Most privacy complaints become harder to act on because they go to the wrong authority, describe conclusions instead of facts, or lack dated evidence. Before filing, decide whether you want to exercise a privacy right, report a potentially deceptive practice, or pursue a private remedy. Each goal follows a different path.

This guide is for U.S. consumers. It focuses on California privacy complaints and reports involving potentially unfair or deceptive privacy practices under the FTC's consumer-protection role. A GDPR complaint follows a different jurisdiction and process; don't assume a U.S. agency will handle it.

This is general consumer information, not legal advice.

The 10 most common privacy complaint mistakes

1. Sending the complaint to the wrong authority

A regulator's authority depends on your location, the business, the industry, and the conduct. A California Consumer Privacy Act complaint is not automatically an FTC matter, and a dispute involving a bank, health provider, telecommunications company, or government agency may have a different route.

The FTC's privacy and security guidance is useful when a company appears to have made a misleading privacy or security promise. California consumers should review the California Attorney General's CCPA guidance for the state's privacy rights and current instructions. For other consumer issues, USAGov's complaint directory can help identify the relevant agency.

Fix: Write down three facts before filing:

If you can't explain the agency's connection in one or two sentences, verify the route before submitting.

2. Treating a data request as a regulator complaint

If you want to access, delete, correct, or opt out of certain data uses, start with the business's privacy-request process when one is available. A regulator complaint is usually a poor substitute for a clearly stated consumer request.

For example, “Please delete the personal information associated with my account” is a request to the company. “I submitted a deletion request on a specific date, and the company refused or ignored it in a way that may violate applicable law” is a stronger basis for a regulatory complaint.

Fix: State your objective clearly:

Keep the original request, identity-verification steps, confirmation number, and response.

3. Presenting a private dispute as a privacy violation

A complaint about a refund, account suspension, employment decision, contract term, or poor customer service does not become a privacy case merely because the company has a privacy policy.

There may be a privacy issue if the business used personal information in a way that was unrelated to the dispute, disclosed it improperly, or made a specific privacy promise it did not follow. Explain that conduct separately from the underlying service problem.

Fix: Divide your statement into two parts:

  1. The ordinary dispute, such as a billing or account problem
  2. The specific collection, use, disclosure, security, or privacy-notice issue

A regulator may review information for enforcement purposes, but a complaint is not a guaranteed route to a refund or damages.

4. Using vague allegations

“They sold my data” is difficult to evaluate without details. The statement could refer to targeted advertising, a data broker, a service provider, an opt-out failure, or an entirely different practice.

Replace broad conclusions with observable facts:

Use careful wording when the evidence is incomplete. “The policy says information is not shared for advertising, but I received a disclosure notice showing an advertising partner received my identifier” is more useful than declaring fraud without supporting records.

5. Failing to preserve the privacy policy as it appeared

Privacy policies change. A current page may not show what you accepted when you opened an account or submitted information.

Save the policy page as a PDF or screenshot and record:

If the page has a “last updated” date, include it, but don't rely on that date alone. A dated screenshot of the actual wording is stronger evidence.

6. Sending evidence that is incomplete or unsafe

A regulator needs enough information to understand the event, but more documents don't automatically make a complaint stronger. A folder of unrelated screenshots can hide the key evidence.

Include relevant records such as:

Redact passwords, security answers, full payment-card numbers, Social Security numbers, health details, and unrelated information. Submit sensitive records only through the agency's official secure process. Keep the originals in case the agency asks for clearer copies.

7. Assuming every company is covered by the same law

The appearance of a privacy policy does not prove that every privacy law applies to the business or to your situation. Coverage can depend on the business, the consumer's state, the type of information, the business activity, and the right being asserted.

California's official guidance explains that the CCPA gives consumers more control over personal information and that the CPRA amendments have been in effect since January 1, 2023. That does not mean every company, transaction, or data practice is automatically subject to every CCPA provision.

Fix: Identify the connection instead of copying a list of statutes. Explain why you believe:

If you aren't sure, say what you know and label the rest as a concern to be reviewed.

8. Confusing different deadlines

Privacy complaints, consumer requests, company incident reporting, pre-suit notices, and court claims can have different deadlines. Borrowing a deadline from another process can make your submission inaccurate.

For California consumers, the Attorney General's CCPA guidance says that before suing, a consumer must give the business written notice identifying the CCPA sections allegedly violated and allow 30 days for the business to respond in writing that it has cured the violation and will not repeat it. That is a pre-suit step, not a universal deadline for filing an agency complaint.

Fix: Label each date in your timeline:

Check the current instructions for the particular complaint route instead of importing a deadline from GDPR, another state, or a different type of request.

9. Writing an unstructured complaint

A long narrative can bury the facts. A short, organized submission is easier to review and less likely to omit the information a form requests.

Use this order:

  1. Who you are: State, country, or other location relevant to the complaint
  2. Who the business is: Legal name if known, website, app, or service
  3. What happened: A dated description in chronological order
  4. What the policy said: Quote only the relevant language
  5. Why it concerns you: Explain the possible mismatch or harm
  6. What you did next: Include your request and the response
  7. Evidence list: Number each attachment
  8. Requested action: Ask the agency to review, investigate, or advise on the appropriate route

Avoid repeating the same allegation in several sections. Put the most important fact near the beginning.

10. Exaggerating the claim or expecting a guaranteed result

A regulator decides whether and how to use a complaint. Filing does not establish that a violation occurred, guarantee an investigation, or promise individual compensation.

Don't describe conduct as criminal, fraudulent, or illegal unless you can support the wording and it is necessary. Avoid inflated damages, speculation about hidden data transfers, and claims about other consumers that you can't document.

Fix: Separate facts from inferences:

Accurate uncertainty is more credible than an unsupported legal conclusion.

Which route fits your problem?

Your main goal Practical starting point What to avoid
Access, deletion, correction, or an opt-out Use the business's privacy request channel Filing a vague complaint without making the request
Report a potentially deceptive privacy promise Review the FTC's privacy and security materials and use the applicable official complaint route Treating every poor privacy practice as an FTC violation
Raise a California privacy concern Review the official CCPA guidance and preserve your request and response Assuming a CCPA citation alone proves coverage
Report a matter governed by another state agency or sector regulator Use the agency connected to your state, industry, or service Sending the same complaint to unrelated agencies
Seek compensation or a court order Research the separate legal process that applies Treating an agency complaint as a lawsuit

These routes can overlap, but they don't have the same powers, deadlines, or remedies.

How to build a strong privacy complaint

Step 1: Define the suspected problem

Choose a specific issue, such as:

Don't combine every complaint about the business into one submission. A focused issue is easier to verify.

Step 2: Create a short timeline

Use dates rather than general phrases such as “recently” or “for a long time.”

Example:

This format helps the reviewer see what happened without interpreting a long story.

Step 3: Match each important fact to evidence

Number your attachments and refer to them in the text:

Don't include an attachment that you never mention. If a document is unavailable, explain that rather than implying you have proof.

Step 4: State a reasonable request

Ask the agency to review the conduct, identify the appropriate authority, or consider whether the practice raises a privacy concern. If you want the business to take a particular action, make that request directly to the business as well.

A regulator may not be able to order the personal outcome you want. That is one reason to keep your privacy complaint separate from any refund, contract, account, or damages claim.

California CCPA complaint mistakes to avoid

California consumers often mix up three separate actions:

  1. Exercising a CCPA right with the business
  2. Reporting a possible violation to a government agency
  3. Giving pre-suit notice before pursuing a lawsuit

The official California CCPA resource says the law gives consumers more control over personal information and explains that businesses must follow the CCPA's statutory and regulatory requirements. Use the current text and instructions rather than relying on an old privacy-policy template or a blog summary.

If you are considering a lawsuit, read the notice requirement carefully. The California Attorney General says the written notice must identify the CCPA sections allegedly violated, and the business must be given 30 days to respond that it cured the violation and will not repeat it. Don't present that step as a general 30-day deadline for every CCPA request or complaint.

A common mistake is citing the CCPA without explaining the connection between the business, the consumer, the information, and the alleged conduct. Another is assuming that a company refusing a request proves bad faith when the business may be asking for verification or applying an exception. Include the request, the verification steps, and the exact response.

FTC privacy complaint mistakes to avoid

The FTC's privacy and security materials address practices that may be unfair or deceptive, including situations where a company makes a privacy or security representation and does not follow it. That makes the wording of the company's promise important.

A useful FTC-related submission should identify:

Don't use the FTC as a catch-all for a billing dispute, account disagreement, or demand for a personal refund. If the privacy concern is only that a customer-service agent handled your account poorly, explain what data practice makes it a privacy issue.

A simple complaint template

You can adapt this structure to an official complaint form:

I am a consumer in [state]. I am reporting a privacy concern involving [business, website, or app].

On [date], I [opened an account, submitted information, changed a setting, or made a request]. The privacy notice at [page address] stated: “[short quotation].”

On [date], [describe the observed conduct]. I believe this may be inconsistent with the notice because [brief explanation]. I contacted the business on [date] through [method]. Its response was [summary], and I have attached the relevant records.

I ask the agency to review whether this conduct falls within its authority and to advise whether another agency is more appropriate. The attached evidence is listed below: [numbered list].

Remove the quotation marks if you don't have a saved copy of the wording. Never include a password or unnecessary account credentials in the template.

What to do after submitting

Save the confirmation page, complaint number, submitted text, and attachments. Check the email address used for the filing and respond promptly if the agency asks for clarification.

If the business contacts you afterward, keep the message and note whether it addresses the actual privacy issue. A resolution may be useful evidence, but don't delete the original records. If you receive no response, look for an official status or escalation process rather than repeatedly filing the same complaint.

Before you submit, read the complaint once as a stranger would. It should answer four questions quickly: what happened, when it happened, why the selected authority may have jurisdiction, and which document proves each important fact.

Frequently asked questions

Can a privacy policy mismatch support a complaint?

It can be a useful starting point, especially when you can show a clear promise and a specific conflicting practice. A mismatch alone doesn't prove that a particular law was violated. The business's coverage, the wording, the facts, and applicable exceptions still matter.

Should I contact the company first?

For a data request, yes: use the business's stated privacy channel and keep proof. For a suspected deceptive practice, contacting the company can clarify the facts, but don't delay if an official process has a time limit that applies to your situation.

Is a GDPR deadline automatically used for a U.S. complaint?

No. GDPR, CCPA, FTC matters, consumer requests, breach reporting, and lawsuits are separate processes. Confirm the jurisdiction and use the current instructions for the route you choose.

Can I file with multiple agencies?

Only when each agency has a plausible connection to a different issue. Explain what you sent elsewhere and why the second agency may have authority. Duplicate, inconsistent filings can create confusion.

What is the most important evidence?

Usually, it is the dated privacy notice, the record showing what happened, and your communications with the business. A clear timeline connecting those documents is more useful than a large collection of unrelated screenshots.