Summary. Who holds your data, what you can make them do, and how to actually do it.
Why there is no single answer
The United States has no comprehensive federal privacy law. What exists instead is a set of sectoral statutes — each covering a particular kind of holder or a particular kind of data — layered under a growing set of comprehensive state laws that apply based on where you live.
Which means the first question in any privacy problem is not "what are my rights?" It is "who has the data, and what category are they in?"
The federal sectoral statutes that matter most to ordinary people:
Communications interception. The definitions that govern electronic surveillance appear at 18 U.S.C. § 2510, covering wire, oral, and electronic communications, and the framework prohibits intentional interception subject to exceptions — most importantly, consent.
Stored communications. 18 U.S.C. § 2701 makes it an offense to intentionally access a facility through which electronic communication service is provided without authorization, or to exceed authorization, and thereby obtain, alter, or prevent authorized access to a stored communication. In plain terms: reading someone else's email or messages without permission is a federal offense, not merely a betrayal.
Financial privacy. 15 U.S.C. § 6801 declares the policy that each financial institution has an affirmative and continuing obligation to respect the privacy of its customers and to protect the security and confidentiality of their nonpublic personal information, with implementing rules at 16 C.F.R. Part 313 — which is where the annual privacy notices and the opt-out rights they describe come from.
Telecommunications privacy. 47 U.S.C. § 222 imposes a duty on every telecommunications carrier to protect the confidentiality of proprietary information of and relating to customers — the statute behind customer proprietary network information rules, which govern what your phone carrier may do with information about whom you call and where you are.
Government records. 5 U.S.C. § 552a — the Privacy Act — governs records federal agencies maintain on individuals, with rights to access your own records and to request amendment of records that are not accurate, relevant, timely, or complete, plus restrictions on disclosure.
Consumer reports. The Fair Credit Reporting Act, beginning at 15 U.S.C. § 1681, is the most powerful individual privacy tool most people have and the one they use least. More on it below.
And then the state laws, which since 2018 have transformed the landscape for residents of a growing number of states, typically providing rights to know, access, delete, correct, and opt out of sale or targeted advertising, plus rights around sensitive data and, in some states, a limited private right of action.
The practical upshot: your leverage over a company depends on what kind of company it is and what state you live in. Both questions are answerable in about ten minutes, and answering them first prevents most wasted effort.
Data brokers, and the honest truth about opting out
A data broker collects information about people it has no direct relationship with, assembles it into profiles, and sells access. Sources include public records, court filings, property records, voter files, licenses, purchase histories, loyalty programs, app data, and other brokers.
Two rough categories, and the difference matters:
People-search sites, which publish profiles you can look up: name, age, addresses going back decades, relatives, phone numbers, and sometimes more. These are the ones that show up when someone searches your name, and they are the ones that matter for personal safety.
Background infrastructure brokers, which sell data to businesses for marketing, risk scoring, identity verification, and targeting. You will never see their output, but their data flows into decisions about you.
What you can do:
Opt out, one site at a time. Most people-search sites have an opt-out process, usually buried, often requiring you to find your own profile first and sometimes requiring an email address or ID.
In states with comprehensive privacy laws, send deletion and opt-out requests under the statute, which converts a courtesy into a legal obligation with a response deadline.
In states with data broker registries, the registry is a list of the brokers operating in your state — which is the closest thing to a comprehensive target list that exists. Some states have gone further and created mechanisms for a single deletion request directed at all registered brokers.
Three honest cautions:
It does not stay done. Profiles reappear — from new data acquisitions, from sister sites operated by the same company, and from the ordinary refresh of public records. Plan to repeat this every six to twelve months.
Removal services exist and can save substantial time. Evaluate them on whether they cover the sites you actually care about, whether they re-check, and what they do with your data. Understand that you are giving a company your personal information in order to have it removed elsewhere.
Public records remain public. Removing a profile from a search site does not remove the underlying court record, property record, or license.
Where it matters most: for survivors of domestic violence and stalking, for people in public-facing work, and for anyone who has been targeted, the people-search profile is the attack surface. Many states operate address confidentiality programs that provide a substitute address for public records — a far stronger protection than opting out one site at a time.
Consumer reports: the strongest tool nobody uses
Most people think "credit report." The category is much broader, and this is where the practical power is.
A consumer reporting agency is one that assembles information on consumers for the purpose of furnishing reports to third parties. Which covers a lot more than the three credit bureaus:
- Tenant screening companies, which decide whether you get an apartment
- Employment background screening companies
- Check and bank account screening services
- Insurance claim history databases
- Medical information exchanges
- Utility and telecom payment databases
- Gig platform and rideshare screening services
What the statute gives you:
Access. You can obtain your file from each of these, and the disclosure must include the sources of the information and, generally, who has received a report about you.
A limit on who can get one. 15 U.S.C. § 1681b restricts furnishing consumer reports to defined permissible purposes — a credit transaction, employment with written authorization, insurance underwriting, a legitimate business need in connection with a transaction initiated by you, and a few others. Obtaining a report without a permissible purpose is a violation, and it happens.
Accuracy obligations. 15 U.S.C. § 1681e requires agencies to follow reasonable procedures to assure maximum possible accuracy of the information they report. This is the provision that matters most in a mixed-file or wrong-person case.
Time limits. 15 U.S.C. § 1681c generally bars reporting most adverse items after defined periods — and bars reporting arrest records that did not result in conviction after the applicable period, a provision that matters enormously in tenant and employment screening.
A dispute process with teeth. 15 U.S.C. § 1681i requires a reasonable reinvestigation within a defined period, requires the agency to forward all relevant information you provide to the furnisher, requires deletion or modification of information that is inaccurate, incomplete, or unverifiable, and requires written notice of the results.
Adverse action notice. If you are denied housing, employment, credit, or insurance based in whole or in part on a report, you must be told, and told which agency provided it — and you may then obtain that file, often free.
Employment-specific protections. Before a report is obtained for employment, you must receive a clear and conspicuous standalone disclosure and provide written authorization. Before adverse action is taken, you must receive a pre-adverse action notice with a copy of the report and a summary of rights — which exists specifically to give you a chance to dispute an error before losing the job.
Why this matters so much in practice: tenant screening reports contain errors at meaningful rates, including eviction filings that were dismissed, records belonging to a different person with a similar name, and criminal records that should have aged off. A person denied an apartment because of someone else's eviction record has a specific statutory remedy and usually does not know it.
Recording, cameras, and consent
The rules here are state-by-state and getting them wrong is a crime.
Recording conversations. Federal law and most states follow a one-party consent rule — a participant in a conversation may record it. A substantial minority of states require all-party consent, meaning every participant must consent.
Which rule applies when the parties are in different states is genuinely unsettled, and the safe practice is to follow the stricter rule.
And note what "oral communication" means under the federal definitions at 18 U.S.C. § 2510 — it covers utterances by a person exhibiting an expectation that the communication is not subject to interception, under circumstances justifying that expectation. A conversation shouted across a parking lot is different from one in a closed office.
Recording police in public is protected in the great majority of jurisdictions to have considered it, subject to reasonable time, place, and manner limits and to not interfering. Audio recording adds a wrinkle in all-party states, though courts have generally protected recording of officers performing duties in public.
Video without audio is generally treated more permissively, but recording where there is a reasonable expectation of privacy — bathrooms, bedrooms, changing areas — is criminal essentially everywhere, regardless of who owns the property.
Home security cameras. Generally lawful pointed at your own property. Problems arise when a camera captures a neighbor's private areas, when audio recording captures conversations in an all-party state, and when a landlord installs cameras in areas a tenant occupies. A camera pointed into a neighbor's bedroom window is not a neighbor dispute; it is potentially a crime.
Workplace monitoring is broadly permitted on employer-owned systems, generally requires notice under some state laws, and is more restricted for oral communications and for areas with an expectation of privacy.
Drones add aviation rules on top of state peeping and privacy statutes, and a growing number of states have drone-specific surveillance offenses.
Location, devices, and the person who has access to your accounts
The most serious privacy harms are usually not committed by corporations. They are committed by people who know you.
Stalkerware — software installed on a phone to monitor location, messages, calls, and activity — is widely available, easy to install with brief physical access, and often invisible to the person being monitored.
Installing it on another adult's device without consent can violate the interception provisions, the stored communications provision at 18 U.S.C. § 2701, state computer crime statutes, and stalking statutes. It is not a gray area.
Where it shows up: in relationships, in separations, and after separations. It is a standard feature of intimate partner surveillance, and it is frequently combined with shared accounts, shared cloud storage, family location sharing, shared vehicle telematics, and shared smart home systems.
The account access problem is the bigger one. A person who knows your passwords, is a recovery contact on your accounts, shares a cloud family plan, is on your phone plan, or has an administrator role in your smart home does not need to install anything. They can already see your location, your messages, your photos, your purchases, and who you contact.
If you are concerned that someone is monitoring you:
Consider safety first. For someone in a dangerous relationship, abruptly cutting off access can escalate the danger. Domestic violence advocates and specialized technology safety programs help plan this, and they should be consulted before acting.
Use a device the other person has never had access to to research, to contact help, and to change credentials.
Then work through the access map systematically — passwords, recovery methods, two-factor settings, trusted devices, family sharing, location sharing, phone plan account access, cloud backups, vehicle telematics, smart home administrators, and shared subscriptions.
Preserve evidence before removing anything, because the record of surveillance supports a protective order and a criminal complaint.
Breaches, and what to actually do
A breach notice is not a crisis, but it is a prompt.
All states require notification of breaches involving defined categories of personal information, with varying triggers, timelines, and content requirements. Read the notice for what data was actually involved — the response is different for an email address than for a Social Security number.
The response ladder, in order of value:
Freeze your credit at each nationwide credit bureau. This is free, it is the single most effective step against new-account identity theft, and it is dramatically underused. It blocks new credit from being opened in your name. You lift it temporarily when you need credit.
Freeze the specialty agencies too — the check and bank account screening services and the telecom and utility databases — which are where account fraud actually happens and which almost nobody freezes.
Place a fraud alert if you do not want a freeze; it is weaker but easier.
Change passwords, starting with your email account, which is the recovery mechanism for everything else. Use unique passwords and a password manager.
Turn on two-factor authentication, preferring an authenticator app or a hardware key over text messages, which are vulnerable to SIM swapping.
Add a PIN or port-out protection to your mobile account, which defends against SIM swapping — the attack that defeats text-message two-factor.
Check your consumer reports — all of them, including the specialty ones.
Watch for medical identity theft by reading explanation-of-benefit statements, and for tax identity theft by filing early and considering an identity protection PIN.
And if identity theft has already occurred: file an identity theft report with the federal trade regulator, file a police report, dispute the fraudulent items with each agency, and use the block provision, which requires an agency to block information resulting from identity theft when you provide an identity theft report. That provision is stronger than an ordinary dispute and it is rarely invoked.
Three problems, three completely different answers
Problem one: Yusuf Abubakar loses an apartment because of someone else's eviction.
Yusuf applies for a two-bedroom and is denied. The property manager says only that the "background check came back bad."
He asks the question that unlocks everything: "Which company provided the report?" Under the adverse action requirement, he is entitled to know, and to a copy of the file.
The report shows an eviction filing from 2019 in a county he has never lived in, against a "Yusuf Abubaker" with a different middle initial and a birth year four years off.
This is a mixed file — one of the most common errors in tenant screening — and it implicates the accuracy obligation at 15 U.S.C. § 1681e, which requires reasonable procedures to assure maximum possible accuracy.
He disputes in writing under 15 U.S.C. § 1681i, attaching his driver's license, his lease history, and a printout of the county docket showing the other person's full name and birth date. He sends it certified.
The agency deletes the item within the reinvestigation period. He requests that corrected reports be sent to the property manager, which the statute permits, and asks the property manager to reconsider.
The apartment is gone, but the file is fixed before the next application — and had he not asked which company, he would have carried the error into every future application without knowing it existed.
Problem two: Yelena Voskresenskaya finds her home address on eleven websites.
She is a nurse who testified in a workplace matter and started receiving unpleasant messages. She searches her own name and finds eleven people-search profiles listing her current address, her prior addresses, her mother's name, and a phone number.
What she does, in order:
Assesses safety first. She documents everything with screenshots — dated, showing the URL — before removing anything, because removal destroys the evidence of what was published.
Checks whether her state has an address confidentiality program, which provides a substitute address usable on public records. It does. She enrolls. This is a far stronger protection than opting out one site at a time, because it addresses the source rather than the republication.
Then opts out of all eleven, keeping a spreadsheet of the site, the opt-out URL, the date submitted, the confirmation, and the date to re-check.
Then, because her state has a comprehensive privacy law, sends statutory deletion and opt-out requests to the larger brokers — which converts a discretionary process into one with a legal deadline.
Then checks the state's data broker registry and sends requests to registered brokers she had never heard of.
Six months later, four profiles have returned. She opts out again. This is the expected outcome, not a failure of the process.
Problem three: Callum Bright discovers his ex-partner still has access to everything.
Two months after moving out, Callum notices his ex knows things he has not told anyone — where he ate dinner, who he was with.
What is actually happening is not exotic. He checks and finds: family location sharing still enabled · his ex is a trusted recovery contact on his email account · his phone is still on his ex's carrier plan, which shows call and text metadata and location · their cloud photo library is shared · and his ex is still an administrator on the smart home account, which logs door and camera activity.
No spyware was installed. Nothing was hacked. The access was never removed.
Because there is no history of violence in his situation, he can act directly. He works through the access map methodically, from a laptop his ex has never touched: changes the email password and every recovery method first, then removes the trusted contact, then disables location sharing, ports his number to his own carrier account with a PIN, unshares the photo library, and removes the smart home administrator.
Had there been a history of violence, the advice would be different and it matters: abruptly cutting off a monitoring partner's access can escalate danger, and a domestic violence advocate or a technology safety program should be consulted before changing anything. In that situation, documenting first and planning the sequence with an advocate is the safer path.
A map of your own data, and how to build it
Most people have no idea who holds their information. Building the map takes an afternoon and it changes what you can do.
Category one: companies you have a relationship with.
Banks and credit unions · credit card issuers · insurers · your employer · your landlord or mortgage servicer · utilities and telecom · health providers and pharmacies · schools · retailers with loyalty programs · every app and service with an account.
Your leverage: state privacy law rights where you have them, sector-specific rights (financial privacy notices under 16 C.F.R. Part 313, telecom rules under 47 U.S.C. § 222, health privacy rules), and account settings — which are the fastest and most underused lever of all.
Category two: consumer reporting agencies.
The three nationwide credit bureaus, plus the specialty agencies: tenant screening · employment screening · check and bank account screening · insurance claims history · medical information · utility and telecom payment · gig platform screening.
Your leverage: the strongest set of rights you have — access, dispute, accuracy obligations, time limits, permissible purpose limits, and adverse action notices.
Category three: data brokers.
People-search sites and background infrastructure brokers, with whom you have no relationship at all.
Your leverage: opt-out processes, state privacy law deletion and opt-out rights, state broker registries, and — for safety cases — address confidentiality programs.
Category four: government.
Federal agencies (access and amendment under 5 U.S.C. § 552a) · state agencies under state public records and privacy laws · courts, whose records are largely public · property, voter, licensing, and business filings.
Your leverage: access and amendment for agency records; for court records, sealing or expungement where available, which addresses the source that feeds everything else.
Category five: people.
Current and former partners · family · roommates · employers with device access · anyone who is a recovery contact, plan owner, or account administrator.
Your leverage: revoking access, and where the conduct crosses lines, criminal and civil remedies.
Build the map on paper. For each entry, note what they have, what right you have, and what you have done. The map is the difference between a vague sense of exposure and a task list.
Sensitive categories with their own rules
Some data has its own regime, and knowing which applies changes the answer.
Health information. Federal health privacy rules cover health plans, most health care providers, and clearinghouses, and their business associates — not health information generally. Which means a fitness app, a symptom tracker, a genetic testing service, and a wellness program are frequently outside the framework entirely. Your rights against a covered entity include access to your records, an accounting of certain disclosures, amendment requests, and restriction requests. Your rights against an app are whatever your state law and the app's own policy provide.
Genetic information. Employment and health insurance discrimination based on genetic information is prohibited federally. Consumer genetic testing services are governed mostly by their own terms and by state law — and the questions worth asking before testing are what they do with the sample, whether they share with researchers or partners, what happens in a bankruptcy or acquisition, and whether relatives can be identified through your data. A genetic test is a disclosure about your family, not only about you.
Biometric information. A small number of states regulate collection and use of biometric identifiers — fingerprints, face geometry, voiceprints, iris scans — typically requiring notice, written consent, retention schedules, and a prohibition on sale. One state's law includes a private right of action, which has driven most of the litigation in this area.
Student records. Federal law gives parents, and students once they reach a defined age, rights to inspect education records, to request amendment, and to limit disclosure — with an exception for "directory information" that schools may release unless you opt out. Opting out of directory information is a real, simple step almost nobody takes.
Children's data. Federal rules require verifiable parental consent before collecting personal information online from children under a defined age, with notice and deletion rights.
Financial data. Beyond the privacy notice framework at 15 U.S.C. § 6801, note that the annual notices you throw away describe an opt out of certain information sharing with unaffiliated third parties — a right that exists precisely because nobody reads the notice.
Telephone and messaging. Restrictions on automated calls, prerecorded messages, and texts without consent carry statutory damages per violation, which is why these cases are litigated. The national do-not-call registry is free and permanent.
Video viewing history has its own federal statute, a historical accident that still produces litigation.
Doxxing, harassment, and getting content removed
When information is published to harm you, the response has three tracks and they run at once.
Track one: preserve.
Screenshot everything before anything is removed — the content, the URL, the account name, the timestamp, and the surrounding context. Removal destroys the evidence of what was published, and you will need it for a protective order, a police report, or a civil claim.
Keep a log: date, platform, account, content, and effect on you.
Track two: remove.
Platform reports, using the specific category — personal information exposure, harassment, or non-consensual intimate imagery, each of which has its own process and its own escalation path.
Search engine removal requests, which exist for categories including personal contact information, financial account numbers, government identification numbers, medical records, non-consensual intimate imagery, and certain doxxing content. Removing something from search does not remove it from the web, but for most practical purposes search is how people find it.
Host and registrar complaints, where the site itself will not act.
For intimate images specifically: federal and state law now provide civil and criminal remedies, and hash-matching services operated by nonprofits allow images to be blocked across participating platforms without the images themselves being uploaded anywhere. These work and they are free.
Track three: enforce.
Police report, particularly where there are threats, stalking conduct, or intimate images.
Protective or restraining order, where the conduct meets the state's definition — many states now expressly cover electronic harassment and cyberstalking.
Civil claims, which vary by state and may include harassment, intentional infliction of emotional distress, publication of private facts, false light, appropriation of name or likeness, and statutory claims for intimate image disclosure.
Employer or school reporting, where the person is identifiable and subject to a code of conduct.
And the practical protections that reduce the damage:
Address confidentiality program enrollment, which cuts off the source.
A post office box or a commercial mail receiving address for anything that will become public.
Locking down your own accounts — profile visibility, friend and follower lists, tagged content, and photo location metadata.
Auditing what you have posted that reveals your home, your workplace, your routine, or your children's school.
Warning the people around you, because family members' public profiles are frequently the route to your address.
Getting your own records: the requests that work
Access requests are the foundation of everything else, and each type has a different form.
Federal agency records. 5 U.S.C. § 552a provides a right to access records an agency maintains about you in a system of records, and a right to request amendment of records that are not accurate, relevant, timely, or complete — with an appeal if the amendment is refused and a right to file a statement of disagreement that must accompany the record thereafter.
How to make it work: address it to the agency's Privacy Act officer, identify yourself sufficiently for verification, describe the system of records if you can, state that you are requesting under both the Privacy Act and the freedom of information statute (requesting under both frequently produces more than either alone), and verify your identity as the agency requires.
Consumer reporting agencies. Request your file from each — the three nationwide bureaus and the specialty agencies. Request the full file disclosure, not just a score, and note that the disclosure should include sources and recipients of reports.
Companies you have a relationship with. In states with comprehensive privacy laws, a right-to-know request obtains the categories and often the specific pieces of personal information collected, the sources, the business purpose, and the categories of third parties it was disclosed to. Send it to the address or portal in the privacy policy, which is required to be provided.
Employers. Several states give employees a right to inspect their personnel file, and some give a right to copies. Ask in writing and cite the statute if your state has one.
Medical records. Federal health privacy rules give you a right of access to your records, in the form you request where readily producible, within a defined period and at a limited cost. Ask for the complete designated record set, not a summary.
Schools. Federal education records law gives inspection and amendment rights.
Your own court records. Public, and worth reviewing — a dismissed case that still appears in a background check is one you can document and dispute.
What makes any of these work:
Be specific about what you want. "All records" is often refused as unreasonably broad; "records relating to me from January 2020 to present in the [named] system" is not.
Verify your identity as required — most refusals are identity verification failures, not substantive denials.
Put a deadline in the letter and note the statutory response period.
Send it in a way that creates proof, and log it.
Follow up in writing when the deadline passes, and note that a failure to respond is itself actionable in several statutes.
The settings that do more than the letters
An honest observation: the highest-value privacy work most people can do takes about two hours and involves no law at all.
Accounts:
- Unique passwords everywhere, kept in a password manager. Reused passwords are the single largest cause of account compromise
- Two-factor authentication on everything, preferring an authenticator app or hardware key over text messages
- A PIN or port-out protection on your mobile account — this is what defeats SIM swapping, and it takes one phone call
- Review recovery methods and trusted contacts on your email account, which is the master key to everything else
- Review connected apps and third-party access, and remove what you do not use
- Review active sessions and trusted devices, and sign out of what you do not recognize
Devices:
- Screen lock with a strong code
- Full-disk encryption enabled
- Review app permissions — location, contacts, microphone, camera, photos — and set location to "while using" or off for anything that does not need it
- Turn off ad identifiers and reset them periodically
- Review location history settings, and delete stored history if you do not want it retained
- Keep the operating system updated
Sharing:
- Audit family sharing, location sharing, and shared albums — the most common source of unwanted visibility
- Review who has administrator access to smart home systems, vehicle apps, and streaming accounts
- Check whether your phone plan account owner can see your usage details
Public exposure:
- Search your own name in more than one engine, and look at the images tab
- Set social profiles to the visibility you actually want, including old posts
- Turn off directory information disclosure at your children's school
- Check whether photos you post carry location metadata
- Register on the national do-not-call list
Financial:
- Freeze your credit at all three nationwide bureaus — free, and the highest-value single action available
- Freeze the specialty agencies too
- Opt out of pre-screened credit offers, which reduces mail-theft account fraud
- Read the annual financial privacy notice once and exercise the sharing opt-out it describes
Do these before writing a single letter. The letters matter, but the settings are where the leverage actually is.
Where to complain, and what each office actually does
Complaints work in this area more than in most, because the enforcement bodies are active and the volume of complaints drives what they investigate.
The federal trade regulator, for deceptive privacy practices, data security failures, and identity theft — and it operates the identity theft reporting system that generates the report you need to invoke the block provision in consumer reporting law.
The federal consumer financial regulator, for consumer reporting agencies, furnishers, debt collectors, and financial institutions. Complaints here get routed to the company with a response deadline, and the responses are frequently substantive — this is one of the most effective free tools available to an individual.
The federal communications regulator, for telecommunications privacy under 47 U.S.C. § 222, unwanted calls, and carrier practices.
Your state attorney general, which enforces the state comprehensive privacy law where one exists, plus the state's unfair and deceptive practices statute. Many state attorneys general have dedicated privacy units.
Your state insurance, banking, or utility regulator, for entities they license.
The health privacy enforcement office, for covered entities and business associates.
Your state's education agency or the federal education department, for student records.
The agency itself, for a Privacy Act access or amendment refusal — there is an internal appeal, and after that, a civil action in federal court.
And note where a private right of action exists, because that changes strategy:
- Consumer reporting law provides for actual damages, and for willful violations, statutory and punitive damages plus attorney's fees — which is why consumer reporting cases are taken on contingency and why an error in your file is worth pursuing.
- Interception and stored communications provisions provide civil remedies.
- Restrictions on automated calls and texts provide statutory damages per violation.
- One state's biometric law provides a private right of action, and it has driven substantial litigation.
- Most comprehensive state privacy laws do not provide a general private right of action, with a notable exception for certain data breaches in one state — meaning enforcement runs through the attorney general.
How to write a complaint that gets acted on:
One page. Chronological. Factual.
What happened, with dates. What you asked for and when. What they did or failed to do. What harm resulted.
The specific statutory provision if you can name it — this alone moves a complaint from the general queue.
What you want — correction, deletion, a response, or an investigation.
Attach the documents, numbered.
And keep the reference number, because a complaint you can point to later is leverage in every subsequent conversation with the company.
Frequently asked questions
What rights do I actually have? It depends on who holds the data and what state you live in. Answer both questions before anything else.
How do I get off people-search sites? Opt out site by site, use your state privacy law's deletion right if you have one, check whether your state has a data broker registry, and repeat every six to twelve months — profiles come back.
A background check cost me an apartment. You are entitled to know which company provided the report, to get a free copy, and to dispute it. Errors — dismissed evictions, wrong person, records that should have aged off — are common.
Can I record a phone call? Depends on your state and possibly the other party's. Follow the stricter rule.
Can I put up a security camera? Generally on your own property. Not where there is a reasonable expectation of privacy, and audio adds consent problems.
I think my partner is tracking my phone. Talk to a domestic violence advocate before changing anything — abrupt changes can escalate danger. Use a device they have never accessed to get help.
Is reading someone's email a crime? Accessing stored communications without authorization is a federal offense under 18 U.S.C. § 2701, plus state offenses.
I got a breach notice. Freeze your credit at all three bureaus — free, and the highest-value step. Then freeze the specialty agencies, change your email password, and add a PIN to your mobile account.
Can I see what the government has on me? For federal agencies, yes — 5 U.S.C. § 552a provides access and amendment rights.
Is a privacy policy a promise? Largely yes — misrepresenting your practices is an unfair or deceptive act, which is the main federal enforcement theory in this area.
Related documents
- Protecting Your Personal Information
- Personal Privacy Checklist
- Privacy Toolkit
- Scams, Fraud, and Elder Financial Exploitation
- Debt Collection and the FDCPA
- Residential Landlord-Tenant Law: Leases, Habitability, Deposits, and Eviction
Educational only, not legal advice. Privacy law is a patchwork of federal sectoral statutes and rapidly changing state laws; check your own state's current law. If you are being surveilled by someone who has been violent toward you, contact a domestic violence advocate before changing device or account settings.