Use the universal template below when you want a company to investigate a privacy problem, explain how it used your information, or take a specific corrective step. Choose a more targeted template when you are exercising a formal privacy right, reporting a suspected breach, or contacting a regulator.
The right route depends on your location, the type of data, and what happened. In the United States, you may start with the company's privacy team, use a state privacy-rights request process where available, contact HHS about a HIPAA concern, or report a scam to the FTC. UK and EU complaints use separate processes.
These templates provide practical information, not legal advice. Replace the bracketed text, remove anything that doesn't apply, and don't send unnecessary sensitive information.
Choose the right message
A privacy complaint and a privacy-rights request can overlap, but they serve different purposes:
- Complaint: You object to collection, sharing, retention, security, marketing, or the company's response.
- Rights request: You want to access, delete, correct, or restrict certain uses of your personal information. The business may require its own form or privacy portal.
- Suspected breach report: You tell the company that your information may have been exposed. Any legal duty to investigate or notify a regulator is separate from your own report.
- Regulator report: You ask an agency to review conduct that may violate a law. A regulator report usually won't fix your account or guarantee compensation, so contact the company separately when you need a practical remedy.
A privacy notice can help show what a company said it would do with your information. It doesn't automatically turn a general complaint into a formal statutory request. If you want to exercise a legal privacy right, label the message as a request and use the submission method listed in the company's privacy notice.
Don't automatically copy a "72-hour," "30-day," or "60-day" deadline into an email. Those periods may concern a company's breach-notification duty, a formal rights request, or an agency process rather than your complaint.
Universal privacy complaint email template
Use this for unauthorized sharing, a misleading privacy notice, weak security, unwanted marketing, or a privacy request that was ignored.
Subject: Privacy complaint about [specific issue] - [Your name or account reference]
Dear [Privacy Officer, Data Protection Officer, or Privacy Team],
I am making a formal complaint about [organization]'s handling of my personal information.
On [date or date range], [describe exactly what happened]. The information involved may include [name, email address, account details, location data, health information, or other data].
My concern is that [explain why the conduct conflicts with the privacy notice, a company communication, a request you made, or an applicable privacy rule]. The relevant policy or notice is [link or document title].
Please:
1. Confirm receipt of this complaint.
2. Investigate the incident and preserve relevant records.
3. Explain what happened, what information was involved, and who received or accessed it.
4. Stop the disputed processing or honor my related request, if applicable.
5. Explain what corrective action and notification, if any, will follow.
6. Tell me how to escalate the matter if your response does not resolve it.
I can complete reasonable identity verification through a secure channel. I have not included my password, full Social Security number, or unnecessary medical information in this email.
Please respond at [email or secure contact method]. My account or reference number is [number].
Sincerely,
[Full name]
[Email and phone]
[Mailing address, if needed]
[Account or customer number]
10 privacy complaint email templates
1. Unauthorized data sharing or sale
Use this when an app, website, broker, or business appears to have shared your information with an unexpected recipient.
Subject: Complaint about unauthorized sharing of my personal information
Dear [Privacy Team],
On [date], I learned that [organization] may have shared or sold my [type of information] to [recipient, advertiser, data broker, or unknown third party].
I was not given clear notice of this use, or I previously [withdrew consent, opted out, or asked that my information not be shared]. The evidence is attached: [list screenshots, notices, messages, or account records].
Please investigate and tell me:
- What information was shared or sold;
- The date or date range of the disclosure;
- The recipients and purpose;
- The legal or policy basis for the disclosure;
- How long the information will be retained; and
- Whether further disclosures have stopped.
If possible, please request deletion or suppression by the recipients and confirm the steps taken. Please also tell me how to submit a formal opt-out or deletion request through your designated process.
Sincerely,
[Name]
[Account email or reference]
2. Personal data access request
Use this when you want to know what information a company holds about you. Submit it through the company's privacy portal or request form as well if the business requires one.
Subject: Personal data access request - [Your name or account number]
Dear [Privacy Team],
Please treat this message as a request for access to the personal information [organization] holds about me, to the extent provided by applicable law.
Please provide, where applicable:
- A copy of my personal information;
- The categories and sources of the information;
- The purposes for which it is used;
- The categories of recipients or specific recipients;
- The retention period or the criteria used to set it;
- Information about relevant profiling or automated decision-making; and
- Any other information required under the law that applies to my request.
My identifying details are [details used on the account]. Please tell me if you need identity verification and provide a secure method for completing it.
Please confirm receipt and explain the response process. If any information is withheld, identify the applicable exception and explain how I can challenge that decision.
Sincerely,
[Name]
[Account email]
[Postal address, if required for verification]
For an EU GDPR access request, the European Commission says an organization generally must respond without undue delay and no later than one month, subject to permitted extensions and exceptions. That period applies to the rights request, not necessarily to a general complaint.
3. California deletion or correction request
Use this when you are a California resident and want to make a request under the CCPA or CPRA, if applicable. Coverage, verification requirements, exemptions, and the business's approved submission methods still matter.
Subject: California privacy request to [delete or correct] my personal information
Dear [Privacy Team],
I am a California resident and request that you [delete the personal information you hold about me / correct the following inaccurate information] under the CCPA and CPRA, if applicable.
My account details are:
- Name: [name]
- Account email or customer number: [details]
- Information to correct or delete: [specific information]
- Correct information, if applicable: [replacement details]
Please also tell me which categories of information are affected and whether any information cannot be deleted or corrected because of a legal, security, transaction, or other exception.
Please confirm receipt, tell me whether additional verification is required, and provide the response through [email or secure method]. If you deny all or part of this request, explain the reason and the available appeal or complaint route.
Sincerely,
[Name]
[Contact information]
A general complaint email doesn't automatically count as a CCPA request. Use the method listed in the company's privacy notice, then keep a copy of both submissions.
4. Opt-out of sale, sharing, or targeted advertising
Use this when a qualifying business does not appear to have honored a California opt-out or a similar request.
Subject: Complaint - privacy opt-out was not honored
Dear [Privacy Team],
On [date], I submitted a request to opt out of [sale of my personal information / sharing for cross-context behavioral advertising / targeted advertising] through [method used].
I continue to see [describe the conduct], or I received [message, notice, or confirmation] suggesting that the request was not applied. Attached are [screenshots, confirmation emails, or dates of contact].
Please:
1. Confirm whether my opt-out request is active.
2. Stop the processing covered by my request, if applicable.
3. Identify the account, cookie, device, or identifier associated with the request.
4. Explain why the request was not honored.
5. Tell me how to escalate the matter if it remains unresolved.
Please don't ask me to provide more personal information than is reasonably necessary to locate my request.
Sincerely,
[Name]
[Account email or reference]
[Date of original opt-out request]
5. Marketing emails continued after unsubscribe
Use this when commercial messages continue after you used an unsubscribe link or directly asked the sender to stop.
Subject: Privacy and marketing complaint - unsubscribe request ignored
Dear [Company or Sender],
I asked [company] to stop sending marketing messages to [email address] on [date] by using [unsubscribe link, account setting, or support request].
I received additional marketing messages on [dates]. Examples are attached, including the message headers and unsubscribe confirmation where available.
Please:
- Stop sending marketing messages to this address;
- Add the address to your suppression list;
- Explain how the address was collected and which service or sender used it;
- Confirm whether my information was shared with other marketing providers; and
- Tell me how you will prevent further messages.
I understand that essential account, security, or transaction messages may be handled separately. This complaint concerns marketing communications.
Please confirm the action taken.
Sincerely,
[Name]
[Email address]
[Customer or account reference]
Keep the original message headers if possible. They can help identify the sender, service provider, and transmission date.
6. Suspected personal data breach
Use this when you believe an account, database, email, device, or service exposed your information. Describe it as suspected unless the company has confirmed an incident.
Subject: Suspected personal data breach - request for investigation
Dear [Security or Privacy Team],
I am reporting a suspected security or privacy incident involving my account or personal information.
The incident appears to have occurred on [date or date range]. I observed [unauthorized login, exposed document, misdirected email, missing device, unusual account activity, or other facts].
The information that may be affected includes [types of information]. My evidence includes [screenshots, account alerts, messages, or other records]. I have not attached unnecessary sensitive information.
Please confirm:
- Whether [organization] has identified or confirmed an incident;
- The relevant dates and systems;
- The categories of information involved;
- Whether my account or information was accessed, copied, or disclosed;
- The steps I should take to protect myself; and
- Whether the organization will provide any legally required notice or support.
Please preserve relevant access logs and other records while this matter is reviewed. Use [secure portal or phone number] for sensitive follow-up.
Sincerely,
[Name]
[Account number or username]
[Safe contact information]
7. Suspected HIPAA privacy or security violation
Use this first with the provider, health plan, or business associate's privacy officer. Don't send a complete medical record through ordinary email.
Subject: HIPAA privacy complaint - possible disclosure of my protected health information
Dear Privacy Officer,
I am reporting a possible privacy or security incident involving my protected health information.
On [date], [describe the disclosure, misdirected message, unauthorized access, tracking technology, or other event]. The information may have involved [limited description of the records or identifiers]. The people or organizations involved appear to be [names, if known].
Please investigate and confirm:
- Whether my records were accessed, used, or disclosed;
- The dates, recipients, and categories of information involved;
- The safeguards and corrective action being taken;
- Whether the event is being treated as a reportable breach; and
- How I can receive a secure explanation or any required notice.
Please preserve relevant audit logs and communications. I can provide additional details through your secure portal or by telephone. I have not attached a complete medical record because ordinary email may not be secure.
If this matter is outside HIPAA, please identify the appropriate privacy complaint process.
Sincerely,
[Name]
[Patient or member number]
[Safe contact information]
HIPAA applies to covered entities and business associates, not every health, fitness, or wellness service. If the provider's response doesn't resolve the issue, use the HHS Office for Civil Rights complaint process and check its current filing instructions. A covered entity's breach-notification duties are separate from your right to report a concern.
8. FTC report narrative for a scam or deceptive privacy practice
The FTC's primary route for an illegal business practice or scam is its Report Fraud service, not the FOIA email address sometimes copied into old complaint templates. Use the following as a concise report narrative:
Business or person reported: [name, website, phone number, email, or social account]
What happened:
On [date], [company or person] collected, used, disclosed, or requested my information by [describe the conduct].
What I was told:
[Quote or summarize the privacy promise, advertisement, message, or representation.]
Why I believe it was deceptive, unfair, or fraudulent:
[Explain the contradiction, pressure, impersonation, unauthorized charge, data request, or other harm.]
Information involved:
[Describe only the categories. Do not include passwords, full account numbers, or unnecessary medical information.]
Money or other loss:
[$ amount, account takeover, identity theft risk, or no known financial loss.]
Evidence available:
[List messages, receipts, screenshots, web pages, and dates.]
The business has been contacted:
[Yes or no. If yes, give the date and response.]
My daytime telephone number is:
[Number]
A report can help the FTC identify patterns, but it doesn't guarantee an investigation, a personal response, or reimbursement. If money or an account is at risk, contact the bank, card issuer, platform, or account provider separately.
The FTC says confidential information should be marked "Confidential" and sent by postal mail to its headquarters:
600 Pennsylvania Ave., NW
Washington, DC 20580
Follow the agency's contact guidance before mailing sensitive material.
9. UK ICO complaint
Use this for an issue involving the UK GDPR or the Data Protection Act 2018 in a UK context. You should normally raise the concern with the organization first.
Subject: Complaint about [organization]'s handling of my personal data
Dear Information Commissioner's Office,
I am asking the ICO to review my concern about [organization].
I first complained to the organization on [date] using [email, form, or postal address]. My complaint concerned [brief description]. The organization responded on [date] with [summary], or has not provided a response.
The personal information involved is [categories of information]. The relevant conduct was [clear factual description]. I believe the organization may not have complied with [UK GDPR or Data Protection Act 2018 provision, if known] because [reason].
I have attached:
- My original complaint;
- The organization's response, if any;
- Relevant privacy notices or policy pages; and
- Supporting evidence with unnecessary sensitive information removed.
Please assess whether the organization handled my personal data properly and tell me if further information is required.
Sincerely,
[Name]
[Address or contact information]
[Organization's details]
[Date of original complaint]
The ICO's complaint guidance says an organization has 30 days to acknowledge a data protection complaint. That is an acknowledgment period, not a promise that the complaint will be resolved within 30 days.
10. EU GDPR complaint to a supervisory authority
Use this for an EU GDPR matter. The UK ICO is a separate route, and a U.S. state regulator isn't automatically the correct authority.
Subject: GDPR complaint about [controller or organization]
Dear [Name of national data protection authority],
I am a data subject asking you to review the processing of my personal information by [controller's legal name and address, if known].
The relevant service or account is [service, website, or account]. The issue occurred on [date or date range] and involves [describe collection, disclosure, refusal, security issue, or other processing].
I contacted the controller on [date] and requested [explain request]. The response was [summary], or no response was received. My concern is that [state the factual basis without overstating the legal conclusion].
Attached are:
- My communication with the controller;
- The controller's response, if any;
- The relevant privacy notice; and
- Supporting evidence with unnecessary personal information redacted.
Please confirm whether this complaint is within your authority and tell me if you need additional information.
Sincerely,
[Name]
[Country of residence]
[Controller details]
[Contact information]
The European Commission's information for individuals explains how people can exercise GDPR rights and complain to a data protection authority. Start with the authority connected to the controller or with the applicable national rules.
Send a privacy complaint safely
- Save evidence first. Keep the original emails, message headers, screenshots, account notices, privacy-policy version, URLs, dates, and support ticket numbers.
- Check the recipient. Look for "Privacy," "Legal," "Data Protection Officer," or "Notice of Privacy Rights." A formal rights request may need a designated portal.
- Share only what is necessary. Don't include passwords, full payment-card numbers, Social Security numbers, or complete medical records in ordinary email.
- Name one primary remedy. Ask to stop sharing, delete information, correct an account record, investigate a breach, or explain the data use. You can ask related questions, but a long list of unrelated demands can make the complaint harder to process.
- Request secure follow-up. Ask for a secure upload link or telephone verification if the company needs sensitive details.
- Keep a paper trail. Save the sent message, delivery confirmation, attachments, and replies. A read receipt alone doesn't prove that anyone reviewed the complaint.
- Follow up once the company has had a reasonable opportunity to respond. Use the follow-up template below instead of sending repeated threats or emotional messages.
If your complaint involves identity theft or an active account takeover, change the password from a trusted device, enable multifactor authentication, contact the account provider, and consider a credit freeze or fraud alert.
Timelines and escalation routes
There isn't one U.S. deadline for every privacy complaint. The applicable rule may depend on the state, industry, type of information, and whether you submitted a formal rights request.
| Situation | First step | Timing or limit to remember |
|---|---|---|
| General U.S. privacy concern | Contact the company's privacy or legal team | No single federal response period applies to every complaint |
| California privacy-rights request | Use the business's listed CCPA or CPRA method | A rights-request response period is different from a general complaint-resolution period |
| Suspected HIPAA issue | Contact the provider or plan's privacy officer, then HHS OCR if needed | The organization's breach-notification duties are separate from your complaint; check OCR's current filing instructions |
| FTC scam or deceptive practice | Use Report Fraud | The FTC doesn't promise an individual investigation or reimbursement |
| UK GDPR concern | Complain to the organization, then use the ICO process | ICO guidance describes a 30-day acknowledgment period, not a guaranteed resolution period |
| EU GDPR concern | Complain to the controller and the relevant national authority | A formal GDPR rights request generally has a one-month response period, subject to exceptions and extensions |
What common deadlines do not mean
- GDPR's 72 hours: This generally concerns a controller's notification to a supervisory authority after a qualifying breach is discovered. It isn't your deadline to email a company.
- A "30-day cure" period: Don't treat language from an older California template as a universal current deadline for every privacy complaint or request.
- A HIPAA breach-notification period: This concerns obligations of covered entities and business associates. It isn't a waiting period before you may complain.
- A regulator acknowledgment: Confirmation that an agency received your report doesn't mean it has decided that a violation occurred.
Optional follow-up email
Send this when the organization hasn't acknowledged your first message or gave an incomplete response.
Subject: Follow-up to privacy complaint sent [date] - [reference number]
Dear [Privacy Team],
I am following up on my privacy complaint sent on [date]. The complaint concerned [one-sentence description].
I have not received a response, or the response did not address [specific unanswered question]. For convenience, I have attached the original message and relevant evidence again.
Please confirm the current status, identify the person or team handling the matter, and answer these outstanding questions:
1. [Question]
2. [Question]
3. [Requested remedy]
Please reply by [date] or explain the expected timetable. If the matter cannot be resolved through your internal process, please provide the appropriate escalation or regulatory contact.
Sincerely,
[Name]
[Account or case reference]
Mistakes that weaken privacy complaints
- Calling every policy breach illegal. Describe the conduct first and identify the policy language or request that appears inconsistent.
- Sending the complaint to the wrong agency. The ICO handles UK matters, EU data protection authorities handle their jurisdictions, HHS OCR handles HIPAA-covered matters, and the FTC is mainly a reporting and enforcement route for scams or unfair or deceptive practices.
- Demanding guaranteed payment. You can ask a company to consider documented losses, but a privacy complaint doesn't automatically create a right to compensation.
- Using an old email address. Check the agency's or company's current contact page. Don't send a general FTC privacy complaint to a FOIA address.
- Attaching too much. Redact account numbers, passwords, medical details, and information about other people unless the recipient specifically requests it through a secure process.
- Confusing marketing with account messages. Identify the exact messages and preserve the unsubscribe confirmation.
- Making a vague accusation. "You violated my privacy" is less useful than "On March 4, I opted out, but your company shared my email with [recipient] on March 8."
Choose the template that matches the conduct, send it through the company's designated channel or the applicable agency's current reporting route, and save the confirmation and reference number for your follow-up.