A reviewer leaves an honest one-star review of a business. Happens every day, right?
However, unusually, the business doesn’t just disagree in its public reply. Instead, it publishes the reviewer’s full name and email address.
That’s not just a bad customer service moment. It’s a privacy breach, potentially defamation, and one of the more disorienting things a business can do to someone in public.
A recent r/AusLegal thread covered exactly this scenario: a medical business retaliating against a reviewer by doxxing them in its reply. The thread pulled over 200 comments, with most of them pointing the reviewer somewhere different.
‘Report it to AHPRA.’ ‘No, it’s a Notifiable Data Breach.’ ‘No, delete the review first.’
Which one is right?
None of those is quite right.
Here’s the decision tree that matters: three different remedies, three different bodies, and none of them do what the others do.
Myth: AHPRA will act on a privacy breach by a health practitioner
The reality: if the business retaliating against you is run by a registered health practitioner, AHPRA and its National Boards exist to protect public health and safety. It’s not there to police privacy.
The Health Practitioner Regulation National Law (NSW) makes the protection of the public the paramount consideration for the whole scheme. That’s what a notification against a practitioner is measured against, not whether your personal information was handled properly.
A notification is the right tool if a practitioner’s clinical conduct, health, or professional behaviour puts patients at risk. Publishing a reviewer’s personal details in a fit of pique doesn’t obviously fit that test, and even where it arguably does, that’s not where the complaint goes first in New South Wales.
NSW runs a co-regulatory model: complaints about a registered health practitioner’s conduct, health or performance go to the Health Care Complaints Commission. This works alongside the practitioner’s Health Professional Council and AHPRA’s National Boards behind the scenes, not to AHPRA on its own.
Either way, a notification or HCCC complaint is not built to remedy a privacy breach.
Myth: this is a Notifiable Data Breach matter
The reality: the Notifiable Data Breaches scheme is a specific, narrow mechanism. It requires an entity to notify the Office of the Australian Information Commissioner (OAIC) and affected individuals when it suffers an eligible data breach: unauthorised access, disclosure, or loss of personal information that’s likely to cause serious harm and can’t be remediated. It’s designed for hacks, lost laptops, and misdirected emails: incidents the entity itself has to assess and self-report.
A business deliberately publishing your details can still be an ‘eligible data breach’ under the Notifiable Data Breaches scheme. The scheme covers unauthorised disclosures whether they are accidental or intentional. If a reasonable person would conclude the disclosure is likely to result in serious harm to you, and the business hasn’t been able to prevent that risk, the business may have NDB obligations to notify you and the OAIC.
The right framing is a straightforward privacy complaint: has the business used or disclosed your personal information for a purpose you never agreed to?
Australian Privacy Principle 6 limits an organisation to using personal information only for the purpose it was collected for, unless you consented to something else.
Leaving a public review is not consent to being publicly identified in response. That’s the complaint to make: not an NDB notification, a privacy complaint about a disclosure.
One wrinkle worth knowing: most small businesses with turnover under $3 million sit outside the Privacy Act entirely. However, that exemption doesn’t apply to a business that’s a private sector health service provider: it’s covered by the Privacy Act 1988 (Cth) regardless of turnover. So the size of the business isn’t the question worth asking here; whether it provides a health service is.
Myth: you have to get the review taken down for this to be resolved
The reality: these are two separate problems, and one doesn’t require the other. Your original review is your own honest opinion. Nothing about the business’s retaliatory reply obliges you to delete it, retract it, or negotiate it away to fix what they did in response.
Conflating the two hands the business leverage it shouldn’t have.
What you can complain about to the OAIC is the business’s own conduct: it disclosed your personal information without your consent, for a purpose (retaliating against a bad review) you never agreed to. That stands on its own. Whether your review stays up, comes down, or gets edited is entirely your call, made on its own merits, not a bargaining chip in resolving the privacy complaint.
So which one actually applies to you?
| Situation | Where it goes | What it can achieve |
|---|---|---|
| The business published your name/details without consent, in a way you never agreed to | OAIC privacy complaint (Privacy Act 1988 (Cth)) | An investigation into the disclosure, and potential remedies including compensation |
| The business is a registered health practitioner and the conduct raises a public safety or professional standards concern | HCCC (NSW) / AHPRA notification | Action against the practitioner’s registration or practice, not a privacy remedy |
| The reply also makes false, damaging statements about you (not just disclosing facts) | Defamation | A concerns notice, and potentially damages, if the statement caused or is likely to cause serious harm |
The first two aren’t mutually exclusive, and the third can run alongside either. Start with what actually happened: did they expose facts about you (privacy), attack a practitioner’s fitness to work (AHPRA/HCCC), or say something false and damaging (defamation)? Most doxxing-in-a-reply situations are squarely the first, sometimes with a side of the third.
When the reply crosses into defamation
Publishing your real name and details is a privacy problem regardless of whether every fact in it is true. Yet, if the business’s reply goes further, with false claims about why you left the review, invented conduct, or characterisations designed to make you look dishonest or unreasonable, that’s a separate, and potentially more serious, problem.
Under the Defamation Act 2005 (NSW), a claim requires the publication to have caused, or be likely to cause, serious harm to your reputation: a threshold introduced by the 2021 amendments (commencing 1 July 2021 in NSW) specifically to filter out minor, low-stakes disputes.
Before any court proceeding, the Act also requires a concerns notice to be issued to the business first, giving it the chance to respond, usually by way of an offer to make amends, before things escalate further.
Whether a reply reaches “serious harm” depends on the facts: how public the reply is, what it actually alleges, and what damage you can point to. That’s not a bar you can safely self-assess from a Reddit thread; it’s the reason to get someone across the actual wording to look at it.
Our fact sheet on fake and defamatory Google reviews covers the review side of this in more depth, including what makes a review itself defamatory.
If you have been doxxed, here’s what you can do
Don’t wait to see if the business quietly deletes the reply. Screenshot it, and the review it responded to, immediately, with visible dates. Note anywhere else the information may have been copied or shared.
Work out which category this actually falls into using the table above, and don’t assume you have to pick just one.
If the retaliatory reply is purely a disclosure of true facts about you, the OAIC privacy complaint is your primary path. If it also makes things up about you, or twists what happened into something false and damaging, that’s when a defamation assessment matters, and the two can run side by side.
How O’Brien Criminal & Civil Solicitors Can Help
O’Brien Criminal & Civil Solicitors acts for people on both sides of a defamation dispute, and our defamation practice, led by Special Counsel Stewart O’Connell, regularly advises plaintiffs on exactly this kind of online reputational attack.
We can assess whether what was published meets the serious harm threshold, prepare a concerns notice where it does, and point you toward the privacy complaint pathway where the core issue is the disclosure itself rather than what was said about you.
Request initial advice (no-obligation) via the form below or call us on (02) 9261 4281.
This content is for general information purposes only and does not constitute legal advice. You should seek independent legal advice relevant to your specific circumstances.

Peter O'Brien is the Principal Solicitor of O'Brien Criminal & Civil Solicitors and Australia's leading expert in intentional torts litigation, with over 25 years of experience securing landmark victories in malicious prosecution and unlawful imprisonment cases. Author of Intentional Tort Litigation in Australia and recipient of the Law Council of Australia President's Medal, Peter has achieved record-breaking compensation for clients and is widely recognised for his unwavering commitment to access to justice.