Quick answer
If a company appears to be using your personal information in a way that conflicts with its privacy notice, send a short, factual complaint asking for an explanation. If you want the company to take a formal action, label that part clearly as a California CCPA request or a GDPR rights request. A general complaint may not trigger a statutory access, deletion, correction, or opt-out process.
Include the policy URL and version date, a date-ordered account of what happened, the information involved, and one remedy you want. Ask for a case number and secure identity-verification instructions. Don't call every policy change a legal violation, and don't demand a 72-hour response to an ordinary privacy email.
Use the California templates only if you're a California resident requesting action from a covered business. Use the GDPR templates only if the GDPR applies to you and the processing. A policy dispute by itself doesn't establish a legal violation, and these samples are general information rather than legal advice.
Keep the first email focused:
- Identify your account without exposing unnecessary personal information.
- Describe the event in date order.
- Link to the relevant privacy notice and record its version date.
- Name one remedy, such as access, correction, deletion, or an opt-out.
- Ask how the company will verify your identity and provide a case number.
Which privacy email do you need?
| Problem | Best request | What it does not automatically prove |
|---|---|---|
| The company's conduct seems inconsistent with its privacy notice | General complaint and request for explanation | That the company violated a statute |
| You want to know what information a California business holds | CCPA request to know or access | That every requested record must be disclosed |
| You want information removed or corrected in California | CCPA deletion or correction request | That all information can be deleted or changed |
| You want to stop certain processing in California | CCPA sale or sharing opt-out | That all advertising or first-party use will stop |
| You want a copy of data processed under the GDPR | GDPR Article 15 access request | That every request can be granted without verification |
| You received information suggesting a breach | Security incident inquiry | That the event meets the legal definition of a breach |
| The company has not answered | Follow-up and possible regulator complaint | That a regulator or court will award compensation |
California CCPA requests versus EU GDPR requests
California: CCPA as amended by the CPRA
California residents may have rights to know or access, delete, correct, and opt out of the sale or sharing of personal information. Depending on the circumstances, they may also be able to limit the use and disclosure of sensitive personal information. The business must be covered by the law, and it may need to verify your identity before responding.
A right-to-know request can cover categories of personal information, sources, business or commercial purposes, categories of recipients, and certain specific pieces of information. Exceptions and limits still matter. The California Privacy Protection Agency consumer FAQ explains these rights.
For requests to know, delete, or correct, the CPPA says a business must confirm receipt within 10 business days. A business generally has 45 calendar days to respond and may extend that period by another 45 days when reasonably necessary and after providing notice. Check the California CCPA regulations for current procedural requirements.
An opt-out request is different from a deletion request. If you want to stop the sale or sharing of personal information, say so directly. California's Attorney General CCPA guidance also explains Global Privacy Control, or GPC, which can communicate an opt-out through a supported browser or device.
The CCPA doesn't apply to every business or every privacy-policy disagreement. A notice that is hard to understand, or a policy that changes, does not by itself prove a CCPA violation.
EU GDPR
The GDPR gives individuals rights that can include access, rectification, erasure, restriction of processing, data portability, and objection. Whether it applies depends on the processing and the organization's connection to people in the EU or EEA. A template mentioning GDPR does not create GDPR rights by itself.
A controller generally must respond to a rights request without undue delay and within one month. It may extend the period by up to two additional months for a complex request, but it should explain the extension within the first month. The European Commission's guidance on individual data requests provides an overview.
The GDPR's 72-hour breach rule is often misunderstood. When a personal data breach is likely to create a risk, the controller may need to notify the relevant supervisory authority within 72 hours of becoming aware of it. That is not a general 72-hour deadline for answering a consumer's email. Communication to affected individuals depends on the level of risk. The European Data Protection Board's breach guidance explains the distinction.
The UK GDPR is a separate regime. If your issue concerns the United Kingdom, check the applicable UK authority rather than assuming that an EU supervisory authority is the correct complaint route.
Prepare before sending a privacy dispute email
- Save the evidence. Keep screenshots, emails, consent records, account notices, invoices, and the privacy notice as it appeared on the relevant date.
- Record the timeline. Note when you supplied information, changed a setting, received a notice, or noticed unexpected use.
- Use the company's official channel. Check its privacy notice for a privacy team, data protection officer, request form, or appeal process.
- Minimize sensitive information. Give enough information to locate your account, but don't email a Social Security number, full payment card number, password, or unnecessary identity documents.
- Choose one remedy. Access, deletion, correction, an objection, consent withdrawal, and an opt-out are different requests.
- Ask for secure verification. If the company needs to verify your identity, use its secure portal or instructions instead of sending documents through ordinary email.
- Set a realistic follow-up date. Use the applicable response period rather than demanding an immediate legal conclusion.
- Keep a complete record. Save the sent email, delivery confirmation, automated reply, case number, and every response.
10 ready-to-use privacy dispute email templates
Replace the bracketed text and remove any paragraph that doesn't apply. Send only the request you actually want the company to process. If you need both an explanation and a statutory rights request, state each one in a separate, clearly labeled section.
1. General privacy complaint and request for review
Use this when you see a possible mismatch but aren't yet sure which specific legal right applies.
Subject: Privacy complaint and request for review - [account ID]
Hello [privacy team or data protection officer],
I am contacting you about the handling of my personal information by [company].
On [date], I [describe what happened]. The information involved appears to be [describe the data]. Your privacy notice at [policy URL], dated [policy date], appears to say [quote or summarize the relevant passage].
Please:
1. Confirm receipt and provide a case number.
2. Explain what information was used, disclosed, or retained.
3. Identify the relevant purpose and, where applicable, the legal basis or California privacy category.
4. Tell me what corrective action you will take.
5. Direct me to any formal access, deletion, correction, or opt-out process that applies.
I can provide supporting screenshots or documents through a secure channel. Please don't ask me to send unnecessary sensitive information by ordinary email.
Regards,
[Full name]
[Account email or other limited identifier]
[Preferred contact method]
2. California CCPA request to know or access
Use this to ask a covered business for information about its collection and use of your personal information.
Subject: California CCPA request to know and access personal information
Hello [privacy team],
I am a California resident. Please treat this message as a request to know and access my personal information under the California Consumer Privacy Act, as amended by the California Privacy Rights Act.
For the preceding 12 months, please provide, to the extent required:
- The categories of personal information collected about me
- The purposes for collecting or using each category
- The sources from which the information was collected
- The categories of third parties, service providers, or contractors that received it
- The categories of personal information sold or shared, if any
- The specific pieces of personal information collected about me, where applicable
My account identifiers are [email address, username, order number, or another limited identifier].
Please confirm receipt and tell me how you will verify my identity and deliver the response securely. If you deny any part of this request, please identify the applicable reason or exception.
Regards,
[Full name]
[California city or other residency information, if needed]
[Account identifier]
3. California CCPA deletion request
A deletion request may have exceptions. If you need the account to remain open, say that clearly.
Subject: California CCPA request to delete personal information
Hello [privacy team],
I am a California resident and request deletion of the personal information that [company] collected from me under the CCPA, as amended by the CPRA.
Please delete the following information and associated account records, where covered by the law:
- [Category or example of information]
- [Category or example of information]
- [Account, subscription, or order identifier]
This request does not ask you to close my account unless account closure is necessary. If you retain any information because of a legal, security, transaction, or other applicable exception, please tell me:
1. What category of information you retained
2. The reason for retaining it
3. How long you expect to keep it
4. Whether the information will be used for any other purpose
Please also notify relevant service providers or contractors where required. Confirm receipt and provide secure identity-verification instructions.
Regards,
[Full name]
[Account identifier]
[Preferred contact method]
4. California CCPA correction request
Be precise. Identify the inaccurate record and provide the corrected wording or value.
Subject: California CCPA request to correct inaccurate personal information
Hello [privacy team],
I am a California resident and request correction of inaccurate personal information under the CCPA, as amended by the CPRA.
The record appears to show:
- Field or record: [name of field]
- Current value: [incorrect value]
- Correct value: [correct value]
- Evidence: [brief description of attached or available evidence]
Please update the relevant records and, where required, communicate the correction to applicable service providers or contractors.
If you cannot make the correction, please explain why, identify any applicable exception, and tell me how to appeal or provide additional evidence. Please confirm receipt and explain your identity-verification process.
Regards,
[Full name]
[Account identifier]
[Preferred contact method]
5. California opt-out of sale or sharing
Use this when your goal is to stop a sale or sharing activity as those terms are defined by California law. An opt-out won't necessarily stop all advertising or the company's first-party use of information.
Subject: California request to opt out of sale or sharing of personal information
Hello [privacy team],
I am a California resident and request to opt out of the sale or sharing of my personal information under the CCPA, including sharing for cross-context behavioral advertising where applicable.
Please apply this request to:
- Account: [account identifier]
- Email or device identifier: [limited identifier]
- Relevant activity: [advertising, data sharing, or other activity]
I have also enabled Global Privacy Control in [browser or device], if applicable. Please honor that signal where required.
Please confirm the date the opt-out was applied and explain any account or browser setting I must change separately. If you believe the activity is not a sale or sharing under California law, please explain the applicable category and available control.
Regards,
[Full name]
[California city or other residency information, if needed]
6. GDPR Article 15 access request
Use this only when the GDPR applies to the processing. Send it to the controller's privacy team or data protection officer.
Subject: GDPR Article 15 request for access to personal data
Hello [controller or data protection officer],
I am making a request for access under Article 15 of the GDPR.
Please confirm whether you process personal data about me and provide a copy of that data together with the following information:
- The purposes of processing
- The categories of personal data involved
- The recipients or categories of recipients
- The planned retention period, or how it is determined
- The source of the data if it was not collected from me
- My available rights to rectify, erase, restrict, or object
- Information about relevant automated decision-making
- Information about safeguards for any applicable international transfer
My account identifiers are [limited identifiers]. Please tell me how to complete proportionate identity verification and deliver the response securely.
If you refuse any part of this request, please explain the reason and tell me how I can complain to the relevant supervisory authority.
Regards,
[Full name]
[Country or region, if relevant]
[Account identifier]
7. GDPR rectification, erasure, restriction, objection, or consent withdrawal
Select only the paragraphs that match your situation. These rights have different conditions and exceptions.
Subject: GDPR request to [rectify, erase, restrict, or stop processing] my personal data
Hello [controller or data protection officer],
I am requesting action under the GDPR regarding my personal data associated with [account or identifier].
Please apply the following request:
[ ] Rectify inaccurate data:
The current information is [incorrect information].
It should be [correct information].
[ ] Erase data under Article 17:
Please erase [specific data or account records].
If an exception applies, explain which data you will retain and why.
[ ] Restrict processing:
Please restrict processing of [specific data] while [the accuracy or lawfulness issue] is reviewed.
[ ] Object under Article 21:
I object to processing for [specific purpose].
If this concerns direct marketing, stop using my data for that purpose.
[ ] Withdraw consent:
I withdraw consent for [specific purpose] from this point forward.
Please stop processing based on that consent and tell me whether another legal basis is being relied on.
Please confirm receipt, explain any identity-verification requirement, and respond within the applicable GDPR time period. If you refuse or limit the request, explain the legal reason and my complaint options.
Regards,
[Full name]
[Account identifier]
[Preferred contact method]
Withdrawing consent generally affects future processing based on consent. It doesn't automatically undo processing that was lawful before withdrawal, and it may not stop processing based on a different lawful basis.
8. Privacy-policy change or new use of data
A revised privacy notice isn't automatically unlawful. This template asks the company to explain the change and records an objection where appropriate.
Subject: Request for explanation of privacy-policy change and new data use
Hello [privacy team or data protection officer],
I noticed that your privacy notice changed from the version dated [old date] to the version dated [new date].
The earlier notice said:
"[short quote or accurate summary]"
The new notice says:
"[short quote or accurate summary]"
Please explain:
1. When the change became effective
2. What personal information and processing purposes changed
3. The legal basis or California privacy category that applies
4. Whether new consent or another choice is required
5. How I can object, withdraw consent, opt out, or request deletion
If my consent is the basis for the new processing, I withdraw consent for [specific purpose]. If the processing is a California sale or sharing activity, please treat this message as an opt-out request where applicable.
Please confirm receipt and tell me what action you will take.
Regards,
[Full name]
[Account identifier]
9. Suspected personal data breach
Use this when an email, file, account, or other event may have exposed your information. Ask for an investigation rather than declaring that the company has already violated a breach-notification rule.
Subject: Possible personal data incident involving my information
Hello [security or privacy team],
On [date], I observed the following event:
[Describe the misdirected email, unauthorized access, lost device, exposed file, or other event.]
The information that may be involved is [categories of information]. My account or transaction identifier is [limited identifier].
Please route this message to the appropriate security and privacy personnel and confirm:
1. Whether my information is involved, if known
2. The dates and categories of information affected
3. What containment and account-protection steps have been taken
4. What steps you recommend I take
5. Whether the company has assessed any required notices to authorities or affected individuals
Please use a secure channel for any sensitive details. I understand that your investigation may not be complete and that you may be unable to disclose every security detail.
Regards,
[Full name]
[Account identifier]
[Safe contact method]
10. Follow-up and escalation notice
Send this after the company's response period has passed or its answer did not address your request. A routine follow-up is not automatically a statutory pre-suit notice.
Subject: Follow-up on privacy request [case number] sent [date]
Hello [privacy team or data protection officer],
I sent [type of request] on [date] through [email, form, or account channel]. The request concerned [short description]. Your case number is [case number], if available.
I have not received a substantive response, or the response did not address:
- [Unanswered question or requested remedy]
- [Unanswered question or requested remedy]
Please provide:
1. The status of the request
2. The information or action required to complete it
3. A substantive response by [reasonable date]
4. The specific legal exception or reason for any denial
5. The appeal or complaint process available to me
If this remains unresolved, I may submit the correspondence and supporting records through the relevant official regulator process. Please preserve the records relating to this request.
Regards,
[Full name]
[Account identifier]
[Original request date]
How to send and track the request
- Send it to the right team. Use the privacy address, request form, or data protection officer listed in the company's notice. A general customer-service inbox may not process a statutory request correctly.
- Use a secure upload link when offered. If identity verification is necessary, follow the company's process and redact unrelated information from any document.
- Keep the policy version. Save the page as a PDF or screenshot and record its URL and date.
- Ask for a case number. This makes later follow-up easier than relying on a subject line.
- Don't overload the first email. One clear request usually produces a better response than a list of every possible legal provision and penalty.
- Reply promptly to verification questions. The company may not be able to locate or release information until it can reasonably confirm your identity.
- Check the response against your request. An acknowledgment is not the same as an access report, deletion confirmation, correction, or explanation.
- Send one concise follow-up. Include the original date, case number, missing items, and the applicable response period.
Practical response periods
| Request or event | General timing to keep in mind |
|---|---|
| California request to know, delete, or correct | Confirmation within 10 business days; generally a response within 45 calendar days, subject to a permitted extension |
| EU GDPR rights request | Usually one month, with a possible extension of up to two additional months for complex requests |
| Suspected GDPR personal data breach | The 72-hour rule concerns notification by the controller to the supervisory authority when the required risk threshold is met, not a universal response deadline to you |
| California opt-out | Use the company's stated process or GPC where applicable; don't automatically assume the access-request deadline applies |
Where to escalate if the company does not resolve it
California
Start with the company's privacy process and preserve the complete record. If the response is missing, incomplete, or unreasonable, review the California Privacy Protection Agency consumer FAQ and the California Attorney General's CCPA guidance for current rights and enforcement information.
Don't threaten a lawsuit for every privacy-policy disagreement. The Attorney General's guidance describes a limited private right of action for certain security breaches, along with specific notice and cure requirements where applicable. That process is not a general remedy for every CCPA complaint.
EU GDPR
If GDPR applies and the controller does not resolve the issue, you can consider complaining to the supervisory authority responsible for the processing. The European Data Protection Board contact page is a starting point for finding official authority information.
Use the authority's own complaint form rather than copying it on an ordinary email to the company. Include the original request, the policy version, the company's response, and a short timeline. Remove unnecessary passwords, identity documents, and unrelated personal information.
Other U.S. states
If you're outside California and GDPR doesn't apply, don't label the complaint as a CCPA or GDPR request. Check your state's privacy law, attorney general, or consumer-protection office and follow the company's policy for requests. State deadlines and available rights can differ.
Common mistakes to avoid
- Calling a policy update a breach. A notice may change prospectively, subject to applicable law and any required choices. Ask what changed and why.
- Demanding a 72-hour customer response. Under the GDPR, 72 hours is generally an authority-notification deadline for certain breaches.
- Requesting deletion when you need access. Deletion may close an account or remove evidence you still need. Save your records first.
- Assuming every request must be granted. Legal, security, transaction, verification, and other exceptions may apply.
- Using "sold" without explaining the evidence. Describe the observed data flow and ask the company to classify it under the applicable law.
- Sending excessive identity information. Verification should be proportionate and completed through a secure channel.
- Adding a compensation demand to every email. A privacy request doesn't automatically create a right to payment. If you suffered documented financial or other harm, preserve proof and seek jurisdiction-specific advice.
- Copying a regulator on the first message. Give the company a clear opportunity to resolve the request, then use the regulator's official complaint route if needed.
- Mixing jurisdictions. CCPA rights and GDPR rights have different definitions, deadlines, exceptions, and escalation paths.
Frequently asked questions
Does a privacy-policy change prove that a company violated the law?
No. It may show that the notice changed or that the company's conduct deserves an explanation, but it doesn't by itself prove unlawful processing. Compare the old and new wording, identify the data use, and ask what legal basis, consent, or consumer choice applies.
Can I use the GDPR template if I live in California?
Use the CCPA templates for a California request unless the GDPR independently applies to the processing. The company's location or its service to international customers does not automatically give every customer GDPR rights.
What if the company asks for identification?
Follow its secure verification instructions, but provide only what is reasonably necessary. Don't send a full government ID, Social Security number, password, or payment card number through ordinary email unless you've verified the channel and the request is genuinely necessary.
Can I demand that a company admit it violated its privacy policy?
You can ask for an investigation and explanation, but an email does not compel the company to adopt your legal conclusion. A more effective request identifies the conduct, quotes the relevant notice, and asks for a specific remedy.
What should I do if the company denies my request?
Ask for the precise reason, applicable exception, verification issue, and appeal or complaint process. Save the denial and your original evidence before contacting the appropriate California or EU supervisory authority.