Skip to content
HumenhukCIPP/US Study Guide
Study library Study guide Free diagnostic Practice questions Full question bank Account
Home / CIPP/US glossary

CIPP/US glossary

Reviewed by Victor Humenhuk. Published 31 August 2026. Reviewed 31 August 2026.

Review the recurring terms in this CIPP/US guide. Use each definition as a prompt, then explain the term without looking.

This glossary supports recall. The linked lessons provide the legal context, exceptions and scenarios that a short definition cannot hold.

21st Century Cures Act
A 2016 law promoting medical research, mental health reform, and EHI interoperability, with privacy-specific provisions.
30-day cure period
California provision allowing a business to cure an alleged violation within 30 days; a successful cure bars the consumer from pursuing statutory damages.
42 CFR Part 2
The Confidentiality of Substance Use Disorder Patient Records Rule protecting records of patients seeking alcohol or substance use treatment at federally assisted programs.
AB 1950
California's data security law (Civil Code 1798.81.5), the country's first state security law, requiring reasonable security procedures and practices.
Abandoned call
An outbound call where, after a person completes their greeting, the telemarketer fails to connect a live sales rep within two seconds.
Abandonment safe harbor
Protection from enforcement if abandonment stays at or below 3% per day per campaign, with required ring time, recorded message and records.
Abusive act or practice
A CFPB enforcement standard covering practices that materially interfere with a consumer's understanding of a product, or take unreasonable advantage of a consumer's lack of understanding, inability to protect their interests, or reasonable reliance on the provider.
Acceptable use policy
An employer policy on permitted use of IT equipment that, with monitoring notices, helps establish employee knowledge and reasonable expectations and can be required by state law.
Acceptance
The assent by the offeree, complying with the offer's terms and communicated to the offeror.
Access
The ability to view personal information held by an organization, sometimes with rights to update or correct it.
Accountability
The principle requiring the controller to be responsible for, and able to demonstrate, compliance with the other six principles.
Accountability Principle
OECD principle that a data controller should be accountable for complying with measures giving effect to the other principles.
Actual damages
Damages tied to the losses actually incurred by the consumer as a result of the breach.
ADA
Americans with Disabilities Act of 1990; bars discrimination against qualified individuals with disabilities and restricts medical examinations and inquiries by employers of 15 or more.
Addressable specification
A Security Rule implementation spec the entity must assess for appropriateness and, if not adopted, document why and adopt an alternative if reasonable.
ADEA
Age Discrimination in Employment Act of 1967; bars discrimination against individuals over 40.
Adequacy decision
An EU determination that a country's protections are essentially equivalent to the GDPR, allowing data to flow freely to it.
Adequacy determination
A government decision that another country's data protections are adequate, enabling freer data flows (a pre-authorization safeguard).
Administrative enforcement action
Enforcement carried out by an agency under the statutes that empower it, governed federally by the APA.
Adversarial mindset
The cybersecurity assumption that attackers anywhere may launch a devastating attack at any moment - we live in a 'bad neighborhood.'
Adverse action
Any business, credit or employment action with a negative impact on a consumer, such as denying or cancelling credit/insurance or denying employment or promotion.
Aerospatiale factors
Factors a U.S. court uses to reconcile conflicts between U.S. discovery and foreign law, including importance, specificity, U.S. origin of data, alternative means, and competing national interests.
Age-Appropriate Design Code Act
A 2022 California law, modeled on the UK's, imposing obligations on online services likely accessed by children under 18, including high-privacy default settings.
Agency opinion
Formal agency guidance that does not necessarily carry the weight of law but helps parties interpret rules and regulations.
Aggregate data
Information about a group of consumers with individual identities removed so it is not reasonably linkable to a consumer; explicitly excluded by California, Utah, and Virginia.
Algorithmic disgorgement
A remedy requiring a company to delete algorithms or models built using improperly obtained data, used in the Everalbum settlement.
ALJ
An administrative law judge who presides over court-like hearings inside an agency's adjudication process.
AMG Capital Management v. FTC
2021 Supreme Court case holding the FTC may not obtain monetary relief or damages under Section 13(b).
AML Act of 2020
Anti-Money Laundering Act of 2020, the most comprehensive AML changes since the USA PATRIOT Act, expanding the BSA to explicitly include virtual currencies.
Anonymization
Putting data in a form that does not identify individuals and where identification by combination with other data is not likely (UK ICO definition).
Anonymized data
Data processed irreversibly so it can no longer identify a person; only then is it outside the definition of personal data.
APA
The Administrative Procedure Act, which sets the basic federal rules for agency enforcement and adjudication.
APEC
Asia-Pacific Economic Cooperation, a multinational organization of 21 Pacific Coast members that operates under nonbinding agreement, unlike the EU.
APEC Cross-Border Privacy Rules
The Asia-Pacific framework allowing trade among participating economies while providing privacy assurances.
APEC Privacy Framework
A 2004 (updated 2015) framework of nine information privacy principles that generally mirror the OECD Guidelines but are more explicit about exceptions.
API (Cures Act)
Application programming interface that certified health IT developers must publish so patients can access, exchange, and use their EHI without special effort.
ARPANET
The 1960s U.S. military computer network that was the precursor of the modern internet.
As expeditiously as possible and without unreasonable delay
The most common timing phrase for breach notice, allowing a reasonable investigation while restoring system integrity.
Asymmetric cryptography
Public-key cryptography using a public/private key pair per user; scalable and the basis for digital certificates.
Attorney-client privilege
Privilege under which an attorney cannot be compelled to testify or produce records about a client within the scope of representation, subject to exceptions like consent or preventing imminent harm.
Autodialer (ATDS)
An automatic telephone dialing system; in 2021 the Supreme Court limited this to equipment with capacity to use a random or sequential number generator to store or produce numbers.
Automated decision-making
Fully automated processing, including profiling, that has a legal or similarly significant effect, generally prohibited under the GDPR.
Automated Employment Decision Tool (AEDT)
Software or AI (using machine learning, analytics, or statistical models) that scores, classifies, or recommends hiring or promotion decisions, substantially assisting or replacing human judgment.
Automated Employment Decision Tools (AEDTs)
AI tools used by employers for hiring or promotion that, under NYC Local Law 144, must undergo a bias audit with published results and candidate notice.
Availability
Knowledge that data is accessible, as needed, by those authorized to use it.
Back end
Devices and software operating separately from the web server, such as databases, that are not essential for operating the server.
Ban the Box laws
Laws that remove the checkbox on job applications asking whether an applicant has a criminal history, delaying criminal-history inquiries.
Bank Secrecy Act (BSA)
The anti-money-laundering statute requiring financial institutions to maintain an adequate AML program and file timely Suspicious Activity Reports.
Bias audit
An assessment of an AEDT for disparate impact that NYC Local Law 144 requires before the tool is used and whose results must be published.
Binding corporate rules (BCRs)
Rules allowing a multinational to transfer data among affiliated entities after certification of its practices by a DPA.
BIPA
The Illinois Biometric Information Privacy Act of 2008, the first U.S. biometric privacy law, with a private right of action and per-violation damages.
BitLicense
NYDFS license required for individuals or businesses that receive, transmit, control, issue, exchange or maintain custody of virtual currencies.
Blacklisting
Blocking access to specified websites or internet activity considered inappropriate.
Bodily privacy
Privacy focused on a person's physical being and invasions such as genetic testing, drug testing, or body cavity searches.
Bona fide occupational qualification
A characteristic reasonably necessary to the normal operation of a business that can justify an otherwise-prohibited inquiry or requirement.
Breach (HITECH)
An unauthorized acquisition, access, use, or disclosure of unsecured PHI, presumed to have occurred unless a risk assessment shows low probability of compromise.
Breach of contract
When one party fails to meet its contractual obligations, allowing the injured party to sue for damages or enforcement.
Breach of system security
Unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information.
Broadened 'breach' definition
Under the 2023 rules, a breach includes the inadvertent access, use, or disclosure of customer information, not only intentional acquisition.
Buckley Amendment
Another name for FERPA, referring to Senator James Buckley who supported its enactment.
Budapest Convention
The 2004 Council of Europe Convention on Cybercrime, the first treaty focused on cybercrime; its Second Additional Protocol (signed 2022) addresses cross-border access to evidence.
Bureau of Consumer Protection (BCP)
The FTC bureau whose Enforcement Division monitors and litigates consent-decree violations, working with the DOJ.
Business / Controller
The entity that conducts business in a state and is subject to the law; California uses business, the other four states use controller.
Business associate
Any person or organization, other than a covered entity's workforce member, that performs services for or on behalf of a covered entity involving the use or disclosure of PHI.
Business associate agreement (BAA)
A written contract requiring a business associate to meet the privacy and security obligations applicable to the covered entity.
BYOD
Bring your own device; employees using personal computing devices for work, raising security and privacy issues.
Cable Communications Policy Act of 1984
Statute regulating notice, collection, disclosure and retention of personal information by cable television providers, with a private right of action and damages.
Caching
When a server saves a copy of content to reduce the need to download it again from the web server.
CALEA
The Communications Assistance to Law Enforcement Act of 1994, requiring telecommunications carriers to design products that can carry out lawful interception orders; enforced via FCC rulemaking.
CalGINA
California's 2011 genetic nondiscrimination act extending protections to emergency services, mortgage lending, housing, education, and other state-funded programs.
California Age-Appropriate Design Code Act
A 2022 California law - the first U.S. age-appropriate design law - requiring online platforms to consider the best interest of child users and set privacy-protective defaults.
California Constitution privacy right
An explicit constitutional right to privacy added by California voters via ballot measure in November 1974 (Article 1, Section 1).
California Delete Act
A 2023 California law requiring data brokers to register with the CPPA and enabling a single centralized deletion request across all registered brokers.
California Privacy Protection Agency (CPPA)
The California agency that administers and enforces the Delete Act's data broker registration and deletion mechanism.
California Privacy Rights Act (CPRA)
A California law effective January 2023 that requires notice and an opt-out right for third-party cookies.
California SB 1386
The first U.S. security breach notification law, covering entities doing business in California that own or license computerized personal information.
CalOPPA
The California Online Privacy Protection Act (2003), the first U.S. law requiring commercial websites/apps to post a privacy notice if they collect PII from Californians; 2013 amendment added Do Not Track disclosure requirements.
CAN-SPAM
The Controlling the Assault of Non-Solicited Pornography and Marketing Act, restricting unsolicited commercial email; enforced by the FTC, FCC, and state AGs.
CAN-SPAM Act
The Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003, governing commercial email directed to or originating from the U.S.
Carpenter v. United States
U.S. Supreme Court decision holding that police need a warrant to conduct long-term tracking of an individual's movements.
Case law
The final decisions made by judges in court cases, used as precedent for future similar issues.
CCPA
California Consumer Privacy Act; its private right of action created statutory damages for breaches caused by failure to maintain reasonable security.
Certificate authority (CA)
A trusted third party that validates identity and issues a digitally signed certificate associating a person with a public key.
Certificate of confidentiality
An NIH-issued protection ensuring research material cannot be used in legal or administrative proceedings without the participant's consent.
CFIPA
California Financial Information Privacy Act (SB-1), which expands GLBA protections and requires written opt-in consent to share personal information with nonaffiliated third parties.
CFPB
Consumer Financial Protection Bureau; also regulates unfair and deceptive practices and enforces laws including the FCRA.
Chief privacy officer (CPO)
Leader charged with developing and implementing policies for data processing and proper handling of personal information.
Children's Advertising Review Unit (CARU)
A self-regulatory program addressing advertising and privacy practices directed at children.
Children's Internet Protection Act (CIPA)
A U.S. law requiring public schools and libraries to install filters to prevent children from viewing inappropriate online content.
Choice
The ability to specify whether personal information is collected and how it is used or disclosed; may be express or implied.
Choice and consent
FIP requiring organizations to describe available choices and obtain implicit or explicit consent for handling personal information.
CIA triad
The traditional model of computer security: confidentiality, integrity, and availability.
Ciphertext
Scrambled, unreadable data produced by encrypting plaintext.
CISA
The Cybersecurity Information Sharing Act of 2015, permitting voluntary sharing of cyberthreat indicators and defensive measures with the government and others, with defined protections.
City of Ontario v. Quon
Supreme Court case allowing a (public) employer to review an employee's text messages to determine whether its electronic-usage policy was violated; the employer provided the pager.
Civil litigation
A court action where a plaintiff sues a defendant to redress a wrong, typically seeking money damages or an injunction.
CJEU
The Court of Justice of the European Union, whose Schrems I and Schrems II decisions scrutinized surveillance practices in countries receiving EU data.
Client
Hardware or software that accesses a service from a server by sending a request; a thick client processes data itself, a thin client relies on remote processing.
CLOUD Act
The 2018 Clarifying Lawful Overseas Use of Data Act; Part 1 lets U.S. orders reach data wherever stored, Part 2 lets qualifying foreign governments access content held by U.S. providers via executive agreements.
Cloud computing
On-demand availability of computing resources, offering cost savings, scalability, and remote access compared to on-premises systems.
CMIA
California's Confidentiality of Medical Information Act, which extends health privacy duties to software, hardware, and online service providers beyond HIPAA's reach.
Co-regulatory model
An approach emphasizing industry-developed enforceable codes against a backdrop of government legal requirements; e.g., COPPA codes approved by the FTC.
COBRA
Consolidated Omnibus Budget Reconciliation Act; requires qualified health plans to provide continuous coverage to certain beneficiaries after termination.
Collection Limitation Principle
OECD principle limiting collection of personal data, obtained by lawful and fair means and, where appropriate, with consent.
Collective bargaining agreement
A union-negotiated contract that often protects employee privacy, e.g., limiting drug testing and workplace monitoring; the most important contracts for employee privacy.
Colorado AI Act
A Colorado law addressing algorithmic discrimination, enforced by the attorney general only.
Commercial surveillance
Defined in the FTC's 2022 proposed rules as the collection, aggregation, analysis, retention, transfer, or monetization of commercial data and its direct derivatives.
Common carriers
Transportation and communications providers, which are outside the FTC's Section 5 jurisdiction.
Common law
Legal principles developed over time in judicial decisions, often from social customs, contrasting with statutory law.
Communications privacy
Privacy protecting the means of correspondence, including postal mail, telephone, email, and other communicative behavior.
Comprehensive model
A data protection approach where the government defines requirements across the whole economy (public and private sectors), usually overseen by a DPA.
Comprehensive privacy law
A law that protects all types of personal data across sectors, as opposed to a sector-by-sector approach.
Computer trespasser exception
PATRIOT Act Section 217 provision permitting (not requiring) a computer system owner/operator to authorize law enforcement interception of a trespasser's communications under defined conditions.
Conditional offer
A job offer made before a medical exam; after it is extended, an employer may require an exam if all entering employees in the job category are treated the same.
Confidentiality
Access to data is limited to authorized parties.
Consent
A freely given, specific, informed, and unambiguous indication of the data subject's wishes, given by statement or clear affirmative action.
Consent decree
A settlement in which the respondent does not admit fault but promises to change its practices and avoid further litigation; posted publicly by the FTC.
Consideration
The bargained-for exchange (money, property, or services); an agreement without consideration is not a contract.
Consumer
The individuals protected by a state comprehensive privacy law - defined as state residents, not limited to people buying products or services.
Consumer Health Data
Health data collected by mobile devices, apps, and wearables that falls outside HIPAA's coverage.
Consumer report
Under FCRA, written/oral/other communications bearing on a consumer's creditworthiness, character, reputation, personal characteristics, or mode of living.
Consumer reporting agency (CRA)
An organization that regularly assembles or evaluates consumer information to furnish consumer reports to third parties for a fee.
Controller
An entity that determines the purposes and means of processing personal data.
Convention 108
The 1981 Council of Europe Convention for the Protection of Individuals with Regard to Automatic Processing of Personal Data, requiring signatory states to adopt data protection provisions in domestic law.
Convention 108+
The 2018 update to Convention 108, bringing it in line with the EU's GDPR on proportionality, breach notice, and transborder flows.
COPPA
The Children's Online Privacy Protection Act, applying to operators of sites or services directed to children under 13, and to general-audience services with actual knowledge they collect personal information from under-13s.
Covered entity
Under HIPAA, an organization such as a health plan, clearinghouse, or provider conducting standard transactions, which is subject to the Privacy Rule.
Covered entity (breach law)
An entity subject to a state breach law, typically one that does business in the state and maintains computerized personal information.
CPA
The Colorado Privacy Act.
CPNI
Customer proprietary network information - subscription and service data, network and billing information, phone features, and call log data (time, date, destination, duration); name, phone number and address are NOT CPNI.
CPPA
The California Privacy Protection Agency, a dedicated privacy regulator created by the CPRA, seen as analogous to an EU data protection authority.
CPRA
California Privacy Rights Act; updated the CCPA, including its statutory-damages framework (see Chapter 6).
Credit monitoring requirement
A mandate in California, Delaware, and Massachusetts to provide affected individuals free credit monitoring for at least 12 months when SSNs or similar data are exposed.
Criminal prosecution
Government action for violations of criminal law that can lead to imprisonment and criminal fines; prosecuted federally by the DOJ.
Cross-Border Privacy Rules (CBPR)
APEC system for cross-border data protection, extended in 2022 into the Global CBPR Forum allowing non-APEC members to participate.
Cross-context behavioral advertising
Advertising targeted to a consumer based on personal information collected over time across different online contexts.
Cross-device behavioral advertising
Targeted advertising based on a consumer's information obtained across websites, services or applications; restricted under the California framework.
Cross-device tracking
The ability to link a single user to multiple devices such as phones, tablets, and laptops.
CTDPA
The Connecticut Data Privacy Act.
CUBI
Texas's biometric privacy law, enforced by the state attorney general with no private right of action.
Cure period
A set number of days an enforcer must give a business to fix a violation before sanction; present in some states, expired or absent in others.
Currency Transaction Report
BSA report (Form 4789) filed for currency transactions of $10,000 or more.
Customer (GLBA)
A consumer with an ongoing relationship with a financial institution; many GLBA notice requirements apply specifically to customers.
Cyber threat indicator
Information needed to describe or identify a malicious cybersecurity threat or vulnerability; the definition excludes sensitive personal and business information.
Cybersecurity Information Sharing Act (CISA)
A 2015 law that encourages the voluntary sharing of unclassified cyber threat information between private companies and the federal government, with liability protection for those who share.
Cybersecurity safe harbor law
A law (Connecticut, Iowa, Ohio, Utah) letting a company defeat a breach lawsuit if it had appropriate safeguards in place before the breach.
Cyberthreat indicator
Technical information about how networks have been attacked, which a company may share under CISA for a cybersecurity purpose.
DAA / AdChoices
The Digital Advertising Alliance's icon program letting consumers exercise choice over online behavioral advertising.
Dark Pattern
A deceptive interface design that manipulates users into actions they did not intend, such as confusing buttons that triggered unwanted Fortnite purchases.
Dark patterns
Design practices that trick or manipulate users into choices they would not otherwise make and that may cause harm.
Data breach (GDPR)
A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.
Data breach notification law
A state law requiring entities to disclose to affected individuals (and often regulators) when personal information is accessed by an unauthorized party.
Data breach readiness assessment
An assessment of the level of breach risk plus the likelihood and severity of a personal data breach.
Data Broker
A company that collects and sells personal data without the consumer's direct relationship or knowledge.
Data brokers
Businesses that obtain data from one or more sources, process and cleanse it, and license it for use by first parties; scrutinized by the FTC over privacy concerns.
Data classification
Categorizing data by sensitivity to set who may access it and the baseline protection required.
Data controller
An organization with authority to decide how and why personal information is processed; bears most obligations under privacy law.
Data destruction law
A state law requiring secure disposal of personal information at the end of the data life cycle so it is no longer readable or decipherable.
Data destruction laws
State laws (discussed in Chapter 7) that mandate requirements in the deletion stage of the data life cycle.
Data fiduciary duty
A novel proposed approach requiring companies that handle data to act in good faith on behalf of consumers.
Data flow mapping
Documenting the systems, applications, and processes that handle data - what, where, and why data is processed.
Data inventory
A documented accounting of the PI an organization collects, stores, uses, or discloses, including its location, flow, and sharing.
Data life cycle
The stages data moves through: creation, storage, sharing and usage, archival, and deletion.
Data lineage
Metadata added to a map identifying the original source of data, the most critical data, and how data sets are built and aggregated.
Data localization
Requirements that data be stored or processed within a country's borders - a growing global trend.
Data loss prevention (DLP)
A strategy and tools to ensure sensitive data is not accessed, misused, or lost by monitoring and controlling endpoint activities; can be highly privacy-invasive.
Data mapping
The process of identifying where personal data resides and how it flows, central to due diligence in mergers, acquisitions, and divestitures.
Data minimization
Processing must be adequate, relevant, and limited to what is necessary for the purpose.
Data portability
The ability of individuals to obtain and reuse their personal data across different services, the subject of a 2020 FTC workshop.
Data processor
An individual or organization that processes data on behalf of a controller; called a 'business associate' under the HIPAA Privacy Rule.
Data protection authority (DPA)
An independent national public authority that investigates and enforces data protection laws and gives interpretive guidance.
Data protection impact assessment (DPIA)
Assessment similar to a PIA, associated with the GDPR.
Data protection law
The European Union (and other countries') term for laws protecting personal information about individuals.
Data protection officer (DPO)
The primary internal point of contact on data protection for an EU-based business, who must have expertise and no conflicts of interest.
Data security law
A state law requiring companies to develop and maintain appropriate security measures to protect personal information, often under a reasonableness standard.
Data subject
The natural person whose personal data is being collected, stored, or processed.
Data subject access
FIP requiring organizations to give individuals access to their personal information for review and updates.
Data subject rights
The set of GDPR rights giving individuals control over their personal data, including access, rectification, erasure, restriction, portability, and objection.
Data-based exemption
An exemption where only a class of data is exempt (e.g., data already covered by a federal law), leaving the rest of the entity's data regulated.
Deceptive practice
A material statement or omission likely to mislead consumers acting reasonably under the circumstances - including failure to honor privacy-notice promises.
Deep packet inspection
Examination by a node of some or all of a packet's contents (beyond the routing header) for purposes such as malware detection, data-leak prevention, ad targeting, or censorship.
Defamation
A tort based on a false, reputation-harming statement, e.g., a false drug-test report or a factually incorrect employer reference.
Defense in depth
Layering obstacles so an initial intrusion still faces multiple barriers before harm occurs.
Deidentified
Data altered so it is no longer identifiable; it is far from simple to determine when data is truly deidentified.
Deidentified data
Data that cannot reasonably be associated or linked with a particular individual; excluded by all five states.
Deidentified information
Health information that does not identify an individual and offers no reasonable basis to do so.
Derogation
An EU term for an exception permitting a transfer where no adequacy decision or safeguard applies, interpreted narrowly.
Designated record set
A patient's medical and billing records and other records a covered entity uses to make decisions about individuals, to which the access right applies.
Deterministic tracking
Cross-device linking based on the user logging in, so the same login is observed across devices.
DHS
The U.S. Department of Homeland Security, which handles privacy issues such as E-Verify, TSA air-traveler records, and ICE immigration matters.
Differential privacy
A mathematical definition of privacy guaranteeing that anyone seeing a result will make essentially the same inference about an individual whether or not that person's data is in the input, defined via the noise needed for a set of queries.
Digital Advertising Alliance (DAA)
A nonprofit whose Self-Regulatory Principles for Online Behavioral Advertising emphasize transparency and consumer opt-out management, enforced via the Council of Better Business Bureaus and the Direct Marketing Association.
Digital signature
A string Alice creates with her private key; if Bob's application of her public key yields readable plaintext, the message is verified as unchanged.
Directory information
Information FERPA treats as not generally harmful if disclosed, such as name, address, email, phone, field of study, and honors, which a school may release unless the student opts out.
Discovery
Information disclosed to another party in a lawsuit before trial, governed by the rules of civil and criminal procedure.
Disgorgement
Requiring a company to repay profits earned from wrongful conduct.
Disposal Rule
FACTA rule requiring any entity using a consumer report for a business purpose to dispose of the information in a way that reasonably prevents unauthorized access and misuse.
DNC Safe Harbor
Protection from penalties for an erroneous call if the seller/telemarketer follows written procedures, trains staff, maintains an entity-specific list, uses registry data no older than 31 days, monitors compliance, and the call resulted from error.
Do Not Sell or Share My Personal Information link
California's per-site link through which a consumer exercises an opt-out on that one business's site, as distinct from a universal signal that applies across all sites.
Dobbs v. Jackson Women's Health Organization
2022 Supreme Court case that overturned Roe v. Wade, stated to be limited to abortion but raising concern about other penumbra-based privacy rights.
DOC
The U.S. Department of Commerce, which leads federal privacy policy and has administered EU-U.S. data-flow agreements.
Dodd-Frank Act
Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010, which created the Consumer Financial Protection Bureau (CFPB).
DOJ
The U.S. Department of Justice, the sole federal agency that brings criminal enforcement actions.
DOL
U.S. Department of Labor; administers federal labor laws including the FLSA, OSHA, and ERISA.
Double opt-in
Email practice where a subscriber indicates interest and then confirms via a follow-up email before receiving marketing.
DPA
A data protection authority - an independent public authority dedicated to data protection enforcement, the EU model the CPPA mirrors.
DPPA
The Driver's Privacy Protection Act, a federal law whose covered data is an example of a data-based exemption under state comprehensive laws.
Duty of loyalty
A proposed obligation in some U.S. federal privacy bills requiring businesses to act in the best interests of those whose personal data is processed.
Dynamic IP address
An IP address an ISP assigns as needed, which may change per session or persist for months.
E-discovery
The discovery of electronically stored information, an important subdiscipline of law and technology since the 2006 FRCP revisions.
ECPA
Electronic Communications Privacy Act; with the Wiretap Act, restricts interception of communications such as emails and calls.
Edge computing
A distributed IT architecture where data is processed at the periphery of the network, as close to the originating source as possible.
Edtech
Companies providing software, apps, and web-based tools to educators, students, and parents, whose data practices are subject to the chapter's privacy laws.
Education record
Any record directly related to a student and maintained by or on behalf of the school, including grades, financial aid, and disciplinary records.
EEA
The European Economic Area - the EU plus Norway, Liechtenstein, and Iceland - from which transfers are regulated.
EEOC
Equal Employment Opportunity Commission; works to prevent workplace discrimination, overseeing Title VII, the ADEA, and Titles I and V of the ADA.
Electronic Communications Privacy Act (ECPA)
Extended the interception ban to electronic communications such as email; violations are a criminal offense with a private right of action.
Electronic fund transfer (EFT)
Any transfer of funds initiated through an electronic terminal, telephone, computer or magnetic tape to debit or credit a consumer's account, such as ATM, direct deposit, point-of-sale or debit card transfers.
Electronic health records (EHRs)
Digital medical records whose meaningful use HITECH funded with $19 billion in provider incentives.
Electronically stored information (ESI)
Email, documents, databases, web pages, server logs, IM transcripts, voicemail, social media, and removable media - the focus of pretrial e-discovery since 2006.
Eligible student
A student who holds the FERPA rights, generally a high schooler who has turned 18 or any student attending only a college or university.
Employment at will
The U.S. default rule giving employers broad discretion to fire an employee, which has also been read to grant broad latitude over other aspects of the employment relationship.
Employment life cycle
The framework of privacy issues spanning before employment (screening), during employment (testing, monitoring), and after employment (access termination, records).
Encryption
A reversible process that converts plaintext into scrambled ciphertext; decryption reverses it using a key.
Encryption safe harbor
A provision excusing breach notice where data was encrypted, redacted, or rendered unreadable/unusable - generally only if the decryption key was not also breached.
Enforcing agency
The FCC enforces these rules; they are distinct from the CPNI rules under the Telecommunications Act and from state breach-notification laws enforced by state attorneys general.
Entity-level exemption
An exemption where an entire type of organization is exempt from the law (e.g., nonprofits, higher education, local governments).
Entity-specific suppression list
An internal Do Not Call list a seller/telemarketer must maintain to honor a consumer's request not to be called again by that company.
ePHI
Electronic protected health information; PHI transmitted or maintained in electronic media such as hard drives, tapes, disks, or memory cards.
EPIC
The Electronic Privacy Information Center, a nongovernmental organization focused on civil liberties and privacy.
Epic Games
The maker of Fortnite, which in 2023 reached a $520 million settlement with the FTC over COPPA violations and dark patterns.
EPPA
Employee Polygraph Protection Act of 1988; prohibits most private employers from using lie detectors on employees or applicants, enforced by the DOL.
Equal Pay Act of 1963
Federal law barring wage disparity based on sex.
ERISA
Employee Retirement Income Security Act; ensures employee benefits programs are created fairly and administered properly.
Established business relationship (EBR)
A relationship permitting calls despite the registry: 18 months from a customer's last purchase/transaction, or three months from a prospect's inquiry or application.
EU representative
A representative appointed by a company with no physical EU presence, who is subject to GDPR enforcement proceedings.
EU-U.S. Data Privacy Framework
The 2023 successor agreement enabling EU-to-U.S. transfers, supported by U.S. Executive Order 14086.
European Convention on Human Rights (1950)
Council of Europe convention whose Article 8 guarantees respect for private and family life, home, and correspondence.
Evidentiary privilege
A rule (generally defined under state law) that prevents a person from being compelled to testify or produce records, such as attorney-client, doctor-patient, priest-penitent, or spousal privilege.
Exclusionary rule
Evidence gathered in violation of the Fourth Amendment may be excluded from a criminal trial.
Executable code
Code that can run a computer program; limiting employees' ability to download it helps prevent spyware installation.
Executive branch
The president, vice president, cabinet, and federal agencies, which enforce and administer the law through rulemaking and civil/criminal procedures.
Executive Order 14086
President Biden's order committing U.S. surveillance to a necessity-and-proportionality standard and creating an independent data protection review court.
Expanded covered PII
The 2023 rules expanded the scope of personally identifiable information covered by the notification obligation.
Expert determination
The deidentification method where a qualified expert certifies the re-identification risk is very small.
Expert determination method
A HIPAA deidentification method in which an expert determines and documents that the risk is very small that an anticipated recipient could identify an individual.
Explicit consent
A heightened form of consent required to process sensitive personal data unless an exception applies.
Express prior authorization
Affirmative opt-in consent required before any MSCM is sent; cannot be a negative option, must be free to give or revoke, and must include specific disclosures.
Express verifiable authorization
The heightened proof of consent the TSR requires when a consumer pays by a method other than credit or debit card (e.g., phone or utility billing).
Extensible markup language (XML)
A language that describes content in terms of the data being produced (not how it is displayed), enabling automated high-volume processing.
FACTA
Fair and Accurate Credit Transactions Act of 2003; amended the FCRA and preempted many state laws, but left employment credit-check laws and certain state laws in effect.
FACTA Disposal Rule
Rule under the Fair and Accurate Credit Transactions Act of 2003 setting required disposal protections for financial institutions; a good baseline for PI disposal generally.
Fair Chance to Compete on Jobs Act (FCA)
2019 law restricting federal agencies and federal contractors from requesting an applicant's criminal-history information until a conditional offer of employment has been made.
Fair Credit Reporting Act (FCRA)
The first U.S. national privacy law, passed in 1970, focused solely on information about consumer credit.
Fair information practices (FIPs)
The foundational privacy principles, originating with the U.S. government in the 1970s, on which the first wave of modern privacy laws was based.
Family Policy Compliance Officer (FPCO)
The office within the U.S. Department of Education that investigates FERPA complaints and typically provides technical assistance.
FAPE
Free appropriate public education, which IDEA ensures for eligible students with disabilities.
FAST Act
The Fixing America's Surface Transportation Act (December 2015), which amended GLBA section 503 to create an exception to the annual privacy notice requirement.
FATCA
Foreign Account Tax Compliance Act of 2010, targeting U.S. taxpayers with foreign accounts and requiring more detailed KYC documentation.
FCC
The Federal Communications Commission, which issues and enforces the TCPA rules on telemarketing, robocalls, faxes and texts.
FCC 2023 breach rules
Updated data breach notification rules the FCC adopted in December 2023 for telecommunications carriers, interconnected VoIP, and telecommunications relay services; enforced by the FCC.
FCRA
Fair Credit Reporting Act of 1970, the first federal law to regulate private businesses' use of personal information, governing consumer reporting agencies and consumer reports.
FDCA
The Federal Food, Drug, and Cosmetic Act, enforced by the FDA to regulate medical devices by levels of risk.
Federal preemption
The displacement of state law by federal law; a contested issue in proposed federal breach legislation, where businesses favor preempting stricter state laws.
Federal Rule of Civil Procedure 45
The rule governing subpoenas; it specifies required contents and authorizes contempt for failure to obey without adequate excuse.
FERPA
The Family Educational Rights and Privacy Act of 1974, a federal statute giving students control over disclosure and access to their education records.
Fifth Amendment privilege
The constitutional privilege against self-incrimination available to a person accused of a crime in state or federal court.
FinCEN
Financial Crimes Enforcement Network within the Department of Treasury, which administers anti-money-laundering laws to 'follow the money.'
FIPPs
Fair Information Practice Principles such as notice, consent, access and correction, security, and accountability, major aspects of which FERPA incorporates.
First responders
Front-line individuals who respond when the organization faces a specific privacy difficulty.
First-party cookie
A cookie set by the primary website the user is visiting.
FLSA
Fair Labor Standards Act; establishes the minimum wage and standards for fair pay.
FMLA
Family and Medical Leave Act; entitles certain employees to unpaid leave for birth or illness of self or a family member.
Foreign Intelligence Surveillance Act (FISA)
1978 law establishing standards and procedures for electronic surveillance collecting foreign intelligence within the United States, with orders from the FISC.
Foreign Intelligence Surveillance Court (FISC)
The special court of federal district judges that issues FISA orders; the USA FREEDOM Act added an amicus curiae of privacy experts for novel matters.
Fourth Amendment
Constitutional protection against unreasonable searches and seizures, requiring warrants on probable cause, supported by oath, particularly describing the place to be searched.
FRCP 5.2
The 2007 'Privacy Protection for Filings Made with the Court' rule requiring attorneys to redact specified personal identifiers from court filings.
Free-to-pay conversion offer
An offer that starts with a free trial then converts to paid service when the trial ends.
Front end
The web-based interface where client and server interact, generally coded in HTML, CSS, and JavaScript.
FTC
Federal Trade Commission; regulates unfair and deceptive practices and enforces laws including the FCRA.
FTC Act
The law under which the FTC polices unfair or deceptive practices, including by health companies not covered by HIPAA.
FTC Disposal Rule
A federal rule, enforced by the FTC, governing disposal of consumer reports and information derived from them (covered in Chapter 9).
FTC Health Breach Notification Rule (HBNR)
A 2009 FTC rule requiring vendors of personal health records and related entities to notify after a breach of identifiable health information held outside HIPAA.
FTC v. LabMD
2018 Eleventh Circuit case that recognized FTC authority but vacated its order as too vague, constraining the FTC's ability to mandate comprehensive security overhauls.
FTC v. Wyndham
2015 Third Circuit case confirming the FTC's Section 5 unfairness authority extends to regulating cybersecurity practices harmful to consumers.
Furnisher
An entity such as a lender or retailer that supplies credit history or other personal information to CRAs; must provide accurate data and respond to disputes.
Furnisher Rule
Rule requiring furnishers to maintain policies and procedures ensuring the accuracy and integrity of consumer information reported to CRAs, including preventing re-aging of delinquency dates.
GDPR
The 2018 comprehensive EU privacy regulation that serves as the worldwide template for data protection law.
General authority
Blanket authority for a government body to regulate an entire field of activity (e.g., the FTC over unfair and deceptive trade practices).
Generalization
Replacing a detailed data element with a more general one (e.g. year of birth instead of full date, municipality instead of GPS).
Genetic Information Nondiscrimination Act (GINA)
The 2008 federal law protecting genetic information in employment and health insurance.
Geofence warrant
A warrant seeking data on all devices within a defined area; challenged under the bar against general warrants, with mixed results in lower courts.
Geofencing
Technology that targets digital advertising to people within a virtual boundary; the data it generates can later be sought by law enforcement via a geofence warrant.
GINA
Genetic Information Nondiscrimination Act of 2008; bars discrimination based on individuals' genetic information.
GIPA
The Illinois Genetic Information Privacy Act of 1998, which restricts use of genetic information and grants a private right of action with uncapped per-violation damages.
GLBA
Gramm-Leach-Bliley Act of 1999, supplying the general framework for confidentiality of records in the financial services sector through its Privacy Rule and Safeguards Rule.
GLBA Privacy Rule
The GLBA rule governing notice of privacy practices and the consumer's opt-out right regarding sharing of nonpublic personal information with nonaffiliated third parties.
GLBA Safeguards Rule
The GLBA rule requiring financial institutions to develop, implement, and maintain administrative, technical, and physical safeguards to protect customer information, including adequate authentication.
Global CBPR Forum
A 2022 international certification system based on the APEC Cross-Border Privacy Rules, independent of APEC so non-members can join.
Global Privacy Control (GPC)
The leading example of a universal opt-out mechanism, communicated as a browser or device signal that businesses in certain states must honor.
GPS
Global positioning satellites that let a device determine its longitude, latitude, and altitude from differences in message arrival times.
Hague Convention on the Taking of Evidence
A treaty providing an alternative route for obtaining foreign evidence; the party invoking it bears the burden of showing it is more appropriate and that foreign law prohibits the discovery.
Hashing
A one-way cryptographic function that transforms an input into an alphanumeric output that cannot be reversed back to the original.
Health care clearinghouse
A third-party organization that hosts, handles, or processes medical information.
Hesse data protection law (1970)
The first known modern data protection law, enacted by the German state of Hesse in 1970.
HEW Code of Fair Information Practices (1973)
A 1973 U.S. Department of Health, Education and Welfare code that is the foundation of FIPs used widely today.
HHS
The U.S. Department of Health and Human Services, which promulgates and enforces HIPAA's privacy and security regulations.
HHS Office for Civil Rights guidance (2022)
Post-Dobbs guidance clarifying that PHI may not be disclosed as 'required by law' where state law does not expressly require reporting, but may be disclosed in response to a court order or court-ordered warrant.
HHS Office of Civil Rights
The U.S. Department of Health and Human Services component with regulatory authority over health privacy.
Higher-level fines
GDPR fines up to the greater of 20 million euros or four percent of global annual revenue, for infringements of basic processing principles, data subject rights, and transfer rules.
HIPAA
Health Insurance Portability and Accountability Act of 1996; its privacy and security rules regulate protected health information for health insurers, including self-funded health plans.
HIPAA Safe Harbor Law
A 2021 law requiring the OCR to consider whether a covered entity used recognized security practices for the prior 12 months, allowing leniency in fines, notably after a breach.
HITECH
The Health Information Technology for Economic and Clinical Health Act; the FTC shares breach-notification authority with HHS for personal health record providers.
HITECH Act
The Health Information Technology for Economic and Clinical Health Act of 2009, enacted within ARRA, which strengthened HIPAA and funded health IT adoption.
HITECH Act (2009)
The Health Information Technology for Economic and Clinical Health Act, which added breach-notification requirements for vendors of personal health records not covered as HIPAA covered entities.
HTTP cookie
A small data file that links a device to its previous web actions, maintaining continuity because HTTP is stateless.
HTTPS
Hypertext transfer protocol secure, which transfers data between browser and website over an encrypted connection; by 2016 it exceeded HTTP traffic.
Hyperlinking
Berners-Lee's term for dynamically tying documents and files together; a hyperlink transports a user to a destination page.
Hypertext markup language (HTML)
A content-authoring language used to create web pages; HTML5 is the most recent version and can run media without plug-ins.
Hypertext transfer protocol (HTTP)
An application protocol that formats and transmits messages over a TCP/IP network and defines how servers and browsers respond to commands.
ICRAA
California's Investigative Consumer Reporting Agencies Act; requires notice and written authorization before obtaining a consumer report and a copy of the report before adverse action.
IDEA
The Individuals with Disabilities Education Act, a federal law ensuring eligible students aged 3 to 21 receive a free appropriate public education.
Identify, Protect, Detect, Respond, Recover
The five NIST CSF Framework Core Functions, designed to operate concurrently and continuously.
Identity theft laws
State laws addressing identity theft; all 50 states have them and more than half permit restitution for victims.
IEP
Individualized education program, the tailored special-education plan IDEA requires for each eligible student.
Illinois BIPA
The Illinois Biometric Information Privacy Act, which regulates the collection and handling of biometric identifiers such as fingerprints and requires consent before collection.
IMAP
Internet Message Access Protocol for receiving email; typically leaves messages on the server, enabling multi-device sync and server-side search.
IMLC
The Interstate Medical Licensure Compact, whose use grew nearly 50 percent during the pandemic to ease cross-state physician licensing.
Information blocking
Any activity likely to interfere with, prevent, or materially discourage access, exchange, or use of electronic health information.
Information broker (Georgia)
Georgia's narrow definition of covered entity, limiting the breach law to businesses whose primary purpose is furnishing personal information to nonaffiliated third parties.
Information management
Establishing, implementing, and monitoring an organization's privacy program under the direction of a senior leader.
Information privacy
Privacy concerned with rules governing the collection and handling of personal information such as financial, medical, government, and internet-activity records.
Information security program
A program containing administrative, technical and physical safeguards to protect the security, confidentiality and integrity of customer information.
Infrastructure as a service (IaaS)
Self-service access to computers, networking, and storage where the customer retains complete control over what is done, including managing databases of personal information.
Injunction
A court order requiring a defendant to stop engaging in certain conduct.
Institute for Advertising Ethics (IAE)
An independent body promoting ethical principles - honesty, fairness, and never compromising consumers' privacy - to build a more trusted digital marketplace.
Integrity
Assurance that data is authentic and complete.
Intentional tort
A wrong the defendant knew or should have known would result from their action or inaction.
Interactive Computer Service
The type of online service or platform that Section 230 shields from being treated as the publisher or speaker of third-party content.
Internet protocol (IP)
The protocol that specifies the format of data packets and provides the addressing scheme; each device gets a unique IP address (currently moving from IPv4 to IPv6).
Internet service provider (ISP)
A provider, such as a cable or wireless company, that connects users and devices to the internet and assigns IP addresses.
Interoperability
The substantial similarity and overlap among the state comprehensive laws, such that compliance approaches can carry across states.
Intrusion on seclusion
A privacy tort imposing liability for intentionally intruding on another's solitude in a manner highly offensive to a reasonable person - a higher bar than telemarketing law's milder-intrusion standard.
Intrusion upon seclusion
A tort imposing liability for intentionally intruding on another's solitude or private affairs in a way highly offensive to a reasonable person (e.g., a camera in a restroom).
Investigative consumer report
A consumer report where some information is gathered through interviews with neighbors, friends, associates, or acquaintances (e.g., reference checks).
IP address
Numbers identifying the location of computers in internet communications; treated as personal data in the EU but generally not under the U.S. Privacy Act.
IRCA
Immigration Reform and Control Act; requires employment eligibility verification.
Joint marketing partner
Another financial institution with which an entity jointly markets a financial product or service, with whom information may be shared under GLBA.
Judicial branch
The federal court system, which interprets laws and examines a law's constitutionality and intent.
Judicial Redress Act
2016 law extending certain U.S. Privacy Act protections to certain non-U.S. persons.
Judicial Redress Act of 2015
U.S. law extending a right to civil action against a U.S. agency for qualifying non-U.S. individuals to access and rectify covered records.
Junk Fax Prevention Act (JFPA)
A 2005 amendment to the TCPA clarifying that consent to commercial faxes can be inferred from an established business relationship, provided the sender offers an opt-out.
Jurisdiction
A court's authority to hear a case, requiring both subject matter jurisdiction (the type of dispute) and personal jurisdiction (over the parties).
Just-in-time notice
Notice provided at or before the point of information collection or before accepting a service/product.
Justices of the Peace Act (1361)
An English statute providing for the arrest of 'peeping Toms' and eavesdroppers, an early legal protection of privacy.
Key
A string of characters applied by a cryptographic algorithm; the longer and more complex, the stronger the security.
Keylogging
A type of spyware (malware) that tracks all keystrokes and sends them to an attacker.
Know Your Customer (KYC)
Requirements, expanded by the USA PATRIOT Act, to identify customers and beneficial owners of accounts to deter money laundering.
Latency
The delay in communicating over a network, which edge computing reduces by keeping data closer to the source.
Law enforcement delay
A provision allowing breach notice to be postponed for a reasonable period when law enforcement determines that notification would impede a criminal investigation.
Layered privacy notice
A short top-layer summary with a link to a comprehensive full notice in the bottom layer.
Lead DPA
The supervisory authority designated to take the lead when a complaint involves more than one DPA.
Least privilege
Giving each user the most limited scope of action needed to do their job.
Legislative branch
Congress (House and Senate), which writes and passes laws and can override presidential vetoes.
Legitimate educational interest
A basis for a school official to access records where the record is relevant and necessary to that official's responsibilities; need not be academic.
Lie detector
Under the EPPA, includes polygraphs, voice stress analyzers, psychological stress evaluators, or similar devices used to render a diagnostic opinion about honesty.
Lifestyle discrimination
Adverse employer action based on an employee's lawful off-duty conduct (e.g., weight or smoking); a developing area governed largely by varied state laws.
Limited data set
PHI stripped of most direct identifiers, which covered entities should aim to use for disclosures, defaulting to minimum necessary if a limited data set is not feasible.
Limited private right of action (California)
California's narrow right allowing individuals to sue over security breaches compromising personal information and over usernames/passwords, not over general consumer rights.
Litigation hold
A suspension of routine retention/destruction policies once a company is on notice of discovery because litigation is underway or anticipated.
Location-based services (LBS)
Geolocation data from phones, GPS, and tablets enabling tracking of a user's physical location; tracking company vehicles is generally allowed, but tracking employees themselves faces greater limits.
Lower-level fines
GDPR fines up to the greater of 10 million euros or two percent of global annual revenue, for administrative and operational infringements.
Madrid Resolution (2009)
International Standards on the Protection of Personal Data and Privacy, approved by data protection and privacy commissioners (not governments) in Madrid in 2009.
Magnuson-Moss
The Magnuson-Moss Warranty FTC Improvements Act of 1975 (Section 18), setting complex, lengthy procedures the FTC must follow to make trade-rule regulations on unfair or deceptive practices.
Major questions doctrine
A doctrine restricting agencies from issuing substantial regulations without precise direction from Congress.
Manifestation of disease
The appearance of actual symptoms; GINA's protections target discrimination based on genetic predisposition in the ABSENCE of such manifestation.
Material change
A change that, at minimum, includes sharing consumer information with third parties after committing at collection not to share it - requiring opt-in if applied retroactively.
Maximum possible accuracy
The FCRA standard requiring CRAs to have procedures ensuring the greatest feasible accuracy of information in a consumer's report.
Meaningful use
The standard providers must meet in using EHRs to qualify for HITECH incentive funds.
Metadata
Data such as location and time automatically stored within content like photos, often without the user's awareness.
Mini-TCPA
A state's own version of the TCPA with additional or different telemarketing requirements and penalties (e.g., Louisiana limits established business relationships to six months).
Mobile service commercial message (MSCM)
A commercial email transmitted directly to a wireless device using an address that references an internet domain; covers SMS-technology messages but not phone-to-phone messages.
MSCMs
Mobile service commercial messages - many commercial text messages, addressed by FCC rules under CAN-SPAM.
Multiple purpose call
A call serving more than one sales purpose; the four basic disclosures must be made for all sales purposes promptly at the start.
Mutual legal assistance treaty (MLAT)
The traditional, slow mechanism (about 10 months on average) for foreign law enforcement to obtain U.S.-held evidence, requiring a showing of U.S.-standard probable cause.
My Health My Data Act (MHMDA)
Washington's 2023 law regulating consumer health data held by entities not covered by HIPAA, with a private right of action.
NAIC Model Bulletin
The NAIC Model Bulletin on the Use of Artificial Intelligence Systems, guidance for insurers emphasizing transparency, accountability, and fairness, adopted by at least 11 states.
National Child Protection Act
Federal law authorizing state officials to access the FBI's National Crime Information Center database for certain positions involving contact with children.
National Do Not Call Registry
The FTC registry, effective 2003, where U.S. residents register numbers they do not wish to receive telemarketing calls on.
National security letter (NSL)
A category of subpoena issued by authorized FBI officials, without judicial involvement, for records relevant to protecting against international terrorism or clandestine intelligence activities.
Negative option feature
An offer in which the consumer's silence or inaction is treated as acceptance of goods or services - one of the material categories that must be disclosed.
Negligent hiring
A tort claim against an employer for hiring an employee it knew or should have known posed a risk of harm; an incentive for employers to gather information and screen candidates.
Negligent supervision
A tort claim that an employer failed to adequately supervise an employee, especially where on notice of a specific risk; an incentive for workplace monitoring.
Negligent tort
A wrong arising when the defendant's actions were unreasonably unsafe, such as failing to maintain appropriate security controls.
Network Advertising Initiative (NAI)
A nonprofit self-regulatory association of third-party digital advertising companies whose Code of Conduct requires notice and choice for interest-based advertising; enforced by its board, with possible referral to the FTC.
NIST
National Institute of Standards and Technology - source of voluntary privacy and cybersecurity frameworks.
NIST Cybersecurity Framework
A voluntary tool to manage and reduce cybersecurity risk with core elements Identify, Protect, Detect, Respond, and Recover.
NIST Cybersecurity Framework (CSF)
A 2014 NIST framework of industry standards and best practices to help organizations manage cybersecurity risk; guidance, not a legal requirement.
NIST Framework
The National Institute of Standards and Technology cybersecurity framework that K-12 schools and universities are encouraged to follow.
NLRA
National Labor Relations Act; sets standards for collective bargaining, which also extend to social media communications.
NLRB
National Labor Relations Board; administers the NLRA, conducts union-representation elections, and remedies unfair labor practices.
No Child Left Behind Act
A 2001 statute that broadened PPRA to limit collection and disclosure of student survey information and add commercial-purpose protections.
No option / commonly accepted practices
Situations where implied authority lets an organization use data without opt-in or opt-out, e.g., order fulfillment.
Noise addition
Replacing actual values with similar but different ones, often preserving statistical properties like the average while disrupting individual identification.
Nonpersonal information
Data from which identifying elements have been removed (deidentified or anonymized), to which privacy and data protection laws generally do not apply.
Nonpublic information
Information not generally available or easily accessed due to law or custom, such as medical records, financial information, or adoption records.
Nonpublic personal information (NPI)
Personally identifiable financial information a consumer provides to, or that results from transactions with, or is otherwise obtained by a financial institution; excludes publicly available information and lists derived without using such information.
Nonpublic-facing technology
One-to-one or one-to-few videoconferencing that OCR temporarily permitted during the public health emergency even when it did not fully meet HIPAA requirements. That discretion has expired.
Notice
A description of an organization's information management practices, serving consumer education and corporate accountability.
Notice at point of collection
A requirement to inform consumers at or before collection about data categories and purposes; required only by California.
NYC Local Law 144
Requires employers using AEDTs to have a bias audit conducted, publish the audit results, and notify candidates that an AEDT is used and of any alternative process.
NYDFS cybersecurity regulation
New York Department of Financial Services 2017 regulation imposing NIST-aligned cybersecurity mandates on covered financial institutions, including a CISO, incident response and audit trails.
OCR
The Office for Civil Rights within HHS, the primary enforcer of the HIPAA Privacy and Security Rules.
OCR (HHS)
The Office for Civil Rights within HHS, which enforces HIPAA.
OECD
The Organisation for Economic Co-operation and Development, which adopted common principles for government access to private-sector personal data.
OECD Guidelines (1980)
Organisation for Economic Co-operation and Development 'Guidelines on the Protection of Privacy and Transborder Flows of Personal Data,' the most widely recognized FIP framework, updated in 2013.
Offer
Proposed language to enter a bargain, communicated to another and open until accepted, rejected, retracted, or expired; a counteroffer ends the original offer.
Office of Technology
An FTC office created in 2023 to strengthen the agency's focus on emerging technology.
OMB
The President's Office of Management and Budget, the lead agency for interpreting the Privacy Act of 1974 and issuing privacy/security guidance to agencies and contractors.
On-premises computing
Computing on resources owned and managed by the organization itself.
ONC
The Office of the National Coordinator for Health Information Technology, which issued the Cures Act Final Rule and enforces information-blocking provisions.
Online behavioral advertising
Per the IAPP, advertising targeted at individuals based on observation of their behavior over time, accomplished by tracking, profiling and targeting.
Opt-in
An affirmative indication of choice through an express act; failure to answer means the information is NOT used or shared.
Opt-in (affirmative/express consent)
Consumer must affirmatively agree before data is collected or used.
Opt-in default for children's data
An age-based requirement that a business obtain consent before handling a minor's data in specified ways; thresholds and triggers vary by state.
Opt-out
Choice implied by a person's failure to object; failure to answer means the information IS used or shared.
Opt-out (consumer choice)
Data may be used unless the consumer affirmatively declines; still creates an enforceable promise.
Ordinary course of business exception
Permits interception using equipment furnished by the communications-service provider when done in the normal course of the user's business, e.g. call-center monitoring or virus scanning.
OSHA
Occupational Safety and Health Act; regulates workplace safety.
Over-the-top (OTT) services
Messaging services that stream content over the internet (e.g. iMessage, Signal, Telegram, WhatsApp), avoiding SMS limits and able to provide end-to-end encryption.
Over-the-top provider (OTT)
A streaming video company delivering content over the internet or to mobile devices; not regulated by the FCC for CPNI as of this guide's writing.
Packet sniffing
Capturing packets sent over a wireless network in the absence of effective encryption, a risk in shared public Wi-Fi hotspots.
Packet switching
The method by which TCP/IP routes packets independently to a destination where they are reassembled in order, retransmitting any that fail to arrive.
Patient-identifying information
Any information that could reasonably identify, directly or indirectly, a person diagnosed with or treated for substance abuse.
PCI DSS
The Payment Card Industry Data Security Standard - a privately drafted, enforceable security standard for payment card data with penalties from $5,000 to $100,000 per month.
PCLOB
The Privacy and Civil Liberties Oversight Board, an independent executive-branch agency that reviewed the Section 215 and Section 702 programs.
Pen register
Traditionally a device recording the numbers of outgoing calls; the PATRIOT Act expanded it to dialing, routing, addressing, or signaling information.
Pen register order
A court order for dialed-number and similar information, issued on the lenient standard that the information is relevant to an ongoing investigation.
Penumbra
Unenumerated constitutional rights, including a right to privacy, inferred by the Supreme Court from several constitutional provisions and due process.
Per-Scan vs Per-Individual Damages
The basis for accruing BIPA damages; the 2024 amendment limited accrual to one violation per individual rather than one per scan.
Per-Violation Damages
Monetary damages assessed for each separate violation rather than capped at a single total amount.
Permissible purpose
An FCRA requirement that a consumer report be obtained only for an allowed reason; 'employment purposes' include preemployment screening and promotion/reassignment/retention decisions.
Persistent cookie
A cookie saved indefinitely (for a duration set by the website that placed it), able to recognize a user across days.
Person
Any entity with legal rights, including an individual (natural person) or a corporation (legal person).
Personal data
Any data relating to an identified or identifiable natural person, who can be identified directly or indirectly.
Personal Health Record (PHR)
A record of individually identifiable health information that can be drawn from multiple sources and is managed by or for the individual.
Personal health record provider
A provider of cloud or app services storing individual health records, subject to HITECH breach rules and FTC enforcement even without seeking federal reimbursement.
Personal information
Any data that can be associated or linked with a particular individual; California also covers household and employment data.
Personal information (breach law)
Generally a person's name plus a sensitive data element (SSN, driver's license/state ID number, or financial account/card number) whose exposure triggers notification duties.
Personally identifiable information (PII)
U.S. term for information that makes it possible to identify an individual, or relates to an identified or identifiable individual.
PHI
Protected health information, the individually identifiable health information protected under HIPAA.
Phishing
A form of social engineering using a routine, trusted communication channel to fool a user into granting access or disclosing sensitive information.
PII
Under the Department of Education's definition, information such as a student's name, identifiers, and any data that alone or combined would allow identifying the student with reasonable certainty.
Plaintext
The original, readable data before encryption.
Platform as a service (PaaS)
A cloud framework providing components for developers to build and use to create customized applications.
POP
Post Office Protocol (POP3) for receiving email; typically deletes mail from the server and is used less over time.
PPRA
The Protection of Pupil Rights Amendment of 1978, amending FERPA to give parents of minors rights over surveys collecting sensitive student information; applies only to K-12 schools.
Practical obscurity
The protection paper records enjoyed because they were expensive and difficult to search; online searchable records greatly reduced it.
Pre-acquired account information
A consumer's billing account information that the telemarketer obtained from a source other than the consumer during the call.
Pre-adverse-action notice
Notice with a copy of the consumer report given before taking adverse action, so the applicant can dispute the report.
Predictive dialer
Equipment that dials multiple consumers per available rep to maximize talk time, which can cause abandoned calls.
Preemption
When federal law overrides state law; HIPAA sets a federal floor and does NOT preempt stricter state protections.
Pregnancy Discrimination Act of 1978
Bars discrimination due to pregnancy, childbirth, and related medical conditions.
Prescreening
Nonconsumer-initiated transactions where a CRA furnishes a list of consumers meeting preset criteria for firm offers of credit or insurance; addressed by 1996 FCRA amendments.
Preservation order
An SCA requirement that a provider, on a government request, take all necessary steps to preserve records pending a court order or other process.
Pretexting
Gaining access to CPNI through fraudulent means; the 2007 CPNI order requires passwords and breach notifications to combat it.
Preventing Harm
The first APEC privacy principle, requiring protection designed to prevent misuse of personal information with remedies proportionate to the harm.
PRISM and Upstream
The two collection programs under Section 702; PRISM sends directives to U.S.-based providers for specific selectors, while Upstream targets communications passing through U.S. internet infrastructure.
Privacy Act
U.S. statute under which federal agencies generally do not consider IP addresses to be covered.
Privacy Act of 1974
Federal law applying to federal agencies and their private-sector contractors, interpreted by the OMB.
Privacy advocates
Public-interest groups, academics, and others who generally support stricter privacy law, oppose broad preemption, and favor a private right of action.
Privacy analyst
Often entry-level role managing legal and operational risks tied to PI, assessing business-unit operations, and developing policies and trainings.
Privacy by design
Embedding privacy principles in architectures, products, and services from the onset; legally required in California and the EU among others.
Privacy champions
Informal advocates passionate about privacy who help understand and implement privacy requirements.
Privacy dashboard
An easy-to-navigate summary of privacy information that also offers user control.
Privacy engineer
Ensures compliance through the organization's technical processes and that strategic direction supports affected customers.
Privacy engineering
An emerging role focused on engineering privacy requirements into systems using increasingly sophisticated mathematical tools.
Privacy fundamentalists
People with a strong desire to protect their privacy (one of Westin's three categories).
Privacy harms
Harms including loss of self-determination (autonomy, exclusion, loss of liberty, physical harm), discrimination, loss of trust, and economic loss.
Privacy impact assessment (PIA)
An analysis of how PI is handled to ensure legal conformity, determine risks/effects, and evaluate protections to mitigate privacy risks.
Privacy law
The U.S. (and some other countries') term for laws protecting information about individuals, also called data privacy or information privacy law.
Privacy log
A description of documents at issue that lets a court differentiate among them without disclosing their contents.
Privacy manager
Mid-level manager responsible for developing, maintaining, and enforcing privacy policies and procedures.
Privacy mission statement
A concise statement of privacy's core function, aligned with the organization's overall objectives.
Privacy notice
Information a controller must provide to data subjects about how it processes their personal data.
Privacy operational life cycle
A continuous-improvement model with four stages - assess, protect, sustain, and respond - for refining the privacy program.
Privacy policy
High-level internal document implementing privacy goals and informing employees/contractors how PI must be handled.
Privacy pragmatists
People whose privacy concern varies with context and who will trade some privacy for benefits.
Privacy program
An organization's framework for establishing accountability and legal compliance in how personal data is handled.
Privacy program framework
The processes, templates, tools, and standards used to operationalize controls for handling and protecting PI.
Privacy Protection Act (PPA)
1980 law protecting media work product and documentary materials from government search or seizure in criminal investigations, passed after Zurcher v. Stanford Daily.
Privacy risk
The likelihood that individuals will experience problems from data processing, and the impact of those problems if they occur.
Privacy risk assessment
Determining the level of privacy risk from two variables: privacy impact and the likelihood of harm given the controls.
Privacy risk management
A process that identifies and assesses risks to information assets and implements mitigation strategies.
Privacy Rule
The HIPAA rule (finalized December 2000, revised 2002 and 2013) governing the use and disclosure of PHI by covered entities.
Privacy seal / trust mark
A third-party certification (e.g., BBB, TrustArc) a company displays to show compliance with a self-regulatory program.
Privacy torts
Common-law claims: intrusion upon seclusion, appropriation of name or likeness, publicity given to private life, and false light.
Privacy unconcerned
People with low worries about privacy (one of Westin's three categories).
Privacy-enhancing technologies (PETs)
Technology-driven tools used to protect and control data access, including in cross-border flows.
Private Right of Action
The ability of an individual consumer to personally sue over a violation, rather than relying solely on a government regulator.
Probabilistic tracking
Cross-device linking based on inferences from sources like IP addresses, cookies, location, and behavioral data.
Processing
Almost anything done with personal information - collection, storage, use, disclosure, combination, erasure, destruction, and more.
Processing threshold
A threshold that triggers coverage based on the number of in-state consumers whose data is processed.
Processor
An entity that processes personal data on behalf of the controller, governed by the controller's instructions in a contract.
Program
Under the rule, an entity, unit, or staff (other than a general medical facility) that holds itself out as providing substance abuse diagnosis, treatment, or referral, and receives federal funding.
Proportionality principle
Madrid principle limiting processing to what is adequate, relevant, and not excessive for the purposes, with reasonable efforts to minimize.
Protective order (FRCP 26(c))
A court order limiting disclosure of confidential information in litigation, granted on a showing of good cause under a three-part test.
Proxy server
An intermediary server that provides a gateway to the web, can mask activity behind a firewall, logs interactions, filters malware, and caches content.
Pseudonymization
A technical safeguard that reduces identifiability of personal data, weighed when assessing breach severity.
Pseudonymized data
Data that has been deidentified but remains personal data because it can still be used to reidentify the person.
Public key infrastructure (PKI)
The policies, standards, people, and systems supporting public-key distribution and identity validation via certificates and a CA.
Public records
Information collected and maintained by a government entity and available to the public; public-records laws vary by jurisdiction.
Publicity given to private life
A tort for publicizing a private matter that would be highly offensive to a reasonable person and is not of legitimate public concern; requires relatively broad dissemination.
Publicly available information
Information lawfully made available by federal, state, or local governments; excluded by all five states.
Purpose limitation
Personal data must be collected for specified, explicit, and legitimate purposes and not further processed in incompatible ways.
Purpose/processing limitation
An obligation to collect/process personal data only for a specific purpose, often described as necessary and proportionate; not imposed by Utah.
QSO
Qualified service organization; an entity that may receive information without consent for information it needs to provide services to the program.
Qualified privilege
A common-law protection allowing former employers to report their experience with and impressions of an employee, providing a defense against defamation suits when made in good faith.
Qualified protective order (QPO)
A HIPAA order, used in state courts outside the Federal Rules, that bars using PHI outside the litigation and requires its return or destruction at the end.
Quasi-identifier
Data, such as date of birth, that can be combined with external knowledge to link data to an individual.
Random testing
Substance testing without individualized suspicion; acceptable mainly in narrowly defined jobs in highly regulated industries or where critical to public safety or national security.
Reasonable accommodation
An adjustment an employer must provide to a qualified individual with a disability unless it would cause undue hardship.
Reasonable expectation of privacy
The standard under which government video surveillance is not generally permitted, such as in a bathroom.
Reasonable expectation of privacy test
From Katz: a person must show an actual (subjective) expectation of privacy that society is prepared to recognize as reasonable.
Reasonable suspicion testing
Substance testing allowed as a condition of continued employment when specific facts and rational inferences (appearance, behavior, speech, odors) suggest drug or alcohol use.
Record of processing activities (RoPA)
GDPR-required documentation of processing purposes, recipients of PI, retention periods, and safeguards; often used to start a top-down data map.
Red Flag Program Clarification Act of 2010
Law narrowing the definition of 'creditor' under the Red Flags Rule to exclude entities that extend credit only for expenses incidental to a service.
Red Flags Rule
FACTA rule requiring financial institutions and creditors to develop written programs to detect, prevent and mitigate identity theft.
Redaction
Identifying and removing or blocking information from documents produced in discovery or filed as evidence.
Regulation E
The rule implementing the EFTA, with rulemaking transferred to the CFPB in 2011 under Dodd-Frank.
Remote access trojan (RAT)
Malware that can turn on a device's webcam or microphone without the user's knowledge, even disabling the in-use indicator light.
Required specification
A Security Rule implementation spec that must be adopted as written.
Restitution
Recouping money losses suffered by consumers.
Restriction of processing
The marking of stored personal data with the aim of limiting its processing in the future.
Retention policy
A policy limiting how long PI is stored; shorter retention reduces breach risk.
Right against automated decision-making
The right to opt out of automated processing that produces decisions or profiling about the consumer; provided by all states except Utah.
Right to access
The right of an individual to obtain the PI an organization holds about them (e.g., credit reports under FCRA, medical records under HIPAA).
Right to appeal
The right to ask a business to reconsider a denied request; provided by Colorado, Connecticut, and Virginia, but not explicitly by California or Utah.
Right to correction
The right to correct inaccuracies in personal information; provided by California, Colorado, Connecticut, and Virginia, but not Utah.
Right to data portability
The right to receive personal data the subject provided in a structured, machine-readable format and to port it to oneself or another controller.
Right to delete
The right to have a business delete personal information, subject to exceptions; provided by all five states with differing scope.
Right to erasure
Also called the right to be forgotten; the right to have personal data deleted in defined circumstances unless an exemption applies.
Right to Financial Privacy Act (RFPA)
1978 law requiring customer authorization, a subpoena/summons, a warrant, or a formal written request before a federal agency may access individuals' or small partnerships' financial records.
Right to nondiscrimination
The right not to be discriminated against (e.g., denied goods, charged different prices, given degraded quality) for exercising privacy rights; provided by all five states.
Right to object
The right to require a controller to stop processing personal data; absolute for direct marketing, qualified otherwise.
Right to rectification
The right to have inaccurate personal data corrected and incomplete data completed.
Risk assessment
A formal privacy/cybersecurity assessment required for processing that presents a heightened risk of harm; required by all but Utah.
Risk-based pricing
Offering different interest rates or loan terms to borrowers based on their creditworthiness.
Risk-Based Pricing Rule
FCRA rule requiring those offering credit to notify customers receiving less favorable terms because of their credit report.
Risk-of-harm analysis
An assessment of whether an incident is reasonably likely to cause harm (such as identity theft or fraud); many states excuse notification when harm is unlikely.
Robocall
A prerecorded-voice telephone call; under the 2012 FCC rules, robocalls to residential lines require prior express written consent.
Robotext
A text message sent to a wireless device without human intervention; subject to the same TCPA consumer protections as voice calls and requiring express consent.
Role-based access controls
Controls that grant access by role (e.g. a doctor vs the cafeteria), implementing least privilege; required by the HIPAA Security Rule.
Ryan Haight Act
The Online Pharmacy Consumer Protection Act includes an in-person medical evaluation requirement for many online controlled-substance prescriptions. Temporary federal telemedicine exceptions changed how it applied during the pandemic.
Safe Harbor
An FTC-approved self-regulatory program that lets member operators be assessed against the program's guidelines; the 2025 Rule strengthens transparency obligations for these programs.
Safe harbor deidentification
Removing at least 18 listed data elements (name, phone, address, etc.) to deidentify data under the Privacy Rule.
Safe harbor method
A HIPAA deidentification method requiring removal of 18 specific types of potentially identifying information (e.g. ZIP codes no more specific than the first three digits).
Safeguards Rule
GLBA rule requiring financial institutions to develop and implement a comprehensive written information security program with administrative, technical and physical safeguards.
Sale
A regulated transfer of personal data; defined narrowly (monetary only) in Utah and Virginia, and broadly (any exchange for value) in California, Colorado, and Connecticut.
Salt
Added input to a hash (approximating an encryption key) that makes lookup-table attacks against the hash much more difficult.
SaMD
Software as a medical device; certain AI-based medtech that the FDA may regulate more heavily.
Sarbanes-Oxley Act (SOX)
2002 law passed after governance scandals (Enron, WorldCom) that increased incentives for corporate leaders to scrutinize practices in areas they manage.
Satisfactory assurances
Under HIPAA, the showing - via an agreed-upon qualified protective order submitted to the court, or a request for one - that allows a covered entity to disclose PHI in response to a discovery request.
SCA
Stored Communications Act; prohibits unauthorized acquisition, alteration, or blocking of electronic communications in storage, with exceptions for the provider and an authorized user.
Schrems I
The 2015 CJEU decision striking down the U.S.-EU Safe Harbor program over U.S. surveillance concerns.
Schrems II
The 2020 CJEU decision striking down the EU-U.S. Privacy Shield over lack of redress and proportionality in U.S. surveillance.
Scope of a law
Defined by who is covered and what information or uses are covered - the first two of the six key questions.
Seal programs
A form of self-regulation requiring participants to follow codes and submit to monitoring, then display a privacy seal; FTC-recognized COPPA seals include CARU, ESRB, iKeepSafe, kidSAFE, PRIVO, and TrustArc.
Search warrant
A Fourth Amendment order requiring probable cause that a crime has been, is, or will be committed.
Section 13(b)
FTC Act provision historically used to seek equitable money relief (restitution, disgorgement) without first issuing a cease-and-desist order.
Section 19
FTC Act provision allowing courts to grant relief once the FTC has issued a final cease-and-desist order.
Section 215
A USA PATRIOT Act provision used to collect bulk call detail records; bulk collection was ended by the USA FREEDOM Act and the provision expired in 2020.
Section 230
CDA provision stating that no provider or user of an interactive computer service shall be treated as the publisher or speaker of information provided by another information content provider; immunizes online platforms from liability for user-generated content and was enacted to encourage internet growth.
Section 230(c)(2) (Good Samaritan)
Provision giving platforms protection for the good-faith removal or restriction of objectionable third-party content.
Section 5 of the FTC Act
The provision letting the FTC pursue unfair and deceptive trade practices; the primary federal statute for medtech companies not covered by HIPAA.
Section 5(l)
FTC Act provision for administrative enforcement: the FTC issues a complaint, finds violations, and issues a cease-and-desist order, pursuing civil penalties for later breaches.
Section 702
A provision of the FISA Amendments Act of 2008 authorizing collection of communications of targeted non-U.S. persons reasonably believed to be located outside the U.S. for foreign intelligence purposes.
Sectoral approach
The U.S. model of regulating privacy through laws targeting specific industries or data types (e.g., HIPAA for health, GLBA for finance).
Sectoral model
A framework, used in the U.S., that protects personal information through laws addressing particular industry sectors rather than the whole economy.
Sectoral regulation
The U.S. approach of regulating privacy by industry sector (medical, financial, education) rather than through one comprehensive law.
Security breach
Unauthorized access to or acquisition of computerized data containing personal information that compromises its confidentiality, security, or integrity and is not protected by encryption or similar means.
Security by default
Configuring systems securely from initial use, such as requiring strong passwords on new hardware/software.
Security Rule
The HIPAA rule (finalized 2003, modified 2013) setting minimum security requirements for ePHI.
Sedona Conference
A leading source of standards and best practices for managing e-discovery compliance through data retention policies.
Self-regulation
Industry-led approaches to privacy that can cover rule-making, enforcement, and adjudication, sometimes with and sometimes without government involvement.
Self-regulatory model
An approach where companies, industries, or independent bodies create codes of practice, often without a generally applicable data protection law; e.g., PCI DSS.
Sender
Anyone who initiates a commercial email and whose product or service is advertised; the 2008 rule lets the entity in the 'from' line be treated as the single sender if other provisions are met.
Sensitive data
Categories such as medical, financial, or children's data that businesses are expected to protect to a higher bar.
Sensitive personal data
A special category of personal data (e.g., race, health, biometrics) that receives additional protection and generally requires explicit consent.
Sensitive personal information
A heightened category of personal data (e.g., health, race, religion, genetic/biometric data) that receives stronger protection under state comprehensive laws.
Separation of powers
The constitutional design dividing government into three branches so each checks and balances the others.
Server
The computer process that responds to client requests, such as serving a news story or processing an order.
Service provider
GLBA term analogous to a processor for handling financial information on an institution's behalf.
Session cookie
A cookie stored only until the browser is closed, holding limited information about that session (e.g. keeping a user logged in or a cart filled during a visit).
Sharing
California's separately defined activity of transferring personal information to a third party for cross-context behavioral advertising, whether or not for consideration.
Smishing
Phishing carried out via SMS text message.
SMS
Short Message Service using the Short Message Peer to Peer Protocol; limited to 160 characters and able to operate over cell service without the internet.
SMTP
Simple Mail Transfer Protocol, the most common protocol for sending email.
SOC 2
Set of controls defined by the AICPA; a vendor's compliance certification can evidence its security controls.
Social engineering
Using manipulation - such as a false online profile or requesting access to private networks - to gain access to otherwise private information; can trigger invasion-of-privacy claims.
Social Security number
A nine-digit federal identifier tied to the Social Security Act of 1935 that became a de facto identifier and a key target in identity theft.
Software as a service (SaaS)
Delivery of vendor-managed applications over the internet, often run directly in a browser with no client-side installation.
SOPIPA
California's Student Online Personal Information Protection Act, the first U.S. law to prohibit using student data for noneducational targeted advertising.
Sources of law
Federal and state constitutions, legislation, case law, contract law, tort law, agency regulations, and consent decrees.
Spear phishing
A phishing attack tailored to a specific individual, such as a message appearing to come from the user's boss.
Special categories of data
Under Convention 108, sensitive data such as racial origin, political opinions, religious beliefs, health, sex life, or criminal convictions that cannot be automatically processed absent appropriate safeguards.
Specific authority
Authority targeted at singular activities outlined by legislation (e.g., the FTC's authority to enforce COPPA).
Spyware
Malicious software covertly installed on a device that monitors activity and sends sensitive personal information to an attacker.
Standard contractual clauses (SCCs)
Contractual commitments to comply with EU law and submit to DPA supervision; the most common legal basis for transfers.
Stare decisis
Latin for 'to let the decision stand' - the practice of following precedent in deciding new cases.
State action
The requirement that government be involved for constitutional protections to apply; private-sector employment generally lacks state action.
State attorney general
A state's chief legal advisor and law enforcement officer, who brings privacy enforcement actions often under unfair-and-deceptive-practices laws.
State attorneys general
Elected constitutional officers who are the primary enforcers of state-level privacy protections and may join certain federal enforcement actions.
Stateless
A property of HTTP/HTTPS meaning the protocols are not designed to remember past interactions with a particular user.
Static IP address
An IP address an ISP dedicates to a specific user or business so it does not change.
Statutory damages
A set amount fixed by statute (in California, $100 to $750 per incident) that consumers can recover without proving actual loss.
Storage limitation
Personal data must be kept no longer than necessary for the purposes of processing.
Stored Communications Act (SCA)
Enacted as part of ECPA in 1986; prohibits unauthorized access to electronic communications in electronic storage, with exceptions for the service provider and the user.
Strict liability tort
A wrong established when an action causes damage regardless of the defendant's degree of carelessness, e.g., product liability.
STRIDE framework
A mnemonic for modeling threats: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, and Elevation of privilege.
Strong identifier
Clearly identifying information such as a Social Security or passport number.
Student
Under FERPA, any individual who is or has been in attendance at an educational agency or institution, with attendance including in-person and internet participation.
Student Privacy Pledge
A self-regulatory pledge created in 2014 by the Future of Privacy Forum and the Software and Information Industry Association, with over 400 signatories by 2020.
Subject access request
A data subject's exercise of the right of access to obtain confirmation, a copy of their data, and related processing information.
Subpoena
An instruction to produce a witness or records, enforceable through contempt of court.
Subprocessor
A party engaged by a processor (like a subcontractor) to whom GDPR requirements flow downstream.
Subscription Account Number (SAN)
A unique, non-transferable account number a seller obtains (upon fee payment) to access the DNC Registry; telemarketers may use a seller-client's SAN at no extra cost, limited to the area codes paid for.
Substitute notice
An alternative method - such as conspicuous website posting or statewide media - permitted for large breaches where individual notice would impose an undue financial burden.
Suppression
Removing identifying values from a record (e.g. dropping customer names for statistical analysis).
Surveillance capitalism
Term coined by Shoshana Zuboff for tech-company practices of collecting data about individuals and using that knowledge to influence their behavior.
Suspicious Activity Report
A report a financial institution must file when it detects potentially suspicious transactions; failure to file timely reports is a BSA violation.
Suspicious activity report (SAR)
A report financial institutions must file with FinCEN in defined situations to alert the government to potentially suspicious transactions.
Symmetric key cryptography
Private-key cryptography using the same short key to encrypt and decrypt; fast, but Alice must securely share the key with Bob.
TAKE IT DOWN Act (2025)
Law criminalizing distribution of nonconsensual intimate imagery (revenge porn), including AI-generated/deepfake images; it does not directly amend Section 230 but creates a new exception for illegal material not protected by Section 230, requiring platforms to remove such content on notice.
TCPA
The Telephone Consumer Protection Act of 1991, enforced by the FCC, restricting unsolicited advertising by telephone, fax, robocalls and (by FCC interpretation) text messages.
Telecommunications Act of 1996
Major legislation reshaping telecom markets; Section 222 governs the privacy of customer information obtained by telecommunications carriers.
Telemarketing
A plan, program or campaign to induce the purchase of goods or services or a charitable contribution, involving more than one interstate telephone call.
Telemedicine
Medical care delivered when doctor and patient are in different physical locations, which expanded dramatically during the COVID-19 pandemic.
Tenth Amendment
Reserves to the states (or the people) all powers not delegated to the federal government nor prohibited to the states.
Terms of use
The longer policy (also called terms of service or terms and conditions) a user agrees to when creating an account, often granting broader data-collection rights than cookie consent.
Territorial privacy
Privacy concerned with limits on intruding into an individual's environment - home, workplace, or public space - via monitoring such as video surveillance.
The right to be let alone
Warren and Brandeis's 1890 definition of privacy, set out in 'The Right to Privacy' in the Harvard Law Review.
Thick client
A client capable of performing many data-processing actions itself even when offline.
Thin client
A client that relies predominantly on remote processing, such as a device running only a web browser with cloud-based tools.
Third-party cookie
A cookie set by any company other than the first-party website, such as an advertising network or social network.
Third-party doctrine
The rule that information voluntarily given to a third party (e.g. bank or phone company) loses Fourth Amendment protection, so a warrant is not required to obtain it.
Threat modeling
Identifying the most salient security risks for an organization, using tools like MITRE ATT&CK and STRIDE.
Title VII
Civil Rights Act of 1964 provision barring employment discrimination based on race, color, religion, sex, and national origin; EEOC has held it covers sexual orientation and gender identity.
Top-level domain
The final segment of a domain such as .com (commercial), .org (organization), .gov (government), .edu (educational), or a two-letter country code; there are over 1,500.
Tort
A civil wrong recognized by law as grounds for a lawsuit, causing injury that supports a claim by the injured party.
TPO
Treatment, payment, and health care operations - the core HIPAA-permitted purposes now reachable by a single Part 2 consent.
Tracking pixel
A small image with a user-unique link or filename loaded when an email is opened, indicating the open (and clicks); disabled by reading in plain text.
Tracking Technologies
Cookies, pixels, and web or app trackers that collect user data and may send it to third-party vendors.
Transactional or relationship message
A message whose primary purpose is to facilitate a transaction, provide warranty/safety info, give info about an ongoing relationship, address employment/benefits, or deliver goods/services already owed - not subject to the commercial-email rules.
Transmission control protocol (TCP)
The protocol that establishes a reliable connection between source and destination and breaks data into packets while preserving integrity.
Transport layer security (TLS)
A protocol that secures the connection between user and server so no third party can eavesdrop or corrupt the message; successor to SSL.
TransUnion v. Ramirez
A 2021 Supreme Court decision requiring a plaintiff to show actual harm, not a mere risk of harm, to have standing to sue.
Trap-and-trace device
Traditionally a device recording the numbers calling into a particular number.
Treatment records
Health records created or maintained by a health professional for treating a student and not disclosed except to those providing treatment; excluded from the definition of education record under conditions.
Triangulation
Determining a phone's position geometrically from its signal timing and strength relative to several cell towers whose locations are known.
TSR
The Telemarketing Sales Rule, first issued by the FTC in 1995 to implement the Telemarketing and Consumer Fraud and Abuse Prevention Act, amended in 2003, 2008, 2010 and 2015.
U.S. West, Inc. v. FCC
A 1999 Tenth Circuit case striking down the FCC's 1998 opt-in CPNI rule as a violation of carriers' First Amendment speech rights, shifting carriers' own use to opt-out.
UCPA
The Utah Consumer Privacy Act, viewed as the narrowest of the five laws.
UDAP statutes
Unfair and Deceptive Acts and Practices statutes that all 50 states have enacted, giving consumer protections similar to the FTC Act.
Unconscionable practices
A contract-law concept for harsh seller practices that some state UDAP statutes also reach.
Unfair practice
A practice that causes or is likely to cause substantial, non-speculative consumer injury that is not reasonably avoidable and not outweighed by countervailing benefits to consumers or competition.
Uniform resource identifier (URI)
A larger class of identifiers formatted like URLs but which may not include information to locate the resource on a network.
Uniform resource locator (URL)
The address of content on a web server, containing a protocol prefix, often 'www', a domain name, and a top-level domain such as .com, .org, .gov, .edu, or a country code.
Uniform resource name (URN)
A related identifier term that may appear interchangeably with URL/URI in some documents.
Universal Declaration of Human Rights (1948)
UN declaration stating no one shall be subjected to arbitrary interference with privacy, family, home, or correspondence.
Universal opt-out mechanism
A browser or device signal that lets a consumer opt out of the sale, sharing, or targeted advertising of their personal information across all sites at once, without making a separate request to each site.
USA FREEDOM Act
2015 law that, among other provisions, ended bulk collection under the Section 215 program and required specific selectors.
User
An entity such as a lender, insurer or employer that uses a consumer report; must have and certify a permissible purpose and provide adverse-action notice.
User-generated content (UGC)
Text, photos, or videos a user posts to a website, providing granular insight into interests and offline activities.
Vail Letter
An FTC advisory opinion holding that an outside firm investigating employee misconduct was a CRA and its report an investigative consumer report, triggering FCRA notice/consent that defeated undercover investigations.
VCDPA
The Virginia Consumer Data Protection Act, the second state comprehensive law and initially seen as the pro-business model.
Verifiable Parental Consent
Express, opt-in consent from a parent that an operator must obtain before collecting, using, or disclosing a child's personal information; under the 2025 Rule it is specifically required to use children's data for targeted advertising.
Videotape service provider
Anyone engaged in the rental, sale or delivery of prerecorded videocassettes or similar audiovisual materials, plus those receiving such personal information in the ordinary course of business or for marketing.
Virtual private network (VPN)
A tool similar to a proxy that encrypts information from the user to the organization's proxy, potentially masking both content and destination from the ISP.
Vishing
Use of a fraudulent voice message or phone call to trick an individual into disclosing information or taking action.
VPPA
The Video Privacy Protection Act of 1988, restricting disclosure of consumers' video viewing/rental records by videotape service providers, enacted after Robert Bork's rental records were disclosed.
Warby Parker
The eyewear company fined $1.5 million by HHS OCR in February 2025 for HIPAA Security Rule violations.
Weak identifier
An identifier that must be combined with other information to determine identity.
Wearable
An electronic device placed on the body that may collect medical information in real time, such as a smartwatch.
Web server
A computer connected to the internet that hosts and shares web content accessed by browsers.
Web server log
An automatically created record of requests that can include the visitor's IP address, date/time, requested URL, referring URL, and browser/OS.
West Virginia v. EPA
2022 Supreme Court case applying the 'major questions doctrine,' potentially narrowing the scope of rules the FTC can enact.
Whaling
Spear phishing targeted at C-suite executives, celebrities, and politicians.
Wireless Domain Registry
An FCC-maintained, periodically updated list of wireless domain names; senders must check it and ensure proper authorization before messaging those domains.
Wiretap Act
Federal statute prohibiting interception of wire, oral, and electronic communications unless an exception applies; provides criminal penalties and a private right of action.
Wiretap Act (Title III)
Derives from a 1968 anticrime law; strictly prohibits interception of wire (aural) and oral communications absent an exception.
Zero trust
An approach where no actor, system, network, or service inside or outside the perimeter is trusted; everything must be verified and traffic encrypted and authenticated.

Sources

  • Current CIPP/US certification page
  • IAPP certification FAQs

Sources and study method

This independent study material uses the current published CIPP/US outline, active recall, spaced retrieval and scenario practice. Read the full method. Current sources. Current CIPP/US certification page, IAPP certification FAQs.

All certifications Support About Privacy Terms Refunds Disclaimer Accessibility Contact

CIPP/US study guide. Use active recall, spaced retrieval and scenario practice. The practice question bank has a one-time unlock.

Independent study guide with exam-style practice questions. Not affiliated with, endorsed by or sponsored by IAPP. IAPP, CIPP, CIPP/E, CIPP/US, AIGP and related marks are trademarks of the IAPP, used for identification only. See the full disclaimer. Contact studyguides@thesmios.com.

© 2026 Humenhuk

CIPP/E study guideAIGP study guide