A company is selling or misusing your data

A company may be misusing your data if it sells, shares, collects, keeps, or uses personal information in ways that conflict with its notices, your consent, or privacy law. The available remedies depend on where you live, the type of information involved, the company’s conduct, and whether the issue concerns marketing,

Jurisdiction
General — United States, England & Wales, Canada, Australia
Topic
Privacy
Last updated
Sep 26, 2026
Editorial status
Not yet reviewed by a licensed attorney

General legal information, published for everyone. It does not apply the law to anyone’s particular situation and is not legal advice. Laws change and differ by place; check the primary sources below.

Quick summary

  • A company may be misusing your data if it sells, shares, collects, keeps, or uses personal information in ways that conflict with its notices, your consent, or privacy law.
  • The available remedies depend on where you live, the type of information involved, the company’s conduct, and whether the issue concerns marketing, a data breach, profiling, or identity theft.

What it means

A company may be misusing your data if it sells, shares, collects, keeps, or uses personal information in ways that conflict with its notices, your consent, or privacy law. The available remedies depend on where you live, the type of information involved, the company’s conduct, and whether the issue concerns marketing, a data breach, profiling, or identity theft.

How the law works

How the law usually works

Privacy laws generally regulate personal information that identifies, relates to, or can reasonably be linked to you. This can include your name, contact details, location, browsing history, purchase records, financial information, health information, and online identifiers.

Common legal questions include:

  • What did the company tell you? Privacy notices, terms of service, cookie banners, consent forms, and marketing preferences may show what uses were disclosed.
  • What legal basis or permission existed? Some laws require consent for particular uses. Others allow processing for contracts, legal obligations, legitimate interests, or business purposes.
  • Was the information shared or sold? “Sale” may have a broader meaning than receiving money. Some laws include sharing data for targeted advertising, analytics, or other valuable consideration.
  • Was the data reasonably protected? A company may face regulatory action or civil claims if it failed to use appropriate security measures and your information was exposed.
  • Do special rules apply? Health, financial, children’s, biometric, employment, telecommunications, and credit information often receive additional protection.

Possible rights include access to copies of data, correction of inaccurate information, deletion in some circumstances, limits on targeted advertising or certain processing, withdrawal of consent, and information about third parties receiving the data. These rights are not unlimited. Companies may retain information for legal, security, fraud-prevention, accounting, or other permitted reasons.

A privacy violation does not automatically create a right to money damages. Remedies may instead include stopping a practice, deleting or correcting information, changing a privacy notice, regulatory penalties, compensation for proven loss, or protection against further misuse.

Common processes

  1. Preserve evidence. People commonly save privacy notices, account settings, consent screens, emails, advertisements, data-access responses, screenshots, and relevant dates. They may record the company name, website, app, product, suspected recipient, and how they learned about the use.
  1. Reduce further sharing. Common measures include changing privacy and advertising settings, withdrawing optional permissions, closing linked accounts, changing passwords, enabling multifactor authentication, and removing unnecessary app access. Closing an account may not delete data already held.
  1. Contact the company. A written privacy request often identifies the information involved and asks what was collected, where it came from, why it was used, who received it, how long it will be kept, and whether it was sold or used for targeted advertising. Depending on local law, people may request access, correction, deletion, or an opt-out.
  1. Keep the response and check the result. Companies may verify identity, ask for clarification, deny part of a request, or explain an exception. People commonly compare the response with the company’s notice and keep records of any incomplete response or continued marketing.
  1. Report the issue to a regulator. A privacy or consumer-protection authority may accept complaints, investigate patterns of misconduct, and seek orders or penalties. A regulator usually does not act as your private lawyer or guarantee compensation.
  1. Address practical harm. If financial or identity information was exposed, people commonly contact banks, card issuers, credit-reporting agencies, insurers, or relevant government identity-theft services. They may monitor accounts, replace credentials, and dispute unauthorized transactions.
  1. Consider a legal claim. Depending on local law, possible claims may involve breach of privacy, breach of contract, negligence, consumer-protection legislation, breach of confidence, or statutory privacy rights. Evidence of actual loss, distress, unauthorized disclosure, or a repeated practice can matter.

Deadlines and time limits

Deadlines vary substantially. Privacy-access or deletion requests commonly receive a response within about 30 days, one month, or a similar statutory period, sometimes with an extension for complex requests. Companies may have to notify regulators of certain serious breaches within a short period, often around 72 hours after becoming aware, while notice to affected people may follow a different standard.

Regulatory complaints and court claims have separate limitation periods. Depending on the claim and place, a civil limitation period may commonly range from one to six years, with shorter periods possible for particular statutory claims. Consumer agencies may also impose complaint-filing windows or require that you first contact the business.

Some laws use special deadlines for credit reporting, electronic communications, government complaints, or arbitration. Confirm the applicable period with the relevant regulator, court, or a licensed attorney where you live. A complaint to a regulator does not always stop the limitation period for a private lawsuit.

Documents that usually matter

  • The company’s privacy policy and earlier versions, if available
  • Terms of service, consent forms, cookie notices, and account settings
  • Emails, texts, advertisements, call records, and support tickets
  • Data-access, deletion, correction, or opt-out requests and responses
  • Screenshots showing settings, disclosures, or suspected data sharing
  • Breach notices and records of when you received them
  • Bank, credit, medical, or other records showing resulting harm
  • Evidence of lost money, identity theft, unwanted contact, or distress
  • A timeline identifying events, people contacted, and company responses

How it differs by jurisdiction

United States. There is no single comprehensive federal privacy law for most private-sector data. The Federal Trade Commission may challenge unfair or deceptive privacy practices under the Federal Trade Commission Act. Sector laws can apply to health, financial, children’s, credit, and communications data. California’s Consumer Privacy Act, as amended by the California Privacy Rights Act, provides rights that can include access, deletion, correction, and opting out of certain sales or sharing. Other states have different rights, definitions, exemptions, and private-action rules.

England and Wales. The UK GDPR and Data Protection Act 2018 generally regulate lawful, fair, and transparent processing, security, retention, and individual rights. The Information Commissioner’s Office can investigate complaints and take enforcement action. Direct marketing and certain electronic communications may also be governed by the Privacy and Electronic Communications Regulations 2003. Compensation claims and regulatory complaints are separate routes.

Canada. The federal Personal Information Protection and Electronic Documents Act (PIPEDA) commonly applies to private-sector organizations in commercial activities, subject to substantially similar provincial laws in some provinces and special rules for certain sectors. The Office of the Privacy Commissioner of Canada investigates many complaints. Provincial privacy, health, consumer, and data-breach laws may change the analysis and available remedies.

Australia. The Privacy Act 1988 and Australian Privacy Principles regulate many covered organizations, although exemptions and thresholds matter. The Office of the Australian Information Commissioner handles privacy complaints and the Notifiable Data Breaches scheme. State and territory laws may apply to public bodies, health information, surveillance, or other activities outside the federal scheme.

When people consult a lawyer

A lawyer may be useful when sensitive information was exposed, the company refuses a substantial request, you suffered financial loss or serious distress, the conduct affects many people, or a lawsuit or arbitration is being considered. Advice can also help with preserving evidence, interpreting a release or arbitration clause, identifying the correct defendant, and calculating a limitation period.

If the misuse includes stalking, threats, blackmail, or an immediate safety risk, contact emergency services first. A lawyer or victim-support service may help with protective measures and related reporting.

Primary sources

  • StatuteFederal Trade Commission Act, section 5, and Federal Trade Commission privacy and security guidanceUnited States (federal)United States (official FTC materials)
  • RegulationCalifornia Consumer Privacy Act, as amended by the California Privacy Rights Act, and California Privacy Protection Agency regulationsUnited States (federal)California, United States (official California sources)
  • RegulationUK General Data Protection Regulation and Data Protection Act 2018England & WalesEngland and Wales (official legislation)
  • RegulationPrivacy and Electronic Communications Regulations 2003England & WalesUnited Kingdom (official legislation)
  • Official sourceInformation Commissioner’s Office guidance on individual rights, complaints, direct marketing, and personal-data breachesEngland & WalesEngland and Wales (official ICO materials)
  • StatutePersonal Information Protection and Electronic Documents Act and Office of the Privacy Commissioner complaint guidanceCanadaCanada (official federal sources)
  • StatutePrivacy Act 1988, Australian Privacy Principles, and Notifiable Data Breaches schemeAustraliaAustralia (official legislation and OAIC materials)

Links go to official or widely used free sources. Check that a source is current before relying on it. Browse all sources →

Last updated
Sep 26, 2026
Jurisdiction
General — United States, England & Wales, Canada, Australia
Written by
House Legal editorial (AI-generated, earlier format)