A privacy-policy complaint works when you can show what the company promised, what it did instead, and who can review it. Save the notice as you saw it, quote the mismatch, write the privacy team, and then pick a regulator that covers your location and the kind of data involved.
The United States does not have one complaint form for every privacy dispute. The Federal Trade Commission (FTC) generally addresses unfair or deceptive business practices. State agencies and attorneys general may handle state privacy-law issues. Children's, health, financial, and biometric information can bring in additional rules.
Privacy policy complaint examples
Match your situation to the evidence and the first step, then write from there.
| Situation | Evidence to collect | Likely first step |
|---|---|---|
| The policy says the company does not sell or share data, but you have evidence of disclosure | Policy copy, recipient information, ad or partner records, dates | Contact the privacy team, then consider a state privacy regulator or the FTC |
| A company ignored an opt-out or privacy-control signal | Opt-out confirmation, screenshots, timestamps, account email, browser settings | Repeat the request in writing and keep the confirmation |
| An access, deletion, or correction request was ignored | Original request, identity-verification messages, response or lack of response | Send a focused rights request, then use the applicable state or national regulator |
| A consent banner or notice did not explain a new use of data | Screenshots of the notice, consent choices, policy version, description of the new use | Ask the company to explain the purpose and legal basis, if applicable |
| A breach appears inconsistent with the company's security statements | Breach notice, account alerts, suspicious activity, relevant policy language | Secure the account, preserve the notice, and report the issue to the appropriate authority |
You don't need to prove the entire case. The recipient needs enough specific information to verify what happened.
What makes the complaint useful?
Pin down four facts before you send anything:
- What did the company promise? Quote the relevant sentence from the privacy notice or consent screen.
- What happened instead? Give dates, account details, recipients, or other verifiable facts.
- What right, promise, or harm is involved? Say whether the issue is access, deletion, correction, opt-out, consent, transparency, or a data breach.
- What should happen next? Ask for an explanation, a correction, deletion, an honored opt-out, or regulatory review.
A privacy policy is evidence of what a business told you. A mismatch does not automatically prove that a law was broken. Policies often include exceptions, separate product notices, and third-party terms. An advertising tracker, for example, does not automatically mean the company legally "sold" your information. Identify what data was collected, who received it, and which legal definition may apply.
Public cases that illustrate common complaint issues
Settlements can help you describe a pattern. They are not a legal test for your own facts.
- The California Sephora matter focused on allegations involving disclosures about selling or sharing personal information and failure to honor certain opt-out signals. A comparable complaint should show the company's statement, the choice you made, and the evidence that the choice was not honored.
- The FTC's Google and YouTube COPPA settlement involved child-directed content and the collection or use of children's personal information. COPPA is a child-privacy law, so it isn't the right citation for an ordinary adult account simply because the company has an online service.
Don't copy a settlement amount into your complaint or claim that a company "definitely violated" a law. Describe the facts and let the agency decide whether the law applies.
Privacy complaint templates
Copy one of these, replace the brackets, and attach the dated evidence.
Template for contacting a company
This version fits a misleading privacy statement, an unexplained disclosure, an ignored opt-out, or another policy concern.
Subject: Privacy complaint about [company] - [short description]
Hello [privacy team or company contact],
I am a [customer, account holder, app user, or website visitor] located in [state or country].
On [date], I reviewed [privacy policy URL, app notice, or consent screen]. It stated: "[short, exact quote]."
On [date], I observed or learned that [describe what happened]. The affected service or account was [identify it without including a password or full account number].
I attempted to [opt out, request deletion, request access, change a setting, or contact support] on [date] through [method]. The result was [describe the response, confirmation, or lack of response].
Please explain what information was collected or shared, the purpose of the activity, and which third parties received it, if applicable. Please also [honor my request, correct the information, stop the processing, or explain why the request cannot be completed].
I have attached [policy screenshot, confirmation email, relevant notice, and a short timeline]. Please confirm receipt and tell me whether you need additional identity verification.
Sincerely, [Name] [Preferred contact information]
Ask for a reasonable response date. Don't invent a universal U.S. deadline. The applicable time limit may depend on the state law and the type of request.
Template for a privacy-rights request
A rights request is different from a general complaint. Use this format only when you have a reasonable basis to believe the relevant law applies.
Subject: Privacy-rights request - [access, deletion, correction, or opt-out]
I am a resident of [state or country] and am requesting [access to my personal information, deletion, correction, or opt-out of sale or sharing] under [law, if known].
My account or identifying details are: [minimum information needed to locate the account].
Please tell me what verification you require and where I should provide it. Do not require me to send a password, full Social Security number, or unnecessary financial information by email.
This request concerns information associated with [email address, phone number, account, or order]. Please confirm receipt and provide the response required by the applicable law.
[Name] [Date] [Preferred contact information]
Save copies of the information before you ask for deletion. Erasing an account may also remove records that help prove what happened.
Template for a regulator complaint
Paste this into an FTC, state, or other regulator form, then adjust it to the agency's questions.
Subject: Complaint about [company] privacy practices
I am asking [agency name] to review [company]'s handling of my personal information.
The company's privacy notice at [URL] stated: "[quote]." On [date], [describe the conduct in factual terms]. The information involved was [type of information], and the affected product or account was [description].
I contacted the company on [date] using [email, form, or support channel]. It responded [summarize the response] or did not respond. I have attached [list the evidence].
I believe this may involve [state privacy law, a deceptive privacy statement, an opt-out failure, or another issue], although I understand that your office determines jurisdiction.
The impact was [privacy exposure, unwanted targeting, account risk, financial loss, or other specific harm]. I ask that the agency review the company's practices and advise whether any further information is needed.
[Name or preferred contact information]
Keep the regulator narrative short. A one-page timeline is usually more useful than a large folder of unsorted screenshots.
How to file a privacy complaint in the United States
1. Confirm the jurisdiction
Start with your residence, the company's location, and the type of information involved. A global privacy policy may apply across countries, but local rights and complaint routes can differ.
For California residents, the CCPA, as amended by the CPRA, gives many consumers rights to know, delete, correct, and opt out of certain sales or sharing. Coverage, exemptions, verification requirements, and deadlines still matter. The EFF's California privacy complaint guide offers a practical checklist; verify the current instructions of the California Privacy Protection Agency or California attorney general before filing.
2. Preserve the policy and your choices
Save the complete policy, its URL, and the date you viewed it. If the page changes, an older screenshot or downloaded copy can show what the company said when the conduct occurred.
Also keep consent banners, privacy dashboards, opt-out confirmations, emails, chat transcripts, support tickets, case numbers, breach notices, and a short chronology with one entry per date. Include the minimum account information needed to identify you and a description of the actual effect on you.
Redact passwords, authentication codes, full government identification numbers, and unrelated information. Submit sensitive documents only through an official, secure portal.
3. Contact the company in writing
Use the privacy contact listed in the notice, account settings, or official website. Label the message clearly as either a general privacy complaint or a rights request. If both are involved, use separate sections so the company can't treat a request for information as a general objection.
Contacting the company first can create a useful record, but U.S. law does not impose one universal requirement to do so before every regulator complaint. Follow the instructions of the agency you plan to use.
4. Choose the right complaint route
- FTC: Use the FTC's current consumer complaint channel for suspected deceptive or unfair privacy practices, particularly when a company's statements or conduct may affect many consumers. An FTC complaint is not a private lawsuit and does not guarantee individual compensation.
- State attorney general or consumer-protection office: Consider this route for state-law issues or conduct affecting residents of a particular state. Check whether the office accepts privacy complaints and whether it directs residents to another state agency.
- Specialized regulator: Health, financial, children's, employment, communications, and biometric data may involve additional rules or authorities. Identify the agency based on the data and service, rather than sending the same sensitive material everywhere.
- App store or platform: A platform can review an app, account, or listing under its own policies, but platform support is not a privacy regulator. A platform report does not replace a government complaint.
Don't use a Freedom of Information Act request to complain about a private company. FOIA and a Privacy Act request concern records held by a federal agency, not the company's records about you. The FTC explains the difference in its FOIA request instructions.
5. Submit a clean chronology
State what happened in date order: you saw the policy or consent notice; you used the service or made a privacy choice; you observed the collection, disclosure, or failure to respond; you contacted the company; the company responded, refused, or remained silent; you experienced a specific impact, if any.
Use "I observed," "the notice stated," and "the company did not respond" instead of "the company is a criminal." Factual wording makes the complaint easier to evaluate.
6. Track the submission
Save the confirmation page, case number, and submitted version. If the company later responds, send the regulator a concise update rather than opening multiple duplicate complaints.
If the issue involves an active account compromise, secure the account, change reused passwords, enable multifactor authentication, and follow any breach instructions. Those steps are separate from a privacy complaint.
What a privacy complaint can and cannot do
A regulator may investigate a pattern, request information, or pursue enforcement. It may not obtain a refund for you, provide a private damages award, or disclose every investigative step. Many agencies prioritize repeated conduct, significant harm, or large numbers of affected people.
You also can't assume that a complaint is anonymous. Some systems allow limited confidentiality or tips without full public disclosure, but a rights request may require identity verification. Ask the agency how it handles your information before submitting documents. An anonymous report can also make follow-up more difficult.
If a company ignores you, send one follow-up with the original request, proof of delivery, and a reasonable response date. Then file the regulator complaint with the silence documented. For substantial financial loss, identity theft, or a request for damages, a regulator complaint may need to be supplemented by a dispute with the relevant financial institution or advice from a qualified attorney.
If your complaint concerns the EU or UK
Don't apply U.S. complaint routes or deadlines to a GDPR or UK GDPR matter.
Under the GDPR, an individual can complain to a national data protection authority and may also have a court route. The European Data Protection Board's guidance explains those options. Start by contacting the organization when practical and keep proof of the exchange.
For the United Kingdom, the ICO's complaint guidance says to give the organization an opportunity to address the concern. The ICO also explains that an organization generally has 30 days to acknowledge a data-protection complaint, but that does not mean it must resolve the issue within 30 days. Its follow-up guidance says complaints should generally be raised within three months of the last meaningful contact.
The often-cited 72-hour GDPR breach notification rule concerns a controller's notification to a data protection authority. It is not a universal deadline for a consumer to file a complaint.
Common questions
Can I complain if I have not suffered financial harm?
Yes. A complaint can concern misleading notice, unwanted collection, an ignored privacy choice, or a failure to handle a rights request. Specific evidence still makes the report stronger.
Should I cite CCPA, GDPR, or the FTC Act?
Cite a law only when you have a reasonable connection to it. State your residence, the service involved, and the facts first. It's better to say "this may involve a state privacy law" than to cite the wrong statute.
What should I do if the privacy policy changed?
Save the current version and look for archived copies, emails, or screenshots from the relevant date. Explain which version was visible when you used the service. A later policy may not describe the company's earlier notice or conduct.
Screenshot or download the policy you see today, send the company template with your dates attached, and reuse that same packet if you later file with the FTC or a state office.