If a company uses your personal information in a way its privacy notice doesn't describe, record the exact mismatch first. Save the policy version and related screens, send a focused written request, and choose an escalation route based on the law and the harm involved.

A policy conflict can help show deceptive conduct, but it doesn't by itself guarantee money, deletion, or a private lawsuit. GDPR, the CCPA, and FTC enforcement work differently. The result may depend on your location, the business, the data involved, and the remedy you're seeking. This is general information, not legal advice.

Start by identifying the dispute

Problem What to check First step
The company refuses access, deletion, or correction Whether a privacy law covers you, and whether the company can verify your identity Send a dated rights request
Your information appears to be sold or shared The policy's definitions, advertising settings, and opt-out tools Submit an opt-out and save the confirmation
The company's conduct conflicts with its policy Older policy versions, emails, consent screens, and account settings Preserve the evidence and consider a regulator complaint
A breach exposed your information What data was involved, when the incident occurred, and what protection the company offers Secure your accounts and assess identity-theft risk
The business ignores or delays your request The date it received the request, the applicable deadline, and its stated reason Send a written follow-up, then escalate

A customer-service disagreement isn't automatically a privacy violation. A company might be allowed to retain information because an exception applies, it can't verify the request, or the right you invoked doesn't cover that record. Ask for the reason in writing before concluding that the company acted unlawfully.

Which rule applies?

U.S. consumers generally

There isn't one federal U.S. privacy deadline for every business. Your rights may come from a state privacy law, a sector-specific law, the company's own policy, or a promise that regulators could view as deceptive or unfair.

A privacy policy is usually a notice about collection, use, sharing, retention, and consumer choices. It isn't a universal promise that every record will be deleted on demand. Compare what the policy said with what happened, including the company's advertising settings, consent screens, emails, and other disclosures.

California residents and the CCPA

California's Consumer Privacy Act, as amended by the CPRA, covers California residents and businesses that meet the law's coverage requirements, subject to exemptions. It isn't a blanket rule for every company serving people anywhere in the United States.

Depending on the circumstances, a California resident may have the right to:

The California Attorney General's CCPA guidance and the California Privacy Protection Agency's FAQ describe the rights and request process.

People covered by the GDPR

The GDPR isn't a general U.S. consumer law. It may apply when an organization's processing falls within the GDPR's territorial scope. A company mentioning GDPR in its policy doesn't, by itself, give every reader GDPR rights.

When the GDPR applies, individuals may have rights involving access, correction, erasure, restriction, objection, portability, and certain automated decisions. The organization generally must respond without undue delay and, in principle, within one month. The European Commission's information for individuals explains these rights and how to complain to a data protection authority.

The FTC

The Federal Trade Commission can pursue deceptive privacy or security promises and unfair practices. A company may attract scrutiny when its actual data-sharing practices materially conflict with clear statements in its policy.

An FTC report is an enforcement referral, not a private case manager. It doesn't guarantee that the company will give you records, delete information, pay compensation, or resolve your individual complaint.

Steps to take

1. Preserve the evidence

Before changing account settings or contacting the business, make a basic record of:

Try to find the policy version that was in effect when the event occurred. A later version may not show what the company told you at the time.

2. Send one specific written request

Use the business's privacy portal or the privacy contact listed in its policy. A phone call can help with support, but written communication gives you a clearer record.

You can adapt this template:

On [date], I am requesting [access, deletion, correction, or opt-out] under [applicable law, if known]. The information or conduct at issue is [specific description]. Please confirm receipt, explain any identity-verification steps, and provide your response by the applicable deadline. If you deny any part of this request, please identify the reason, exception, or other basis for the denial and explain the available complaint or appeal process.

For a California request to know, ask for the categories of information collected, the purposes and sources, and the categories of recipients or businesses with which the information was sold or shared, as applicable. For deletion or correction, identify the account or records without sending more information than necessary.

For an opt-out request, say clearly that you don't want your personal information sold or shared where that right applies. A user-enabled Global Privacy Control signal may also serve as an opt-out for applicable California transactions. California businesses generally must wait at least 12 months before asking a consumer to opt back in.

Don't email a password, full Social Security number, or identity document unless the company's secure verification process specifically requires it. If verification is required, use the official portal and keep a copy of what you submitted.

3. Mark the relevant deadline

The timing depends on the request and jurisdiction:

Situation General timing or limit
California request to know, delete, or correct The business generally must confirm receipt within 10 business days and respond within 45 calendar days, subject to an allowed extension
California opt-out Don't assume the 45-day rights-request period applies; follow the business's opt-out process and applicable California requirements
GDPR request Generally one month, with a possible extension for complex requests if the organization explains the delay
U.S. complaint outside a specific state or sector law No single privacy deadline applies to every business
GDPR data breach The commonly cited 72-hour period generally concerns a controller's notification to a supervisory authority after a qualifying breach, not a deadline for you to file a complaint
Before a qualifying CCPA private action Limited circumstances apply, especially certain data-breach claims; California law may require written notice and a 30-day opportunity to cure before suit

The CCPA's 30-day cure period isn't a universal 30-day response rule for privacy requests or complaints. It also isn't the same as a data-breach notification deadline.

4. Check the response

A response isn't necessarily complete just because it arrived on time. Look for whether the business:

If something is missing, send a short follow-up quoting the unanswered part of your original request and repeating the date the business received it. Ask it to identify the exact exception or process it relied on.

When the problem is a data breach

Treat a breach as a security problem first and a policy dispute second.

  1. Read the notice and record the incident date, discovery date, data categories, and contact details.
  2. Change exposed or reused passwords and turn on multifactor authentication.
  3. Contact banks, card issuers, and other account providers through a verified phone number or app.
  4. Consider a credit freeze or fraud alert if Social Security numbers, financial information, or identity documents may be involved.
  5. Monitor account statements and credit reports for unfamiliar activity.
  6. Keep the breach notice and any promised credit-monitoring terms.

The FTC's data breach response guide is written for businesses, but it identifies response basics such as preserving forensic evidence and clearly describing what is known. It can help you assess whether a notice gives the basic facts and remediation steps. It doesn't create a consumer deadline.

A credit freeze is free and can help prevent new accounts from being opened in your name. The FTC's guidance on credit freezes and fraud alerts explains how to contact Equifax, Experian, or TransUnion. A freeze won't correct existing fraud, so report unfamiliar accounts separately.

State breach-notification rules vary. Don't assume that the GDPR's regulator-notice timeline, a CCPA cure period, or the date on the company's email establishes whether the business met every notice obligation.

Escalate when the company doesn't fix the issue

Choose the route that matches the problem:

A regulator may investigate a pattern or enforce the law, but a complaint doesn't necessarily recover money or obtain a custom deletion order for one consumer.

Arbitration and terms of service

Read the terms of service separately from the privacy policy. An arbitration clause may affect how a private claim is brought, but it doesn't replace a privacy rights request or prevent you from contacting a regulator. Its effect and enforceability depend on the agreement and applicable law.

Don't add an arbitration demand to a basic access or deletion request unless you understand the reason. First create a clear record of the problem and the remedy you want.

Mistakes that can weaken your complaint

Frequently asked questions

Is a privacy policy contradiction enough to win a claim?

Not automatically. The conflict may be useful evidence, but the outcome depends on the wording, what the company did, the law that applies, proof of harm, and statutory exceptions.

Does the GDPR's 72-hour breach rule give consumers 72 hours to act?

No. The frequently cited 72-hour period generally concerns a controller notifying a supervisory authority about a qualifying breach. Secure your accounts immediately instead of waiting for that clock.

Can any U.S. consumer use the CCPA?

No. The CCPA is a California law with coverage requirements and exemptions. Other states may provide different rights and deadlines.

Can I sue after a CCPA violation?

Possibly, but the CCPA's private right of action is limited, particularly for certain data breaches involving specified personal information. California's written-notice and cure process may apply before a qualifying lawsuit. A regulator complaint isn't the same as a private claim.

What should I do first?

Save the relevant policy and account evidence, write down the dates, and send a focused request through the company's official privacy channel. Keep the confirmation, mark the deadline for your jurisdiction, and compare the response with each part of your request.