OAIC Complaints: How to Report a Privacy Breach in Australia
If an Australian business, government agency, or organisation has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). This guide explains exactly how to report a privacy breach, what the OAIC can (and cannot) do, and how to maximise your chances of a successful outcome.
What Is the OAIC and When Can You Complain?
The Office of the Australian Information Commissioner (OAIC) is the independent federal regulator responsible for enforcing the Privacy Act 1988 and the 13 Australian Privacy Principles (APPs). You can lodge a complaint when you believe an entity covered by the Privacy Act has interfered with your personal information.
The OAIC handles complaints about:
- Australian Government agencies
- Private sector organisations with an annual turnover of more than $3 million
- Health service providers of any size
- Credit reporting bodies and credit providers
- Tax File Number (TFN) recipients
- Businesses that trade in personal information or provide services to the Commonwealth
Common Examples of Privacy Breaches
- A company exposed your personal data in a cyber incident and failed to notify you.
- An organisation collected sensitive information without consent.
- A business refused to give you access to, or correct, your own personal data.
- Your information was disclosed to a third party without lawful basis.
- Marketing continued after you opted out.
- A health provider shared your medical records inappropriately.
Before You Lodge an OAIC Complaint: Contact the Organisation First
The OAIC generally requires you to complain directly to the organisation before escalating. This is a mandatory first step unless there are special circumstances (such as the entity being impossible to contact).
Step-by-Step: Making an Internal Complaint
- Find the Privacy Officer. Check the organisation's privacy policy — it must list a contact point under APP 1.
- Write a clear complaint. State what happened, when, and what personal information is involved.
- Specify the resolution you want. Examples: deletion of data, an apology, compensation, a correction, or a change in practice.
- Keep copies of everything. Save emails, screenshots, letters, and reference numbers.
- Wait 30 days for a response. If the organisation doesn't reply or you're unhappy with the response, you can go to the OAIC.
How to Lodge a Privacy Complaint with the OAIC
Lodging an OAIC complaint is free and can be done entirely online. The process is designed to be accessible without needing a lawyer.
The Three Lodgement Methods
- Online form: The fastest option, available at oaic.gov.au via the "Privacy complaint form".
- Post: Download the PDF complaint form and mail it to GPO Box 5288, Sydney NSW 2001.
- Phone: Call 1300 363 992 for assistance, especially if you need help due to disability, language, or other accessibility needs.
Information You'll Need to Provide
- Your full name and contact details.
- The name of the organisation you're complaining about.
- A clear description of what happened and when.
- Evidence you contacted the organisation first (dates, copies of correspondence).
- Supporting documents: screenshots, emails, data breach notification letters, policy excerpts.
- The outcome you're seeking.
What Happens After You Lodge a Complaint
The OAIC follows a structured assessment and conciliation process. Most complaints are resolved informally rather than through formal determinations.
The OAIC Complaint Lifecycle
| Stage | What Happens | Typical Timeframe |
|---|---|---|
| 1. Acknowledgement | OAIC confirms receipt and assigns a reference number. | Within 10 business days |
| 2. Preliminary assessment | OAIC checks jurisdiction and whether you contacted the organisation first. | 2–6 weeks |
| 3. Investigation | OAIC requests information from both parties under s 44 of the Privacy Act. | 3–12 months |
| 4. Conciliation | OAIC facilitates a negotiated outcome between you and the organisation. | 1–6 months |
| 5. Determination (rare) | If conciliation fails, the Commissioner may issue a binding determination under s 52. | 6–18 months |
Possible Outcomes
- Apology from the organisation.
- Correction or deletion of your personal information.
- Compensation for financial loss or non-economic loss (hurt, humiliation, distress). Awards typically range from a few hundred dollars to tens of thousands, depending on severity.
- Changes to practices, such as revised policies, staff training, or new security controls.
- Enforceable undertakings or civil penalty proceedings against the organisation in serious cases.
Notifiable Data Breaches: A Separate but Related Scheme
Since February 2018, the Notifiable Data Breaches (NDB) scheme has required covered entities to notify the OAIC and affected individuals of an "eligible data breach" — one likely to cause serious harm. If you received a data breach notification letter, that is the result of this scheme.
What to Do if You've Been Notified of a Data Breach
- Read the notification carefully. It should describe what data was exposed, when, and recommended steps.
- Change compromised passwords immediately and enable multi-factor authentication on affected accounts.
- Place a credit ban with Equifax, Experian, and illion if financial data was exposed. This is free and lasts 21 days (extendable).
- Watch for phishing. Breached email addresses are often sold to scammers who impersonate the breached brand. Be careful of shortened links from unknown senders — tools like Lunyb let you preview the destination of a short URL before clicking, which can help you spot malicious redirects.
- Report to IDCARE (1800 595 160) for free identity recovery support.
- Complain to the OAIC if you believe the organisation's response was inadequate.
Strengthening Your Complaint: Evidence That Matters
Well-documented complaints are resolved faster and more favourably. Weak evidence is the single biggest reason complaints stall or get dismissed.
Evidence Checklist
| Evidence Type | Why It Helps |
|---|---|
| Dated screenshots | Proves what the organisation displayed or sent at a specific time. |
| Email trails | Shows you raised the issue and documents the organisation's response. |
| Data breach notification | Confirms the organisation acknowledged an incident. |
| Medical or financial records | Demonstrates harm — e.g. counselling for distress, fraudulent transactions. |
| Witness statements | Supports your account if third parties observed the breach. |
| Privacy policy excerpts | Highlights contradictions between stated practices and actual conduct. |
When the OAIC May Decline to Investigate
The Commissioner has discretion under s 41 of the Privacy Act to decline investigations. Understanding these grounds helps you present a stronger case.
- You didn't give the organisation a chance to respond first.
- More than 12 months have passed since you became aware of the breach (unless there's a good reason).
- The complaint is frivolous, vexatious, or lacks substance.
- Another body is better placed to deal with it (e.g. a state privacy regulator or the Australian Human Rights Commission).
- The matter is already before a court or tribunal.
- The complaint has already been adequately dealt with.
What to Do if Your Complaint Is Declined
- Request written reasons for the decision.
- Apply for internal review within 28 days.
- Consider the Administrative Appeals Tribunal (AAT) if the decision was legally flawed.
- Explore alternative avenues — industry ombudsmen, state regulators, or private legal action.
State and Territory Privacy Regulators
The OAIC covers federal matters, but each state and territory has its own regime for public sector agencies. If your complaint is about a state school, state hospital, or local council, you likely need a different regulator.
| Jurisdiction | Regulator |
|---|---|
| NSW | Information and Privacy Commission NSW |
| VIC | Office of the Victorian Information Commissioner |
| QLD | Office of the Information Commissioner Queensland |
| WA | No standalone privacy law for state agencies (as of 2024) |
| SA | SA Privacy Committee |
| TAS | Tasmanian Ombudsman |
| ACT | OAIC (under service arrangement) |
| NT | Information Commissioner NT |
Protecting Yourself Going Forward
Lodging a complaint addresses past harm, but reducing your exposure to future breaches matters just as much. A few practical habits make a significant difference.
Practical Privacy Hygiene
- Use a password manager and unique passwords for every account.
- Enable multi-factor authentication wherever available, preferably with an authenticator app rather than SMS.
- Minimise data you share. If a form asks for your date of birth or address and doesn't need it, leave it blank or ask why.
- Use encrypted DNS (such as DNS over HTTPS) to reduce passive tracking by your internet provider.
- Preview shortened links before clicking. Reputable shorteners like Lunyb let recipients inspect destinations and offer privacy-respecting analytics, unlike some trackers that aggressively profile users. For a broader comparison, see our 2026 URL shortener buyer's guide.
- Review app permissions monthly on your phone — revoke location, contacts, and microphone access from apps that don't need them.
- Freeze your credit file if you're not actively applying for finance.
Frequently Asked Questions
How long do I have to lodge an OAIC complaint?
Generally, you should complain within 12 months of becoming aware of the privacy breach. The OAIC can accept later complaints if you provide a reasonable explanation for the delay, such as serious illness or the breach only recently coming to light.
Can I get compensation from an OAIC complaint?
Yes. The Commissioner can order compensation for both financial loss and non-economic harm (distress, humiliation, injury to feelings). Awards vary widely — most are between $3,000 and $20,000, though serious cases involving sensitive health or financial data have attracted higher sums.
Do I need a lawyer to complain to the OAIC?
No. The process is deliberately designed to be accessible to ordinary members of the public. Most complainants self-represent through the conciliation stage. Legal advice can be helpful if your matter is complex, involves significant loss, or proceeds to a formal determination or AAT review.
Will the organisation know I complained?
Yes. The OAIC must share your complaint with the respondent organisation so they can respond. Your identity cannot usually be kept confidential, though in limited circumstances the OAIC can anonymise certain details. If you fear retaliation, raise this with the case officer early.
What's the difference between the OAIC and the ACCC for data issues?
The OAIC enforces the Privacy Act and APPs — rules about how personal information is handled. The ACCC enforces the Australian Consumer Law and competition law, which can cover misleading privacy claims, dark patterns, or unfair contract terms. Serious cases sometimes involve both regulators acting in parallel.
Final Thoughts
Making an OAIC complaint is one of the most effective tools Australians have to hold organisations accountable for mishandling personal information. The process is free, doesn't require legal representation, and can result in meaningful outcomes — from apologies and corrections through to financial compensation and systemic change. The keys to success are contacting the organisation first, documenting everything, and lodging within the 12-month window. Combined with sensible day-to-day privacy habits, exercising your complaint rights helps shift the balance of power back toward individuals in an increasingly data-driven economy.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A practical, step-by-step guide to filing a privacy complaint with the Irish Data Protection Commission in 2026. Learn eligibility, required evidence, submission channels, realistic timelines, and your rights throughout the process.
Singapore PDPA: Your Personal Data Protection Rights Explained
Discover your rights under Singapore's Personal Data Protection Act (PDPA), including access, correction, consent, and data breach notifications. Learn how to file complaints, protect your NRIC, and understand how the PDPA compares to global privacy laws in 2026.
Data Protection Act 2018 Ireland: Complete Guide
Ireland's Data Protection Act 2018 implements the GDPR and sets out the powers of the Data Protection Commission. This complete guide explains who it applies to, your rights, business obligations, penalties and practical compliance steps.
Singapore PDPA vs GDPR: Key Differences for Businesses in 2026
Singapore's PDPA and the EU's GDPR both protect personal data, but they differ significantly in scope, consent rules, penalties, and individual rights. This guide breaks down the key differences every Singapore business should know to stay compliant across both frameworks.