Short answer: There isn't one deadline for every privacy complaint. HIPAA complaints to HHS's Office for Civil Rights generally must be filed within 180 days after you knew or should have known about the violation. The FTC and COPPA don't give consumers one general filing window. The GDPR has no single European Union-wide cutoff for complaints to a data protection authority, although national procedures can matter. California's 30-day written notice is a pre-suit cure step for certain CCPA security-breach claims, not a general deadline for every privacy complaint.

Start by naming the clock

A privacy problem can involve several different deadlines. Identify what you're trying to do before you count days:

Situation Clock that usually matters What it means
HIPAA complaint Generally 180 days after you knew or should have known of the violation File with HHS OCR or explain why you need a waiver
GDPR complaint No single EU-wide cutoff; national procedure may apply Complain promptly to the appropriate supervisory authority
GDPR rights request One month, with a possible two-month extension for complex requests This is the organization's response clock
CCPA consumer request Generally 45 days for a request to know, delete, or correct information This is the business's response period, not your complaint deadline
CCPA private action Written notice and a 30-day cure period for certain security-breach claims This is a pre-suit step, not a general CCPA complaint deadline
FTC or COPPA report No single consumer filing window Report promptly, but the agency decides whether to act
State privacy complaint Varies by state and claim Separate the business's response deadline from a regulator or lawsuit deadline

One incident may justify both an agency complaint and a private claim. Filing with a regulator doesn't automatically preserve, extend, or pause the time limit for a lawsuit.

HIPAA complaints: generally 180 days

Under 45 C.F.R. § 160.306, a HIPAA complaint generally must be filed within 180 days after you knew or should have known about the alleged violation. HHS OCR may waive that period for good cause, but a waiver isn't automatic.

HIPAA applies to covered entities and business associates, including many health plans, health care providers, clearinghouses, and service providers working for them. It doesn't cover every company that handles health-related information.

How to file with HHS OCR

  1. Check whether HIPAA may apply. Identify the provider, health plan, clearinghouse, or business associate involved.
  2. Record when you discovered the problem. Use the date you knew, or reasonably should have known, about the conduct.
  3. Gather focused evidence. Keep the entity's name, request dates, denial letters, emails, screenshots, and a short description of what happened.
  4. Submit the complaint promptly. Don't wait indefinitely for the organization to respond.
  5. Explain any delay. If more than 180 days have passed, give the exact dates, explain the reason, and ask OCR for a good-cause waiver.

Include only the health information needed to explain the complaint. An OCR complaint is an agency process; it doesn't automatically create a damages claim or extend a separate deadline for going to court.

California: separate the request, complaint, and lawsuit

The California Consumer Privacy Act has different procedures for consumer requests, regulatory reports, and private lawsuits. A missing privacy-policy disclosure, ignored opt-out, or mishandled consumer request doesn't automatically give you a private right to sue.

If you made a CCPA request

For requests to know, delete, or correct personal information, a business generally has 45 days to respond. A permitted extension may be available when reasonably necessary, but the business should explain the extension.

Save:

The 45-day period is mainly the business's response clock. It isn't automatically a 45-day deadline for you to report the business or file a lawsuit.

If you want to report a CCPA issue

Use the current California privacy regulator or consumer complaint route that fits the issue. The California Attorney General's CCPA guidance describes the law and available consumer rights.

Don't apply the CCPA's private-action notice rule to every privacy complaint. The private right of action is limited to certain security breaches involving specified personal information. Before bringing one of those claims, the statute requires written notice identifying the alleged CCPA violations and gives the business 30 days to respond in writing that it has cured the problem and that further violations won't occur.

That 30-day period is:

California also restricts a business from asking you to opt back in to the sale or sharing of your personal information for at least 12 months after you opt out. That is a business-conduct rule, not a deadline for filing a complaint.

GDPR: one month belongs to the organization

The GDPR generally requires an organization to respond to many data-rights requests without undue delay and within one month. For a complex request or multiple requests, it may extend the response period by up to two additional months. It should notify you within the first month and explain the reason.

That one-month period is the organization's response deadline. It isn't a universal deadline for filing a complaint.

If you believe an organization mishandled your personal data, you can complain to a supervisory authority. The European Commission's information for individuals says you may contact the authority in the country where you live, work, or where the alleged infringement occurred.

A practical GDPR sequence

  1. Send the organization a clear written request or complaint when doing so is safe and useful.
  2. Record when the organization received it and mark the one-month response date.
  3. Save the privacy policy, notices, consent screens, and relevant account messages. Policies can change after a dispute starts.
  4. File with the appropriate supervisory authority if the response is inadequate or the issue needs regulatory review.
  5. Check the authority's local procedure, especially if the complaint is late or you may seek compensation in court.

The GDPR's 72-hour breach-notification rule is a different clock. It generally concerns a controller notifying its supervisory authority after becoming aware of a qualifying personal-data breach. It isn't a 72-hour deadline for an affected individual to complain.

A supervisory-authority complaint and a compensation claim are separate routes. If you may seek money through court, check the applicable national limitation period instead of relying on the complaint process.

FTC and COPPA reports

The Federal Trade Commission doesn't operate under one general consumer deadline for privacy reports. The applicable law and the FTC's enforcement role vary by issue. A report may help the agency identify a broader pattern, but it doesn't promise an individual refund, damages award, or investigation.

COPPA applies to certain online services directed to children under 13 or that knowingly collect personal information from children. The FTC's COPPA FAQ explains factors used to assess whether a service is child-directed and what notice and parental-consent duties may apply.

If you report a suspected COPPA or FTC privacy problem:

A report to the FTC isn't the same as filing a private lawsuit, and it doesn't necessarily preserve a separate claim under state law, a consumer-protection statute, or a breach statute.

State privacy laws use different clocks

U.S. state privacy laws don't share one complaint deadline. They differ in coverage thresholds, definitions, enforcement powers, cure periods, and private-action rules.

Before relying on a state deadline, identify:

  1. Which state law may apply to your residence, the business, or the conduct
  2. Whether the business is covered
  3. Whether consumers can sue under that law
  4. Whether written notice must come before a regulator complaint or lawsuit
  5. Whether the business receives a cure period
  6. The limitation period for any court claim

A 45-day period often refers to how long a business has to answer a consumer request. It shouldn't automatically be treated as a 45-day deadline to contact an attorney general or file in court.

California's CCPA notice rule doesn't automatically apply to Kentucky, Indiana, Rhode Island, or another state's privacy law. State enforcement and private litigation can also follow different procedures. Read the current state attorney general instructions and statute, particularly when the conduct crossed state lines.

UK, Canada, Brazil, and Australia

There is no worldwide privacy-complaint deadline. The UK GDPR, Canada's PIPEDA, Brazil's LGPD, and Australia's privacy framework have different regulators and procedures.

A company's global privacy policy doesn't determine which legal deadline applies. Start with:

Use the relevant country's official regulator. Don't import the GDPR's 72-hour breach-notice rule or California's 30-day cure process into another jurisdiction without checking its own law.

Build the filing record

Whether you're contacting a regulator or considering a lawsuit, make a simple date sheet first:

  1. Record the event date, discovery date, date you contacted the company, and any response deadline.
  2. Label the possible route: HIPAA complaint, CCPA request, GDPR complaint, FTC report, state complaint, or court claim.
  3. Save the privacy-policy version as a PDF or screenshot and note when you saved it.
  4. Write a short timeline in date order. Separate what you know from what you suspect.
  5. Attach focused evidence such as emails, request confirmations, account notices, and relevant screenshots.
  6. Remove passwords, full payment details, complete medical records, and other unnecessary sensitive information.
  7. Submit before the earliest plausible deadline and keep the confirmation number and a copy of everything sent.
  8. Track the agency and the business separately. An agency acknowledgment or investigation timetable doesn't necessarily change a court limitation period.

If the deadline may have passed

A late complaint may still be worth submitting, but acceptance isn't guaranteed.

Don't wait for an agency to decide whether it has jurisdiction before checking a possible lawsuit deadline. The two processes can run at the same time.

Frequently asked questions

Is the GDPR 72-hour rule my deadline to complain?

No. It generally concerns a controller's notification to a supervisory authority after a qualifying breach. An individual's complaint procedure is different.

Does the CCPA require a 30-day wait for every complaint?

No. The written notice and 30-day cure process concerns certain CCPA private security-breach claims. It isn't a universal waiting period or filing deadline for regulator complaints.

Does filing with the FTC or HHS OCR preserve my lawsuit?

Not necessarily. Agency complaints and civil claims can have separate limitation periods and procedural requirements.

What should I do if I don't know which law applies?

Save the policy and evidence, write down when you discovered the problem, and contact the organization in writing if that is safe and useful. Then review the relevant regulator's current procedure. If money damages or a court filing may be involved, record the discovery date and have a qualified professional verify the applicable limitation period promptly.

This is general consumer information, not legal advice.