Privacy Rights Request Generator
A formal request to exercise a privacy right — access, deletion, correction, objection to AI training use, or restriction of processing — addressed to any company.
KIBBO · PRIVACY & DATA
3 generators, 6 templates, 9 free checklists, 5 directory sections, and 35 guides — covering the US, UK, EU, and Australia, all indexed here.
The two situations most people land on this page for — go straight to the right sequence.
Exercising a right
After a breach
Every generator, template and checklist Kibbo has built for privacy rights requests, breaches, data brokers, and tracking, grouped by what it actually does.
Answer a few questions, get a formal letter — to the company, or to the correct data protection regulator for your country.
A formal request to exercise a privacy right — access, deletion, correction, objection to AI training use, or restriction of processing — addressed to any company.
A formal complaint to a company about a data breach or a cookie/tracking consent violation — the required first step before escalating to a regulator.
A formal complaint to the correct data protection authority for your country, after a company has failed to resolve the issue directly.
Paid, downloadable — for building the evidence a rights request, a complaint, or a breach actually needs.
Document any personal data rights request — access, deletion, correction, objection, or restriction — in one pack. Covers the right being exercised, identity verification, response tracking against your deadline, and an escalation-ready evidence checklist. PDF + Word.
Build a complete file for a privacy dispute that goes beyond a single rights request — incident overview, communications timeline, deadlines the company made and missed, remedy requested, and a 3-stage escalation tracker up to your data protection authority. PDF + Word.
Document a security incident that may have exposed your personal data — what data was involved, what the company disclosed, actions you've taken (password changes, fraud alerts), and ongoing monitoring for misuse. PDF + Word.
Log every time a company shares your personal data with a third party — recipient, purpose, legal basis claimed, and source — with an auto-calculated summary flagging disclosures with no stated purpose or basis. Excel.
Manage multiple privacy rights requests at once — access, deletion, correction, objection, restriction — with auto-calculated days remaining per deadline and a summary that flags overdue requests automatically. Excel.
Compare two versions of a privacy policy side by side across 13 criteria — data collected, retention, third parties, rights listed — to spot exactly what changed between updates. Excel.
Free, interactive — before you sign up, after a breach, or when you need to work out which authority actually handles your problem.
Check what to share before you sign up, what to change at account creation, and the ongoing habits that keep your privacy settings from drifting back open.
ChecklistFind where your personal information is listed, submit removal requests the right way, and track them until the listings actually come down.
ChecklistFind the AI/ML training opt-out settings that actually exist across the platforms you use, and submit requests where no global setting does the job.
Evaluate a website's cookie banner for real compliance — reject-vs-accept parity, pre-checked boxes, and whether tracking starts regardless of your choice.
ChecklistThe first 24 hours after a breach notification, what to do if financial data or login credentials were involved, and what to document for follow-up.
ChecklistReview which apps have location, microphone, and camera access, and revoke what they don't actually need to function.
ChecklistSearch yourself, check what your social accounts expose publicly, and decide what's actually worth acting on.
ChecklistWork out the right path — an OAIC complaint, a Google search-results removal, or the eSafety Commissioner — what each can and can't do, and the steps for each.
ChecklistFile with your own country's DPA (never the company's), and check whether a GDPR deadline is genuinely overdue once you account for a valid one-month extension notice.
A quick preview of what's in each section of the full Privacy & Data directory — expand a section or click through to see every entry.
Where your information is listed for sale, and how to get it taken down — including California's DROP platform and direct opt-out links for the highest-traffic people-search sites.
See all Data Broker Directory →Who to complain to when a company has mishandled your data — mapped to the jurisdiction branches of our privacy generators (US, UK, EU-by-country, Australia).
See all Privacy Regulators Directory →Cross-cutting reference material for the whole block — GDPR, UK GDPR/DPA 2018, CCPA/CPRA, the California Delete Act, FTC Act Section 5, and more.
See all Privacy Laws Directory →The direct privacy-request portal for Meta, Google, Amazon, Microsoft, Apple, LinkedIn, TikTok, and X — not a generic help center, so you don't have to search for it.
See all Company Privacy Request Directory →Have I Been Pwned, plus the most recent significant breaches — kept to roughly the last 6-12 months rather than a complete historical record, and flagged for periodic review.
See all Data Breach Directory →35 in-depth guides — kept separate by jurisdiction, never merged, since privacy law differs sharply by region. A handful of guides apply globally and get their own tab rather than being forced into one country.
California consumers have powerful privacy rights, but they don't apply to every company. How to make a request that's complete, verifiable and trackable.
Recent FTC orders show that selling sensitive location data can trigger serious federal enforcement. What that means, and how to lock down app permissions.
A health app doesn't need to be a hospital to fall under the FTC's Health Breach Notification Rule. What that covers, and what consumers should do.
California's Delete Act moved from legislation to an operational statewide deletion mechanism. What Californians can actually do in 2026.
COPPA gives parents important rights over data collected online from children under 13. What it actually covers, and what it doesn't.
As of 2026, ~20 US states have their own comprehensive privacy law granting rights beyond what CCPA gives California residents.
A company's privacy policy says one thing and it does another. Section 5 of the FTC Act is the federal backstop, even without a single comprehensive US privacy law.
A well-structured SAR doesn't guarantee every document, but it gives you a clear legal route to your personal data.
A camera that analyses faces to identify people is a different privacy proposition from ordinary CCTV. What UK law requires.
The rules are stronger than just "register with the TPS". What UK law actually requires for marketing calls.
A data breach doesn't automatically create a payout. But UK law recognises non-material damage such as distress.
UK privacy rules don't treat scrolling, silence or a pre-ticked choice as valid consent for non-essential cookies.
You asked a company to delete your data and a month went by. UK data protection law gives you a real escalation route.
A website gives you two choices: accept behavioural advertising or pay. What the EDPB has actually said about that model.
The answer isn't a universal AI Act opt-out. The correct route depends on the GDPR legal basis and the service's actual processing.
A tech company may be headquartered in Ireland while you live elsewhere. How EU cross-border GDPR complaints actually get coordinated.
Usually a right to have search results delisted — not a power to erase the original webpage from the internet.
A US company can process EU personal data lawfully under the DPF only if it's a certified organisation. How to check.
A free, formal GDPR complaint can trigger a real government investigation — backed by fines that can reach 4% of global turnover.
Under the GDPR One-Stop-Shop you always file with your own country's DPA — never the company's — and it coordinates from there.
Article 17 GDPR — what it forces a company to delete, the one-month deadline (extendable to three), and the exceptions that can block it.
A Subject Access Request (Article 15) gets you a complete copy of the data a company holds — here's how to make one that works.
Reporting a serious GDPR violation is a protected public-interest act in the EU — here's the actual process.
One major claim needs correcting: the small-business exemption hasn't simply disappeared. What's actually in force in 2026.
A venue can sometimes require identity verification, but that doesn't mean it can collect and retain biometric data however it wants.
Your bank, insurer or telco says your data was exposed. What the NDB scheme actually requires — and what it doesn't guarantee.
Your supermarket loyalty card can reveal far more than points earned. What Australian regulators have found, and what to check.
Deleting a name is not automatically de-identification. What Australian privacy law actually requires.
The Privacy Act 1988 and its 13 Australian Privacy Principles give you a free, formal complaint route — here's how to use it.
Australia has no GDPR-style "right to be forgotten" — but two real pathways exist, and here's how each actually works.
Just sent money to a scammer or entered your details into a fake portal? The steps that actually matter, in order.
Scamwatch (the ACCC's National Anti-Scam Centre) is a national intelligence hub — here's what reporting to it actually does.
A strong, unique password doesn't protect you from a breach you had no part in. How to actually use HIBP correctly.
Google's Results About You cuts the visibility of your phone number and home address — but doesn't touch the source site.
You have a legal right to ask a company to delete what it holds about you — but the right, and the deadline, depend on where you live.