Start with the data, not the privacy badge
A privacy seal or certification badge doesn't tell you whether a service needs your precise location, shares your purchase history, or deletes an old account. Before giving sensitive information to a website, app, retailer, clinic, or subscription service, find out what it collects, why it needs it, who receives it, how long it keeps it, and what you can control.
U.S. privacy rights aren't uniform. Your state, the type of business, the information involved, the company's privacy notice and terms, and breach-notification rules can all change the answer. No single U.S. privacy law gives everyone the same set of rights.
The Federal Trade Commission's guide to protecting personal information is written for businesses, but its first questions work well for consumers: take stock of the data and trace how it moves.
Six questions to ask before sharing personal information
| Question | A useful answer | Reason to pause |
|---|---|---|
| What does the business collect? | Specific categories such as contact, payment, location, or account data | A vague statement that it collects "any information available" |
| Why is it collected? | Purposes connected to the feature or transaction you requested | Broad language covering unrelated advertising or profiling |
| Who receives it? | Named companies or understandable categories of service providers | No explanation of affiliates, advertisers, or vendors |
| How long is it kept? | A retention period or criteria for deciding when data is deleted | "As long as necessary" with no further detail |
| What choices do you have? | Instructions for access, correction, deletion, or marketing opt-out requests | No privacy contact or request process |
| How does the business handle incidents? | A security contact and a clear breach-notice process | Security claims with no way to report a problem |
A reason to pause isn't proof that a business broke the law. It tells you to ask a follow-up question, provide less information, or choose another service.
A privacy check for a new account
Start with every collection point
The registration form is only one source of information. Check mobile permissions, cookies, location services, loyalty programs, customer-support recordings, connected accounts, and uploaded documents.
Give extra scrutiny to Social Security numbers, financial and payment information, health information, precise location, biometric identifiers, and information about children. The FTC specifically tells businesses to identify and protect sensitive information. As a consumer, ask why each sensitive field is needed, what feature depends on it, and whether you can complete the transaction another way.
Read and save the privacy notice
Read the notice before creating the account, not after a problem arises. These sections usually answer the main questions:
- Categories of personal information collected
- Purposes for collecting or using it
- Whether information is sold, shared, or used for targeted advertising
- Service providers, affiliates, or other recipients
- Retention and deletion practices
- Security measures described at a high level
- Privacy request methods and contact details
- International transfers, if relevant
Save a copy or screenshot and record the date you viewed it. Privacy wording can change, and a dated copy shows what the business disclosed when you signed up.
Mark required and optional information
A business may need a shipping address to deliver a product, but it may not need your birthday for the same order. An app may need location access for navigation, but not for basic account creation.
Don't fill in optional fields just because a form displays them. If sensitive information is mandatory, ask what part of the service depends on it and whether the business will also use it for marketing or profiling.
Trace the recipients
The recipient section is often where the practical answer is buried. Search the notice for terms such as "service providers," "affiliates," "advertising partners," "sale," "sharing," "analytics," and "targeted advertising."
A company may not sell a mailing list in the ordinary sense and may still share information with advertising or analytics partners. You probably won't be able to approve every vendor individually, but you should be able to understand the categories of recipients and why the sharing occurs.
Ask what closing the account actually does
Closing a login isn't necessarily the same as deleting personal information. Find out whether the business will delete the data or merely disable your access. Ask whether it may retain order records, fraud-prevention records, backups, or information it must keep by law.
Deletion rights often have exceptions. If a business denies a request, ask which information it retained, why it kept it, and whether it can restrict the information's use instead.
Treat cookie and marketing controls separately
A cookie banner usually addresses browser trackers, not every type of information in an account. It may not control purchase history, customer-support records, or information you enter directly.
Choose nonessential tracking settings carefully. Unsubscribe from marketing messages you don't want, and look for a separate option to opt out of the sale or sharing of personal information where applicable.
Protect the account yourself
Use a unique password and turn on multifactor authentication when it's available. Review active sessions and connected apps, keep software updated, and don't send identity documents through an unverified email address or support channel.
Those steps don't remove a company's obligations, but they can reduce the damage from stolen credentials or an account takeover.
Keep a dated file
Save:
- The privacy notice and terms in effect when you signed up
- Screenshots of consent and tracking choices
- Copies of privacy requests and business replies
- Breach notices and the date you received them
- Receipts, account numbers, and support case numbers
- Evidence of unauthorized access or suspicious charges
A dated timeline is more useful than a general claim that a company "has too much data."
Match the problem to the rule
There is no single U.S. privacy law that gives every consumer identical rights. The relevant rule depends on your state, the business, the information involved, and what the company promised.
| Rule or policy | Where it may fit | What it does not automatically establish |
|---|---|---|
| Company privacy notice and terms | The promises and disclosures made to users of a service | That every statement is a legal guarantee or that the data is secure |
| State privacy law | When your state and the business meet that law's coverage conditions | That residents of every state receive the same rights |
| CCPA, as amended by CPRA | California residents and covered businesses handling their personal information | That every business serving a California resident is covered |
| HIPAA | Certain healthcare organizations and business associates handling protected health information | That every health, fitness, or wellness app is covered |
| Breach-notification law | When personal information is compromised and an applicable rule requires notice | That every incident has the same deadline or remedy |
| GDPR | Processing covered by the European Union's data-protection framework | That a global website automatically gives every U.S. user GDPR rights |
| ISO 27701 or another certification | A privacy-management framework used or claimed by a business | That the certification replaces legal rights or guarantees a particular outcome |
A business's claim that it is "GDPR-ready," "HIPAA-compliant," or "ISO certified" is only a starting point. Ask which entity made the claim, what information and activities it covers, and how it affects your specific data.
California consumers: check the CCPA process
The California Attorney General's CCPA guidance says the California Consumer Privacy Act gives consumers more control over personal information collected by businesses. The California Privacy Rights Act amendments are part of the CCPA framework.
If you're a California resident, look for instructions to:
- Know what personal information a business collects and how it is used
- Request access or deletion where the law allows
- Correct inaccurate information where applicable
- Opt out of the sale or sharing of personal information
- Limit certain uses of sensitive personal information
- Use a user-enabled global privacy control, such as GPC, to submit an opt-out request where applicable
If you opt out of the sale or sharing of your information, the California Attorney General says a business must wait at least 12 months before asking you to opt back in.
Use the business's official privacy link rather than a third-party form. State your request clearly, identify the account or transaction, and provide only the information reasonably needed for identity verification. Coverage, exceptions, and response procedures depend on the business and the request.
Health-related information doesn't always mean HIPAA
HIPAA is a sector-specific framework. It can apply to certain healthcare providers, health plans, healthcare clearinghouses, and business associates handling protected health information. A service that handles health or wellness information isn't automatically a HIPAA-covered entity.
Before uploading medical records or answering detailed health questions, check:
- Which legal entity is collecting the information
- Whether the service says it is subject to HIPAA
- Whether the information is used for care, payment, operations, advertising, or research
- Whether the service shares data with an employer, insurer, platform, or analytics provider
- How to request access, correction, or deletion
- How to report a privacy or security concern
The U.S. Department of Health and Human Services Office for Civil Rights provides information about complaints involving the HIPAA Privacy, Security, and Breach Notification Rules. If HIPAA doesn't apply, a state privacy law, contract, or the company's own notice may still matter.
GDPR applies only when the framework covers the processing
GDPR is a European Union data-protection framework, not a universal U.S. consumer checklist. A U.S. customer of a global website shouldn't assume that a one-month response period applies simply because the company has customers around the world.
If you're in the European Union, or the processing is otherwise subject to GDPR, the European Commission's information for individuals says an organization should respond without undue delay and, in principle, within one month. The Commission also provides guidance on requests for access, correction, erasure, and objection.
For an international service, check its notice for the countries where data is processed, the vendors involved, and the transfer safeguards it describes. If you're a U.S. consumer, check your state's law and the company's own privacy-request process as well.
Send a privacy request that can be answered
Use this process for an access, correction, deletion, or marketing opt-out request:
- Find the privacy or consumer-rights email address, web form, or account setting.
- Identify the specific account, phone number, order, or data category involved.
- State exactly what you want changed or stopped.
- Ask what identity verification is required before sending documents.
- Don't include a full Social Security number or other unnecessary sensitive information.
- Save the submission, date, confirmation number, and response.
- If the business refuses, ask which exception or policy it relied on.
- If the response is incomplete, follow up in writing and identify the missing point.
You can adapt this template:
Subject: Privacy request for [account or order]
I am requesting [access to, correction of, deletion of, or opt-out from] the following personal information: [describe the data or activity]. My account or transaction details are [details]. Please confirm receipt, explain any identity-verification steps, and identify any information you will retain and the reason for retaining it. Please respond through [secure contact method].
A privacy request isn't the same as deleting an account, stopping all marketing, or disputing an unauthorized payment. If the issue involves a charge, contact the bank or card issuer through its official channel too.
If the business reports a data breach
Use the notice to identify what the business says happened, which types of information may be involved, and what protective steps it recommends. The FTC's data breach response guide for businesses emphasizes mobilizing a response, preserving evidence, consulting experts, and describing the compromise clearly. Those points give you useful questions to ask the company.
- Verify the notice through the company's official website or a phone number you already trust. Don't use an unexpected link in an email or text.
- Save the notice and record when you received it.
- Find out whether passwords, payment information, Social Security numbers, health information, or identity documents were involved.
- Change any exposed password, especially if you reused it elsewhere, and enable multifactor authentication.
- Review bank, card, and online accounts for unfamiliar activity.
- Contact the financial institution using the number on your card or statement if payment information may be exposed.
- If identity-theft risk is a concern, consider a credit freeze. The FTC's credit-freeze guidance says freezes are free, can be placed with Equifax, Experian, and TransUnion, and remain until you ask the bureaus to remove them.
- Follow up with the business if the notice doesn't explain what happened or what assistance is available.
Breach-notification requirements vary by state and by the type of information involved. A company saying "no action is required" doesn't stop you from changing a reused password or monitoring an account.
Signs that deserve a closer look
Pause before continuing when:
- A service asks for highly sensitive information without explaining why
- The privacy notice combines unrelated purposes in one broad paragraph
- The business doesn't identify advertising, analytics, or other sharing
- There is no clear way to access, correct, delete, or restrict information
- Closing an account has no stated effect on stored data
- The company changes its privacy policy without clearly describing the change
- Support asks you to send identity documents through an unverified channel
- A breach notice omits the types of information involved or provides no contact method
These signs don't establish a legal violation by themselves. They give you a basis to ask for clarification, reduce the data you provide, or compare another service.
Where to take a privacy problem
Start with the business and create a written record. Include the account details, the specific information at issue, and the outcome you want.
Then match the next step to the problem:
- California privacy issue: Review the California Attorney General's CCPA guidance for rights and official state information.
- Possible HIPAA issue: Review the HHS Office for Civil Rights portal for complaints involving covered healthcare organizations.
- European Union data-protection issue: Use the European Commission's guidance for individuals to understand rights and supervisory-authority options.
- Unauthorized financial activity: Contact the bank, card issuer, or payment provider immediately through an official channel.
- Identity-theft risk: Use the FTC's credit-freeze guidance and preserve the breach notice and account records.
This is practical information, not legal advice. Before you click "accept" on the next account, save the privacy notice and leave optional sensitive fields blank unless the service explains why it needs them.