The company "should" have a DPO, whou you can complain to. If that fails you can complain to the DPA [0]
[0] https://ec.europa.eu/info/law/law-topic/data-protection/refo...