The complete study library
Explore the CIPP/US study library
Search 321 free study resources for CIPP/US. Find a lesson, review a term or choose a practice session.
321 resources
No matching resources
Try a broader term or reset the search to see the complete library.
CIPP/US exam format and blueprint
The current CIPP/US exam format, timing, question types and a practical way to use the IAPP Body of Knowledge and blueprint.
Guide · CIPP/USCIPP/US exam questions explained
CIPP/US practice questions for exam prep: 604 exam-style questions, a 90-question timed set, worked explanations and a free diagnostic.
Guide · CIPP/USCIPP/US practice questions and practice exam
Take a free CIPP/US diagnostic, then use 604 practice questions and a timed 90-question set with explanations.
Guide · CIPP/USCIPP/US study guide
CIPP/US study guide with free lessons, a ten-question diagnostic and 604 exam-style practice questions for scenario-based exam prep.
Guide · CIPP/USCIPP/US study plan
A four-week CIPP/US study plan that turns the published outline into a 30-hour schedule with review and timed practice.
Practice · CIPP/USCIPP/US cram sheet
The complete CIPP/US memorisation sheet: the timeline, dollar amounts and deadlines, opt-in vs opt-out, who enforces what, the sectoral laws, the Supreme…
Practice · CIPP/USFind the CIPP/US areas to study next.
Take a free 10-question CIPP/US diagnostic. Get an immediate domain score and a personalised study plan without creating an account.
Guide · CIPP/USCIPP/US essentials
The essentials tier for the IAPP CIPP/US - the most-tested laws, regulators, opt-in/opt-out rules and distinctions per exam area, condensed to one page…
Guide · CIPP/USCIPP/US: the whole exam on one page
Every exam-relevant U.S. privacy law, regulator, threshold, opt-in vs opt-out rule, distinction and landmark case for the IAPP CIPP/US - condensed onto…
Glossary · CIPP/USCIPP/US glossary
Plain-language definitions for recurring terms in the CIPP/US study guide.
Guide · CIPP/USHIPAA vs FERPA
A practical HIPAA versus FERPA decision guide for school nurses, outside providers, university clinics and mixed student and nonstudent records.
Guide · CIPP/USHow to pass the CIPP/US
How to pass the IAPP CIPP/US exam: what it tests, the format, a study plan, the sectoral-law traps, and free study notes plus the exam-style question set.
Guide · CIPP/USIs the CIPP/US exam hard?
Is the CIPP/US exam hard? Format, pass mark, domain weights, where candidates struggle and a practical way to prepare.
Practice · CIPP/USFree CIPP/US mini mock
Try 25 exam-style CIPP/US practice questions free, with explanations and a domain score. No account or payment required.
Practice · CIPP/USA processor discovers a breach affecting personal data it handles for a controller. What is the processor's obligation under the GDPR?
A processor discovers a breach affecting personal data it handles for a controller. What is the processor's obligation under the GDPR? Answer with a worked…
Lesson · CIPP/USAPEC Privacy Framework (2004)
APEC is a 21-member organization operating under nonbinding agreement. Its 2004 Privacy Framework (updated 2015) sets nine principles that mirror the OECD…
Lesson · CIPP/USThe Four Classes of Privacy
Privacy splits into four classes: information, bodily, territorial, and communications privacy. This book focuses primarily on information privacy.
Lesson · CIPP/USCo-Regulatory, Self-Regulatory, and Technology Models
Co-regulation (e.g., Australia; U.S. COPPA codes approved by the FTC) pairs industry codes with government law. Self-regulation (e.g., PCI DSS, seal…
Lesson · CIPP/USComprehensive Model of Data Protection
Comprehensive laws govern personal data across public and private sectors economy-wide, typically with an oversight DPA. Countries adopt them to remedy…
Lesson · CIPP/USCouncil of Europe Convention 108 (1981)
Convention 108 (1981) required its parties to enact data protection provisions in domestic law. It was modernised through the 2018 protocol known as…
Lesson · CIPP/USDefining Privacy
In 1890, Warren and Brandeis defined privacy as the right to be let alone in the Harvard Law Review. U.S. law calls this field privacy law while the EU…
Lesson · CIPP/USFair Information Practices (FIPs) Overview
Since the 1970s, Fair Information Practices (FIPs/FIPPs) have organized individual rights and organizational responsibilities into four categories: rights…
Lesson · CIPP/USU.S. HEW Fair Information Practices (1973)
The FIPs used widely today trace to a 1973 U.S. Department of Health, Education and Welfare report whose Code of Fair Information Practices set five core…
Lesson · CIPP/USHistorical and Social Origins of Privacy
Privacy roots run from classical Greece and the Bible to England's 1361 Justices of the Peace Act. The U.S. Constitution protects privacy without naming…
Lesson · CIPP/USInformation Technology and the Rise of Data Protection Law
Mainframes in the 1960s spurred privacy fears (Orwell's '1984'). In 1970, Hesse, Germany enacted the first modern data protection law; the same year the…
Lesson · CIPP/USMadrid Resolution (2009)
The 2009 Madrid Resolution was approved by data protection commissioners themselves, not governments, to define uniform privacy principles and facilitate…
Lesson · CIPP/USNonpersonal, Deidentified, and Pseudonymized Information
Remove identifying elements and data becomes nonpersonal (deidentified/anonymized), generally outside privacy laws. Pseudonymized data is only temporarily…
Lesson · CIPP/USOECD Guidelines (1980)
The 1980 OECD Guidelines (updated 2013) are the most widely recognized FIP framework and have been endorsed by the FTC. They set eight principles, from…
Lesson · CIPP/USPersonal Information and Sensitive Personal Information
In the U.S., personal information and personally identifiable information (PII) cover data that can identify an individual. Sensitive personal information…
Lesson · CIPP/USThe Line Between Personal and Nonpersonal Information
Where personal ends and nonpersonal begins is unclear and varies by regime. The EU generally treats IP addresses as personal data; U.S. agencies under the…
Lesson · CIPP/USProcessing and Data Roles - Subject, Controller, Processor
Processing covers almost anything done with personal data. The data controller decides how and why data is processed and bears most obligations; the data…
Lesson · CIPP/USSectoral Model (United States)
The sectoral model (the U.S. approach) protects personal data through laws targeting specific industries. Strengths: tailored, lower burden. Weaknesses…
Lesson · CIPP/USSources of Personal Information
The same data can be treated differently by source: public records (held by government, available to the public), publicly available information (broadly…
Lesson · CIPP/USSources of Privacy Protection
Privacy protection comes from four sources: markets, technology, law, and self-regulation/co-regulation. Law is the traditional approach but real…
Lesson · CIPP/USCybersecurity Requirements in Education
FERPA expects reasonable security but specifies no particular controls; the GLBA Safeguards Rule applies to universities holding financial aid information…
Lesson · CIPP/USEdtech under COPPA and Self-Regulation
In 2022 the FTC announced it would police edtech through COPPA, prohibiting use of children's data for commercial purposes, barring unreasonable mandatory…
Lesson · CIPP/USEducation Technology and FERPA
Edtech companies that handle student data are subject to FERPA. The 2014 Google Apps for Education lawsuit (with EPIC alleging FERPA violations over email…
Lesson · CIPP/USRights to Access, Review, and Correction
FERPA gives students the right to access and review most records within 45 days of a request and the right to seek correction of inaccurate, misleading…
Lesson · CIPP/USStatutory Exceptions to FERPA Consent
FERPA lists many no-consent disclosure exceptions, including school officials with a legitimate educational interest, transfer schools, financial aid…
Lesson · CIPP/USValid Consent and Identity Verification
Valid FERPA consent must be signed, dated, and written, identifying the records, the purpose, and the recipient. When relying on a statutory exception…
Lesson · CIPP/USDirectory Information and Opt-Out
Directory information is data that would not generally be considered harmful if disclosed; each institution defines its own list, and before using it the…
Lesson · CIPP/USWhen Disclosure of Education Records Is Permitted
FERPA permits disclosure of education records only if the data is not PII, it is unblocked directory information, the rights holder consents, the…
Lesson · CIPP/USEducation Record and Its Exceptions
An education record is broadly any record directly related to a student and maintained by or on behalf of the school, but FERPA carves out important…
Lesson · CIPP/USFERPA Enforcement, No Private Right, and Preemption
FERPA is enforced by the Department of Education through the Family Policy Compliance Officer (FPCO); the ultimate penalty is loss of federal funding…
Lesson · CIPP/USHolder of FERPA Rights
Who holds FERPA rights depends on context: in high school the parent holds rights until the student turns 18; once a student attends only a college or…
Lesson · CIPP/USFERPA Overview and Scope
The Family Educational Rights and Privacy Act of 1974 (FERPA), also called the Buckley Amendment, gives students control over disclosure of and access to…
Lesson · CIPP/USPersonally Identifiable Information under FERPA
FERPA's PII definition covers names, family member names, addresses, SSNs and student numbers, dates and places of birth, and any information that alone…
Lesson · CIPP/USFERPA Definition of Student
Under FERPA, a student is anyone who is or has been in attendance at an educational institution, including online attendees, but the term excludes…
Lesson · CIPP/USIndividuals with Disabilities Education Act
IDEA guarantees eligible students aged 3 to 21 a free appropriate public education through an IEP, and protects the privacy of special-education records…
Lesson · CIPP/USPPRA and the No Child Left Behind Amendments
The PPRA (1978) amended FERPA to protect parents of minors over surveys collecting sensitive information and applies only to K-12 schools, not colleges…
Lesson · CIPP/USState Student Privacy Laws and SOPIPA
Because FERPA does not preempt state law, states add their own protections. California's SOPIPA was the first U.S. law to prohibit using student data for…
Lesson · CIPP/USCIPP/US COPPA rule and children's data guide
COPPA requirements and current FTC rule material explained for CIPP/US study.
Lesson · CIPP/USCIPP/US Epic Games COPPA enforcement guide
Epic Games COPPA enforcement as a CIPP/US scenario review, with primary FTC source material.
Lesson · CIPP/USThe Cable Communications Policy Act of 1984
The Cable Act regulates cable providers' notice, collection, disclosure and retention of subscriber data, and grants a private right of action. Providers…
Lesson · CIPP/USThe CAN-SPAM Act of 2003
CAN-SPAM governs commercial email to or from the U.S. on an opt-out basis: no false headers or deceptive subject lines, a working return address, a clear…
Lesson · CIPP/USCAN-SPAM Wireless Rules: MSCMs, Express Prior Authorization and the Wireless Domain Registry
The FCC's CAN-SPAM wireless rules require express prior authorization (opt-in) for each mobile service commercial message (MSCM) sent to wireless devices…
Lesson · CIPP/USCPNI Opt-in/Opt-out Rules, Pretexting and Covered Entities
After U.S. West v. FCC struck a 1998 opt-in rule on First Amendment grounds, carriers' own use of CPNI shifted to opt-out. The 2007 CPNI order requires…
Lesson · CIPP/USDigital Advertising Ethics: Behavioral Advertising, Dark Patterns and Children
Beyond legal compliance, ethical digital advertising stresses honesty, fairness and transparency. Key concerns: online behavioral advertising (tracking…
Lesson · CIPP/USExceptions to the DNC Rules: EBR, Consent and DNC Safe Harbor
DNC rules do not apply to nonprofits calling for themselves, existing-customer calls within 18 months, non-upsell inbound calls, or most B2B calls. An EBR…
Lesson · CIPP/USFax Marketing: TCPA and the Junk Fax Prevention Act
The TCPA (enforced by the FCC) bars unsolicited commercial faxes; consent can be explicit or inferred from an EBR. The 2005 Junk Fax Prevention Act…
Lesson · CIPP/USThe National Do Not Call Registry
The National DNC Registry (effective 2003) lets residents register residential and wireless numbers. Sellers/telemarketers must access it before calling…
Lesson · CIPP/USRobocall Enforcement Actions and State Telemarketing Laws
Regulators have escalated robocall enforcement (a 2021 FCC $225 million record fine for ~1 billion robocalls; a 2019 multistate initiative). Because…
Lesson · CIPP/USSelf-Regulation for Digital Advertising: DAA and NAI
Two voluntary codes govern much online behavioral advertising: the DAA Self-Regulatory Principles and the NAI Code of Conduct, both emphasizing opt-outs…
Lesson · CIPP/USState Laws on Digital Advertising: CalOPPA, Age-Appropriate Design, and Comprehensive Laws
California leads on digital advertising: CalOPPA (2003) requires website privacy notices and Do Not Track disclosures; the 2022 California Age-Appropriate…
Lesson · CIPP/USTCPA Updates: Robocalls, Autodialers, Robotexts and Facebook v. Duguid
The FCC's 2012 TCPA revisions require prior express written consent for all robocalls to residential lines, even with an established business…
Lesson · CIPP/USThe Telecommunications Act of 1996 and CPNI
Section 222 of the Telecommunications Act of 1996 restricts how carriers access, use and disclose customer proprietary network information (CPNI) - call…
Lesson · CIPP/USTelemarketing Regulatory Framework: TCPA, TSR, FCC and FTC
Two coordinated federal regimes govern telemarketing: the FCC enforces the Telephone Consumer Protection Act (TCPA) of 1991, and the FTC enforces the…
Lesson · CIPP/USTSR abandoned calls. CIPP/US safe harbor guide
TSR abandoned call rules explained with a safe-harbor example and CIPP/US study context.
Lesson · CIPP/USTSR Rules on How Calls May Be Made
The TSR sets detailed conduct rules: telemarketers may call only between 8 a.m. and 9 p.m., must scrub against the Do Not Call list, display caller ID…
Lesson · CIPP/USTransmission of Caller ID Information
Telemarketers must transmit accurate caller ID. They may show their own name/number or substitute the seller's name and a customer-service number that is…
Lesson · CIPP/USTSR Enforcement, Penalties and the Private Right of Action
The TSR is enforced by the FTC and state attorneys general, with civil penalties up to $50,120 per call. A limited private right of action requires…
Lesson · CIPP/USTSR Misrepresentations, Material Omissions and Payment Authorization
The TSR bars misrepresentations and material omissions across ten categories (cost, restrictions, refund policy, prize/investment terms, etc.). When…
Lesson · CIPP/USTSR Recordkeeping Requirements
The TSR requires sellers and telemarketers to keep specified records (ads, prize recipients, sales, employees, consent authorizations) for two years from…
Lesson · CIPP/USTSR required disclosures. CIPP/US telemarketing guide
TSR required call disclosures explained with a practical example and CIPP/US study context.
Lesson · CIPP/USProhibition on Unauthorized Billing and Pre-Acquired Account Information
The TSR bars billing without express, informed consent. Where the telemarketer already holds the consumer's account data (pre-acquired account…
Lesson · CIPP/USThe Video Privacy Protection Act of 1988
The VPPA, passed after Robert Bork's video rental records were disclosed, bars videotape service providers from disclosing customer information except…
Lesson · CIPP/USCIPP/US Section 230 and online content guide
Section 230 and online content issues explained with a source-backed CIPP/US study bridge.
Lesson · CIPP/USCIPP/US FCC telecom breach notification guide
FCC telecom breach notification rules explained with a source-backed CIPP/US study bridge.
Lesson · CIPP/USADA Restrictions on Medical Screening
The ADA covers employers with 15 or more employees. Before an offer, medical exams/inquiries are allowed only if job-related and consistent with business…
Lesson · CIPP/USAfter Employment: Access Termination and HR Records
On departure, employers should terminate access (badges, accounts, devices), recover company data, and forward personal mail while reviewing work mail. HR…
Lesson · CIPP/USAntidiscrimination Laws as Limits on Screening
Federal antidiscrimination laws (Title VII, Equal Pay Act, ADEA, Pregnancy Discrimination Act, ADA, GINA) bar discrimination and indirectly limit what…
Lesson · CIPP/USReasons for Background Screening
Employers screen to hire the best candidate, counter false applicant claims, protect brand, and mitigate negligent hiring liability. Some professions…
Lesson · CIPP/USBiometric, Video, and Mail Monitoring; Union Activity
Three state biometric laws reach employer data: Illinois BIPA (notice, consent, and a private right of action), plus Texas and Washington (no private…
Lesson · CIPP/USConstitutional Law and the State-Action Limit
Constitutional privacy protections like the Fourth Amendment apply to government (public-sector) employers but not to private-sector employment, because…
Lesson · CIPP/USThe Employment Life Cycle Framework
Workplace privacy issues arise before, during, and after employment: background screening (before); polygraphs, testing, monitoring, social media, and…
Lesson · CIPP/USFACTA Preemption and Stronger State Credit Laws
FACTA (2003) amended the FCRA and preempted many state laws on credit reporting and identity theft, but the FCRA does not preempt stronger state laws on…
Lesson · CIPP/USFair Chance Act and Ban-the-Box Laws
The Fair Chance to Compete on Jobs Act (FCA), enacted in 2019, bars federal agencies and federal contractors from asking about an applicant's criminal…
Lesson · CIPP/USFCRA Restrictions on Background Checks
The FCRA governs background checks via consumer reports from a CRA - not just credit, but criminal and driving records too. Employers need a permissible…
Lesson · CIPP/USFederal Laws Affecting Employment Privacy
A cluster of federal laws bears on employment privacy: antidiscrimination laws, benefits laws (HIPAA, COBRA, ERISA, FMLA), and recordkeeping/data laws…
Lesson · CIPP/USIntercepting Communications: Wiretap Act and ECPA
The Wiretap Act and ECPA generally prohibit intercepting wire, oral, and electronic communications. Two workplace exceptions: consent (party or one party…
Lesson · CIPP/USInvestigating Employee Misconduct: Vail Letter and FACTA Fix
Investigations should be fair, documented, and compliant with CBAs. The FTC's Vail Letter made third-party investigators CRAs, requiring notice and…
Lesson · CIPP/USLBS, DLP, BYOD, and Teleworking Policies
Monitoring policies must address location-based services (GPS on vehicles generally OK; tracking people themselves is more limited), data loss prevention…
Lesson · CIPP/USWorkplace Privacy: The U.S. Legal Landscape
The U.S. has no overarching law for employment privacy. Federal statutes cover specific areas, state contract and tort law offer narrow protections, and…
Lesson · CIPP/USLifestyle Discrimination
Off-duty lifestyle is generally treated as private. Weight-based rules can invite discrimination suits (and obesity from a physiological disability may be…
Lesson · CIPP/USWorkplace Monitoring: Baseline and Policies
U.S. private-sector employees have limited expectations of privacy at work - facilities and equipment belong to the employer, granting broad monitoring…
Lesson · CIPP/USPolygraphs and the EPPA
The Employee Polygraph Protection Act of 1988 (EPPA), enforced by the DOL, bars private employers from using lie detectors on workers or applicants…
Lesson · CIPP/USLegal Obligations and Incentives to Monitor
Employers monitor to meet safety laws (OSHA), improve quality (recorded service calls), limit negligent-supervision liability, protect physical security…
Lesson · CIPP/USFederal Agencies Protecting Employee Privacy
Five federal agencies are central: the DOL (administers FLSA, OSHA, ERISA), the EEOC (Title VII, ADEA, ADA), the FTC and CFPB (unfair/deceptive practices…
Lesson · CIPP/USScreening Technologies: Social Media and AI
Using social media to screen is generally allowed but risks discrimination claims if protected-class info is used, FCRA exposure for nontraditional…
Lesson · CIPP/USState Contract, Tort, and Statutory Protections
Contracts (especially collective bargaining agreements) can create enforceable privacy obligations. Three common-law torts - intrusion upon seclusion…
Lesson · CIPP/USStored Communications Act and City of Ontario v. Quon
The SCA bars unauthorized access to stored electronic communications, with exceptions for the service provider (often the employer) and an authorized…
Lesson · CIPP/USSubstance Use Testing
There is no federal privacy statute directly governing employer substance testing. The ADA excludes current illegal drug use (a drug test is not a medical…
Lesson · CIPP/USCIPP/US automated employment decision tool guide
Automated employment decision tools explained with a source-backed CIPP/US study bridge.
Lesson · CIPP/USCALEA and the Cybersecurity Information Sharing Act
CALEA (1994) requires telecommunications carriers to design interception capability into their products; the FCC extended it to broadband and VoIP. CISA…
Lesson · CIPP/USEvidence Stored Abroad - CLOUD Act and Budapest Convention
The CLOUD Act (2018) lets the DOJ compel U.S. providers to produce data regardless of where it is stored (mooting the Microsoft Ireland case) and lets…
Lesson · CIPP/USDisclosures Forbidden by Law and Evidentiary Privileges
Many privacy laws forbid disclosure using opt-in or opt-out rules: HIPAA and COPPA require opt-in consent; GLBA forbids disclosure if the individual has…
Lesson · CIPP/USDisclosures Permitted by Law
Some laws permit but do not require disclosure. HIPAA requires very few disclosures but permits many (public health, law enforcement, national security)…
Lesson · CIPP/USDisclosures Required by Law
Certain laws compel disclosure: FDA adverse-event reporting, OSHA injury reporting, state injury and disease reporting, and the BSA. HIPAA permits…
Lesson · CIPP/USDiscovery Under HIPAA and GLBA
Sectoral laws coexist with discovery. HIPAA permits PHI in discovery via patient authorization, a court order, or satisfactory assurances (a qualified…
Lesson · CIPP/USElectronic Discovery and ESI
Since the 2006 FRCP revisions, electronically stored information (ESI) drives pretrial discovery. Sound data retention (per Sedona Conference guidance)…
Lesson · CIPP/USFISA, Section 702, Section 215, and FISC
FISA orders issue from the FISC on probable cause that the target is a foreign power or agent, not probable cause of a crime, when foreign intelligence is…
Lesson · CIPP/USEmerging Fourth Amendment Issues - Abortion Data and Geofence Warrants
Post-Dobbs, states that outlaw abortion may send warrants to companies in states that do not, creating an interstate conflict of law (California bars…
Lesson · CIPP/USFourth Amendment Limits on Law Enforcement Searches
The Fourth Amendment bars unreasonable searches; warrants need probable cause, particularity, and a neutral magistrate. Katz created the reasonable…
Lesson · CIPP/USNational Security Letters
An NSL is a subpoena issued by the FBI without judicial involvement for records relevant to terrorism or clandestine intelligence. The PATRIOT Act…
Lesson · CIPP/USNational Security Surveillance - Constitutional Tension and Post-Snowden Reform
National security surveillance pits the president's Article II powers against Article III judicial limits. FISA (1978) balanced both. The PATRIOT Act…
Lesson · CIPP/USHow Disclosures Are Required, Permitted, or Forbidden
When responding to litigation and investigations, the law can require, permit, or forbid disclosure of personal information. The same statute can do all…
Lesson · CIPP/USPreservation Orders and Pen Register / Trap-and-Trace
Under the SCA, a provider must preserve records on a government request pending a court order, similar to a litigation hold. Pen register and…
Lesson · CIPP/USPublic Court Records, Protective Orders, and Required Redaction
U.S. courts are traditionally open, but online records ended practical obscurity. Litigants use protective orders (FRCP 26(c), three-part test) and HIPAA…
Lesson · CIPP/USRight to Financial Privacy Act and Privacy Protection Act
RFPA (1978) requires customer authorization or specific legal process for federal access to individuals' financial records, with advance notice and a…
Lesson · CIPP/USStatutes That Go Beyond Fourth Amendment Requirements
After the Supreme Court held the Fourth Amendment did not protect bank records or dialed numbers, Congress added statutory process. RFPA (1978) covers…
Lesson · CIPP/USCross-Border Discovery and the Hague Convention
U.S. broad-discovery rules collide with foreign laws like the GDPR that protect personal data. Courts split on how to resolve the conflict; the Hague…
Lesson · CIPP/USWiretap Act, ECPA, and Stored Communications Act
The Wiretap Act (Title III) strictly bars intercepting calls; ECPA extends this to electronic communications. Federal law permits one-party consent, but…
Lesson · CIPP/USCIPP/US cybersecurity information sharing guide
Cybersecurity information sharing rules explained with a source-backed CIPP/US study bridge.
Lesson · CIPP/USBreach Notification and Response
A GDPR data breach is broad, covering destruction, loss, alteration, or unauthorized disclosure/access. Controllers must notify the DPA within 72 hours…
Lesson · CIPP/USConsent Under the GDPR
GDPR consent must be freely given, specific, informed, and an unambiguous indication of the data subject's wishes, expressed by statement or clear…
Lesson · CIPP/USController, Processor, and Data Subject
The controller determines the purposes and means of processing; the processor processes on the controller's behalf under contract. The data subject is the…
Lesson · CIPP/USData Subject Rights: Overview and Handling Requests
The GDPR grants individuals control through rights to be informed, access, rectification, erasure, restriction, portability, objection, and freedom from…
Lesson · CIPP/USData Protection Authorities and Data Protection Officers
DPAs are independent national authorities that enforce data protection law - one per member state except Germany (federal plus 16 Lander). The DPO is the…
Lesson · CIPP/USEnforcement: Complaints and Liability
A complaint can be initiated by a data subject or a DPA; where multiple DPAs are involved a lead DPA is determined. Both controllers and processors can be…
Lesson · CIPP/USRights to Erasure and Restriction of Processing
The right to erasure (right to be forgotten) applies in defined situations and requires deletion even from backups unless an exemption applies. As an…
Lesson · CIPP/USGDPR Overview, Scope, and Sanctions
The General Data Protection Regulation (GDPR) is the worldwide template for data protection, applying broadly to companies with EU assets and employees…
Lesson · CIPP/USRecent Developments in Global Data Flows
Beyond the GDPR's influence, the Global CBPR Forum builds on APEC's Cross-Border Privacy Rules to allow trade with privacy assurances, and the OECD…
Lesson · CIPP/USLevels of Fines and Criminal Sanctions
The GDPR has two tiers of fines. Higher-level fines (up to four percent of global revenue or €20 million, whichever is greater) target core processing…
Lesson · CIPP/USPersonal Data and Sensitive Personal Data
Personal data is any data relating to an identified or identifiable natural person, directly or indirectly. Sensitive personal data is a special category…
Lesson · CIPP/USRights to Portability, to Object, and Against Automated Decision-Making
Portability gives data the subject provided in a machine-readable format, only where processing is by consent or contract and automated. The right to…
Lesson · CIPP/USRights to Be Informed, Access, and Rectification
The right to be informed drives privacy notices (layered, just-in-time, dashboards). The right of access underlies the subject access request and is the…
Lesson · CIPP/USAppropriate Safeguards and Derogations
For third countries, transfers need an appropriate safeguard. The two most common are SCCs (the most widely used) and BCRs (for intra-group transfers…
Lesson · CIPP/USEU-U.S. Transfers: Schrems I, Schrems II, and the Data Privacy Framework
The CJEU struck down Safe Harbor (Schrems I, 2015) and Privacy Shield (Schrems II, 2020) over U.S. surveillance concerns. The EU-U.S. Data Privacy…
Lesson · CIPP/USThe Seven General Principles
All processing must abide by the GDPR's seven principles: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage…
Lesson · CIPP/USInternational Transfers and Adequate Countries
Transfers from the EEA to non-EEA countries are prohibited unless supported by an adequacy decision, an appropriate safeguard, or a derogation. Adequate…
Lesson · CIPP/USApplying the Framework: California SB 1386 Breach Notification
California SB 1386 was the first breach-notification law. It covers entities doing business in California that hold computerized personal information…
Lesson · CIPP/USCase Law, Common Law, and Stare Decisis
Case law is judges' final decisions; courts follow precedent under stare decisis. Common law is principles built over time in judicial decisions…
Lesson · CIPP/USConsent Decrees
A consent decree is a judge-approved settlement where the defendant agrees to stop alleged illegal activity, typically without admitting guilt. Once…
Lesson · CIPP/USConstitutions as a Source of Privacy Law
The U.S. Constitution never uses the word privacy, but the Fourth Amendment limits government searches and the Supreme Court recognized a penumbra of…
Lesson · CIPP/USContract Law and Privacy Notices
A contract needs offer, acceptance, and consideration. Privacy obligations often live in vendor contracts, and a privacy notice can itself be a contract…
Lesson · CIPP/USKey Definitions: Person, Jurisdiction, Authority, Preemption, Private Right of Action
Core terms for U.S. privacy law: person (natural or legal), jurisdiction (subject-matter and personal), general vs. specific authority, preemption, and…
Lesson · CIPP/USSix Keys to Understanding Any Law
Analyze any privacy law with six questions: who is covered, what information/uses, what is required/prohibited, who enforces, what happens if you don't…
Lesson · CIPP/USLegislation and Federal Preemption
Both Congress and state legislatures enact privacy laws. The key question is whether a federal law preempts state law: HIPAA lets states pass stricter…
Lesson · CIPP/USNotice, Choice, and Access (Opt-In vs. Opt-Out)
Notice describes information practices; choice lets individuals control collection/use - opt-in is an affirmative yes, opt-out implies consent unless the…
Lesson · CIPP/USRegulations, Rules, and Agency Guidance
Some statutes direct agencies like the FTC or FCC to issue regulations carrying compliance force - e.g., CAN-SPAM rules on the opt-out mechanism. Agencies…
Lesson · CIPP/USFederal and State Regulatory Authorities for Private-Sector Privacy
The FTC has general authority over unfair/deceptive practices plus specific authority in areas like children's privacy; sector regulators include banking…
Lesson · CIPP/USSelf-Regulation in Privacy
Self-regulatory regimes govern many industries' privacy practices - examples include the NAI, the Association of National Advertisers (formerly the DMA)…
Lesson · CIPP/USSources of Law in the United States
U.S. law flows from many sources: constitutions, legislation, case law, contract law, tort law, agency regulations, and consent decrees. Privacy…
Lesson · CIPP/USThe Three Branches of U.S. Government
The U.S. Constitution creates three branches - legislative makes laws, executive enforces them, judicial interprets them - with checks and balances. This…
Lesson · CIPP/USTort Law and Privacy Torts
Torts are civil wrongs in three categories: intentional, negligent, and strict liability. Privacy torts (intrusion on seclusion, public disclosure of…
Lesson · CIPP/USThe Adversarial Mindset: STRIDE, Zero Trust and Least Privilege
Cybersecurity adopts the adversarial mindset and threat modeling (e.g. the STRIDE framework and MITRE ATT&CK). Key principles include zero trust, least…
Lesson · CIPP/USCybersecurity Foundations: The CIA Triad
Security underpins privacy. The CIA triad - confidentiality, integrity, and availability - frames cybersecurity. A useful first approximation: privacy…
Lesson · CIPP/USClient-Server Architecture: Front End and Back End
In the client-server model a client requests a service from a server. The browser-facing front end is separated from the back end databases; separating…
Lesson · CIPP/USCloud Computing: SaaS, PaaS and IaaS
Cloud computing is on-demand availability of computing resources, replacing on-premises computing. The three models - Software as a service (SaaS)…
Lesson · CIPP/USDeep Packet Inspection
Deep packet inspection examines packet contents beyond the header, useful for malware detection and data-leak prevention but also enabling tracking and…
Lesson · CIPP/USDeidentification: Anonymous vs Pseudonymous and Identifiers
When data cannot be traced to a person, privacy law no longer applies. Anonymization removes identifiability; pseudonymization masks identity with a…
Lesson · CIPP/USDeidentification Standards: HIPAA Methods and FTC Guidance
The longest-standing U.S. deidentification rules are under HIPAA: the safe harbor method removes 18 identifiers and the expert determination method relies…
Lesson · CIPP/USApproaches to Deidentification: Suppression, Generalization, Noise Addition
Three core techniques hide identity: suppression removes values, generalization replaces detail with a broader category, and noise addition substitutes…
Lesson · CIPP/USEdge Computing and Latency
Edge computing processes data at the network periphery, close to the source. Driven by the growth of IoT sensors, it reduces the cost of centralized…
Lesson · CIPP/USHow Emails and Texts Work: SMTP, IMAP, POP, SMS and OTT
SMTP sends email; IMAP (which leaves mail on the server) is overtaking POP (which deletes it). Texts use SMS (160-character limit, works without internet)…
Lesson · CIPP/USTracking Email Recipients and Cross-Device Tracking
HTML email can track opens via a unique tracking pixel; reading in plain text defeats it. Cross-device tracking links a user across devices using…
Lesson · CIPP/USEncryption: Symmetric, Asymmetric, Certificates and PKI
Encryption shields data by converting plaintext to ciphertext using a key. Symmetric key cryptography uses one shared key (fast but sharing is hard)…
Lesson · CIPP/USFirst-Party Data Collection and Data Brokers
First parties collect data via cookies, user-generated content (UGC), and account terms of use; in California and the EU they give notice before setting…
Lesson · CIPP/USHashing, Salt and Digital Signatures
Hashing is a one-way function producing an output that does not reveal the input, used for pseudonyms and integrity checks. Plain hashes can be defeated…
Lesson · CIPP/USHTTP Cookies: Session vs Persistent, First vs Third Party
Because HTTP/HTTPS are stateless, HTTP cookies maintain continuity. Session cookies last until the browser closes; persistent cookies can last…
Lesson · CIPP/USBasics of the Internet: TCP/IP and Packet Switching
The internet is a network of networks descended from the ARPANET. Transmission control protocol (TCP) establishes reliable connections and breaks data…
Lesson · CIPP/USKey Web Infrastructure: Servers, Proxies, VPNs, ISPs and IP Addresses
Web content lives on web servers; a proxy server and Virtual private network (VPN) act as gateways that can mask activity. An Internet service provider…
Lesson · CIPP/USLocation Tracking: Technologies and Carpenter
Location is tracked via cell-tower/Wi-Fi triangulation, GPS, and photo metadata. The U.S. has historically had few restrictions, but Carpenter v. United…
Lesson · CIPP/USInternet Monitoring by Employers, Schools and Parents
U.S. employers may generally monitor internet use and emails on company networks/devices. The Children's Internet Protection Act (CIPA) requires public…
Lesson · CIPP/USThe NIST Cybersecurity Framework
The NIST Cybersecurity Framework (CSF), first published in 2014, is guidance rather than law and popularized five Framework Core Functions: Identify…
Lesson · CIPP/USPrivacy by Design and Limits of Technical Measures
Privacy by design embeds privacy from the onset and is legally required in California and the EU. Privacy-enhancing technologies altering or shielding…
Lesson · CIPP/USReidentification Risk and Differential Privacy
Computer scientists have repeatedly re-identified supposedly anonymized data. Differential privacy is a mathematical definition of privacy that adds…
Lesson · CIPP/USSurveillance by Audio, Video and Other Sensors
Devices' microphones and cameras can be hijacked by remote access trojan (RAT) malware, or activated by employers/police. Government video surveillance is…
Lesson · CIPP/USSpyware and Phishing Variants
Spyware (including keylogging) covertly surveils a device, often delivered by phishing social engineering. Variants include spear phishing, whaling…
Lesson · CIPP/USThird-Party Data Collection and the Decline of Third-Party Cookies
Ad networks long used third-party cookies to track users across sites. Market and regulatory changes are shrinking this: the CPRA (effective January 2023)…
Lesson · CIPP/USURLs, URIs, URNs and Hyperlinks
A Uniform resource locator (URL) is a web address with a protocol prefix, optional www, a domain name and a top-level domain. URLs are a subset of Uniform…
Lesson · CIPP/USWeb Infrastructure: HTTP, HTML, HTTPS and XML
The web is narrower than the internet. Hypertext transfer protocol (HTTP) and Hypertext markup language (HTML), invented by Tim Berners-Lee, drive the…
Lesson · CIPP/USWireless Eavesdropping and Defenses
On unencrypted Wi-Fi, packet sniffing can capture traffic, a risk in shared public hotspots. Defenses include encrypted Wi-Fi (per-user keys), VPNs (which…
Lesson · CIPP/USData Breach Readiness Assessments
A data breach readiness assessment examines the risk of a breach plus the likelihood and severity of a personal data breach, weighing data type, technical…
Lesson · CIPP/USThe Business Case for Privacy and the Cost of Mishandling Data
Privacy compliance carries real cost, but mishandling personal data can be far more expensive in fines, breach costs, and lost consumer trust. Privacy is…
Lesson · CIPP/USResponding to User Requests and Consumer Rights
Many federal and state laws grant rights of control: access, correction, deletion, portability, against automated decision-making, and nondiscrimination…
Lesson · CIPP/USData Accountability - Controllers, Processors, and Encryption
Accountability questions cover where/how/how long data is stored, sensitivity, encryption, cross-border transfer, and who sets the rules. A controller…
Lesson · CIPP/USData Flow Mapping - Top-Down and Bottom-Up
After inventory and classification, data flows are mapped and documented (what, where, and why data is processed). The top-down approach used for…
Lesson · CIPP/USData Inventory and Data Classification
An organization should inventory all PI it collects, stores, uses, or discloses (customer and employee), then classify it by sensitivity to set access…
Lesson · CIPP/USThe Data Life Cycle
Data should be managed across its life cycle - creation, storage, sharing and usage, archival, and deletion - because privacy-protecting approaches at one…
Lesson · CIPP/USGlobal Perspective and Cross-Border Data Transfer Mechanisms
More than 160 nations have significant privacy laws; the GDPR draws the most attention, with fines based on worldwide revenue. Cross-border trust…
Lesson · CIPP/USInformation Management and the Privacy Professional's Role
Information management establishes, implements, and monitors the organization's privacy program under a senior leader such as the CPO, drawing on legal…
Lesson · CIPP/USInformation Security - CIA Triad and Control Types
Information security protects information per three attributes - confidentiality, integrity, availability (CIA) - using physical, administrative, and…
Lesson · CIPP/USManaging User Preferences and Dark Patterns
Managing preferences raises challenges of scope, mechanism, linking across channels, time period, and third-party vendors. Good practice: the channel for…
Lesson · CIPP/USOpt-In, Opt-Out, and No Option
U.S. laws differ on consent: opt-in (COPPA parental consent, HIPAA PHI disclosure, FCRA credit report release); opt-out (GLBA third-party transfers, VPPA…
Lesson · CIPP/USDPIA vs PIA: What Is the Difference? CIPP/US Guide
DPIA vs PIA explained: what each assessment is, when the GDPR requires a DPIA, what a U.S. PIA covers and how CIPP/US questions test the difference.
Lesson · CIPP/USDelivering Privacy Notices - Layered, Just-in-Time, and Mobile
Notices should be accessible online and in-person, with training for staff. Common techniques include the layered notice (short top layer plus full bottom…
Lesson · CIPP/USPrivacy Operational Life Cycle - Assess, Protect, Sustain, Respond
The privacy operational life cycle continuously improves the program through four stages: assess, protect, sustain, and respond - from baselining and…
Lesson · CIPP/USDrafting, Updating, and Versioning the Privacy Policy
Policies need legal review and executive approval, periodic review (at least annually), and version control. The FTC says express affirmative consent…
Lesson · CIPP/USPrivacy Policy vs Privacy Notice: The Difference for CIPP/US
Privacy policy vs privacy notice explained: the policy is the internal rulebook, the notice is the external statement to consumers, and the exam tests…
Lesson · CIPP/USThe Privacy Program and Four Business Risks
A privacy program establishes accountability and compliance, and should balance four business risks: legal, reputational, operational, and strategic. The…
Lesson · CIPP/USPrivacy Program Framework and Metrics
A privacy program framework operationalizes controls and should begin with a privacy mission statement/vision aligned to the organization. Building it…
Lesson · CIPP/USPrivacy Risk Management and Privacy Harms
Privacy risk management identifies and mitigates risks to information assets. Privacy risk is the likelihood individuals will experience problems from…
Lesson · CIPP/USPrivacy Team Roles - CPO, DPO, and Others
A privacy team may include a CPO, DPO, chief legal officer, privacy engineer, privacy manager, and privacy analyst, plus informal privacy champions and…
Lesson · CIPP/USVendor and Third-Party Risk Assessments
Companies remain responsible for vendor actions and must use contract protections (confidentiality, no further use, subcontractor flow-down, breach…
Lesson · CIPP/USAdditional FTC Authority: COPPA, HITECH, FCRA, CAN-SPAM
Beyond Section 5 the FTC enforces COPPA (children under 13, parental consent), shares HITECH breach authority with HHS, has historic FCRA/FACTA authority…
Lesson · CIPP/USAdditional State Protections: Torts, BIPA, and the AADC Act
States add protection via constitutions, common-law privacy torts, and contract theories. Illinois's BIPA (2008) requires notice and consent for…
Lesson · CIPP/USDeceptive Trade Practices and Broken Privacy Promises
A deceptive practice is a material statement or omission likely to mislead reasonable consumers. Breaking a privacy-notice promise is deceptive under…
Lesson · CIPP/USFederal Privacy Enforcement Outside the FTC
Many federal agencies enforce privacy depending on the statute violated: OCR/HHS for HIPAA, CFPB and bank regulators for GLBA, Dept. of Education for…
Lesson · CIPP/USThe Federal and State Regulatory Landscape
In the U.S., privacy is regulated at both federal and state level. Federal regulators are largely sectoral (medical, financial, education), the FTC is the…
Lesson · CIPP/USFTC Enforcement Process and Consent Decrees
Most FTC privacy actions end in a consent decree: the respondent does not admit fault but promises to change practices. Decrees are public, may require…
Lesson · CIPP/USFTC Enforcement Tools and the AMG Decision
The FTC uses Section 5(l) for administrative cease-and-desist enforcement and Sections 13(b) and 19 for judicial relief. The Supreme Court in AMG Capital…
Lesson · CIPP/USThe FTC, Section 5, and Jurisdictional Limits
Section 5 of the FTC Act bars unfair or deceptive acts or practices in or affecting commerce and is the single most important piece of U.S. privacy law…
Lesson · CIPP/USThe Future of FTC Enforcement
FTC priorities track technology: a 2023 Office of Technology, 2022 proposed commercial surveillance rules (under Magnuson-Moss), a 2020 data portability…
Lesson · CIPP/USFTC Rulemaking Under Magnuson-Moss
The FTC's UDAP rulemaking does not use ordinary APA notice-and-comment. It must follow the complex Magnuson-Moss (Section 18) procedures, showing the…
Lesson · CIPP/USOther Federal Privacy Actors and the DOJ's Criminal Role
Beyond sector regulators, agencies like State, Commerce, Transportation, OMB, IRS/Treasury, DHS, and DOE touch privacy. OMB interprets the Privacy Act of…
Lesson · CIPP/USSelf-Regulation and Enforcement
Self-regulation spans legislation, enforcement, and adjudication. Under Section 5/UDAP it is only quasi-legislative (a government agency still enforces)…
Lesson · CIPP/USState Attorneys General and UDAP Statutes
State AGs are the primary privacy enforcers in most states and may join federal actions under HIPAA, GLBA, and CAN-SPAM. All 50 states have UDAP statutes…
Lesson · CIPP/USState Breach Notification, SSN Protections, and Identity Theft Laws
California enacted the first breach law in 2002; all 50 states now have one. Breach-law personal information centers on name + SSN, driver's license/ID…
Lesson · CIPP/USState Comprehensive Laws and Federal Sectoral Exemptions
By end of 2022, five states had comprehensive laws: California, Colorado, Connecticut, Utah, Virginia. They reference COPPA for children and exempt…
Lesson · CIPP/USTypes of Litigation and Enforcement
Three main categories of legal action: civil litigation (private plaintiff seeks damages or an injunction), criminal prosecution (government, can mean…
Lesson · CIPP/USUnfair Trade Practices
An unfair practice causes or is likely to cause substantial injury that is not reasonably avoidable by consumers and not outweighed by countervailing…
Lesson · CIPP/USCourt Confirmation of FTC Authority: Wyndham and LabMD
FTC v. Wyndham (2015, Third Circuit) confirmed the FTC's unfairness authority extends to cybersecurity. FTC v. LabMD (2018, Eleventh Circuit) recognized…
Lesson · CIPP/USAccess, Correction, and Deletion Rights
All five states grant access and deletion; the right to correction is provided by everyone except Utah. Deletion scope differs: Colorado, Connecticut…
Lesson · CIPP/USDefining Business - Applicability Thresholds
Which companies are covered turns on the definition of business (called controller in the four non-California states). California is broadest ($25M…
Lesson · CIPP/USWhich Entities Are Excluded from Business
All five states exempt governments, nonprofits, and FCRA-covered entities. But the states diverge on higher education, securities associations, and…
Lesson · CIPP/USCCPA vs CPRA: What Changed? CIPP/US California Guide
CCPA vs CPRA explained: the CPRA amended the CCPA rather than replacing it. What changed, what the exam tests and how to answer California questions.
Lesson · CIPP/USOpt-In Default for Children's Data
Age-based opt-in rules vary: California requires opt-in to sell/share data of consumers under 16; Connecticut requires opt-in for ages 13-16 to sell or…
Lesson · CIPP/USDefining Consumer - Who Is Protected
All five laws protect their state residents, and the term is NOT limited to purchasers. The key distinction: California includes employees in its…
Lesson · CIPP/USConsumer Rights Overview and Response Timelines
These laws grant GDPR-like rights (access, correction, deletion, portability, opt-outs, etc.). Response times: Colorado, Connecticut, Utah, Virginia allow…
Lesson · CIPP/USCure Periods and the Private Right of Action
Cure periods split: California's expired; Colorado and Connecticut's sunset Dec 31, 2024; Utah and Virginia have a 30-day cure with no end date. No state…
Lesson · CIPP/USEnforcement - Penalties and Enforcers
The state attorney general has sole or joint enforcement power in every state; California adds the CPPA. Penalty caps vary: California $2,500 (up to…
Lesson · CIPP/USEntity-Level vs Data-Based Exemptions
State comprehensive laws use two exemption types: entity-level exemptions (a whole organization is exempt) and data-based exemptions (only a class of data…
Lesson · CIPP/USThe U.S. Has No Federal Comprehensive Privacy Law
The United States regulates privacy sectorally (HIPAA, GLBA, COPPA) and as of this writing has no federal comprehensive privacy law, unlike most countries…
Lesson · CIPP/USBusiness Obligation - Notice and Transparency
All five states require a privacy notice and a notice of the right to opt out. Only California requires notice at the point of collection, and California…
Lesson · CIPP/USOpt-Out Rights - Sales, Targeted Advertising, Automated Decisions
All five states allow opt out of sales; California also lets consumers opt out of sharing. For targeting/cross-context behavioral advertising, Colorado…
Lesson · CIPP/USPersonal Information and Its Exclusions
All five define personal information as data linkable to an individual, going beyond breach-notification definitions. California uniquely includes…
Lesson · CIPP/USFederal Preemption and Private Right of Action Debates
The two most contested issues in any U.S. national privacy bill are preemption (would it override stricter state laws?) and a private right of action…
Lesson · CIPP/USPurpose Limits, Risk Assessments, and Security
California, Colorado, Connecticut, Virginia impose purpose/processing limitations and require risk assessments for heightened-risk processing; Utah lacks…
Lesson · CIPP/USSale and California's Unique Sharing Regulation
Each state regulates the sale of personal data, but the definition splits: Utah and Virginia limit sale to monetary compensation, while California…
Lesson · CIPP/USRights Concerning Sensitive Data and Nondiscrimination
Sensitive-data handling splits sharply: Colorado, Connecticut, Virginia require opt-in consent; Utah requires only notice and opt-out; California uses a…
Lesson · CIPP/USSensitive Personal Information
All five states treat citizenship, genetic/biometric data, physical/mental health, race/ethnicity, religion, and sexual orientation as sensitive. States…
Lesson · CIPP/USThe Five State Laws in Effect in 2023
This chapter focuses on the five state comprehensive laws in effect in 2023: California, plus the CPA (Colorado), CTDPA (Connecticut), UCPA (Utah), and…
Lesson · CIPP/USCIPP/US Global Privacy Control and opt-out signals
Global Privacy Control and California opt-out handling explained for CIPP/US study.
Lesson · CIPP/USNotification: Attorney General and State Agency Notice
About two-thirds of states require notice to the attorney general/state agency, often above a numeric threshold (commonly 250 to 1,000 people). Vermont's…
Lesson · CIPP/USCommon Structure of State Breach Laws
Despite differences, state breach laws share three building blocks: key terms (personal information, covered entities, security breach), notification…
Lesson · CIPP/USCalifornia Statutory Damages (CCPA/CPRA)
In 2020 California became the first state to let consumers recover statutory damages for breaches: $100 to $750 per incident where the breach resulted…
Lesson · CIPP/USState Breach, Security, and Destruction Laws: The Landscape
All 50 states have data breach notification laws, and many states layer on data security laws and data destruction laws. With no comprehensive federal…
Lesson · CIPP/USBreach Laws: Covered Entities
Most states cover entities that conduct business in the state and maintain computerized data containing personal information. Georgia is a notable…
Lesson · CIPP/USNotification: Consumer Reporting Agencies
About two-thirds of states require notice to nationwide CRAs, often above a 250 to 1,000 threshold. The common timing standard is without unreasonable…
Lesson · CIPP/USNotification: Free Credit Monitoring
When SSNs are exposed, the FTC suggests offering at least a year of free credit monitoring. Three states - California, Delaware, and Massachusetts -…
Lesson · CIPP/USWhen Notification May Be Delayed
When a breach is suspected to involve criminal activity, all states allow delay if law enforcement determines notice would impede a criminal…
Lesson · CIPP/USEnforcement: Penalties and Private Rights of Action
All 50 states impose civil penalties; about one-third let the attorney general levy fines, often capped per breach ($750,000 being the highest noted, in…
Lesson · CIPP/USExceptions to Notification
Three exceptions excuse notice: an entity subject to a more stringent law (e.g., HIPAA or the GLBA Safeguards Rule), an entity following its own…
Lesson · CIPP/USNotification: Method and Substitute Notice
The default method is written notice by postal mail. Email or phone are usually allowed only if the person previously and explicitly chose that channel…
Lesson · CIPP/USThe Absence of a Federal Breach Law
Calls for a uniform federal breach law go back to 2003, but no comprehensive federal data breach notification law has been enacted. The deadlock turns on…
Lesson · CIPP/USNotification: Content of the Letter
About half of states mandate specific content (incident description, approximate date, data types, steps taken, contact phone, identity-theft steps, CRA…
Lesson · CIPP/USBreach Laws: Defining Personal Information
In most states, personal information means a person's first name or first initial and last name combined with at least one of: SSN, driver's license/state…
Lesson · CIPP/USBreach Laws: Security Breach and Risk-of-Harm
A security breach is generally unauthorized access to or acquisition of computerized personal data that compromises its confidentiality, security, or…
Lesson · CIPP/USState Data Destruction Laws
About two-thirds of states have data destruction (disposal) laws requiring personal information to be disposed of so it is no longer readable or…
Lesson · CIPP/USState Data Security Laws
About two-thirds of states require data security measures. Roughly 20 states use a 'reasonable security' standard (e.g., California's AB 1950); about 10…
Lesson · CIPP/USUS Approach in Context
The lack of comprehensive federal breach, security, and destruction requirements leads some to call the US less stringent than jurisdictions like Europe…
Lesson · CIPP/USNotification: Timing to Affected Parties
The most common timing standard is as expeditiously as possible and without unreasonable delay. Where a specific cap is set, 45 days after discovery is…
Lesson · CIPP/USNotification: Whom to Notify
Breach laws commonly require notice to three audiences: affected residents (all 50 states), state attorneys general/agencies (about two-thirds), and…
Lesson · CIPP/USCIPP/US data broker registration and deletion guide
California data broker registration and deletion mechanisms explained for CIPP/US study.
Lesson · CIPP/USCIPP/US biometric privacy law and facial data guide
State biometric privacy law concepts explained with a source-backed CIPP/US study bridge.
Lesson · CIPP/USCIPP/US Illinois genetic privacy law guide
Illinois genetic privacy law explained with a direct answer and CIPP/US study context.
Lesson · CIPP/USCIPP/US Washington consumer health data law guide
Washington consumer health data law explained with a source-backed CIPP/US study bridge.
Lesson · CIPP/USCIPP/US state AI and employment decision guide
Automated employment decision tool rules explained with a source-backed CIPP/US study bridge.
Lesson · CIPP/USBusiness Associates and BAAs
A business associate performs services for a covered entity involving the use or disclosure of PHI. Before HITECH they were bound only by contract; after…
Lesson · CIPP/USCovered Entities Under HIPAA
HIPAA directly covers health care providers conducting certain electronic transactions, health plans, and health care clearinghouses. Cash-only providers…
Lesson · CIPP/US21st Century Cures Act and Information Blocking
The Cures Act (2016) promotes EHI interoperability by prohibiting information blocking - activity likely to interfere with access, exchange, or use of…
Lesson · CIPP/USCures Act: API Portability and Other Privacy Provisions
The Cures Act requires certified health IT developers to publish APIs so patients can move EHI to apps of their choosing - raising the concern that data…
Lesson · CIPP/USGINA Preemption and State Genetic Laws
GINA is a floor and does not preempt stricter state law. Because GINA leaves life insurers, mortgage lenders, and schools untouched, states like…
Lesson · CIPP/USGenetic Information Nondiscrimination Act (GINA)
GINA (2008) bars health insurers from discriminating on genetic predisposition absent manifest symptoms and bars employers from using genetic information…
Lesson · CIPP/USHIPAA Enforcement and Penalties
The OCR enforces both rules with civil penalties up to roughly $2 million per year per violation type and audits entities. HIPAA has no private right of…
Lesson · CIPP/USHIPAA Origins and Purpose
HIPAA became law in 1996 to improve health care efficiency, requiring electronic reimbursement formats for Medicare and Medicaid. Recognizing the privacy…
Lesson · CIPP/USHIPAA Preemption and State Laws
HIPAA does not preempt stricter state laws. Practitioners must review state law for added patient rights, extra disclosures, and shorter deadlines, and…
Lesson · CIPP/USHealth Information Is Protected Differently by Setting
HIPAA only applies to covered entities and their business associates. The same health-related data held by a bookstore, website, or smartwatch maker…
Lesson · CIPP/USHITECH and Breach Notification
HITECH (2009) strengthened HIPAA and created breach notification. A breach is presumed unless a risk assessment shows low probability of compromise…
Lesson · CIPP/USHITECH: Penalties, Limited Data, and EHRs
HITECH increased penalties (up to $2 million for willful violations, even without knowledge) and extended criminal liability to individuals. It encourages…
Lesson · CIPP/USMedical Technology: FTC Act, FDCA, and State Laws
For medtech outside HIPAA, Section 5 of the FTC Act is the primary federal tool against deceptive and unfair practices (e.g., the 2021 Flo Health action)…
Lesson · CIPP/USPHI and ePHI Defined
PHI is individually identifiable health information held by a covered entity or business associate relating to a person's health, care, or payment. ePHI…
Lesson · CIPP/USLimits and Exceptions to the Privacy Rule
The Privacy Rule does not apply to deidentified information and offers flexibility for research. Other exceptions allow disclosure without consent for…
Lesson · CIPP/USThe HIPAA Privacy Rule and the FIPPs
The Privacy Rule is HIPAA's most detailed implementation of Fair Information Privacy Practices: privacy notices, authorizations, minimum necessary limits…
Lesson · CIPP/USThe HIPAA Security Rule
Finalized in 2003, the Security Rule covers only ePHI and binds both covered entities and business associates. It requires administrative, physical, and…
Lesson · CIPP/USConfidentiality of Substance Use Disorder Patient Records Rule
Rooted in 1970s laws, this rule protects patient-identifying information held by federally funded substance abuse treatment programs. It requires written…
Lesson · CIPP/USTemporary COVID-19 telehealth measures
During the COVID-19 public health emergency, OCR temporarily allowed nonpublic-facing videoconferencing even when it did not fully meet HIPAA rules. That…
Lesson · CIPP/USWhy Medical Privacy Gets Special Protection
Health information is treated as especially sensitive because it relates to one's body and mind, encourages candor with doctors, and protects against…
Lesson · CIPP/USCIPP/US FTC health breach notification rule guide
The FTC Health Breach Notification Rule explained with a source-backed CIPP/US study bridge.
Lesson · CIPP/USCIPP/US 42 CFR Part 2 confidentiality guide
42 CFR Part 2 explained with a source-backed CIPP/US study bridge.
Lesson · CIPP/USCIPP/US HIPAA online tracking technology guide
HIPAA online tracking technology issues explained with a source-backed CIPP/US study bridge.
Lesson · CIPP/USAnti-Money-Laundering: The Bank Secrecy Act
The Bank Secrecy Act (1970) imposes recordkeeping and reporting on financial institutions, requiring reports of currency transactions over $10,000 to the…
Lesson · CIPP/USThe Disposal Rule
The Disposal Rule requires anyone using a consumer report for business to dispose of that information reasonably to prevent unauthorized access. It…
Lesson · CIPP/USDodd-Frank and the CFPB's Authority
Dodd-Frank (2010) created the CFPB within the Federal Reserve. The CFPB has rulemaking authority over the FCRA, GLBA and Fair Debt Collection Practices…
Lesson · CIPP/USFACTA Amendments and Consumer Protections
FACTA (2003) amended the FCRA, preempting stricter state laws in most areas (states keep some identity-theft powers). It required truncation of card…
Lesson · CIPP/USAdverse Action Notices
An adverse action is any negative business, credit or employment decision. When a user acts adversely based even in part on a consumer report, it must…
Lesson · CIPP/USCRAs and Consumer Reports Defined
A consumer reporting agency (CRA) compiles or evaluates personal information to furnish consumer reports to third parties for a fee. The FCRA's…
Lesson · CIPP/USCRA Core Requirements: Access, Accuracy, Obsolescence
CRAs must give consumers access and the right to dispute, take reasonable steps for maximum possible accuracy, and not report outdated negatives…
Lesson · CIPP/USConsumer Reports for Employment
Employers using consumer reports must give a clear written stand-alone notice, get prior written authorization, certify compliance to the CRA (including…
Lesson · CIPP/USFCRA Enforcement and Penalties
FCRA enforcement runs through dispute resolution, private litigation (including class actions), and government action by the FTC, CFPB and state attorneys…
Lesson · CIPP/USFurnisher Duties and the Furnisher Rule
Furnishers must provide accurate data, correct and update it, give notice of disputes to CRAs, and respond to identity-theft information. The Furnisher…
Lesson · CIPP/USMisconduct Investigations and Investigative Consumer Reports
Internal misconduct investigations are not consumer reports if the employer follows the act's procedures, uses no credit information, and gives a summary…
Lesson · CIPP/USMedical Information and Prescreened Lists Under FCRA
FCRA limits use of medical information from CRAs, generally requiring consent or coding for insurance, employment or credit uses. Prescreened lists let…
Lesson · CIPP/USPermissible Purpose and Certification
A user may obtain a consumer report only with a permissible purpose and must certify that purpose to the CRA, plus certify the report will not be used for…
Lesson · CIPP/USFCRA Purpose, History and Preemption
Enacted in 1970, the FCRA was the first federal law to regulate private businesses' use of personal information. It mandates accurate, relevant data…
Lesson · CIPP/USRisk-Based Pricing and Credit Score Disclosures
Under the Risk-Based Pricing Rule, lenders must notify consumers who receive less favorable terms because of their credit report. Anyone using credit…
Lesson · CIPP/USUsers and Furnishers Under the FCRA
Beyond CRAs, the FCRA binds users (lenders, insurers, employers who use reports) and furnishers (lenders, retailers who supply data to CRAs). Users need a…
Lesson · CIPP/USFinancial Privacy Landscape and Regulators
U.S. financial privacy is governed mainly by the FCRA (1970), GLBA (1999), and the Dodd-Frank Act (2010), which created the CFPB. Financial institutions…
Lesson · CIPP/USFuture of Financial Regulation and Cryptocurrency Privacy
Cryptocurrency privacy depends on whether governments take a high- or low-regulation approach. Under low regulation, privacy depends on market and…
Lesson · CIPP/USGLBA Overview and Privacy Provisions
GLBA (Title V of the 1999 Financial Services Modernization Act) produced a Privacy Rule and a Safeguards Rule. Spurred by the U.S. Bancorp/MemberWorks…
Lesson · CIPP/USThe GLBA Privacy Rule
The Privacy Rule requires initial and annual privacy notices and processing of opt-outs within 30 days. Institutions may freely share with affiliates and…
Lesson · CIPP/USThe GLBA Safeguards Rule
The Safeguards Rule (effective 2003, updated by the FTC in 2021) requires a written information security program with administrative, technical and…
Lesson · CIPP/USGLBA Scope, NPI and Enforcement
GLBA covers financial institutions significantly engaged in financial activities and regulates nonpublic personal information (NPI). Enforcement runs…
Lesson · CIPP/USUSA PATRIOT Act, KYC, FATCA and the AML Act of 2020
The International Money Laundering Abatement and Anti-Terrorist Financing Act (2001), part of the USA PATRIOT Act, expanded the BSA and added Know Your…
Lesson · CIPP/USThe Red Flags Rule
The Red Flags Rule requires financial institutions and creditors to maintain written identity-theft detection programs that spot and respond to red flags…
Lesson · CIPP/USRegulation E and EFTA. CIPP/US transfer rules guide
Regulation E and the EFTA explained with coverage, consumer protections and CIPP/US study context.
Lesson · CIPP/USSuspicious Activity Reports and BSA Enforcement
Institutions must file a Suspicious Activity Report (SAR) with FinCEN for insider crimes regardless of amount, crimes of $5,000+ with a suspect, crimes of…
Lesson · CIPP/USState Financial Privacy: California (CFIPA) and New York (NYDFS)
Because GLBA does not preempt states, California's CFIPA (SB-1) adds opt-in consent for sharing with nonaffiliated third parties, and New York's NYDFS…
Lesson · CIPP/USCIPP/US Bank Secrecy Act and merger privacy guide
Bank Secrecy Act and merger privacy issues explained with a CIPP/US study bridge.
Lesson · CIPP/USCIPP/US GLBA annual privacy notice guide
GLBA annual privacy notices explained with a source-backed CIPP/US study bridge.
Looking for AI governance? Explore the AIGP study guide.