If a company collects, uses, or shares personal information contrary to its privacy notice, ignores a valid privacy choice, or makes a misleading promise, you may have grounds for a complaint. A confusing policy alone doesn't prove that a law was broken.
The useful question is narrower: what did the company promise, what actually happened, and which law or privacy choice applies? The checklist below is for U.S. consumers and is general information, not legal advice.
Privacy policy violation checklist
- Identify the business. Record its legal name, website or app, parent company if listed, and any third parties named in the notice.
- Save the policy version. Capture the privacy policy, cookie notice, terms, consent banner, and relevant settings. Keep the URL, date, and time.
- Build a timeline. Note when you opened the account, gave or withdrew consent, changed a setting, made a rights request, or noticed the suspected problem.
- Describe the information involved. List categories such as account details, location, identifiers, financial information, health information, children's data, biometrics, or communications.
- Compare the promise with the conduct. Quote the relevant policy language and describe the practice that appears inconsistent with it.
- Test the privacy controls. Record whether an opt-out link, deletion tool, consent choice, app permission, or browser signal worked as described.
- Make a rights request if one applies. Access, deletion, correction, and opt-out requests are separate from a regulator complaint. Save the confirmation.
- Contact the company in writing. Use the privacy or support address in the notice and ask specific questions.
- Choose the complaint route. Consider the FTC, your state consumer-protection agency, California privacy authorities, or HHS OCR, depending on the facts.
- Secure the account and track the matter. Change reused passwords, revoke unnecessary app access, enable multifactor authentication, and save case numbers.
Don't describe the conduct as illegal unless you can explain the specific mismatch. A short, factual account is more useful than a broad accusation.
What may support a privacy complaint?
A complaint may be worth pursuing when the evidence shows one of these problems:
- A meaningful gap between the notice and the practice. For example, the company says it doesn't share information for advertising, but credible evidence suggests that it does.
- A misleading consent or privacy choice. Preselected options, confusing buttons, or an opt-out process that doesn't work may matter when assessing whether a choice was meaningful.
- Missing or unclear disclosures. Depending on the applicable law, a notice may need to describe information categories, purposes, disclosures, retention, or consumer rights.
- A failure to honor a valid request or choice. This could include ignoring an applicable deletion request, refusing a lawful opt-out, or continuing a practice after consent was withdrawn.
- Improper handling of regulated information. Health records, substance-use-disorder records, children's information, and financial data may be subject to different rules.
Some signs are useful leads but don't prove a violation on their own:
- A third-party cookie or tracking request can show that information may have been transmitted. It doesn't automatically prove a legal sale or a breach of the company's notice.
- Targeted advertising alone doesn't establish that the company broke its policy.
- A refusal to delete information may be allowed by an exception, a retention obligation, or an identity-verification problem.
- A data breach doesn't automatically establish a HIPAA or state privacy violation.
Put the evidence in order
A compact evidence file is easier for a company or agency to review. Include:
- Screenshots or a saved copy of each relevant policy version
- The exact page address and capture date
- Account emails, notices, consent records, and privacy-setting changes
- A chronology of events
- The categories of information involved
- Evidence of tracking, unexpected messages, disclosures, or account activity
- Copies of your requests and the company's replies
- The business's legal name and privacy contact information
Keep the original files. Make a separate redacted copy for sharing. Remove passwords, full payment-card numbers, Social Security numbers, unnecessary medical details, and other people's information. Don't bypass security controls or access another person's account to obtain proof.
A browser tool or privacy extension can help you observe network activity. Treat its results as supporting evidence, not as a legal conclusion.
Contact the company first when it's safe and useful
A written complaint gives the company a chance to explain the practice and creates a record for a regulator. It may also reveal that a setting failed, an old policy was displayed, or the company misunderstood your request.
Ask questions that the company can answer:
- What information was collected?
- Why was it collected?
- Which companies or service providers received it?
- Which policy applied on the date in question?
- What retention period applies?
- Can the company stop the processing, honor an opt-out, or address a valid rights request?
You can adapt this message:
Subject: Privacy concern about [company or product]
I am writing about a possible mismatch between your privacy policy and your data practices. The policy at [policy URL], viewed on [date], states: "[short quotation]."
On [date], I observed: [specific facts]. The information involved may include [categories of information]. I have attached [short list of evidence].
Please explain the purpose of this processing, the recipients of the information, the policy version that applied, and the steps you will take to address the concern. If applicable, please treat this as a request to [access, delete, correct, or opt out] under the privacy law that applies to me.
Please confirm receipt and respond in writing.
Don't send more personal information than the company needs to locate your account or process the request.
Where U.S. consumers can report privacy problems
| Situation | Possible route | Important limit |
|---|---|---|
| Misleading privacy promises, unfair data practices, or a business practice affecting many consumers | ReportFraud.gov | An FTC report isn't a guaranteed individual investigation, refund, or deletion order. |
| A California consumer-rights, opt-out, or CCPA/CPRA concern | Review the California Attorney General's CCPA information and follow its current complaint instructions | The CCPA applies only when its scope and exemptions are met. Its private lawsuit remedy isn't a general claim for every policy mismatch. |
| A suspected HIPAA violation involving a covered entity or business associate | Use the HHS Office for Civil Rights complaint portal | Many health, fitness, and wellness apps aren't covered by HIPAA. Confirm that the entity is regulated. |
| A state-specific privacy, consumer-protection, or breach issue | Find the consumer-protection or attorney general page for your state | Filing requirements and available remedies vary by state. |
| Information about children under 13 or a child-directed service | Report the facts through the FTC route and identify the children's privacy issue | COPPA coverage depends on the service, the operator's knowledge, the audience, and the information collected. |
A global company may use one privacy policy for several countries, but that policy doesn't decide which law applies. Your location, the company's activities, and the type of information can change the analysis.
California CCPA and CPRA checklist
The California Consumer Privacy Act gives qualifying California consumers more control over personal information. The CPRA amendments took effect on January 1, 2023, but the business's scope, exemptions, and request-verification rules still matter.
If you're raising a California concern:
- Confirm that you're a California resident and check whether the business appears to fall within the law.
- Save the policy and any "Do Not Sell or Share My Personal Information" controls.
- Record whether the business honored a browser-based Global Privacy Control signal where applicable.
- Keep proof of any access, deletion, correction, or opt-out request.
- Save the company's response, refusal, verification request, or failure to respond.
- Check whether an exemption or legal retention requirement explains the result.
The California Attorney General's information says a business must wait at least 12 months before asking you to opt back in to the sale or sharing of your personal information after you opt out.
The CCPA's 30-day written-notice rule is narrower than many summaries suggest. For a covered private action, a consumer must identify the specific CCPA provisions allegedly violated and give the business an opportunity to cure and provide a written statement. That rule isn't a universal prerequisite for submitting a complaint to a regulator, and it doesn't create a general right to sue over every privacy-policy concern.
FTC complaints and children's privacy
The FTC may be a route when a company makes deceptive privacy claims, uses unfair practices, or mishandles children's information. Describe what happened in plain language and attach only relevant evidence.
For a children's privacy complaint, include:
- The child's age or the service's child-directed features
- What information was collected
- How notice or consent was presented
- Whether a parent tried to revoke consent or request deletion
- The dates, account details, and company response
The FTC finalized changes to its Children's Online Privacy Protection Rule in 2025. Its announcement addresses limits on retaining children's information and greater transparency for FTC-approved safe-harbor programs. The final rule becomes effective 60 days after publication in the Federal Register. Use the announcement as a starting point, then check the current rule and compliance dates.
COPPA isn't a general privacy law for all adults or all teenagers. A child using an app doesn't, by itself, establish that the operator is covered.
HIPAA and Part 2 complaints
Send a complaint to HHS OCR when the facts involve a HIPAA-covered health plan, health care provider, clearinghouse, or business associate. Include the entity's name, what happened, when it happened, the information involved, and relevant correspondence.
OCR also handles complaints about the confidentiality of substance-use-disorder patient records under 42 CFR Part 2 when the program or entity is subject to that rule. The OCR complaint portal provides the current filing process.
A medical, fitness, or mental-health app may collect sensitive information without being a HIPAA-covered entity. If HIPAA doesn't apply, consider the company's promises, state privacy law, and the appropriate consumer-protection agency instead.
Can you file a privacy complaint anonymously?
Sometimes, but don't assume that every agency or form accepts anonymous submissions. Without contact information, an agency may have less ability to verify the facts, ask follow-up questions, or tell you what happened.
Anonymous and confidential aren't the same:
- Anonymous means you don't identify yourself to the agency.
- Confidential means you provide your identity but ask the agency to limit disclosure.
A company may still infer who complained from an account number, incident date, or unusual transaction. If retaliation or personal safety is a concern, read the portal's instructions before filing and avoid unnecessary identifying details. A named complaint with a confidentiality request may be easier to investigate, but confidentiality isn't an absolute guarantee.
What happens after filing?
Save the confirmation page, case number, and submitted documents. If the agency offers a way to update an existing report, use it instead of sending repeated copies.
An agency may close a report, refer it, request more information, or use it with other complaints to identify a pattern. Filing doesn't guarantee a personal response, a deletion order, damages, or a public enforcement action.
If the company confirms unauthorized access, secure the account immediately. Change reused passwords, revoke connected applications, and monitor related accounts. If you suffered financial loss or identity theft, document that separately because a privacy complaint may not provide the remedy for those losses.
Frequently asked questions
Is a privacy-policy violation automatically illegal?
No. The policy, actual conduct, applicable law, consent records, and exceptions all matter. A mismatch is a reason to investigate and document the facts, not proof by itself.
Do I have to contact the company before filing?
There isn't one U.S. rule requiring that step for every complaint. Contacting the company can create a useful record and may resolve a setting or account problem. Don't delay if there's an active security risk or a deadline that may apply.
Can I use a CCPA complaint for a company anywhere in the United States?
Not automatically. The CCPA is California-specific and has business thresholds, exemptions, and qualifying-consumer requirements. If you live elsewhere, start with your state's privacy or consumer-protection rules.
Will the FTC or HHS delete my information?
Don't assume so. These agencies may investigate or seek broader corrective action, but their complaint systems aren't guaranteed individual data-deletion services.
What if I live outside the United States?
Use the data-protection authority serving your country or region and follow its current procedure. U.S. concepts such as the CCPA's 30-day pre-suit notice and Global Privacy Control rules shouldn't be treated as universal.
Before you submit, put the policy URL and capture date, timeline, company response, and numbered evidence in one folder. Redact the copy you upload, keep the originals, and save the confirmation number.