Part 2 of my CIPP/US Privacy MaterialsJohn Bandler’s CIPP/US and US Privacy Learning Part 2

Introduction to U.S. Law and the U.S. Privacy Environment, BoK I

by John Bandler

This is Part 2 of my U.S. law, privacy and CIPP/US learning materials, aligning with CIPP/US BoK I (and Section 2, or Course 2 in my online courses).

+ This page is greatly updated and mostly comprehensive after a recent revamp in August 2026 +

1. To navigate John's CIPP/US pages

2. Topics covered

Here we cover an introduction to U.S. law and U.S. privacy law, and to information governance. This tracks CIPP/US Body of Knowledge (BoK) Domain I. This is the most heavily tested portion of the CIPP/US exam, and one of my favorites because of it's emphasis on basic U.S. law.

A nation of laws that is a democracy needs its citizens to understand basic law. In my years teaching cyberlaw and privacy, I have realized how many people need solid, simply presented materials on basic law, and have developed those over the years.

This is the biggest domain, covering the most ground, and is the most tested. It's one of my favorites because it is solidly at the intersection of cyber and law. It includes these subdomains:

  • U.S. Legal Framework
    • Branches of government, sources of law, legal concepts
  • U.S. Enforcement of Privacy and Cybersecurity Laws
    • Our diverse and widespread (confusing) array of regulators and enforcers, state and federal, liability theories, etc.
  • U.S. Information Management
    • Data management principles, incident response, privacy programs and policies and notices, vendor management, international transfers and issues.

If you are strong on either of these topics, it's still an excellent refresher for you, and you will learn something new, or view it with a new perspective.

Do not let the length of this page intimidate you. I am sharing my research for those that want to dive deeper into a particular area, and you don't need to read everything listed on this page. Be realistic on the time you can spend, and how long it takes to read particular resources, and prioritize your time. Learn the basics first.

3. Don't forget the overall references for CIPP/US and my courses

  • See my Part 1 webpage for the overall references and additional reading (including IAPP resources)
  • My online courses provide priority coverage of important areas, so if you are in my online course, listen to those first.
  • If you are taking one of my online courses and want to dig deeper into the materials, I provide resources and references here. Prioritize your time, start by learning the basics before digging into the weeds.
  • If you are not taking one of my online courses, that's OK too, I hope they help you, and please consider this.

4. Part 2 specific references

  • See my Part 1 course for the overall references and additional reading (including IAPP resources, the coursebook, etc.)
  • My courses provide priority coverage of important areas. If you want to dig deeper (or are not taking one of my courses) see these resources.

Part 2 prioritization: Start with the basics on U.S. law, privacy, and information management (information governance). As we walk through the body of knowledge (BoK) in the videos, we touch on lots of different topics, and references are provided for that, but following all those references would be a rabbit-hole.

Relevant Cyberlaw book parts and chapters relating to this domain include:Cyberlaw by John Bandler front cover

  • Part 2: Introducing Law and Our Legal System (Chapters 4-12)
  • Part 3: Entering the Digital Domain of “Cyberspace”: Introducing Technology, Cybersecurity, Cybercrime, and Data Privacy Issues (Chapters 13-18)
  • Part 6: Civil Cyberlaw II: Data Law, Cybersecurity Law, and Privacy Law (Chapters 29-34)
  • Part 9: Organization Management and Cyberlaws (Chapters 37-41)

4.1 Introductory law, cyberlaw, data law, privacy law  (I built companion videos which you can watch at bottom of each webpage, or directly at YouTube)

4.2 Intro to regulators and the laws and regulations they enforce

4.3 Federal regulators and their links

Remember that a federal regulator may have multiple regulatory responsibilities, so we focus on their data law, privacy, and cybersecurity regulations and enforcement authorities and actions. These regulators cover general, communications, commerce, health, education, finance, workplace, and more.

4.4 Some state regulators and their links

Part 6 (Domain V) dives into state privacy and cybersecurity laws, so this is just an introduction.

California’s comprehensive privacy law is called the California Consumer Privacy Act (CCPA). The California Privacy Rights Act (CPRA) was a ballot initiative that amended CCPA.

4.5 Information governance, cybersecurity, and cybercrime

Organizations need privacy programs, cybersecurity programs, and so forth. That is part of the process of information governance.

I have more resources on information governance, privacy policies, programs, and notices, but one step at a time.

4.6 NIST frameworks for privacy and cybersecurity

These are respected and free, you should know they exist. Start with my explainer articles, then see what NIST says about them, then if you have time read the actual framework.

4.7 International privacy rules, cross border transfers into the U.S., etc.

Prioritize with basics on the U.S. Department of Commerce, Data Privacy Framework (DPF) Program, and basics on GDPR, APEC, and GPEN (from OECD), and the concept of getting data into the U.S. from another country. DPF is the current method for data transfer to the U.S. from the European Union (EU) and other countries. (DPF is the successor to the “Privacy Shield” program which was deemed invalid in 2020, and to “Safe Harbor” which was deemed invalid in 2015).

Again, stick with the basics. Realize this is complicated and you are not expected to become an international privacy lawyer for this certification. And just because I provide a link here doesn't mean you have to read it (but I didn't want to keep my research to myself).

U.S. DPF

EU GDPR

Switzerland FADP

APEC

OECD - GPEN

4.8 Privacy programs, policies, notices, policy work, etc.

Part of information governance is managing the privacy program, cybersecurity, creating and updating policies, notices, procedures, etc.

4.9 Incident response

4.10 Vendor management

5. Conclusion

Remember, don't let the size of this references page intimidate you, and you don't have to visit all the links nor read them all.

I'm just sharing my research for those who want to dive deeper in a particular area.

This lets you start your research where I left off. Do your own research and I don't promise to keep this updated.

 

This page is hosted at https://johnbandler.com/cippus/part2. Copyright John Bandler, all rights reserved. No claim to IAPP materials or legal references.

Page posted 3/22/2026, drawing upon my previous materials. This page updated 08/10/2026.

These pages will always remain a work-in-progress and I cannot guarantee to keep them accurate or updated. Please contact me if you have an update, suggestion, or correction, and if these free resources helped you, please consider this to give back.