A privacy complaint gets more traction when it links a dated company statement or consumer request to evidence. Before you write anything, decide what you want: access to your information, deletion, correction, an end to a specific sharing practice, a regulator review, or compensation. Those goals do not always use the same path.

This is general consumer information, not legal advice.

Pick the route that matches the problem

Your main problem Practical first step Where it can go next
You want to access, delete, or correct personal information Send a request to the company's privacy contact or rights form Privacy regulator or state consumer agency
A company made a misleading privacy or security claim Save the claim and report the conduct FTC, state attorney general, or applicable data authority
A company ignored a privacy-rights request Keep the request, identity-verification records, and response Regulator responsible for the applicable law
Your information was exposed in a breach Secure accounts and contact affected providers FTC, state regulator, attorney general, or another authority
You want money for an individual loss Document the loss and review dispute or legal options Lawyer, court, or remedy-specific process

A company request and a regulator complaint do different jobs. The company may be the fastest way to get a copy of your data or fix an error. A regulator can look for a broader unlawful or deceptive practice, but it usually will not act as your personal lawyer.

What makes a complaint useful?

Don't rely on a conclusion such as "the company violated my privacy." Give the facts that support it. Strong reports identify:

A policy statement can show what the company represented to users. It is not automatically a contract or a full statement of your legal rights. The applicable law, exemptions, account terms, and facts determine whether the conduct is unlawful.

If targeted ads or cookies make you suspect a sale or undisclosed tracking, say that you suspect it. Then list the facts behind the concern.

Step 1: Preserve evidence safely

If a policy page or account setting may change, save it before you contact the company.

  1. Capture the policy or notice. Save a PDF or screenshot with the web address and, if possible, the date and time. Note the policy version or effective date.
  2. Build a short timeline. Put sign-up, consent, account activity, disclosure, request, and response dates in order.
  3. Save communications. Keep emails, chat transcripts, support tickets, privacy-request confirmations, and case numbers.
  4. Record relevant settings. Save cookie choices, advertising settings, app permissions, and account privacy controls when they relate to the complaint.
  5. Name the right company and service. A social-media account, advertising service, voice assistant, and marketplace order can involve different entities and policies.
  6. Redact sensitive information. Don't send passwords, verification codes, full payment-card numbers, or unnecessary identity documents. If an official form requires identity verification, follow its secure instructions.
  7. Protect yourself after a breach. Change reused passwords, turn on multifactor authentication, review account activity, and contact your bank or card issuer if financial information may be exposed.

Keep originals. Send copies unless official instructions say otherwise.

Step 2: Ask the company to fix it

A direct request is often the right move when you want your data copied, corrected, deleted, or removed from a particular use. Look for the privacy contact, consumer-rights form, or data protection officer listed in the company's policy. Use the official account or website, not a link from an unexpected message.

Make the request narrow and specific. Include:

A company may ask you to verify your identity. That is normal, but it does not mean you should email a password or send documents to an address you cannot verify. Check the address against the company's official website.

If the company resolves the issue, save the response. If it refuses, gives an incomplete answer, or fails to respond through the applicable process, include that history in your complaint.

Step 3: Identify the governing jurisdiction

U.S. federal complaints and the FTC

The Federal Trade Commission is a possible route when a company's privacy or security conduct appears deceptive, unfair, or tied to another illegal business practice. The FTC's official contact page directs people targeted by an illegal business practice or scam to ReportFraud.gov.

In the report, identify:

An FTC report is not a court judgment. It does not guarantee a refund, investigation, or personal response. The agency may use reports to spot patterns and decide whether enforcement makes sense. If you need an individual resolution, keep using the company's privacy-request process or a remedy-specific legal route.

California CCPA and CPRA complaints

The California Consumer Privacy Act gives California consumers more control over personal information collected by covered businesses. The CPRA amendments have been in effect since January 1, 2023, but rights and exemptions depend on the business, data, and situation.

Start with the California CCPA information and complaint page. The California Privacy Protection Agency FAQ also explains consumer rights and procedures for access, deletion, correction, and related choices.

For a California complaint, include:

A regulator complaint is not the same thing as a private lawsuit. If a private CCPA lawsuit is available, the California Attorney General's page describes a pre-suit notice: the consumer must tell the business which CCPA sections were allegedly violated and allow 30 days for the business to respond in writing that it has cured the violation and will not continue it. That notice requirement is separate from filing an agency complaint. Private-action rules and remedies are fact-specific, so get legal advice before relying on a deadline.

State attorney general complaints

If the issue involves a state privacy law, deceptive business practice, or data breach, check your state attorney general's consumer-protection portal. States use different forms and may limit the subjects they investigate.

The Texas Attorney General's consumer complaint page, for example, includes complaints about companies that may violate laws protecting privacy and information related to data breaches. It asks for a clear description of the problem and useful identifying details about the business. After online submission, Texas says it sends a confirmation email with a complaint number.

A state attorney general may refer a matter, request information, investigate a broader practice, or take no action. It does not guarantee money recovery or representation in an individual dispute.

Complaints outside the United States

There is no single worldwide privacy complaint form. Use the official data protection or privacy authority in the country or region connected to your rights. In the European Union and European Economic Area, that generally means the supervisory authority for the applicable data-processing complaint. The United Kingdom has a separate privacy regime and regulator.

For a cross-border complaint, provide:

A local authority may coordinate with another country's authority, but that does not guarantee jurisdiction, a particular deadline, or compensation. Privacy Guides' reporting overview can help you identify the type of authority to look for; confirm filing instructions on the regulator's own website.

Don't copy a U.S. deadline into a GDPR, UK, Canadian, or other complaint. Rights, time limits, language requirements, fees, and appeal procedures vary.

Step 4: Write a factual complaint

Use this structure for an agency form, letter, or message to a company privacy team. Replace the brackets and remove anything you cannot support.

Subject: Privacy complaint about [company and service]

I am [your name, or the identifier permitted by the official form]. I live in [city, state, country].

Company and service: [legal or trading name, website, app, account, or product]

Privacy statement or request: The relevant policy or notice is [policy URL or document name], accessed on [date]. It states: "[short, exact quotation]."

What happened: On [date], [describe the collection, use, disclosure, retention, refusal, or security event]. I learned this from [email, account setting, notice, record, or other evidence].

Contact with the company: I contacted [company or privacy team] on [date] and requested [action]. The company [responded with / failed to provide] [brief result]. Reference number: [number, if available].

Why I am reporting it: I believe the conduct may conflict with [the quoted policy, the response to my request, or the privacy law that may apply]. I am asking the authority to review the facts and determine whether a violation occurred.

Requested outcome: [Investigate the practice, require a response, correct or delete information, stop a stated use, or provide another remedy available through this process.]

Evidence: [List attachments by name and date.]

I have redacted passwords, verification codes, and unnecessary financial or identity information. I can provide additional details through the official process if requested.

Avoid exaggeration. "I believe the policy may have allowed sharing with this category of partner" is more useful than claiming a specific sale you cannot prove.

Evidence checklist

Before submitting, make sure you have:

Evidence should show how you know something happened. If you only suspect a data transfer, say that and explain the facts behind the concern.

Filing against Google, Meta, Amazon, or another large platform

A large platform does not need a special complaint theory. Ask the same questions:

  1. Which legal entity and service handled the data?
  2. What policy, notice, consent choice, or privacy request is involved?
  3. Which country or state governs your rights?
  4. What did you ask the company to do?
  5. What evidence shows the conduct?

Use the platform's privacy or data-request channel when you want an account-level remedy. Use the FTC, a state attorney general, a California agency, or an overseas authority when the conduct may affect other consumers or appears to violate applicable law.

A news report about a fine or settlement can provide context, but it does not prove your account was handled the same way. Name your specific service, dates, settings, and communications.

What happens after you submit?

Save the confirmation number, downloaded copy, and submission date. Check the agency's email or portal for requests for clarification, and answer only through a verified channel.

There is no universal privacy-complaint timetable. The California 30-day period described above concerns a pre-lawsuit notice, not a general regulator response deadline. Don't promise that an FTC, CCPA, GDPR, or state complaint will be resolved in 30, 45, or 90 days.

Possible outcomes include:

Keep pursuing separate practical remedies while the complaint is pending. Continue a deletion request, secure a compromised account, dispute an unauthorized payment through the appropriate payment provider, or seek legal advice about compensation.

Common mistakes to avoid

Frequently asked questions

Can I file a privacy complaint anonymously?

Sometimes, but don't assume it. An agency may need your identity to verify a request, ask follow-up questions, or provide an outcome. Check the official form before leaving out contact details, and never include unnecessary sensitive information.

Does a privacy-policy violation automatically mean the company broke the law?

No. The policy is one piece of evidence. The applicable statute, the company's conduct, consent records, exemptions, and the type of information involved all matter. A regulator decides whether the facts support enforcement.

Can the FTC get my money back?

An FTC report may help the agency identify a pattern, but it is not a guaranteed individual recovery process. For a refund, unauthorized charge, or direct account dispute, use the company and payment-provider procedures that apply to that problem.

How long will a privacy complaint take?

Timing varies by agency, jurisdiction, complexity, and whether the matter is referred. The only specific period discussed here is California's 30-day written cure-notice period before a qualifying private CCPA lawsuit. Don't treat it as a general complaint deadline.

Do I need a lawyer to report a privacy problem?

You can usually submit a factual consumer report without one. Consider legal advice if you suffered substantial financial harm, received a legal notice, want compensation, or are thinking about a lawsuit. Organize your evidence before seeking help.

Start with one dated record

Before you file anything, save one anchor document: the policy version, consent screen, request confirmation, breach notice, or account setting. Name the file with the date and source. That single record gives the company, regulator, or lawyer a concrete point to test, and it keeps your complaint from becoming a vague accusation.