A privacy-policy complaint works when you can show what the company promised, what it did instead, and who can review it. Save the notice as you saw it, quote the mismatch, write the privacy team, and then pick a regulator that covers your location and the kind of data involved.

The United States does not have one complaint form for every privacy dispute. The Federal Trade Commission (FTC) generally addresses unfair or deceptive business practices. State agencies and attorneys general may handle state privacy-law issues. Children's, health, financial, and biometric information can bring in additional rules.

Privacy policy complaint examples

Match your situation to the evidence and the first step, then write from there.

Situation Evidence to collect Likely first step
The policy says the company does not sell or share data, but you have evidence of disclosure Policy copy, recipient information, ad or partner records, dates Contact the privacy team, then consider a state privacy regulator or the FTC
A company ignored an opt-out or privacy-control signal Opt-out confirmation, screenshots, timestamps, account email, browser settings Repeat the request in writing and keep the confirmation
An access, deletion, or correction request was ignored Original request, identity-verification messages, response or lack of response Send a focused rights request, then use the applicable state or national regulator
A consent banner or notice did not explain a new use of data Screenshots of the notice, consent choices, policy version, description of the new use Ask the company to explain the purpose and legal basis, if applicable
A breach appears inconsistent with the company's security statements Breach notice, account alerts, suspicious activity, relevant policy language Secure the account, preserve the notice, and report the issue to the appropriate authority

You don't need to prove the entire case. The recipient needs enough specific information to verify what happened.

What makes the complaint useful?

Pin down four facts before you send anything:

  1. What did the company promise? Quote the relevant sentence from the privacy notice or consent screen.
  2. What happened instead? Give dates, account details, recipients, or other verifiable facts.
  3. What right, promise, or harm is involved? Say whether the issue is access, deletion, correction, opt-out, consent, transparency, or a data breach.
  4. What should happen next? Ask for an explanation, a correction, deletion, an honored opt-out, or regulatory review.

A privacy policy is evidence of what a business told you. A mismatch does not automatically prove that a law was broken. Policies often include exceptions, separate product notices, and third-party terms. An advertising tracker, for example, does not automatically mean the company legally "sold" your information. Identify what data was collected, who received it, and which legal definition may apply.

Public cases that illustrate common complaint issues

Settlements can help you describe a pattern. They are not a legal test for your own facts.

Don't copy a settlement amount into your complaint or claim that a company "definitely violated" a law. Describe the facts and let the agency decide whether the law applies.

Privacy complaint templates

Copy one of these, replace the brackets, and attach the dated evidence.

Template for contacting a company

This version fits a misleading privacy statement, an unexplained disclosure, an ignored opt-out, or another policy concern.

Subject: Privacy complaint about [company] - [short description]

Hello [privacy team or company contact],

I am a [customer, account holder, app user, or website visitor] located in [state or country].

On [date], I reviewed [privacy policy URL, app notice, or consent screen]. It stated: "[short, exact quote]."

On [date], I observed or learned that [describe what happened]. The affected service or account was [identify it without including a password or full account number].

I attempted to [opt out, request deletion, request access, change a setting, or contact support] on [date] through [method]. The result was [describe the response, confirmation, or lack of response].

Please explain what information was collected or shared, the purpose of the activity, and which third parties received it, if applicable. Please also [honor my request, correct the information, stop the processing, or explain why the request cannot be completed].

I have attached [policy screenshot, confirmation email, relevant notice, and a short timeline]. Please confirm receipt and tell me whether you need additional identity verification.

Sincerely, [Name] [Preferred contact information]

Ask for a reasonable response date. Don't invent a universal U.S. deadline. The applicable time limit may depend on the state law and the type of request.

Template for a privacy-rights request

A rights request is different from a general complaint. Use this format only when you have a reasonable basis to believe the relevant law applies.

Subject: Privacy-rights request - [access, deletion, correction, or opt-out]

I am a resident of [state or country] and am requesting [access to my personal information, deletion, correction, or opt-out of sale or sharing] under [law, if known].

My account or identifying details are: [minimum information needed to locate the account].

Please tell me what verification you require and where I should provide it. Do not require me to send a password, full Social Security number, or unnecessary financial information by email.

This request concerns information associated with [email address, phone number, account, or order]. Please confirm receipt and provide the response required by the applicable law.

[Name] [Date] [Preferred contact information]

Save copies of the information before you ask for deletion. Erasing an account may also remove records that help prove what happened.

Template for a regulator complaint

Paste this into an FTC, state, or other regulator form, then adjust it to the agency's questions.

Subject: Complaint about [company] privacy practices

I am asking [agency name] to review [company]'s handling of my personal information.

The company's privacy notice at [URL] stated: "[quote]." On [date], [describe the conduct in factual terms]. The information involved was [type of information], and the affected product or account was [description].

I contacted the company on [date] using [email, form, or support channel]. It responded [summarize the response] or did not respond. I have attached [list the evidence].

I believe this may involve [state privacy law, a deceptive privacy statement, an opt-out failure, or another issue], although I understand that your office determines jurisdiction.

The impact was [privacy exposure, unwanted targeting, account risk, financial loss, or other specific harm]. I ask that the agency review the company's practices and advise whether any further information is needed.

[Name or preferred contact information]

Keep the regulator narrative short. A one-page timeline is usually more useful than a large folder of unsorted screenshots.

How to file a privacy complaint in the United States

1. Confirm the jurisdiction

Start with your residence, the company's location, and the type of information involved. A global privacy policy may apply across countries, but local rights and complaint routes can differ.

For California residents, the CCPA, as amended by the CPRA, gives many consumers rights to know, delete, correct, and opt out of certain sales or sharing. Coverage, exemptions, verification requirements, and deadlines still matter. The EFF's California privacy complaint guide offers a practical checklist; verify the current instructions of the California Privacy Protection Agency or California attorney general before filing.

2. Preserve the policy and your choices

Save the complete policy, its URL, and the date you viewed it. If the page changes, an older screenshot or downloaded copy can show what the company said when the conduct occurred.

Also keep consent banners, privacy dashboards, opt-out confirmations, emails, chat transcripts, support tickets, case numbers, breach notices, and a short chronology with one entry per date. Include the minimum account information needed to identify you and a description of the actual effect on you.

Redact passwords, authentication codes, full government identification numbers, and unrelated information. Submit sensitive documents only through an official, secure portal.

3. Contact the company in writing

Use the privacy contact listed in the notice, account settings, or official website. Label the message clearly as either a general privacy complaint or a rights request. If both are involved, use separate sections so the company can't treat a request for information as a general objection.

Contacting the company first can create a useful record, but U.S. law does not impose one universal requirement to do so before every regulator complaint. Follow the instructions of the agency you plan to use.

4. Choose the right complaint route

Don't use a Freedom of Information Act request to complain about a private company. FOIA and a Privacy Act request concern records held by a federal agency, not the company's records about you. The FTC explains the difference in its FOIA request instructions.

5. Submit a clean chronology

State what happened in date order: you saw the policy or consent notice; you used the service or made a privacy choice; you observed the collection, disclosure, or failure to respond; you contacted the company; the company responded, refused, or remained silent; you experienced a specific impact, if any.

Use "I observed," "the notice stated," and "the company did not respond" instead of "the company is a criminal." Factual wording makes the complaint easier to evaluate.

6. Track the submission

Save the confirmation page, case number, and submitted version. If the company later responds, send the regulator a concise update rather than opening multiple duplicate complaints.

If the issue involves an active account compromise, secure the account, change reused passwords, enable multifactor authentication, and follow any breach instructions. Those steps are separate from a privacy complaint.

What a privacy complaint can and cannot do

A regulator may investigate a pattern, request information, or pursue enforcement. It may not obtain a refund for you, provide a private damages award, or disclose every investigative step. Many agencies prioritize repeated conduct, significant harm, or large numbers of affected people.

You also can't assume that a complaint is anonymous. Some systems allow limited confidentiality or tips without full public disclosure, but a rights request may require identity verification. Ask the agency how it handles your information before submitting documents. An anonymous report can also make follow-up more difficult.

If a company ignores you, send one follow-up with the original request, proof of delivery, and a reasonable response date. Then file the regulator complaint with the silence documented. For substantial financial loss, identity theft, or a request for damages, a regulator complaint may need to be supplemented by a dispute with the relevant financial institution or advice from a qualified attorney.

If your complaint concerns the EU or UK

Don't apply U.S. complaint routes or deadlines to a GDPR or UK GDPR matter.

Under the GDPR, an individual can complain to a national data protection authority and may also have a court route. The European Data Protection Board's guidance explains those options. Start by contacting the organization when practical and keep proof of the exchange.

For the United Kingdom, the ICO's complaint guidance says to give the organization an opportunity to address the concern. The ICO also explains that an organization generally has 30 days to acknowledge a data-protection complaint, but that does not mean it must resolve the issue within 30 days. Its follow-up guidance says complaints should generally be raised within three months of the last meaningful contact.

The often-cited 72-hour GDPR breach notification rule concerns a controller's notification to a data protection authority. It is not a universal deadline for a consumer to file a complaint.

Common questions

Can I complain if I have not suffered financial harm?

Yes. A complaint can concern misleading notice, unwanted collection, an ignored privacy choice, or a failure to handle a rights request. Specific evidence still makes the report stronger.

Should I cite CCPA, GDPR, or the FTC Act?

Cite a law only when you have a reasonable connection to it. State your residence, the service involved, and the facts first. It's better to say "this may involve a state privacy law" than to cite the wrong statute.

What should I do if the privacy policy changed?

Save the current version and look for archived copies, emails, or screenshots from the relevant date. Explain which version was visible when you used the service. A later policy may not describe the company's earlier notice or conduct.

Screenshot or download the policy you see today, send the company template with your dates attached, and reuse that same packet if you later file with the FTC or a state office.