Chapter 5: Federal and State Regulators and Enforcement of Privacy Law

Federal Privacy Enforcement Outside the FTC

Many federal agencies enforce privacy depending on the statute violated: OCR/HHS for HIPAA, CFPB and bank regulators for GLBA, Dept. of Education for FERPA, FCC for TCPA, and EEOC for the ADA. The FTC may have overlapping responsibility.

How this supports CIPP/US study

Use this lesson to connect a privacy programme decision with the relevant regulator, duty or enforcement route. Continue with the CIPP/US exam questions.

Who enforces what (sectoral federal regulators)
Sector / lawLead agency
Medical - HIPAAOCR (HHS)
Financial - GLBACFPB and federal financial regulators (Federal Reserve, OCC)
Education - FERPAU.S. Department of Education
Telecom / marketing - TCPAFCC
Workplace - ADA and antidiscriminationEEOC and others
Overlap is the trap

The FTC may have overlapping responsibilities with these sector agencies. On the exam, match the statute to its primary regulator (HIPAA to OCR (HHS), GLBA to CFPB/bank regulators, FERPA to Education, TCPA to FCC) - and watch that the FTC is not the answer for sector-specific statutes.

Agencies can apply existing sectoral and civil-rights frameworks to AI. For example, OCR (HHS) administers HIPAA protections for covered health information, while the EEOC enforces federal employment discrimination law when employers use algorithmic tools.

Key terms - quick answers

What is “OCR (HHS)”?
The Office for Civil Rights within HHS, which enforces HIPAA.
What is “HIPAA”?
The Health Insurance Portability and Accountability Act, governing protected health information held by covered entities.
What is “CFPB”?
The Consumer Financial Protection Bureau, generally responsible for financial consumer-protection issues.
What is “GLBA”?
The Gramm-Leach-Bliley Act, governing nonpublic personal information held by financial institutions.

Sources and study method

This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.