Part 2 of my CIPP/US Privacy Materials
Introduction to U.S. Law and the U.S. Privacy Environment, BoK I
by John Bandler
This is Part 2 of my U.S. law, privacy and CIPP/US learning materials, aligning with CIPP/US BoK I (and Section 2, or Course 2 in my online courses).
+ This page is greatly updated and mostly comprehensive after a recent revamp in August 2026 +
1. To navigate John's CIPP/US pages
2. Topics covered
Here we cover an introduction to U.S. law and U.S. privacy law, and to information governance. This tracks CIPP/US Body of Knowledge (BoK) Domain I. This is the most heavily tested portion of the CIPP/US exam, and one of my favorites because of it's emphasis on basic U.S. law.
A nation of laws that is a democracy needs its citizens to understand basic law. In my years teaching cyberlaw and privacy, I have realized how many people need solid, simply presented materials on basic law, and have developed those over the years.
This is the biggest domain, covering the most ground, and is the most tested. It's one of my favorites because it is solidly at the intersection of cyber and law. It includes these subdomains:
- U.S. Legal Framework
- Branches of government, sources of law, legal concepts
- U.S. Enforcement of Privacy and Cybersecurity Laws
- Our diverse and widespread (confusing) array of regulators and enforcers, state and federal, liability theories, etc.
- U.S. Information Management
- Data management principles, incident response, privacy programs and policies and notices, vendor management, international transfers and issues.
If you are strong on either of these topics, it's still an excellent refresher for you, and you will learn something new, or view it with a new perspective.
Do not let the length of this page intimidate you. I am sharing my research for those that want to dive deeper into a particular area, and you don't need to read everything listed on this page. Be realistic on the time you can spend, and how long it takes to read particular resources, and prioritize your time. Learn the basics first.
3. Don't forget the overall references for CIPP/US and my courses
- See my Part 1 webpage for the overall references and additional reading (including IAPP resources)
- My online courses provide priority coverage of important areas, so if you are in my online course, listen to those first.
- I have created two online courses to help people learn about privacy and prepare for this certification exam.
- My Udemy CIPP/US course was originally geared for lawyers and law students, but many non-lawyers have taken it too. It is on the Udemy learning platform, and you can purchase it for under $20, including with my coupon code.
- Another course is geared for information security professionals on the Infosec Skills subscription based learning platform (Infosec Skills was bought by online education behemoth Cengage).
- If you are taking one of my online courses and want to dig deeper into the materials, I provide resources and references here. Prioritize your time, start by learning the basics before digging into the weeds.
- If you are not taking one of my online courses, that's OK too, I hope they help you, and please consider this.
4. Part 2 specific references
- See my Part 1 course for the overall references and additional reading (including IAPP resources, the coursebook, etc.)
- My courses provide priority coverage of important areas. If you want to dig deeper (or are not taking one of my courses) see these resources.
Part 2 prioritization: Start with the basics on U.S. law, privacy, and information management (information governance). As we walk through the body of knowledge (BoK) in the videos, we touch on lots of different topics, and references are provided for that, but following all those references would be a rabbit-hole.
Relevant Cyberlaw book parts and chapters relating to this domain include:
- Part 2: Introducing Law and Our Legal System (Chapters 4-12)
- Part 3: Entering the Digital Domain of “Cyberspace”: Introducing Technology, Cybersecurity, Cybercrime, and Data Privacy Issues (Chapters 13-18)
- Part 6: Civil Cyberlaw II: Data Law, Cybersecurity Law, and Privacy Law (Chapters 29-34)
- Part 9: Organization Management and Cyberlaws (Chapters 37-41)
4.1 Introductory law, cyberlaw, data law, privacy law (I built companion videos which you can watch at bottom of each webpage, or directly at YouTube)
- Rules, https://johnbandler.com/rules/
- Law, https://johnbandler.com/law/
- What is Law (YouTube), https://youtu.be/t0nBK26-5n4
- Cyberlaw, https://johnbandler.com/cyberlaw/
- What is Cyberlaw (YouTube), https://youtu.be/lLG3WhY6BHY
- Data law, https://johnbandler.com/data-law/
- What is Data law (YouTube), https://youtu.be/thyW3XoGrYg
- Privacy, https://johnbandler.com/privacy/
- What is Privacy (YouTube), https://youtu.be/xvdoZNULC-8
- Law in the United States Introduced, https://johnbandler.com/law-in-united-states-introduced/
- The United States Constitution and Amendments (including Bill of Rights), https://johnbandler.com/us-constitution/
- Criminal Law vs. Civil Law, https://johnbandler.com/criminal-law-vs-civil-law/
- Criminal law, https://johnbandler.com/criminal-law/
- Civil law, https://johnbandler.com/civil-law/
- Introduction to Law (an outline) https://johnbandler.com/introduction-to-law-outline/
- Ethics, https://johnbandler.com/ethics/
- Cyberlaw (2025) Part 2, Chapters 4-12 is an introduction to law and the U.S. legal system. See chapter-by-chapter resources starting at https://johnbandler.com/cyberlawbook-resources/
4.2 Intro to regulators and the laws and regulations they enforce
- The FTC Act and the FTC, https://johnbandler.com/ftc-act/
- Health Sector Cyber Laws and Regulations, https://johnbandler.com/health-sector-laws-and-regulations/
- Financial Sector Cyber Laws and Regulations, https://johnbandler.com/financial-sector-cyber-laws-regulations/
- New York Cybersecurity Requirements and the SHIELD Act, https://johnbandler.com/new-york-cybersecurity-requirements-and-the-shield-act/
4.3 Federal regulators and their links
Remember that a federal regulator may have multiple regulatory responsibilities, so we focus on their data law, privacy, and cybersecurity regulations and enforcement authorities and actions. These regulators cover general, communications, commerce, health, education, finance, workplace, and more.
- Federal Trade Commission (FTC), https://www.ftc.gov/
- Federal Communications Commission (FCC), https://www.fcc.gov/
- Department of Commerce (DoC), https://www.commerce.gov/
- Department of Health and Human Services (HHS), https://www.hhs.gov/
- U.S. Department of Education, https://www.ed.gov/
- Consumer Financial Protection Bureau (CFPB), https://www.consumerfinance.gov/
- Federal Reserve Board (FRB or “the Fed”), https://www.federalreserve.gov/
- Federal Deposit Insurance Corporation (FDIC), https://www.fdic.gov/
- Office of Comptroller of the Currency (OCC), https://www.occ.treas.gov/
- National Credit Union Administration (NCUA), https://ncua.gov/
- Securities and Exchange Commission (SEC), https://www.sec.gov/ (for publicly held companies, securities, stocks, etc.)
- Public Company Accounting Oversight Board (PCAOB), https://pcaobus.org/
- Commodity Futures Trading Commission (CFTC), https://www.cftc.gov/
- Financial Industry Regulatory Authority (FINRA), https://www.finra.org/
- Federal Financial Institutions Examination Council (FFIEC), https://www.ffiec.gov/ (not a regulator per se, but a body of federal financial regulators that establishes common federal standards)
- Financial Crimes Enforcement Network (FinCEN), https://www.fincen.gov/
- U.S. Department of Labor, https://www.dol.gov/
- Equal Employment Opportunity Commission (EEOC), https://www.eeoc.gov/
- National Labor Relations Board (NLRB), https://www.nlrb.gov/
- Occupational Safety and Health Administration (OSHA), https://www.osha.gov/
- More
4.4 Some state regulators and their links
- New York State (NYS) Attorney General, https://ag.ny.gov/
- New York State (NYS) Department of Financial Services (DFS), https://www.dfs.ny.gov/
- California Attorney General, https://oag.ca.gov/
- California Privacy Protection Agency (CPPA), https://cppa.ca.gov/
- See for your state
Part 6 (Domain V) dives into state privacy and cybersecurity laws, so this is just an introduction.
California’s comprehensive privacy law is called the California Consumer Privacy Act (CCPA). The California Privacy Rights Act (CPRA) was a ballot initiative that amended CCPA.
4.5 Information governance, cybersecurity, and cybercrime
Organizations need privacy programs, cybersecurity programs, and so forth. That is part of the process of information governance.
- Information governance (information management), https://johnbandler.com/information-governance/
- Information system, https://johnbandler.com/information-system/
- Technology Basics, https://johnbandler.com/technology-basics/
- Technology things to know, https://johnbandler.com/things-to-know-technology/
- Cybersecurity, https://johnbandler.com/cybersecurity/
- Cybersecurity landing page, https://johnbandler.com/cybersecurity-landing1/
- Cybersecurity things to know, https://johnbandler.com/things-to-know-cybersecurity/
- Cybercrime, https://johnbandler.com/cybercrime/
- The Three Priority Cybercrime Threats, https://johnbandler.com/priority-cybercrime-threats/
- Identity theft, https://johnbandler.com/identity-theft/
- Policies, Procedures, and Governance of an Organization, https://johnbandler.com/policies-procedures-and-governance-of-an-organization/
- Cyberlaw (2025) Part 3, Chapters 13-18 is an introduction to cyber, including technology, cybersecurity, cybercrime, and the need for privacy. See chapter-by-chapter resources starting at https://johnbandler.com/cyberlawbook-resources/
- Cyberlaw (2025) Part 9, Chapters 37-41 discusses organization management regarding cyber and data issues. See chapter-by-chapter resources starting at https://johnbandler.com/cyberlawbook-resources/
I have more resources on information governance, privacy policies, programs, and notices, but one step at a time.
4.6 NIST frameworks for privacy and cybersecurity
These are respected and free, you should know they exist. Start with my explainer articles, then see what NIST says about them, then if you have time read the actual framework.
- About the NIST Privacy Framework, https://johnbandler.com/nist-privacy-framework/
- About the NIST Cybersecurity Framework, https://johnbandler.com/nist-cybersecurity-framework/
- NIST Privacy Framework landing page, https://www.nist.gov/privacy-framework
- NIST Privacy Framework v 1.0, https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.01162020.pdf
- NIST Privacy Framework v 1.1 (Draft), https://www.nist.gov/privacy-framework/new-projects/privacy-framework-version-11
- NIST Cybersecurity Framework landing page, https://www.nist.gov/cyberframework
- NIST Cybersecurity Framework (CSF) v 2.0, https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf
4.7 International privacy rules, cross border transfers into the U.S., etc.
Prioritize with basics on the U.S. Department of Commerce, Data Privacy Framework (DPF) Program, and basics on GDPR, APEC, and GPEN (from OECD), and the concept of getting data into the U.S. from another country. DPF is the current method for data transfer to the U.S. from the European Union (EU) and other countries. (DPF is the successor to the “Privacy Shield” program which was deemed invalid in 2020, and to “Safe Harbor” which was deemed invalid in 2015).
Again, stick with the basics. Realize this is complicated and you are not expected to become an international privacy lawyer for this certification. And just because I provide a link here doesn't mean you have to read it (but I didn't want to keep my research to myself).
U.S. DPF
- U.S. Data Privacy Framework (DPF) Program, https://www.dataprivacyframework.gov/
- Data Privacy Framework (DPF) Program Overview, https://www.dataprivacyframework.gov/Program-Overview
- EU-U.S. Data Privacy Framework, https://www.dataprivacyframework.gov/EU-US-Framework
- DPF FAQs – Swiss–U.S. Data Privacy Framework, https://www.dataprivacyframework.gov/program-articles/FAQs%20%E2%80%93%20Swiss%E2%80%93U.S.-Data-Privacy-Framework-(Swiss%E2%80%93U.S.-DPF)-(1%E2%80%934)
EU GDPR
- European Union’s General Data Protection Regulation (GDPR) main site, https://ec.europa.eu/info/index_en
Switzerland FADP
- Swiss Federal Act on Data Protection (FADP) of 2020, https://www.fedlex.admin.ch/eli/cc/2022/491/en
APEC
- Asia-Pacific Economic Cooperation (APEC), https://www.apec.org/
- APEC Privacy Framework (2015), https://www.apec.org/publications/2017/08/apec-privacy-framework-(2015)
- Guidebook on APEC Privacy and Trustmark, https://www.apec.org/publications/2012/11/guidebook-on-apec-privacy-and-trustmark
- Enabling Legal Compliance & Cross-Border Data Transfers with the APEC Cross-Border Privacy Rules (2016), https://www.apec.org/publications/2016/11/enabling-legal-compliance-crossborder-data-transfers-with-the-apec-crossborder-privacy-rules-cbpr
- APEC Cross-Border Privacy Rules System goes public, https://www.apec.org/press/news-releases/2012/0731_cbpr
OECD - GPEN
- Organisation for Economic Co-operation and Development, https://www.oecd.org/en.html
- OECD Privacy principles, https://www.oecd.org/en/topics/privacy-principles.html
- GPEN (from OECD): https://www.privacyenforcement.net/
- GPEN Action Plan (adopted 15 June 2012; Part E amended 22 January 2013; amended December 2022 and October 2023), https://www.privacyenforcement.net/content/action-plan-global-privacy-enforcement-network-gpen
- GPEN Action Plan (adopted 15 June 2012; Part E amended 22 January 2013; amended December 2022 and October 2023), https://www.privacyenforcement.net/content/action-plan-global-privacy-enforcement-network-gpen
- Privacy Online, OECD Guidance on Policy and Practice (2003), https://www.oecd.org/en/publications/privacy-online_9789264101630-en.html
- OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data (2002), https://www.oecd.org/en/publications/oecd-guidelines-on-the-protection-of-privacy-and-transborder-flows-of-personal-data_9789264196391-en.html
- Recommendation of the Council concerning Guidelines Governing the Protection of Privacy and Transborder Flows of Personal Data, https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0188
- Cross‑border Data Flows, https://www.oecd.org/en/publications/cross-border-data-flows_5031dd97-en.html
- Transborder flows of personal data, https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0188
- Review of the OECD Recommendation on Cross‑Border Co‑operation in the Enforcement of Laws Protecting Privacy, https://www.oecd.org/en/publications/review-of-the-oecd-recommendation-on-cross-border-co-operation-in-the-enforcement-of-laws-protecting-privacy_67774f69-en.html
- Explanatory memoranda of the OECD Privacy Guidelines, https://www.oecd.org/en/publications/explanatory-memoranda-of-the-oecd-privacy-guidelines_ea4e9759-en.html
4.8 Privacy programs, policies, notices, policy work, etc.
Part of information governance is managing the privacy program, cybersecurity, creating and updating policies, notices, procedures, etc.
- Policies and Procedures for Your Organization: Build solid governance documents on any topic ... including cybersecurity (2024), https://johnbandler.com/policiesbook/
- Policy and Procedure References, https://johnbandler.com/policy-and-procedure-references/
- Cyberlaw: Law for Digital Spaces and Information Systems (2025), https://johnbandler.com/cyberlawbook/
- Five Components for Policy Work and Management, https://johnbandler.com/five-components-for-policy-work/
- Three Platforms to Connect for Compliance, https://johnbandler.com/bandlers-three-platforms-to-connect/
- Fourth Platform to Connect for Policy Work and Management, https://johnbandler.com/bandlers-fourth-platform-to-connect/
- Policies, Procedures, and Governance of an Organization, https://johnbandler.com/policies-procedures-and-governance-of-an-organization/
- Policies and procedures (and other governance documents), https://johnbandler.com/policies-and-procedures/
- Your organization's privacy policy — and privacy notice, John Bandler, October 16, 2024, Reuters Legal News, https://johnbandler.com/organization-privacy-policy-notice/
- Project management, https://johnbandler.com/project-management/
- Document project management, https://johnbandler.com/document-project-management/
- Policy checklist, https://johnbandler.com/policy-checklist/
- Writing, https://johnbandler.com/writing/
4.9 Incident response
- Incident response, https://johnbandler.com/incident-response/
- NIST Special Publication 800, NIST SP 800-61r3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management, Version 3, April 2025, https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r3.pdf
- Cybercrime Investigations: A Comprehensive Resource for Everyone (2020), https://johnbandler.com/cybercrime-investigations/
- See my other resources on information governance, policies, cybersecurity, and cybercrime.
- See NIST resources relating to cybersecurity and privacy
4.10 Vendor management
- See about incident response regarding vendor incidents
- Introduction to Contract Law, https://johnbandler.com/contract-law/
- About the NIST Privacy Framework, https://johnbandler.com/nist-privacy-framework/
- About the NIST Cybersecurity Framework, https://johnbandler.com/nist-cybersecurity-framework/
- NIST SP 800-161r1-upd1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations, https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161r1-upd1.pdf
- Best Practices in Vendor Selection and Management, (2015?), https://csrc.nist.gov/CSRC/media/Projects/Supply-Chain-Risk-Management/documents/briefings/Workshop-Brief-on-Cyber-SCRM-Vendor-Selection-and-Management.pdf
- NIST Cybersecurity Framework v 2.0, https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf
- NIST Privacy Framework v 1.0, https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.01162020.pdf
- Delta v CrowdStrike and the 2024 outage, https://johnbandler.com/delta-v-crowdstrike-and-2024-outage/ (example of incident with vendor)
5. Conclusion
Remember, don't let the size of this references page intimidate you, and you don't have to visit all the links nor read them all.
I'm just sharing my research for those who want to dive deeper in a particular area.
This lets you start your research where I left off. Do your own research and I don't promise to keep this updated.
This page is hosted at https://johnbandler.com/cippus/part2. Copyright John Bandler, all rights reserved. No claim to IAPP materials or legal references.
Page posted 3/22/2026, drawing upon my previous materials. This page updated 08/10/2026.
These pages will always remain a work-in-progress and I cannot guarantee to keep them accurate or updated. Please contact me if you have an update, suggestion, or correction, and if these free resources helped you, please consider this to give back.

