Data Breaches and Privacy Complaints

What to do after your personal information is exposed, misused or withheld: the regulator route, the evidence of harm, and the deadlines involved.

3 min read · Updated August 1, 2026 · Concaso Editorial

General guidance

This guide currently contains general legal information. Jurisdiction-specific guidance for your location is coming soon. The Concaso assessment will still tailor its questions and analysis based on your jurisdiction.

Tailored versions available: Canada (General), Ontario, United States (General), England & Wales.

Defendant Centre

If you are defending this

Someone has raised this against you, so the guide below is most useful for understanding what you must respond to, and by when.

  • Find the deadline on anything you have been served with and diarise it immediately.
  • Do not ignore it — many processes allow a decision to be made against you if you do not respond.
  • Preserve documents and messages now; deleting anything is far worse than the underlying dispute.
  • Separate what you genuinely dispute from what you accept, so the response is focused.
  • Consider whether you have a claim of your own arising from the same events.
  • Check whether an insurance policy or an employer may be required to cover or defend it.

Reading this from the other side? Switch to the Plaintiff Centre view.

Identify what actually happened

Privacy disputes take a few recognisable forms, and each has a different route. Being precise about which one applies saves time, because the regulator and the remedies differ.

SituationUsual first route
A security breach exposed your dataThe organisation's breach notification, then the regulator
Someone inside an organisation looked at your fileInternal privacy officer complaint, then the regulator
Your information was shared without consentComplaint to the organisation, then the regulator
An access or correction request was refusedInternal review, then the regulator or tribunal
Information posted about you onlinePlatform removal routes, and possibly defamation or privacy claims

The first steps that protect you

  1. Immediately

    Change passwords, enable multi-factor authentication, and review account activity.

  2. Same week

    Place fraud alerts or a credit freeze where financial data was involved.

  3. In writing

    Ask the organisation what data was involved, when, and what they are doing.

  4. Keep

    A log of every notification, call, cost and hour spent dealing with it.

Regulators, and proving harm

Privacy regulators can investigate, make findings and in some places issue penalties, but they do not usually award compensation to an individual. A claim for compensation is generally a separate route, and it depends on showing what the exposure actually caused.

  • Fraudulent transactions or accounts opened in your name
  • Money spent on credit monitoring, replacement documents or identity restoration
  • Time lost dealing with the consequences, recorded contemporaneously
  • Documented distress, particularly where sensitive information was involved
  • Consequences at work or in a relationship traceable to the disclosure

Deadlines and reporting dutiesGeneral guidance

Organisations often have mandatory breach reporting duties measured in days. From your side, complaint windows to regulators are usually measured in months from when you became aware, and any civil claim runs on the ordinary limitation period.

Documents to gather

  • The breach notification letter or email you received
  • Your complaint to the organisation and its response
  • Any access or correction request you made, and the reply
  • The organisation's privacy policy in force at the relevant time
  • Bank, credit and account statements showing suspicious activity
  • Receipts for monitoring services, replacement documents or other costs

Evidence that carries weight

  • A dated log of everything you did in response and how long it took
  • Screenshots of the exposed information where it was published
  • Correspondence identifying who accessed the information and when
  • Credit reports before and after the incident
  • Medical or counselling records where distress is claimed

Want both lists in one printable page?

Common mistakes

  • Going straight to a regulator without complaining to the organisation first
  • Not making a written access request to find out what was actually held
  • Failing to record time and costs spent responding
  • Accepting a free monitoring offer without checking whether it releases claims
  • Letting the regulator complaint window pass while waiting for a response

Frequently asked

Can I find out exactly what data they hold about me?

Most privacy regimes give individuals a right to request access to their own personal information, usually with a defined response deadline and limited grounds for refusal.

Will the regulator get me compensation?

Generally no. Regulators investigate and can make findings or order changes, but compensation typically comes from a separate civil claim or a class proceeding.

What if the breach was caused by an employee snooping?

Unauthorised internal access is treated seriously in most systems and is usually handled first through the organisation's privacy officer, then the regulator.

Should I join a class action?

Large breaches often attract class proceedings. Joining one is usually low effort but limits individual control, and any settlement typically releases individual claims.

Nothing has happened yet — is it too early to act?

The protective steps are worth taking immediately, and keeping records from the start is what makes a later claim provable. Complaint windows can begin running from awareness rather than from harm.

Assess my situation

Concaso turns what you already know into a structured, confidential report — strengths, weaknesses, missing evidence, and the deadlines that matter. We will start you in the right place based on this guide.

Assess my situation

Assessment topics related to this guide

Topics in this guide

Related guides

This guide is general information, not legal advice, and Concaso is not a law firm. Reading it does not create a lawyer–client relationship. Deadlines and procedures differ by jurisdiction and change over time — confirm anything you intend to rely on.