Privacy & Data

Report a breach, check if your email was leaked, request data deletion.

← All free resources

Data breaches happen constantly. Most affected users are never told directly. These tools let you check, report, and act — from finding out whether your email is already circulating to forcing a company to delete everything it holds on you.

Need to send a formal request? Draft a data deletion or GDPR erasure letter with our free letter generator.

Check if your email or password was stolen in a data breach

Have I Been Pwned haveibeenpwned.com →

What: Free database by security researcher Troy Hunt. Enter your email or phone number to see if it appeared in any known data breach from major companies.

When to use: After receiving a suspicious login email, or every 6 months as a routine check. If your email appears, change the password for that service immediately.

Want to know more? Read our full guide →

Remove your personal information from Google search results

What: Official free Google tool that monitors whether your phone number, home address or email appears in search results and lets you request removal directly.

When to use: If you search your own name and find your mobile number or address publicly visible in results.

Want to know more? Read our full guide →

Report a GDPR data protection violation in the UK

ICO — Information Commissioner's Office ico.org.uk/make-a-complaint →

What: The UK's data protection regulator. Accepts complaints about GDPR violations, unlawful data processing, and companies that ignore data deletion requests.

When to use: When a company has mishandled your data, refused a deletion request under your right to erasure, or failed to notify you of a breach.

Want to know more? Read our full guide →

Report a privacy violation to the US federal regulator

FTC Privacy Complaints reportfraud.ftc.gov →

What: The FTC handles complaints about companies that violate US privacy laws, including unauthorized data sharing and deceptive data practices.

When to use: When a US company has misused your personal data or violated its own stated privacy policy.

Want to know more? Read our full guide →

Request any company to delete all your personal data (GDPR)

What: Under UK/EU GDPR, any company must delete all personal data they hold about you within 30 days of a written request. Under CCPA, California residents have the same right.

When to use: To remove your data from any company's database. Send a written request to their Data Protection Officer stating "I am exercising my right to erasure under Article 17 of the UK GDPR."

Want to know more? Read our full guide →

Check if your state has its own privacy law

IAPP — US State Privacy Legislation Tracker iapp.org/resources/article/us-state-privacy-legislation-tracker →

What: Independent, frequently updated tracker of all US state comprehensive privacy laws — which states have one, what rights they grant, and current status.

When to use: To check whether your state gives you rights to access, correct, or delete your data beyond what CCPA gives California residents.

Want to know more? Read our full guide →

Australian Privacy Complaint & Data Removal Resources

OAIC, Google Removal & the eSafety Commissioner (Australia) oaic.gov.au →

What: The three Australian paths for a privacy problem — the OAIC for a formal complaint against a company, Google's form for removing personal information from search results, and the eSafety Commissioner for image-based abuse.

When to use: Use this when a company has mishandled your personal data, your information appears in Google search results, or you need to report non-consensual imagery or serious cyberbullying. These are not equivalent legal mechanisms: the OAIC path is a formal legal complaint process under the Privacy Act 1988; Google's removal form is a discretionary company policy, not a legal right in Australia; and the eSafety Commissioner has genuine statutory takedown power for image-based abuse.

Official pathways:
OAIC — Lodge a Privacy Complaint (legal complaint) →
Google — Personal Information Removal Request (discretionary policy) →
eSafety Commissioner — Report Image-Based Abuse (statutory takedown power) →

Not sure which path? Run the free checklist → Want to know more? Read our full guide → Want to know more? Read our full guide →

EU GDPR Rights & Data Protection Authority Resources

European Data Protection Board (EDPB) — Member DPAs Directory edpb.europa.eu — member DPAs →

What: The official EU pathways for enforcing GDPR rights — the EDPB directory listing every national Data Protection Authority (you always file with your own country's DPA, which coordinates with the company's lead authority via the One-Stop-Shop), plus direct links to major national DPAs: Spain's AEPD, France's CNIL, and Italy's Garante.

When to use: Use this to file a GDPR complaint, find your national Data Protection Authority, exercise your rights of access or erasure, or report a serious GDPR violation as a whistleblower.

Official pathways:
EDPB — Member DPAs Directory →
AEPD (Spain) →
CNIL (France) →
Garante (Italy) →

Not sure which DPA, or whether your deadline actually passed? Run the free checklist → What data does a company hold on you? (Right of Access) — Read our full guide → Ask a company to delete your data (Right to Erasure) — Read our full guide → File a GDPR complaint, step by step — Read our full guide → Which Data Protection Authority to contact — Read our full guide → Report a GDPR violation (whistleblowers & consumers) — Read our full guide →