If a company says your personal information was exposed, work on two tracks: protect your accounts and report the conduct. A bank or card issuer handles suspicious transactions; a regulator may examine security, notification, privacy, or misleading statements. One route doesn't replace the other.

Start with account protection and a dated evidence file. Then choose the office whose authority matches the problem. This article is for U.S. consumers. State procedures differ, and the GDPR's 72-hour rule is not a U.S. consumer deadline.

Start here

  1. Save the breach notice. Note when and how you received it, the company's stated incident date, and the categories of information involved.
  2. Secure exposed accounts. Change exposed or reused passwords, turn on multifactor authentication, and contact banks or card issuers about suspicious activity.
  3. Record any harm. Keep statements, unauthorized-charge records, identity-theft reports, lost-time notes, fees, and out-of-pocket costs.
  4. Ask the company questions in writing. Ask what happened, what data was involved, and what protection or correction it offers. You usually don't have to wait for an answer before contacting a regulator.
  5. Pick the right route. The FTC, a state office, HHS OCR, IC3, and a financial institution deal with different problems.
  6. Write from confirmed facts. Separate what the notice establishes from what you suspect. Attach copies and redact sensitive information.
  7. Keep the confirmation. Store the complaint number, submitted materials, and follow-up dates together.

What a data-breach complaint can do

A breach notice is the company's account of an incident. A consumer complaint adds your account of what may have gone wrong: weak security, an inaccurate or delayed notice, a misleading promise, an unanswered request, or harm that followed.

The exposure itself doesn't prove that the company violated a particular law. Regulators generally need facts about what happened, what the company knew, how it responded, and whether that conduct falls within the agency's authority.

Problem Appropriate starting point What to expect
Poor security, misleading statements, or a company that won't respond FTC complaint portal The FTC may use reports in enforcement work. It generally doesn't act as your private lawyer or promise compensation.
Possible state privacy, consumer-protection, or breach-notification violation Your state attorney general or, where applicable, state privacy regulator The office may review, investigate, or refer the complaint. Authority, filing methods, and deadlines differ by state.
Protected health information handled by a HIPAA-covered organization HHS Office for Civil Rights OCR can review possible HIPAA violations. HIPAA doesn't cover every health app, employer, website, or data broker.
Hacking, extortion, account takeover, or another internet crime IC3 and local law enforcement A report can help law enforcement identify patterns. It doesn't replace notifying your bank or card issuer.
Unauthorized credit-card transaction or billing error The card issuer's billing-dispute department This is a payment dispute, not just a privacy complaint. Separate deadlines and documentation rules apply.

Protect yourself before filing

Secure exposed accounts

Reach the company through a website or phone number you already know, rather than through a link in an unexpected breach email. If a password was exposed or reused elsewhere, change it and use a different password for each important account. Turn on multifactor authentication where it's available.

Contact your bank, credit-card issuer, payment app, or other financial provider immediately if account or payment information may have been exposed. Ask whether the account, card, credentials, or payment method should be blocked or replaced.

A security freeze with the major credit bureaus or a fraud alert may also help. A regulator complaint won't stop someone from using stolen credentials, so account protection comes first.

Build an evidence file

Keep the original notice, but send copies unless a portal specifically asks for the original. Don't put full Social Security numbers, passwords, authentication codes, or complete account numbers in ordinary email. Redact them from attachments unless a secure form requires the information.

Useful records include:

The FTC's breach-response guidance is written for businesses, not consumers. Its questions can still help you organize a complaint: What does the company know? Did it investigate the affected systems? What remediation did it offer?

Choose the complaint route

FTC complaints

The FTC is a reasonable starting point for reports about a company's security practices, inaccurate or deceptive breach communications, or conduct that may affect many consumers. Identify the company and service, explain what the notice said, and compare the company's response with any promises it made.

A useful report answers these questions:

The FTC may use your report to spot patterns or support enforcement priorities. Filing doesn't guarantee that the agency will contact you, open a case, or recover your losses.

State attorney general and privacy complaints

State attorneys general often accept consumer-protection complaints, but the correct office depends on the facts and the law involved. Begin at your state's official website and look for its consumer-protection or privacy complaint process. Some states have a separate privacy regulator.

Don't assume that a breach notice alone establishes a state-law violation. State laws differ on the information covered, the required security standard, notice timing, available remedies, and the deadline for a legal claim.

California has a separate issue to check. The California attorney general's CCPA guidance says that, before filing a qualifying private lawsuit, a consumer must give the business written notice identifying the alleged CCPA violations and allow 30 days for a written response about whether the violations have been cured. That isn't a universal 30-day waiting period for an attorney general complaint. The CCPA private right of action also applies only to specific data-breach circumstances. Verify the current law before relying on a pre-suit notice.

HIPAA complaints to HHS OCR

HHS OCR is the route for a possible HIPAA violation involving a covered health care provider, health plan, health care clearinghouse, or business associate. An ordinary consumer app or an employer may not fall under HIPAA merely because it collects health-related information.

OCR complaints generally must be filed within 180 days of when you knew or reasonably should have known about the alleged violation. OCR may extend that period for good cause. This is your complaint deadline; it is different from the HIPAA breach-notification rule that generally gives the organization up to 60 days to notify affected individuals.

Use the HHS Office for Civil Rights resources and the current complaint instructions. Include:

OCR can review a possible HIPAA violation, but an OCR complaint isn't a guaranteed claim for personal damages.

IC3 and law-enforcement reports

Report suspected criminal conduct, such as hacking, extortion, account takeover, or online theft, through the Internet Crime Complaint Center's data-breach reporting page. The page asks for a detailed complaint and recommends using the words "data breach" in the incident description.

The Department of Justice reporting guidance lists federal and local reporting options. Include transaction details, suspicious messages, account or wallet information, and the approximate financial loss. Report the same activity to your bank or card issuer immediately. An IC3 report doesn't freeze an account or reverse a transaction.

Credit-card and bank disputes

A privacy complaint and an unauthorized-transaction dispute are separate matters. If a credit-card statement contains a billing error, the FTC says the issuer should receive your written dispute within 60 days after the first statement containing the error was sent. Use the issuer's billing-dispute address, keep a copy, and retain proof of delivery.

The FTC provides a sample dispute letter and explains the credit-card billing-error process.

Debit cards, prepaid cards, electronic transfers, payment apps, and wire transfers can follow different rules. Notify the provider right away, use its required reporting method, and ask what documents it needs. Don't wait for a regulator to decide whether the company failed to protect your data.

Deadlines that are easy to confuse

Deadline Applies to What it means for you
180 days HIPAA complaint to OCR File promptly after learning of the alleged violation. Ask OCR about a good-cause extension if necessary.
Generally 60 days HIPAA breach notification by the organization This is generally the entity's notification duty, not your deadline to complain.
30 days California CCPA pre-suit notice A written notice and response period may be required before a qualifying private lawsuit. It isn't a universal deadline for an attorney general complaint.
60 days Credit-card billing-error dispute The issuer must receive the written dispute within the applicable period described in the FTC guidance.
No single nationwide period FTC and state reports Agency procedures and state legal limitation periods vary. File when you have enough facts rather than waiting for a perfect record.

The GDPR's 72-hour rule concerns an organization notifying a supervisory authority after certain breaches. It isn't a general deadline for a U.S. resident to file a complaint. GDPR procedures belong with the relevant European or UK supervisory authority.

How to write the complaint

Put the incident and your main concern near the top. A short timeline is easier to evaluate than a long account that mixes facts, guesses, and conclusions.

General complaint template

Subject: Complaint about a data breach at [Company]

I am a U.S. consumer and account holder or customer of [Company].

Company and service:
[Company name, website, product, and account type]

What happened:
I learned about the incident on [date] through [breach notice, account activity, news report, or other source]. The company said [quote or summarize the notice]. The information involved may include [list only what you know].

Why I am complaining:
I believe the company may have [failed to secure the information, delayed or failed to notify consumers, made an inaccurate statement, failed to investigate, or failed to address a reported problem]. The facts supporting this concern are:

- [Fact and date]
- [Fact and date]
- [Fact and date]

My contact with the company:
I contacted [department or person] on [date]. The response was [summarize], or I received no response.

Harm or continuing risk:
[Describe unauthorized transactions, identity-theft activity, account access, expenses, or other specific effects. If you have no confirmed loss, describe the risk without claiming a loss.]

Documents available:
[List the breach notice, correspondence, statements, screenshots, reports, and other evidence. Attach copies and redact sensitive information.]

I ask your office to review whether the company complied with the laws within your authority and to record the company's response to affected consumers. I understand that the agency may not represent me or recover money for me.

Name:
Mailing address:
Email:
Phone:
Preferred contact method:

Keep each statement accurate. If you suspect that the company knew about a vulnerability before the incident, write "the available records suggest" and identify those records. Don't present the suspicion as a proven fact.

California pre-suit notice template

Use this only when evaluating a qualifying California private lawsuit. It isn't a substitute for an attorney general complaint:

Subject: Written notice of alleged CCPA violation

To [Company]:

I am a California resident. I believe [Company] violated [specific CCPA provision, if verified] by [describe the specific conduct] in connection with [incident and date].

The personal information involved was [describe the category without including the full identifier]. The facts supporting this notice are [brief timeline and evidence].

Please provide a written response within 30 days stating whether the alleged violation has been cured and that it will not recur. I am preserving the breach notice, account records, and our communications.

Name:
Address:
Date:

Check the current California statute and the company's correct legal name before sending the notice. A vague allegation or notice sent to the wrong entity may not satisfy a legal requirement.

After you submit

Save the confirmation page, email, case number, and exact version of the complaint. Keep a calendar reminder for follow-up requests, but don't send the same material every few days.

If another unauthorized charge appears, contact the financial institution again and update the dispute record. If the company corrects its notice or offers a remedy, save that communication and send it to the agency when it bears on your complaint.

An agency report doesn't automatically enroll you in a class action or settlement. If you receive a settlement notice, verify the case through the court docket or the named settlement administrator before providing more personal information.

Common mistakes to avoid

Frequently asked questions

Will an FTC complaint get my money back?

Not necessarily. The FTC may use your report for enforcement or pattern detection, but it generally doesn't handle individual reimbursement claims. Pursue unauthorized charges directly with the bank, card issuer, or payment provider.

Do I have to contact the company before filing?

U.S. consumers generally can report a concern to the FTC, a state agency, OCR, or IC3 without waiting for the company. Contacting the company first is still useful when you need account protection, a correction, transaction assistance, or a written explanation. California's pre-suit CCPA notice requirement is a separate issue.

What if I don't know exactly what data was exposed?

State what the notice confirms and label everything else as unknown or suspected. Ask the company to identify the affected data categories, dates, and mitigation steps. Don't assume that a Social Security number or medical record was exposed unless the evidence supports it.

Is a 72-hour deadline part of a U.S. data-breach complaint?

No. The commonly cited 72-hour period comes from the GDPR and generally concerns a business notifying a supervisory authority. It isn't a nationwide U.S. deadline for consumers.

Can I file a HIPAA complaint about any health-data breach?

No. HIPAA generally applies to covered entities and business associates. Confirm that the organization falls within that scope, then check the 180-day OCR complaint period and the current filing instructions.

Before submitting anything, make the bank or card-issuer calls, change exposed or reused credentials, and create the dated evidence file. Then send the complaint through the route that matches the conduct.