A privacy policy complaint is strongest when it connects a specific promise to a documented action. U.S. consumers don't have one federal privacy statute, and there's no universal complaint deadline that covers every case. Depending on what happened, the right destination may be the company, the Federal Trade Commission, a state regulator, or an agency that oversees a particular industry.

Save the privacy notice and related records first. Write to the company. Keep any formal data-rights request separate from the complaint itself, and escalate only through a route that matches the facts. This is general consumer information, not legal advice.

Quick answer: How to file a privacy policy complaint

  1. Name the problem. Is it a misleading privacy promise, an ignored access or deletion request, or a security incident? Those aren't the same filing.
  2. Save the evidence. Keep the policy version that was live when the conduct happened, plus screenshots, account notices, emails, and a dated timeline.
  3. Write the company. Use the privacy contact in the notice or the company's rights-request form. Point to the contradiction in plain language.
  4. Ask for a specific remedy. That might be an explanation, a correction, deletion, a stop on sharing, or written confirmation that a practice has ended.
  5. Follow up in writing. Keep the case number and the reply. Don't treat 30 days as a nationwide U.S. deadline.
  6. Escalate only if the facts fit. The FTC is the usual federal route for potentially unfair or deceptive practices. State-law issues go to a state regulator. EU or UK matters go to a data protection authority.
  7. Treat legal help as optional. A regulator complaint does not, by itself, create a private lawsuit or guarantee compensation.

What is a privacy policy complaint?

You're saying a business collected, used, disclosed, retained, or protected personal information in a way that conflicts with its privacy notice or with a law that actually applies.

Common examples:

A mismatch is not automatically a legal violation. Notices often define terms and carve out service providers, affiliates, legal demands, fraud prevention, business transfers, and later policy changes. Check the exact wording, the version in force when the conduct happened, and any consent or account notice you received.

The notice also isn't automatically a contract. Whether it supports a private claim depends on the applicable law, the company's terms, and the facts.

Privacy policy complaint versus data breach

Issue What it usually concerns First step
Privacy policy complaint A mismatch between a company's promise and its collection, use, sharing, or retention of data Save the policy and complain to the privacy team
Privacy-rights request A request to access, correct, delete, or limit the use of your information Use the company's designated rights-request channel
Data breach or security incident Unauthorized access, loss, disclosure, or theft of information Report the incident promptly and preserve security-related evidence

One event can sit in more than one row. A security incident may also involve a misleading notice or an ignored deletion request. Describe each issue separately so the recipient can route it.

Check which rule controls your situation

What controls the file usually depends on where you live, where the company operates, what kind of information is involved, and the industry.

For a U.S. consumer, possible sources of protection include:

California residents should keep a general complaint separate from a formal CCPA or CPRA rights request. Covered consumers can have rights to know, delete, correct, and opt out of some selling or sharing, but eligibility and procedure depend on the business and the request. Don't treat a blanket 30-day cure period as a current rule for every CCPA complaint. Check the current California instructions for the specific right or violation. EFF's California privacy complaint guide explains the available routes.

Gather evidence before contacting the company

Businesses can change privacy policies, settings, and account screens. Capture what you saw before you file.

Build a small evidence file:

A simple timeline is enough:

Date Event Evidence
March 3 Privacy notice said the company would not share data for a stated purpose Policy screenshot
March 12 A third party appeared to receive or use the information Account notice or message
March 14 Complaint sent to the privacy team Email and case number

Redact passwords, Social Security numbers, financial account numbers, health details, and other people's information. Send only what the recipient needs to identify and investigate the issue.

Explain the violation clearly

A useful complaint answers five questions:

  1. What did the company promise? Quote the exact language and identify the policy version.
  2. What happened instead? Give dates, actions, products, and accounts. Skip speculation.
  3. What information was involved? Describe the type of data without attaching extra copies.
  4. Why do the two things conflict? One or two sentences is enough.
  5. What outcome do you want? Ask for a realistic remedy and a written explanation.

Don't say a company "stole" your data unless you have a reliable basis for that claim. "The conduct appears inconsistent with Section 4.2 of the privacy notice" is more useful than a broad accusation.

Name a statute only when you can explain why it applies. A complaint that cites several unrelated laws is harder to evaluate.

Privacy policy complaint letter template

Subject: Privacy policy complaint regarding [company and issue]

Hello [privacy team, privacy officer, or customer support]:

I am [name], a [customer or account holder] identified by [account email, customer number, or other safe identifier]. I am writing to complain about a possible inconsistency between [company]'s privacy notice and its handling of my information.

Please confirm receipt, identify the person or team handling this matter, and explain the expected response process. I have attached or listed the following evidence: [evidence list].

Sincerely,
[Name]
[Preferred contact method]

Use the company's published privacy contact when you can. A support ticket can still help, but label the message as a privacy complaint and ask support to route it to the privacy team.

What to do if the company does not resolve it

File a report with the FTC

The FTC may be relevant when a company's privacy statements or practices appear unfair or deceptive. Its privacy and security guidance explains how privacy failures can raise issues under Section 5 of the FTC Act.

You can submit information through ReportFraud.gov. Include:

An FTC report is not a private lawsuit. The agency generally does not act as your personal lawyer, require a company to give you a refund through the complaint form, or guarantee that it will investigate your individual case. Reports can still help it spot patterns and decide where to put enforcement resources.

Contact your state regulator

Your state attorney general may accept consumer complaints about businesses operating in or serving residents of that state. Some states also have a dedicated privacy regulator. Use the official state website for eligibility, required documents, and the correct filing route.

Don't assume a state privacy law covers every company or every type of data. Coverage may depend on the business's size, revenue, data practices, industry, and your status as a resident or consumer.

A regulator complaint also does not automatically give you a right to sue. California's private-action provision, for example, is limited and generally centers on certain data-security breaches rather than every disagreement about a privacy notice.

Use the proper route for an EU or UK complaint

GDPR and UK privacy rules are separate from ordinary U.S. consumer-protection procedures. If you are in the EU or European Economic Area, you may be able to complain to the supervisory authority in your country. The European Data Protection Board's explanation of individual complaint and court options is a useful starting point.

A GDPR rights request generally has a one-month response period, with a possible extension for complex requests. That's a deadline for responding to the rights request, not a promise that a data protection authority will finish an investigation in one month.

In the UK, the ICO says an organization has 30 days to acknowledge a data protection complaint, starting the day after it receives it. If that period ends on a weekend or public holiday, acknowledgment is due the next working day. Acknowledgment is not the same as resolution. See the ICO guidance on making a data protection complaint.

If you are outside the United States, the EU, or the UK, use the privacy authority and deadlines for your own jurisdiction. A company's headquarters in another country does not, by itself, decide which complaint process applies.

Privacy complaint timelines

There is no single timeline for every privacy complaint.

Situation What to expect
Ordinary U.S. complaint to a company No universal federal response deadline. Ask for acknowledgment and keep proof of delivery.
U.S. privacy-rights request The applicable state or sector law may set a response procedure and deadline. Treat it separately from a general complaint.
FTC or state report Processing and investigation times vary. The agency may not provide an individual resolution.
GDPR rights request Generally one month, with possible extension for complexity.
UK data protection complaint The organization has 30 days to acknowledge the complaint, not necessarily resolve it.

A deadline you put in your letter is not automatically a legal deadline. If a time limit may affect a lawsuit, appeal, charge, account closure, or regulatory filing, verify it with the relevant authority or a qualified professional.

Possible outcomes and limits

A company may explain the practice, point to an exception in the policy, correct an account record, restore a privacy setting, or delete information when no legal or operational exception applies. It may also stop a particular use or sharing activity, deny the request because it can't verify your identity, retain information it is required to keep, or send you to a service provider, affiliate, or separate controller.

A regulator may request information, refer the matter, open an investigation, seek a settlement, or close the complaint. A penalty usually goes to the government or is imposed as part of an enforcement resolution. It is not automatically paid to the person who reported the issue.

The FTC's 2019 Facebook settlement, which included a $5 billion civil penalty, shows the scale a regulatory outcome can reach. It does not mean every consumer complaint produces a payment, or that an individual complainant caused the enforcement action.

Common mistakes to avoid

Frequently asked questions

Does breaking a privacy policy automatically violate the law?

No. The wording, policy version, exceptions, consent records, actual conduct, and applicable law all matter. A misleading or materially incomplete representation can be more significant than a minor wording difference.

Do I have to contact the company first?

There's no universal U.S. rule requiring that step for every complaint, but writing the company usually creates a clearer record and may resolve the issue faster. Some rights-request procedures also expect you to use the company's designated method.

Is there always a 30-day CCPA cure period?

No. Don't rely on a blanket 30-day rule. The relevant CCPA or CPRA provision, the type of request, and current California enforcement instructions determine what procedures and deadlines apply.

Will the FTC get my information back?

Not necessarily. The FTC accepts reports for enforcement and intelligence purposes. It does not guarantee that it will investigate your complaint, order a company to respond to you, or recover money for you.

Can I receive compensation?

Possibly, but only if an applicable law, contract, settlement, arbitration process, or court claim provides a remedy. A regulatory fine is not the same as compensation to an individual.

What should I do if the company ignores my complaint?

Send one concise follow-up with the original case number and a copy of your first message. If the issue involves a specific privacy right, use the formal rights-request channel. Then consider the FTC, your state regulator, or the relevant data protection authority, depending on the facts and your location.

Save the policy version you actually saw, write the company's privacy contact using the template above, and keep the case number. If you don't get a usable answer, file at ReportFraud.gov or with your state attorney general, and keep EU or UK issues on their own DPA track.