CIPP/US Certification Privacy Law Compilation
by John Bandler
If you are reading this it is probably because you are preparing for the CIPP/US privacy certification exam, perhaps taking one of my online courses.
My CIPP/US online courses have the prioritized information you need first. My references pages on this site (including this page) are merely a supplemental resource to list laws, regulations, and regulators that are outlined in the IAPP CIPP/US Body of Knowledge (BoK).
I have greatly built out and realigned my webpages because there was too much to fit on just a few pages. I have now created new pages as I break the study into seven parts, including parts for each of the five domains in the BoK. Within each of those pages are considerable resources for that domain, rendering this page mostly moot (obsolete). See the next links section.
The only caveat is the CIPP/US organization by BoK is not perfect, and there is overlap among the domains.
Do not become intimidated by the size of my reference pages, including this one. It is easy to feel overwhelmed, but remember that you do not need to be a master of the detail of these laws. My courses have the prioritized information, the rest of this is for people who want more. Remember that only a small group of attorneys that choose to specialize in this area of privacy and cybersecurity laws.
Recap:
- CIPP/US stands for Certified Information Privacy Professional, United States and focuses on US privacy law and practice. The certification is administered by the IAPP
- IAPP stands for International Association of Privacy Professionals.
- What the CIPP/US calls "Privacy Law", includes other types of law relating to data, cybersecurity, data breach reporting, and more, including relating to discrimination, employment. It also covers a lot of traditional law.
If you are not ready for a deep dive yet into this area, here's some introductory materials on data law and privacy:
- Data law, https://johnbandler.com/data-law/
- What is Data law (YouTube), https://youtu.be/thyW3XoGrYg
- Privacy, https://johnbandler.com/privacy/
- What is Privacy (YouTube), https://youtu.be/xvdoZNULC-8
1. Links to John's 7 CIPP/US Parts plus more
- Main CIPP/US jump off page with links
- Part 1 CIPP/US: Intro to law, privacy, CIPP/US, and learning
- Part 2 CIPP/US: BoK I, Intro US Law and Privacy
- Part 3 CIPP/US: BoK II, Federal Privacy Law
- Part 4 CIPP/US: BoK III, Government Access
- Part 5 CIPP/US: BoK IV, Workplace Privacy
- Part 6 CIPP/US: BoK V, State Privacy Law
- Part 7 CIPP/US: Conclusion and Bring it Together
- Updates in CIPP/US
- FAQ on John's CIPP/US
2. My cyberlaw book and resources
My book on Cyberlaw has a lot about privacy (to include cybersecurity and breach notification) and I organized it the way I like. It also includes a solid introduction to law.
I have resource pages for each chapter too.
- Cyberlaw: Law for Digital Spaces and Information Systems (my 2025 book, see my chapter resource pages also)
- Chapter 29, Data law introduced
- Ch 29 resource page, https://johnbandler.com/cyberlawbook-resources-ch29/
- Chapter 30, Data breach notification laws
- Ch 30 resource page, https://johnbandler.com/cyberlawbook-resources-ch30/
- Chapter 31, Cybersecurity and data protection laws
- Ch 31 resource page, https://johnbandler.com/cyberlawbook-resources-ch31/
- Chapter 32, Privacy and privacy laws
- Ch 32 resource page, https://johnbandler.com/cyberlawbook-resources-ch32/
- Chapter 33, Artificial intelligence
- Ch 33 resource page, https://johnbandler.com/cyberlawbook-resources-ch33/
- Chapter 34, Data laws comprehensively
- Ch 34 resource page, https://johnbandler.com/cyberlawbook-resources-ch34/
- Chapter 29, Data law introduced
3. Here this page gets messy
I will start to ensure each of the below is placed into a page relating to the appropriate BoK part, then I may remove from this page.
Privacy regulators in the US
Here is a list of regulatory authorities emphasized in the BoK for having responsibilities relating to privacy.
- Federal Trade Commission (FTC) ***
- Federal Communications Commission (FCC)
- Department of Commerce (DoC)
- Department of Health and Human Services (HHS)
- Federal Reserve Board
- Comptroller of the Currency
- Consumer Financial Protection Bureau
- State attorneys general
- Self-regulatory programs and trust marks
- More!
U.S. agencies regulating workplace privacy issues
- Federal Trade Commission (FTC)
- Department of Labor
- Equal Employment Opportunity Commission (EEOC)
- National Labor Relations Board (NLRB)
- Occupational Safety and Health Act (OSHA)
- Securities and Exchange Commission (SEC)
Privacy frameworks to know
- APEC privacy framework, Asia-Pacific Economic Cooperation https://www.apec.org/
- OECD privacy framework, Organisation for Economic Co-operation and Development
Privacy laws listed in the CIPP US body of knowledge
Here is a list of specific privacy laws mentioned in the CIPP/US body of knowledge, with light annotations and some links.
Europe (important for the U.S.!)
- GDPR General Data Protection Regulation
- The text of GDPR can be found through https://ec.europa.eu/info/law/law-topic/data-protection/data-protection-eu_en
- https://commission.europa.eu/law/law-topic/data-protection/reform/rules-business-and-organisations_en
- Text of GDPR: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN
- IAPP GDPR topic page https://iapp.org/resources/topics/eu-gdpr/
- U.S. Safe Harbor and Privacy Shield
- Binding Corporate Rules (BCRs)
- Standard Contractual Clauses
US general
- The Federal Trade Commission Act
- The Children’s Online Privacy Protection Act of 1998 (COPPA)
- 15 U.S.C Chapter 91 - Children’s Online Privacy Protection Act, 15 USC §6501 et seq, https://www.law.cornell.edu/uscode/text/15/chapter-91
- 16 CFR Part 312 - Children's Online Privacy Protection Rule, 16 CFR §312. et seq, https://www.law.cornell.edu/cfr/text/16/part-312
Health
- The Health Insurance Portability and Accountability Act of 1996 (HIPAA)
- HIPAA privacy rule
- HIPAA security rule
- Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009
- The 21st Century Cures Act of 2016
- Confidentiality of Substance Use Disorder Patient Records Rule, 42 CFR Part 2
Financial
- The Fair Credit Reporting Act of 1970 (FCRA)
- The Fair and Accurate Credit Transactions Act of 2003 (FACTA)
- The Financial Services Modernization Act of 1999 (“Gramm-Leach-Bliley” or GLBA)
- GLBA privacy rule
- GLBA safeguards rule
- Red Flags Rule
- Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010
- Created Consumer Financial Protection Bureau
- Right to Financial Privacy Act of 1978
- Bank Secrecy Act of 1970 (BSA)
Education
- Family Educational Rights and Privacy Act of 1974 (FERPA)
Telecommunications - marketing - entertainment
- Telephone Consumer Protection Act of 1991 (TCPA)
- Telemarketing sales rule (TSR)
- The Do-Not-Call registry (DNC)
- Combating the Assault of Non-solicited Pornography and Marketing Act of 2003 (CAN-SPAM)
- The Junk Fax Prevention Act of 2005 (JFPA)
- The Wireless Domain Registry
- Telecommunications Act of 1996 and Customer Proprietary Network Information
- Cable Communications Privacy Act of 1984 (CCPA)
- Video Privacy Protection Act of 1988 (VPPA)
- Video Privacy Protection Act Amendments Act of 2012 (H.R. 6671) (VPPAAA)
Law enforcement
- Electronic Communications Privacy Act (ECPA)
- Wiretap Act
- Stored Communications Act (SCA)
- Pen Register Trap and Trace Devices
- The Communications Assistance to Law Enforcement Act (CALEA)
- Privacy Protection Act of 1980
National security
- Foreign Intelligence Surveillance Act of 1978 (FISA)
- Amendments Act: Section 702 (2008)
- USA-PATRIOT Act: Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act of 2001
- The USA Freedom Act of 2015
- The Cybersecurity Information Sharing Act of 2015 (CISA)
U.S. Anti-discrimination laws
- Civil Rights Act of 1964
- Americans with Disabilities Act (ADA)
- Genetic Information Nondiscrimination Act (GINA)
State laws
Remember again that privacy, cybersecurity, and breach notification laws often overlap. And federal and state enforcement can overlap too.
IAPP has great summaries of state laws and they are changing rapidly. Here is the list of laws specifically mentioned in recent BOKs. You cannot be expected to master every state's law.
State “privacy" and "security" laws
- Illinois Biometric Information Privacy Act (BIPA) (2008)
- California Electronic Communications Privacy Act (2015)
- California Consumer Privacy Act (CCPA) (2018)
- California Privacy Rights Act (CPRA) (2020)
- Note that California has created a separate privacy regulator, the California Privacy Protection Agency (CPPA) (unlike other states where the state Attorney General does privacy and cybersecurity regulation and enforcement)
- Delaware Online Privacy and Protection Act (2016)
- Nevada SB 538 (2017)
- Illinois Right to Know Act (2017)
- New Jersey Personal Information and Privacy Protection Act (2017)
- Washington Biometric Privacy Law (H.B. 1493) (2017)
- NYDFS Cybersecurity Regulation (financial sector) (2017)
- Virginia Consumer Data Protection Act (VCDPA) (2021)
- Colorado Privacy Act (CPA) 2021
- Nevada Privacy Law & Amendment (SB280) (2019/2021)
- Connecticut Data Privacy Act (CTDPA) (2022)
- Utah Consumer Privacy Act (UCPA) (2022)
- California Age-Appropriate Design Code Act (A.B. 2273) (2022)
State “Data Breach Notification Laws”
Remember that every state now has a data breach notification law. Recent BoK's have mentioned these laws.
- Tennessee SB 2005
- Illinois HB 1260
- California AB 2828
- New Mexico HB 15
- Massachusetts HB 4806
Also consider
- NYS SHIELD Act (2019) (not mentioned in the BoK but is my home state, a notification and security law)
Additional privacy laws you should know about
Take a look at some of my other articles on this site and at the IAPP site.
Conclusion and Disclaimer
The CIPP/US is an excellent certification from an excellent organization, and studying for it will give you an excellent foundation in law and privacy (and laws relating to information security).
I prepared the CIPP/US study course on the Udemy platform, and another one before that for another platform. I learn a lot each time I build a course or update it. I think you will learn a lot studying this material.
See other CIPP/US and law references on this site and remember this is just a brief summary and that IAPP is the final authority on the certification and body of knowledge that they administer.
- My Udemy course was originally geared for lawyers and law students, but many non-lawyers have taken it too. It is on the Udemy learning platform, and you can purchase it for under $20, including with my coupon code.
- Another course is geared for information security professionals, on the Infosec Skills learning platform (they were bought by Cengage, and that platform is subscription based).
-
This page is hosted at https://johnbandler.com/cipp-us-certification-law-compilation. Copyright John Bandler, all rights reserved. No claim to legal materials.
Please notify me of any corrections or updates.
Page posted 12/09/2021. Page updated 08/13/2026 but law links need work, and construction in progress.
