Privacy problems split into genuinely different questions — is your data listed by a data broker, do you need to complain to a regulator, what does the law actually require, how do you reach a specific company's own privacy team, or has your data already been exposed in a breach? This directory keeps those apart deliberately. Some organizations (the FTC, the ICO) appear more than once because they serve a different purpose in each section, not because of a duplicate.
Regulator coverage is primarily US and UK. EU and Australia entries are limited to what supports the jurisdiction branches of our existing privacy generators, not a full EU/AU directory.
Need to act in writing right now? Use our free GDPR Rights Request Generator (EU/UK), GDPR Violation Report Generator (EU/UK), or Privacy Complaint Letter Generator (Australia).
Section 1 · Data Broker Directory
Where your information is listed for sale, and how to get it taken down. Removal is not permanent — most listings can reappear within 3-6 months as brokers re-aggregate public records, so treat this as ongoing maintenance, not a one-time fix.
See which data brokers are registered in California
What: The official public list of every data broker registered to operate in California, filterable by what data they collect and who they sell it to.
When to use: To see the scale of the data broker industry, or to check whether a specific broker you've found is actually registered.
Submit one deletion request that reaches every registered California data broker
What: This is genuinely the highest-value entry in this section. DROP has been live since 1 January 2026 and lets California residents submit a single deletion request that reaches every data broker registered in the state — over 600 of them — instead of opting out one by one. Brokers are required to process requests every 45 days starting 1 August 2026. Verify your residency through the California Identity Gateway, create a profile, and submit one request; status updates can take up to 90 days to appear. The actual request tool is at consumer.drop.privacy.ca.gov.
When to use: If you're a California resident, start here before opting out of individual broker sites one at a time.
Remove a specific listing from Whitepages
What: Whitepages' own removal form. Submit the exact URL of your listing (not a search-results page) and complete phone verification; most listings come down within 24-48 hours.
When to use: When your specific listing appears on Whitepages and you have the exact profile URL to submit.
Remove a specific listing from Spokeo
What: Spokeo's official opt-out page. No account or payment required — submit the listing URL and confirm by email; processed within 24-48 hours.
When to use: When your specific listing appears on Spokeo. Each listing needs its own separate opt-out.
Remove a specific listing from BeenVerified
What: BeenVerified's opt-out flow — search for your listing, request removal, then confirm via the verification email. Typically processed within 24-72 hours.
When to use: When your specific listing appears on BeenVerified.
Remove a specific listing from TruePeopleSearch
What: Copy the exact URL of your listing, submit it on the removal page, and confirm via the emailed link within 24 hours; removal follows within 72 hours.
When to use: When your specific listing appears on TruePeopleSearch.
Remove a specific listing from Radaris
What: Submit your name, city, state, and profile URL to request removal, then confirm via the emailed link; typically removed within 24 hours of confirmation.
When to use: When your specific listing appears on Radaris.
Remove your personal information from Google search results
What: Official free Google tool that monitors whether your phone number, home address, or email appears in search results and lets you request removal directly.
When to use: If you search your own name and find your mobile number or address publicly visible in results — a different problem from a data broker profile, since Google isn't the original source.
Want to know more? Read our full guide →Check whether your email or data has appeared in a known breach first
What: Also covered in Section 5 below, but worth checking here too — useful context before you start broker removal, since a breach can be a separate source of exposure from what data brokers have aggregated.
Want to know more? Read our full guide →Related Kibbo tool: Work through finding your listings, submitting removal requests, and tracking them until they actually come down with our free Data Broker Removal Checklist →
Section 2 · Privacy Regulators Directory
Who to complain to when a company has mishandled your data — mapped to the jurisdiction branches of our privacy generators below (US, UK, EU-by-country, Australia).
Report a US company for violating its own privacy policy or federal privacy rules
What: The FTC handles complaints about companies that violate US privacy laws, including unauthorized data sharing and deceptive data practices — under its Section 5 authority (see Section 3 below).
When to use: When a US company has misused your personal data or violated its own stated privacy policy.
Want to know more? Read our full guide →File the actual complaint with the FTC
What: The FTC's own complaint portal. The FTC doesn't resolve individual complaints directly, but reports feed its enforcement priorities.
When to use: After you've identified the issue and want it on record with the FTC.
Report a GDPR data protection violation in the UK
What: The UK's data protection regulator. Accepts complaints about GDPR violations, unlawful data processing, and companies that ignore data deletion requests.
When to use: When a company has mishandled your data, refused a deletion request under your right to erasure, or failed to notify you of a breach.
Want to know more? Read our full guide →Australian Privacy Complaint & Data Removal Resources
What: The three Australian paths for a privacy problem — the OAIC for a formal complaint against a company, Google's form for removing personal information from search results, and the eSafety Commissioner for image-based abuse.
When to use: Use this when a company has mishandled your personal data, your information appears in Google search results, or you need to report non-consensual imagery or serious cyberbullying. These are not equivalent legal mechanisms: the OAIC path is a formal legal complaint process under the Privacy Act 1988; Google's removal form is a discretionary company policy, not a legal right in Australia; and the eSafety Commissioner has genuine statutory takedown power for image-based abuse.
Official pathways:
OAIC — Lodge a Privacy Complaint (legal complaint) →
Google — Personal Information Removal Request (discretionary policy) →
eSafety Commissioner — Report Image-Based Abuse (statutory takedown power) →
EU GDPR Rights & Data Protection Authority Resources
What: The official EU pathways for enforcing GDPR rights — the EDPB directory listing every national Data Protection Authority (you always file with your own country's DPA, which coordinates with the company's lead authority via the One-Stop-Shop), plus direct links to major national DPAs: Spain's AEPD, France's CNIL, and Italy's Garante.
When to use: Use this to file a GDPR complaint, find your national Data Protection Authority, exercise your rights of access or erasure, or report a serious GDPR violation as a whistleblower.
Official pathways:
EDPB — Member DPAs Directory →
AEPD (Spain) →
CNIL (France) →
Garante (Italy) →
Section 3 · Privacy Laws Directory
Cross-cutting reference material for the whole block — the underlying legal text, kept brief and factual rather than tied to a specific tool.
Read the GDPR itself
What: The official full text of the GDPR via EUR-Lex, the EU's own legal database — used consistently across this site as the reference source for GDPR's actual text.
UK's version of GDPR
What: The official UK legislation that retained and adapted GDPR after Brexit, alongside the UK's own data protection framework.
California's privacy law, explained by the state itself
What: The California Attorney General's official CCPA/CPRA page — covers the right to know, delete, opt out of sale/sharing, correct, and limit use of sensitive data. CPRA amends the CCPA; it isn't a separate law.
The law behind the DROP tool in Section 1
What: The 2023 law requiring data brokers registered in California to implement an accessible, single-request deletion mechanism — this is what DROP (Section 1) actually implements.
The US federal authority behind FTC privacy enforcement
What: The FTC's own page explaining how it uses Section 5's prohibition on unfair or deceptive practices as its core authority over privacy and data security — the general federal backstop since the US has no single comprehensive federal privacy law.
Check if your state has its own privacy law
What: Independent, frequently updated tracker of all US state comprehensive privacy laws — which states have one, what rights they grant, and current status.
When to use: To check whether your state gives you rights to access, correct, or delete your data beyond what CCPA gives California residents.
Want to know more? Read our full guide →Request any company to delete all your personal data
What: Under UK/EU GDPR, a company must delete all personal data it holds about you within one month of a written request (extendable to three for complex requests). Under CCPA, California residents have a comparable right.
When to use: To remove your data from any company's database — send a written request stating you are exercising your right to erasure.
Want to know more? Read our full guide →Section 4 · Company Privacy Request Directory
The direct privacy-request portal for each company — not a generic help center — so you don't have to search for it. Verified as of 29 August 2026; a company is listed here only when its actual data-request page could be confirmed.
Request your data or exercise privacy rights with Meta (Facebook/Instagram)
What: Meta's dedicated privacy-rights request channel covering Facebook, Instagram, and Messenger — access, deletion, correction, and opt-out of targeted advertising.
Download or manage your Google data
What: Google's own account section for downloading your data (via Google Takeout) or deleting specific activity and data — requires signing in.
Request your personal information from Amazon
What: Amazon's direct data-request page — select the information you want, confirm via email, then download it through a secure link.
Manage your Microsoft privacy data
What: Microsoft's account privacy dashboard for viewing and clearing cloud-saved data. For requests beyond what the dashboard covers, Microsoft's privacy support form is at aka.ms/privacyresponse.
Request a copy of your Apple data
What: Apple's dedicated portal (launched for GDPR) to download a copy of the personal data Apple holds — sign in with your Apple ID and two-factor authentication.
Download your LinkedIn account data
What: LinkedIn's direct data-export settings page — select specific data categories (delivered within minutes) or your full archive (within 24 hours).
Exercise a privacy request with TikTok
What: TikTok's dedicated privacy request channel — access, correction, or deletion of the data it holds, plus a direct link to download your data from within the app.
Download your data archive from X (Twitter)
What: X's direct settings page for requesting a full archive of your account data — confirm your password, request the archive, and download it within 7 days of the email arriving.
Section 5 · Data Breach Directory
Scope note: this section is not a complete historical record and covers only the most recent, significant breaches — roughly the last 6-12 months as of this page's last update (29 August 2026). It needs periodic review; a breach that happened after that date won't yet appear here.
Check if your email or password was stolen in a data breach
What: The primary consumer tool for this entire section. Free database by security researcher Troy Hunt — enter your email or phone number to see if it appeared in any known breach.
When to use: After a suspicious login email, or every 6 months as a routine check. If your email appears, change that password immediately.
Want to know more? Read our full guide →Browse every breach loaded into Have I Been Pwned
What: A browsable, searchable list of every breach HIBP has loaded, including the data types exposed in each.
Suno (AI music platform) — ~55.3 million accounts
What: A breach that occurred in November 2025 but was only publicly disclosed and loaded into HIBP on 20-21 July 2026, exposing 55.3 million accounts. Exposed data included phone numbers and, for some users, Stripe purchase records with names, addresses, and partial payment card details (card type, expiry, last 4 digits). An attacker used compromised employee credentials to reach internal systems.
RingCentral — ~1.6 million accounts
What: The ShinyHunters extortion group breached RingCentral in July 2026 via a voice-phishing (vishing) attack on an employee, then published data on roughly 1.6 million accounts — names, email addresses, physical addresses, and phone numbers — after an extortion attempt, with disclosure in mid-August 2026.
Panera Bread — 5.1 million email addresses among 14 million exposed records
What: Occurred in January 2026, also attributed to ShinyHunters, via a compromised Microsoft Entra single-sign-on code. 14 million records were stolen — but that figure counts records, not unique individuals; HIBP confirmed 5.1 million unique email addresses were actually exposed, along with names, phone numbers, and physical addresses.
Related Kibbo tool: Know exactly what to do in the first 24 hours and beyond after a breach notification with our free Data Breach Response Checklist →