How to Make a GDPR Complaint to a Data Protection Authority
How to make a GDPR complaint: raise it with the organization first, pick the right data protection authority, what to include, rough timelines, and what regulators can and can't do.
To make a GDPR complaint, first raise the problem in writing with the organization (the “controller”) and give it a chance to fix it. If it ignores you or refuses without a good reason, complain to a data protection authority: in the EU and EEA, that’s usually the authority in the country where you live, work or where the problem happened, and in the UK it’s the Information Commissioner’s Office (ICO). Complaining is free, and you don’t need a lawyer.
This guide explains how the process works across Europe, what to put in your complaint and what to expect afterward. It’s general information, not legal advice. If your complaint is about a UK organization, our step-by-step guide to making an ICO complaint goes into the UK process in more detail.
What you can complain about under the GDPR
The GDPR gives you rights over your personal data and puts duties on the organizations that handle it. Article 77 gives you the right to lodge a complaint with a supervisory authority if you think the processing of your data breaks the regulation. Common reasons include:
- An ignored or incomplete access request. You asked what data a company holds and got nothing, or only part of it. Our guide to making a data subject access request covers the request itself.
- A refused deletion request. The organization won’t delete data it no longer needs. See our guide to the GDPR right to erasure for when that right applies.
- Marketing after you objected. You told a company to stop using your data for direct marketing and it carried on. Our guide to the GDPR right to object explains that right.
- Processing with no lawful basis. Your details were shared, published or sold without any valid legal ground.
- A search engine refusing to delist a result. A refused “right to be forgotten” request can be taken to a regulator.
- Poor security or a mishandled breach. Your data was exposed and the organization didn’t take reasonable steps or tell you when it should have.
A GDPR complaint is about how your data is handled. It isn’t the route for a rude review, a disputed invoice or a defamatory post by a private individual, although some of those situations overlap with data rights.
Does the GDPR cover your situation?
The GDPR applies to organizations established in the EU or EEA, and to organizations elsewhere that offer goods or services to people in the EU or monitor their behavior there. The UK has its own near-identical version, the UK GDPR, overseen by the ICO.
That reach matters for readers outside Europe. A Singapore or US business that sells to customers in France, or tracks visitors from Germany, can be covered for that activity. But if you live in Singapore and your problem is with a Singapore company that doesn’t target Europe, the GDPR usually won’t help; the local law is the PDPA, covered in our guide to the PDPA in Singapore.
Step 1: Raise the problem with the controller first
Regulators expect organizations to get the first chance to put things right, and many complaints are resolved at this stage. A written complaint also creates the paper trail the authority will want to see.
- Find the right contact. Check the organization’s privacy notice for its data protection officer (DPO), a privacy email address or a rights request form. Use that rather than general customer service.
- Describe the problem plainly. Say what you asked for, when, and what happened. Name the right involved if you can, such as access, erasure or objection.
- Say what you want. A copy of your data, deletion, a correction, an end to marketing, or an explanation of the legal basis they rely on.
- Set a reasonable deadline. For rights requests, the GDPR already requires a response without undue delay and generally within one month, extendable by up to two further months for complex or numerous requests if they tell you why.
- Keep copies of everything, with dates.
Here’s wording you can adapt:
Subject: Data protection complaint
Dear Data Protection Officer,
On [date], I [asked for a copy of my personal data / asked you to erase my data / objected to your use of my data for marketing]. [Describe what has happened since, for example: I have not received a response, or I received a partial response that does not include X.]
I would like you to [describe the outcome you want]. Please respond by [date]. If this is not resolved, I intend to lodge a complaint with the data protection authority.
[Your name, contact details and any account or reference number]
Step 2: Choose the right supervisory authority
Every EU and EEA country has at least one data protection authority (DPA), sometimes called a supervisory authority. Germany has regional authorities as well as a federal one. The European Data Protection Board publishes a list of national authorities with links to their official websites.
The GDPR lets you complain in particular to the authority in the member state where you habitually live, where you work, or where the alleged infringement took place. You don’t have to find the “right” regulator for the company yourself.
| Situation | Where to complain |
|---|---|
| You live in the EU or EEA | Your local data protection authority, in your own language, is usually the simplest choice |
| The company has its main EU establishment in another country | You can still complain locally; your authority works with the lead supervisory authority where the company is based |
| The organization is covered by UK data protection law | The ICO |
| You live outside Europe but the organization is covered | The authority where the infringement happened, or the lead authority for the company |
The “lead supervisory authority” idea is part of the GDPR’s one-stop-shop system. When a company processes data across borders, the authority in the country of its main EU establishment normally leads the investigation, working with other concerned authorities. For many large technology companies, that lead authority is Ireland’s Data Protection Commission, because their European headquarters are in Ireland. You can still start with your own authority, which passes the complaint on and keeps you informed.
Step 3: Prepare and submit your GDPR complaint
Most authorities have an online complaint form, and some also accept email or post. Use the official website, which you should reach by typing the address yourself or finding it through the EDPB list, and ignore services that charge to “file” for you.
A strong complaint usually includes:
- Who you are and how to contact you.
- The organization: its name, website, and any address or DPO contact you have.
- What happened: a short, dated timeline of your request and their response.
- Which right or rule is involved, in plain words if you’re unsure of the article number.
- Your evidence: copies of your request, their reply or proof of no reply, screenshots, and any relevant links.
- The outcome you want, such as the organization answering your access request or deleting specific data.
If you’re complaining in a country whose language you don’t speak well, use the authority where you live instead, or check whether the authority accepts complaints in English. Many do, but not all.
What happens after you complain
Timelines vary a lot between authorities and depend on the complexity of the case, how many countries are involved and the regulator’s workload. Straightforward local complaints can move in weeks or months; cross-border cases against large companies can take much longer.
The GDPR does set some baseline duties. The authority must handle your complaint, investigate it to the extent appropriate, and inform you of the progress and outcome. If it doesn’t handle your complaint, or doesn’t tell you about progress or the outcome within three months, you have the right to go to court against the authority itself.
Typical outcomes include:
- The authority contacting the organization and asking it to comply, which often resolves the problem.
- An amicable settlement or mediation, which some authorities use for individual complaints.
- Formal orders, such as requiring the organization to answer your request or stop certain processing.
- Reprimands or fines in more serious cases, which usually go to the state rather than to you.
- A decision that no breach occurred, with reasons.
Not sure where to start?
Get a free audit of your search results and review profiles, with a prioritized fix list.
Get a free auditWhat a regulator can’t do
Data protection authorities can investigate and order organizations to comply, but they don’t award you compensation. If you’ve suffered financial loss or distress because of a GDPR breach, the right to compensation is enforced through the courts, and you may bring a claim against the controller directly whether or not you complained to a regulator. The GDPR also lets certain not-for-profit organizations bring complaints on your behalf. For a court claim, speak to a lawyer who handles data protection in the relevant country.
Regulators also can’t force a news publisher to delete accurate reporting, because freedom of expression is protected. For old coverage, a delisting or update request is often the better route, as our guide on the right to be forgotten explains.
A worked example
This is an illustrative scenario, not a real client. Marta, a nurse living in Lisbon, finds that an online directory run by a company based in the Netherlands shows her full name, home street and phone number alongside a photo scraped from an old social profile.
- She writes to the directory’s privacy address, objecting to the processing and asking for erasure. She gets an automated reply and nothing else.
- After a month passes, she sends a short reminder quoting her original request and its date. Still nothing.
- She complains to Portugal’s data protection authority, in Portuguese, attaching screenshots of the listing, her two emails and the automated reply.
- The Portuguese authority passes the case to the Dutch authority as the lead supervisory authority, and keeps Marta updated.
Marta can’t control what the regulators decide or when. But her complaint is easy to follow, and she has a record if she later needs a lawyer. While it’s pending, she also uses Google’s tools to request removal of search results showing her contact details.
Common mistakes
- Skipping the organization. Most authorities will ask whether you’ve contacted the controller first.
- Sending no evidence. Without copies of your request and replies, the regulator can’t assess what happened.
- Waiting too long. The GDPR doesn’t set one fixed deadline for complaints, but some authorities and national laws have their own expectations. Complain while the facts are fresh.
- Expecting compensation from the regulator. That needs a court claim.
- Using the GDPR where it doesn’t reach. A local company outside Europe with no European customers is usually covered by its own country’s law instead.
- Paying a middleman. Complaining to a data protection authority is free.
When to get help
Most people can make a GDPR complaint themselves. It’s worth getting help when your data is spread across many sites, when a complaint is part of a bigger dispute, or when harmful search results are doing the real damage. Our content removal service handles data protection and delisting requests and tells you plainly which are likely to work. For court claims, talk to a data protection lawyer.
Frequently asked questions
Is it free to make a GDPR complaint?
Yes. Complaining to a data protection authority in the EU, EEA or UK is free, and you don’t need a lawyer. Be wary of services that charge to submit a complaint for you.
Which authority should I complain to if the company is in another EU country?
You can usually complain to the authority where you live or work. For cross-border cases, it works with the lead supervisory authority in the country of the company’s main EU establishment and keeps you informed.
How long does a GDPR complaint take?
It varies by authority and case. Simple complaints may be resolved in weeks or months, while cross-border cases can take much longer. If the authority doesn’t tell you about progress or the outcome within three months, you can take it to court.
Can I get compensation through a GDPR complaint?
Not from the regulator. Authorities can order compliance and impose fines, but compensation for loss or distress is claimed through the courts. Speak to a data protection lawyer about that route.
Can I make a GDPR complaint if I live outside Europe?
Possibly, if the organization is covered by the GDPR, for example because it offers services to people in the EU. If the organization is local to you and doesn’t target Europe, your own country’s privacy law and regulator are usually the better route.