Your Privacy Rights

Where to File a Privacy Complaint That Gets Results

By the RedactZero Team · July 25, 2026 · 9 min read

The short version

When a company ignores your deletion or opt-out request, the ladder is: save the evidence, escalate to the company's privacy contact, then file with your state attorney general - plus the CPPA if you are in California, the CFPB for credit and financial data, and the FTC for deception or identity theft. Be realistic: these agencies aggregate complaints and act on patterns. Most will not personally get your record deleted. This article is general information, not legal advice.

Build the paper trail before you complain

Every complaint form asks the same questions: what you asked for, when, who you asked, and what happened. If you cannot answer those, your complaint gets filed as noise. So before you escalate anywhere, spend ten minutes assembling the record. It is the single highest-value step in this entire process.

Capture and store, in one folder or one email thread:

Screenshots matter more than people expect. A profile page can quietly change between the day you complain and the day someone reviews it, and a dated image is the only thing that proves what you saw.

Escalate inside the company first

Regulators want to see that you gave the business a chance to fix it. Most privacy laws also assume a direct request came first, so an internal escalation is not a wasted step - it is the step that makes your later complaint credible, and it resolves a surprising number of cases outright.

Look for a named privacy contact rather than general support. Check the bottom of the privacy policy, which usually lists a privacy email address or a postal address for rights requests, and send a short, factual follow-up: the original request date, the confirmation number, the legal deadline you believe applies, and a request for written confirmation within ten business days.

Keep it unemotional and specific. "I submitted a deletion request on June 2, confirmation 4471, and have received no response in 52 days" gets acted on. A paragraph of frustration does not.

Match the problem to the right complaint desk

There is no single privacy ombudsman in the United States. Which body helps depends entirely on what kind of data and what kind of company is involved, and sending a credit-report problem to the FTC or a robocall to your attorney general mostly guarantees it goes nowhere. Use this map.

Your situationWhere to fileWhat it can realistically do
A business ignored or refused your deletion or opt-out requestYour state attorney general (directory at usa.gov/state-attorney-general)Logs the pattern; can investigate and sue the business. Will not act as your lawyer.
Same, and you are a California residentCPPA complaint form, and the California AGEnforces the CCPA; uses complaints to monitor industry compliance and inform enforcement actions.
A registered data broker ignored your California DROP requestCPPADROP is the CPPA's own program, so it is the correct venue for non-compliance.
A company lied about what it collects, sells, or deletesFTC at ReportFraud.ftc.govFeeds Consumer Sentinel, a law-enforcement database; the FTC sues over deceptive practices.
Someone opened accounts or filed taxes in your nameFTC at IdentityTheft.govGenerates an official FTC Identity Theft Report plus a step-by-step recovery plan.
Wrong, stale, or fraudulent data on your credit reportCFPB at consumerfinance.gov/complaintForwards your complaint to the company and publishes a response timeline.
Unwanted robocalls or spam textsFCC at consumercomplaints.fcc.govInforms enforcement and policy. The FCC says it does not resolve individual unwanted-call complaints.

Venues and scope per the official pages of the CPPA (cppa.ca.gov), the California Attorney General (oag.ca.gov), the FTC (ftc.gov), the CFPB (consumerfinance.gov), the FCC (fcc.gov), and USAGov (usa.gov), checked July 2026.

Your state attorney general is the default first stop

For a business that stonewalled a privacy request, your state attorney general is almost always the right first filing. Most US state privacy laws are enforced by the AG rather than by individuals, so that office is the one with actual authority over the company. Find yours through the USAGov directory of all fifty states and the territories.

The directory lives at usa.gov/state-attorney-general, and each office runs its own consumer complaint portal. Texas, for example, routes privacy issues through a dedicated privacy complaint form for personal information that is unlawfully collected, shared, or mishandled by a business.

Be aware that state law often gives companies a grace period. The Texas Data Privacy and Security Act requires the Attorney General to send written notice and allow 30 days to cure before an enforcement action, with civil penalties of up to $7,500 per violation after that. Colorado's Attorney General is blunt that private citizens cannot enforce the Colorado Privacy Act at all - only the AG and district attorneys can.

California residents: the CPPA and the state AG

California is the only state with a dedicated privacy regulator. The California Privacy Protection Agency takes consumer complaints at cppa.ca.gov/webapplications/complaint, and it is the correct venue when a business blows past a CCPA request deadline or when a registered data broker ignores a Delete Act request.

Two useful details from the agency's own form. It accepts unsworn complaints that can be filed anonymously, but warns that anonymity means it cannot follow up with you. And it states directly that it uses complaints "to broadly monitor industry compliance or to inform an enforcement action" - not to litigate your individual case.

You can also file with the California Attorney General at oag.ca.gov/contact/consumer-complaint-against-business-or-company. The AG's CCPA page notes that businesses must respond to your request within 45 calendar days, extendable by another 45 with notice. If you are still filing the underlying request, start with our California DROP guide.

The FTC: deception, scams, and identity theft

The Federal Trade Commission is the right venue when a company has been deceptive rather than merely slow - a privacy policy that contradicts what the company actually does, a "delete" button that deletes nothing, or an outright scam. Consumer reports go to reportfraud.ftc.gov.

Set expectations correctly. Your report lands in the Consumer Sentinel Network, which the FTC describes as a secure online database available only to law enforcement, and the agency is explicit that it "does not intervene in individual consumer disputes." What your report does is add a data point that helps investigators spot patterns and build cases.

The exception, and it is a real one, is identity theft. Reporting at identitytheft.gov produces something you can use immediately: an official FTC Identity Theft Report and a personalised recovery plan with pre-filled letters. If that is your situation, read what to do after a data breach next.

The CFPB: credit reports and financial data

If your privacy problem involves a credit report, a lender, a debt collector, a bank, or a payment app, the Consumer Financial Protection Bureau is the venue with the most concrete process. File at consumerfinance.gov/complaint. It covers credit reports and personal consumer reports, debt collection, mortgages, student loans, prepaid cards, and more.

The CFPB is unusual because it routes your complaint to the company and publishes what happens next: companies generally respond in 15 days, and where a response is in progress they provide a final response within 60 days. You then get 60 days to give feedback on that response.

Do the underlying dispute first, though. The CFPB says furnishers - the companies that report data about you - generally must investigate and respond to your dispute within 30 days of receiving it. Complain to the Bureau after that clock has run out, not instead of starting it. Prescreened credit offers are a related nuisance with their own opt-out, covered in how to stop prescreened credit card offers.

What these agencies will not do for you

This is the part most guides leave out, and it is the reason people give up. Regulators are pattern-matching machines, not customer service for your specific record. Going in with the right expectation is what keeps you filing instead of concluding the system is fake.

Three limits are stated in plain language on the agencies' own pages. The CPPA says it "does not represent individual consumers and cannot act as your attorney." The California Attorney General says it "does not represent individual California consumers." The FTC says it does not intervene in individual consumer disputes, and the FCC says the same about unwanted-call complaints.

So no, a complaint will not usually get your listing pulled. What it does is create an official, timestamped record of a violation. Enforcement actions are built from stacks of those records, and the deletion you personally want is far more likely to come from filing the request again, correctly, than from the complaint itself.

Realistic timelines and what a good outcome looks like

Privacy escalation runs on published deadlines for the company and unpublished ones for the regulator. Knowing which clocks are real tells you when to wait and when to escalate. Here are the ones with numbers attached, all from official sources.

ClockWho it bindsDeadline
CCPA request responseThe business45 calendar days, extendable by another 45 (90 total) with notice
Credit-report disputeThe furnisherGenerally 30 days from receiving your dispute
CFPB complaint responseThe companyGenerally 15 days; final response within 60 days
Your CFPB feedback windowYou60 days after the company responds
Cure period before Texas enforcementThe business30 days after the Attorney General's written notice
CCPA pre-suit notice to cureThe business30 days after your written notice

Deadlines per the California Attorney General (oag.ca.gov/privacy/ccpa), the CFPB (consumerfinance.gov), and the Texas Attorney General (texasattorneygeneral.gov), checked July 2026.

A good outcome, honestly defined, is one of three things: the company complies after your internal escalation, the CFPB routes your complaint and the company fixes the record, or your complaint joins a pattern that a regulator later acts on. Anything faster is a bonus, not the baseline.

When small claims or a lawsuit is on the table

Suing is possible in narrow circumstances and is genuinely not the usual path. Most state privacy laws give enforcement to the attorney general and give you nothing to sue with. Where a private right of action exists, it is normally tied to a data breach rather than to an ignored deletion request.

California is the clearest example. Its Attorney General explains that you can sue only if your nonencrypted, nonredacted personal information was stolen in a breach caused by the business failing to maintain reasonable security, for actual damages or statutory damages of up to $750 per incident - and you must first give the business written notice and 30 days to cure. Small-claims court is a separate track with its own state-specific limits and rules.

This article is general information for US consumers, not legal advice, and reading it does not create an attorney-client relationship. Privacy laws, deadlines, and complaint procedures vary by state and change often. Before filing a lawsuit or a small-claims action, or if you have been personally harmed, consult a licensed attorney in your state.

Keep filing the requests, not just the complaints

Complaints are the pressure valve, not the mechanism. The thing that actually removes your name from a people-search profile is a correctly filed opt-out, repeated when the listing comes back. Treat regulators as the escalation path for the minority of companies that refuse, and keep the routine work going in parallel.

Re-check your exposure every few months, because brokers re-ingest public records continuously and listings commonly reappear within three to six months. Our library of dated opt-out guides covers 57 major brokers, the broader walkthrough is in how to remove yourself from data brokers, and a smaller overall footprint starts with reducing your digital footprint. It is also worth knowing what a "do not sell" toggle really covers before you assume it failed - we unpack that in what "do not sell my personal info" actually does.

Know what you are complaining about

Run a free exposure scan to see which data brokers likely list you, plus any breaches tied to your email. No account, nothing stored - and it gives you the dated evidence your complaint needs.

Run a free exposure scan

Frequently asked questions

What should I do if a company ignores my deletion request?

Save your evidence first: the date you filed, the exact wording, any confirmation number, and a screenshot of the listing. Then email the company's privacy contact one more time with a clear deadline. If that fails, file with your state attorney general, and with the CPPA if you are a California resident.

Which agency should I complain to first?

Your state attorney general is the default first stop for a business ignoring a privacy request, because most state privacy laws are enforced by the AG. Add the CPPA if you live in California, the CFPB for credit-report or financial-data problems, and the FTC for deception or identity theft.

Will filing a complaint actually get my data deleted?

Usually not on its own. The California Privacy Protection Agency states plainly that it does not represent individual consumers and cannot act as your attorney, and the FTC says it does not intervene in individual consumer disputes. Complaints mainly build the record that drives investigations and enforcement.

How long does a privacy complaint take?

Expect months, not days. The one venue with a fast published clock is the CFPB, which says companies generally respond in 15 days and provide a final response within 60 days. State attorney general and CPPA complaints feed longer investigations with no promised individual reply.

Can I file a privacy complaint anonymously?

Sometimes. The CPPA accepts unsworn complaints that can be filed anonymously, but it notes the Agency will not be able to follow up with you about them. If you want any chance of a response or a case reference, file under your name and include contact details.

Do I need a lawyer to file a privacy complaint?

No. Every complaint form named in this article is free, consumer-facing, and designed to be filled in without legal help. A lawyer becomes relevant only if you are considering a lawsuit or a small-claims filing. This article is general information, not legal advice.

Can I sue a company over a privacy violation?

Rarely, and it depends on your state and the facts. California's Attorney General says consumers can sue only in limited data-breach circumstances, with statutory damages of up to $750 per incident and a required 30-day written notice to cure. Colorado's Attorney General says private citizens cannot enforce that state's privacy act at all. Consult an attorney.

What if I do not live in California?

You still have complaint venues. Every state and territory has an attorney general with a consumer complaint process, listed at usa.gov/state-attorney-general, and the FTC, CFPB, and FCC are federal and open to everyone. You just will not have the CPPA or California's DROP platform.

Sources: California Privacy Protection Agency complaint form (cppa.ca.gov); California Attorney General CCPA page (oag.ca.gov/privacy/ccpa); Federal Trade Commission, ReportFraud.ftc.gov, IdentityTheft.gov and Consumer Sentinel Network materials (ftc.gov); Consumer Financial Protection Bureau complaint and credit-report pages (consumerfinance.gov); Federal Communications Commission Consumer Complaint Center (fcc.gov); Texas Attorney General consumer privacy rights pages (texasattorneygeneral.gov); Colorado Attorney General Colorado Privacy Act page (coag.gov); USAGov state attorney general directory (usa.gov). All URLs checked July 2026. General information only, not legal advice.