If you think a company broke its privacy policy, start by preserving the exact version of the policy and matching one specific fact to its wording. Then contact the company's privacy team in writing. For a U.S. consumer, you can also report suspected deceptive business practices through the FTC's ReportFraud form.
An FTC report isn't a substitute for asking the company for access, deletion, correction, or an opt-out. It also doesn't guarantee a personal remedy, compensation, or an investigation.
The right next step depends on what actually happened. A misleading promise, a missed rights request, a security exposure, and unclear wording aren't the same complaint.
Identify the type of privacy complaint
| Problem | Best first step | Possible escalation |
|---|---|---|
| The company's conduct appears to contradict its policy | Preserve the policy wording and ask for an explanation | FTC report or state consumer-protection agency |
| You want access, deletion, correction, or an opt-out | Send a clearly labeled privacy-rights request through the company's designated method | Applicable state privacy agency or regulator |
| Your account or data may have been exposed | Secure the account and document the incident | A separate security or data-breach complaint may be appropriate |
| The policy is vague or leaves out an important detail | Record the omission and describe the actual practice | A transparency or deception concern may be reportable |
A policy can be useful evidence without automatically proving that a law was violated. The result may depend on the wording, the version in effect, what the company actually did, where you live, the kind of business involved, and the remedy you want.
A browser connection to an analytics or advertising domain is also not, by itself, proof that your information was sold or disclosed. It may show a technical connection, but it doesn't establish what data was sent, whether it identified you, or how the recipient used it.
Gather evidence before filing
Create a short, factual record before you complain. Keep the complete file privately and send only the material needed to explain the issue.
- Save the policy. Record the page address, the date you accessed it, any effective date, and the exact paragraph that concerns you. Save a PDF or screenshot because online policies can change.
- Make a timeline. Include the dates and times of the relevant account action, purchase, consent choice, email, call, or privacy request.
- Describe what you observed. Say what happened without guessing about the company's internal systems. Identify the message you received, the setting you selected, or the request you submitted.
- Keep the correspondence. Save confirmation emails, support tickets, chat transcripts, and replies. Note every case number.
- Describe the impact. Explain the unwanted disclosure, continued marketing, account access, privacy risk, financial loss, or other concrete effect. Avoid overstating harm.
- Redact unnecessary information. Remove passwords, full payment-card numbers, Social Security numbers, medical details, and other people's information from attachments.
You can use a private case label in your own notes, but don't assume a formal rights request can be completely anonymous. The company may need enough information to locate your account and verify your identity. If it asks for verification, request a secure submission method instead of emailing a government ID or sensitive account information.
Contact the company in writing
Use the privacy, data-protection, or consumer-rights contact listed in the policy. If there isn't one, ask customer support to route the matter to the privacy team. Written contact gives you a record of what you asked for and when the company received it.
Keep the message focused. Include:
- The policy page and version you relied on
- The specific conduct that appears inconsistent with the policy
- The information involved, if known
- The result you want, such as an explanation, access, deletion, correction, or an opt-out
- Any deadline that applies to the particular legal request
- A secure way for the company to verify your identity
Make a general complaint distinct from a formal rights request. Saying that a policy is misleading may not clearly ask for deletion or access. If you want one of those remedies, name it directly.
Privacy policy complaint letter template
Subject: Privacy concern about [company] and request for [specific remedy]
[Date]
Hello [privacy team or data protection officer],
I am writing about [account, product, or service]. I live in [state or country, if relevant].
On [date and time], I [describe the relevant event]. The privacy policy at [policy page] said:
"[Short, exact quotation]"
I am concerned that this differs from what happened because [brief comparison based on facts].
Please:
- Explain whether [type of information] was collected, used, disclosed, sold, or shared.
- Identify the policy version that applied on [date].
- [State your specific request, such as access, deletion, correction, or an opt-out.]
- Explain any refusal, limitation, retention period, or identity-verification requirement.
Please confirm receipt and provide a case number. If you need to verify my identity, please send instructions for a secure submission method.
Attachments: [policy screenshot or PDF, timeline, relevant correspondence]
Sincerely,
[Name or account identifier]
Reporting a suspected deceptive practice to the FTC
The FTC is a possible federal reporting route when a company's privacy promise or disclosure appears misleading. Examples include a statement that the company doesn't share information when its conduct appears inconsistent with that statement, or a material privacy change that wasn't clearly disclosed.
Submit the report through the FTC's ReportFraud form. Give the agency enough detail to see the difference between the promise and the conduct:
- The company's legal or trading name
- Its website, app, or relevant policy page
- The exact promise or disclosure
- When you saw the promise and when the conduct occurred
- The information or account activity involved
- Your attempts to contact the company
- The consumer harm or risk, stated briefly
- The documents that support your account
Separate observation from conclusion. "The policy said X, but I observed Y" is more useful than claiming an unverified data sale. If you don't know what happened inside the company's systems, say that plainly.
An FTC report isn't a private hearing between you and the company. The agency may use reports to identify patterns and decide whether to take action, but a submission doesn't guarantee a response, investigation, deletion, or compensation.
Don't put passwords, full financial details, or sensitive medical information in a report. If genuinely confidential material is necessary, review the FTC's contact instructions. The FTC says confidential information should be marked "Confidential" and sent by postal mail to its headquarters rather than through ordinary email.
California privacy complaints
California residents should keep a CCPA or CPRA rights request separate from an FTC report about deceptive conduct. If you want access, deletion, correction, or certain opt-outs, begin with the business's designated privacy-request method.
If the business ignores the request, gives an incomplete answer, or appears not to provide required privacy notices, check the current filing instructions of the California Privacy Protection Agency or the California Attorney General. Coverage depends on the business and the activity; having a California address doesn't establish that every CCPA provision applies.
For help organizing the facts, see the EFF overview of filing a California privacy complaint and Consumer Action's CCPA rights guide. These are explanatory resources. Current agency instructions control the filing process and any deadlines.
An agency complaint and a claim for damages are different routes. Filing a complaint doesn't itself award compensation.
Other U.S. state privacy laws
State privacy laws use different definitions, coverage thresholds, rights, deadlines, and enforcement processes. A CCPA rule, a GDPR deadline, or an FTC report won't answer every state-law question.
If you live outside California, check the official privacy or consumer-protection page for the state connected to your residence or transaction. A company's office location alone may not decide which law applies. An FTC report can supplement a state-law request when the conduct appears broadly deceptive, but it shouldn't replace the request or complaint process that applies to your state.
If GDPR or UK GDPR applies
A global privacy policy doesn't automatically give every U.S. customer rights under European law. The relevant location, organization, processing activity, and other jurisdictional facts matter.
European Union and EEA
Where the GDPR applies, an individual can complain to a data-protection supervisory authority under Article 77. That complaint is separate from asking the company or organization to provide, correct, or erase personal data.
For a GDPR rights request, the organization must respond without undue delay and, in principle, within one month. If it refuses the request, ask for the reason in writing. The European Commission's information for individuals describes access, correction, erasure, and complaint options.
Deletion isn't absolute. Legal obligations, public-interest needs, freedom of expression, and other exceptions can affect an erasure request. If the organization refuses, ask which reason applies and what category of data it will retain.
United Kingdom
For a UK data-protection complaint, the Information Commissioner's Office is the main regulator. The ICO says an organization generally has 30 days to acknowledge a data-protection complaint. That acknowledgment doesn't mean the complaint must be resolved within 30 days.
A rights request has different timing and procedures. Use the ICO guidance on making a data-protection complaint and its guidance on the right to get your data deleted.
Don't copy a European deadline into a U.S. complaint. Use the deadline attached to the jurisdiction and type of request that actually applies.
Follow up and assess the response
Once you've sent the complaint:
- Save the sent message and proof of delivery.
- Record the case number and any response date the company gives you.
- Send one concise follow-up that includes the original date and request.
- If identity verification is required, use the company's secure process and provide only what is reasonably necessary.
- If you escalate, attach the original complaint and response instead of rewriting the history each time.
A useful reply should address the facts, identify the policy version, explain the relevant data use, and say what the company did or will do. If it denies a request, it should explain the reason and any limits that apply. "We value your privacy" without an answer to the specific question is a reason to follow up, not proof by itself that a violation occurred.
If the company says the policy changed after the event, compare the old and new versions and ask which one governed the collection or use at issue. If it says data was retained, ask what category was retained, why, and for how long.
Common mistakes
- Making only a general accusation: Quote the policy and connect it to the conduct you observed.
- Treating one technical clue as proof: A cookie, pixel, or third-party domain may need more context.
- Submitting only the current policy: The older version may be the key evidence.
- Sending unredacted records: Remove information that isn't needed to evaluate the complaint.
- Using the wrong route: An FTC report, a state privacy request, and a GDPR complaint serve different purposes.
- Expecting an agency to handle your customer-service request: Ask the company for the remedy you want, then use the agency to report or challenge broader conduct.
- Making unsupported threats: State what you observed and what you want the company to do.
- Missing a formal request deadline: Record the submission date and follow the instructions for the applicable jurisdiction.
Common questions
Does a policy contradiction automatically mean the company broke the law?
No. The contradiction may be evidence of a misleading promise or inadequate disclosure, but the legal result depends on the wording, the conduct, the applicable law, and the surrounding facts.
Should I contact the company before the FTC?
Contacting the company first is usually useful when you want an explanation, access, deletion, correction, or an opt-out. You can still report suspected deceptive conduct to the FTC, especially if the issue may affect other consumers. Don't delay if waiting could cause you to miss an applicable deadline.
Can I file anonymously?
You can reduce unnecessary exposure by redacting documents and using a secure channel. The company or regulator may still need your identity or contact information to verify an account, investigate the facts, or process a rights request. Complete anonymity can limit what it can do.
Can I demand that a company delete all my data?
You can request deletion when an applicable law provides that right, but recognized exceptions may allow the company to retain some information for legal, security, accounting, or other reasons. Ask for a written explanation and the categories retained.
How long will a privacy complaint take?
There is no single response period for every U.S. privacy-policy complaint. FTC reports don't work like standard customer-service tickets. GDPR rights requests generally use a one-month response principle, while UK guidance distinguishes a 30-day acknowledgment for a complaint from the time needed to resolve it.
Filing checklist
- [ ] Saved the policy page, effective date, and exact quotation
- [ ] Written a dated, factual timeline
- [ ] Preserved company responses and case numbers
- [ ] Redacted passwords, financial data, and unrelated personal information
- [ ] Identified the remedy or explanation requested
- [ ] Chosen the route that matches the conduct and jurisdiction
- [ ] Kept copies of every submission
Before sending the first message, download the policy and write the timeline. Those two records give the company or regulator something concrete to assess.