Privacy & Data · European Union

How to File a GDPR Complaint: A Step-by-Step Enforcement Guide

It's easy to assume an individual complaint against a large tech company or e-commerce platform in Europe simply disappears into a void. The GDPR was built specifically to prevent that outcome — backed by fines of up to €20 million or 4% of a company's global annual turnover, whichever is higher, a free, formal complaint from any individual can trigger a real government investigation.

What actually makes a complaint credible

A successful privacy complaint isn't built on suspicion — it needs concrete evidence. Screenshots of account settings showing you couldn't withdraw consent, copies of emails with readable technical headers, and a clear timeline showing the organisation missed its legal response deadlines all strengthen your case significantly more than a general description of feeling surveilled.

Contact the company's DPO first

Reach out to the alleged infringing company's Data Protection Officer (DPO) — most organisations processing significant personal data are required to have one, and their contact details should be in the privacy policy. If they don't respond satisfactorily within 30 days, compile all your correspondence and prepare to file the formal complaint.

Filing with your national DPA

Access your national Data Protection Authority's online complaint portal. Enter your case details in chronological order, attaching your evidence. Once the case is accepted for processing, investigators formally request a response from the company, opening an enforcement file that can lead to forced system changes and public penalties.

What happens to your case after filing

Your complaint doesn't need to resolve everything on its own — DPAs use the volume and pattern of complaints against a given organisation to prioritise enforcement resources, meaning even a complaint that doesn't personally satisfy you may still contribute to a larger action against a company with systemic issues.

Sources