OAIC Complaints: How to Report a Privacy Breach in Australia
If an Australian organisation has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). This guide explains exactly how to report a privacy breach, what the OAIC can and can't do, and how to give your complaint the best chance of a meaningful outcome.
What Is the OAIC and When Can You Complain?
The Office of the Australian Information Commissioner (OAIC) is the independent federal regulator responsible for enforcing the Privacy Act 1988 and the Australian Privacy Principles (APPs). It handles complaints about how Australian Government agencies and most private sector organisations with an annual turnover of more than A$3 million collect, use, store, disclose and secure personal information.
You can lodge an OAIC complaint if you believe an entity covered by the Privacy Act has:
- Collected your personal information unfairly or without consent
- Used or disclosed your information for a purpose you didn't agree to
- Failed to keep your data secure, resulting in a data breach
- Refused to let you access or correct your own information
- Sent you direct marketing you can't opt out of
- Transferred your information overseas without appropriate safeguards
The OAIC also oversees the Notifiable Data Breaches (NDB) scheme, the Consumer Data Right (CDR), My Health Record, and the handling of Tax File Numbers (TFNs) and credit information.
Who the OAIC Cannot Help With
The OAIC does not handle every privacy issue. It generally cannot assist with:
- Small businesses with turnover under A$3 million (with some exceptions, like health service providers)
- State or territory government agencies — these have their own privacy regulators
- Employee records held by your current or former employer in direct relation to employment
- Media organisations acting in the course of journalism
- Registered political parties and political acts
For state matters, contact the relevant body — for example, the Information and Privacy Commission NSW, the Office of the Victorian Information Commissioner, or the Office of the Information Commissioner Queensland.
Step 1: Complain to the Organisation First
Before the OAIC will investigate, you are usually required to complain directly to the organisation and give them a reasonable chance to respond — typically 30 days. This is a mandatory first step under section 40(1A) of the Privacy Act.
How to Make an Effective Internal Complaint
- Find the privacy officer. Check the organisation's privacy policy — it's required to list a contact point. Look for a "Privacy Officer" or "Data Protection Officer" email.
- Put your complaint in writing. Email is best because it creates a timestamped record.
- Be specific. State exactly what happened, when, what personal information was involved, and which APP you believe was breached (if you know).
- State what outcome you want. An apology, deletion of your data, a change to their processes, or compensation.
- Set a deadline. Mention that if you don't receive a satisfactory response within 30 days, you'll escalate to the OAIC.
Keep every email, letter and reference number. The OAIC will ask for this correspondence when you escalate.
Step 2: Gather Your Evidence
A well-documented complaint moves faster. Before contacting the OAIC, collect:
- Copies of all communications with the organisation (emails, letters, chat transcripts)
- Screenshots of the breach — for example, an exposed account, a phishing email referencing leaked data, or a public web page revealing your details
- Any data breach notifications you received
- News articles if the incident was publicly reported (e.g. Optus, Medibank, Latitude)
- Evidence of harm: unauthorised credit enquiries, scam calls, identity theft, financial loss, or psychological distress
- A clear timeline of events with dates
If the breach involves credential leaks or exposed URLs that revealed personal data, archive those pages (using a tool like the Wayback Machine) before they disappear.
Step 3: Lodge Your Complaint With the OAIC
Once 30 days have passed without a satisfactory response, you can formally complain to the OAIC. There are three ways to do this.
Online Form (Recommended)
Visit oaic.gov.au and use the "Privacy complaint form". It walks you through each required field and lets you upload supporting documents directly. This is the fastest route and gives you an immediate reference number.
By Post or Email
You can download the paper complaint form and send it to:
Director of Complaints
Office of the Australian Information Commissioner
GPO Box 5288
Sydney NSW 2001
Or email it as a PDF attachment to enquiries@oaic.gov.au.
By Phone
Call the OAIC Enquiries Line on 1300 363 992. They can take details and send you the appropriate forms, and offer the National Relay Service and Translating and Interpreting Service (TIS) on 131 450.
What Information Your Complaint Must Include
To be accepted, your complaint should contain:
- Your full name and contact details (anonymous complaints generally cannot be investigated)
- The name of the organisation or agency you're complaining about
- A clear description of what happened and when
- How you believe your privacy was interfered with
- Evidence you've already complained to the organisation and their response (or lack of)
- What you'd like to resolve the matter
- Any supporting documents
What Happens After You Lodge
The OAIC follows a structured process. Understanding each stage helps set realistic expectations.
1. Acknowledgement and Early Assessment
Within a few weeks you'll receive acknowledgement and a case officer may be assigned. They assess whether the OAIC has jurisdiction and whether the complaint is suitable for investigation.
2. Preliminary Enquiries
The OAIC may ask the organisation for its side of the story and request documents. They often try to broker an early resolution at this stage without a formal investigation.
3. Conciliation
If the matter isn't resolved informally, the Commissioner can direct the parties to conciliation under section 40A of the Privacy Act. This is a confidential, without-prejudice negotiation. Most OAIC complaints end here with an agreed outcome.
4. Formal Investigation and Determination
If conciliation fails and the Commissioner believes the matter warrants it, a formal investigation can lead to a determination under section 52. The Commissioner can order the organisation to:
- Stop the conduct
- Take specific steps to prevent repetition
- Apologise
- Compensate you for loss or damage, including for hurt feelings
Typical Timeframes
Simple matters may resolve in 3–6 months. Complex complaints, especially those tied to large-scale data breaches, can take 12 months or longer. The OAIC publishes current timeframes on its website.
Compensation: What You Might Receive
Historically, OAIC determinations have awarded compensation ranging from a few hundred dollars for minor distress up to tens of thousands for serious cases involving financial loss, identity theft or significant psychological injury. The 2024 representative complaint against the Department of Home Affairs over the detainee data breach, for example, resulted in substantial payments to affected individuals.
Compensation is not automatic. You must demonstrate loss — keep records of counselling bills, time spent remediating the breach, cancelled cards, lost opportunities, and documented distress.
The Notifiable Data Breaches Scheme
If an organisation subject to the Privacy Act experiences an "eligible data breach" likely to result in serious harm, it must notify both the affected individuals and the OAIC — generally within 30 days of becoming aware. If you receive such a notification, you should:
- Read it carefully and note what categories of data were exposed
- Change passwords on affected accounts and enable multi-factor authentication
- Place a free credit ban with Equifax, Experian and illion if financial data was involved
- Watch for phishing attempts referencing the breach
- Keep the notification — it's evidence if you later lodge a complaint
You do not have to wait for a notification to complain. If you independently discover a breach, you can report it yourself.
Protecting Your Privacy Day-to-Day
Lodging complaints is reactive. The best strategy is layered prevention. A few practical habits reduce how much personal data ends up in risky hands in the first place:
- Minimise data sharing. Only provide personal information when legally required or genuinely necessary.
- Use a password manager and unique passwords for every account.
- Enable multi-factor authentication on email, banking, government and social accounts.
- Use encrypted DNS (such as DNS-over-HTTPS) and privacy-respecting browsers.
- Be careful what you click. When sharing links — especially on social media, in bios or in marketing — use a privacy-conscious shortener like Lunyb that doesn't harvest click data to profile recipients. For an in-depth look at how shorteners compare on privacy, see our 2026 buyer's guide to URL shorteners.
- Review app permissions on your phone every few months and revoke anything unused.
Alternatives and Parallel Actions
Depending on the circumstances, you might also consider:
- IDCARE (1800 595 160) — Australia's national identity and cyber support service, free for individuals
- ReportCyber — for cybercrime reports to police via cyber.gov.au
- Scamwatch — if the breach has led to scams targeting you
- Australian Financial Complaints Authority (AFCA) — if a bank, insurer or super fund mishandled your data
- Telecommunications Industry Ombudsman (TIO) — for telco-related breaches
- Civil action — the new statutory tort of serious invasions of privacy, introduced in late 2024, opens the door to direct court claims in some circumstances
You can pursue several of these in parallel with your OAIC complaint.
Common Mistakes to Avoid
- Skipping the internal complaint. The OAIC will usually bounce it back.
- Being vague. "They leaked my data" isn't enough — specify what, when and how you know.
- Emotional language without evidence. Stick to facts and attach documents.
- Waiting too long. There's no strict deadline, but the OAIC can decline stale complaints and evidence degrades.
- Expecting a criminal outcome. The OAIC is a civil regulator; it doesn't prosecute individuals.
Frequently Asked Questions
How much does it cost to complain to the OAIC?
Nothing. Lodging a privacy complaint with the OAIC is completely free, and you don't need a lawyer. If a formal determination awards compensation, you receive it in full.
Can I complain anonymously?
Generally no. The OAIC needs to identify you to investigate meaningfully and to communicate outcomes. You can request that your identity be kept confidential from the respondent in some circumstances, but this is rare and limits what the regulator can do.
What if the organisation is overseas?
The Privacy Act applies extraterritorially to overseas organisations that have an "Australian link" — for example, carrying on business in Australia and collecting personal information here. Major global platforms generally fall within scope. The OAIC can and does investigate them, as seen in actions against companies like Facebook and Clearview AI.
How long do I have to lodge a complaint?
There is no strict statutory limitation, but the Commissioner may decline to investigate a complaint lodged more than 12 months after you became aware of the issue. Lodge as soon as practical after the 30-day internal response window closes.
Can I appeal if I'm unhappy with the outcome?
Yes. If the Commissioner makes a formal determination under section 52, either party can seek review in the Administrative Review Tribunal (ART), which replaced the AAT in late 2024. If the OAIC simply closes your file without a determination, you can request internal review or lodge a complaint with the Commonwealth Ombudsman about the handling of your matter.
Final Thoughts
The OAIC complaint process rewards preparation. Document everything, exhaust the internal complaint channel, present a clear narrative supported by evidence, and know what outcome you want. Even if your individual complaint settles at conciliation, these matters feed into the OAIC's regulatory intelligence and influence enforcement priorities — meaning your effort helps raise the privacy bar for every Australian.
Privacy protection is a shared responsibility. Regulators enforce the rules, organisations must comply, and individuals need to stay vigilant about where their data goes. Combine formal complaints when something goes wrong with proactive habits — minimal data sharing, strong authentication, and privacy-respecting tools — and you'll be far better placed than most.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
GDPR in Ireland: Your Privacy Rights Explained
GDPR gives everyone in Ireland powerful rights over their personal data, from access and erasure to portability and objection. This guide explains each right in plain English, how to enforce it through the Data Protection Commission, and practical steps to protect your privacy online.
Singapore Online Safety Act 2026: Complete Guide for Businesses and Users
Singapore's Online Safety Act 2026 reshapes how online platforms, advertisers, and intermediaries handle harmful content. This complete guide covers scope, obligations, penalties, and practical compliance steps for businesses and users in Singapore.
How Canadian Businesses Should Handle Data Privacy in 2026
A practical 2026 guide to data privacy for Canadian businesses — covering PIPEDA, Quebec Law 25, consent, breach response, vendor management, and CPPA preparation. Learn exactly what to implement to stay compliant and build customer trust.
Privacy Rights in Canada 2026: A Complete Guide for Individuals and Businesses
Canadian privacy law has changed dramatically with Bill C-27, Quebec's Law 25, and expanded provincial rules. This 2026 guide explains your rights, business obligations, and practical steps to protect personal information in the digital age.