If a company says your personal information was exposed, you can report how it handled the incident to a regulator. That filing is not an identity-theft report, a billing dispute, or a lawsuit.
For most U.S. consumers, the useful order is simple: lock down reused passwords and financial accounts, save the notice, ask the company for facts about your data, then send a short complaint to the agency that matches the problem. A complaint can feed enforcement. It will not, by itself, freeze your credit, reverse a charge, or pay you.
Choose the right next step
| Your main concern | Start with | Important limit |
|---|---|---|
| Someone may misuse your information | Change passwords, turn on multifactor authentication, contact your bank or card issuer, and consider a credit freeze | A regulator complaint will not stop an unauthorized transaction |
| The company gave a misleading notice or used poor security | The Federal Trade Commission or your state attorney general | Reporting conduct does not guarantee an individual remedy |
| A California business may have violated your privacy rights | California Privacy Protection Agency | The agency does not act as your attorney |
| Medical information may have been mishandled | The organization's privacy contact or HHS Office for Civil Rights, if HIPAA applies | HIPAA does not cover every company that holds health-related information |
| You want money for losses | The company's claims process, a settlement administrator, or advice about a possible legal claim | Deadlines and eligibility are separate from a regulator complaint |
What a data breach complaint covers
A data breach complaint is a written report that an organization may have exposed, used, disclosed, or protected personal information improperly. The information can include a Social Security number, account credentials, financial details, medical information, or a mix of identifying details.
Typical issues include:
- The company never explained which information was involved.
- The notice was delayed, incomplete, or misleading.
- A reasonable privacy or security request went unanswered.
- Poor safeguards, an error, or unauthorized access exposed your data.
- The organization kept using or sharing information in a way you believe violated applicable law.
You do not have to prove a legal violation before you file. Say what you know, flag what you don't, and attach reliable evidence. The agency decides whether the conduct falls within its authority.
What to do before filing
1. Verify the notice
Don't click links or call numbers in an unexpected breach email until you've checked that it is genuine. Use the phone number on your account statement, or type the organization's official website into your browser yourself.
Ask, in writing if you can:
- When did the incident happen, and when was it discovered?
- What categories of information were involved?
- Was your information accessed or downloaded, or only treated as potentially exposed?
- Was the information encrypted or otherwise protected?
- What has the organization done to contain the incident?
- Who handles follow-up questions?
- Is there a reimbursement, monitoring, or claims process, and what are its terms?
A line that "some customer information may have been involved" may not tell you whether your record was affected. Ask for clarification.
2. Protect accounts and credit
Change any password you reused on the affected account, starting with email. Use a different password for every service and turn on multifactor authentication where it is available. Review active sessions, recovery addresses, forwarding rules, and recent activity.
If Social Security or other identity information was exposed, consider a credit freeze. The FTC's guidance on credit freezes and fraud alerts explains how to contact Equifax, Experian, and TransUnion. A freeze is free and stays in place until you ask the bureaus to lift it. A fraud alert is another option, but it does not replace checking your accounts and credit reports.
See unauthorized payments? Contact the bank, card issuer, or other provider right away. That fraud or billing-dispute process has its own rules and deadlines. A data breach complaint does not replace it.
The FTC also points consumers to IdentityTheft.gov/databreach and to its post-breach consumer advice.
3. Build an evidence file
Keep copies of:
- The original breach notice, including its date and how it arrived
- Emails, letters, texts, screenshots, and account alerts
- Call notes with the date, department, and representative
- The types of data that may have been involved
- Unauthorized accounts, transactions, fees, or other measurable losses
- Your requests to the company and its replies
- Any police, identity-theft, or bank report numbers
Leave original files unchanged when you can. Redact extra sensitive details before you upload anything. Don't put a full Social Security number, password, security code, or complete bank account number in an ordinary email.
4. Contact the company when it helps
U.S. law does not give every consumer a universal duty to contact the company first. Still, a written request is useful when you need facts, a correction, account protection, or claims information.
Send a short note to the privacy, security, or customer-support contact named in the notice. Give enough information to locate your account, and no more sensitive data than the company's secure process requires.
The FTC's data breach response guide is written for organizations, not consumers. It tells businesses to mobilize a response team, use forensic experts when appropriate, consult legal counsel, and describe clearly what is known about the compromise. Those points can shape your questions. They do not create a private right to compensation.
Where to report a data breach in the U.S.
Federal Trade Commission
Use ReportFraud.gov when the incident involves a scam, fraud, an illegal business practice, or a potentially deceptive statement about how the company handled your information.
An FTC report can help the agency spot patterns and set enforcement priorities. It is not a private case file. The FTC does not promise to investigate your individual complaint, recover your money, or send you a status update.
If someone is already using your information, report the identity theft separately and contact the affected bank, card issuer, or account provider. Do both when they fit: the payment provider handles the account problem, and the FTC report creates a record of the broader conduct.
Your state attorney general
A state attorney general's consumer-protection office may be the better route when a company appears to have missed state privacy, security, or breach-notification rules. Search for your state's official attorney general complaint page rather than a third-party form.
State rules differ. The relevant state can depend on where you live, which business was affected, what data was involved, and where the conduct occurred. State agencies can route complaints, request information, or take enforcement action. They generally do not act as your personal lawyer.
California Privacy Protection Agency
California residents can use the California Privacy Protection Agency complaint form for a possible violation of California consumer privacy law. The official CCPA complaints page explains that complaints may help the agency monitor compliance or inform enforcement.
The CCPA applies only when its coverage rules are met. An old revenue-only description is not enough to decide whether a business is covered, and not every breach is a CCPA violation.
The agency states that it does not represent individual consumers or act as their attorney. It also warns that information you submit may be used or disclosed to enforce the law. Read the form's privacy information before you attach detailed medical, financial, or identity documents.
HHS Office for Civil Rights
If a hospital, health plan, medical provider, or vendor handling protected health information appears to be covered by HIPAA, look at the HHS Office for Civil Rights complaint process. Use the official HHS instructions to check whether the organization is a covered entity or business associate, and whether the issue fits HIPAA's privacy, security, or breach-notification rules.
HIPAA does not automatically cover every health app, fitness service, employer, data broker, or technology company that stores health-related information. The company may still have duties under state law or its own privacy policy.
Include the organization's name, relevant dates, the type of information involved, the notice you received, and your correspondence. Follow the current OCR filing instructions instead of a deadline copied from an old article.
Other account and sector routes
Use the organization's own privacy or security contact for a government account, school record, employment system, or other service with a specialized complaint path. If a bank or payment account is involved, report unauthorized activity through that institution's official fraud channel.
A privacy-regulator complaint and a law-enforcement report serve different purposes. If you believe a crime is in progress, contact the relevant law-enforcement agency as well as the affected provider.
Data breach complaint template
Adapt this for a company, regulator, or state agency. Keep it factual and cut details the recipient does not need.
Subject: Data breach or privacy complaint about [company]
I am a resident of [state]. On [date], I received a notice from [company] or learned that my information may have been involved in an incident.
Known facts: [State what happened, when you learned about it, and the information categories identified in the notice.]
My concern: [Explain the missing information, misleading statement, unresolved privacy request, unauthorized use, or other conduct.]
Steps already taken: [List account changes, calls, written requests, fraud reports, and the company's responses.]
I ask that you review whether [company] complied with the applicable privacy, security, or breach-notification requirements. Please confirm receipt and tell me whether additional information is needed.
Attachments: [List the notice, correspondence, screenshots, and loss records. Redact unnecessary account numbers and government identifiers.]
[Name] [Safe contact information] [Case or account reference, if appropriate]
Don't pad the complaint by pasting every email. A dated timeline and a few clear attachments are easier to review than a dump of files.
What happens after you file
Save the confirmation number, submitted form, and attachments. A regulator may acknowledge or route the complaint, ask for more information, send it to another agency, combine it with other reports, open an inquiry, seek changes, or take no further action.
Closing a complaint without telling you the company broke the law does not prove the company acted properly. An open inquiry does not prove liability either.
Keep working directly with your bank, card issuer, or account provider on any fraud. If the company later announces a settlement or reimbursement program, read that program's eligibility rules and deadline on their own terms. An FTC, state, California, or HIPAA complaint does not enroll you automatically.
Deadlines, the GDPR 72-hour rule, and compensation
There is no single U.S. deadline for every consumer data breach complaint. Organization notification deadlines vary by state and sector. A regulator's complaint process may have its own filing window. A court claim or payment dispute can have still another clock.
The often-cited GDPR 72-hour rule is not a general U.S. consumer deadline. In qualifying circumstances, it concerns an organization's notice to a European supervisory authority after the organization becomes aware of a breach. It does not give a U.S. consumer 72 hours to complain, and it does not apply to every U.S. incident.
Money recovery usually needs a separate path. Keep records of unauthorized transactions, fees, replacement costs, lost wages, and other losses, but don't assume every expense is recoverable. A regulator's fine or enforcement order does not automatically create a payment to each complainant. A settlement claim, direct reimbursement request, or civil claim will have its own eligibility rules and time limits.
If you suffered substantial financial loss, identity theft, or sensitive-data exposure, consider getting advice about the law in your state before a claim deadline expires. That is not legal advice from this page; it is a reminder that complaint routes and money claims are not the same process.
Common questions
Do I have to contact the company first?
Not always. Contacting the company can clarify what happened and create a paper trail. Don't delay an urgent fraud report, or a filing with a time limit, while you wait for a reply.
Should I file with the FTC or my state?
Use the FTC for fraud, scams, and potentially deceptive business conduct. Consider your state attorney general for state privacy, security, or notification concerns. You can report to both when they address different parts of the problem.
Will a complaint get me compensation?
Not by itself. A complaint may contribute to enforcement. Compensation normally comes through the company, a specific settlement, a payment-dispute process, or a separate legal claim.
Can I file anonymously?
Don't assume that you can. Complaint forms may ask for contact information, and the CPPA warns that submitted personal information may be used or disclosed for enforcement. Use a safe email address, and ask the agency about confidentiality before you share sensitive details.
What if I don't know exactly what data was exposed?
Say so. Attach the notice, list the unanswered questions, and ask the company or regulator to determine whether your information was involved. Don't guess, and don't say data was stolen when the notice only says it may have been accessible.
Save the breach notice today, change reused passwords, freeze your credit if identity data was involved, then file through the route that matches the conduct.