Sectoral Model (United States)
The sectoral model (the U.S. approach) protects personal data through laws targeting specific industries. Strengths: tailored, lower burden. Weaknesses: no single DPA, plus gaps and overlaps - illustrated by HITECH filling a gap and HIPAA/FTC overlap.
How this supports CIPP/US study
Use this lesson to identify the legal source, actor, data and activity before applying a rule to a scenario. Continue with the CIPP/US exam format and blueprint.
The sectoral model protects personal information by enacting laws for particular industry sectors - in the U.S., separate laws cover video rental records, financial transactions, credit records, law enforcement, and medical records. Supporters cite tailored protection and lower burden on unregulated sectors.
Critics note no single DPA plus gaps (new tech like drones may go unregulated until the legislature acts) and overlaps. The HITECH Act (2009) filled a gap by requiring breach notice from personal-health-record vendors that were not HIPAA covered entities.
A HIPAA-covered medical provider may be enforced either by HHS under HIPAA or by the FTC under its general authority against unfair and deceptive practices - an example of overlap in the sectoral model.
Key terms - quick answers
What is “Sectoral model”?
What is “HITECH Act (2009)”?
What is “HIPAA”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.