A data breach complaint asks a regulator or government office to review a company’s conduct. It usually isn’t a request for automatic compensation.

If a company has notified you, save the notice, secure any affected accounts, and choose the reporting route that matches your situation. The FTC handles reports about fraud and bad business practices. A state attorney general may review state privacy or security concerns. HHS Office for Civil Rights handles certain HIPAA complaints. Your bank or card issuer handles unauthorized transactions, while a company or settlement administrator handles remediation and claims.

Choose the right data breach complaint route

Main concern First step What it does not replace
A company misled you, ignored security concerns, or exposed information File a report with the FTC’s ReportFraud portal A lawsuit, settlement claim, or bank dispute
A possible violation of state privacy or data security law Use the official consumer protection or privacy process for your state attorney general State-specific deadlines and any private legal action
Medical information was exposed by a HIPAA-covered organization File with the HHS OCR complaint portal A claim for personal damages
You see unauthorized charges or account activity Contact the bank, card issuer, or payment provider immediately A regulatory complaint
The notice offers credit monitoring, reimbursement, or a settlement claim Follow the company’s or claims administrator’s instructions A complaint to a regulator

A regulator may record your report, request information, investigate, or seek corrective action. That doesn’t guarantee a personal payment or require the agency to pursue your individual case.

What to do before filing

1. Verify the breach notice

Read the notice carefully and record:

Don’t assume every email about a breach is genuine. Visit the company’s website by typing the address yourself or use a phone number from a prior statement. Avoid entering passwords, security codes, or financial information through an unexpected link.

2. Secure exposed accounts

If a password was exposed or reused elsewhere, change it immediately on the affected account and every account using the same password. The FTC’s consumer guidance on data breaches also recommends unique passwords and stronger sign-in protection, such as an authentication app or security key.

Consider a credit freeze or fraud alert if sensitive identity information was exposed. If you see an unauthorized payment, contact the financial institution through its official number and ask about its dispute process. A government complaint does not replace the separate deadlines that may apply to a payment dispute.

3. Document actual harm

Create a timeline rather than relying on memory. Include:

Be precise. If you haven’t seen misuse, say that you haven’t seen misuse. A report can still explain why the company’s handling concerns you, but speculation can make the complaint harder to evaluate.

4. Redact sensitive information

Do not include a password, full Social Security number, authentication code, recovery phrase, or complete bank account number in a complaint narrative. Redact unnecessary medical details and account numbers from attachments. Submit identity documents only when the official portal specifically requests them.

Copy-and-paste data breach complaint templates

These examples are designed for online forms. Replace the brackets and keep the wording factual. You don’t need to identify a statute unless you have verified that it applies.

FTC data breach complaint sample

Use the FTC’s ReportFraud portal to describe the company, the notice, and any suspected fraud or misleading conduct. The FTC says reports can concern fraud, scams, or bad business practices and provides a report number after submission.

Company: [Company name]

I am reporting a data security incident involving [company name].

On [date], I received a notice stating that unauthorized access occurred between
[date range, if known]. The notice says the information involved included
[describe only the affected information, such as name, email address, phone
number, account information, or Social Security number].

The company told me that [summarize the company’s explanation, including whether
it offered monitoring, a password reset, reimbursement, or other assistance].

My concern is [state the specific concern, such as a misleading notice, failure
to provide promised assistance, repeated exposure, suspicious account activity,
or possible identity theft]. I first noticed [describe any actual impact] on
[date]. I contacted the company on [date] using [method], and it responded
[briefly describe the response or lack of response].

I have attached or can provide the breach notice, relevant communications, and
records of any documented loss. Please send confirmation of this report and any
available guidance on next steps.

Name: [Your name]
State: [State]
Email or phone: [Contact information]

The FTC may use information from reports for enforcement and consumer education, but filing doesn’t mean the agency will investigate or recover your losses.

State attorney general complaint sample

State procedures differ. Start with your state’s official attorney general website and follow its privacy or consumer-protection instructions. A complaint should identify your connection to the state and explain what the company did or failed to do.

Subject: Data breach and privacy complaint involving [Company name]

I am a resident of [state]. On [date], [company name] notified me that a data
security incident affected my information.

According to the notice, the incident occurred on or around [date or date
range], and the information involved was [list the affected information].
The company’s notice or response said [summarize the explanation and assistance
offered].

I contacted the company on [date] because [describe the problem]. The result
was [explain the response, delay, refusal, or continuing concern]. My documented
impact is [describe unauthorized activity, expenses, account problems, or state
that no misuse is currently known].

I ask your office to review whether the company complied with applicable state
privacy and data security requirements. I have attached the breach notice and
relevant records. I have redacted passwords, full account numbers, and other
unnecessary sensitive information.

Name: [Your name]
State and city: [Location]
Email or phone: [Contact information]

Don’t send the same generic complaint to several states without checking their jurisdiction rules. A state AG may be able to enforce state law, but the office generally doesn’t act as your private lawyer or guarantee individual compensation.

HIPAA complaint sample for HHS OCR

HHS OCR handles complaints involving covered health care providers, health plans, health care clearinghouses, and their business associates. A company holding health information isn’t automatically subject to HIPAA, so identify the organization and explain why you believe HIPAA may apply.

Subject: Possible HIPAA privacy or security violation involving [Entity name]

Entity involved: [Provider, health plan, clearinghouse, or business associate]

On [date], I learned that [describe what happened and how you learned about it].
The entity notified me that [summarize the breach notice, if one was provided].

The information involved appears to include [describe the type of protected
health information involved without including unnecessary medical details].
The incident occurred on or around [date or date range], and I believe the
problem may still be continuing because [explain, if applicable].

I contacted the entity’s privacy or security office on [date]. Its response
was [summarize the response or state that no response was received].

I am asking OCR to review whether the entity complied with HIPAA requirements.
I have included the notice and relevant communications and will provide
additional information through the secure complaint process if requested.

Name: [Your name]
Address: [Your address]
Email or phone: [Contact information]

OCR complaints generally have a 180-day filing period measured from when you knew or should have known about the issue. An extension may be available for good cause, but filing promptly is safer. The 60-day period often mentioned in breach notices is mainly a covered entity’s notification obligation; it isn’t a general 60-day deadline for consumers to file an OCR complaint.

OCR may check whether the organization is subject to HIPAA and whether the complaint is timely. Possible outcomes include technical assistance, corrective action, or a resolution process. OCR’s process focuses on compliance and does not function as an individual damages claim.

Illustrative complaint example

A strong complaint can be short:

On May 8, I received a notice from a retailer stating that my name, email address, phone number, and hashed password were involved in unauthorized access discovered in April. The company recommended changing my password but did not explain whether the attacker accessed account activity. I changed the affected password and every reused password on May 8. On May 10, I received several password-reset messages that I did not request. I have attached the notice and copies of those messages. I have not seen an unauthorized charge, but I am concerned about the company’s explanation and the continuing attempts to access my account.

This example separates confirmed facts from concerns. It doesn’t claim that the company violated a particular law or invent a dollar amount.

California CCPA complaints and private claims

California’s CCPA provides consumer privacy rights, but it isn’t a universal remedy for every data exposure. The California Attorney General’s CCPA page explains the law and says that, before filing a private lawsuit, a consumer must give the business written notice identifying the alleged CCPA violations and allow 30 days for a written cure response.

That pre-suit step is different from submitting a complaint to a regulator. It also doesn’t mean every breach supports a private CCPA claim. The private right of action has specific limits concerning the type of information and the security failure involved. Exposure of an email address alone, for example, doesn’t automatically establish a right to damages.

If your concern is that a business sold or shared personal information, failed to honor an opt-out request, or mishandled another CCPA right, describe that conduct separately from the breach. The AG publishes examples of enforcement activity on its privacy enforcement actions page, but an enforcement action and a consumer’s private claim are separate paths.

How to file and track the complaint

  1. Choose one primary route. Use the FTC for a federal report about suspected fraud or bad business practices, your state AG for a state-law concern, or OCR for a possible HIPAA violation.
  2. Prepare the evidence. Keep the original notice, a timeline, company correspondence, and records of actual loss. Redact information that the agency doesn’t need.
  3. Paste a concise narrative. Start with who notified you, what happened, what information was involved, and what you want reviewed.
  4. Submit through the official portal. Avoid sending sensitive documents to an address found in an unexpected email or text.
  5. Save confirmation. Keep the report number, submission date, screenshots, and any follow-up instructions. The FTC provides a report number and tips after a report is submitted; other offices may use different systems.
  6. Respond to requests. Agencies may ask for clarification or additional documents. Answer the specific question and don’t resend unnecessary sensitive data.
  7. Continue account monitoring. A regulator’s review can take time. Keep checking financial accounts, credit reports, and security alerts while the complaint is pending.

Can a data breach complaint get you compensation?

Usually, not by itself. Separate the regulatory report from the payment or recovery process:

Don’t rely on an old article about a major breach to determine current eligibility. Check the notice, court documents, or official claims administrator for the specific incident.

If the breach involves the United Kingdom

The Information Commissioner’s Office is a UK regulator, not the usual complaint route for a U.S. consumer. If you live in the UK or the complaint concerns an organization handled through the UK data protection system, use the ICO’s official complaint service and follow its current instructions.

A reference to GDPR or the ICO in a company’s notice doesn’t by itself create a U.S. claim or make the ICO the correct agency for a U.S. resident.

Common mistakes to avoid

If you received a breach notice today, save a copy first, change any reused password, contact your financial institution about suspicious activity, and then submit the fact-based complaint to the agency that matches the issue.