Study resourcesCIPP/US

The complete study library

Explore the CIPP/US study library

Search 321 free study resources for CIPP/US. Find a lesson, review a term or choose a practice session.

321 resources

Guide · CIPP/US

CIPP/US exam format and blueprint

The current CIPP/US exam format, timing, question types and a practical way to use the IAPP Body of Knowledge and blueprint.

Guide · CIPP/US

CIPP/US exam questions explained

CIPP/US practice questions for exam prep: 604 exam-style questions, a 90-question timed set, worked explanations and a free diagnostic.

Guide · CIPP/US

CIPP/US practice questions and practice exam

Take a free CIPP/US diagnostic, then use 604 practice questions and a timed 90-question set with explanations.

Guide · CIPP/US

CIPP/US study guide

CIPP/US study guide with free lessons, a ten-question diagnostic and 604 exam-style practice questions for scenario-based exam prep.

Guide · CIPP/US

CIPP/US study plan

A four-week CIPP/US study plan that turns the published outline into a 30-hour schedule with review and timed practice.

Practice · CIPP/US

CIPP/US cram sheet

The complete CIPP/US memorisation sheet: the timeline, dollar amounts and deadlines, opt-in vs opt-out, who enforces what, the sectoral laws, the Supreme…

Practice · CIPP/US

Find the CIPP/US areas to study next.

Take a free 10-question CIPP/US diagnostic. Get an immediate domain score and a personalised study plan without creating an account.

Guide · CIPP/US

CIPP/US essentials

The essentials tier for the IAPP CIPP/US - the most-tested laws, regulators, opt-in/opt-out rules and distinctions per exam area, condensed to one page…

Guide · CIPP/US

CIPP/US: the whole exam on one page

Every exam-relevant U.S. privacy law, regulator, threshold, opt-in vs opt-out rule, distinction and landmark case for the IAPP CIPP/US - condensed onto…

Glossary · CIPP/US

CIPP/US glossary

Plain-language definitions for recurring terms in the CIPP/US study guide.

Guide · CIPP/US

HIPAA vs FERPA

A practical HIPAA versus FERPA decision guide for school nurses, outside providers, university clinics and mixed student and nonstudent records.

Guide · CIPP/US

How to pass the CIPP/US

How to pass the IAPP CIPP/US exam: what it tests, the format, a study plan, the sectoral-law traps, and free study notes plus the exam-style question set.

Guide · CIPP/US

Is the CIPP/US exam hard?

Is the CIPP/US exam hard? Format, pass mark, domain weights, where candidates struggle and a practical way to prepare.

Practice · CIPP/US

Free CIPP/US mini mock

Try 25 exam-style CIPP/US practice questions free, with explanations and a domain score. No account or payment required.

Practice · CIPP/US

A processor discovers a breach affecting personal data it handles for a controller. What is the processor's obligation under the GDPR?

A processor discovers a breach affecting personal data it handles for a controller. What is the processor's obligation under the GDPR? Answer with a worked…

Lesson · CIPP/US

APEC Privacy Framework (2004)

APEC is a 21-member organization operating under nonbinding agreement. Its 2004 Privacy Framework (updated 2015) sets nine principles that mirror the OECD…

Lesson · CIPP/US

The Four Classes of Privacy

Privacy splits into four classes: information, bodily, territorial, and communications privacy. This book focuses primarily on information privacy.

Lesson · CIPP/US

Co-Regulatory, Self-Regulatory, and Technology Models

Co-regulation (e.g., Australia; U.S. COPPA codes approved by the FTC) pairs industry codes with government law. Self-regulation (e.g., PCI DSS, seal…

Lesson · CIPP/US

Comprehensive Model of Data Protection

Comprehensive laws govern personal data across public and private sectors economy-wide, typically with an oversight DPA. Countries adopt them to remedy…

Lesson · CIPP/US

Council of Europe Convention 108 (1981)

Convention 108 (1981) required its parties to enact data protection provisions in domestic law. It was modernised through the 2018 protocol known as…

Lesson · CIPP/US

Defining Privacy

In 1890, Warren and Brandeis defined privacy as the right to be let alone in the Harvard Law Review. U.S. law calls this field privacy law while the EU…

Lesson · CIPP/US

Fair Information Practices (FIPs) Overview

Since the 1970s, Fair Information Practices (FIPs/FIPPs) have organized individual rights and organizational responsibilities into four categories: rights…

Lesson · CIPP/US

U.S. HEW Fair Information Practices (1973)

The FIPs used widely today trace to a 1973 U.S. Department of Health, Education and Welfare report whose Code of Fair Information Practices set five core…

Lesson · CIPP/US

Historical and Social Origins of Privacy

Privacy roots run from classical Greece and the Bible to England's 1361 Justices of the Peace Act. The U.S. Constitution protects privacy without naming…

Lesson · CIPP/US

Information Technology and the Rise of Data Protection Law

Mainframes in the 1960s spurred privacy fears (Orwell's '1984'). In 1970, Hesse, Germany enacted the first modern data protection law; the same year the…

Lesson · CIPP/US

Madrid Resolution (2009)

The 2009 Madrid Resolution was approved by data protection commissioners themselves, not governments, to define uniform privacy principles and facilitate…

Lesson · CIPP/US

Nonpersonal, Deidentified, and Pseudonymized Information

Remove identifying elements and data becomes nonpersonal (deidentified/anonymized), generally outside privacy laws. Pseudonymized data is only temporarily…

Lesson · CIPP/US

OECD Guidelines (1980)

The 1980 OECD Guidelines (updated 2013) are the most widely recognized FIP framework and have been endorsed by the FTC. They set eight principles, from…

Lesson · CIPP/US

Personal Information and Sensitive Personal Information

In the U.S., personal information and personally identifiable information (PII) cover data that can identify an individual. Sensitive personal information…

Lesson · CIPP/US

The Line Between Personal and Nonpersonal Information

Where personal ends and nonpersonal begins is unclear and varies by regime. The EU generally treats IP addresses as personal data; U.S. agencies under the…

Lesson · CIPP/US

Processing and Data Roles - Subject, Controller, Processor

Processing covers almost anything done with personal data. The data controller decides how and why data is processed and bears most obligations; the data…

Lesson · CIPP/US

Sectoral Model (United States)

The sectoral model (the U.S. approach) protects personal data through laws targeting specific industries. Strengths: tailored, lower burden. Weaknesses…

Lesson · CIPP/US

Sources of Personal Information

The same data can be treated differently by source: public records (held by government, available to the public), publicly available information (broadly…

Lesson · CIPP/US

Sources of Privacy Protection

Privacy protection comes from four sources: markets, technology, law, and self-regulation/co-regulation. Law is the traditional approach but real…

Lesson · CIPP/US

Cybersecurity Requirements in Education

FERPA expects reasonable security but specifies no particular controls; the GLBA Safeguards Rule applies to universities holding financial aid information…

Lesson · CIPP/US

Edtech under COPPA and Self-Regulation

In 2022 the FTC announced it would police edtech through COPPA, prohibiting use of children's data for commercial purposes, barring unreasonable mandatory…

Lesson · CIPP/US

Education Technology and FERPA

Edtech companies that handle student data are subject to FERPA. The 2014 Google Apps for Education lawsuit (with EPIC alleging FERPA violations over email…

Lesson · CIPP/US

Rights to Access, Review, and Correction

FERPA gives students the right to access and review most records within 45 days of a request and the right to seek correction of inaccurate, misleading…

Lesson · CIPP/US

Statutory Exceptions to FERPA Consent

FERPA lists many no-consent disclosure exceptions, including school officials with a legitimate educational interest, transfer schools, financial aid…

Lesson · CIPP/US

Valid Consent and Identity Verification

Valid FERPA consent must be signed, dated, and written, identifying the records, the purpose, and the recipient. When relying on a statutory exception…

Lesson · CIPP/US

Directory Information and Opt-Out

Directory information is data that would not generally be considered harmful if disclosed; each institution defines its own list, and before using it the…

Lesson · CIPP/US

When Disclosure of Education Records Is Permitted

FERPA permits disclosure of education records only if the data is not PII, it is unblocked directory information, the rights holder consents, the…

Lesson · CIPP/US

Education Record and Its Exceptions

An education record is broadly any record directly related to a student and maintained by or on behalf of the school, but FERPA carves out important…

Lesson · CIPP/US

FERPA Enforcement, No Private Right, and Preemption

FERPA is enforced by the Department of Education through the Family Policy Compliance Officer (FPCO); the ultimate penalty is loss of federal funding…

Lesson · CIPP/US

Holder of FERPA Rights

Who holds FERPA rights depends on context: in high school the parent holds rights until the student turns 18; once a student attends only a college or…

Lesson · CIPP/US

FERPA Overview and Scope

The Family Educational Rights and Privacy Act of 1974 (FERPA), also called the Buckley Amendment, gives students control over disclosure of and access to…

Lesson · CIPP/US

Personally Identifiable Information under FERPA

FERPA's PII definition covers names, family member names, addresses, SSNs and student numbers, dates and places of birth, and any information that alone…

Lesson · CIPP/US

FERPA Definition of Student

Under FERPA, a student is anyone who is or has been in attendance at an educational institution, including online attendees, but the term excludes…

Lesson · CIPP/US

Individuals with Disabilities Education Act

IDEA guarantees eligible students aged 3 to 21 a free appropriate public education through an IEP, and protects the privacy of special-education records…

Lesson · CIPP/US

PPRA and the No Child Left Behind Amendments

The PPRA (1978) amended FERPA to protect parents of minors over surveys collecting sensitive information and applies only to K-12 schools, not colleges…

Lesson · CIPP/US

State Student Privacy Laws and SOPIPA

Because FERPA does not preempt state law, states add their own protections. California's SOPIPA was the first U.S. law to prohibit using student data for…

Lesson · CIPP/US

CIPP/US COPPA rule and children's data guide

COPPA requirements and current FTC rule material explained for CIPP/US study.

Lesson · CIPP/US

CIPP/US Epic Games COPPA enforcement guide

Epic Games COPPA enforcement as a CIPP/US scenario review, with primary FTC source material.

Lesson · CIPP/US

The Cable Communications Policy Act of 1984

The Cable Act regulates cable providers' notice, collection, disclosure and retention of subscriber data, and grants a private right of action. Providers…

Lesson · CIPP/US

The CAN-SPAM Act of 2003

CAN-SPAM governs commercial email to or from the U.S. on an opt-out basis: no false headers or deceptive subject lines, a working return address, a clear…

Lesson · CIPP/US

CAN-SPAM Wireless Rules: MSCMs, Express Prior Authorization and the Wireless Domain Registry

The FCC's CAN-SPAM wireless rules require express prior authorization (opt-in) for each mobile service commercial message (MSCM) sent to wireless devices…

Lesson · CIPP/US

CPNI Opt-in/Opt-out Rules, Pretexting and Covered Entities

After U.S. West v. FCC struck a 1998 opt-in rule on First Amendment grounds, carriers' own use of CPNI shifted to opt-out. The 2007 CPNI order requires…

Lesson · CIPP/US

Digital Advertising Ethics: Behavioral Advertising, Dark Patterns and Children

Beyond legal compliance, ethical digital advertising stresses honesty, fairness and transparency. Key concerns: online behavioral advertising (tracking…

Lesson · CIPP/US

Exceptions to the DNC Rules: EBR, Consent and DNC Safe Harbor

DNC rules do not apply to nonprofits calling for themselves, existing-customer calls within 18 months, non-upsell inbound calls, or most B2B calls. An EBR…

Lesson · CIPP/US

Fax Marketing: TCPA and the Junk Fax Prevention Act

The TCPA (enforced by the FCC) bars unsolicited commercial faxes; consent can be explicit or inferred from an EBR. The 2005 Junk Fax Prevention Act…

Lesson · CIPP/US

The National Do Not Call Registry

The National DNC Registry (effective 2003) lets residents register residential and wireless numbers. Sellers/telemarketers must access it before calling…

Lesson · CIPP/US

Robocall Enforcement Actions and State Telemarketing Laws

Regulators have escalated robocall enforcement (a 2021 FCC $225 million record fine for ~1 billion robocalls; a 2019 multistate initiative). Because…

Lesson · CIPP/US

Self-Regulation for Digital Advertising: DAA and NAI

Two voluntary codes govern much online behavioral advertising: the DAA Self-Regulatory Principles and the NAI Code of Conduct, both emphasizing opt-outs…

Lesson · CIPP/US

State Laws on Digital Advertising: CalOPPA, Age-Appropriate Design, and Comprehensive Laws

California leads on digital advertising: CalOPPA (2003) requires website privacy notices and Do Not Track disclosures; the 2022 California Age-Appropriate…

Lesson · CIPP/US

TCPA Updates: Robocalls, Autodialers, Robotexts and Facebook v. Duguid

The FCC's 2012 TCPA revisions require prior express written consent for all robocalls to residential lines, even with an established business…

Lesson · CIPP/US

The Telecommunications Act of 1996 and CPNI

Section 222 of the Telecommunications Act of 1996 restricts how carriers access, use and disclose customer proprietary network information (CPNI) - call…

Lesson · CIPP/US

Telemarketing Regulatory Framework: TCPA, TSR, FCC and FTC

Two coordinated federal regimes govern telemarketing: the FCC enforces the Telephone Consumer Protection Act (TCPA) of 1991, and the FTC enforces the…

Lesson · CIPP/US

TSR abandoned calls. CIPP/US safe harbor guide

TSR abandoned call rules explained with a safe-harbor example and CIPP/US study context.

Lesson · CIPP/US

TSR Rules on How Calls May Be Made

The TSR sets detailed conduct rules: telemarketers may call only between 8 a.m. and 9 p.m., must scrub against the Do Not Call list, display caller ID…

Lesson · CIPP/US

Transmission of Caller ID Information

Telemarketers must transmit accurate caller ID. They may show their own name/number or substitute the seller's name and a customer-service number that is…

Lesson · CIPP/US

TSR Enforcement, Penalties and the Private Right of Action

The TSR is enforced by the FTC and state attorneys general, with civil penalties up to $50,120 per call. A limited private right of action requires…

Lesson · CIPP/US

TSR Misrepresentations, Material Omissions and Payment Authorization

The TSR bars misrepresentations and material omissions across ten categories (cost, restrictions, refund policy, prize/investment terms, etc.). When…

Lesson · CIPP/US

TSR Recordkeeping Requirements

The TSR requires sellers and telemarketers to keep specified records (ads, prize recipients, sales, employees, consent authorizations) for two years from…

Lesson · CIPP/US

TSR required disclosures. CIPP/US telemarketing guide

TSR required call disclosures explained with a practical example and CIPP/US study context.

Lesson · CIPP/US

Prohibition on Unauthorized Billing and Pre-Acquired Account Information

The TSR bars billing without express, informed consent. Where the telemarketer already holds the consumer's account data (pre-acquired account…

Lesson · CIPP/US

The Video Privacy Protection Act of 1988

The VPPA, passed after Robert Bork's video rental records were disclosed, bars videotape service providers from disclosing customer information except…

Lesson · CIPP/US

CIPP/US Section 230 and online content guide

Section 230 and online content issues explained with a source-backed CIPP/US study bridge.

Lesson · CIPP/US

CIPP/US FCC telecom breach notification guide

FCC telecom breach notification rules explained with a source-backed CIPP/US study bridge.

Lesson · CIPP/US

ADA Restrictions on Medical Screening

The ADA covers employers with 15 or more employees. Before an offer, medical exams/inquiries are allowed only if job-related and consistent with business…

Lesson · CIPP/US

After Employment: Access Termination and HR Records

On departure, employers should terminate access (badges, accounts, devices), recover company data, and forward personal mail while reviewing work mail. HR…

Lesson · CIPP/US

Antidiscrimination Laws as Limits on Screening

Federal antidiscrimination laws (Title VII, Equal Pay Act, ADEA, Pregnancy Discrimination Act, ADA, GINA) bar discrimination and indirectly limit what…

Lesson · CIPP/US

Reasons for Background Screening

Employers screen to hire the best candidate, counter false applicant claims, protect brand, and mitigate negligent hiring liability. Some professions…

Lesson · CIPP/US

Biometric, Video, and Mail Monitoring; Union Activity

Three state biometric laws reach employer data: Illinois BIPA (notice, consent, and a private right of action), plus Texas and Washington (no private…

Lesson · CIPP/US

Constitutional Law and the State-Action Limit

Constitutional privacy protections like the Fourth Amendment apply to government (public-sector) employers but not to private-sector employment, because…

Lesson · CIPP/US

The Employment Life Cycle Framework

Workplace privacy issues arise before, during, and after employment: background screening (before); polygraphs, testing, monitoring, social media, and…

Lesson · CIPP/US

FACTA Preemption and Stronger State Credit Laws

FACTA (2003) amended the FCRA and preempted many state laws on credit reporting and identity theft, but the FCRA does not preempt stronger state laws on…

Lesson · CIPP/US

Fair Chance Act and Ban-the-Box Laws

The Fair Chance to Compete on Jobs Act (FCA), enacted in 2019, bars federal agencies and federal contractors from asking about an applicant's criminal…

Lesson · CIPP/US

FCRA Restrictions on Background Checks

The FCRA governs background checks via consumer reports from a CRA - not just credit, but criminal and driving records too. Employers need a permissible…

Lesson · CIPP/US

Federal Laws Affecting Employment Privacy

A cluster of federal laws bears on employment privacy: antidiscrimination laws, benefits laws (HIPAA, COBRA, ERISA, FMLA), and recordkeeping/data laws…

Lesson · CIPP/US

Intercepting Communications: Wiretap Act and ECPA

The Wiretap Act and ECPA generally prohibit intercepting wire, oral, and electronic communications. Two workplace exceptions: consent (party or one party…

Lesson · CIPP/US

Investigating Employee Misconduct: Vail Letter and FACTA Fix

Investigations should be fair, documented, and compliant with CBAs. The FTC's Vail Letter made third-party investigators CRAs, requiring notice and…

Lesson · CIPP/US

LBS, DLP, BYOD, and Teleworking Policies

Monitoring policies must address location-based services (GPS on vehicles generally OK; tracking people themselves is more limited), data loss prevention…

Lesson · CIPP/US

Workplace Privacy: The U.S. Legal Landscape

The U.S. has no overarching law for employment privacy. Federal statutes cover specific areas, state contract and tort law offer narrow protections, and…

Lesson · CIPP/US

Lifestyle Discrimination

Off-duty lifestyle is generally treated as private. Weight-based rules can invite discrimination suits (and obesity from a physiological disability may be…

Lesson · CIPP/US

Workplace Monitoring: Baseline and Policies

U.S. private-sector employees have limited expectations of privacy at work - facilities and equipment belong to the employer, granting broad monitoring…

Lesson · CIPP/US

Polygraphs and the EPPA

The Employee Polygraph Protection Act of 1988 (EPPA), enforced by the DOL, bars private employers from using lie detectors on workers or applicants…

Lesson · CIPP/US

Legal Obligations and Incentives to Monitor

Employers monitor to meet safety laws (OSHA), improve quality (recorded service calls), limit negligent-supervision liability, protect physical security…

Lesson · CIPP/US

Federal Agencies Protecting Employee Privacy

Five federal agencies are central: the DOL (administers FLSA, OSHA, ERISA), the EEOC (Title VII, ADEA, ADA), the FTC and CFPB (unfair/deceptive practices…

Lesson · CIPP/US

Screening Technologies: Social Media and AI

Using social media to screen is generally allowed but risks discrimination claims if protected-class info is used, FCRA exposure for nontraditional…

Lesson · CIPP/US

State Contract, Tort, and Statutory Protections

Contracts (especially collective bargaining agreements) can create enforceable privacy obligations. Three common-law torts - intrusion upon seclusion…

Lesson · CIPP/US

Stored Communications Act and City of Ontario v. Quon

The SCA bars unauthorized access to stored electronic communications, with exceptions for the service provider (often the employer) and an authorized…

Lesson · CIPP/US

Substance Use Testing

There is no federal privacy statute directly governing employer substance testing. The ADA excludes current illegal drug use (a drug test is not a medical…

Lesson · CIPP/US

CIPP/US automated employment decision tool guide

Automated employment decision tools explained with a source-backed CIPP/US study bridge.

Lesson · CIPP/US

CALEA and the Cybersecurity Information Sharing Act

CALEA (1994) requires telecommunications carriers to design interception capability into their products; the FCC extended it to broadband and VoIP. CISA…

Lesson · CIPP/US

Evidence Stored Abroad - CLOUD Act and Budapest Convention

The CLOUD Act (2018) lets the DOJ compel U.S. providers to produce data regardless of where it is stored (mooting the Microsoft Ireland case) and lets…

Lesson · CIPP/US

Disclosures Forbidden by Law and Evidentiary Privileges

Many privacy laws forbid disclosure using opt-in or opt-out rules: HIPAA and COPPA require opt-in consent; GLBA forbids disclosure if the individual has…

Lesson · CIPP/US

Disclosures Permitted by Law

Some laws permit but do not require disclosure. HIPAA requires very few disclosures but permits many (public health, law enforcement, national security)…

Lesson · CIPP/US

Disclosures Required by Law

Certain laws compel disclosure: FDA adverse-event reporting, OSHA injury reporting, state injury and disease reporting, and the BSA. HIPAA permits…

Lesson · CIPP/US

Discovery Under HIPAA and GLBA

Sectoral laws coexist with discovery. HIPAA permits PHI in discovery via patient authorization, a court order, or satisfactory assurances (a qualified…

Lesson · CIPP/US

Electronic Discovery and ESI

Since the 2006 FRCP revisions, electronically stored information (ESI) drives pretrial discovery. Sound data retention (per Sedona Conference guidance)…

Lesson · CIPP/US

FISA, Section 702, Section 215, and FISC

FISA orders issue from the FISC on probable cause that the target is a foreign power or agent, not probable cause of a crime, when foreign intelligence is…

Lesson · CIPP/US

Emerging Fourth Amendment Issues - Abortion Data and Geofence Warrants

Post-Dobbs, states that outlaw abortion may send warrants to companies in states that do not, creating an interstate conflict of law (California bars…

Lesson · CIPP/US

Fourth Amendment Limits on Law Enforcement Searches

The Fourth Amendment bars unreasonable searches; warrants need probable cause, particularity, and a neutral magistrate. Katz created the reasonable…

Lesson · CIPP/US

National Security Letters

An NSL is a subpoena issued by the FBI without judicial involvement for records relevant to terrorism or clandestine intelligence. The PATRIOT Act…

Lesson · CIPP/US

National Security Surveillance - Constitutional Tension and Post-Snowden Reform

National security surveillance pits the president's Article II powers against Article III judicial limits. FISA (1978) balanced both. The PATRIOT Act…

Lesson · CIPP/US

How Disclosures Are Required, Permitted, or Forbidden

When responding to litigation and investigations, the law can require, permit, or forbid disclosure of personal information. The same statute can do all…

Lesson · CIPP/US

Preservation Orders and Pen Register / Trap-and-Trace

Under the SCA, a provider must preserve records on a government request pending a court order, similar to a litigation hold. Pen register and…

Lesson · CIPP/US

Public Court Records, Protective Orders, and Required Redaction

U.S. courts are traditionally open, but online records ended practical obscurity. Litigants use protective orders (FRCP 26(c), three-part test) and HIPAA…

Lesson · CIPP/US

Right to Financial Privacy Act and Privacy Protection Act

RFPA (1978) requires customer authorization or specific legal process for federal access to individuals' financial records, with advance notice and a…

Lesson · CIPP/US

Statutes That Go Beyond Fourth Amendment Requirements

After the Supreme Court held the Fourth Amendment did not protect bank records or dialed numbers, Congress added statutory process. RFPA (1978) covers…

Lesson · CIPP/US

Cross-Border Discovery and the Hague Convention

U.S. broad-discovery rules collide with foreign laws like the GDPR that protect personal data. Courts split on how to resolve the conflict; the Hague…

Lesson · CIPP/US

Wiretap Act, ECPA, and Stored Communications Act

The Wiretap Act (Title III) strictly bars intercepting calls; ECPA extends this to electronic communications. Federal law permits one-party consent, but…

Lesson · CIPP/US

CIPP/US cybersecurity information sharing guide

Cybersecurity information sharing rules explained with a source-backed CIPP/US study bridge.

Lesson · CIPP/US

Breach Notification and Response

A GDPR data breach is broad, covering destruction, loss, alteration, or unauthorized disclosure/access. Controllers must notify the DPA within 72 hours…

Lesson · CIPP/US

Consent Under the GDPR

GDPR consent must be freely given, specific, informed, and an unambiguous indication of the data subject's wishes, expressed by statement or clear…

Lesson · CIPP/US

Controller, Processor, and Data Subject

The controller determines the purposes and means of processing; the processor processes on the controller's behalf under contract. The data subject is the…

Lesson · CIPP/US

Data Subject Rights: Overview and Handling Requests

The GDPR grants individuals control through rights to be informed, access, rectification, erasure, restriction, portability, objection, and freedom from…

Lesson · CIPP/US

Data Protection Authorities and Data Protection Officers

DPAs are independent national authorities that enforce data protection law - one per member state except Germany (federal plus 16 Lander). The DPO is the…

Lesson · CIPP/US

Enforcement: Complaints and Liability

A complaint can be initiated by a data subject or a DPA; where multiple DPAs are involved a lead DPA is determined. Both controllers and processors can be…

Lesson · CIPP/US

Rights to Erasure and Restriction of Processing

The right to erasure (right to be forgotten) applies in defined situations and requires deletion even from backups unless an exemption applies. As an…

Lesson · CIPP/US

GDPR Overview, Scope, and Sanctions

The General Data Protection Regulation (GDPR) is the worldwide template for data protection, applying broadly to companies with EU assets and employees…

Lesson · CIPP/US

Recent Developments in Global Data Flows

Beyond the GDPR's influence, the Global CBPR Forum builds on APEC's Cross-Border Privacy Rules to allow trade with privacy assurances, and the OECD…

Lesson · CIPP/US

Levels of Fines and Criminal Sanctions

The GDPR has two tiers of fines. Higher-level fines (up to four percent of global revenue or €20 million, whichever is greater) target core processing…

Lesson · CIPP/US

Personal Data and Sensitive Personal Data

Personal data is any data relating to an identified or identifiable natural person, directly or indirectly. Sensitive personal data is a special category…

Lesson · CIPP/US

Rights to Portability, to Object, and Against Automated Decision-Making

Portability gives data the subject provided in a machine-readable format, only where processing is by consent or contract and automated. The right to…

Lesson · CIPP/US

Rights to Be Informed, Access, and Rectification

The right to be informed drives privacy notices (layered, just-in-time, dashboards). The right of access underlies the subject access request and is the…

Lesson · CIPP/US

Appropriate Safeguards and Derogations

For third countries, transfers need an appropriate safeguard. The two most common are SCCs (the most widely used) and BCRs (for intra-group transfers…

Lesson · CIPP/US

EU-U.S. Transfers: Schrems I, Schrems II, and the Data Privacy Framework

The CJEU struck down Safe Harbor (Schrems I, 2015) and Privacy Shield (Schrems II, 2020) over U.S. surveillance concerns. The EU-U.S. Data Privacy…

Lesson · CIPP/US

The Seven General Principles

All processing must abide by the GDPR's seven principles: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage…

Lesson · CIPP/US

International Transfers and Adequate Countries

Transfers from the EEA to non-EEA countries are prohibited unless supported by an adequacy decision, an appropriate safeguard, or a derogation. Adequate…

Lesson · CIPP/US

Applying the Framework: California SB 1386 Breach Notification

California SB 1386 was the first breach-notification law. It covers entities doing business in California that hold computerized personal information…

Lesson · CIPP/US

Case Law, Common Law, and Stare Decisis

Case law is judges' final decisions; courts follow precedent under stare decisis. Common law is principles built over time in judicial decisions…

Lesson · CIPP/US

Consent Decrees

A consent decree is a judge-approved settlement where the defendant agrees to stop alleged illegal activity, typically without admitting guilt. Once…

Lesson · CIPP/US

Constitutions as a Source of Privacy Law

The U.S. Constitution never uses the word privacy, but the Fourth Amendment limits government searches and the Supreme Court recognized a penumbra of…

Lesson · CIPP/US

Contract Law and Privacy Notices

A contract needs offer, acceptance, and consideration. Privacy obligations often live in vendor contracts, and a privacy notice can itself be a contract…

Lesson · CIPP/US

Key Definitions: Person, Jurisdiction, Authority, Preemption, Private Right of Action

Core terms for U.S. privacy law: person (natural or legal), jurisdiction (subject-matter and personal), general vs. specific authority, preemption, and…

Lesson · CIPP/US

Six Keys to Understanding Any Law

Analyze any privacy law with six questions: who is covered, what information/uses, what is required/prohibited, who enforces, what happens if you don't…

Lesson · CIPP/US

Legislation and Federal Preemption

Both Congress and state legislatures enact privacy laws. The key question is whether a federal law preempts state law: HIPAA lets states pass stricter…

Lesson · CIPP/US

Notice, Choice, and Access (Opt-In vs. Opt-Out)

Notice describes information practices; choice lets individuals control collection/use - opt-in is an affirmative yes, opt-out implies consent unless the…

Lesson · CIPP/US

Regulations, Rules, and Agency Guidance

Some statutes direct agencies like the FTC or FCC to issue regulations carrying compliance force - e.g., CAN-SPAM rules on the opt-out mechanism. Agencies…

Lesson · CIPP/US

Federal and State Regulatory Authorities for Private-Sector Privacy

The FTC has general authority over unfair/deceptive practices plus specific authority in areas like children's privacy; sector regulators include banking…

Lesson · CIPP/US

Self-Regulation in Privacy

Self-regulatory regimes govern many industries' privacy practices - examples include the NAI, the Association of National Advertisers (formerly the DMA)…

Lesson · CIPP/US

Sources of Law in the United States

U.S. law flows from many sources: constitutions, legislation, case law, contract law, tort law, agency regulations, and consent decrees. Privacy…

Lesson · CIPP/US

The Three Branches of U.S. Government

The U.S. Constitution creates three branches - legislative makes laws, executive enforces them, judicial interprets them - with checks and balances. This…

Lesson · CIPP/US

Tort Law and Privacy Torts

Torts are civil wrongs in three categories: intentional, negligent, and strict liability. Privacy torts (intrusion on seclusion, public disclosure of…

Lesson · CIPP/US

The Adversarial Mindset: STRIDE, Zero Trust and Least Privilege

Cybersecurity adopts the adversarial mindset and threat modeling (e.g. the STRIDE framework and MITRE ATT&CK). Key principles include zero trust, least…

Lesson · CIPP/US

Cybersecurity Foundations: The CIA Triad

Security underpins privacy. The CIA triad - confidentiality, integrity, and availability - frames cybersecurity. A useful first approximation: privacy…

Lesson · CIPP/US

Client-Server Architecture: Front End and Back End

In the client-server model a client requests a service from a server. The browser-facing front end is separated from the back end databases; separating…

Lesson · CIPP/US

Cloud Computing: SaaS, PaaS and IaaS

Cloud computing is on-demand availability of computing resources, replacing on-premises computing. The three models - Software as a service (SaaS)…

Lesson · CIPP/US

Deep Packet Inspection

Deep packet inspection examines packet contents beyond the header, useful for malware detection and data-leak prevention but also enabling tracking and…

Lesson · CIPP/US

Deidentification: Anonymous vs Pseudonymous and Identifiers

When data cannot be traced to a person, privacy law no longer applies. Anonymization removes identifiability; pseudonymization masks identity with a…

Lesson · CIPP/US

Deidentification Standards: HIPAA Methods and FTC Guidance

The longest-standing U.S. deidentification rules are under HIPAA: the safe harbor method removes 18 identifiers and the expert determination method relies…

Lesson · CIPP/US

Approaches to Deidentification: Suppression, Generalization, Noise Addition

Three core techniques hide identity: suppression removes values, generalization replaces detail with a broader category, and noise addition substitutes…

Lesson · CIPP/US

Edge Computing and Latency

Edge computing processes data at the network periphery, close to the source. Driven by the growth of IoT sensors, it reduces the cost of centralized…

Lesson · CIPP/US

How Emails and Texts Work: SMTP, IMAP, POP, SMS and OTT

SMTP sends email; IMAP (which leaves mail on the server) is overtaking POP (which deletes it). Texts use SMS (160-character limit, works without internet)…

Lesson · CIPP/US

Tracking Email Recipients and Cross-Device Tracking

HTML email can track opens via a unique tracking pixel; reading in plain text defeats it. Cross-device tracking links a user across devices using…

Lesson · CIPP/US

Encryption: Symmetric, Asymmetric, Certificates and PKI

Encryption shields data by converting plaintext to ciphertext using a key. Symmetric key cryptography uses one shared key (fast but sharing is hard)…

Lesson · CIPP/US

First-Party Data Collection and Data Brokers

First parties collect data via cookies, user-generated content (UGC), and account terms of use; in California and the EU they give notice before setting…

Lesson · CIPP/US

Hashing, Salt and Digital Signatures

Hashing is a one-way function producing an output that does not reveal the input, used for pseudonyms and integrity checks. Plain hashes can be defeated…

Lesson · CIPP/US

HTTP Cookies: Session vs Persistent, First vs Third Party

Because HTTP/HTTPS are stateless, HTTP cookies maintain continuity. Session cookies last until the browser closes; persistent cookies can last…

Lesson · CIPP/US

Basics of the Internet: TCP/IP and Packet Switching

The internet is a network of networks descended from the ARPANET. Transmission control protocol (TCP) establishes reliable connections and breaks data…

Lesson · CIPP/US

Key Web Infrastructure: Servers, Proxies, VPNs, ISPs and IP Addresses

Web content lives on web servers; a proxy server and Virtual private network (VPN) act as gateways that can mask activity. An Internet service provider…

Lesson · CIPP/US

Location Tracking: Technologies and Carpenter

Location is tracked via cell-tower/Wi-Fi triangulation, GPS, and photo metadata. The U.S. has historically had few restrictions, but Carpenter v. United…

Lesson · CIPP/US

Internet Monitoring by Employers, Schools and Parents

U.S. employers may generally monitor internet use and emails on company networks/devices. The Children's Internet Protection Act (CIPA) requires public…

Lesson · CIPP/US

The NIST Cybersecurity Framework

The NIST Cybersecurity Framework (CSF), first published in 2014, is guidance rather than law and popularized five Framework Core Functions: Identify…

Lesson · CIPP/US

Privacy by Design and Limits of Technical Measures

Privacy by design embeds privacy from the onset and is legally required in California and the EU. Privacy-enhancing technologies altering or shielding…

Lesson · CIPP/US

Reidentification Risk and Differential Privacy

Computer scientists have repeatedly re-identified supposedly anonymized data. Differential privacy is a mathematical definition of privacy that adds…

Lesson · CIPP/US

Surveillance by Audio, Video and Other Sensors

Devices' microphones and cameras can be hijacked by remote access trojan (RAT) malware, or activated by employers/police. Government video surveillance is…

Lesson · CIPP/US

Spyware and Phishing Variants

Spyware (including keylogging) covertly surveils a device, often delivered by phishing social engineering. Variants include spear phishing, whaling…

Lesson · CIPP/US

Third-Party Data Collection and the Decline of Third-Party Cookies

Ad networks long used third-party cookies to track users across sites. Market and regulatory changes are shrinking this: the CPRA (effective January 2023)…

Lesson · CIPP/US

URLs, URIs, URNs and Hyperlinks

A Uniform resource locator (URL) is a web address with a protocol prefix, optional www, a domain name and a top-level domain. URLs are a subset of Uniform…

Lesson · CIPP/US

Web Infrastructure: HTTP, HTML, HTTPS and XML

The web is narrower than the internet. Hypertext transfer protocol (HTTP) and Hypertext markup language (HTML), invented by Tim Berners-Lee, drive the…

Lesson · CIPP/US

Wireless Eavesdropping and Defenses

On unencrypted Wi-Fi, packet sniffing can capture traffic, a risk in shared public hotspots. Defenses include encrypted Wi-Fi (per-user keys), VPNs (which…

Lesson · CIPP/US

Data Breach Readiness Assessments

A data breach readiness assessment examines the risk of a breach plus the likelihood and severity of a personal data breach, weighing data type, technical…

Lesson · CIPP/US

The Business Case for Privacy and the Cost of Mishandling Data

Privacy compliance carries real cost, but mishandling personal data can be far more expensive in fines, breach costs, and lost consumer trust. Privacy is…

Lesson · CIPP/US

Responding to User Requests and Consumer Rights

Many federal and state laws grant rights of control: access, correction, deletion, portability, against automated decision-making, and nondiscrimination…

Lesson · CIPP/US

Data Accountability - Controllers, Processors, and Encryption

Accountability questions cover where/how/how long data is stored, sensitivity, encryption, cross-border transfer, and who sets the rules. A controller…

Lesson · CIPP/US

Data Flow Mapping - Top-Down and Bottom-Up

After inventory and classification, data flows are mapped and documented (what, where, and why data is processed). The top-down approach used for…

Lesson · CIPP/US

Data Inventory and Data Classification

An organization should inventory all PI it collects, stores, uses, or discloses (customer and employee), then classify it by sensitivity to set access…

Lesson · CIPP/US

The Data Life Cycle

Data should be managed across its life cycle - creation, storage, sharing and usage, archival, and deletion - because privacy-protecting approaches at one…

Lesson · CIPP/US

Global Perspective and Cross-Border Data Transfer Mechanisms

More than 160 nations have significant privacy laws; the GDPR draws the most attention, with fines based on worldwide revenue. Cross-border trust…

Lesson · CIPP/US

Information Management and the Privacy Professional's Role

Information management establishes, implements, and monitors the organization's privacy program under a senior leader such as the CPO, drawing on legal…

Lesson · CIPP/US

Information Security - CIA Triad and Control Types

Information security protects information per three attributes - confidentiality, integrity, availability (CIA) - using physical, administrative, and…

Lesson · CIPP/US

Managing User Preferences and Dark Patterns

Managing preferences raises challenges of scope, mechanism, linking across channels, time period, and third-party vendors. Good practice: the channel for…

Lesson · CIPP/US

Opt-In, Opt-Out, and No Option

U.S. laws differ on consent: opt-in (COPPA parental consent, HIPAA PHI disclosure, FCRA credit report release); opt-out (GLBA third-party transfers, VPPA…

Lesson · CIPP/US

DPIA vs PIA: What Is the Difference? CIPP/US Guide

DPIA vs PIA explained: what each assessment is, when the GDPR requires a DPIA, what a U.S. PIA covers and how CIPP/US questions test the difference.

Lesson · CIPP/US

Delivering Privacy Notices - Layered, Just-in-Time, and Mobile

Notices should be accessible online and in-person, with training for staff. Common techniques include the layered notice (short top layer plus full bottom…

Lesson · CIPP/US

Privacy Operational Life Cycle - Assess, Protect, Sustain, Respond

The privacy operational life cycle continuously improves the program through four stages: assess, protect, sustain, and respond - from baselining and…

Lesson · CIPP/US

Drafting, Updating, and Versioning the Privacy Policy

Policies need legal review and executive approval, periodic review (at least annually), and version control. The FTC says express affirmative consent…

Lesson · CIPP/US

Privacy Policy vs Privacy Notice: The Difference for CIPP/US

Privacy policy vs privacy notice explained: the policy is the internal rulebook, the notice is the external statement to consumers, and the exam tests…

Lesson · CIPP/US

The Privacy Program and Four Business Risks

A privacy program establishes accountability and compliance, and should balance four business risks: legal, reputational, operational, and strategic. The…

Lesson · CIPP/US

Privacy Program Framework and Metrics

A privacy program framework operationalizes controls and should begin with a privacy mission statement/vision aligned to the organization. Building it…

Lesson · CIPP/US

Privacy Risk Management and Privacy Harms

Privacy risk management identifies and mitigates risks to information assets. Privacy risk is the likelihood individuals will experience problems from…

Lesson · CIPP/US

Privacy Team Roles - CPO, DPO, and Others

A privacy team may include a CPO, DPO, chief legal officer, privacy engineer, privacy manager, and privacy analyst, plus informal privacy champions and…

Lesson · CIPP/US

Vendor and Third-Party Risk Assessments

Companies remain responsible for vendor actions and must use contract protections (confidentiality, no further use, subcontractor flow-down, breach…

Lesson · CIPP/US

Additional FTC Authority: COPPA, HITECH, FCRA, CAN-SPAM

Beyond Section 5 the FTC enforces COPPA (children under 13, parental consent), shares HITECH breach authority with HHS, has historic FCRA/FACTA authority…

Lesson · CIPP/US

Additional State Protections: Torts, BIPA, and the AADC Act

States add protection via constitutions, common-law privacy torts, and contract theories. Illinois's BIPA (2008) requires notice and consent for…

Lesson · CIPP/US

Deceptive Trade Practices and Broken Privacy Promises

A deceptive practice is a material statement or omission likely to mislead reasonable consumers. Breaking a privacy-notice promise is deceptive under…

Lesson · CIPP/US

Federal Privacy Enforcement Outside the FTC

Many federal agencies enforce privacy depending on the statute violated: OCR/HHS for HIPAA, CFPB and bank regulators for GLBA, Dept. of Education for…

Lesson · CIPP/US

The Federal and State Regulatory Landscape

In the U.S., privacy is regulated at both federal and state level. Federal regulators are largely sectoral (medical, financial, education), the FTC is the…

Lesson · CIPP/US

FTC Enforcement Process and Consent Decrees

Most FTC privacy actions end in a consent decree: the respondent does not admit fault but promises to change practices. Decrees are public, may require…

Lesson · CIPP/US

FTC Enforcement Tools and the AMG Decision

The FTC uses Section 5(l) for administrative cease-and-desist enforcement and Sections 13(b) and 19 for judicial relief. The Supreme Court in AMG Capital…

Lesson · CIPP/US

The FTC, Section 5, and Jurisdictional Limits

Section 5 of the FTC Act bars unfair or deceptive acts or practices in or affecting commerce and is the single most important piece of U.S. privacy law…

Lesson · CIPP/US

The Future of FTC Enforcement

FTC priorities track technology: a 2023 Office of Technology, 2022 proposed commercial surveillance rules (under Magnuson-Moss), a 2020 data portability…

Lesson · CIPP/US

FTC Rulemaking Under Magnuson-Moss

The FTC's UDAP rulemaking does not use ordinary APA notice-and-comment. It must follow the complex Magnuson-Moss (Section 18) procedures, showing the…

Lesson · CIPP/US

Other Federal Privacy Actors and the DOJ's Criminal Role

Beyond sector regulators, agencies like State, Commerce, Transportation, OMB, IRS/Treasury, DHS, and DOE touch privacy. OMB interprets the Privacy Act of…

Lesson · CIPP/US

Self-Regulation and Enforcement

Self-regulation spans legislation, enforcement, and adjudication. Under Section 5/UDAP it is only quasi-legislative (a government agency still enforces)…

Lesson · CIPP/US

State Attorneys General and UDAP Statutes

State AGs are the primary privacy enforcers in most states and may join federal actions under HIPAA, GLBA, and CAN-SPAM. All 50 states have UDAP statutes…

Lesson · CIPP/US

State Breach Notification, SSN Protections, and Identity Theft Laws

California enacted the first breach law in 2002; all 50 states now have one. Breach-law personal information centers on name + SSN, driver's license/ID…

Lesson · CIPP/US

State Comprehensive Laws and Federal Sectoral Exemptions

By end of 2022, five states had comprehensive laws: California, Colorado, Connecticut, Utah, Virginia. They reference COPPA for children and exempt…

Lesson · CIPP/US

Types of Litigation and Enforcement

Three main categories of legal action: civil litigation (private plaintiff seeks damages or an injunction), criminal prosecution (government, can mean…

Lesson · CIPP/US

Unfair Trade Practices

An unfair practice causes or is likely to cause substantial injury that is not reasonably avoidable by consumers and not outweighed by countervailing…

Lesson · CIPP/US

Court Confirmation of FTC Authority: Wyndham and LabMD

FTC v. Wyndham (2015, Third Circuit) confirmed the FTC's unfairness authority extends to cybersecurity. FTC v. LabMD (2018, Eleventh Circuit) recognized…

Lesson · CIPP/US

Access, Correction, and Deletion Rights

All five states grant access and deletion; the right to correction is provided by everyone except Utah. Deletion scope differs: Colorado, Connecticut…

Lesson · CIPP/US

Defining Business - Applicability Thresholds

Which companies are covered turns on the definition of business (called controller in the four non-California states). California is broadest ($25M…

Lesson · CIPP/US

Which Entities Are Excluded from Business

All five states exempt governments, nonprofits, and FCRA-covered entities. But the states diverge on higher education, securities associations, and…

Lesson · CIPP/US

CCPA vs CPRA: What Changed? CIPP/US California Guide

CCPA vs CPRA explained: the CPRA amended the CCPA rather than replacing it. What changed, what the exam tests and how to answer California questions.

Lesson · CIPP/US

Opt-In Default for Children's Data

Age-based opt-in rules vary: California requires opt-in to sell/share data of consumers under 16; Connecticut requires opt-in for ages 13-16 to sell or…

Lesson · CIPP/US

Defining Consumer - Who Is Protected

All five laws protect their state residents, and the term is NOT limited to purchasers. The key distinction: California includes employees in its…

Lesson · CIPP/US

Consumer Rights Overview and Response Timelines

These laws grant GDPR-like rights (access, correction, deletion, portability, opt-outs, etc.). Response times: Colorado, Connecticut, Utah, Virginia allow…

Lesson · CIPP/US

Cure Periods and the Private Right of Action

Cure periods split: California's expired; Colorado and Connecticut's sunset Dec 31, 2024; Utah and Virginia have a 30-day cure with no end date. No state…

Lesson · CIPP/US

Enforcement - Penalties and Enforcers

The state attorney general has sole or joint enforcement power in every state; California adds the CPPA. Penalty caps vary: California $2,500 (up to…

Lesson · CIPP/US

Entity-Level vs Data-Based Exemptions

State comprehensive laws use two exemption types: entity-level exemptions (a whole organization is exempt) and data-based exemptions (only a class of data…

Lesson · CIPP/US

The U.S. Has No Federal Comprehensive Privacy Law

The United States regulates privacy sectorally (HIPAA, GLBA, COPPA) and as of this writing has no federal comprehensive privacy law, unlike most countries…

Lesson · CIPP/US

Business Obligation - Notice and Transparency

All five states require a privacy notice and a notice of the right to opt out. Only California requires notice at the point of collection, and California…

Lesson · CIPP/US

Opt-Out Rights - Sales, Targeted Advertising, Automated Decisions

All five states allow opt out of sales; California also lets consumers opt out of sharing. For targeting/cross-context behavioral advertising, Colorado…

Lesson · CIPP/US

Personal Information and Its Exclusions

All five define personal information as data linkable to an individual, going beyond breach-notification definitions. California uniquely includes…

Lesson · CIPP/US

Federal Preemption and Private Right of Action Debates

The two most contested issues in any U.S. national privacy bill are preemption (would it override stricter state laws?) and a private right of action…

Lesson · CIPP/US

Purpose Limits, Risk Assessments, and Security

California, Colorado, Connecticut, Virginia impose purpose/processing limitations and require risk assessments for heightened-risk processing; Utah lacks…

Lesson · CIPP/US

Sale and California's Unique Sharing Regulation

Each state regulates the sale of personal data, but the definition splits: Utah and Virginia limit sale to monetary compensation, while California…

Lesson · CIPP/US

Rights Concerning Sensitive Data and Nondiscrimination

Sensitive-data handling splits sharply: Colorado, Connecticut, Virginia require opt-in consent; Utah requires only notice and opt-out; California uses a…

Lesson · CIPP/US

Sensitive Personal Information

All five states treat citizenship, genetic/biometric data, physical/mental health, race/ethnicity, religion, and sexual orientation as sensitive. States…

Lesson · CIPP/US

The Five State Laws in Effect in 2023

This chapter focuses on the five state comprehensive laws in effect in 2023: California, plus the CPA (Colorado), CTDPA (Connecticut), UCPA (Utah), and…

Lesson · CIPP/US

CIPP/US Global Privacy Control and opt-out signals

Global Privacy Control and California opt-out handling explained for CIPP/US study.

Lesson · CIPP/US

Notification: Attorney General and State Agency Notice

About two-thirds of states require notice to the attorney general/state agency, often above a numeric threshold (commonly 250 to 1,000 people). Vermont's…

Lesson · CIPP/US

Common Structure of State Breach Laws

Despite differences, state breach laws share three building blocks: key terms (personal information, covered entities, security breach), notification…

Lesson · CIPP/US

California Statutory Damages (CCPA/CPRA)

In 2020 California became the first state to let consumers recover statutory damages for breaches: $100 to $750 per incident where the breach resulted…

Lesson · CIPP/US

State Breach, Security, and Destruction Laws: The Landscape

All 50 states have data breach notification laws, and many states layer on data security laws and data destruction laws. With no comprehensive federal…

Lesson · CIPP/US

Breach Laws: Covered Entities

Most states cover entities that conduct business in the state and maintain computerized data containing personal information. Georgia is a notable…

Lesson · CIPP/US

Notification: Consumer Reporting Agencies

About two-thirds of states require notice to nationwide CRAs, often above a 250 to 1,000 threshold. The common timing standard is without unreasonable…

Lesson · CIPP/US

Notification: Free Credit Monitoring

When SSNs are exposed, the FTC suggests offering at least a year of free credit monitoring. Three states - California, Delaware, and Massachusetts -…

Lesson · CIPP/US

When Notification May Be Delayed

When a breach is suspected to involve criminal activity, all states allow delay if law enforcement determines notice would impede a criminal…

Lesson · CIPP/US

Enforcement: Penalties and Private Rights of Action

All 50 states impose civil penalties; about one-third let the attorney general levy fines, often capped per breach ($750,000 being the highest noted, in…

Lesson · CIPP/US

Exceptions to Notification

Three exceptions excuse notice: an entity subject to a more stringent law (e.g., HIPAA or the GLBA Safeguards Rule), an entity following its own…

Lesson · CIPP/US

Notification: Method and Substitute Notice

The default method is written notice by postal mail. Email or phone are usually allowed only if the person previously and explicitly chose that channel…

Lesson · CIPP/US

The Absence of a Federal Breach Law

Calls for a uniform federal breach law go back to 2003, but no comprehensive federal data breach notification law has been enacted. The deadlock turns on…

Lesson · CIPP/US

Notification: Content of the Letter

About half of states mandate specific content (incident description, approximate date, data types, steps taken, contact phone, identity-theft steps, CRA…

Lesson · CIPP/US

Breach Laws: Defining Personal Information

In most states, personal information means a person's first name or first initial and last name combined with at least one of: SSN, driver's license/state…

Lesson · CIPP/US

Breach Laws: Security Breach and Risk-of-Harm

A security breach is generally unauthorized access to or acquisition of computerized personal data that compromises its confidentiality, security, or…

Lesson · CIPP/US

State Data Destruction Laws

About two-thirds of states have data destruction (disposal) laws requiring personal information to be disposed of so it is no longer readable or…

Lesson · CIPP/US

State Data Security Laws

About two-thirds of states require data security measures. Roughly 20 states use a 'reasonable security' standard (e.g., California's AB 1950); about 10…

Lesson · CIPP/US

US Approach in Context

The lack of comprehensive federal breach, security, and destruction requirements leads some to call the US less stringent than jurisdictions like Europe…

Lesson · CIPP/US

Notification: Timing to Affected Parties

The most common timing standard is as expeditiously as possible and without unreasonable delay. Where a specific cap is set, 45 days after discovery is…

Lesson · CIPP/US

Notification: Whom to Notify

Breach laws commonly require notice to three audiences: affected residents (all 50 states), state attorneys general/agencies (about two-thirds), and…

Lesson · CIPP/US

CIPP/US data broker registration and deletion guide

California data broker registration and deletion mechanisms explained for CIPP/US study.

Lesson · CIPP/US

CIPP/US biometric privacy law and facial data guide

State biometric privacy law concepts explained with a source-backed CIPP/US study bridge.

Lesson · CIPP/US

CIPP/US Illinois genetic privacy law guide

Illinois genetic privacy law explained with a direct answer and CIPP/US study context.

Lesson · CIPP/US

CIPP/US Washington consumer health data law guide

Washington consumer health data law explained with a source-backed CIPP/US study bridge.

Lesson · CIPP/US

CIPP/US state AI and employment decision guide

Automated employment decision tool rules explained with a source-backed CIPP/US study bridge.

Lesson · CIPP/US

Business Associates and BAAs

A business associate performs services for a covered entity involving the use or disclosure of PHI. Before HITECH they were bound only by contract; after…

Lesson · CIPP/US

Covered Entities Under HIPAA

HIPAA directly covers health care providers conducting certain electronic transactions, health plans, and health care clearinghouses. Cash-only providers…

Lesson · CIPP/US

21st Century Cures Act and Information Blocking

The Cures Act (2016) promotes EHI interoperability by prohibiting information blocking - activity likely to interfere with access, exchange, or use of…

Lesson · CIPP/US

Cures Act: API Portability and Other Privacy Provisions

The Cures Act requires certified health IT developers to publish APIs so patients can move EHI to apps of their choosing - raising the concern that data…

Lesson · CIPP/US

GINA Preemption and State Genetic Laws

GINA is a floor and does not preempt stricter state law. Because GINA leaves life insurers, mortgage lenders, and schools untouched, states like…

Lesson · CIPP/US

Genetic Information Nondiscrimination Act (GINA)

GINA (2008) bars health insurers from discriminating on genetic predisposition absent manifest symptoms and bars employers from using genetic information…

Lesson · CIPP/US

HIPAA Enforcement and Penalties

The OCR enforces both rules with civil penalties up to roughly $2 million per year per violation type and audits entities. HIPAA has no private right of…

Lesson · CIPP/US

HIPAA Origins and Purpose

HIPAA became law in 1996 to improve health care efficiency, requiring electronic reimbursement formats for Medicare and Medicaid. Recognizing the privacy…

Lesson · CIPP/US

HIPAA Preemption and State Laws

HIPAA does not preempt stricter state laws. Practitioners must review state law for added patient rights, extra disclosures, and shorter deadlines, and…

Lesson · CIPP/US

Health Information Is Protected Differently by Setting

HIPAA only applies to covered entities and their business associates. The same health-related data held by a bookstore, website, or smartwatch maker…

Lesson · CIPP/US

HITECH and Breach Notification

HITECH (2009) strengthened HIPAA and created breach notification. A breach is presumed unless a risk assessment shows low probability of compromise…

Lesson · CIPP/US

HITECH: Penalties, Limited Data, and EHRs

HITECH increased penalties (up to $2 million for willful violations, even without knowledge) and extended criminal liability to individuals. It encourages…

Lesson · CIPP/US

Medical Technology: FTC Act, FDCA, and State Laws

For medtech outside HIPAA, Section 5 of the FTC Act is the primary federal tool against deceptive and unfair practices (e.g., the 2021 Flo Health action)…

Lesson · CIPP/US

PHI and ePHI Defined

PHI is individually identifiable health information held by a covered entity or business associate relating to a person's health, care, or payment. ePHI…

Lesson · CIPP/US

Limits and Exceptions to the Privacy Rule

The Privacy Rule does not apply to deidentified information and offers flexibility for research. Other exceptions allow disclosure without consent for…

Lesson · CIPP/US

The HIPAA Privacy Rule and the FIPPs

The Privacy Rule is HIPAA's most detailed implementation of Fair Information Privacy Practices: privacy notices, authorizations, minimum necessary limits…

Lesson · CIPP/US

The HIPAA Security Rule

Finalized in 2003, the Security Rule covers only ePHI and binds both covered entities and business associates. It requires administrative, physical, and…

Lesson · CIPP/US

Confidentiality of Substance Use Disorder Patient Records Rule

Rooted in 1970s laws, this rule protects patient-identifying information held by federally funded substance abuse treatment programs. It requires written…

Lesson · CIPP/US

Temporary COVID-19 telehealth measures

During the COVID-19 public health emergency, OCR temporarily allowed nonpublic-facing videoconferencing even when it did not fully meet HIPAA rules. That…

Lesson · CIPP/US

Why Medical Privacy Gets Special Protection

Health information is treated as especially sensitive because it relates to one's body and mind, encourages candor with doctors, and protects against…

Lesson · CIPP/US

CIPP/US FTC health breach notification rule guide

The FTC Health Breach Notification Rule explained with a source-backed CIPP/US study bridge.

Lesson · CIPP/US

CIPP/US 42 CFR Part 2 confidentiality guide

42 CFR Part 2 explained with a source-backed CIPP/US study bridge.

Lesson · CIPP/US

CIPP/US HIPAA online tracking technology guide

HIPAA online tracking technology issues explained with a source-backed CIPP/US study bridge.

Lesson · CIPP/US

Anti-Money-Laundering: The Bank Secrecy Act

The Bank Secrecy Act (1970) imposes recordkeeping and reporting on financial institutions, requiring reports of currency transactions over $10,000 to the…

Lesson · CIPP/US

The Disposal Rule

The Disposal Rule requires anyone using a consumer report for business to dispose of that information reasonably to prevent unauthorized access. It…

Lesson · CIPP/US

Dodd-Frank and the CFPB's Authority

Dodd-Frank (2010) created the CFPB within the Federal Reserve. The CFPB has rulemaking authority over the FCRA, GLBA and Fair Debt Collection Practices…

Lesson · CIPP/US

FACTA Amendments and Consumer Protections

FACTA (2003) amended the FCRA, preempting stricter state laws in most areas (states keep some identity-theft powers). It required truncation of card…

Lesson · CIPP/US

Adverse Action Notices

An adverse action is any negative business, credit or employment decision. When a user acts adversely based even in part on a consumer report, it must…

Lesson · CIPP/US

CRAs and Consumer Reports Defined

A consumer reporting agency (CRA) compiles or evaluates personal information to furnish consumer reports to third parties for a fee. The FCRA's…

Lesson · CIPP/US

CRA Core Requirements: Access, Accuracy, Obsolescence

CRAs must give consumers access and the right to dispute, take reasonable steps for maximum possible accuracy, and not report outdated negatives…

Lesson · CIPP/US

Consumer Reports for Employment

Employers using consumer reports must give a clear written stand-alone notice, get prior written authorization, certify compliance to the CRA (including…

Lesson · CIPP/US

FCRA Enforcement and Penalties

FCRA enforcement runs through dispute resolution, private litigation (including class actions), and government action by the FTC, CFPB and state attorneys…

Lesson · CIPP/US

Furnisher Duties and the Furnisher Rule

Furnishers must provide accurate data, correct and update it, give notice of disputes to CRAs, and respond to identity-theft information. The Furnisher…

Lesson · CIPP/US

Misconduct Investigations and Investigative Consumer Reports

Internal misconduct investigations are not consumer reports if the employer follows the act's procedures, uses no credit information, and gives a summary…

Lesson · CIPP/US

Medical Information and Prescreened Lists Under FCRA

FCRA limits use of medical information from CRAs, generally requiring consent or coding for insurance, employment or credit uses. Prescreened lists let…

Lesson · CIPP/US

Permissible Purpose and Certification

A user may obtain a consumer report only with a permissible purpose and must certify that purpose to the CRA, plus certify the report will not be used for…

Lesson · CIPP/US

FCRA Purpose, History and Preemption

Enacted in 1970, the FCRA was the first federal law to regulate private businesses' use of personal information. It mandates accurate, relevant data…

Lesson · CIPP/US

Risk-Based Pricing and Credit Score Disclosures

Under the Risk-Based Pricing Rule, lenders must notify consumers who receive less favorable terms because of their credit report. Anyone using credit…

Lesson · CIPP/US

Users and Furnishers Under the FCRA

Beyond CRAs, the FCRA binds users (lenders, insurers, employers who use reports) and furnishers (lenders, retailers who supply data to CRAs). Users need a…

Lesson · CIPP/US

Financial Privacy Landscape and Regulators

U.S. financial privacy is governed mainly by the FCRA (1970), GLBA (1999), and the Dodd-Frank Act (2010), which created the CFPB. Financial institutions…

Lesson · CIPP/US

Future of Financial Regulation and Cryptocurrency Privacy

Cryptocurrency privacy depends on whether governments take a high- or low-regulation approach. Under low regulation, privacy depends on market and…

Lesson · CIPP/US

GLBA Overview and Privacy Provisions

GLBA (Title V of the 1999 Financial Services Modernization Act) produced a Privacy Rule and a Safeguards Rule. Spurred by the U.S. Bancorp/MemberWorks…

Lesson · CIPP/US

The GLBA Privacy Rule

The Privacy Rule requires initial and annual privacy notices and processing of opt-outs within 30 days. Institutions may freely share with affiliates and…

Lesson · CIPP/US

The GLBA Safeguards Rule

The Safeguards Rule (effective 2003, updated by the FTC in 2021) requires a written information security program with administrative, technical and…

Lesson · CIPP/US

GLBA Scope, NPI and Enforcement

GLBA covers financial institutions significantly engaged in financial activities and regulates nonpublic personal information (NPI). Enforcement runs…

Lesson · CIPP/US

USA PATRIOT Act, KYC, FATCA and the AML Act of 2020

The International Money Laundering Abatement and Anti-Terrorist Financing Act (2001), part of the USA PATRIOT Act, expanded the BSA and added Know Your…

Lesson · CIPP/US

The Red Flags Rule

The Red Flags Rule requires financial institutions and creditors to maintain written identity-theft detection programs that spot and respond to red flags…

Lesson · CIPP/US

Regulation E and EFTA. CIPP/US transfer rules guide

Regulation E and the EFTA explained with coverage, consumer protections and CIPP/US study context.

Lesson · CIPP/US

Suspicious Activity Reports and BSA Enforcement

Institutions must file a Suspicious Activity Report (SAR) with FinCEN for insider crimes regardless of amount, crimes of $5,000+ with a suspect, crimes of…

Lesson · CIPP/US

State Financial Privacy: California (CFIPA) and New York (NYDFS)

Because GLBA does not preempt states, California's CFIPA (SB-1) adds opt-in consent for sharing with nonaffiliated third parties, and New York's NYDFS…

Lesson · CIPP/US

CIPP/US Bank Secrecy Act and merger privacy guide

Bank Secrecy Act and merger privacy issues explained with a CIPP/US study bridge.

Lesson · CIPP/US

CIPP/US GLBA annual privacy notice guide

GLBA annual privacy notices explained with a source-backed CIPP/US study bridge.

Looking for AI governance? Explore the AIGP study guide.