">

Start with the data, not the privacy badge

A privacy seal or certification badge doesn't tell you whether a service needs your precise location, shares your purchase history, or deletes an old account. Before giving sensitive information to a website, app, retailer, clinic, or subscription service, find out what it collects, why it needs it, who receives it, how long it keeps it, and what you can control.

U.S. privacy rights aren't uniform. Your state, the type of business, the information involved, the company's privacy notice and terms, and breach-notification rules can all change the answer. No single U.S. privacy law gives everyone the same set of rights.

The Federal Trade Commission's guide to protecting personal information is written for businesses, but its first questions work well for consumers: take stock of the data and trace how it moves.

Six questions to ask before sharing personal information

Question A useful answer Reason to pause
What does the business collect? Specific categories such as contact, payment, location, or account data A vague statement that it collects "any information available"
Why is it collected? Purposes connected to the feature or transaction you requested Broad language covering unrelated advertising or profiling
Who receives it? Named companies or understandable categories of service providers No explanation of affiliates, advertisers, or vendors
How long is it kept? A retention period or criteria for deciding when data is deleted "As long as necessary" with no further detail
What choices do you have? Instructions for access, correction, deletion, or marketing opt-out requests No privacy contact or request process
How does the business handle incidents? A security contact and a clear breach-notice process Security claims with no way to report a problem

A reason to pause isn't proof that a business broke the law. It tells you to ask a follow-up question, provide less information, or choose another service.

A privacy check for a new account

Start with every collection point

The registration form is only one source of information. Check mobile permissions, cookies, location services, loyalty programs, customer-support recordings, connected accounts, and uploaded documents.

Give extra scrutiny to Social Security numbers, financial and payment information, health information, precise location, biometric identifiers, and information about children. The FTC specifically tells businesses to identify and protect sensitive information. As a consumer, ask why each sensitive field is needed, what feature depends on it, and whether you can complete the transaction another way.

Read and save the privacy notice

Read the notice before creating the account, not after a problem arises. These sections usually answer the main questions:

Save a copy or screenshot and record the date you viewed it. Privacy wording can change, and a dated copy shows what the business disclosed when you signed up.

Mark required and optional information

A business may need a shipping address to deliver a product, but it may not need your birthday for the same order. An app may need location access for navigation, but not for basic account creation.

Don't fill in optional fields just because a form displays them. If sensitive information is mandatory, ask what part of the service depends on it and whether the business will also use it for marketing or profiling.

Trace the recipients

The recipient section is often where the practical answer is buried. Search the notice for terms such as "service providers," "affiliates," "advertising partners," "sale," "sharing," "analytics," and "targeted advertising."

A company may not sell a mailing list in the ordinary sense and may still share information with advertising or analytics partners. You probably won't be able to approve every vendor individually, but you should be able to understand the categories of recipients and why the sharing occurs.

Ask what closing the account actually does

Closing a login isn't necessarily the same as deleting personal information. Find out whether the business will delete the data or merely disable your access. Ask whether it may retain order records, fraud-prevention records, backups, or information it must keep by law.

Deletion rights often have exceptions. If a business denies a request, ask which information it retained, why it kept it, and whether it can restrict the information's use instead.

Treat cookie and marketing controls separately

A cookie banner usually addresses browser trackers, not every type of information in an account. It may not control purchase history, customer-support records, or information you enter directly.

Choose nonessential tracking settings carefully. Unsubscribe from marketing messages you don't want, and look for a separate option to opt out of the sale or sharing of personal information where applicable.

Protect the account yourself

Use a unique password and turn on multifactor authentication when it's available. Review active sessions and connected apps, keep software updated, and don't send identity documents through an unverified email address or support channel.

Those steps don't remove a company's obligations, but they can reduce the damage from stolen credentials or an account takeover.

Keep a dated file

Save:

A dated timeline is more useful than a general claim that a company "has too much data."

Match the problem to the rule

There is no single U.S. privacy law that gives every consumer identical rights. The relevant rule depends on your state, the business, the information involved, and what the company promised.

Rule or policy Where it may fit What it does not automatically establish
Company privacy notice and terms The promises and disclosures made to users of a service That every statement is a legal guarantee or that the data is secure
State privacy law When your state and the business meet that law's coverage conditions That residents of every state receive the same rights
CCPA, as amended by CPRA California residents and covered businesses handling their personal information That every business serving a California resident is covered
HIPAA Certain healthcare organizations and business associates handling protected health information That every health, fitness, or wellness app is covered
Breach-notification law When personal information is compromised and an applicable rule requires notice That every incident has the same deadline or remedy
GDPR Processing covered by the European Union's data-protection framework That a global website automatically gives every U.S. user GDPR rights
ISO 27701 or another certification A privacy-management framework used or claimed by a business That the certification replaces legal rights or guarantees a particular outcome

A business's claim that it is "GDPR-ready," "HIPAA-compliant," or "ISO certified" is only a starting point. Ask which entity made the claim, what information and activities it covers, and how it affects your specific data.

California consumers: check the CCPA process

The California Attorney General's CCPA guidance says the California Consumer Privacy Act gives consumers more control over personal information collected by businesses. The California Privacy Rights Act amendments are part of the CCPA framework.

If you're a California resident, look for instructions to:

If you opt out of the sale or sharing of your information, the California Attorney General says a business must wait at least 12 months before asking you to opt back in.

Use the business's official privacy link rather than a third-party form. State your request clearly, identify the account or transaction, and provide only the information reasonably needed for identity verification. Coverage, exceptions, and response procedures depend on the business and the request.

Health-related information doesn't always mean HIPAA

HIPAA is a sector-specific framework. It can apply to certain healthcare providers, health plans, healthcare clearinghouses, and business associates handling protected health information. A service that handles health or wellness information isn't automatically a HIPAA-covered entity.

Before uploading medical records or answering detailed health questions, check:

The U.S. Department of Health and Human Services Office for Civil Rights provides information about complaints involving the HIPAA Privacy, Security, and Breach Notification Rules. If HIPAA doesn't apply, a state privacy law, contract, or the company's own notice may still matter.

GDPR applies only when the framework covers the processing

GDPR is a European Union data-protection framework, not a universal U.S. consumer checklist. A U.S. customer of a global website shouldn't assume that a one-month response period applies simply because the company has customers around the world.

If you're in the European Union, or the processing is otherwise subject to GDPR, the European Commission's information for individuals says an organization should respond without undue delay and, in principle, within one month. The Commission also provides guidance on requests for access, correction, erasure, and objection.

For an international service, check its notice for the countries where data is processed, the vendors involved, and the transfer safeguards it describes. If you're a U.S. consumer, check your state's law and the company's own privacy-request process as well.

Send a privacy request that can be answered

Use this process for an access, correction, deletion, or marketing opt-out request:

  1. Find the privacy or consumer-rights email address, web form, or account setting.
  2. Identify the specific account, phone number, order, or data category involved.
  3. State exactly what you want changed or stopped.
  4. Ask what identity verification is required before sending documents.
  5. Don't include a full Social Security number or other unnecessary sensitive information.
  6. Save the submission, date, confirmation number, and response.
  7. If the business refuses, ask which exception or policy it relied on.
  8. If the response is incomplete, follow up in writing and identify the missing point.

You can adapt this template:

Subject: Privacy request for [account or order]

I am requesting [access to, correction of, deletion of, or opt-out from] the following personal information: [describe the data or activity]. My account or transaction details are [details]. Please confirm receipt, explain any identity-verification steps, and identify any information you will retain and the reason for retaining it. Please respond through [secure contact method].

A privacy request isn't the same as deleting an account, stopping all marketing, or disputing an unauthorized payment. If the issue involves a charge, contact the bank or card issuer through its official channel too.

If the business reports a data breach

Use the notice to identify what the business says happened, which types of information may be involved, and what protective steps it recommends. The FTC's data breach response guide for businesses emphasizes mobilizing a response, preserving evidence, consulting experts, and describing the compromise clearly. Those points give you useful questions to ask the company.

  1. Verify the notice through the company's official website or a phone number you already trust. Don't use an unexpected link in an email or text.
  2. Save the notice and record when you received it.
  3. Find out whether passwords, payment information, Social Security numbers, health information, or identity documents were involved.
  4. Change any exposed password, especially if you reused it elsewhere, and enable multifactor authentication.
  5. Review bank, card, and online accounts for unfamiliar activity.
  6. Contact the financial institution using the number on your card or statement if payment information may be exposed.
  7. If identity-theft risk is a concern, consider a credit freeze. The FTC's credit-freeze guidance says freezes are free, can be placed with Equifax, Experian, and TransUnion, and remain until you ask the bureaus to remove them.
  8. Follow up with the business if the notice doesn't explain what happened or what assistance is available.

Breach-notification requirements vary by state and by the type of information involved. A company saying "no action is required" doesn't stop you from changing a reused password or monitoring an account.

Signs that deserve a closer look

Pause before continuing when:

These signs don't establish a legal violation by themselves. They give you a basis to ask for clarification, reduce the data you provide, or compare another service.

Where to take a privacy problem

Start with the business and create a written record. Include the account details, the specific information at issue, and the outcome you want.

Then match the next step to the problem:

This is practical information, not legal advice. Before you click "accept" on the next account, save the privacy notice and leave optional sensitive fields blank unless the service explains why it needs them.