If a company's actual data practice seems to conflict with its privacy policy, preserve the policy version and other evidence before contacting the company. Then send one focused written request that says what happened and what you want done. The right escalation route depends on your state, the type of information involved, the company's industry, and whether a specific law gives you a right.

A privacy-policy conflict doesn't automatically give you a right to compensation or a federal lawsuit. The policy wording, applicable state or federal law, the company's terms, and the facts of the case all matter. This is general consumer information, not legal advice.

Start with these steps

  1. Preserve the record. Download or screenshot the privacy policy, consent notice, cookie banner, account settings, and relevant messages. Save the version that applied when you opened the account or provided the information, if you can find it.
  2. Name the problem. Decide whether you are dealing with a misleading promise, an ignored privacy request, unwanted sharing, marketing after an opt-out, health information, or a security incident.
  3. Write to the company. Use the privacy-request email, web form, or mailing address in its policy. Include the older policy version if that is the one relevant to your concern.
  4. Ask for a defined result. Depending on the facts and the law, that might be access, correction, deletion, an opt-out, an explanation, or information about a suspected breach.
  5. Keep a dated trail. Save the request, confirmation, identity-verification records, ticket number, and every response.
  6. Escalate only to an authority with jurisdiction. The FTC, a state privacy regulator or attorney general, and HHS OCR handle different kinds of complaints.
  7. Get individual legal help when the stakes are high. A licensed consumer-law attorney or legal-aid service may be appropriate if the matter involves financial loss, sensitive medical records, identity theft, a threatened claim, or a possible deadline.

What controls the dispute?

There isn't one U.S. deadline or complaint form for every privacy problem. Start by identifying the source of authority that may apply:

Issue What may control it What to check
A company made a privacy promise The policy, notice, consent screen, and the version in effect when the data was collected Exact wording, dates, and definitions of terms such as "sale," "sharing," "service provider," and "business purpose"
You want access, deletion, correction, or an opt-out A state privacy law or a sector-specific law Your state, the company's coverage, the type of data, and legal exceptions
Health information was disclosed HIPAA or another health-privacy rule, if the entity and records are covered Whether the organization is a covered entity or business associate and whether the information is protected health information
Substance-use-disorder records were involved Federal 42 CFR part 2, when the program or entity is subject to it Whether the records came from a federally assisted substance-use-disorder treatment program
The business made a deceptive privacy claim A consumer-protection law and potentially FTC enforcement What the company said, what it did, and whether the statement was likely to mislead consumers
You accepted online terms The terms may contain arbitration, notice, dispute, or venue provisions Whether those terms affect a private claim or the way you must present the dispute

A privacy policy can be evidence of what a business represented, but broad language may give it discretion. For example, "we may share information with service providers and partners" is different from a promise that information will not be shared. Save the exact language instead of relying on memory.

An arbitration clause may affect a private legal claim, but it doesn't decide whether the data practice complied with privacy law. It also doesn't replace a regulator's complaint process.

Match the response to what happened

The conduct appears different from the policy

Examples include a policy that says information isn't sold while a data broker receives it, or a notice that leaves out a significant use of location, browsing, or contact data. Keep the policy language and evidence of the actual use or disclosure.

A conflict can support a complaint, but the company may argue that the transfer was covered by a different definition, consent screen, partner disclosure, or contract. Ask it to identify the specific provision on which it relied.

The company ignored a privacy request

The request might concern:

These rights aren't identical in every state. The company may also have a lawful reason to retain some information or may say it cannot verify the requester. If it refuses, ask for a written explanation identifying the reason and any exception it says applies.

Marketing continued after you opted out

Save the opt-out confirmation, the submission date, and the later messages. Note whether the messages came from the business, a contractor, or a separate brand. Marketing and privacy rules can differ by communication channel, the consent given, and whether an affiliate sent the message.

Health information was involved

Health-related information alone doesn't prove that HIPAA applies. Many wellness, fitness, employment, and consumer apps aren't covered in the same way as hospitals, health plans, or their business associates.

Check the organization's privacy notice, its relationship to a covered health provider, and the type of records involved. Substance-use-disorder records may also be subject to the separate Part 2 rules.

A security incident occurred

A data breach and a misleading privacy policy are related but different issues. A breach concerns unauthorized access, loss, or disclosure. A policy dispute concerns what the company said it would collect, use, or share.

If you suspect a breach, change reused passwords, turn on multifactor authentication, and contact the affected account provider through an official channel. Ask what information was involved, when the company discovered the incident, and what protective steps it recommends.

Preserve evidence before you write

A simple timeline is often more useful than a long narrative. For each event, record the date, what happened, the company's response, and the file that supports it.

Keep:

Don't put medical records, account credentials, Social Security numbers, full payment-card numbers, or another person's personal information in a public post or complaint. Redact unnecessary details before sending documents. The company or agency needs enough information to identify and investigate the issue, not your entire file.

Send a precise written request

Use the privacy contact method in the company's current policy. A general customer-service channel may still help, but a dedicated privacy form or email gives you a clearer record. If the relevant policy is an older version, attach it or quote the relevant passage and identify the date.

Include:

  1. Your name and the account or email address associated with the issue
  2. The date and product involved
  3. A short description of what happened
  4. The policy language or notice you believe is relevant
  5. The result you are requesting
  6. The documents that support your account
  7. A request for a written response

You can adapt this template:

Subject: Privacy request and policy concern

I am contacting you about the account or service associated with [identifier]. On [date], I observed [brief description]. The privacy notice I viewed on [date] stated [short quotation or summary].

I am requesting [access, correction, deletion, opt-out, explanation, or breach information]. Please confirm receipt, explain what information was collected or shared, and tell me what action you will take. If you deny the request, please identify the reason and any applicable exception.

Please send your response in writing to [contact information].

Keep separate issues in separate requests when possible. A short request is easier to verify and harder to misinterpret than a long message combining unrelated complaints.

Use the deadline that actually applies

California requests

California residents may have rights under the CCPA when the business and the request are covered by that law. California's privacy request guidance says consumers can usually submit a request through a web form, email, or phone number listed in the company's privacy policy. It says businesses should respond within 45 days.

The same page explains that businesses must tell service providers or third parties with which they have shared the information about a deletion request so those parties can follow it. California consumers can also use the state's DROP service to submit one deletion request to registered data brokers.

The 45-day response period isn't a universal deadline for every privacy complaint, and it doesn't necessarily determine the deadline for a lawsuit. Keep the submission date and read the company's response for information about verification, extensions, or legal exceptions.

GDPR and UK GDPR matters

The GDPR is not a U.S.-wide privacy rule. Don't use its deadlines simply because a U.S. company has a European customer or mentions GDPR in its policy.

If the processing is subject to UK GDPR, the Information Commissioner's Office breach guidance says an organization must report a notifiable breach without undue delay and no later than 72 hours after it becomes aware of it. That is an organization-to-regulator reporting duty, not a general U.S. consumer deadline.

If the relevant processing occurred outside the United States, use the authority for the country or region covered by that processing rather than assuming a U.S. route applies.

HIPAA and Part 2 matters

Don't assume that a company must follow HIPAA merely because it handles health-related data. Confirm that the organization's role, the information, and the activity fall within the rule.

For a potential HIPAA complaint or a concern involving Part 2 records, start with the HHS OCR complaint portal and follow its current filing instructions. HHS says OCR can investigate Part 2 complaints against federally assisted substance-use-disorder treatment programs and other entities subject to Part 2.

Where to escalate

Escalation is more useful when you have a dated request and a clear record of the company's response.

Federal Trade Commission

The FTC may be relevant when a business appears to have used a deceptive privacy statement, engaged in an illegal business practice, or operated a scam. Use the FTC's contact guidance and, for suspected fraud or scams, the ReportFraud complaint route.

Describe the conduct in dates and facts. Include the policy language, what the company did, its response, and the consumer impact. An FTC report can alert the agency to a pattern, but it doesn't guarantee an investigation of your individual matter, an order requiring deletion, or compensation.

California privacy resources

If you are a California resident, keep the confirmation from your business request. If the company refuses to respond, gives an incomplete answer, or appears to disregard a covered right, consult California's current official privacy-agency instructions for the appropriate next step.

The California request page helps explain submission methods and the DROP service. A request form by itself isn't a private lawsuit or an enforcement case.

HHS OCR

Use the HHS OCR route when the concern plausibly involves HIPAA or Part 2 and the organization falls within the relevant coverage. Include the provider or program name, dates, records involved, and the company's response.

Don't send a complaint to HHS simply because a fitness app or retailer collected information about your health. HHS may lack authority if the entity or conduct isn't covered.

State regulators and courts

For other U.S. privacy laws, check your state attorney general's or privacy regulator's official website. State rights vary by residency, business size or type, data category, and conduct. A regulator complaint and a private legal claim are separate paths with different deadlines and possible remedies.

If the matter involves substantial harm, sensitive health information, a threatened claim, or a contract requiring arbitration, consider consulting a licensed attorney promptly. Bring the policy version, timeline, requests, and responses rather than only a general description of what you believe happened.

Mistakes that can weaken a complaint

Frequently asked questions

Does breaking a privacy policy automatically mean I can sue?

No. The policy may be useful evidence, but a private claim depends on the applicable law, the company's coverage, the policy language, the facts, and any harm or other required element. A regulator complaint doesn't automatically create a lawsuit or a right to compensation.

Can a company refuse to delete my information?

Sometimes. Privacy laws can contain exceptions, and a company may be unable to verify the requester or may need to retain certain records. Ask for a written explanation identifying the reason and the information affected.

Is every health app covered by HIPAA?

No. HIPAA coverage depends on the organization's role and the information and activity involved. A health-related product may instead be governed by its privacy policy and other consumer or state rules.

What should I do if the company never responds?

Send one short follow-up that references the original request and its date. Attach the confirmation, identify what response is missing, and then use the official regulator or attorney-general route that matches your state and the type of data involved.

Should I file with the FTC or a state regulator?

Use the FTC for a suspected deceptive or illegal business practice, especially when the conduct may affect many consumers. Use a state privacy regulator or attorney general when a state-specific right or local enforcement route is the better fit. Both routes may be available, but neither replaces a private legal assessment.

Before sending a complaint, put the policy version, dated request, company response, and one-page timeline in a single folder. Redact unnecessary sensitive information and submit only the records needed to identify the business and the alleged conduct.