of privacy, though reforms are progressing. Class actions have been successful for large breaches (for example, following major telco and health insurer incidents). The OAIC process is usually faster and cheaper than litigation for individual complaints.

Final Thoughts

Filing an OAIC complaint takes patience, but it's one of the few mechanisms Australians have to hold organisations accountable for mishandling personal information. Follow the process: complain to the organisation first, gather solid evidence, quantify your harm, and lodge within 12 months. Even if your individual matter is small, complaints contribute to regulatory attention on systemic problems — and in an era of near-monthly major data breaches, that regulatory pressure matters.

Combine formal complaint mechanisms with proactive privacy hygiene: limit what you share, use tools that respect user data, and audit your digital footprint regularly. The best breach is the one that never touches your information in the first place.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles