Recent Privacy Awareness Week puts privacy complaints and dispute resolution under the spotlight

Trust is built in the moment a complaint is handled, not when the privacy policy is published.

The OAIC Privacy Awareness Week 2026 has passed and everyone has moved on. However, the message was not just important for that one week, it is important every day.

The theme was “Trust is built here – In every privacy complaint. In every resolution.”

The message is straightforward: government agencies and commercial entities should lift the standard of how they handle privacy complaints and disputes, with clearer channels, better reasoning, stronger documentation and a more disciplined use of privacy impact assessments.

For organisations, the message is important: complaint handling is no longer a back-office admin task. It is now a trust, conduct and governance issue that can expose whether privacy obligations are genuinely embedded or only written down.

In plain English, the OAIC is saying that people expect to be heard, and they expect organisations to respond fairly, quickly and transparently. If the process is hard to find, hard to use or poorly explained, the organisation may be creating the very distrust it is trying to avoid. That matters for banks, insurers, health providers, technology firms, universities, councils and any business that collects personal information.

It also matters beyond the obvious Privacy team.

Complaint handling touches customer service, risk, legal, compliance, cyber incident response, HR, frontline operations and the board’s oversight of culture and accountability.

Two practical questions are worth asking every day:

  • Can a person easily find the right channel to complain?
  • If a privacy issue landed on the board table tomorrow, would we be able to show how it was handled, who owned it and what changed?

Boards and executives should be asking whether privacy complaints are being treated as signals of systemic weakness, not isolated nuisances. They should want to see trend data, root cause analysis, time to resolution, evidence of learning and proof that recurring issues are being fixed rather than repeatedly explained away.

The critical role of risk managers is to connect the dots. Complaint data, breach data, conduct issues and operational failures often sit in separate silos. Risk managers should help turn those fragments into a single view of control effectiveness, accountability and uplift priorities.

Practical next steps include checking maturity in complaint handling, evidence quality and escalation discipline; clarifying ownership across functions; and making sure remediation actions are tracked to completion. That is where a targeted maturity assessment can be valuable: it helps identify gaps quickly, prioritise uplift and give leaders board-ready discussion points without immediately defaulting to a large consulting program.

Signal: if your complaint handling process cannot stand up to scrutiny, it is probably not strong enough for the next wave of privacy expectations.

#Privacy #OAIC #RiskManagement #Governance #CyberSecurity #ConductRisk #PrivacyAwarenessWeek

More from the Reading Room

Regulator sharpens the warning on facial recognition

The OAIC has updated its facial recognition guidance for APP entities using biometric technology in high-volume, publicly accessible retail spaces. The update reflects the ART’s March 2026 Bunnings decision and reinforces that each deployment needs…

Risk Maturity in Action: Turning Customer Promises into Reliable Outcomes

Two recent ASIC matters provide a useful opportunity to think differently about risk management. They can be read as stories about compensation, penalties and compliance...

APRA grants Revolut an ADI licence — a reminder that prudential entry standards still matter

APRA has granted an authorised deposit-taking institution (ADI) licence to Revolut. This is a substantive licensing decision and a current prudential development for boards, risk teams and governance functions watching new entrants into the banking…

The Qantas privacy finding: a positive lesson in third-party oversight

A serious data breach does not automatically mean governance failed. The more important question is whether an organisation can demonstrate that it understood the risks,...