Quick answer
File a privacy complaint when you can point to a specific concern about how a company collected, used, shared, retained, or protected your personal information. Save the relevant policy before it changes, gather a short record of what happened, contact the company's privacy team, and use the regulator that covers the business and conduct if the response is missing or unsatisfactory.
The route depends on where you live and what kind of information is involved:
- In the United States, the possible routes include a state privacy regulator or attorney general, the Federal Trade Commission (FTC), or the HHS Office for Civil Rights (OCR) when HIPAA applies.
- In the UK, people generally contact the organization first and then the Information Commissioner's Office (ICO).
- In the EU, complaints usually go to the data protection authority with jurisdiction over the processing.
A privacy policy is evidence of what a company said it would do. It isn't, by itself, a universal law. The controlling rule might instead be a state privacy statute, a sector rule such as HIPAA, a consent requirement, a contract, or a rule against deceptive business practices.
First decide what kind of complaint you have
"Privacy complaint" can mean several different things. Choosing the right label helps the company or regulator send your submission to the right process.
| What you want | Likely process | What to request |
|---|---|---|
| Find out what information a company has about you | Privacy rights request | Access to your information and details about its use |
| Remove, correct, or stop certain uses of your data | Privacy rights request or opt-out request | Deletion, correction, sale or sharing opt-out, or another available right |
| Challenge collection, tracking, disclosure, retention, or security | Privacy complaint | An investigation, explanation, and corrective action |
| Report misleading privacy promises | Consumer protection complaint | Review of potentially deceptive or unfair conduct |
| Report misuse of protected health information | HIPAA complaint, if HIPAA applies | Review by the organization and, when appropriate, HHS OCR |
A rights request asks the company to carry out a particular right. A complaint asks someone to examine conduct. They can be submitted at the same time, but keep them separate. A company may use a different form, identity-verification process, and deadline for a rights request.
What may justify a privacy complaint?
The strongest complaints identify a concrete mismatch between the company's notice, what you observed, and the rule that may apply. Examples include:
- The privacy notice says information won't be shared for a particular purpose, but the company appears to share it for unrelated advertising.
- Tracking or cookies appear to run before you make a consent choice in a situation where consent is required.
- The company gives no clear explanation of how long it keeps information or who receives it.
- You can't find a reasonable way to exercise a privacy right described in the company's notice.
- A business sends personal information to the wrong person or exposes it through poor security.
- The company ignores a specific privacy complaint or sends a response that doesn't address the facts.
These are reasons to ask for an investigation, not automatic proof of a legal violation. The notice may have changed, another policy may apply to your account, or an exception may cover the conduct. Save the wording, page address, and date before relying on it.
Build your record before contacting the company
A reviewer should be able to understand the problem without sorting through a long email chain. Start with a short chronology:
- Record what happened. Note the date, time, website or app, account involved, and the action you observed.
- Save the relevant policy. Keep a PDF or screenshot with the page address and date. Include its version or effective date if shown.
- Capture proof of the conduct. Save consent banners, account settings, emails, notices, disclosures, or other relevant screens. For a tracking issue, write down the choice you made and what happened afterward.
- Keep every response. Preserve your original complaint, automated confirmation, replies, and case number.
- Describe the effect. Say whether the issue caused unwanted marketing, account risk, exposure of sensitive information, financial loss, or another identifiable concern.
- Identify the business. Record its legal name, website, app, country, and any parent company named in the privacy notice.
Redact unnecessary account numbers, medical details, passwords, government identification numbers, and other people's information. A complete medical record or a folder of unrelated messages usually adds risk without adding useful proof.
Contact the organization first when practical
Look for the privacy notice, privacy choices page, data protection officer, designated rights-request form, or official privacy email address. Customer support can sometimes route the issue, but a privacy team is more likely to understand questions about data use.
Keep the first message focused. Include:
- What happened and when
- The wording in the privacy notice that concerns you
- Why the conduct appears inconsistent or unclear
- The information or account involved
- The correction, explanation, or other response you want
Ask the company to confirm receipt, explain the practice, preserve relevant records, and tell you how to escalate the matter. Put any access, deletion, correction, or opt-out request in a separate, clearly labeled section and use the company's required process.
Contacting the business first isn't a universal requirement for every U.S. complaint. It is often the quickest way to fix an account error, and some regulators may ask what the company said in response. If contacting the business could create a safety problem, use a safer channel and check the regulator's instructions.
Sample privacy complaint letter
Use the template as a starting point. Replace the brackets and remove requests that don't fit your situation.
Subject: Privacy complaint about [specific practice]
Dear [privacy team or official contact],
I am submitting a complaint about [collection, use, sharing, retention, tracking, security, or other practice].
On [date], I observed [describe exactly what happened]. This occurred at [website, app, account area, or other location]. The information involved was [brief description].
The privacy notice I viewed on [date] states: "[short quotation]." The relevant page or document is [link, title, or saved copy].
Please:
1. Confirm that you received this complaint;
2. Explain what information was involved, why it was used, and who received it, if applicable;
3. Explain the retention period and the steps taken to investigate;
4. Correct the practice or provide another appropriate remedy; and
5. Tell me how to escalate the matter if I disagree with your response.
I have attached redacted screenshots and a chronology. Any access, deletion, correction, or opt-out request is listed separately.
Please identify the person or team handling this complaint and provide the applicable response timeframe.
Sincerely,
[Name or preferred contact method]
[Account reference, if needed]
Don't cite the GDPR, CCPA, or HIPAA just to make the letter sound formal. Name a law only after checking that it covers your location, the business, and the type of information involved.
Where U.S. consumers can report privacy problems
There isn't one U.S. privacy office for every situation. Match the complaint to the conduct and the business.
| Problem | Possible route | Main limit |
|---|---|---|
| A company appears to make misleading privacy promises or use data in a deceptive way | The FTC or your state attorney general, after contacting the company when practical | An agency complaint doesn't guarantee an investigation or personal payment |
| A state privacy right is denied | The company's designated rights channel, followed by the relevant state privacy regulator or attorney general | Eligibility, covered businesses, rights, and deadlines vary by state |
| A California business ignores a CCPA or CPRA issue | The business's privacy-rights process and California's current privacy enforcement authority | A rights request is different from a general complaint, and remedies vary |
| Protected health information may have been mishandled | The covered entity or business associate, followed by HHS OCR when HIPAA applies | HIPAA doesn't cover every health app, employer, wellness service, or data broker |
| A sector-specific business is involved | The company and the regulator responsible for that sector | Financial, education, children's, and communications rules have different coverage |
The FTC is generally a better fit for suspected unfair or deceptive conduct than for an ordinary customer-service dispute. A complaint can help an agency identify a broader pattern, but the FTC doesn't act as your private lawyer.
Before filing over a state privacy issue, check whether you qualify as a covered resident and whether the business falls within the law. State laws differ on the rights available, the businesses covered, and the complaint process. Don't copy a "30-day" deadline from an online template and assume it applies to every California or other state privacy request.
UK and EU complaints
UK complaints to the ICO
For a UK data protection issue, the UK government's data protection complaint guidance says to contact the organization that holds your information. The ICO can investigate potential misuse of personal data.
You can then use the ICO guidance on making a data protection complaint. The guidance says the organization has 30 days to acknowledge a data protection complaint. The period starts on the day after the organization receives it. When the last day falls on a weekend or public holiday, the organization has until the next working day.
That is an acknowledgment period, not a promise that the complaint will be resolved within 30 days. The ICO guidance also says this timing doesn't apply to a request to exercise a privacy right, even though an organization might acknowledge that request in practice.
Keep your original message and the organization's response. The ICO may need them to understand what you raised and how the organization handled it.
EU complaints to a data protection authority
For an EU complaint, use the data protection authority with jurisdiction over the organization or the relevant processing. Check that authority's current filing instructions before sending anything. It may ask for your communications with the business, copies of the privacy notice, and information showing where you live or where the conduct occurred.
The UK ICO is a separate regulator. A global company's UK presence doesn't, by itself, make the ICO the right authority for an EU complaint.
HIPAA complaints
HIPAA applies to covered health care providers, health plans, health care clearinghouses, and their business associates. It doesn't automatically apply to every health, fitness, genealogy, or wellness app.
Start with the organization if you can do so safely. When the issue involves protected health information and the organization is covered, review the HHS Office for Civil Rights complaint information.
OCR generally requires a HIPAA complaint to be filed within 180 days of when you knew, or reasonably should have known, about the incident. An extension may be available in some circumstances, so check the current OCR instructions rather than waiting.
Include the covered entity's name, the relevant dates, the type of information involved, what was disclosed or denied, and supporting documents. A complaint without contact information may be harder for OCR to verify or investigate because it can't ask follow-up questions or request additional records.
Can you file anonymously?
Sometimes. The answer depends on the organization or regulator receiving the complaint.
- Company complaint: A business may accept an anonymous report, but it may not be able to investigate an account-specific issue or tell you the result.
- U.S. regulator: Some agencies accept tips or complaints without full contact information. Check the current form; a no-contact submission can be harder to act on.
- UK or EU regulator: Follow the authority's instructions. A safe contact method may make it easier to clarify dates and facts.
- HIPAA complaint: Ask about confidentiality instead of assuming that an anonymous submission will receive follow-up.
If retaliation or personal safety is a concern, provide only the contact information needed for the investigation and ask for confidentiality where the process allows it. An alternate email address may help, but don't include identifying details that aren't necessary.
What happens after you file?
The company or regulator may first check whether the complaint is complete and within its jurisdiction. It can then ask for dates, identity verification, a policy copy, or the company's response. The reviewer may contact the business, compare the notice with the practice, refer the issue to another authority, or close the matter without further action.
Possible results include an explanation, corrected information, deletion or restriction where a right applies, changes to a privacy notice or process, a referral, or enforcement action. There is no universal U.S. deadline for resolving a general privacy complaint. The ICO's 30-day period described above concerns acknowledgment, not completion.
A fine, settlement, or corrective order usually benefits the public or changes the business process rather than paying the individual who complained. Compensation may require a separate legal claim, private settlement, or another remedy allowed by the applicable law.
If the company or regulator rejects your complaint
A rejection may mean that the wrong process was used, the evidence was too general, the entity isn't covered, or the matter is outside the agency's authority. It doesn't necessarily resolve whether the conduct was acceptable.
Before escalating, check the following:
- Ask for the reason for closure in writing.
- Confirm whether you filed a complaint when you should have filed a rights request, or the other way around.
- Add missing dates, policy versions, screenshots, or the company's response.
- Confirm the business's legal name and the regulator's jurisdiction.
- Follow any review, appeal, or court instructions in the decision.
- Keep copies of every submission and deadline.
If your account or identity is at immediate risk, change the password, turn on multifactor authentication, revoke unfamiliar sessions, and contact your financial institution about suspected fraud. Those steps address the immediate risk; they don't replace a privacy complaint.
Common questions
Is a confusing privacy policy enough to file a complaint?
It can justify asking for clarification or regulatory review, particularly when important data uses are hidden or hard to understand. Confusing wording alone doesn't prove that the company broke a specific law. Explain what a reasonable reader would understand and what the company actually did.
Do I have to contact the company first?
Not always in the United States, although it is usually practical. UK guidance tells people to contact the organization before approaching the ICO. Other regulators have their own instructions, so keep proof of your earlier contact and check the relevant filing process.
Does the 30-day period mean my complaint must be resolved?
No. The ICO period is for acknowledging a UK data protection complaint. It isn't a 30-day resolution guarantee, and it doesn't automatically apply to U.S. complaints or privacy rights requests.
Will filing a complaint get me money?
Not necessarily. A complaint may lead to an explanation, correction, process change, deletion where applicable, referral, or enforcement. Compensation depends on a separate legal or settlement process.
What is the strongest evidence?
Usually, it's a dated copy of the privacy notice, a short timeline, screenshots showing the conduct, your consent or account settings, and the company's written response. Specific, redacted evidence is more useful than a large collection of unrelated files.
Save the current policy first, then write a five-line chronology. Send a focused complaint to the company's official privacy contact and use the regulator route that matches your jurisdiction and the type of information involved.