The short answer: there isn't one universal complaint deadline

A data breach notice doesn't give you a single 30-, 60-, or 72-day deadline. The 72-hour GDPR rule and HIPAA's 60-day rule generally tell an organization when it must notify an authority or affected people. They aren't, by themselves, deadlines for a consumer complaint.

Your next step depends on the route you choose:

A breach notice, a regulator complaint, and a lawsuit are separate processes. One incident can involve all three.

Data breach deadlines at a glance

Situation Typical deadline Who owns the deadline? What it means for you
U.S. state breach notification Varies by state, data type, and circumstances The business The notice's timing may be useful evidence, but it isn't your complaint deadline.
HIPAA breach notification Without unreasonable delay and generally no later than 60 calendar days after discovery The covered entity or business associate You can question a late or incomplete response. The 60 days isn't your OCR filing limit.
HIPAA complaint to HHS OCR Generally 180 days after you knew or should have known of the violation The consumer File promptly. OCR may extend the period for good cause.
California CCPA pre-suit notice A written notice and 30-day response step before certain individual-damages claims The consumer and business This is not a universal breach-reporting or privacy-complaint deadline.
EU GDPR notification Up to 72 hours after the organization becomes aware of a reportable breach The organization This is a business-to-authority deadline, not a general U.S. consumer deadline.
Texas Attorney General notice As soon as practicable, and no later than 30 days after discovery when 250 or more Texans are affected The business This is a Texas reporting rule, not a national consumer filing deadline.

Use the table to identify the right question, not to set a single calendar reminder. The controlling rule can change with your state of residence, the organization's location, the kind of information involved, encryption, and the type of organization.

What to do in the first 24 hours

1. Check that the notice is genuine

A real incident can be used as a pretext for a phishing message. Don't enter a password, Social Security number, payment-card number, or one-time code through an unexpected email or text link.

Instead, type the company's website address yourself or use a phone number from an old statement or account record. Confirm the incident reference number, the dates stated in the notice, and the information the company says may have been involved.

2. Keep the notice and make a timeline

Save the letter, email, envelope, attachments, and any online messages. Note:

Those dates can help you compare the company's discovery and notification timing. They also give a regulator a clearer account of what happened.

3. Secure affected accounts

Change the affected password and any password reused on another account. Turn on multifactor authentication and sign out of unfamiliar sessions.

If financial information or account credentials were involved, contact your bank, card issuer, or payment provider promptly. If your Social Security number or other identity information was exposed, consider a fraud alert or credit freeze through the three major credit bureaus.

Be cautious about follow-up messages offering "breach assistance." A legitimate company won't need your account password or verification code to provide help.

4. Put questions to the company in writing

Use the privacy, security, or breach-response contact listed in the notice. Ask for facts rather than a general statement that the issue has been resolved.

Questions worth asking include:

Don't send a full Social Security number, password, bank login, or other unnecessary sensitive information in an ordinary email.

U.S. state laws control many consumer breach notices

The United States has no single breach-notification deadline for every business. State laws commonly address:

Which law applies can depend on where affected consumers live, where the business operates, or both. A rule requiring notice "without unreasonable delay" works differently from one that sets a fixed number of days.

Texas illustrates the difference between a business deadline and a consumer deadline. Under the Texas Attorney General's data breach reporting guidance, a business or organization affecting 250 or more Texas residents must report to the Texas Attorney General as soon as practicable and no later than 30 days after discovering the breach. It must also notify affected consumers.

That 30-day period belongs to the business. A Texas resident doesn't automatically have 30 days to file a complaint.

State laws can cover mistakes as well as criminal attacks. The District of Columbia Attorney General's breach-notification overview gives hacking and ransomware as examples, but also identifies employee error, such as sending information to the wrong person.

HIPAA has a 60-day notice rule and a separate OCR complaint period

HIPAA may apply when a covered entity or business associate, such as a healthcare provider, health plan, health insurer, or certain service provider, handles protected health information. The organization generally must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering a breach of unsecured protected health information.

Large breaches can also require notice to HHS and the media. Smaller breaches have a different HHS reporting schedule. Those organization deadlines don't stop you from asking questions or raising a concern.

If you believe a covered organization violated HIPAA, you can use the HHS Office for Civil Rights online complaint portal. OCR generally expects a complaint within 180 days after you knew or should have known about the violation, although it may extend that period for good cause.

Include:

OCR can investigate covered entities and business associates. Its complaint system also addresses certain Part 2 complaints involving federally assisted substance-use-disorder treatment programs.

A health app, wearable, or personal health record provider isn't automatically covered by HIPAA. Some may instead be subject to the FTC Health Breach Notification Rule or state privacy law. Identify the provider before selecting a complaint route.

California CCPA complaints and the 30-day notice step

The California Consumer Privacy Act doesn't create one general deadline for complaining about any data breach. Its private right of action is limited to certain security incidents involving defined personal information and alleged failures to maintain reasonable security.

The California Attorney General's CCPA information describes a written-notice step before a consumer brings a qualifying individual-damages claim. The notice identifies the CCPA provisions allegedly violated and gives the business 30 days to respond in writing that it cured the violation and won't repeat it.

That step is not the same as:

If you're considering a lawsuit, don't treat the CCPA's 30-day step as your only deadline. Other filing deadlines may apply, and a regulatory complaint doesn't necessarily pause a civil claim.

Why the GDPR's 72-hour rule is often misunderstood

For an organization subject to the GDPR, the controller generally must notify the relevant supervisory authority within 72 hours of becoming aware of a reportable personal-data breach. Individuals must be notified without undue delay when the breach is likely to create a high risk to their rights and freedoms.

That is the organization's reporting clock. It isn't a deadline for a U.S. consumer to complain, and not every personal-data breach has to be reported to a data protection authority. The organization must assess the incident and document its decision.

If the GDPR applies to the company's processing of your information, you may be able to complain to the appropriate supervisory authority. The correct authority depends on the organization and the processing activity. Don't select an agency solely because the notice mentions 72 hours.

How to make a data breach complaint useful

Start with a written request

Even if you already called the company, send a dated written request through the contact listed in the notice. State when you received the notice and include the incident reference number. Ask the focused questions listed above.

The FTC's business data breach response guide is written for companies, not consumers. Its advice nevertheless identifies useful subjects to look for in a response: a clear description of what is known, an organized investigation, forensic review, and appropriate legal and technical support. A polished general assurance isn't the same as an answer to your questions.

Choose the regulator that fits the facts

Attach evidence without exposing more information

Provide the breach notice, relevant account records, dated correspondence, screenshots, and proof of suspicious activity. Redact unnecessary account numbers and identity documents. Never attach passwords, one-time codes, or full financial credentials.

Write the complaint as a timeline: what happened, what the company said, what it didn't answer, and what harm or risk you experienced. Don't guess how an attacker obtained or used the information.

A concise opening might look like this:

I received a breach notice from [company] on [date], reference [number]. The notice states that [data type] may have been involved. Please confirm the affected information, the discovery and containment dates, the notification steps taken, and the available remedy.

Put each deadline on its own calendar

Record the date you received the notice, the company's requested response date, the OCR period if HIPAA is relevant, the CCPA notice period if you're considering a qualifying damages claim, and any possible civil claim deadline.

A late notice may matter, but it doesn't automatically prove a legal violation. If you've lost money, experienced identity theft, or are considering court action, speak with a qualified consumer or privacy attorney promptly. Filing a regulator complaint doesn't necessarily extend or pause a civil statute of limitations.

Questions consumers often ask

Do I need to report a breach within 72 hours?

Usually, no. The 72-hour GDPR period generally applies to an organization's notice to a supervisory authority. Secure your accounts and report suspected fraud immediately instead of waiting for the company's investigation to finish.

What if the company took more than 60 days to notify me?

Save the notice and compare its stated discovery date with the date you received it. The HIPAA 60-day rule applies only when HIPAA covers the organization and the information. State law and other federal rules may use different standards. Raise the delay with the company, the relevant state agency, or OCR when appropriate.

Can I file a HIPAA complaint against any health app?

No. OCR's HIPAA jurisdiction generally covers covered entities and business associates. A health app may be subject to another rule. Identify the provider and the type of information involved before filing.

Does the CCPA give me 30 days to complain?

No. The 30-day period is a written notice and business-response step for certain California individual-damages claims. It isn't a universal deadline for reporting a breach or contacting a regulator.

What if the breach notice is vague?

Preserve the notice, send specific questions in writing, and record the response. You can still report the concern to the regulator that matches the organization and information, even if the company hasn't answered everything.

Save the notice today, mark when you learned about the incident, change reused passwords, and send the company a short written request. This information is general and not legal advice.

Official sources