eraser

Privacy authorities

If a broker blows past the statutory deadline or refuses without a valid basis, you can escalate to the regulator for your country. eraser export names the one for your profile’s country and lists the brokers that are overdue.

This list is not exhaustive — it covers the jurisdictions with a practical complaint route — and links move. If an entry is wrong or your country is missing, please open an issue or a pull request.

European Union / EEA

CountryAuthorityWebsite
AustriaÖsterreichische Datenschutzbehörde (Austrian Data Protection Authority) (DSB)https://www.dsb.gv.at
BelgiumGegevensbeschermingsautoriteit / Autorité de la protection des données (GBA/APD)https://www.gegevensbeschermingsautoriteit.be
BulgariaCommission for Personal Data Protection (CPDP)https://www.cpdp.bg
CroatiaAgencija za zaštitu osobnih podataka (AZOP)https://azop.hr
CyprusOffice of the Commissioner for Personal Data Protectionhttps://www.dataprotection.gov.cy
Czech RepublicÚřad pro ochranu osobních údajů (Office for Personal Data Protection) (ÚOOÚ)https://www.uoou.gov.cz
DenmarkDatatilsynethttps://www.datatilsynet.dk
EstoniaAndmekaitse Inspektsioon (Data Protection Inspectorate) (AKI)https://www.aki.ee
FinlandOffice of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)https://tietosuoja.fi
FranceCommission Nationale de l'Informatique et des Libertés (CNIL)https://www.cnil.fr
GermanyDie Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
For a complaint against a private company (a data broker), a resident normally goes to the supervisory authority of their own federal state (Land), not the federal BfDI. The BfDI site links the list of the 16 Landesdatenschutzbehörden.
https://www.bfdi.bund.de
GreeceHellenic Data Protection Authority (HDPA)https://www.dpa.gr
HungaryNemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)https://www.naih.hu
IrelandData Protection Commission (DPC)https://www.dataprotection.ie
ItalyGarante per la protezione dei dati personalihttps://www.garanteprivacy.it
LatviaDatu valsts inspekcija (Data State Inspectorate) (DVI)https://www.dvi.gov.lv
LithuaniaValstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate) (VDAI)https://vdai.lrv.lt
LuxembourgCommission Nationale pour la Protection des Données (CNPD)https://cnpd.public.lu
MaltaOffice of the Information and Data Protection Commissioner (IDPC)https://idpc.org.mt
NetherlandsAutoriteit Persoonsgegevens (AP)https://www.autoriteitpersoonsgegevens.nl
PolandUrząd Ochrony Danych Osobowych (UODO)https://uodo.gov.pl
PortugalComissão Nacional de Proteção de Dados (CNPD)https://www.cnpd.pt
RomaniaAutoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)https://www.dataprotection.ro
SlovakiaÚrad na ochranu osobných údajov Slovenskej republiky (ÚOOÚ)https://dataprotection.gov.sk
SloveniaInformacijski pooblaščenec (Information Commissioner) (IP-RS)https://www.ip-rs.si
SpainAgencia Española de Protección de Datos (AEPD)https://www.aepd.es
SwedenIntegritetsskyddsmyndigheten (Authority for Privacy Protection) (IMY)https://www.imy.se
IcelandPersónuvernd (Data Protection Authority)
The authority's site moved onto Iceland's national portal island.is; www.personuvernd.is redirects there.
https://island.is/s/personuvernd
LiechtensteinDatenschutzstelle (Data Protection Authority) (DSS)https://www.datenschutzstelle.li
NorwayDatatilsynet (Norwegian Data Protection Authority)https://www.datatilsynet.no

United Kingdom

CountryAuthorityLawWebsite
United KingdomInformation Commissioner's Office (ICO)
Post-Brexit; the UK GDPR mirrors the EU GDPR's right to erasure.
UK GDPR / Data Protection Act 2018https://ico.org.uk/make-a-complaint/

North America

CountryAuthorityLawWebsite
United States (federal)Federal Trade Commission (FTC)
The catch-all US regulator for data brokers, regardless of which state you live in. It doesn't act on individual complaints one by one, but complaints feed its enforcement and it has repeatedly sued data brokers.
FTC Act §5 (unfair or deceptive practices)https://reportfraud.ftc.gov
United States (California)California Privacy Protection Agency (CPPA)
Runs the DELETE Act data-broker registry and (from 2026) the DROP one-request deletion service. Complaints also go to the California Attorney General: oag.ca.gov/privacy/ccpa.
CCPA / CPRAhttps://cppa.ca.gov/
United States (other states)Your state Attorney General's consumer-protection office
Most US state privacy laws are enforced only by the state AG, with no individual complaint portal - but the AG's consumer-protection division takes complaints. Texas and Oregon also run data-broker registries.
State privacy acts (VA, CO, CT, UT, TX, OR, MT, ...)https://www.usa.gov/state-attorney-general
CanadaOffice of the Privacy Commissioner of Canada (OPC)
Quebec, British Columbia and Alberta have their own provincial commissioners for provincially-regulated businesses.
PIPEDAhttps://www.priv.gc.ca/en/report-a-concern/

Rest of world

CountryAuthorityLawWebsite
SwitzerlandFederal Data Protection and Information Commissioner (FDPIC)revFADP (Federal Act on Data Protection, 2023)https://www.edoeb.admin.ch/en
AustraliaOffice of the Australian Information Commissioner (OAIC)Privacy Act 1988https://www.oaic.gov.au/privacy/privacy-complaints
New ZealandOffice of the Privacy Commissioner (OPC)Privacy Act 2020https://www.privacy.org.nz/your-rights/making-a-complaint/
BrazilAutoridade Nacional de Proteção de Dados (ANPD)LGPDhttps://www.gov.br/anpd/pt-br
JapanPersonal Information Protection Commission (PPC)APPIhttps://www.ppc.go.jp/en/
South KoreaPersonal Information Protection Commission (PIPC)PIPAhttps://www.pipc.go.kr/eng/
SingaporePersonal Data Protection Commission (PDPC)PDPAhttps://www.pdpc.gov.sg/how-we-can-help/lodge-a-complaint
South AfricaInformation RegulatorPOPIAhttps://inforegulator.org.za
ArgentinaAgencia de Acceso a la Información Pública (AAIP)Personal Data Protection Act 25.326https://www.argentina.gob.ar/aaip

Also: noyb.eu — GDPR complaint templates and strategic litigation.