A privacy policy complaint is strongest when it connects a specific promise to a documented action. U.S. consumers don't have one federal privacy statute, and there's no universal complaint deadline that covers every case. Depending on what happened, the right destination may be the company, the Federal Trade Commission, a state regulator, or an agency that oversees a particular industry.
Save the privacy notice and related records first. Write to the company. Keep any formal data-rights request separate from the complaint itself, and escalate only through a route that matches the facts. This is general consumer information, not legal advice.
Quick answer: How to file a privacy policy complaint
- Name the problem. Is it a misleading privacy promise, an ignored access or deletion request, or a security incident? Those aren't the same filing.
- Save the evidence. Keep the policy version that was live when the conduct happened, plus screenshots, account notices, emails, and a dated timeline.
- Write the company. Use the privacy contact in the notice or the company's rights-request form. Point to the contradiction in plain language.
- Ask for a specific remedy. That might be an explanation, a correction, deletion, a stop on sharing, or written confirmation that a practice has ended.
- Follow up in writing. Keep the case number and the reply. Don't treat 30 days as a nationwide U.S. deadline.
- Escalate only if the facts fit. The FTC is the usual federal route for potentially unfair or deceptive practices. State-law issues go to a state regulator. EU or UK matters go to a data protection authority.
- Treat legal help as optional. A regulator complaint does not, by itself, create a private lawsuit or guarantee compensation.
What is a privacy policy complaint?
You're saying a business collected, used, disclosed, retained, or protected personal information in a way that conflicts with its privacy notice or with a law that actually applies.
Common examples:
- The notice says information will not be sold, but the company's conduct appears to share it for targeted advertising.
- Personal information is used for a major new purpose without a clear explanation of the change.
- A valid request to access, correct, delete, or stop certain uses is ignored.
- Privacy settings or consent choices don't match the stated practices.
- Information is kept longer than the notice appears to allow.
A mismatch is not automatically a legal violation. Notices often define terms and carve out service providers, affiliates, legal demands, fraud prevention, business transfers, and later policy changes. Check the exact wording, the version in force when the conduct happened, and any consent or account notice you received.
The notice also isn't automatically a contract. Whether it supports a private claim depends on the applicable law, the company's terms, and the facts.
Privacy policy complaint versus data breach
| Issue | What it usually concerns | First step |
|---|---|---|
| Privacy policy complaint | A mismatch between a company's promise and its collection, use, sharing, or retention of data | Save the policy and complain to the privacy team |
| Privacy-rights request | A request to access, correct, delete, or limit the use of your information | Use the company's designated rights-request channel |
| Data breach or security incident | Unauthorized access, loss, disclosure, or theft of information | Report the incident promptly and preserve security-related evidence |
One event can sit in more than one row. A security incident may also involve a misleading notice or an ignored deletion request. Describe each issue separately so the recipient can route it.
Check which rule controls your situation
What controls the file usually depends on where you live, where the company operates, what kind of information is involved, and the industry.
For a U.S. consumer, possible sources of protection include:
- Federal consumer-protection law. The FTC can address conduct that is potentially unfair or deceptive, including misleading privacy representations in appropriate cases.
- State privacy law. Rights and coverage differ by state. Some laws give rights to know, delete, correct, or opt out of certain data uses.
- Sector-specific rules. Health, financial, children's, employment, education, communications, and biometric information may carry extra requirements.
- Company policy and terms. These show what you were told. They may also list exceptions or allow future changes.
California residents should keep a general complaint separate from a formal CCPA or CPRA rights request. Covered consumers can have rights to know, delete, correct, and opt out of some selling or sharing, but eligibility and procedure depend on the business and the request. Don't treat a blanket 30-day cure period as a current rule for every CCPA complaint. Check the current California instructions for the specific right or violation. EFF's California privacy complaint guide explains the available routes.
Gather evidence before contacting the company
Businesses can change privacy policies, settings, and account screens. Capture what you saw before you file.
Build a small evidence file:
- The privacy policy URL, the date you viewed it, and a saved copy or screenshot
- The exact section or sentence that matters
- The date and a short description of the company's action
- Account notices, consent screens, privacy-setting screenshots, and emails
- Records of access, deletion, correction, or opt-out requests
- Names of representatives, call dates, and support ticket numbers
- Evidence of the data involved, such as an unexpected disclosure or account record
- A brief note on any financial, privacy, safety, or practical harm
A simple timeline is enough:
| Date | Event | Evidence |
|---|---|---|
| March 3 | Privacy notice said the company would not share data for a stated purpose | Policy screenshot |
| March 12 | A third party appeared to receive or use the information | Account notice or message |
| March 14 | Complaint sent to the privacy team | Email and case number |
Redact passwords, Social Security numbers, financial account numbers, health details, and other people's information. Send only what the recipient needs to identify and investigate the issue.
Explain the violation clearly
A useful complaint answers five questions:
- What did the company promise? Quote the exact language and identify the policy version.
- What happened instead? Give dates, actions, products, and accounts. Skip speculation.
- What information was involved? Describe the type of data without attaching extra copies.
- Why do the two things conflict? One or two sentences is enough.
- What outcome do you want? Ask for a realistic remedy and a written explanation.
Don't say a company "stole" your data unless you have a reliable basis for that claim. "The conduct appears inconsistent with Section 4.2 of the privacy notice" is more useful than a broad accusation.
Name a statute only when you can explain why it applies. A complaint that cites several unrelated laws is harder to evaluate.
Privacy policy complaint letter template
Subject: Privacy policy complaint regarding [company and issue]
Hello [privacy team, privacy officer, or customer support]:
I am [name], a [customer or account holder] identified by [account email, customer number, or other safe identifier]. I am writing to complain about a possible inconsistency between [company]'s privacy notice and its handling of my information.
- Policy promise: The [policy title] available at [link] on [date] states: "[short quotation]." The relevant section is [section number or heading].
- What happened: On [date], [describe the collection, use, disclosure, retention, or response to your request].
- Information involved: [Describe the type of information without attaching unnecessary sensitive data.]
- Why this appears inconsistent: [Explain the conflict in plain language.]
- Previous contact: I contacted [department] on [date] using [method]. The case number is [number], if applicable.
- Remedy requested: Please investigate, explain the practice and recipients involved, and [delete, correct, stop sharing, restore a privacy setting, or confirm another specific remedy] if available.
- Separate rights request: [If applicable, state clearly: "I am also requesting access to, correction of, or deletion of my personal information under the privacy law that applies to me."]
Please confirm receipt, identify the person or team handling this matter, and explain the expected response process. I have attached or listed the following evidence: [evidence list].
Sincerely,
[Name]
[Preferred contact method]
Use the company's published privacy contact when you can. A support ticket can still help, but label the message as a privacy complaint and ask support to route it to the privacy team.
What to do if the company does not resolve it
File a report with the FTC
The FTC may be relevant when a company's privacy statements or practices appear unfair or deceptive. Its privacy and security guidance explains how privacy failures can raise issues under Section 5 of the FTC Act.
You can submit information through ReportFraud.gov. Include:
- The company's legal or trading name and website
- The policy statement and its date
- A short timeline of what happened
- Copies or descriptions of your communications with the company
- The type of information involved
- Any concrete harm or risk
- Other people who may have experienced the same practice, if known
An FTC report is not a private lawsuit. The agency generally does not act as your personal lawyer, require a company to give you a refund through the complaint form, or guarantee that it will investigate your individual case. Reports can still help it spot patterns and decide where to put enforcement resources.
Contact your state regulator
Your state attorney general may accept consumer complaints about businesses operating in or serving residents of that state. Some states also have a dedicated privacy regulator. Use the official state website for eligibility, required documents, and the correct filing route.
Don't assume a state privacy law covers every company or every type of data. Coverage may depend on the business's size, revenue, data practices, industry, and your status as a resident or consumer.
A regulator complaint also does not automatically give you a right to sue. California's private-action provision, for example, is limited and generally centers on certain data-security breaches rather than every disagreement about a privacy notice.
Use the proper route for an EU or UK complaint
GDPR and UK privacy rules are separate from ordinary U.S. consumer-protection procedures. If you are in the EU or European Economic Area, you may be able to complain to the supervisory authority in your country. The European Data Protection Board's explanation of individual complaint and court options is a useful starting point.
A GDPR rights request generally has a one-month response period, with a possible extension for complex requests. That's a deadline for responding to the rights request, not a promise that a data protection authority will finish an investigation in one month.
In the UK, the ICO says an organization has 30 days to acknowledge a data protection complaint, starting the day after it receives it. If that period ends on a weekend or public holiday, acknowledgment is due the next working day. Acknowledgment is not the same as resolution. See the ICO guidance on making a data protection complaint.
If you are outside the United States, the EU, or the UK, use the privacy authority and deadlines for your own jurisdiction. A company's headquarters in another country does not, by itself, decide which complaint process applies.
Privacy complaint timelines
There is no single timeline for every privacy complaint.
| Situation | What to expect |
|---|---|
| Ordinary U.S. complaint to a company | No universal federal response deadline. Ask for acknowledgment and keep proof of delivery. |
| U.S. privacy-rights request | The applicable state or sector law may set a response procedure and deadline. Treat it separately from a general complaint. |
| FTC or state report | Processing and investigation times vary. The agency may not provide an individual resolution. |
| GDPR rights request | Generally one month, with possible extension for complexity. |
| UK data protection complaint | The organization has 30 days to acknowledge the complaint, not necessarily resolve it. |
A deadline you put in your letter is not automatically a legal deadline. If a time limit may affect a lawsuit, appeal, charge, account closure, or regulatory filing, verify it with the relevant authority or a qualified professional.
Possible outcomes and limits
A company may explain the practice, point to an exception in the policy, correct an account record, restore a privacy setting, or delete information when no legal or operational exception applies. It may also stop a particular use or sharing activity, deny the request because it can't verify your identity, retain information it is required to keep, or send you to a service provider, affiliate, or separate controller.
A regulator may request information, refer the matter, open an investigation, seek a settlement, or close the complaint. A penalty usually goes to the government or is imposed as part of an enforcement resolution. It is not automatically paid to the person who reported the issue.
The FTC's 2019 Facebook settlement, which included a $5 billion civil penalty, shows the scale a regulatory outcome can reach. It does not mean every consumer complaint produces a payment, or that an individual complainant caused the enforcement action.
Common mistakes to avoid
- Relying only on the company's current policy when the conduct happened under an older version
- Treating a general complaint as a formal access, deletion, or correction request
- Assuming a privacy-policy mismatch automatically proves a legal violation
- Sending complete identity documents or sensitive data through an unverified email address
- Filing with the FTC and expecting it to negotiate your personal dispute
- Invoking CCPA, GDPR, or another law without checking whether it covers your location and situation
- Ignoring a separate security-breach reporting or identity-protection need
- Waiting so long that account records, screenshots, or applicable filing periods become harder to establish
Frequently asked questions
Does breaking a privacy policy automatically violate the law?
No. The wording, policy version, exceptions, consent records, actual conduct, and applicable law all matter. A misleading or materially incomplete representation can be more significant than a minor wording difference.
Do I have to contact the company first?
There's no universal U.S. rule requiring that step for every complaint, but writing the company usually creates a clearer record and may resolve the issue faster. Some rights-request procedures also expect you to use the company's designated method.
Is there always a 30-day CCPA cure period?
No. Don't rely on a blanket 30-day rule. The relevant CCPA or CPRA provision, the type of request, and current California enforcement instructions determine what procedures and deadlines apply.
Will the FTC get my information back?
Not necessarily. The FTC accepts reports for enforcement and intelligence purposes. It does not guarantee that it will investigate your complaint, order a company to respond to you, or recover money for you.
Can I receive compensation?
Possibly, but only if an applicable law, contract, settlement, arbitration process, or court claim provides a remedy. A regulatory fine is not the same as compensation to an individual.
What should I do if the company ignores my complaint?
Send one concise follow-up with the original case number and a copy of your first message. If the issue involves a specific privacy right, use the formal rights-request channel. Then consider the FTC, your state regulator, or the relevant data protection authority, depending on the facts and your location.
Save the policy version you actually saw, write the company's privacy contact using the template above, and keep the case number. If you don't get a usable answer, file at ReportFraud.gov or with your state attorney general, and keep EU or UK issues on their own DPA track.