CIPP/US glossary
Review the recurring terms in this CIPP/US guide. Use each definition as a prompt, then explain the term without looking.
This glossary supports recall. The linked lessons provide the legal context, exceptions and scenarios that a short definition cannot hold.
- 21st Century Cures Act
- A 2016 law promoting medical research, mental health reform, and EHI interoperability, with privacy-specific provisions.
- 30-day cure period
- California provision allowing a business to cure an alleged violation within 30 days; a successful cure bars the consumer from pursuing statutory damages.
- 42 CFR Part 2
- The Confidentiality of Substance Use Disorder Patient Records Rule protecting records of patients seeking alcohol or substance use treatment at federally assisted programs.
- AB 1950
- California's data security law (Civil Code 1798.81.5), the country's first state security law, requiring reasonable security procedures and practices.
- Abandoned call
- An outbound call where, after a person completes their greeting, the telemarketer fails to connect a live sales rep within two seconds.
- Abandonment safe harbor
- Protection from enforcement if abandonment stays at or below 3% per day per campaign, with required ring time, recorded message and records.
- Abusive act or practice
- A CFPB enforcement standard covering practices that materially interfere with a consumer's understanding of a product, or take unreasonable advantage of a consumer's lack of understanding, inability to protect their interests, or reasonable reliance on the provider.
- Acceptable use policy
- An employer policy on permitted use of IT equipment that, with monitoring notices, helps establish employee knowledge and reasonable expectations and can be required by state law.
- Acceptance
- The assent by the offeree, complying with the offer's terms and communicated to the offeror.
- Access
- The ability to view personal information held by an organization, sometimes with rights to update or correct it.
- Accountability
- The principle requiring the controller to be responsible for, and able to demonstrate, compliance with the other six principles.
- Accountability Principle
- OECD principle that a data controller should be accountable for complying with measures giving effect to the other principles.
- Actual damages
- Damages tied to the losses actually incurred by the consumer as a result of the breach.
- ADA
- Americans with Disabilities Act of 1990; bars discrimination against qualified individuals with disabilities and restricts medical examinations and inquiries by employers of 15 or more.
- Addressable specification
- A Security Rule implementation spec the entity must assess for appropriateness and, if not adopted, document why and adopt an alternative if reasonable.
- ADEA
- Age Discrimination in Employment Act of 1967; bars discrimination against individuals over 40.
- Adequacy decision
- An EU determination that a country's protections are essentially equivalent to the GDPR, allowing data to flow freely to it.
- Adequacy determination
- A government decision that another country's data protections are adequate, enabling freer data flows (a pre-authorization safeguard).
- Administrative enforcement action
- Enforcement carried out by an agency under the statutes that empower it, governed federally by the APA.
- Adversarial mindset
- The cybersecurity assumption that attackers anywhere may launch a devastating attack at any moment - we live in a 'bad neighborhood.'
- Adverse action
- Any business, credit or employment action with a negative impact on a consumer, such as denying or cancelling credit/insurance or denying employment or promotion.
- Aerospatiale factors
- Factors a U.S. court uses to reconcile conflicts between U.S. discovery and foreign law, including importance, specificity, U.S. origin of data, alternative means, and competing national interests.
- Age-Appropriate Design Code Act
- A 2022 California law, modeled on the UK's, imposing obligations on online services likely accessed by children under 18, including high-privacy default settings.
- Agency opinion
- Formal agency guidance that does not necessarily carry the weight of law but helps parties interpret rules and regulations.
- Aggregate data
- Information about a group of consumers with individual identities removed so it is not reasonably linkable to a consumer; explicitly excluded by California, Utah, and Virginia.
- Algorithmic disgorgement
- A remedy requiring a company to delete algorithms or models built using improperly obtained data, used in the Everalbum settlement.
- ALJ
- An administrative law judge who presides over court-like hearings inside an agency's adjudication process.
- AMG Capital Management v. FTC
- 2021 Supreme Court case holding the FTC may not obtain monetary relief or damages under Section 13(b).
- AML Act of 2020
- Anti-Money Laundering Act of 2020, the most comprehensive AML changes since the USA PATRIOT Act, expanding the BSA to explicitly include virtual currencies.
- Anonymization
- Putting data in a form that does not identify individuals and where identification by combination with other data is not likely (UK ICO definition).
- Anonymized data
- Data processed irreversibly so it can no longer identify a person; only then is it outside the definition of personal data.
- APA
- The Administrative Procedure Act, which sets the basic federal rules for agency enforcement and adjudication.
- APEC
- Asia-Pacific Economic Cooperation, a multinational organization of 21 Pacific Coast members that operates under nonbinding agreement, unlike the EU.
- APEC Cross-Border Privacy Rules
- The Asia-Pacific framework allowing trade among participating economies while providing privacy assurances.
- APEC Privacy Framework
- A 2004 (updated 2015) framework of nine information privacy principles that generally mirror the OECD Guidelines but are more explicit about exceptions.
- API (Cures Act)
- Application programming interface that certified health IT developers must publish so patients can access, exchange, and use their EHI without special effort.
- ARPANET
- The 1960s U.S. military computer network that was the precursor of the modern internet.
- As expeditiously as possible and without unreasonable delay
- The most common timing phrase for breach notice, allowing a reasonable investigation while restoring system integrity.
- Asymmetric cryptography
- Public-key cryptography using a public/private key pair per user; scalable and the basis for digital certificates.
- Attorney-client privilege
- Privilege under which an attorney cannot be compelled to testify or produce records about a client within the scope of representation, subject to exceptions like consent or preventing imminent harm.
- Autodialer (ATDS)
- An automatic telephone dialing system; in 2021 the Supreme Court limited this to equipment with capacity to use a random or sequential number generator to store or produce numbers.
- Automated decision-making
- Fully automated processing, including profiling, that has a legal or similarly significant effect, generally prohibited under the GDPR.
- Automated Employment Decision Tool (AEDT)
- Software or AI (using machine learning, analytics, or statistical models) that scores, classifies, or recommends hiring or promotion decisions, substantially assisting or replacing human judgment.
- Automated Employment Decision Tools (AEDTs)
- AI tools used by employers for hiring or promotion that, under NYC Local Law 144, must undergo a bias audit with published results and candidate notice.
- Availability
- Knowledge that data is accessible, as needed, by those authorized to use it.
- Back end
- Devices and software operating separately from the web server, such as databases, that are not essential for operating the server.
- Ban the Box laws
- Laws that remove the checkbox on job applications asking whether an applicant has a criminal history, delaying criminal-history inquiries.
- Bank Secrecy Act (BSA)
- The anti-money-laundering statute requiring financial institutions to maintain an adequate AML program and file timely Suspicious Activity Reports.
- Bias audit
- An assessment of an AEDT for disparate impact that NYC Local Law 144 requires before the tool is used and whose results must be published.
- Binding corporate rules (BCRs)
- Rules allowing a multinational to transfer data among affiliated entities after certification of its practices by a DPA.
- BIPA
- The Illinois Biometric Information Privacy Act of 2008, the first U.S. biometric privacy law, with a private right of action and per-violation damages.
- BitLicense
- NYDFS license required for individuals or businesses that receive, transmit, control, issue, exchange or maintain custody of virtual currencies.
- Blacklisting
- Blocking access to specified websites or internet activity considered inappropriate.
- Bodily privacy
- Privacy focused on a person's physical being and invasions such as genetic testing, drug testing, or body cavity searches.
- Bona fide occupational qualification
- A characteristic reasonably necessary to the normal operation of a business that can justify an otherwise-prohibited inquiry or requirement.
- Breach (HITECH)
- An unauthorized acquisition, access, use, or disclosure of unsecured PHI, presumed to have occurred unless a risk assessment shows low probability of compromise.
- Breach of contract
- When one party fails to meet its contractual obligations, allowing the injured party to sue for damages or enforcement.
- Breach of system security
- Unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information.
- Broadened 'breach' definition
- Under the 2023 rules, a breach includes the inadvertent access, use, or disclosure of customer information, not only intentional acquisition.
- Buckley Amendment
- Another name for FERPA, referring to Senator James Buckley who supported its enactment.
- Budapest Convention
- The 2004 Council of Europe Convention on Cybercrime, the first treaty focused on cybercrime; its Second Additional Protocol (signed 2022) addresses cross-border access to evidence.
- Bureau of Consumer Protection (BCP)
- The FTC bureau whose Enforcement Division monitors and litigates consent-decree violations, working with the DOJ.
- Business / Controller
- The entity that conducts business in a state and is subject to the law; California uses business, the other four states use controller.
- Business associate
- Any person or organization, other than a covered entity's workforce member, that performs services for or on behalf of a covered entity involving the use or disclosure of PHI.
- Business associate agreement (BAA)
- A written contract requiring a business associate to meet the privacy and security obligations applicable to the covered entity.
- BYOD
- Bring your own device; employees using personal computing devices for work, raising security and privacy issues.
- Cable Communications Policy Act of 1984
- Statute regulating notice, collection, disclosure and retention of personal information by cable television providers, with a private right of action and damages.
- Caching
- When a server saves a copy of content to reduce the need to download it again from the web server.
- CALEA
- The Communications Assistance to Law Enforcement Act of 1994, requiring telecommunications carriers to design products that can carry out lawful interception orders; enforced via FCC rulemaking.
- CalGINA
- California's 2011 genetic nondiscrimination act extending protections to emergency services, mortgage lending, housing, education, and other state-funded programs.
- California Age-Appropriate Design Code Act
- A 2022 California law - the first U.S. age-appropriate design law - requiring online platforms to consider the best interest of child users and set privacy-protective defaults.
- California Constitution privacy right
- An explicit constitutional right to privacy added by California voters via ballot measure in November 1974 (Article 1, Section 1).
- California Delete Act
- A 2023 California law requiring data brokers to register with the CPPA and enabling a single centralized deletion request across all registered brokers.
- California Privacy Protection Agency (CPPA)
- The California agency that administers and enforces the Delete Act's data broker registration and deletion mechanism.
- California Privacy Rights Act (CPRA)
- A California law effective January 2023 that requires notice and an opt-out right for third-party cookies.
- California SB 1386
- The first U.S. security breach notification law, covering entities doing business in California that own or license computerized personal information.
- CalOPPA
- The California Online Privacy Protection Act (2003), the first U.S. law requiring commercial websites/apps to post a privacy notice if they collect PII from Californians; 2013 amendment added Do Not Track disclosure requirements.
- CAN-SPAM
- The Controlling the Assault of Non-Solicited Pornography and Marketing Act, restricting unsolicited commercial email; enforced by the FTC, FCC, and state AGs.
- CAN-SPAM Act
- The Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003, governing commercial email directed to or originating from the U.S.
- Carpenter v. United States
- U.S. Supreme Court decision holding that police need a warrant to conduct long-term tracking of an individual's movements.
- Case law
- The final decisions made by judges in court cases, used as precedent for future similar issues.
- CCPA
- California Consumer Privacy Act; its private right of action created statutory damages for breaches caused by failure to maintain reasonable security.
- Certificate of confidentiality
- An NIH-issued protection ensuring research material cannot be used in legal or administrative proceedings without the participant's consent.
- CFIPA
- California Financial Information Privacy Act (SB-1), which expands GLBA protections and requires written opt-in consent to share personal information with nonaffiliated third parties.
- CFPB
- Consumer Financial Protection Bureau; also regulates unfair and deceptive practices and enforces laws including the FCRA.
- Chief privacy officer (CPO)
- Leader charged with developing and implementing policies for data processing and proper handling of personal information.
- Children's Advertising Review Unit (CARU)
- A self-regulatory program addressing advertising and privacy practices directed at children.
- Children's Internet Protection Act (CIPA)
- A U.S. law requiring public schools and libraries to install filters to prevent children from viewing inappropriate online content.
- Choice
- The ability to specify whether personal information is collected and how it is used or disclosed; may be express or implied.
- Choice and consent
- FIP requiring organizations to describe available choices and obtain implicit or explicit consent for handling personal information.
- CIA triad
- The traditional model of computer security: confidentiality, integrity, and availability.
- Ciphertext
- Scrambled, unreadable data produced by encrypting plaintext.
- CISA
- The Cybersecurity Information Sharing Act of 2015, permitting voluntary sharing of cyberthreat indicators and defensive measures with the government and others, with defined protections.
- City of Ontario v. Quon
- Supreme Court case allowing a (public) employer to review an employee's text messages to determine whether its electronic-usage policy was violated; the employer provided the pager.
- Civil litigation
- A court action where a plaintiff sues a defendant to redress a wrong, typically seeking money damages or an injunction.
- CJEU
- The Court of Justice of the European Union, whose Schrems I and Schrems II decisions scrutinized surveillance practices in countries receiving EU data.
- Client
- Hardware or software that accesses a service from a server by sending a request; a thick client processes data itself, a thin client relies on remote processing.
- CLOUD Act
- The 2018 Clarifying Lawful Overseas Use of Data Act; Part 1 lets U.S. orders reach data wherever stored, Part 2 lets qualifying foreign governments access content held by U.S. providers via executive agreements.
- Cloud computing
- On-demand availability of computing resources, offering cost savings, scalability, and remote access compared to on-premises systems.
- CMIA
- California's Confidentiality of Medical Information Act, which extends health privacy duties to software, hardware, and online service providers beyond HIPAA's reach.
- Co-regulatory model
- An approach emphasizing industry-developed enforceable codes against a backdrop of government legal requirements; e.g., COPPA codes approved by the FTC.
- COBRA
- Consolidated Omnibus Budget Reconciliation Act; requires qualified health plans to provide continuous coverage to certain beneficiaries after termination.
- Collection Limitation Principle
- OECD principle limiting collection of personal data, obtained by lawful and fair means and, where appropriate, with consent.
- Collective bargaining agreement
- A union-negotiated contract that often protects employee privacy, e.g., limiting drug testing and workplace monitoring; the most important contracts for employee privacy.
- Colorado AI Act
- A Colorado law addressing algorithmic discrimination, enforced by the attorney general only.
- Commercial surveillance
- Defined in the FTC's 2022 proposed rules as the collection, aggregation, analysis, retention, transfer, or monetization of commercial data and its direct derivatives.
- Common carriers
- Transportation and communications providers, which are outside the FTC's Section 5 jurisdiction.
- Common law
- Legal principles developed over time in judicial decisions, often from social customs, contrasting with statutory law.
- Communications privacy
- Privacy protecting the means of correspondence, including postal mail, telephone, email, and other communicative behavior.
- Comprehensive model
- A data protection approach where the government defines requirements across the whole economy (public and private sectors), usually overseen by a DPA.
- Comprehensive privacy law
- A law that protects all types of personal data across sectors, as opposed to a sector-by-sector approach.
- Computer trespasser exception
- PATRIOT Act Section 217 provision permitting (not requiring) a computer system owner/operator to authorize law enforcement interception of a trespasser's communications under defined conditions.
- Conditional offer
- A job offer made before a medical exam; after it is extended, an employer may require an exam if all entering employees in the job category are treated the same.
- Confidentiality
- Access to data is limited to authorized parties.
- Consent
- A freely given, specific, informed, and unambiguous indication of the data subject's wishes, given by statement or clear affirmative action.
- Consent decree
- A settlement in which the respondent does not admit fault but promises to change its practices and avoid further litigation; posted publicly by the FTC.
- Consideration
- The bargained-for exchange (money, property, or services); an agreement without consideration is not a contract.
- Consumer
- The individuals protected by a state comprehensive privacy law - defined as state residents, not limited to people buying products or services.
- Consumer Health Data
- Health data collected by mobile devices, apps, and wearables that falls outside HIPAA's coverage.
- Consumer report
- Under FCRA, written/oral/other communications bearing on a consumer's creditworthiness, character, reputation, personal characteristics, or mode of living.
- Consumer reporting agency (CRA)
- An organization that regularly assembles or evaluates consumer information to furnish consumer reports to third parties for a fee.
- Controller
- An entity that determines the purposes and means of processing personal data.
- Convention 108
- The 1981 Council of Europe Convention for the Protection of Individuals with Regard to Automatic Processing of Personal Data, requiring signatory states to adopt data protection provisions in domestic law.
- Convention 108+
- The 2018 update to Convention 108, bringing it in line with the EU's GDPR on proportionality, breach notice, and transborder flows.
- COPPA
- The Children's Online Privacy Protection Act, applying to operators of sites or services directed to children under 13, and to general-audience services with actual knowledge they collect personal information from under-13s.
- Covered entity
- Under HIPAA, an organization such as a health plan, clearinghouse, or provider conducting standard transactions, which is subject to the Privacy Rule.
- Covered entity (breach law)
- An entity subject to a state breach law, typically one that does business in the state and maintains computerized personal information.
- CPA
- The Colorado Privacy Act.
- CPNI
- Customer proprietary network information - subscription and service data, network and billing information, phone features, and call log data (time, date, destination, duration); name, phone number and address are NOT CPNI.
- CPPA
- The California Privacy Protection Agency, a dedicated privacy regulator created by the CPRA, seen as analogous to an EU data protection authority.
- CPRA
- California Privacy Rights Act; updated the CCPA, including its statutory-damages framework (see Chapter 6).
- Credit monitoring requirement
- A mandate in California, Delaware, and Massachusetts to provide affected individuals free credit monitoring for at least 12 months when SSNs or similar data are exposed.
- Criminal prosecution
- Government action for violations of criminal law that can lead to imprisonment and criminal fines; prosecuted federally by the DOJ.
- Cross-Border Privacy Rules (CBPR)
- APEC system for cross-border data protection, extended in 2022 into the Global CBPR Forum allowing non-APEC members to participate.
- Cross-context behavioral advertising
- Advertising targeted to a consumer based on personal information collected over time across different online contexts.
- Cross-device behavioral advertising
- Targeted advertising based on a consumer's information obtained across websites, services or applications; restricted under the California framework.
- Cross-device tracking
- The ability to link a single user to multiple devices such as phones, tablets, and laptops.
- CTDPA
- The Connecticut Data Privacy Act.
- CUBI
- Texas's biometric privacy law, enforced by the state attorney general with no private right of action.
- Cure period
- A set number of days an enforcer must give a business to fix a violation before sanction; present in some states, expired or absent in others.
- Currency Transaction Report
- BSA report (Form 4789) filed for currency transactions of $10,000 or more.
- Customer (GLBA)
- A consumer with an ongoing relationship with a financial institution; many GLBA notice requirements apply specifically to customers.
- Cyber threat indicator
- Information needed to describe or identify a malicious cybersecurity threat or vulnerability; the definition excludes sensitive personal and business information.
- Cybersecurity Information Sharing Act (CISA)
- A 2015 law that encourages the voluntary sharing of unclassified cyber threat information between private companies and the federal government, with liability protection for those who share.
- Cybersecurity safe harbor law
- A law (Connecticut, Iowa, Ohio, Utah) letting a company defeat a breach lawsuit if it had appropriate safeguards in place before the breach.
- Cyberthreat indicator
- Technical information about how networks have been attacked, which a company may share under CISA for a cybersecurity purpose.
- DAA / AdChoices
- The Digital Advertising Alliance's icon program letting consumers exercise choice over online behavioral advertising.
- Dark Pattern
- A deceptive interface design that manipulates users into actions they did not intend, such as confusing buttons that triggered unwanted Fortnite purchases.
- Dark patterns
- Design practices that trick or manipulate users into choices they would not otherwise make and that may cause harm.
- Data breach (GDPR)
- A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.
- Data breach notification law
- A state law requiring entities to disclose to affected individuals (and often regulators) when personal information is accessed by an unauthorized party.
- Data breach readiness assessment
- An assessment of the level of breach risk plus the likelihood and severity of a personal data breach.
- Data Broker
- A company that collects and sells personal data without the consumer's direct relationship or knowledge.
- Data brokers
- Businesses that obtain data from one or more sources, process and cleanse it, and license it for use by first parties; scrutinized by the FTC over privacy concerns.
- Data classification
- Categorizing data by sensitivity to set who may access it and the baseline protection required.
- Data controller
- An organization with authority to decide how and why personal information is processed; bears most obligations under privacy law.
- Data destruction law
- A state law requiring secure disposal of personal information at the end of the data life cycle so it is no longer readable or decipherable.
- Data destruction laws
- State laws (discussed in Chapter 7) that mandate requirements in the deletion stage of the data life cycle.
- Data fiduciary duty
- A novel proposed approach requiring companies that handle data to act in good faith on behalf of consumers.
- Data flow mapping
- Documenting the systems, applications, and processes that handle data - what, where, and why data is processed.
- Data inventory
- A documented accounting of the PI an organization collects, stores, uses, or discloses, including its location, flow, and sharing.
- Data life cycle
- The stages data moves through: creation, storage, sharing and usage, archival, and deletion.
- Data lineage
- Metadata added to a map identifying the original source of data, the most critical data, and how data sets are built and aggregated.
- Data localization
- Requirements that data be stored or processed within a country's borders - a growing global trend.
- Data loss prevention (DLP)
- A strategy and tools to ensure sensitive data is not accessed, misused, or lost by monitoring and controlling endpoint activities; can be highly privacy-invasive.
- Data mapping
- The process of identifying where personal data resides and how it flows, central to due diligence in mergers, acquisitions, and divestitures.
- Data minimization
- Processing must be adequate, relevant, and limited to what is necessary for the purpose.
- Data portability
- The ability of individuals to obtain and reuse their personal data across different services, the subject of a 2020 FTC workshop.
- Data processor
- An individual or organization that processes data on behalf of a controller; called a 'business associate' under the HIPAA Privacy Rule.
- Data protection impact assessment (DPIA)
- Assessment similar to a PIA, associated with the GDPR.
- Data protection law
- The European Union (and other countries') term for laws protecting personal information about individuals.
- Data protection officer (DPO)
- The primary internal point of contact on data protection for an EU-based business, who must have expertise and no conflicts of interest.
- Data security law
- A state law requiring companies to develop and maintain appropriate security measures to protect personal information, often under a reasonableness standard.
- Data subject
- The natural person whose personal data is being collected, stored, or processed.
- Data subject access
- FIP requiring organizations to give individuals access to their personal information for review and updates.
- Data subject rights
- The set of GDPR rights giving individuals control over their personal data, including access, rectification, erasure, restriction, portability, and objection.
- Data-based exemption
- An exemption where only a class of data is exempt (e.g., data already covered by a federal law), leaving the rest of the entity's data regulated.
- Deceptive practice
- A material statement or omission likely to mislead consumers acting reasonably under the circumstances - including failure to honor privacy-notice promises.
- Deep packet inspection
- Examination by a node of some or all of a packet's contents (beyond the routing header) for purposes such as malware detection, data-leak prevention, ad targeting, or censorship.
- Defamation
- A tort based on a false, reputation-harming statement, e.g., a false drug-test report or a factually incorrect employer reference.
- Defense in depth
- Layering obstacles so an initial intrusion still faces multiple barriers before harm occurs.
- Deidentified
- Data altered so it is no longer identifiable; it is far from simple to determine when data is truly deidentified.
- Deidentified data
- Data that cannot reasonably be associated or linked with a particular individual; excluded by all five states.
- Deidentified information
- Health information that does not identify an individual and offers no reasonable basis to do so.
- Derogation
- An EU term for an exception permitting a transfer where no adequacy decision or safeguard applies, interpreted narrowly.
- Designated record set
- A patient's medical and billing records and other records a covered entity uses to make decisions about individuals, to which the access right applies.
- Deterministic tracking
- Cross-device linking based on the user logging in, so the same login is observed across devices.
- DHS
- The U.S. Department of Homeland Security, which handles privacy issues such as E-Verify, TSA air-traveler records, and ICE immigration matters.
- Differential privacy
- A mathematical definition of privacy guaranteeing that anyone seeing a result will make essentially the same inference about an individual whether or not that person's data is in the input, defined via the noise needed for a set of queries.
- Digital Advertising Alliance (DAA)
- A nonprofit whose Self-Regulatory Principles for Online Behavioral Advertising emphasize transparency and consumer opt-out management, enforced via the Council of Better Business Bureaus and the Direct Marketing Association.
- Digital signature
- A string Alice creates with her private key; if Bob's application of her public key yields readable plaintext, the message is verified as unchanged.
- Directory information
- Information FERPA treats as not generally harmful if disclosed, such as name, address, email, phone, field of study, and honors, which a school may release unless the student opts out.
- Discovery
- Information disclosed to another party in a lawsuit before trial, governed by the rules of civil and criminal procedure.
- Disgorgement
- Requiring a company to repay profits earned from wrongful conduct.
- Disposal Rule
- FACTA rule requiring any entity using a consumer report for a business purpose to dispose of the information in a way that reasonably prevents unauthorized access and misuse.
- DNC Safe Harbor
- Protection from penalties for an erroneous call if the seller/telemarketer follows written procedures, trains staff, maintains an entity-specific list, uses registry data no older than 31 days, monitors compliance, and the call resulted from error.
- Dobbs v. Jackson Women's Health Organization
- 2022 Supreme Court case that overturned Roe v. Wade, stated to be limited to abortion but raising concern about other penumbra-based privacy rights.
- DOC
- The U.S. Department of Commerce, which leads federal privacy policy and has administered EU-U.S. data-flow agreements.
- Dodd-Frank Act
- Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010, which created the Consumer Financial Protection Bureau (CFPB).
- DOJ
- The U.S. Department of Justice, the sole federal agency that brings criminal enforcement actions.
- DOL
- U.S. Department of Labor; administers federal labor laws including the FLSA, OSHA, and ERISA.
- Double opt-in
- Email practice where a subscriber indicates interest and then confirms via a follow-up email before receiving marketing.
- DPA
- A data protection authority - an independent public authority dedicated to data protection enforcement, the EU model the CPPA mirrors.
- DPPA
- The Driver's Privacy Protection Act, a federal law whose covered data is an example of a data-based exemption under state comprehensive laws.
- Duty of loyalty
- A proposed obligation in some U.S. federal privacy bills requiring businesses to act in the best interests of those whose personal data is processed.
- Dynamic IP address
- An IP address an ISP assigns as needed, which may change per session or persist for months.
- E-discovery
- The discovery of electronically stored information, an important subdiscipline of law and technology since the 2006 FRCP revisions.
- ECPA
- Electronic Communications Privacy Act; with the Wiretap Act, restricts interception of communications such as emails and calls.
- Edge computing
- A distributed IT architecture where data is processed at the periphery of the network, as close to the originating source as possible.
- Edtech
- Companies providing software, apps, and web-based tools to educators, students, and parents, whose data practices are subject to the chapter's privacy laws.
- Education record
- Any record directly related to a student and maintained by or on behalf of the school, including grades, financial aid, and disciplinary records.
- EEA
- The European Economic Area - the EU plus Norway, Liechtenstein, and Iceland - from which transfers are regulated.
- EEOC
- Equal Employment Opportunity Commission; works to prevent workplace discrimination, overseeing Title VII, the ADEA, and Titles I and V of the ADA.
- Electronic Communications Privacy Act (ECPA)
- Extended the interception ban to electronic communications such as email; violations are a criminal offense with a private right of action.
- Electronic fund transfer (EFT)
- Any transfer of funds initiated through an electronic terminal, telephone, computer or magnetic tape to debit or credit a consumer's account, such as ATM, direct deposit, point-of-sale or debit card transfers.
- Electronic health records (EHRs)
- Digital medical records whose meaningful use HITECH funded with $19 billion in provider incentives.
- Electronically stored information (ESI)
- Email, documents, databases, web pages, server logs, IM transcripts, voicemail, social media, and removable media - the focus of pretrial e-discovery since 2006.
- Eligible student
- A student who holds the FERPA rights, generally a high schooler who has turned 18 or any student attending only a college or university.
- Employment at will
- The U.S. default rule giving employers broad discretion to fire an employee, which has also been read to grant broad latitude over other aspects of the employment relationship.
- Employment life cycle
- The framework of privacy issues spanning before employment (screening), during employment (testing, monitoring), and after employment (access termination, records).
- Encryption
- A reversible process that converts plaintext into scrambled ciphertext; decryption reverses it using a key.
- Encryption safe harbor
- A provision excusing breach notice where data was encrypted, redacted, or rendered unreadable/unusable - generally only if the decryption key was not also breached.
- Enforcing agency
- The FCC enforces these rules; they are distinct from the CPNI rules under the Telecommunications Act and from state breach-notification laws enforced by state attorneys general.
- Entity-level exemption
- An exemption where an entire type of organization is exempt from the law (e.g., nonprofits, higher education, local governments).
- Entity-specific suppression list
- An internal Do Not Call list a seller/telemarketer must maintain to honor a consumer's request not to be called again by that company.
- ePHI
- Electronic protected health information; PHI transmitted or maintained in electronic media such as hard drives, tapes, disks, or memory cards.
- EPIC
- The Electronic Privacy Information Center, a nongovernmental organization focused on civil liberties and privacy.
- Epic Games
- The maker of Fortnite, which in 2023 reached a $520 million settlement with the FTC over COPPA violations and dark patterns.
- EPPA
- Employee Polygraph Protection Act of 1988; prohibits most private employers from using lie detectors on employees or applicants, enforced by the DOL.
- Equal Pay Act of 1963
- Federal law barring wage disparity based on sex.
- ERISA
- Employee Retirement Income Security Act; ensures employee benefits programs are created fairly and administered properly.
- Established business relationship (EBR)
- A relationship permitting calls despite the registry: 18 months from a customer's last purchase/transaction, or three months from a prospect's inquiry or application.
- EU representative
- A representative appointed by a company with no physical EU presence, who is subject to GDPR enforcement proceedings.
- EU-U.S. Data Privacy Framework
- The 2023 successor agreement enabling EU-to-U.S. transfers, supported by U.S. Executive Order 14086.
- European Convention on Human Rights (1950)
- Council of Europe convention whose Article 8 guarantees respect for private and family life, home, and correspondence.
- Evidentiary privilege
- A rule (generally defined under state law) that prevents a person from being compelled to testify or produce records, such as attorney-client, doctor-patient, priest-penitent, or spousal privilege.
- Exclusionary rule
- Evidence gathered in violation of the Fourth Amendment may be excluded from a criminal trial.
- Executable code
- Code that can run a computer program; limiting employees' ability to download it helps prevent spyware installation.
- Executive branch
- The president, vice president, cabinet, and federal agencies, which enforce and administer the law through rulemaking and civil/criminal procedures.
- Executive Order 14086
- President Biden's order committing U.S. surveillance to a necessity-and-proportionality standard and creating an independent data protection review court.
- Expanded covered PII
- The 2023 rules expanded the scope of personally identifiable information covered by the notification obligation.
- Expert determination
- The deidentification method where a qualified expert certifies the re-identification risk is very small.
- Expert determination method
- A HIPAA deidentification method in which an expert determines and documents that the risk is very small that an anticipated recipient could identify an individual.
- Explicit consent
- A heightened form of consent required to process sensitive personal data unless an exception applies.
- Extensible markup language (XML)
- A language that describes content in terms of the data being produced (not how it is displayed), enabling automated high-volume processing.
- FACTA
- Fair and Accurate Credit Transactions Act of 2003; amended the FCRA and preempted many state laws, but left employment credit-check laws and certain state laws in effect.
- FACTA Disposal Rule
- Rule under the Fair and Accurate Credit Transactions Act of 2003 setting required disposal protections for financial institutions; a good baseline for PI disposal generally.
- Fair Chance to Compete on Jobs Act (FCA)
- 2019 law restricting federal agencies and federal contractors from requesting an applicant's criminal-history information until a conditional offer of employment has been made.
- Fair Credit Reporting Act (FCRA)
- The first U.S. national privacy law, passed in 1970, focused solely on information about consumer credit.
- Fair information practices (FIPs)
- The foundational privacy principles, originating with the U.S. government in the 1970s, on which the first wave of modern privacy laws was based.
- Family Policy Compliance Officer (FPCO)
- The office within the U.S. Department of Education that investigates FERPA complaints and typically provides technical assistance.
- FAPE
- Free appropriate public education, which IDEA ensures for eligible students with disabilities.
- FAST Act
- The Fixing America's Surface Transportation Act (December 2015), which amended GLBA section 503 to create an exception to the annual privacy notice requirement.
- FATCA
- Foreign Account Tax Compliance Act of 2010, targeting U.S. taxpayers with foreign accounts and requiring more detailed KYC documentation.
- FCC
- The Federal Communications Commission, which issues and enforces the TCPA rules on telemarketing, robocalls, faxes and texts.
- FCC 2023 breach rules
- Updated data breach notification rules the FCC adopted in December 2023 for telecommunications carriers, interconnected VoIP, and telecommunications relay services; enforced by the FCC.
- FCRA
- Fair Credit Reporting Act of 1970, the first federal law to regulate private businesses' use of personal information, governing consumer reporting agencies and consumer reports.
- FDCA
- The Federal Food, Drug, and Cosmetic Act, enforced by the FDA to regulate medical devices by levels of risk.
- Federal preemption
- The displacement of state law by federal law; a contested issue in proposed federal breach legislation, where businesses favor preempting stricter state laws.
- Federal Rule of Civil Procedure 45
- The rule governing subpoenas; it specifies required contents and authorizes contempt for failure to obey without adequate excuse.
- FERPA
- The Family Educational Rights and Privacy Act of 1974, a federal statute giving students control over disclosure and access to their education records.
- Fifth Amendment privilege
- The constitutional privilege against self-incrimination available to a person accused of a crime in state or federal court.
- FinCEN
- Financial Crimes Enforcement Network within the Department of Treasury, which administers anti-money-laundering laws to 'follow the money.'
- FIPPs
- Fair Information Practice Principles such as notice, consent, access and correction, security, and accountability, major aspects of which FERPA incorporates.
- First responders
- Front-line individuals who respond when the organization faces a specific privacy difficulty.
- FLSA
- Fair Labor Standards Act; establishes the minimum wage and standards for fair pay.
- FMLA
- Family and Medical Leave Act; entitles certain employees to unpaid leave for birth or illness of self or a family member.
- Foreign Intelligence Surveillance Act (FISA)
- 1978 law establishing standards and procedures for electronic surveillance collecting foreign intelligence within the United States, with orders from the FISC.
- Foreign Intelligence Surveillance Court (FISC)
- The special court of federal district judges that issues FISA orders; the USA FREEDOM Act added an amicus curiae of privacy experts for novel matters.
- Fourth Amendment
- Constitutional protection against unreasonable searches and seizures, requiring warrants on probable cause, supported by oath, particularly describing the place to be searched.
- FRCP 5.2
- The 2007 'Privacy Protection for Filings Made with the Court' rule requiring attorneys to redact specified personal identifiers from court filings.
- Free-to-pay conversion offer
- An offer that starts with a free trial then converts to paid service when the trial ends.
- Front end
- The web-based interface where client and server interact, generally coded in HTML, CSS, and JavaScript.
- FTC
- Federal Trade Commission; regulates unfair and deceptive practices and enforces laws including the FCRA.
- FTC Act
- The law under which the FTC polices unfair or deceptive practices, including by health companies not covered by HIPAA.
- FTC Disposal Rule
- A federal rule, enforced by the FTC, governing disposal of consumer reports and information derived from them (covered in Chapter 9).
- FTC Health Breach Notification Rule (HBNR)
- A 2009 FTC rule requiring vendors of personal health records and related entities to notify after a breach of identifiable health information held outside HIPAA.
- FTC v. LabMD
- 2018 Eleventh Circuit case that recognized FTC authority but vacated its order as too vague, constraining the FTC's ability to mandate comprehensive security overhauls.
- FTC v. Wyndham
- 2015 Third Circuit case confirming the FTC's Section 5 unfairness authority extends to regulating cybersecurity practices harmful to consumers.
- Furnisher
- An entity such as a lender or retailer that supplies credit history or other personal information to CRAs; must provide accurate data and respond to disputes.
- Furnisher Rule
- Rule requiring furnishers to maintain policies and procedures ensuring the accuracy and integrity of consumer information reported to CRAs, including preventing re-aging of delinquency dates.
- GDPR
- The 2018 comprehensive EU privacy regulation that serves as the worldwide template for data protection law.
- Generalization
- Replacing a detailed data element with a more general one (e.g. year of birth instead of full date, municipality instead of GPS).
- Genetic Information Nondiscrimination Act (GINA)
- The 2008 federal law protecting genetic information in employment and health insurance.
- Geofence warrant
- A warrant seeking data on all devices within a defined area; challenged under the bar against general warrants, with mixed results in lower courts.
- Geofencing
- Technology that targets digital advertising to people within a virtual boundary; the data it generates can later be sought by law enforcement via a geofence warrant.
- GINA
- Genetic Information Nondiscrimination Act of 2008; bars discrimination based on individuals' genetic information.
- GIPA
- The Illinois Genetic Information Privacy Act of 1998, which restricts use of genetic information and grants a private right of action with uncapped per-violation damages.
- GLBA
- Gramm-Leach-Bliley Act of 1999, supplying the general framework for confidentiality of records in the financial services sector through its Privacy Rule and Safeguards Rule.
- GLBA Privacy Rule
- The GLBA rule governing notice of privacy practices and the consumer's opt-out right regarding sharing of nonpublic personal information with nonaffiliated third parties.
- GLBA Safeguards Rule
- The GLBA rule requiring financial institutions to develop, implement, and maintain administrative, technical, and physical safeguards to protect customer information, including adequate authentication.
- Global CBPR Forum
- A 2022 international certification system based on the APEC Cross-Border Privacy Rules, independent of APEC so non-members can join.
- Global Privacy Control (GPC)
- The leading example of a universal opt-out mechanism, communicated as a browser or device signal that businesses in certain states must honor.
- GPS
- Global positioning satellites that let a device determine its longitude, latitude, and altitude from differences in message arrival times.
- Hague Convention on the Taking of Evidence
- A treaty providing an alternative route for obtaining foreign evidence; the party invoking it bears the burden of showing it is more appropriate and that foreign law prohibits the discovery.
- Hashing
- A one-way cryptographic function that transforms an input into an alphanumeric output that cannot be reversed back to the original.
- Health care clearinghouse
- A third-party organization that hosts, handles, or processes medical information.
- Hesse data protection law (1970)
- The first known modern data protection law, enacted by the German state of Hesse in 1970.
- HEW Code of Fair Information Practices (1973)
- A 1973 U.S. Department of Health, Education and Welfare code that is the foundation of FIPs used widely today.
- HHS
- The U.S. Department of Health and Human Services, which promulgates and enforces HIPAA's privacy and security regulations.
- HHS Office for Civil Rights guidance (2022)
- Post-Dobbs guidance clarifying that PHI may not be disclosed as 'required by law' where state law does not expressly require reporting, but may be disclosed in response to a court order or court-ordered warrant.
- HHS Office of Civil Rights
- The U.S. Department of Health and Human Services component with regulatory authority over health privacy.
- Higher-level fines
- GDPR fines up to the greater of 20 million euros or four percent of global annual revenue, for infringements of basic processing principles, data subject rights, and transfer rules.
- HIPAA
- Health Insurance Portability and Accountability Act of 1996; its privacy and security rules regulate protected health information for health insurers, including self-funded health plans.
- HIPAA Safe Harbor Law
- A 2021 law requiring the OCR to consider whether a covered entity used recognized security practices for the prior 12 months, allowing leniency in fines, notably after a breach.
- HITECH
- The Health Information Technology for Economic and Clinical Health Act; the FTC shares breach-notification authority with HHS for personal health record providers.
- HITECH Act
- The Health Information Technology for Economic and Clinical Health Act of 2009, enacted within ARRA, which strengthened HIPAA and funded health IT adoption.
- HITECH Act (2009)
- The Health Information Technology for Economic and Clinical Health Act, which added breach-notification requirements for vendors of personal health records not covered as HIPAA covered entities.
- HTTPS
- Hypertext transfer protocol secure, which transfers data between browser and website over an encrypted connection; by 2016 it exceeded HTTP traffic.
- Hyperlinking
- Berners-Lee's term for dynamically tying documents and files together; a hyperlink transports a user to a destination page.
- Hypertext markup language (HTML)
- A content-authoring language used to create web pages; HTML5 is the most recent version and can run media without plug-ins.
- Hypertext transfer protocol (HTTP)
- An application protocol that formats and transmits messages over a TCP/IP network and defines how servers and browsers respond to commands.
- ICRAA
- California's Investigative Consumer Reporting Agencies Act; requires notice and written authorization before obtaining a consumer report and a copy of the report before adverse action.
- IDEA
- The Individuals with Disabilities Education Act, a federal law ensuring eligible students aged 3 to 21 receive a free appropriate public education.
- Identify, Protect, Detect, Respond, Recover
- The five NIST CSF Framework Core Functions, designed to operate concurrently and continuously.
- Identity theft laws
- State laws addressing identity theft; all 50 states have them and more than half permit restitution for victims.
- IEP
- Individualized education program, the tailored special-education plan IDEA requires for each eligible student.
- Illinois BIPA
- The Illinois Biometric Information Privacy Act, which regulates the collection and handling of biometric identifiers such as fingerprints and requires consent before collection.
- IMAP
- Internet Message Access Protocol for receiving email; typically leaves messages on the server, enabling multi-device sync and server-side search.
- IMLC
- The Interstate Medical Licensure Compact, whose use grew nearly 50 percent during the pandemic to ease cross-state physician licensing.
- Information blocking
- Any activity likely to interfere with, prevent, or materially discourage access, exchange, or use of electronic health information.
- Information broker (Georgia)
- Georgia's narrow definition of covered entity, limiting the breach law to businesses whose primary purpose is furnishing personal information to nonaffiliated third parties.
- Information management
- Establishing, implementing, and monitoring an organization's privacy program under the direction of a senior leader.
- Information privacy
- Privacy concerned with rules governing the collection and handling of personal information such as financial, medical, government, and internet-activity records.
- Information security program
- A program containing administrative, technical and physical safeguards to protect the security, confidentiality and integrity of customer information.
- Infrastructure as a service (IaaS)
- Self-service access to computers, networking, and storage where the customer retains complete control over what is done, including managing databases of personal information.
- Injunction
- A court order requiring a defendant to stop engaging in certain conduct.
- Institute for Advertising Ethics (IAE)
- An independent body promoting ethical principles - honesty, fairness, and never compromising consumers' privacy - to build a more trusted digital marketplace.
- Integrity
- Assurance that data is authentic and complete.
- Intentional tort
- A wrong the defendant knew or should have known would result from their action or inaction.
- Interactive Computer Service
- The type of online service or platform that Section 230 shields from being treated as the publisher or speaker of third-party content.
- Internet protocol (IP)
- The protocol that specifies the format of data packets and provides the addressing scheme; each device gets a unique IP address (currently moving from IPv4 to IPv6).
- Internet service provider (ISP)
- A provider, such as a cable or wireless company, that connects users and devices to the internet and assigns IP addresses.
- Interoperability
- The substantial similarity and overlap among the state comprehensive laws, such that compliance approaches can carry across states.
- Intrusion on seclusion
- A privacy tort imposing liability for intentionally intruding on another's solitude in a manner highly offensive to a reasonable person - a higher bar than telemarketing law's milder-intrusion standard.
- Intrusion upon seclusion
- A tort imposing liability for intentionally intruding on another's solitude or private affairs in a way highly offensive to a reasonable person (e.g., a camera in a restroom).
- Investigative consumer report
- A consumer report where some information is gathered through interviews with neighbors, friends, associates, or acquaintances (e.g., reference checks).
- IP address
- Numbers identifying the location of computers in internet communications; treated as personal data in the EU but generally not under the U.S. Privacy Act.
- IRCA
- Immigration Reform and Control Act; requires employment eligibility verification.
- Joint marketing partner
- Another financial institution with which an entity jointly markets a financial product or service, with whom information may be shared under GLBA.
- Judicial branch
- The federal court system, which interprets laws and examines a law's constitutionality and intent.
- Judicial Redress Act
- 2016 law extending certain U.S. Privacy Act protections to certain non-U.S. persons.
- Judicial Redress Act of 2015
- U.S. law extending a right to civil action against a U.S. agency for qualifying non-U.S. individuals to access and rectify covered records.
- Junk Fax Prevention Act (JFPA)
- A 2005 amendment to the TCPA clarifying that consent to commercial faxes can be inferred from an established business relationship, provided the sender offers an opt-out.
- Jurisdiction
- A court's authority to hear a case, requiring both subject matter jurisdiction (the type of dispute) and personal jurisdiction (over the parties).
- Just-in-time notice
- Notice provided at or before the point of information collection or before accepting a service/product.
- Justices of the Peace Act (1361)
- An English statute providing for the arrest of 'peeping Toms' and eavesdroppers, an early legal protection of privacy.
- Key
- A string of characters applied by a cryptographic algorithm; the longer and more complex, the stronger the security.
- Keylogging
- A type of spyware (malware) that tracks all keystrokes and sends them to an attacker.
- Know Your Customer (KYC)
- Requirements, expanded by the USA PATRIOT Act, to identify customers and beneficial owners of accounts to deter money laundering.
- Latency
- The delay in communicating over a network, which edge computing reduces by keeping data closer to the source.
- Law enforcement delay
- A provision allowing breach notice to be postponed for a reasonable period when law enforcement determines that notification would impede a criminal investigation.
- Layered privacy notice
- A short top-layer summary with a link to a comprehensive full notice in the bottom layer.
- Lead DPA
- The supervisory authority designated to take the lead when a complaint involves more than one DPA.
- Least privilege
- Giving each user the most limited scope of action needed to do their job.
- Legislative branch
- Congress (House and Senate), which writes and passes laws and can override presidential vetoes.
- Legitimate educational interest
- A basis for a school official to access records where the record is relevant and necessary to that official's responsibilities; need not be academic.
- Lie detector
- Under the EPPA, includes polygraphs, voice stress analyzers, psychological stress evaluators, or similar devices used to render a diagnostic opinion about honesty.
- Lifestyle discrimination
- Adverse employer action based on an employee's lawful off-duty conduct (e.g., weight or smoking); a developing area governed largely by varied state laws.
- Limited data set
- PHI stripped of most direct identifiers, which covered entities should aim to use for disclosures, defaulting to minimum necessary if a limited data set is not feasible.
- Limited private right of action (California)
- California's narrow right allowing individuals to sue over security breaches compromising personal information and over usernames/passwords, not over general consumer rights.
- Litigation hold
- A suspension of routine retention/destruction policies once a company is on notice of discovery because litigation is underway or anticipated.
- Location-based services (LBS)
- Geolocation data from phones, GPS, and tablets enabling tracking of a user's physical location; tracking company vehicles is generally allowed, but tracking employees themselves faces greater limits.
- Lower-level fines
- GDPR fines up to the greater of 10 million euros or two percent of global annual revenue, for administrative and operational infringements.
- Madrid Resolution (2009)
- International Standards on the Protection of Personal Data and Privacy, approved by data protection and privacy commissioners (not governments) in Madrid in 2009.
- Magnuson-Moss
- The Magnuson-Moss Warranty FTC Improvements Act of 1975 (Section 18), setting complex, lengthy procedures the FTC must follow to make trade-rule regulations on unfair or deceptive practices.
- Major questions doctrine
- A doctrine restricting agencies from issuing substantial regulations without precise direction from Congress.
- Manifestation of disease
- The appearance of actual symptoms; GINA's protections target discrimination based on genetic predisposition in the ABSENCE of such manifestation.
- Material change
- A change that, at minimum, includes sharing consumer information with third parties after committing at collection not to share it - requiring opt-in if applied retroactively.
- Maximum possible accuracy
- The FCRA standard requiring CRAs to have procedures ensuring the greatest feasible accuracy of information in a consumer's report.
- Meaningful use
- The standard providers must meet in using EHRs to qualify for HITECH incentive funds.
- Metadata
- Data such as location and time automatically stored within content like photos, often without the user's awareness.
- Mini-TCPA
- A state's own version of the TCPA with additional or different telemarketing requirements and penalties (e.g., Louisiana limits established business relationships to six months).
- Mobile service commercial message (MSCM)
- A commercial email transmitted directly to a wireless device using an address that references an internet domain; covers SMS-technology messages but not phone-to-phone messages.
- MSCMs
- Mobile service commercial messages - many commercial text messages, addressed by FCC rules under CAN-SPAM.
- Multiple purpose call
- A call serving more than one sales purpose; the four basic disclosures must be made for all sales purposes promptly at the start.
- Mutual legal assistance treaty (MLAT)
- The traditional, slow mechanism (about 10 months on average) for foreign law enforcement to obtain U.S.-held evidence, requiring a showing of U.S.-standard probable cause.
- My Health My Data Act (MHMDA)
- Washington's 2023 law regulating consumer health data held by entities not covered by HIPAA, with a private right of action.
- NAIC Model Bulletin
- The NAIC Model Bulletin on the Use of Artificial Intelligence Systems, guidance for insurers emphasizing transparency, accountability, and fairness, adopted by at least 11 states.
- National Child Protection Act
- Federal law authorizing state officials to access the FBI's National Crime Information Center database for certain positions involving contact with children.
- National Do Not Call Registry
- The FTC registry, effective 2003, where U.S. residents register numbers they do not wish to receive telemarketing calls on.
- National security letter (NSL)
- A category of subpoena issued by authorized FBI officials, without judicial involvement, for records relevant to protecting against international terrorism or clandestine intelligence activities.
- Negative option feature
- An offer in which the consumer's silence or inaction is treated as acceptance of goods or services - one of the material categories that must be disclosed.
- Negligent hiring
- A tort claim against an employer for hiring an employee it knew or should have known posed a risk of harm; an incentive for employers to gather information and screen candidates.
- Negligent supervision
- A tort claim that an employer failed to adequately supervise an employee, especially where on notice of a specific risk; an incentive for workplace monitoring.
- Negligent tort
- A wrong arising when the defendant's actions were unreasonably unsafe, such as failing to maintain appropriate security controls.
- Network Advertising Initiative (NAI)
- A nonprofit self-regulatory association of third-party digital advertising companies whose Code of Conduct requires notice and choice for interest-based advertising; enforced by its board, with possible referral to the FTC.
- NIST
- National Institute of Standards and Technology - source of voluntary privacy and cybersecurity frameworks.
- NIST Cybersecurity Framework
- A voluntary tool to manage and reduce cybersecurity risk with core elements Identify, Protect, Detect, Respond, and Recover.
- NIST Cybersecurity Framework (CSF)
- A 2014 NIST framework of industry standards and best practices to help organizations manage cybersecurity risk; guidance, not a legal requirement.
- NIST Framework
- The National Institute of Standards and Technology cybersecurity framework that K-12 schools and universities are encouraged to follow.
- NLRA
- National Labor Relations Act; sets standards for collective bargaining, which also extend to social media communications.
- NLRB
- National Labor Relations Board; administers the NLRA, conducts union-representation elections, and remedies unfair labor practices.
- No Child Left Behind Act
- A 2001 statute that broadened PPRA to limit collection and disclosure of student survey information and add commercial-purpose protections.
- No option / commonly accepted practices
- Situations where implied authority lets an organization use data without opt-in or opt-out, e.g., order fulfillment.
- Noise addition
- Replacing actual values with similar but different ones, often preserving statistical properties like the average while disrupting individual identification.
- Nonpersonal information
- Data from which identifying elements have been removed (deidentified or anonymized), to which privacy and data protection laws generally do not apply.
- Nonpublic information
- Information not generally available or easily accessed due to law or custom, such as medical records, financial information, or adoption records.
- Nonpublic personal information (NPI)
- Personally identifiable financial information a consumer provides to, or that results from transactions with, or is otherwise obtained by a financial institution; excludes publicly available information and lists derived without using such information.
- Nonpublic-facing technology
- One-to-one or one-to-few videoconferencing that OCR temporarily permitted during the public health emergency even when it did not fully meet HIPAA requirements. That discretion has expired.
- Notice
- A description of an organization's information management practices, serving consumer education and corporate accountability.
- Notice at point of collection
- A requirement to inform consumers at or before collection about data categories and purposes; required only by California.
- NYC Local Law 144
- Requires employers using AEDTs to have a bias audit conducted, publish the audit results, and notify candidates that an AEDT is used and of any alternative process.
- NYDFS cybersecurity regulation
- New York Department of Financial Services 2017 regulation imposing NIST-aligned cybersecurity mandates on covered financial institutions, including a CISO, incident response and audit trails.
- OCR
- The Office for Civil Rights within HHS, the primary enforcer of the HIPAA Privacy and Security Rules.
- OCR (HHS)
- The Office for Civil Rights within HHS, which enforces HIPAA.
- OECD
- The Organisation for Economic Co-operation and Development, which adopted common principles for government access to private-sector personal data.
- OECD Guidelines (1980)
- Organisation for Economic Co-operation and Development 'Guidelines on the Protection of Privacy and Transborder Flows of Personal Data,' the most widely recognized FIP framework, updated in 2013.
- Offer
- Proposed language to enter a bargain, communicated to another and open until accepted, rejected, retracted, or expired; a counteroffer ends the original offer.
- Office of Technology
- An FTC office created in 2023 to strengthen the agency's focus on emerging technology.
- OMB
- The President's Office of Management and Budget, the lead agency for interpreting the Privacy Act of 1974 and issuing privacy/security guidance to agencies and contractors.
- On-premises computing
- Computing on resources owned and managed by the organization itself.
- ONC
- The Office of the National Coordinator for Health Information Technology, which issued the Cures Act Final Rule and enforces information-blocking provisions.
- Online behavioral advertising
- Per the IAPP, advertising targeted at individuals based on observation of their behavior over time, accomplished by tracking, profiling and targeting.
- Opt-in
- An affirmative indication of choice through an express act; failure to answer means the information is NOT used or shared.
- Opt-in (affirmative/express consent)
- Consumer must affirmatively agree before data is collected or used.
- Opt-in default for children's data
- An age-based requirement that a business obtain consent before handling a minor's data in specified ways; thresholds and triggers vary by state.
- Opt-out
- Choice implied by a person's failure to object; failure to answer means the information IS used or shared.
- Opt-out (consumer choice)
- Data may be used unless the consumer affirmatively declines; still creates an enforceable promise.
- Ordinary course of business exception
- Permits interception using equipment furnished by the communications-service provider when done in the normal course of the user's business, e.g. call-center monitoring or virus scanning.
- OSHA
- Occupational Safety and Health Act; regulates workplace safety.
- Over-the-top (OTT) services
- Messaging services that stream content over the internet (e.g. iMessage, Signal, Telegram, WhatsApp), avoiding SMS limits and able to provide end-to-end encryption.
- Over-the-top provider (OTT)
- A streaming video company delivering content over the internet or to mobile devices; not regulated by the FCC for CPNI as of this guide's writing.
- Packet sniffing
- Capturing packets sent over a wireless network in the absence of effective encryption, a risk in shared public Wi-Fi hotspots.
- Packet switching
- The method by which TCP/IP routes packets independently to a destination where they are reassembled in order, retransmitting any that fail to arrive.
- Patient-identifying information
- Any information that could reasonably identify, directly or indirectly, a person diagnosed with or treated for substance abuse.
- PCI DSS
- The Payment Card Industry Data Security Standard - a privately drafted, enforceable security standard for payment card data with penalties from $5,000 to $100,000 per month.
- PCLOB
- The Privacy and Civil Liberties Oversight Board, an independent executive-branch agency that reviewed the Section 215 and Section 702 programs.
- Pen register
- Traditionally a device recording the numbers of outgoing calls; the PATRIOT Act expanded it to dialing, routing, addressing, or signaling information.
- Pen register order
- A court order for dialed-number and similar information, issued on the lenient standard that the information is relevant to an ongoing investigation.
- Penumbra
- Unenumerated constitutional rights, including a right to privacy, inferred by the Supreme Court from several constitutional provisions and due process.
- Per-Scan vs Per-Individual Damages
- The basis for accruing BIPA damages; the 2024 amendment limited accrual to one violation per individual rather than one per scan.
- Per-Violation Damages
- Monetary damages assessed for each separate violation rather than capped at a single total amount.
- Permissible purpose
- An FCRA requirement that a consumer report be obtained only for an allowed reason; 'employment purposes' include preemployment screening and promotion/reassignment/retention decisions.
- Person
- Any entity with legal rights, including an individual (natural person) or a corporation (legal person).
- Personal data
- Any data relating to an identified or identifiable natural person, who can be identified directly or indirectly.
- Personal Health Record (PHR)
- A record of individually identifiable health information that can be drawn from multiple sources and is managed by or for the individual.
- Personal health record provider
- A provider of cloud or app services storing individual health records, subject to HITECH breach rules and FTC enforcement even without seeking federal reimbursement.
- Personal information
- Any data that can be associated or linked with a particular individual; California also covers household and employment data.
- Personal information (breach law)
- Generally a person's name plus a sensitive data element (SSN, driver's license/state ID number, or financial account/card number) whose exposure triggers notification duties.
- Personally identifiable information (PII)
- U.S. term for information that makes it possible to identify an individual, or relates to an identified or identifiable individual.
- PHI
- Protected health information, the individually identifiable health information protected under HIPAA.
- Phishing
- A form of social engineering using a routine, trusted communication channel to fool a user into granting access or disclosing sensitive information.
- PII
- Under the Department of Education's definition, information such as a student's name, identifiers, and any data that alone or combined would allow identifying the student with reasonable certainty.
- Plaintext
- The original, readable data before encryption.
- Platform as a service (PaaS)
- A cloud framework providing components for developers to build and use to create customized applications.
- POP
- Post Office Protocol (POP3) for receiving email; typically deletes mail from the server and is used less over time.
- PPRA
- The Protection of Pupil Rights Amendment of 1978, amending FERPA to give parents of minors rights over surveys collecting sensitive student information; applies only to K-12 schools.
- Practical obscurity
- The protection paper records enjoyed because they were expensive and difficult to search; online searchable records greatly reduced it.
- Pre-acquired account information
- A consumer's billing account information that the telemarketer obtained from a source other than the consumer during the call.
- Pre-adverse-action notice
- Notice with a copy of the consumer report given before taking adverse action, so the applicant can dispute the report.
- Predictive dialer
- Equipment that dials multiple consumers per available rep to maximize talk time, which can cause abandoned calls.
- Preemption
- When federal law overrides state law; HIPAA sets a federal floor and does NOT preempt stricter state protections.
- Pregnancy Discrimination Act of 1978
- Bars discrimination due to pregnancy, childbirth, and related medical conditions.
- Prescreening
- Nonconsumer-initiated transactions where a CRA furnishes a list of consumers meeting preset criteria for firm offers of credit or insurance; addressed by 1996 FCRA amendments.
- Preservation order
- An SCA requirement that a provider, on a government request, take all necessary steps to preserve records pending a court order or other process.
- Pretexting
- Gaining access to CPNI through fraudulent means; the 2007 CPNI order requires passwords and breach notifications to combat it.
- Preventing Harm
- The first APEC privacy principle, requiring protection designed to prevent misuse of personal information with remedies proportionate to the harm.
- PRISM and Upstream
- The two collection programs under Section 702; PRISM sends directives to U.S.-based providers for specific selectors, while Upstream targets communications passing through U.S. internet infrastructure.
- Privacy Act
- U.S. statute under which federal agencies generally do not consider IP addresses to be covered.
- Privacy Act of 1974
- Federal law applying to federal agencies and their private-sector contractors, interpreted by the OMB.
- Privacy advocates
- Public-interest groups, academics, and others who generally support stricter privacy law, oppose broad preemption, and favor a private right of action.
- Privacy analyst
- Often entry-level role managing legal and operational risks tied to PI, assessing business-unit operations, and developing policies and trainings.
- Privacy by design
- Embedding privacy principles in architectures, products, and services from the onset; legally required in California and the EU among others.
- Privacy champions
- Informal advocates passionate about privacy who help understand and implement privacy requirements.
- Privacy dashboard
- An easy-to-navigate summary of privacy information that also offers user control.
- Privacy engineer
- Ensures compliance through the organization's technical processes and that strategic direction supports affected customers.
- Privacy engineering
- An emerging role focused on engineering privacy requirements into systems using increasingly sophisticated mathematical tools.
- Privacy fundamentalists
- People with a strong desire to protect their privacy (one of Westin's three categories).
- Privacy harms
- Harms including loss of self-determination (autonomy, exclusion, loss of liberty, physical harm), discrimination, loss of trust, and economic loss.
- Privacy impact assessment (PIA)
- An analysis of how PI is handled to ensure legal conformity, determine risks/effects, and evaluate protections to mitigate privacy risks.
- Privacy law
- The U.S. (and some other countries') term for laws protecting information about individuals, also called data privacy or information privacy law.
- Privacy log
- A description of documents at issue that lets a court differentiate among them without disclosing their contents.
- Privacy manager
- Mid-level manager responsible for developing, maintaining, and enforcing privacy policies and procedures.
- Privacy mission statement
- A concise statement of privacy's core function, aligned with the organization's overall objectives.
- Privacy notice
- Information a controller must provide to data subjects about how it processes their personal data.
- Privacy operational life cycle
- A continuous-improvement model with four stages - assess, protect, sustain, and respond - for refining the privacy program.
- Privacy policy
- High-level internal document implementing privacy goals and informing employees/contractors how PI must be handled.
- Privacy pragmatists
- People whose privacy concern varies with context and who will trade some privacy for benefits.
- Privacy program
- An organization's framework for establishing accountability and legal compliance in how personal data is handled.
- Privacy program framework
- The processes, templates, tools, and standards used to operationalize controls for handling and protecting PI.
- Privacy Protection Act (PPA)
- 1980 law protecting media work product and documentary materials from government search or seizure in criminal investigations, passed after Zurcher v. Stanford Daily.
- Privacy risk
- The likelihood that individuals will experience problems from data processing, and the impact of those problems if they occur.
- Privacy risk assessment
- Determining the level of privacy risk from two variables: privacy impact and the likelihood of harm given the controls.
- Privacy risk management
- A process that identifies and assesses risks to information assets and implements mitigation strategies.
- Privacy Rule
- The HIPAA rule (finalized December 2000, revised 2002 and 2013) governing the use and disclosure of PHI by covered entities.
- Privacy seal / trust mark
- A third-party certification (e.g., BBB, TrustArc) a company displays to show compliance with a self-regulatory program.
- Privacy torts
- Common-law claims: intrusion upon seclusion, appropriation of name or likeness, publicity given to private life, and false light.
- Privacy unconcerned
- People with low worries about privacy (one of Westin's three categories).
- Privacy-enhancing technologies (PETs)
- Technology-driven tools used to protect and control data access, including in cross-border flows.
- Private Right of Action
- The ability of an individual consumer to personally sue over a violation, rather than relying solely on a government regulator.
- Probabilistic tracking
- Cross-device linking based on inferences from sources like IP addresses, cookies, location, and behavioral data.
- Processing
- Almost anything done with personal information - collection, storage, use, disclosure, combination, erasure, destruction, and more.
- Processing threshold
- A threshold that triggers coverage based on the number of in-state consumers whose data is processed.
- Processor
- An entity that processes personal data on behalf of the controller, governed by the controller's instructions in a contract.
- Program
- Under the rule, an entity, unit, or staff (other than a general medical facility) that holds itself out as providing substance abuse diagnosis, treatment, or referral, and receives federal funding.
- Proportionality principle
- Madrid principle limiting processing to what is adequate, relevant, and not excessive for the purposes, with reasonable efforts to minimize.
- Protective order (FRCP 26(c))
- A court order limiting disclosure of confidential information in litigation, granted on a showing of good cause under a three-part test.
- Proxy server
- An intermediary server that provides a gateway to the web, can mask activity behind a firewall, logs interactions, filters malware, and caches content.
- Pseudonymization
- A technical safeguard that reduces identifiability of personal data, weighed when assessing breach severity.
- Pseudonymized data
- Data that has been deidentified but remains personal data because it can still be used to reidentify the person.
- Public key infrastructure (PKI)
- The policies, standards, people, and systems supporting public-key distribution and identity validation via certificates and a CA.
- Public records
- Information collected and maintained by a government entity and available to the public; public-records laws vary by jurisdiction.
- Publicity given to private life
- A tort for publicizing a private matter that would be highly offensive to a reasonable person and is not of legitimate public concern; requires relatively broad dissemination.
- Publicly available information
- Information lawfully made available by federal, state, or local governments; excluded by all five states.
- Purpose limitation
- Personal data must be collected for specified, explicit, and legitimate purposes and not further processed in incompatible ways.
- Purpose/processing limitation
- An obligation to collect/process personal data only for a specific purpose, often described as necessary and proportionate; not imposed by Utah.
- QSO
- Qualified service organization; an entity that may receive information without consent for information it needs to provide services to the program.
- Qualified privilege
- A common-law protection allowing former employers to report their experience with and impressions of an employee, providing a defense against defamation suits when made in good faith.
- Qualified protective order (QPO)
- A HIPAA order, used in state courts outside the Federal Rules, that bars using PHI outside the litigation and requires its return or destruction at the end.
- Quasi-identifier
- Data, such as date of birth, that can be combined with external knowledge to link data to an individual.
- Random testing
- Substance testing without individualized suspicion; acceptable mainly in narrowly defined jobs in highly regulated industries or where critical to public safety or national security.
- Reasonable accommodation
- An adjustment an employer must provide to a qualified individual with a disability unless it would cause undue hardship.
- Reasonable expectation of privacy
- The standard under which government video surveillance is not generally permitted, such as in a bathroom.
- Reasonable expectation of privacy test
- From Katz: a person must show an actual (subjective) expectation of privacy that society is prepared to recognize as reasonable.
- Reasonable suspicion testing
- Substance testing allowed as a condition of continued employment when specific facts and rational inferences (appearance, behavior, speech, odors) suggest drug or alcohol use.
- Record of processing activities (RoPA)
- GDPR-required documentation of processing purposes, recipients of PI, retention periods, and safeguards; often used to start a top-down data map.
- Red Flag Program Clarification Act of 2010
- Law narrowing the definition of 'creditor' under the Red Flags Rule to exclude entities that extend credit only for expenses incidental to a service.
- Red Flags Rule
- FACTA rule requiring financial institutions and creditors to develop written programs to detect, prevent and mitigate identity theft.
- Redaction
- Identifying and removing or blocking information from documents produced in discovery or filed as evidence.
- Regulation E
- The rule implementing the EFTA, with rulemaking transferred to the CFPB in 2011 under Dodd-Frank.
- Remote access trojan (RAT)
- Malware that can turn on a device's webcam or microphone without the user's knowledge, even disabling the in-use indicator light.
- Required specification
- A Security Rule implementation spec that must be adopted as written.
- Restitution
- Recouping money losses suffered by consumers.
- Restriction of processing
- The marking of stored personal data with the aim of limiting its processing in the future.
- Retention policy
- A policy limiting how long PI is stored; shorter retention reduces breach risk.
- Right against automated decision-making
- The right to opt out of automated processing that produces decisions or profiling about the consumer; provided by all states except Utah.
- Right to access
- The right of an individual to obtain the PI an organization holds about them (e.g., credit reports under FCRA, medical records under HIPAA).
- Right to appeal
- The right to ask a business to reconsider a denied request; provided by Colorado, Connecticut, and Virginia, but not explicitly by California or Utah.
- Right to correction
- The right to correct inaccuracies in personal information; provided by California, Colorado, Connecticut, and Virginia, but not Utah.
- Right to data portability
- The right to receive personal data the subject provided in a structured, machine-readable format and to port it to oneself or another controller.
- Right to delete
- The right to have a business delete personal information, subject to exceptions; provided by all five states with differing scope.
- Right to erasure
- Also called the right to be forgotten; the right to have personal data deleted in defined circumstances unless an exemption applies.
- Right to Financial Privacy Act (RFPA)
- 1978 law requiring customer authorization, a subpoena/summons, a warrant, or a formal written request before a federal agency may access individuals' or small partnerships' financial records.
- Right to nondiscrimination
- The right not to be discriminated against (e.g., denied goods, charged different prices, given degraded quality) for exercising privacy rights; provided by all five states.
- Right to object
- The right to require a controller to stop processing personal data; absolute for direct marketing, qualified otherwise.
- Right to rectification
- The right to have inaccurate personal data corrected and incomplete data completed.
- Risk assessment
- A formal privacy/cybersecurity assessment required for processing that presents a heightened risk of harm; required by all but Utah.
- Risk-based pricing
- Offering different interest rates or loan terms to borrowers based on their creditworthiness.
- Risk-Based Pricing Rule
- FCRA rule requiring those offering credit to notify customers receiving less favorable terms because of their credit report.
- Risk-of-harm analysis
- An assessment of whether an incident is reasonably likely to cause harm (such as identity theft or fraud); many states excuse notification when harm is unlikely.
- Robocall
- A prerecorded-voice telephone call; under the 2012 FCC rules, robocalls to residential lines require prior express written consent.
- Robotext
- A text message sent to a wireless device without human intervention; subject to the same TCPA consumer protections as voice calls and requiring express consent.
- Role-based access controls
- Controls that grant access by role (e.g. a doctor vs the cafeteria), implementing least privilege; required by the HIPAA Security Rule.
- Ryan Haight Act
- The Online Pharmacy Consumer Protection Act includes an in-person medical evaluation requirement for many online controlled-substance prescriptions. Temporary federal telemedicine exceptions changed how it applied during the pandemic.
- Safe Harbor
- An FTC-approved self-regulatory program that lets member operators be assessed against the program's guidelines; the 2025 Rule strengthens transparency obligations for these programs.
- Safe harbor deidentification
- Removing at least 18 listed data elements (name, phone, address, etc.) to deidentify data under the Privacy Rule.
- Safe harbor method
- A HIPAA deidentification method requiring removal of 18 specific types of potentially identifying information (e.g. ZIP codes no more specific than the first three digits).
- Safeguards Rule
- GLBA rule requiring financial institutions to develop and implement a comprehensive written information security program with administrative, technical and physical safeguards.
- Sale
- A regulated transfer of personal data; defined narrowly (monetary only) in Utah and Virginia, and broadly (any exchange for value) in California, Colorado, and Connecticut.
- Salt
- Added input to a hash (approximating an encryption key) that makes lookup-table attacks against the hash much more difficult.
- SaMD
- Software as a medical device; certain AI-based medtech that the FDA may regulate more heavily.
- Sarbanes-Oxley Act (SOX)
- 2002 law passed after governance scandals (Enron, WorldCom) that increased incentives for corporate leaders to scrutinize practices in areas they manage.
- Satisfactory assurances
- Under HIPAA, the showing - via an agreed-upon qualified protective order submitted to the court, or a request for one - that allows a covered entity to disclose PHI in response to a discovery request.
- SCA
- Stored Communications Act; prohibits unauthorized acquisition, alteration, or blocking of electronic communications in storage, with exceptions for the provider and an authorized user.
- Schrems I
- The 2015 CJEU decision striking down the U.S.-EU Safe Harbor program over U.S. surveillance concerns.
- Schrems II
- The 2020 CJEU decision striking down the EU-U.S. Privacy Shield over lack of redress and proportionality in U.S. surveillance.
- Scope of a law
- Defined by who is covered and what information or uses are covered - the first two of the six key questions.
- Seal programs
- A form of self-regulation requiring participants to follow codes and submit to monitoring, then display a privacy seal; FTC-recognized COPPA seals include CARU, ESRB, iKeepSafe, kidSAFE, PRIVO, and TrustArc.
- Search warrant
- A Fourth Amendment order requiring probable cause that a crime has been, is, or will be committed.
- Section 13(b)
- FTC Act provision historically used to seek equitable money relief (restitution, disgorgement) without first issuing a cease-and-desist order.
- Section 19
- FTC Act provision allowing courts to grant relief once the FTC has issued a final cease-and-desist order.
- Section 215
- A USA PATRIOT Act provision used to collect bulk call detail records; bulk collection was ended by the USA FREEDOM Act and the provision expired in 2020.
- Section 230
- CDA provision stating that no provider or user of an interactive computer service shall be treated as the publisher or speaker of information provided by another information content provider; immunizes online platforms from liability for user-generated content and was enacted to encourage internet growth.
- Section 230(c)(2) (Good Samaritan)
- Provision giving platforms protection for the good-faith removal or restriction of objectionable third-party content.
- Section 5 of the FTC Act
- The provision letting the FTC pursue unfair and deceptive trade practices; the primary federal statute for medtech companies not covered by HIPAA.
- Section 5(l)
- FTC Act provision for administrative enforcement: the FTC issues a complaint, finds violations, and issues a cease-and-desist order, pursuing civil penalties for later breaches.
- Section 702
- A provision of the FISA Amendments Act of 2008 authorizing collection of communications of targeted non-U.S. persons reasonably believed to be located outside the U.S. for foreign intelligence purposes.
- Sectoral approach
- The U.S. model of regulating privacy through laws targeting specific industries or data types (e.g., HIPAA for health, GLBA for finance).
- Sectoral model
- A framework, used in the U.S., that protects personal information through laws addressing particular industry sectors rather than the whole economy.
- Sectoral regulation
- The U.S. approach of regulating privacy by industry sector (medical, financial, education) rather than through one comprehensive law.
- Security breach
- Unauthorized access to or acquisition of computerized data containing personal information that compromises its confidentiality, security, or integrity and is not protected by encryption or similar means.
- Security by default
- Configuring systems securely from initial use, such as requiring strong passwords on new hardware/software.
- Security Rule
- The HIPAA rule (finalized 2003, modified 2013) setting minimum security requirements for ePHI.
- Sedona Conference
- A leading source of standards and best practices for managing e-discovery compliance through data retention policies.
- Self-regulation
- Industry-led approaches to privacy that can cover rule-making, enforcement, and adjudication, sometimes with and sometimes without government involvement.
- Self-regulatory model
- An approach where companies, industries, or independent bodies create codes of practice, often without a generally applicable data protection law; e.g., PCI DSS.
- Sender
- Anyone who initiates a commercial email and whose product or service is advertised; the 2008 rule lets the entity in the 'from' line be treated as the single sender if other provisions are met.
- Sensitive data
- Categories such as medical, financial, or children's data that businesses are expected to protect to a higher bar.
- Sensitive personal data
- A special category of personal data (e.g., race, health, biometrics) that receives additional protection and generally requires explicit consent.
- Sensitive personal information
- A heightened category of personal data (e.g., health, race, religion, genetic/biometric data) that receives stronger protection under state comprehensive laws.
- Separation of powers
- The constitutional design dividing government into three branches so each checks and balances the others.
- Server
- The computer process that responds to client requests, such as serving a news story or processing an order.
- Service provider
- GLBA term analogous to a processor for handling financial information on an institution's behalf.
- Sharing
- California's separately defined activity of transferring personal information to a third party for cross-context behavioral advertising, whether or not for consideration.
- Smishing
- Phishing carried out via SMS text message.
- SMS
- Short Message Service using the Short Message Peer to Peer Protocol; limited to 160 characters and able to operate over cell service without the internet.
- SMTP
- Simple Mail Transfer Protocol, the most common protocol for sending email.
- SOC 2
- Set of controls defined by the AICPA; a vendor's compliance certification can evidence its security controls.
- Software as a service (SaaS)
- Delivery of vendor-managed applications over the internet, often run directly in a browser with no client-side installation.
- SOPIPA
- California's Student Online Personal Information Protection Act, the first U.S. law to prohibit using student data for noneducational targeted advertising.
- Sources of law
- Federal and state constitutions, legislation, case law, contract law, tort law, agency regulations, and consent decrees.
- Spear phishing
- A phishing attack tailored to a specific individual, such as a message appearing to come from the user's boss.
- Special categories of data
- Under Convention 108, sensitive data such as racial origin, political opinions, religious beliefs, health, sex life, or criminal convictions that cannot be automatically processed absent appropriate safeguards.
- Spyware
- Malicious software covertly installed on a device that monitors activity and sends sensitive personal information to an attacker.
- Standard contractual clauses (SCCs)
- Contractual commitments to comply with EU law and submit to DPA supervision; the most common legal basis for transfers.
- Stare decisis
- Latin for 'to let the decision stand' - the practice of following precedent in deciding new cases.
- State action
- The requirement that government be involved for constitutional protections to apply; private-sector employment generally lacks state action.
- State attorney general
- A state's chief legal advisor and law enforcement officer, who brings privacy enforcement actions often under unfair-and-deceptive-practices laws.
- State attorneys general
- Elected constitutional officers who are the primary enforcers of state-level privacy protections and may join certain federal enforcement actions.
- Stateless
- A property of HTTP/HTTPS meaning the protocols are not designed to remember past interactions with a particular user.
- Static IP address
- An IP address an ISP dedicates to a specific user or business so it does not change.
- Statutory damages
- A set amount fixed by statute (in California, $100 to $750 per incident) that consumers can recover without proving actual loss.
- Storage limitation
- Personal data must be kept no longer than necessary for the purposes of processing.
- Stored Communications Act (SCA)
- Enacted as part of ECPA in 1986; prohibits unauthorized access to electronic communications in electronic storage, with exceptions for the service provider and the user.
- Strict liability tort
- A wrong established when an action causes damage regardless of the defendant's degree of carelessness, e.g., product liability.
- STRIDE framework
- A mnemonic for modeling threats: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, and Elevation of privilege.
- Strong identifier
- Clearly identifying information such as a Social Security or passport number.
- Student
- Under FERPA, any individual who is or has been in attendance at an educational agency or institution, with attendance including in-person and internet participation.
- Student Privacy Pledge
- A self-regulatory pledge created in 2014 by the Future of Privacy Forum and the Software and Information Industry Association, with over 400 signatories by 2020.
- Subject access request
- A data subject's exercise of the right of access to obtain confirmation, a copy of their data, and related processing information.
- Subpoena
- An instruction to produce a witness or records, enforceable through contempt of court.
- Subprocessor
- A party engaged by a processor (like a subcontractor) to whom GDPR requirements flow downstream.
- Subscription Account Number (SAN)
- A unique, non-transferable account number a seller obtains (upon fee payment) to access the DNC Registry; telemarketers may use a seller-client's SAN at no extra cost, limited to the area codes paid for.
- Substitute notice
- An alternative method - such as conspicuous website posting or statewide media - permitted for large breaches where individual notice would impose an undue financial burden.
- Suppression
- Removing identifying values from a record (e.g. dropping customer names for statistical analysis).
- Surveillance capitalism
- Term coined by Shoshana Zuboff for tech-company practices of collecting data about individuals and using that knowledge to influence their behavior.
- Suspicious Activity Report
- A report a financial institution must file when it detects potentially suspicious transactions; failure to file timely reports is a BSA violation.
- Suspicious activity report (SAR)
- A report financial institutions must file with FinCEN in defined situations to alert the government to potentially suspicious transactions.
- Symmetric key cryptography
- Private-key cryptography using the same short key to encrypt and decrypt; fast, but Alice must securely share the key with Bob.
- TAKE IT DOWN Act (2025)
- Law criminalizing distribution of nonconsensual intimate imagery (revenge porn), including AI-generated/deepfake images; it does not directly amend Section 230 but creates a new exception for illegal material not protected by Section 230, requiring platforms to remove such content on notice.
- TCPA
- The Telephone Consumer Protection Act of 1991, enforced by the FCC, restricting unsolicited advertising by telephone, fax, robocalls and (by FCC interpretation) text messages.
- Telecommunications Act of 1996
- Major legislation reshaping telecom markets; Section 222 governs the privacy of customer information obtained by telecommunications carriers.
- Telemarketing
- A plan, program or campaign to induce the purchase of goods or services or a charitable contribution, involving more than one interstate telephone call.
- Telemedicine
- Medical care delivered when doctor and patient are in different physical locations, which expanded dramatically during the COVID-19 pandemic.
- Tenth Amendment
- Reserves to the states (or the people) all powers not delegated to the federal government nor prohibited to the states.
- Terms of use
- The longer policy (also called terms of service or terms and conditions) a user agrees to when creating an account, often granting broader data-collection rights than cookie consent.
- Territorial privacy
- Privacy concerned with limits on intruding into an individual's environment - home, workplace, or public space - via monitoring such as video surveillance.
- The right to be let alone
- Warren and Brandeis's 1890 definition of privacy, set out in 'The Right to Privacy' in the Harvard Law Review.
- Thick client
- A client capable of performing many data-processing actions itself even when offline.
- Thin client
- A client that relies predominantly on remote processing, such as a device running only a web browser with cloud-based tools.
- Third-party doctrine
- The rule that information voluntarily given to a third party (e.g. bank or phone company) loses Fourth Amendment protection, so a warrant is not required to obtain it.
- Threat modeling
- Identifying the most salient security risks for an organization, using tools like MITRE ATT&CK and STRIDE.
- Title VII
- Civil Rights Act of 1964 provision barring employment discrimination based on race, color, religion, sex, and national origin; EEOC has held it covers sexual orientation and gender identity.
- Top-level domain
- The final segment of a domain such as .com (commercial), .org (organization), .gov (government), .edu (educational), or a two-letter country code; there are over 1,500.
- Tort
- A civil wrong recognized by law as grounds for a lawsuit, causing injury that supports a claim by the injured party.
- TPO
- Treatment, payment, and health care operations - the core HIPAA-permitted purposes now reachable by a single Part 2 consent.
- Tracking pixel
- A small image with a user-unique link or filename loaded when an email is opened, indicating the open (and clicks); disabled by reading in plain text.
- Tracking Technologies
- Cookies, pixels, and web or app trackers that collect user data and may send it to third-party vendors.
- Transactional or relationship message
- A message whose primary purpose is to facilitate a transaction, provide warranty/safety info, give info about an ongoing relationship, address employment/benefits, or deliver goods/services already owed - not subject to the commercial-email rules.
- Transmission control protocol (TCP)
- The protocol that establishes a reliable connection between source and destination and breaks data into packets while preserving integrity.
- Transport layer security (TLS)
- A protocol that secures the connection between user and server so no third party can eavesdrop or corrupt the message; successor to SSL.
- TransUnion v. Ramirez
- A 2021 Supreme Court decision requiring a plaintiff to show actual harm, not a mere risk of harm, to have standing to sue.
- Trap-and-trace device
- Traditionally a device recording the numbers calling into a particular number.
- Treatment records
- Health records created or maintained by a health professional for treating a student and not disclosed except to those providing treatment; excluded from the definition of education record under conditions.
- Triangulation
- Determining a phone's position geometrically from its signal timing and strength relative to several cell towers whose locations are known.
- TSR
- The Telemarketing Sales Rule, first issued by the FTC in 1995 to implement the Telemarketing and Consumer Fraud and Abuse Prevention Act, amended in 2003, 2008, 2010 and 2015.
- U.S. West, Inc. v. FCC
- A 1999 Tenth Circuit case striking down the FCC's 1998 opt-in CPNI rule as a violation of carriers' First Amendment speech rights, shifting carriers' own use to opt-out.
- UCPA
- The Utah Consumer Privacy Act, viewed as the narrowest of the five laws.
- UDAP statutes
- Unfair and Deceptive Acts and Practices statutes that all 50 states have enacted, giving consumer protections similar to the FTC Act.
- Unconscionable practices
- A contract-law concept for harsh seller practices that some state UDAP statutes also reach.
- Unfair practice
- A practice that causes or is likely to cause substantial, non-speculative consumer injury that is not reasonably avoidable and not outweighed by countervailing benefits to consumers or competition.
- Uniform resource identifier (URI)
- A larger class of identifiers formatted like URLs but which may not include information to locate the resource on a network.
- Uniform resource locator (URL)
- The address of content on a web server, containing a protocol prefix, often 'www', a domain name, and a top-level domain such as .com, .org, .gov, .edu, or a country code.
- Uniform resource name (URN)
- A related identifier term that may appear interchangeably with URL/URI in some documents.
- Universal Declaration of Human Rights (1948)
- UN declaration stating no one shall be subjected to arbitrary interference with privacy, family, home, or correspondence.
- Universal opt-out mechanism
- A browser or device signal that lets a consumer opt out of the sale, sharing, or targeted advertising of their personal information across all sites at once, without making a separate request to each site.
- USA FREEDOM Act
- 2015 law that, among other provisions, ended bulk collection under the Section 215 program and required specific selectors.
- User
- An entity such as a lender, insurer or employer that uses a consumer report; must have and certify a permissible purpose and provide adverse-action notice.
- User-generated content (UGC)
- Text, photos, or videos a user posts to a website, providing granular insight into interests and offline activities.
- Vail Letter
- An FTC advisory opinion holding that an outside firm investigating employee misconduct was a CRA and its report an investigative consumer report, triggering FCRA notice/consent that defeated undercover investigations.
- VCDPA
- The Virginia Consumer Data Protection Act, the second state comprehensive law and initially seen as the pro-business model.
- Verifiable Parental Consent
- Express, opt-in consent from a parent that an operator must obtain before collecting, using, or disclosing a child's personal information; under the 2025 Rule it is specifically required to use children's data for targeted advertising.
- Videotape service provider
- Anyone engaged in the rental, sale or delivery of prerecorded videocassettes or similar audiovisual materials, plus those receiving such personal information in the ordinary course of business or for marketing.
- Virtual private network (VPN)
- A tool similar to a proxy that encrypts information from the user to the organization's proxy, potentially masking both content and destination from the ISP.
- Vishing
- Use of a fraudulent voice message or phone call to trick an individual into disclosing information or taking action.
- VPPA
- The Video Privacy Protection Act of 1988, restricting disclosure of consumers' video viewing/rental records by videotape service providers, enacted after Robert Bork's rental records were disclosed.
- Warby Parker
- The eyewear company fined $1.5 million by HHS OCR in February 2025 for HIPAA Security Rule violations.
- Weak identifier
- An identifier that must be combined with other information to determine identity.
- Wearable
- An electronic device placed on the body that may collect medical information in real time, such as a smartwatch.
- Web server
- A computer connected to the internet that hosts and shares web content accessed by browsers.
- Web server log
- An automatically created record of requests that can include the visitor's IP address, date/time, requested URL, referring URL, and browser/OS.
- West Virginia v. EPA
- 2022 Supreme Court case applying the 'major questions doctrine,' potentially narrowing the scope of rules the FTC can enact.
- Whaling
- Spear phishing targeted at C-suite executives, celebrities, and politicians.
- Wireless Domain Registry
- An FCC-maintained, periodically updated list of wireless domain names; senders must check it and ensure proper authorization before messaging those domains.
- Wiretap Act
- Federal statute prohibiting interception of wire, oral, and electronic communications unless an exception applies; provides criminal penalties and a private right of action.
- Wiretap Act (Title III)
- Derives from a 1968 anticrime law; strictly prohibits interception of wire (aural) and oral communications absent an exception.
- Zero trust
- An approach where no actor, system, network, or service inside or outside the perimeter is trusted; everything must be verified and traffic encrypted and authenticated.
Sources
Sources and study method
This independent study material uses the current published CIPP/US outline, active recall, spaced retrieval and scenario practice. Read the full method. Current sources. Current CIPP/US certification page, IAPP certification FAQs.