

Preparing for managing customer complaints after a privacy breach is a critical step in your data breach response planning. In this post, we delve into the steps organisations can take to ensure that it’s not the breach itself that’s memorable, but your well-executed response to it.
Your customers may make a complaint to the Office of the Australian Information Commissioner (OAIC) if they believe their personal information has been mishandled in a manner that breaches the Australian Privacy Principles. However, they must follow a specific process – and your organisation has an opportunity to resolve the complaints and improve customer sentiments at the first stage.
Individuals must first bring their complaint to your organisation if they think you have mishandled their data before they can go to the OAIC.
There is no specific format or other requirements covering how the complaint has to be lodged or handled by your organisation. Instead, customers are directed to the organisation’s privacy policy to find those contact details.
This is where you have an opportunity to improve customer relations. Try and make it as easy as possible for customers to contact you. It will only make things worse if you make an already unhappy customer jump through more hoops.
Contacting you should be easy. Your privacy policy should clearly set out:
The OAIC provides a template letter for privacy complaints. And we think sharing a template can be helpful too. It helps your customers understand the information you’re after and helps your organisation better manage the complaints, since the information is more likely to be shared logically and clearly. You can even provide the customer with an opportunity to tell you what they want out of it, which can make resolving the complaint easier.
Here’s the OAIC’s template:

Source: https://www.oaic.gov.au/privacy/privacy-complaints/complain-to-an-organisation-or-agency
Legally, you are not required to respond to the complaint. However, again, it does offer an opportunity for you to improve customer relations.
As we outlined above, offering a template can prove helpful when you give your customers the opportunity to let you know what a successful resolution looks like.
You could also review the OAIC’s likely resolutions and use them for inspiration for your response.
The OAIC, if asked to investigate, may seek the following resolutions:
You might choose to use this list as a guide when offering solutions to your customer complaints following a privacy breach. However, often people are interested in a genuine apology and an undertaking to ensure that the same issue doesn’t reoccur.
Remember, if you can resolve the complaint at this stage, then it won’t proceed to the OAIC.
Once the customer complains to the OAIC, the process is largely out of your hands.
From there, this is what will happen:
Your legal obligations following a breach are one thing, but you will also need to consider your reputation and how to best manage it with your customers in the aftermath.
Here are some quick tips for managing complaints and queries from concerned (and upset) customers following a privacy breach:
If you need assistance developing your processes for handling customer privacy complaints or your data breach response plan, reach out. Our experienced privacy consultants would love to help.
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.