Fair Information Practices (FIPs) Overview
Since the 1970s, Fair Information Practices (FIPs/FIPPs) have organized individual rights and organizational responsibilities into four categories: rights of individuals, controls on the information, information life cycle, and management.
How this supports CIPP/US study
Use this lesson to identify the legal source, actor, data and activity before applying a rule to a scenario. Continue with the CIPP/US exam format and blueprint.
Fair Information Practices (FIPs), sometimes called FIPPs, have since the 1970s been the main way of organizing individual rights and organizational responsibilities for personal information. Definitions vary over time and place, but the major themes are similar.
| Category | Principles included |
|---|---|
| Rights of individuals | Notice; choice and consent; data subject access |
| Controls on the information | Information security; information quality |
| Information life cycle | Collection; use and retention; disclosure |
| Management | Management and administration; monitoring and enforcement |
Key FIP codifications: 1973 HEW principles, 1980 OECD Guidelines, 1981 Convention 108, 2004 APEC Privacy Framework, and the 2009 Madrid Resolution.
Key terms - quick answers
What is “Fair Information Practices (FIPs)”?
What is “Notice”?
What is “Choice and consent”?
What is “Data subject access”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.