EnglishEspañol

How to File a Data Privacy Complaint (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 7, 2026. How we verify our legal content

How to File a Data Privacy Complaint (2026)

Frequently Asked Questions

Can I file a data privacy complaint with multiple agencies at the same time?

Yes, and you often should. Filing with your state AG and the FTC simultaneously is common practice. California residents may file with both the CPPA and the California AG. Cross-filing with multiple agencies is not prohibited, is not considered duplicative, and increases the likelihood that an investigation is opened. Each agency maintains its own complaint record independently.

What happens after I submit a complaint to the CPPA or a state AG?

The agency reviews your complaint, may request additional information from you, and may contact the company you complained about. They can open an investigation, issue a warning or demand letter, or pursue formal enforcement. They are not required to act on every complaint, and they do not guarantee a response to you (particularly if you file anonymously). If you want status updates, provide your contact information and file a named complaint.

Will I receive money if the FTC or HHS takes action based on my complaint?

Usually no. HIPAA civil penalties and FTC fines go to the government, not to individual complainants. In rare cases where a settlement creates a consumer restitution fund, eligible consumers may receive claim notices and nominal payments, though this is not guaranteed and typically takes several years. For direct monetary recovery, you need to consult a private attorney about whether a private right of action exists under the applicable law.

I am in California and the company failed my deletion request, not a data breach. Can I sue?

No. California Civil Code section 1798.150 limits the CCPA private right of action strictly to data-breach scenarios where nonencrypted and nonredacted personal information was exposed due to inadequate security. For all other CCPA violations (failed deletion requests, refused opt-outs, missing privacy notices, continued data selling after opt-out), your only formal remedy is filing with the CPPA or the California AG. A private attorney can advise on whether any other California statute applies to your situation.

I am in Europe and a US company violated my GDPR rights. Do I file in Europe or the US?

File with the Data Protection Authority in your country of habitual residence or where the infringement occurred, not in the United States. US companies that process EU resident data are subject to GDPR, and your national DPA has jurisdiction over your complaint. For major US tech firms with EU headquarters in Ireland, the Irish DPC will often serve as the Lead Supervisory Authority and coordinate the response. The EDPB's DPA directory at edpb.europa.eu/about-edpb/about-edpb/members_en lists every national authority.

Is there a deadline to file a state data privacy complaint with the CPPA or a state AG?

The CPPA and state AGs (Virginia, Colorado, Connecticut, Texas) do not publish a statutory consumer complaint deadline equivalent to HIPAA's 180-day rule. However, filing promptly preserves evidence, ensures the violation is recent enough to investigate, and improves your credibility as a complainant. Document the date of the violation, save all relevant communications, and file as soon as you have gathered your documentation.

What should I do if the company ignores my complaint or stops responding?

Document every step: keep copies of every request you sent, every response or non-response, and every deadline that passed without action. When you file with the regulator, this paper trail is your core evidence. Include the dates of each communication and attach copies. A company's failure to respond to a verified consumer rights request within the statutory deadline is itself a violation regulators can act on.

My doctor disclosed my health information to my employer. Is that HIPAA or a state law issue?

If the disclosure was made by a covered entity (doctor, hospital, health plan) without your authorization and without a valid HIPAA exception, it is a HIPAA violation. File with HHS OCR within 180 days of when you knew or should have known of the disclosure. Some states also have separate health privacy laws (California's CMIA, for example) that may give you additional rights including a private cause of action. An attorney can advise on state-specific options alongside your HHS OCR complaint.

Updates

Corrected the HIPAA complaint deadline to run from when you knew or should have known of the violation, and clarified that Connecticut's 63 warning letters concerned late data breach notices rather than consumer rights complaints.

Updated HIPAA civil penalty figures to the current inflation-adjusted amounts, corrected state attorney general penalty maximums for Colorado and Connecticut, and repaired a dead EDPB citation link.

Independently fact-checked against the cited primary sources

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. cppa.ca.gov
  2. cppa.ca.gov
  3. cppa.ca.gov
  4. oag.ca.gov
  5. oag.ca.gov
  6. leginfo.legislature.ca.gov
  7. oag.state.va.us
  8. oag.state.va.us
  9. coag.gov
  10. coag.gov
  11. dir.ct.gov
  12. portal.ct.gov
  13. texasattorneygeneral.gov
  14. ftc.gov
  15. reportfraud.ftc.gov
  16. hhs.gov
  17. hhs.gov
  18. ocrportal.hhs.gov
  19. edpb.europa.eu
  20. edpb.europa.eu
  21. edpb.europa.eu
  22. 45 CFR 160.306(b)(3): HIPAA Complaint Filing Deadline (knew or should have known)(ecfr.gov)
  23. Connecticut Attorney General: 2025 Connecticut Data Privacy Act Enforcement Report(portal.ct.gov)
Share: