Everything Kibbo has for a privacy problem — in one place

3 generators, 6 templates, 9 free checklists, 5 directory sections, and 35 guides — covering the US, UK, EU, and Australia, all indexed here.

Start here

The two situations most people land on this page for — go straight to the right sequence.

Tools by type

Every generator, template and checklist Kibbo has built for privacy rights requests, breaches, data brokers, and tracking, grouped by what it actually does.

Generators (3)

Answer a few questions, get a formal letter — to the company, or to the correct data protection regulator for your country.

Generator · $4.60

Privacy Rights Request Generator

A formal request to exercise a privacy right — access, deletion, correction, objection to AI training use, or restriction of processing — addressed to any company.

$4.60 per letter Open tool →
Generator · $4.60

Privacy Breach & Compliance Complaint Generator

A formal complaint to a company about a data breach or a cookie/tracking consent violation — the required first step before escalating to a regulator.

$4.60 per letter Open tool →
Generator · $4.60

Privacy Regulator Complaint Generator

A formal complaint to the correct data protection authority for your country, after a company has failed to resolve the issue directly.

$4.60 per letter Open tool →

Templates (6)

Paid, downloadable — for building the evidence a rights request, a complaint, or a breach actually needs.

Template · $5.90

Personal Data Rights Request Evidence Pack

Document any personal data rights request — access, deletion, correction, objection, or restriction — in one pack. Covers the right being exercised, identity verification, response tracking against your deadline, and an escalation-ready evidence checklist. PDF + Word.

Template · $5.90

Privacy Complaint & Escalation Evidence Pack

Build a complete file for a privacy dispute that goes beyond a single rights request — incident overview, communications timeline, deadlines the company made and missed, remedy requested, and a 3-stage escalation tracker up to your data protection authority. PDF + Word.

Template · $5.90

Personal Data Breach Incident Record

Document a security incident that may have exposed your personal data — what data was involved, what the company disclosed, actions you've taken (password changes, fraud alerts), and ongoing monitoring for misuse. PDF + Word.

Template · $5.90

Data Sharing & Third-Party Disclosure Tracker

Log every time a company shares your personal data with a third party — recipient, purpose, legal basis claimed, and source — with an auto-calculated summary flagging disclosures with no stated purpose or basis. Excel.

Template · $5.90

Privacy Rights Request Tracker

Manage multiple privacy rights requests at once — access, deletion, correction, objection, restriction — with auto-calculated days remaining per deadline and a summary that flags overdue requests automatically. Excel.

Template · $5.90

Privacy Policy Change Comparison Workbook

Compare two versions of a privacy policy side by side across 13 criteria — data collected, retention, third parties, rights listed — to spot exactly what changed between updates. Excel.

Checklists (9)

Free, interactive — before you sign up, after a breach, or when you need to work out which authority actually handles your problem.

Checklist

Privacy Audit Checklist

Check what to share before you sign up, what to change at account creation, and the ongoing habits that keep your privacy settings from drifting back open.

⏱ 10 min✓ 11 checksStart →
Checklist

Data Broker Removal Checklist

Find where your personal information is listed, submit removal requests the right way, and track them until the listings actually come down.

⏱ 20 min✓ 11 checksStart →
Checklist

AI Privacy Checklist

Find the AI/ML training opt-out settings that actually exist across the platforms you use, and submit requests where no global setting does the job.

⏱ 12 min✓ 9 checksStart →
Checklist For Auditing a Website

Cookie Banner Compliance Checklist

Evaluate a website's cookie banner for real compliance — reject-vs-accept parity, pre-checked boxes, and whether tracking starts regardless of your choice.

⏱ 8 min✓ 10 checksStart →
Checklist

Data Breach Response Checklist

The first 24 hours after a breach notification, what to do if financial data or login credentials were involved, and what to document for follow-up.

⏱ 10 min✓ 13 checksStart →
Checklist

App Permissions Checklist

Review which apps have location, microphone, and camera access, and revoke what they don't actually need to function.

⏱ 10 min✓ 11 checksStart →
Checklist

Public Profile Exposure Checklist

Search yourself, check what your social accounts expose publicly, and decide what's actually worth acting on.

⏱ 15 min✓ 12 checksStart →
Checklist

Privacy Breach? Which Path to Take (Australia)

Work out the right path — an OAIC complaint, a Google search-results removal, or the eSafety Commissioner — what each can and can't do, and the steps for each.

⏱ 10 min✓ 12 checksStart →
Checklist

Which DPA Do I Contact? + Is My Deadline Actually Overdue? (EU)

File with your own country's DPA (never the company's), and check whether a GDPR deadline is genuinely overdue once you account for a valid one-month extension notice.

⏱ 5 min✓ 7 checksStart →

Directory, grouped

A quick preview of what's in each section of the full Privacy & Data directory — expand a section or click through to see every entry.

Data Broker Directory 9 resources

Where your information is listed for sale, and how to get it taken down — including California's DROP platform and direct opt-out links for the highest-traffic people-search sites.

See all Data Broker Directory →
Privacy Regulators Directory 5 resources

Who to complain to when a company has mishandled your data — mapped to the jurisdiction branches of our privacy generators (US, UK, EU-by-country, Australia).

See all Privacy Regulators Directory →
Privacy Laws Directory 7 resources

Cross-cutting reference material for the whole block — GDPR, UK GDPR/DPA 2018, CCPA/CPRA, the California Delete Act, FTC Act Section 5, and more.

See all Privacy Laws Directory →
Company Privacy Request Directory 8 resources

The direct privacy-request portal for Meta, Google, Amazon, Microsoft, Apple, LinkedIn, TikTok, and X — not a generic help center, so you don't have to search for it.

See all Company Privacy Request Directory →
Data Breach Directory 5 resources

Have I Been Pwned, plus the most recent significant breaches — kept to roughly the last 6-12 months rather than a complete historical record, and flagged for periodic review.

See all Data Breach Directory →

Guides, by region

35 in-depth guides — kept separate by jurisdiction, never merged, since privacy law differs sharply by region. A handful of guides apply globally and get their own tab rather than being forced into one country.

Practical CCPA/CPRA Guide: How to Make a Covered California Business Reveal, Delete and Limit Your Personal Information

California consumers have powerful privacy rights, but they don't apply to every company. How to make a request that's complete, verifiable and trackable.

How to Stop the Sale of Your Geolocation Data: The FTC's Data-Broker Enforcement Precedents

Recent FTC orders show that selling sensitive location data can trigger serious federal enforcement. What that means, and how to lock down app permissions.

Your Medical History in Danger: How the FTC Health Breach Notification Rule Protects Consumers

A health app doesn't need to be a hospital to fall under the FTC's Health Breach Notification Rule. What that covers, and what consumers should do.

How to Delete Your Information from People-Search and Data-Broker Services Under California's Delete Act

California's Delete Act moved from legislation to an operational statewide deletion mechanism. What Californians can actually do in 2026.

Children's Online Privacy Rights: How to Address Tracking and Profiling of Kids Under COPPA

COPPA gives parents important rights over data collected online from children under 13. What it actually covers, and what it doesn't.

Your State Probably Has Its Own Privacy Law Now — Not Just California's CCPA

As of 2026, ~20 US states have their own comprehensive privacy law granting rights beyond what CCPA gives California residents.

How to Report a US Company for Violating Its Own Privacy Policy (And Why the FTC Actually Takes This Seriously)

A company's privacy policy says one thing and it does another. Section 5 of the FTC Act is the federal backstop, even without a single comprehensive US privacy law.

Subject Access Request (SAR) Guide: How to Get a UK Organisation to Give You the Personal Data It Holds

A well-structured SAR doesn't guarantee every document, but it gives you a clear legal route to your personal data.

Are They Scanning Your Face? UK Rights Against Facial Recognition in Shops and Retail

A camera that analyses faces to identify people is a different privacy proposition from ordinary CCTV. What UK law requires.

The End of Spam Calls in the UK: How to Use PECR to Report Unwanted Marketing

The rules are stronger than just "register with the TPS". What UK law actually requires for marketing calls.

Data-Breach Compensation in the UK: When Distress Can Support a Claim

A data breach doesn't automatically create a payout. But UK law recognises non-material damage such as distress.

Illegal Cookie Walls? What UK Websites Must Do to Obtain Valid Consent

UK privacy rules don't treat scrolling, silence or a pre-ticked choice as valid consent for non-essential cookies.

How to Report a GDPR Violation to the ICO When a Company Ignores Your Right to Erasure

You asked a company to delete your data and a month went by. UK data protection law gives you a real escalation route.

Consent or Pay Cookies in the EU: What the EDPB Says About Fair Choice in 2026

A website gives you two choices: accept behavioural advertising or pay. What the EDPB has actually said about that model.

How to Object to AI Training With Your Personal Data: GDPR Rights and the EU AI Act

The answer isn't a universal AI Act opt-out. The correct route depends on the GDPR legal basis and the service's actual processing.

How to Complain About a Multinational Tech Company Under the GDPR One-Stop-Shop

A tech company may be headquartered in Ireland while you live elsewhere. How EU cross-border GDPR complaints actually get coordinated.

The EU Right to Be Forgotten: How to Request Delisting from Google, Bing and Other Search Engines

Usually a right to have search results delisted — not a power to erase the original webpage from the internet.

Where Does Your Data Go? How to Audit an EU–U.S. Data Privacy Framework Transfer

A US company can process EU personal data lawfully under the DPF only if it's a certified organisation. How to check.

How to File a GDPR Complaint: A Step-by-Step Enforcement Guide

A free, formal GDPR complaint can trigger a real government investigation — backed by fines that can reach 4% of global turnover.

Which Data Protection Authority Should I Contact? Navigating the EU DPA Grid

Under the GDPR One-Stop-Shop you always file with your own country's DPA — never the company's — and it coordinates from there.

How to Ask a Company to Delete Your Data: Master the Right to Erasure

Article 17 GDPR — what it forces a company to delete, the one-month deadline (extendable to three), and the exceptions that can block it.

Right of Access Under GDPR: How to Find Out Exactly What Data a Company Has on You

A Subject Access Request (Article 15) gets you a complete copy of the data a company holds — here's how to make one that works.

How to Report a GDPR Violation: A Guide for Whistleblowers and Consumers

Reporting a serious GDPR violation is a protected public-interest act in the EU — here's the actual process.

Australia's Privacy Reform: What Consumers Actually Gain from the New Privacy Rules

One major claim needs correcting: the small-business exemption hasn't simply disappeared. What's actually in force in 2026.

Facial Recognition and ID Scanners in Australian Venues: What the APPs Actually Require

A venue can sometimes require identity verification, but that doesn't mean it can collect and retain biometric data however it wants.

How the Australian Notifiable Data Breaches Scheme Works After a Cyberattack

Your bank, insurer or telco says your data was exposed. What the NDB scheme actually requires — and what it doesn't guarantee.

Coles, Flybuys and Woolworths Rewards: How Australian Consumers Can Challenge Loyalty-Data Profiling

Your supermarket loyalty card can reveal far more than points earned. What Australian regulators have found, and what to check.

De-identification in Australia: How to Understand the Difference Between Deleting Data and Breaking the Identity Link

Deleting a name is not automatically de-identification. What Australian privacy law actually requires.

How to Make a Privacy Complaint to the OAIC

The Privacy Act 1988 and its 13 Australian Privacy Principles give you a free, formal complaint route — here's how to use it.

How to Remove Your Personal Information from Google Australia

Australia has no GDPR-style "right to be forgotten" — but two real pathways exist, and here's how each actually works.

What to Do If You've Been Scammed in Australia: Immediate Action Steps

Just sent money to a scammer or entered your details into a fake portal? The steps that actually matter, in order.

How to Report an Online Scam to Scamwatch Australia

Scamwatch (the ACCC's National Anti-Scam Centre) is a national intelligence hub — here's what reporting to it actually does.

How to Check If Your Email or Password Was Exposed in a Data Breach (Have I Been Pwned, Explained Properly)

A strong, unique password doesn't protect you from a breach you had no part in. How to actually use HIBP correctly.

How to Remove Your Phone Number and Address from Google Search (And What This Tool Doesn't Actually Delete)

Google's Results About You cuts the visibility of your phone number and home address — but doesn't touch the source site.

How to Request Any Company Delete Your Personal Data (GDPR Right to Erasure and CCPA, Explained Separately)

You have a legal right to ask a company to delete what it holds about you — but the right, and the deadline, depend on where you live.

Browse the full Directory → See all Checklists → See all Templates →