If you're trying to report a data broker in the United States, start with the practical answer: there is no single consumer filing deadline. The FTC's ReportFraud intake does not post a cutoff for consumers. California privacy requests have their own response clocks, while 72-hour breach-reporting rules under the GDPR and New York Department of Financial Services (NYDFS) generally apply to organizations, not to an individual's complaint.
Timing still matters. A listing can change, information can spread, and emails or screenshots can be lost. Save what you can, send the broker a specific privacy request if you want deletion or an opt-out, and report the conduct through the agency that fits the problem. If you may file a lawsuit or dispute a credit report, check those separate deadlines promptly.
Data broker complaint deadlines at a glance
| Route | Clock that matters | What it means |
|---|---|---|
| FTC complaint | No stated consumer filing cutoff on the ReportFraud intake | You can report suspected unfair or deceptive conduct, but the FTC doesn't promise an investigation, deletion, or payment. |
| California request to know or delete | Confirmation generally within 10 business days; response within 45 calendar days | A business may usually add up to 45 more calendar days when it gives a valid extension notice. |
| California sale or sharing opt-out | As soon as feasible, and no later than 15 business days under the regulations | This generally stops certain future sales or sharing. It isn't the same as deleting information. |
| California DROP request | Registered brokers must check at least every 45 days beginning August 1, 2026 | This is the broker's checking interval, not your deadline to complain. |
| CCPA private action | Written 30-day notice in a qualifying security-breach case | The notice procedure isn't required before an agency complaint and doesn't apply to every CCPA dispute. |
| CFPB complaint | No universal consumer filing deadline | This route is mainly for problems involving financial products, services, or consumer reporting. |
| GDPR breach notification | A covered organization may have 72 hours to notify a supervisory authority | It isn't a 72-hour deadline for an individual to complain. |
| NYDFS cybersecurity reporting | A covered regulated entity generally reports certain events within 72 hours | NYDFS isn't a general complaint channel for every data broker. |
Choose the route by the result you need
- Want your information removed or future sales stopped? Send the broker a deletion or opt-out request. California residents may have additional rights under the CCPA or California Delete Act.
- Want an agency to review misleading or unfair practices? Report the conduct to the FTC and, when appropriate, your state attorney general or privacy regulator.
- Need inaccurate information corrected after it affected a decision? Check whether the company is acting as a consumer reporting agency under the Fair Credit Reporting Act (FCRA). A general FTC complaint doesn't replace an FCRA dispute.
- Are you dealing with a breach or identity theft? Follow the company's breach instructions and consider a credit freeze, fraud alert, or identity-theft report if the exposed information creates a real risk.
- Does the issue involve a financial company? The CFPB may be appropriate for a bank, lender, credit bureau, debt collector, payment provider, or another company covered by its complaint process.
A business calling itself a "data broker" doesn't automatically fall under every privacy law. Coverage can depend on your state, the company's business model, the type of information involved, and how the company uses it.
FTC complaints: no posted consumer filing deadline
You can submit a report through the FTC's ReportFraud portal about deceptive privacy promises, unauthorized data sales, impersonation, fraud, or other unfair conduct.
The portal doesn't state a fixed deadline by which a consumer must file. That is only an intake rule, not a guarantee that every possible legal claim remains available. Statutes of limitation, evidence rules, and deadlines for private lawsuits are separate questions.
Give the FTC enough detail to identify the conduct:
- The broker's name, website, app, or mailing address
- When you found the listing or learned that your information was being sold
- The types of information involved
- What the company promised in its privacy policy or opt-out instructions
- Screenshots, emails, invoices, notices, and confirmation numbers
- The dates and results of any deletion, correction, or opt-out requests
- Concrete harm, such as identity theft, harassment, targeted scams, or a decision based on inaccurate information
An FTC report adds information to the agency's enforcement database. It normally won't order the broker to delete your record or pay you. Send the direct privacy request separately, and keep proof of both submissions.
California CCPA request clocks
California residents can ask covered businesses to disclose, delete, or correct certain personal information. They can also opt out of the sale or sharing of personal information in situations covered by the law.
The California Attorney General's CCPA guidance describes the main rights and the written notice requirement that can apply before a private lawsuit. A request usually goes more smoothly when you treat it as a dated record rather than an informal email:
- Find the company's privacy, consumer-rights, or "Do Not Sell or Share My Personal Information" page.
- Choose the right request. Say whether you want access, deletion, correction, or an opt-out.
- Submit it through the company's listed method.
- Save the confirmation screen, email, ticket number, and exact submission date.
- Provide only the verification information reasonably needed to match your record.
- Mark the response date on your calendar.
For a request to know or delete, a covered business generally must confirm receipt within 10 business days and respond within 45 calendar days. It may extend the response period by up to another 45 days when necessary, but it should notify you during the initial period.
Opt-outs use a different clock. California regulations generally require a business to process a sale or sharing opt-out as soon as feasible and no later than 15 business days. A user-enabled Global Privacy Control signal, such as GPC, can also function as an opt-out in covered situations.
Deletion and opt-out requests solve different problems. Deletion seeks removal of qualifying information, subject to exceptions. An opt-out generally concerns future sale or sharing and doesn't necessarily remove information already held.
A business may deny or limit a request if it can't verify your identity or if a legal exception applies. The response should explain the reason and, where required, provide appeal information.
The CCPA 30-day notice rule
The 30-day written notice often mentioned in CCPA articles is not a general deadline for reporting a data broker. It concerns the limited private right of action for certain data-security breaches.
When that private action applies, California requires the consumer to give the business written notice identifying the alleged CCPA violation and allow 30 days for a written response stating that the violation has been cured and won't recur. An ignored deletion request, failed opt-out, or questionable data-broker marketing practice doesn't automatically create a CCPA lawsuit.
You generally don't need to wait 30 days before submitting a complaint to a California regulator. A regulatory complaint and a private lawsuit are separate paths.
The 12-month opt-back-in rule
After a consumer opts out of the sale or sharing of personal information, a business must wait at least 12 months before asking that consumer to opt back in. That restriction applies to the business's follow-up request. It isn't a 12-month waiting period for you to file a complaint or make a deletion request.
California DROP and the Delete Act
California's Delete Act created a centralized deletion mechanism known as DROP for California consumers and registered data brokers. The California Privacy Protection Agency FAQ provides current agency information and links to its privacy resources.
Beginning August 1, 2026, registered data brokers must check DROP at least once every 45 days. They then match requests against their records and take the action required by law.
The 45-day period is easy to misread:
- It is the maximum interval between required checks by a registered broker.
- It isn't your deadline to submit a complaint.
- It doesn't promise that every record will disappear exactly 45 days after you submit a request.
- It applies to registered data brokers, not every company that stores or publishes personal information.
Keep the DROP confirmation and any result displayed by the platform. If a registered broker doesn't check the system, continues selling information after a valid request, or reports an inaccurate result, use the current CPPA or California consumer-protection complaint instructions. Include the broker's name, the request date, screenshots, and follow-up messages.
A broker's registration renewal date or registration fee is a business compliance matter. It doesn't set your personal deadline for making a request or reporting a violation.
CFPB and FCRA complaints
The CFPB complaint portal may help when a data problem involves a financial product or service. Examples include a credit bureau, lender, debt collector, bank, mortgage company, or another covered financial provider.
The CFPB usually isn't the best first route for an ordinary people-search site with no connection to a financial decision. Any company response time in a CFPB complaint workflow is not a universal deadline limiting your right to complain.
Use the FCRA dispute process when a broker or reporting company supplied inaccurate information for a decision involving:
- Credit or a loan
- Employment
- Housing
- Insurance
- Another transaction requiring a permissible purpose
Send a written dispute to the consumer reporting agency and, when appropriate, to the company that furnished the information. Identify each inaccurate item, explain what is wrong, attach supporting documents, and keep delivery records. An FTC or CFPB complaint can supplement that dispute, but it doesn't replace it.
If an employer, landlord, lender, or insurer has already taken adverse action, request the adverse-action notice and act quickly. It may identify the reporting company and point you toward the correct dispute route.
State complaints and the NYDFS distinction
There is no single state deadline for all U.S. data broker complaints. A state attorney general, privacy agency, secretary of state, or financial regulator may have a different role depending on the conduct and the company's status.
New York's Department of Financial Services cybersecurity rules are a frequent source of confusion. The NYDFS 72-hour cybersecurity-event reporting requirement applies to covered NYDFS-regulated entities. It is a business-to-regulator obligation, not a 72-hour or 30-day deadline for a consumer reporting a general data broker.
The same distinction applies to data-broker registration renewals, termination notices, and civil penalties. Those are business obligations. If a website lists a Vermont, Texas, or Oregon registration date, don't use it as your complaint deadline; check the relevant state agency's current instructions instead.
When filing a state complaint, describe the conduct without guessing at the statute:
- Identify what the business collected, published, sold, or failed to delete.
- State where you live.
- Say whether you made an opt-out, deletion, access, or correction request.
- Give the dates and attach the company's response.
- Ask the agency to review the conduct under any applicable privacy or consumer-protection law.
GDPR: the 72-hour rule isn't a consumer complaint deadline
The GDPR's familiar 72-hour period concerns a controller's notification to a supervisory authority after a personal data breach, when notification is required. It doesn't require an individual to complain within 72 hours, and 96 hours isn't a standard consumer complaint window.
For someone in the United States, GDPR usually won't be the primary route unless the facts show that the organization is processing data in a way covered by the regulation, such as targeting or monitoring people in the European Economic Area. If GDPR does apply, the relevant data request and supervisory-authority procedures have their own rules. Don't wait for a supposed 72-hour consumer deadline before preserving evidence or contacting the organization.
What to save before you complain
Make a folder for the issue and keep:
- Screenshots of the broker listing, search results, privacy policy, and opt-out page
- The full web address and the date captured
- Copies of every request, response, and automated confirmation
- The exact information exposed, with unnecessary sensitive details redacted
- Proof of identity or residency only when the legitimate request process requires it
- Evidence of harm, such as unwanted contact, fraud attempts, or a credit or housing decision
- A timeline showing when you discovered the issue and when each request was sent
Don't email a Social Security number, full driver's license, or another highly sensitive document unless the company provides a secure, verified method and genuinely needs it. A broker may need enough information to locate your record, but a deletion request shouldn't become a reason to disclose more personal data than necessary.
A workable request and complaint sequence
- Preserve the page. Take screenshots before the listing, privacy policy, or opt-out form changes.
- Choose the outcome. Decide whether you want deletion, access, correction, an opt-out, or an agency investigation.
- Send one clear request. Use the broker's official privacy channel and name the right you are exercising.
- Calculate the applicable clock. For a California access or deletion request, count 45 calendar days and watch for an extension notice. Don't apply that 45-day period to an opt-out.
- Follow up after the clock runs out. Quote the original date and attach the confirmation instead of starting over with an identical form.
- Escalate to the matching agency. Use the FTC for broad unfair or deceptive conduct, California regulators for California privacy issues, and the CFPB or FCRA dispute process for financial or consumer-reporting problems.
- Reduce further risk. Consider a credit freeze, fraud alert, password change, or identity-theft report when the exposed information creates a real threat.
You can keep the direct request short:
On [date], I request [deletion, access, correction, or opt-out] of personal information associated with [identifying details]. Please confirm receipt, tell me if additional verification is required, and provide the response or appeal information required by applicable law.
Only say that you're a California resident or invoke a specific law when that's true. If the company rejects the request, save its explanation; repeatedly submitting the same form won't fix a verification problem or a statutory exception.
Frequently asked questions
Is there an FTC deadline for reporting a data broker?
The FTC's ReportFraud intake doesn't state a fixed consumer filing deadline. Report the conduct promptly because the agency's ability to use the information depends on the evidence available and its enforcement priorities. A private legal claim may have a separate limitation period.
Does the CCPA give a business 45 days to delete my information?
For a covered California business, 45 calendar days is generally the response period for a request to know or delete. It isn't always the date by which every record must be gone. A business may extend the response by up to 45 additional days with notice. Opt-out requests follow a different processing rule.
Do I need to wait 30 days before filing a California privacy complaint?
No. The 30-day written notice concerns the limited CCPA private action procedure for certain security-breach claims. It isn't a general waiting period for a complaint to a California regulator.
Is the DROP 45-day period my deadline?
No. Beginning August 1, 2026, registered data brokers must check DROP at least every 45 days. Keep your request confirmation and report a failure to process the request through the current California privacy agency instructions.
Should I file with the FTC or the CFPB?
Use the FTC for suspected deceptive or unfair data practices. Use the CFPB when the issue involves a covered financial company or consumer reporting. Both may be appropriate when the facts genuinely involve both types of conduct.
What if a data broker ignores my request?
Save the request, confirmation, and missed response date. Send a concise follow-up, then complain to the appropriate state or federal agency. If the information affected credit, employment, housing, or insurance, start the separate FCRA dispute process rather than relying only on a general privacy complaint.
This is general consumer information, not legal advice. Save the broker's page, send the specific request, and put the applicable response date on your calendar.