If a company collected, used, shared, or kept your personal information contrary to its privacy notice, save the notice and your evidence before you file. In the United States, the usual path is to contact the company's privacy team, then report the issue to the regulator that matches the conduct and jurisdiction.
A mismatch can support a complaint. It does not, by itself, prove the company broke the law. The privacy notice, consent screens, account settings, contracts, and the statute that actually applies all matter. GDPR, HIPAA, and COPPA apply only when their specific requirements are met.
Quick answer: 6 steps to file a privacy complaint
- Identify the conduct. Write down what happened, which information was involved, and when.
- Preserve the policy and evidence. Save the policy version, URL, screenshots, emails, settings, and relevant notices.
- Choose your goal. Decide whether you want access, deletion, correction, an opt-out, an explanation, or an investigation.
- Contact the company. Use the privacy contact or request method listed in its policy. Keep a copy of everything you send.
- File with the right regulator. Depending on the facts, that may be the FTC, a state attorney general, HHS OCR, the FTC's COPPA process, or an EU data protection authority.
- Track the complaint. Save the confirmation number, response dates, and any follow-up documents.
Don't put passwords, full payment-card numbers, Social Security numbers, or extra medical details in an email or complaint form.
Is this a privacy policy violation?
Look for a gap between what the company said and what it did:
- It shared information with a category of third party that its notice says it doesn't share with.
- An app kept tracking after you used a stated opt-out control.
- It ignored an access, deletion, correction, or opt-out request.
- It collected information for a purpose that wasn't disclosed clearly.
- It gave a misleading explanation after a security incident.
- A health provider, plan, or business associate disclosed protected health information without a permitted reason.
- A child-directed service collected information from a child without following applicable consent and notice rules.
The posted policy is not a guarantee that every practice is lawful or permanent. Companies can update notices, and another document may describe a practice in more detail. Save the version that was displayed when the conduct occurred, including its effective date.
Decide whether you need a request or a complaint
A privacy request asks the company to act on your information. A regulatory complaint asks an agency to review possible unlawful, unfair, or deceptive conduct.
| Your main goal | First route |
|---|---|
| See what information the company holds | Submit an access or "know" request |
| Delete or correct information | Submit a deletion or correction request |
| Stop certain sale, sharing, or marketing uses | Use the company's opt-out method |
| Challenge a misleading privacy statement | Contact the company, then consider the FTC or a state regulator |
| Report a health-information privacy issue | Contact the organization and consider HHS OCR |
| Report collection from a child under 13 | Contact the operator and consider the FTC |
| Report unauthorized access or a leak | Notify the company, protect your accounts, and report the incident through the appropriate channel |
You can use both routes. For example, submit a deletion request and, separately, report that the company repeatedly ignored similar requests.
Gather evidence before contacting the company
Regulators need specific facts, not a conclusion that a company "violated privacy." Build a short chronological record with:
- The company's name, website, app, and account identifier
- The privacy policy URL, effective date, and the relevant quoted language
- Screenshots of the policy, consent screen, privacy setting, opt-out confirmation, or error message
- The date, time, time zone, and device or app involved
- The type of information involved, such as an email address, location, browsing history, health information, or a child's information
- Emails, texts, support chats, letters, and notices from the company
- The date and method of any privacy request and the company's response
- Evidence of harm, such as targeted spam, account-takeover attempts, financial loss, or exposure of sensitive information
- The names of any third parties shown in the disclosure or notice, if known
Keep the original files and a separate redacted copy for sharing. Take out details the agency doesn't need. Don't try to get evidence by using another person's account or bypassing a security control.
Contact the company's privacy team
Use the method in the privacy policy. That may be a web form, a customer-support channel, a privacy email address, a mailing address, or a data protection officer for some organizations.
Keep the message factual and specific:
- Identify the account or transaction without oversharing sensitive information.
- Quote the relevant policy language.
- Describe what happened and when.
- State the action you want.
- Ask how the company will verify your identity, if verification is required.
- Request written confirmation and a reference number.
No universal U.S. rule requires you to contact a company before every privacy complaint. Doing so still gives the company a chance to fix the problem and creates a record an agency can use.
Privacy complaint letter template
Subject: Privacy concern about [product or account] - [date]
Hello [privacy team, privacy officer, or data protection officer],
I am writing about [brief description of the issue] involving account or reference number [number, if needed].
Your privacy policy dated [date] states: "[short quotation]."
On [date], [describe the event in factual terms]. The information involved appears to be [type of information]. I have attached [list of relevant documents].
Please [state the requested action, such as provide access, delete or correct the information, stop a stated use, investigate the disclosure, or explain the company's position]. Please confirm receipt, tell me whether additional identity verification is required, and provide a written response by [date], subject to any applicable legal deadline.
Please preserve records relevant to this issue while it is being reviewed.
Thank you, [Name] [Contact information]
Don't threaten a fine, cite a statute you haven't checked, or demand a specific amount of compensation unless you have a clear legal basis.
Choose the right U.S. complaint route
FTC complaints about deceptive privacy practices
The Federal Trade Commission is a common route when a business made false or misleading privacy or security promises, used information in a way that contradicted its representations, or engaged in unfair conduct.
Submit the report through the FTC complaint service. Include the company, the relevant policy statement, dates, and supporting documents. The FTC uses complaints to spot enforcement patterns. Filing does not guarantee an investigation, a response from the company, or money for you.
The FTC's consumer complaint information explains what happens when consumers report unfair or deceptive practices.
California privacy complaints
California residents may have rights under the California Consumer Privacy Act, as amended by the CPRA, when the business is covered by the law. Depending on the business and the request, those rights can include knowing what information is collected, deleting or correcting information, and opting out of certain sale or sharing practices.
Use the company's designated method for a consumer privacy request. If the business fails to follow applicable California requirements, review the California Attorney General's CCPA information and its complaint options.
A CCPA request is not the same as an enforcement complaint. A covered business generally has 45 days to respond to a verifiable request, with a possible 45-day extension when it gives the required notice. That response period does not automatically set the deadline for an enforcement complaint.
California law does not generally create a private lawsuit for every privacy-policy disagreement. Private claims are more limited and can depend on facts such as the type of security incident and the harm involved.
HIPAA complaints about health information
HIPAA applies to covered entities such as many health care providers and health plans, along with their business associates. It does not cover every health, fitness, or wellness app.
Possible HIPAA concerns include an impermissible disclosure of protected health information, failure to provide access to records, inadequate safeguards, or a missing or misleading Notice of Privacy Practices.
You may complain to the organization and file with the U.S. Department of Health and Human Services Office for Civil Rights through the HHS OCR complaint portal. Complaints generally must be filed within 180 days after you knew or should have known about the alleged violation. OCR may allow more time for good cause, but don't wait to ask for an extension.
Include the covered entity or business associate's name, the relevant dates, a clear description, and only the health information needed to explain the issue.
COPPA complaints involving children under 13
The Children's Online Privacy Protection Act applies to operators of child-directed websites and services, and to certain operators that know they are collecting personal information from children under 13.
A parent or guardian can first contact the operator and ask what information was collected, how it was used, and whether it can be deleted. You can also report the issue through the FTC complaint service. The FTC's COPPA frequently asked questions explain how the law considers whether a service is directed to children and what notice and consent rules may apply.
COPPA is not a general privacy law for everyone under 18. If the concern involves a teenager or a general-audience service, another federal or state rule may be more relevant.
GDPR complaints
The GDPR may apply to an organization outside Europe in some circumstances, such as when it offers goods or services to people in the European Economic Area or monitors their behavior there. A U.S. consumer shouldn't assume the GDPR applies merely because a company has a global privacy policy.
If the GDPR applies, you can usually complain to the data protection authority in the relevant EU or EEA country. Contacting the company first may help, but it isn't a universal precondition to filing. The European Data Protection Board FAQ provides background on national data protection authorities and complaint decisions.
A GDPR rights request and a complaint to a supervisory authority are separate. An individual-rights request generally has a one-month response period, subject to permitted extensions. An authority's investigation does not have one guaranteed completion time.
How to submit an effective regulator complaint
Use the agency's official form or portal, not a link from an unsolicited message or social-media post. Name the correct business, including its legal name if you know it, plus the product, website, or app.
Lead with a short timeline of dates and actions rather than an emotional description. Quote the relevant promise or notice and explain why the actual conduct appears inconsistent. Describe your contact with the company, including request dates, reference numbers, and responses. Attach organized evidence with descriptive filenames and skip duplicate files. State the outcome you want, such as correction, deletion, an explanation, or review of the practice. Then save the confirmation number and follow the agency's instructions for any follow-up.
A useful narrative might say:
On March 4, I used the company's listed deletion form. The confirmation number was 12345. The company's policy says it deletes account information after a verified request, but my April 2 response stated that the request was not received. I have attached the policy, confirmation, response, and a timeline. I am asking the agency to review whether the company followed its stated process and applicable law.
Privacy complaint timelines and possible outcomes
There is no single U.S. deadline or resolution period for every privacy complaint.
| Matter | Timing to watch |
|---|---|
| Company complaint | Follow the company's stated process; no universal 14-day response rule applies |
| CCPA access, deletion, or correction request | Generally 45 days, with a possible 45-day extension when properly noticed |
| HIPAA complaint | Generally file within 180 days after learning, or reasonably being expected to learn, of the violation |
| GDPR individual-rights request | Generally one month, subject to permitted extensions |
| FTC or state enforcement complaint | No guaranteed investigation or resolution date |
The company may explain, correct or delete information, change a setting, investigate an employee or vendor, or update its practices. A regulator may seek compliance or impose an enforcement remedy. Neither result is guaranteed.
Regulatory penalties usually go to the government, not to the person who complained. If you suffered significant financial loss, identity theft, discrimination, or exposure of highly sensitive information, consider advice from a qualified attorney or a consumer legal-aid organization. Whether you can sue depends on the applicable law, actual harm, contract terms, arbitration provisions, and filing deadlines.
If the issue is also a data breach
A data-breach complaint focuses on unauthorized access, loss, or disclosure. A privacy-policy complaint focuses on how the company described or handled information. One incident can involve both.
If your account may be exposed:
- Change the affected password and any reused password.
- Turn on multifactor authentication.
- Contact your bank or card issuer if financial information may be involved.
- Watch account statements and credit reports.
- Keep the breach notice and any support correspondence.
- Report suspected identity theft through the appropriate government identity-theft channel, in addition to a privacy complaint.
You are not responsible for making a regulator notification within the 72-hour GDPR breach-reporting window. That type of notification, where it applies, is generally an obligation of the organization to its supervisory authority.
Common mistakes to avoid
Sending a vague accusation wastes time. State what happened, when, and which information was involved, and pick the agency whose scope matches the facts: FTC, state, HIPAA, COPPA, or GDPR.
Don't treat a request as a complaint. Ask the company to access or delete data; report suspected unlawful conduct separately. Rely on the policy version and effective date connected to the event, not an older copy you found later.
Provide enough evidence without exposing passwords or full identity numbers. A complaint does not guarantee a refund, settlement, or individual damages. If an account is being abused right now, secure it and contact financial institutions immediately. Send private evidence through an official, secure channel instead of posting it publicly.
Frequently asked questions
Do I have to contact the company before filing?
Not always. There is no universal U.S. requirement for every privacy complaint, and GDPR complaints generally can go directly to a supervisory authority. Contacting the company first is often useful because it may resolve the issue and creates a documented record.
Is breaking a privacy policy automatically illegal?
No. It may be evidence of deceptive conduct or a failure to honor a legal privacy right, but the result depends on the wording, the company's actual practices, consent, applicable law, and the facts of the case.
Can the FTC get my money back?
The FTC can use complaints in investigations and enforcement actions, but it doesn't promise to resolve individual disputes or obtain payment for every complainant.
What if the company ignores my complaint?
Save proof of the unanswered message, confirm you used the method listed in the privacy policy, and file with the regulator that matches the conduct. Include your original request, the delivery or confirmation record, and the lack of response.
Save the privacy policy and a one-page timeline, then send a focused request through the company's listed privacy channel and keep the confirmation for any regulator filing.