What is the OAIC?

Claudia AinsleyWritten byClaudia Ainsley
Reviewed byMatt Leeburn
Updated 26 Aug 2026

The OAIC is the Office of the Australian Information Commissioner, Australia's independent privacy regulator, which enforces the Privacy Act, the Australian Privacy Principles and the Notifiable Data Breaches scheme.

Also known as: Office of the Australian Information Commissioner, Australian Information Commissioner, privacy commissioner

Key points

  • It enforces the 13 Australian Privacy Principles covering how personal information is collected, used, disclosed, stored, accessed and corrected.
  • Organisations must notify the OAIC and affected people of an eligible data breach that is likely to cause serious harm.
  • It handles privacy complaints through conciliation and binding determinations, and can accept enforceable undertakings or seek civil penalties in court.
  • Brokers and lenders handle payslips, bank statements and identity documents every day, so data protection obligations sit squarely with them.
  • It also reviews freedom of information (FOI) decisions about government-held information.

What the OAIC does

Powers and enforcement

Notifiable data breaches and what organisations must do

Not to be confused with

Privacy Act
the Privacy Act is the law; the OAIC is the regulator that enforces it
ASIC
ASIC regulates conduct in credit and financial services; the OAIC regulates how personal information is handled, so a lender can answer to both
Data protection
data protection is what an organisation does to keep personal information safe; the OAIC is the regulator it answers to if that fails

Frequently asked questions

What is the role of the OAIC?

It enforces the Privacy Act 1988 and the Australian Privacy Principles, oversees the Notifiable Data Breaches scheme, handles privacy complaints through conciliation and determinations, investigates serious breaches and can seek civil penalties, publishes guidance for organisations, and reviews freedom of information decisions about government-held information.

Do all data breaches have to be reported to the OAIC?

No. Only eligible data breaches, where personal information has been accessed or disclosed in a way likely to result in serious harm, must be notified to the OAIC and affected individuals. Assess every incident promptly; lower-harm incidents should still be contained, documented and remediated even if notification is not required.

How do I make a privacy complaint to the OAIC?

Raise it with the organisation first, in writing, and keep records of dates, names and correspondence. Let its internal process run. If that does not resolve it, lodge a complaint through the OAIC's online form with your supporting documents and a clear timeline. The OAIC checks jurisdiction, usually tries conciliation, and can investigate and determine the matter if conciliation fails.

How long does the OAIC take to resolve a complaint?

It varies. Conciliation can resolve matters in weeks to months, while formal investigations and determinations often take considerably longer depending on complexity. Being clear about the outcome you want and providing complete evidence up front helps. The OAIC does not give legal advice but will explain the dispute-resolution options.

Can I sue for a privacy breach in Australia?

Yes, in some cases. The Privacy Act now includes a statutory tort for serious invasions of privacy, covering intrusion into someone's seclusion and misuse of their information where the invasion is serious and there was a reasonable expectation of privacy. A complaint to the OAIC is still the usual first route, so get legal advice about both.

Go deeper

Sources

This article is general information only and is not financial advice.