If a company uses your personal information in a way its privacy notice doesn't describe, record the exact mismatch first. Save the policy version and related screens, send a focused written request, and choose an escalation route based on the law and the harm involved.
A policy conflict can help show deceptive conduct, but it doesn't by itself guarantee money, deletion, or a private lawsuit. GDPR, the CCPA, and FTC enforcement work differently. The result may depend on your location, the business, the data involved, and the remedy you're seeking. This is general information, not legal advice.
Start by identifying the dispute
| Problem | What to check | First step |
|---|---|---|
| The company refuses access, deletion, or correction | Whether a privacy law covers you, and whether the company can verify your identity | Send a dated rights request |
| Your information appears to be sold or shared | The policy's definitions, advertising settings, and opt-out tools | Submit an opt-out and save the confirmation |
| The company's conduct conflicts with its policy | Older policy versions, emails, consent screens, and account settings | Preserve the evidence and consider a regulator complaint |
| A breach exposed your information | What data was involved, when the incident occurred, and what protection the company offers | Secure your accounts and assess identity-theft risk |
| The business ignores or delays your request | The date it received the request, the applicable deadline, and its stated reason | Send a written follow-up, then escalate |
A customer-service disagreement isn't automatically a privacy violation. A company might be allowed to retain information because an exception applies, it can't verify the request, or the right you invoked doesn't cover that record. Ask for the reason in writing before concluding that the company acted unlawfully.
Which rule applies?
U.S. consumers generally
There isn't one federal U.S. privacy deadline for every business. Your rights may come from a state privacy law, a sector-specific law, the company's own policy, or a promise that regulators could view as deceptive or unfair.
A privacy policy is usually a notice about collection, use, sharing, retention, and consumer choices. It isn't a universal promise that every record will be deleted on demand. Compare what the policy said with what happened, including the company's advertising settings, consent screens, emails, and other disclosures.
California residents and the CCPA
California's Consumer Privacy Act, as amended by the CPRA, covers California residents and businesses that meet the law's coverage requirements, subject to exemptions. It isn't a blanket rule for every company serving people anywhere in the United States.
Depending on the circumstances, a California resident may have the right to:
- Know the categories and specific details of personal information collected, used, sold, or shared.
- Delete personal information, subject to exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information.
- Limit certain uses of sensitive personal information.
- Receive equal treatment for exercising privacy rights.
The California Attorney General's CCPA guidance and the California Privacy Protection Agency's FAQ describe the rights and request process.
People covered by the GDPR
The GDPR isn't a general U.S. consumer law. It may apply when an organization's processing falls within the GDPR's territorial scope. A company mentioning GDPR in its policy doesn't, by itself, give every reader GDPR rights.
When the GDPR applies, individuals may have rights involving access, correction, erasure, restriction, objection, portability, and certain automated decisions. The organization generally must respond without undue delay and, in principle, within one month. The European Commission's information for individuals explains these rights and how to complain to a data protection authority.
The FTC
The Federal Trade Commission can pursue deceptive privacy or security promises and unfair practices. A company may attract scrutiny when its actual data-sharing practices materially conflict with clear statements in its policy.
An FTC report is an enforcement referral, not a private case manager. It doesn't guarantee that the company will give you records, delete information, pay compensation, or resolve your individual complaint.
Steps to take
1. Preserve the evidence
Before changing account settings or contacting the business, make a basic record of:
- The privacy policy and its effective date, if shown.
- Screenshots of relevant account, cookie, advertising, or consent settings.
- Emails, text messages, support chats, and case numbers.
- When you noticed the problem and what you did afterward.
- The personal information involved, without copying unnecessary sensitive details.
- Any breach notice, suspicious account activity, or unfamiliar disclosure.
Try to find the policy version that was in effect when the event occurred. A later version may not show what the company told you at the time.
2. Send one specific written request
Use the business's privacy portal or the privacy contact listed in its policy. A phone call can help with support, but written communication gives you a clearer record.
You can adapt this template:
On [date], I am requesting [access, deletion, correction, or opt-out] under [applicable law, if known]. The information or conduct at issue is [specific description]. Please confirm receipt, explain any identity-verification steps, and provide your response by the applicable deadline. If you deny any part of this request, please identify the reason, exception, or other basis for the denial and explain the available complaint or appeal process.
For a California request to know, ask for the categories of information collected, the purposes and sources, and the categories of recipients or businesses with which the information was sold or shared, as applicable. For deletion or correction, identify the account or records without sending more information than necessary.
For an opt-out request, say clearly that you don't want your personal information sold or shared where that right applies. A user-enabled Global Privacy Control signal may also serve as an opt-out for applicable California transactions. California businesses generally must wait at least 12 months before asking a consumer to opt back in.
Don't email a password, full Social Security number, or identity document unless the company's secure verification process specifically requires it. If verification is required, use the official portal and keep a copy of what you submitted.
3. Mark the relevant deadline
The timing depends on the request and jurisdiction:
| Situation | General timing or limit |
|---|---|
| California request to know, delete, or correct | The business generally must confirm receipt within 10 business days and respond within 45 calendar days, subject to an allowed extension |
| California opt-out | Don't assume the 45-day rights-request period applies; follow the business's opt-out process and applicable California requirements |
| GDPR request | Generally one month, with a possible extension for complex requests if the organization explains the delay |
| U.S. complaint outside a specific state or sector law | No single privacy deadline applies to every business |
| GDPR data breach | The commonly cited 72-hour period generally concerns a controller's notification to a supervisory authority after a qualifying breach, not a deadline for you to file a complaint |
| Before a qualifying CCPA private action | Limited circumstances apply, especially certain data-breach claims; California law may require written notice and a 30-day opportunity to cure before suit |
The CCPA's 30-day cure period isn't a universal 30-day response rule for privacy requests or complaints. It also isn't the same as a data-breach notification deadline.
4. Check the response
A response isn't necessarily complete just because it arrived on time. Look for whether the business:
- Answered every part of your request.
- Used the correct account or identity.
- Explained what information it retained and why.
- Confirmed an opt-out or correction.
- Gave a specific reason for refusing access or deletion.
- Identified an appeal, complaint, or regulator route.
If something is missing, send a short follow-up quoting the unanswered part of your original request and repeating the date the business received it. Ask it to identify the exact exception or process it relied on.
When the problem is a data breach
Treat a breach as a security problem first and a policy dispute second.
- Read the notice and record the incident date, discovery date, data categories, and contact details.
- Change exposed or reused passwords and turn on multifactor authentication.
- Contact banks, card issuers, and other account providers through a verified phone number or app.
- Consider a credit freeze or fraud alert if Social Security numbers, financial information, or identity documents may be involved.
- Monitor account statements and credit reports for unfamiliar activity.
- Keep the breach notice and any promised credit-monitoring terms.
The FTC's data breach response guide is written for businesses, but it identifies response basics such as preserving forensic evidence and clearly describing what is known. It can help you assess whether a notice gives the basic facts and remediation steps. It doesn't create a consumer deadline.
A credit freeze is free and can help prevent new accounts from being opened in your name. The FTC's guidance on credit freezes and fraud alerts explains how to contact Equifax, Experian, or TransUnion. A freeze won't correct existing fraud, so report unfamiliar accounts separately.
State breach-notification rules vary. Don't assume that the GDPR's regulator-notice timeline, a CCPA cure period, or the date on the company's email establishes whether the business met every notice obligation.
Escalate when the company doesn't fix the issue
Choose the route that matches the problem:
- California privacy rights or an opt-out problem: Review the CPPA and California Attorney General resources, then use the complaint or enforcement route identified in the agencies' current instructions.
- A GDPR rights request with no satisfactory response: Complain to the appropriate data protection authority. Keep the original request, identity-verification records, response, and follow-up.
- Misleading privacy or security statements in the United States: Report the conduct to the FTC and your state attorney general. Explain the exact statement, what the company actually did, and the evidence connecting the two.
- Identity theft or fraudulent accounts: Contact the affected financial institution, place a credit freeze or fraud alert, and use the FTC's identity-theft resources.
- Financial loss or highly sensitive exposure: Consider speaking with a licensed attorney or qualified legal-aid organization about deadlines and available remedies.
A regulator may investigate a pattern or enforce the law, but a complaint doesn't necessarily recover money or obtain a custom deletion order for one consumer.
Arbitration and terms of service
Read the terms of service separately from the privacy policy. An arbitration clause may affect how a private claim is brought, but it doesn't replace a privacy rights request or prevent you from contacting a regulator. Its effect and enforceability depend on the agreement and applicable law.
Don't add an arbitration demand to a basic access or deletion request unless you understand the reason. First create a clear record of the problem and the remedy you want.
Mistakes that can weaken your complaint
- Claiming GDPR rights without checking whether the GDPR covers the processing.
- Treating the word "GDPR" in a privacy policy as proof of coverage.
- Assuming every CCPA complaint has a 30-day cure period or a private right to sue.
- Sending repeated vague requests instead of one specific, dated request.
- Posting account numbers, identity documents, or breach notices publicly.
- Accepting credit monitoring without reading what it covers and how long it lasts.
- Assuming a regulator complaint guarantees compensation.
- Relying on the current policy when the dispute concerns an older version.
Frequently asked questions
Is a privacy policy contradiction enough to win a claim?
Not automatically. The conflict may be useful evidence, but the outcome depends on the wording, what the company did, the law that applies, proof of harm, and statutory exceptions.
Does the GDPR's 72-hour breach rule give consumers 72 hours to act?
No. The frequently cited 72-hour period generally concerns a controller notifying a supervisory authority about a qualifying breach. Secure your accounts immediately instead of waiting for that clock.
Can any U.S. consumer use the CCPA?
No. The CCPA is a California law with coverage requirements and exemptions. Other states may provide different rights and deadlines.
Can I sue after a CCPA violation?
Possibly, but the CCPA's private right of action is limited, particularly for certain data breaches involving specified personal information. California's written-notice and cure process may apply before a qualifying lawsuit. A regulator complaint isn't the same as a private claim.
What should I do first?
Save the relevant policy and account evidence, write down the dates, and send a focused request through the company's official privacy channel. Keep the confirmation, mark the deadline for your jurisdiction, and compare the response with each part of your request.