← All companies

GDPR Request — T-Mobile

T-Mobile suffered a 2021 breach exposing Social Security numbers and driver's licence data for over 54 million people, and a 2023 API breach affecting 37 million accounts. Although T-Mobile is a US carrier, EU residents whose data T-Mobile processes can exercise GDPR rights under Article 3(2), which applies GDPR extraterritorially to non-EU controllers targeting EU residents.

This letter is pre-addressed to T-Mobile USA, Inc., the official EU data controller for T-Mobile. Fill in your details and copy or send it directly.

T-Mobile does not publish a direct DPO email. Use their privacy contact form or send by post to the address shown in the letter.

⚠️ T-Mobile has had data breaches. See the breach guide and exercise your rights →
To: T-Mobile USA, Inc.
12920 SE 38th Street, Bellevue, WA 98006, USA

Dear Data Protection Officer,

I am writing to exercise my rights under the General Data Protection Regulation (GDPR). As an individual whose personal data you process, I am requesting the following information:

  1. Confirmation that you are processing my personal data.
  2. A copy of my personal data.
  3. The purposes of the processing.
  4. The categories of personal data concerned.
  5. The recipients or categories of recipients to whom my personal data has been or will be disclosed.
  6. The envisaged period for which my personal data will be stored, or the criteria used to determine that period.
  7. The existence of my right to request rectification or erasure of my personal data, or restriction of processing, or to object to such processing.
  8. Information about the source of my personal data if it was not collected directly from me.
  9. The existence of automated decision-making, including profiling, and meaningful information about the logic involved.

Below is my information for your reference:

Name:
Email:
Address:

This request is of utmost importance to me and should not be ignored. The GDPR mandates that you respond within one month. Failure to comply may result in further action being taken.

Thank you for your prompt attention to this matter.

Sincerely,

Text copied to clipboard

1. Copy and send this letter to the data controller of the organisation.

2. Follow up until you hear back. The GDPR requires a response within one month.

3. No response? Lodge a complaint with your local data protection authority.

No response after one month? File a complaint with your DPA →

Select your country to find your data protection authority:

Share: