Complaining to a data protection authority
When and how to lodge a complaint with a data protection authority if a company does not reply to your GDPR request or failed to protect your data.
In the European Union, each country has an independent data protection authority responsible for enforcing the GDPR. You can lodge a complaint free of charge, usually online.
When to complain
- the company does not reply to your erasure or access request within one month (or three months if it told you of an extension);
- it refuses without a valid reason;
- you believe it failed to protect your data or did not inform you of a breach that posed a high risk to you.
Which authority
As a rule, the authority of the country where you live: for example the CNIL in France, the AEPD in Spain, or the data protection authority of your federal state in Germany. The European Data Protection Board (edpb.europa.eu) lists all of them. In the United Kingdom, it is the ICO (ico.org.uk).
Before complaining
In most cases, the authority expects you to have contacted the company first. Keep a record of your request (email, registered letter) and the date it was sent. See our erasure request template.
Good to know
A company that suffers a breach must notify its data protection authority within 72 hours, and inform the people concerned if the breach poses a high risk to them. Notifying the breach does not exempt it from replying to your requests.