When a website's privacy policy conflicts with its cookie banner, app permissions, or privacy settings, don't begin by threatening a lawsuit. First capture what the company said, what you selected, and what happened afterward. Then use the company's privacy controls and send a focused written request.

For U.S. consumers, the possible remedy depends on state law, the industry, the data involved, and the wording of the notice. A mismatch may support a correction or complaint, but it doesn't automatically create a fine, refund, or private lawsuit.

What a privacy policy tells you

A privacy policy is generally a disclosure about how a business collects, uses, stores, and shares personal information. Look for answers to these questions:

The policy isn't necessarily a promise that the company will never collect data. It may also sit alongside terms that include arbitration or class-action provisions. Whether the notice is legally enforceable, or whether a practice violates privacy law, depends on the wording, the facts, and the law that applies.

The practical question is narrower: did the company do what it described, and did the privacy choice work as presented?

Discrepancies worth documenting

Optional cookies still load after you reject them

A cookie banner doesn't prove that tracking has stopped. The New York Attorney General reported websites where marketing tags continued firing after visitors disabled them. Its investigation identified hardcoded tags and poor communication between consent-management and tag-management tools. The agency's website privacy controls guidance describes those problems.

When a site calls analytics or advertising cookies optional but related tools appear after rejection, note the setting, time, page, and result. That is a meaningful discrepancy, though it isn't by itself proof that the conduct was unlawful.

The policy uses vague language about third parties

Phrases such as "trusted partners" may not tell you who receives information or what they receive. The relevant provider could be an analytics company, advertising network, social-media plug-in, or payment service with its own policy.

A provider's name alone doesn't establish improper sharing. The concern is whether the notice accurately describes the category of data, the purpose, and the recipient. Ask the company to identify the provider and explain the relevant data flow if the policy leaves those points unclear.

An app asks for more access than the notice describes

An operating-system prompt may request access to your location, contacts, microphone, photos, or Bluetooth. Granting that permission doesn't necessarily explain how long the app will retain the information or whether vendors will receive it.

Compare the prompt with the app's privacy notice. For example, if the app requests precise location access while the policy discusses only broad "device information," save both screens and record the app version. A permission request shows what access the app sought; it doesn't, by itself, establish what the app actually collected or shared.

A child-directed service gives little information about children's data

COPPA can apply to a website or online service directed to children under 13 and, in some situations, to a service that knows it is collecting personal information from children. The FTC says a children's privacy policy should describe the information collected and how it is used, and identify each third-party operator collecting or maintaining that information. Its COPPA compliance plan explains those notice requirements.

A parent can preserve the age screen, consent flow, app permissions, and advertising or location settings. An age prompt that is easy to bypass isn't proof of a violation on its own, but it can help show what the service asked and how the flow worked.

The policy changed after the collection

Companies can update their policies. The current version may not be the version that applied when you created an account, accepted cookies, or submitted information.

Save a PDF or screenshots with the policy text, URL, and date. Keep emails announcing changes. If you can't locate an older version, say that in your request and ask the company to identify the notice it relied on for the relevant collection.

The privacy choice is hard to use or withdraw

A choice may be difficult to use when accepting is prominent but rejection takes several screens, or when the withdrawal link is buried in an account menu. The legal standard varies by jurisdiction and practice, so describe what happened instead of declaring the design illegal.

Record the number of screens, the labels, any preselected options, and whether the setting remained in place after you returned to the site.

What to do after finding a mismatch

1. Decide what you want fixed

Put the problem in the right category before contacting the company:

These categories can overlap, but they often use different procedures. A privacy complaint won't necessarily cancel a subscription or reverse a charge.

2. Build an evidence file

Keep the following together:

Don't put passwords, full Social Security numbers, or unrelated sensitive documents in an ordinary email. If the company requires identity verification, use its official privacy-request channel and provide only what is reasonably necessary.

3. Use the company's controls once, then check them

Reject optional cookies, turn off targeted advertising, revoke unnecessary app permissions, or disable sharing in the account privacy center. Take a screenshot before and after the change.

Reload the page or revisit the privacy center to see whether the choice remains active. A confirmation message helps document what the company displayed, but it doesn't prove that every related tracking tool stopped. If the setting fails, record that failure and move to a written request rather than repeatedly testing it and exposing more information.

4. Send a specific written request

"You violated my privacy" is less useful than a description of the setting, the observed result, and the remedy you want. You can adapt this wording:

On [date], I used [setting or consent choice] on [website or app]. The privacy policy at [link] said [short description], but I observed [specific practice]. Please explain what information was collected, the purpose, the third parties involved, the retention period, and how I can stop the practice. If a privacy right applies to my request, please treat this as a request for the applicable access, deletion, correction, or opt-out action. Please respond in writing.

Ask which version of the policy governed the conduct. Keep the message, delivery date, and any ticket number. Don't assume that every state has the same response deadline or identity-verification rules; those requirements vary.

5. Read the response against what actually happened

A useful response should address the disputed practice, not merely repeat the policy. Check whether the company has:

If the company blames a vendor, keep that response. Responsibility can still depend on the company's relationship with the vendor and the law that applies.

Where to take a complaint

Choose the route that matches the problem. A regulator may investigate or pursue enforcement, but filing a complaint doesn't guarantee individual compensation.

Problem Possible next route Evidence to include
Misleading privacy notice or tracking that ignores your choice Your state attorney general's consumer-protection or privacy office; a relevant federal agency may also be available Policy copy, screenshots, dates, and the company's response
California privacy rights or sale and sharing concerns The company's designated CCPA request process and the appropriate California privacy authority The request, verification steps, opt-out records, and response
Child-directed service or collection from a child under 13 The company first, followed by the appropriate federal or state agency Age screen, consent flow, child-data notice, and third-party details
Possible data breach The company and relevant authorities; the FTC's breach-response guidance provides useful questions about the incident Breach notice, affected data, dates, account records, and fraud evidence
Subscription charge or account problem The merchant, app store, bank, or payment provider under the applicable billing process Receipts, cancellation records, and transaction details

California consumers can review the California Attorney General's privacy enforcement actions. For a plain-English overview of certain California rights, see this CCPA consumer rights overview. Eligibility, exceptions, and available remedies depend on the business and the data involved.

For another state, use its official government website. Be wary of paid complaint services that promise a guaranteed settlement or claim to file a lawsuit for you.

If the problem may be a data breach

A privacy-policy mismatch and a data breach are different problems. A cookie that fires after an opt-out may show that a privacy control is broken. A breach generally involves unauthorized access, acquisition, disclosure, or loss of information, although the legal definition varies by state.

If the company sends a breach notice, ask:

Use a unique password and multifactor authentication on affected accounts. If the exposed information could help someone open new accounts in your name, the FTC says a credit freeze can help stop identity theft. A freeze is free. You can place one with Equifax, Experian, or TransUnion through the FTC's credit-freeze guidance. Check your credit reports and watch existing accounts for unfamiliar activity.

What you can realistically get

The most likely immediate result is a correction: the company fixes a consent tool, honors an opt-out, explains a vendor relationship, or processes an eligible data request.

A regulator decides whether the conduct merits investigation or enforcement. That process is separate from a private lawsuit and usually doesn't guarantee money for the person who complained. A private claim depends on the applicable law, the type of information, proof of harm, the company's terms, and any arbitration or class-action provisions.

Don't describe an identity-theft loss, unauthorized disclosure, or financial injury unless you can document it. Specific records give the company, an agency, or a legal professional something concrete to evaluate.

Quick checklist

Before escalating, make sure you have:

Is an inaccurate privacy policy automatically illegal?

No. It may be a technical error, a vendor configuration problem, or evidence that the business's disclosures are misleading. The answer depends on what was promised, what occurred, what data was involved, and which law applies.

Can I get a refund because a website tracked me?

Not automatically. Privacy rights and billing rights are separate. Ask the business for the privacy remedy, and handle a disputed charge through the merchant, app store, bank, or payment provider's applicable process.

Should I delete my account immediately?

Save the policy, settings, and communications first. After that, decide whether deletion, permission changes, or account closure matches your goal. Deleting an account may remove access to useful records, while an eligible deletion request may require identity verification.

Start by saving one dated copy of the policy and one dated screenshot of the privacy setting. Then write down the exact mismatch before contacting the company.