Legislation and Federal Preemption
Both Congress and state legislatures enact privacy laws. The key question is whether a federal law preempts state law: HIPAA lets states pass stricter rules, while CAN-SPAM preempts stricter state email rules.
How this supports CIPP/US study
Use this lesson to identify the legal source, actor, data and activity before applying a rule to a scenario. Continue with the CIPP/US exam format and blueprint.
Both the federal Congress and state legislatures enact privacy and security laws, regulating uses of information, certain industries, certain data elements, or specific harms. Law-making power is shared: under the Tenth Amendment, powers not delegated to the federal government are reserved to the states.
The critical analysis is whether a federal law preempts - overrides - state law on the subject. Sometimes federal law sets a floor states may exceed; sometimes it bars stricter state rules entirely.
| Law | Effect on state law |
|---|---|
| HIPAA Privacy Rule | States MAY pass stricter requirements (federal sets a floor) |
| CAN-SPAM Act (commercial email) | Federal PREEMPTS stricter state law; states cannot impose greater obligations |
A classic trap: HIPAA allows stricter state laws, but CAN-SPAM preempts them. Memorize which way each cuts.
Key terms - quick answers
What is “Preemption”?
What is “Tenth Amendment”?
What is “CAN-SPAM Act”?
What is “HIPAA”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.