Federal Privacy Enforcement Outside the FTC
Many federal agencies enforce privacy depending on the statute violated: OCR/HHS for HIPAA, CFPB and bank regulators for GLBA, Dept. of Education for FERPA, FCC for TCPA, and EEOC for the ADA. The FTC may have overlapping responsibility.
How this supports CIPP/US study
Use this lesson to connect a privacy programme decision with the relevant regulator, duty or enforcement route. Continue with the CIPP/US exam questions.
| Sector / law | Lead agency |
|---|---|
| Medical - HIPAA | OCR (HHS) |
| Financial - GLBA | CFPB and federal financial regulators (Federal Reserve, OCC) |
| Education - FERPA | U.S. Department of Education |
| Telecom / marketing - TCPA | FCC |
| Workplace - ADA and antidiscrimination | EEOC and others |
The FTC may have overlapping responsibilities with these sector agencies. On the exam, match the statute to its primary regulator (HIPAA to OCR (HHS), GLBA to CFPB/bank regulators, FERPA to Education, TCPA to FCC) - and watch that the FTC is not the answer for sector-specific statutes.
Agencies can apply existing sectoral and civil-rights frameworks to AI. For example, OCR (HHS) administers HIPAA protections for covered health information, while the EEOC enforces federal employment discrimination law when employers use algorithmic tools.
Key terms - quick answers
What is “OCR (HHS)”?
What is “HIPAA”?
What is “CFPB”?
What is “GLBA”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.