The OAIC is the Office of the Australian Information Commissioner, Australia's independent privacy regulator, which enforces the Privacy Act, the Australian Privacy Principles and the Notifiable Data Breaches scheme.
Also known as: Office of the Australian Information Commissioner, Australian Information Commissioner, privacy commissioner
Key points
- It enforces the 13 Australian Privacy Principles covering how personal information is collected, used, disclosed, stored, accessed and corrected.
- Organisations must notify the OAIC and affected people of an eligible data breach that is likely to cause serious harm.
- It handles privacy complaints through conciliation and binding determinations, and can accept enforceable undertakings or seek civil penalties in court.
- Brokers and lenders handle payslips, bank statements and identity documents every day, so data protection obligations sit squarely with them.
- It also reviews freedom of information (FOI) decisions about government-held information.
What the OAIC does
The OAIC is led by the Information Commissioner and supported by investigators, dispute-resolution officers and guidance teams. Its functions are privacy regulation and enforcement under the Privacy Act 1988 and the Australian Privacy Principles; oversight of the Notifiable Data Breaches scheme; handling privacy complaints, attempting conciliation and making determinations where that fails; investigations, enforceable undertakings and civil penalty proceedings; plain-English guidance, templates and compliance tools; and reviewing freedom of information decisions.
That makes it both the point of contact for people whose privacy has been affected and the practical regulator for any organisation that handles personal information, from a two-person brokerage to a bank.
Powers and enforcement
The OAIC uses a graduated approach. It can require documents and information and interview people in a formal inquiry. Many complaints resolve through conciliation; where that fails it can issue binding determinations with remedial directions, such as orders to amend practices, give access to or correct information, and public findings. Organisations can give enforceable undertakings, which the Federal Court can enforce if breached, and for serious or repeated breaches the OAIC can seek civil penalties through the courts.
Which tool it uses depends on how serious and systemic the conduct is, how cooperative the organisation has been and the public interest in deterrence. Its enforcement history includes major data breach investigations, enforceable undertakings and court action for penalties.
Notifiable data breaches and what organisations must do
An eligible data breach occurs when personal information is accessed or disclosed in a way likely to result in serious harm, whether financial, physical, psychological or reputational. The organisation must assess the incident reasonably and quickly and, if it is eligible, notify the OAIC and affected individuals as soon as practicable, describing the breach and the information involved, the estimated number of people affected, recommended steps for them and a contact point.
Practical preparation reduces the risk of getting this wrong: a current privacy policy, a map of personal information flows, privacy impact assessments for high-risk projects, security controls such as encryption, access controls and logging, a tested breach response plan with a named incident lead, staff training, clear privacy clauses in vendor and cloud contracts, and regular reviews of retention and destruction practices.
Not to be confused with
- Privacy Act
- the Privacy Act is the law; the OAIC is the regulator that enforces it
- ASIC
- ASIC regulates conduct in credit and financial services; the OAIC regulates how personal information is handled, so a lender can answer to both
- Data protection
- data protection is what an organisation does to keep personal information safe; the OAIC is the regulator it answers to if that fails
Frequently asked questions
What is the role of the OAIC?
It enforces the Privacy Act 1988 and the Australian Privacy Principles, oversees the Notifiable Data Breaches scheme, handles privacy complaints through conciliation and determinations, investigates serious breaches and can seek civil penalties, publishes guidance for organisations, and reviews freedom of information decisions about government-held information.
Do all data breaches have to be reported to the OAIC?
No. Only eligible data breaches, where personal information has been accessed or disclosed in a way likely to result in serious harm, must be notified to the OAIC and affected individuals. Assess every incident promptly; lower-harm incidents should still be contained, documented and remediated even if notification is not required.
How do I make a privacy complaint to the OAIC?
Raise it with the organisation first, in writing, and keep records of dates, names and correspondence. Let its internal process run. If that does not resolve it, lodge a complaint through the OAIC's online form with your supporting documents and a clear timeline. The OAIC checks jurisdiction, usually tries conciliation, and can investigate and determine the matter if conciliation fails.
How long does the OAIC take to resolve a complaint?
It varies. Conciliation can resolve matters in weeks to months, while formal investigations and determinations often take considerably longer depending on complexity. Being clear about the outcome you want and providing complete evidence up front helps. The OAIC does not give legal advice but will explain the dispute-resolution options.
Can I sue for a privacy breach in Australia?
Yes, in some cases. The Privacy Act now includes a statutory tort for serious invasions of privacy, covering intrusion into someone's seclusion and misuse of their information where the invasion is serious and there was a reasonable expectation of privacy. A complaint to the OAIC is still the usual first route, so get legal advice about both.
Related terms
Privacy Act
The Privacy Act 1988 is the Australian law that sets out how government agencies and many organisations must collect, use, disclose and correct personal information, including credit reporting data.
Read definitionData protection
Data protection is the legal duty of brokers and lenders to handle customers' personal information under the Privacy Act and the Australian Privacy Principles, from collection to secure destruction.
Read definitionASIC
ASIC is the Australian Securities and Investments Commission, the regulator for companies, markets, financial services and consumer credit, which licenses providers, keeps public registers and enforces conduct laws.
Read definitionACCC
The ACCC is the Australian Competition and Consumer Commission, the national regulator that enforces competition and consumer law, covering misleading conduct, cartels, product safety and unfair contract terms.
Read definitionAPRA
APRA is the Australian Prudential Regulation Authority, the statutory regulator responsible for prudential regulation of banks, credit unions, insurers and superannuation funds, protecting depositors, policyholders and fund members.
Read definitionAUSTRAC
AUSTRAC is Australia's financial intelligence unit and anti-money laundering regulator: it collects reports from regulated businesses, analyses them and supervises reporting entities under the AML/CTF Act.
Read definitionGo deeper
Sources
This article is general information only and is not financial advice.