Part 3 of John's CIPP/US Privacy MaterialsJohn Bandler’s CIPP/US and US Privacy Learning Part 3

Federal Privacy and Cybersecurity Laws, BoK II

by John Bandler

This is Part 3 of my U.S. law, privacy and CIPP/US learning materials (aligning with CIPP/US BoK Domain II).

+ This page is greatly updated and mostly comprehensive after a recent revamp in August 2026 +

1. To navigate John's CIPP/US pages

2. Topics covered

Here we cover federal privacy laws, meaning federal laws that relate to privacy, cybersecurity, and data breach notifications. Or "federal civil data law".

We don't cover issues relating to privacy from law enforcement here (that's in the next domain, Part 4, BoK III). We don't cover state data laws (that's BoK V, Part 6).

Still I try to weave in comparisons or mentions about each, so you get used to the difference.

IAPP renamed the title of this domain, and I'm glad they did, but the basic content remains very similar. The current name is "Federal Privacy Law", the prior name was "Limits on Private-sector Collection and Use of Data". That old name never sat well for me. "Limits" really meant "laws", and the domain was always primarily about federal laws, and state laws are the subject of an entirely different domain (BoK V).

This area of "privacy law" is also called "data law", encompassing privacy, cybersecurity, and data breach notifications. My short articles and videos on cyberlaw, data law, and privacy lay that out, but remember there's differing terminology and understandings out there.

In this domain it is about privacy from private companies.

If we want to learn about privacy from government, that's in a different domain and in my Fourth Amendment resources.

This is an important domain, since federal law is important. We see how the U.S. does things sector-by-sector for many areas of privacy (also known as the sectoral model). This domain essentially covers:

  • Federal Trade Commission (FTC), authority (FTC Act) and their role in privacy and cybersecurity consumer protection and enforcement
    • Much privacy is across various sectors
    • Privacy for children: Children’s Online Privacy Protection Act of 1998 (COPPA)
  • Healthcare and Medical Sector Privacy Laws and Regulations
    • Health Insurance Portability and Accountability Act of 1996 (HIPAA)
      • Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009
  • Financial Sector Privacy Laws and Regulations
    • The Fair Credit Reporting Act of 1970 (FCRA)
    • The Fair and Accurate Credit Transactions Act of 2003 (FACTA)
    • The Financial Services Modernization Act of 1999 (“Gramm-Leach-Bliley” or GLBA)
  • Education Sector Privacy Laws and Regulations
    • Family Educational Rights and Privacy Act of 1974 (FERPA)
  • Telecommunications and Marketing Privacy and Laws
    • Telephone Consumer Protection Act of 1991 (TCPA)
    • Telemarketing sales rule (TSR)
    • The Do-Not-Call registry (DNC)
    • Combating the Assault of Non-solicited Pornography and Marketing Act of 2003 (CAN-SPAM)
    • The Junk Fax Prevention Act of 2005 (JFPA)

Federal enforcement and priorities can change significantly with different administrations, and it is fair to say the changes have been unprecedented since early 2025. There have been extensive layoffs in most federal agencies, consumer protection has been deprioritized and reduced, there are plans to disband the Department of Education, which oversees FERPA.

3. Don't forget the overall references for CIPP/US and my courses

  • See my Part 1 webpage for the overall references and additional reading (including IAPP resources)
  • My online courses provide priority coverage of important areas, so if you are in my online course, listen to those first.
  • If you are taking one of my online courses and want to dig deeper into the materials, I provide resources and references here. Prioritize your time, start by learning the basics before digging into the weeds.
  • If you are not taking one of my online courses, that's OK too, I hope they help you, and please consider this.

4. Part 3 specific references

  • See my Part 1 course for the overall references and additional reading (including IAPP resources, the coursebook, etc.)
  • My courses provide priority coverage of important areas. If you want to dig deeper (or are not taking one of my courses) see these resources.

Part 3 prioritization: As always, start with the basics. There are a lot of federal regulators and laws, so become familiar with them through repetition to achieve understanding. Obtain reliable information on current events, especially regarding actions by the federal executive branch, since there have been many changes since January 2025, and continues to evolve rapidly. Keep your focus on the solid core of federal privacy laws. There are some obscure laws (e.g., end of the health section) so skip over my detailed research and links.

Key Cyberlaw book parts and chapters relating to this domain include:Cyberlaw by John Bandler front cover

4.1 FTC, FTC Act, COPPA

4.2 Health (medical) sector privacy, HIPAA, HITECH

For these next health related subcategories, don’t go down a rabbit hole, just understand the basics of them, skip most of my links.

Substance abuse confidentiality

  • Confidentiality of Substance Use Disorder Patient Records Rule, 42 CFR Part 2, https://www.law.cornell.edu/cfr/text/42/part-2
  • 1970 Comprehensive Alcohol Abuse and Alcoholism Prevention, Treatment and Rehabilitation Act
  • 1972 Drug Abuse Prevention, Treatment and Rehabilitation Act
  • Regulations (rules)

21st Century Cures Act of 2016

This is an enormous law with some privacy provisions, so learn the basic privacy provisions but don’t read the law.

2008 Genetic Information Nondiscrimination Act (GINA)

4.3 Financial sector, GLBA, Red Flags, FACTA, AML

Financial sector laws and regulations include:

  • The Fair Credit Reporting Act of 1970 (FCRA)
  • The Fair and Accurate Credit Transactions Act of 2003 (FACTA)
    • Disposal Rule
    • Red Flags Rule (2013 ID Theft Red Flags Rule from SEC and CFTC)
  • The Financial Services Modernization Act of 1999 (“Gramm-Leach-Bliley” or GLBA), and the GLBA Privacy Rule and GLBA Safeguards (security) Rule.
  • Red Flags Rule
  • Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010
  • Consumer Financial Protection Bureau (CFPB)
  • Bank Secrecy Act (BSA) of 1970 and amendments
  • USA PATRIOT Act of 2001 and amendments

Financial sector federal regulators include:

GLBA

FCRA

 AML, CTF, BSA, financial investigation

4.4 Education – FERPA

4.5 Telecommunications and marketing privacy and laws

Digital advertising, data ethics

AI: Do your research and consider these

5. Conclusion

Remember, don't let the size of this references page intimidate you, and you don't have to visit all the links nor read them all.

I'm just sharing my research for those who want to dive deeper in a particular area.

This lets you start your research where I left off. Do your own research and I don't promise to keep this updated.

 

This page is hosted at https://johnbandler.com/cippus/part3. Copyright John Bandler, all rights reserved. No claim to IAPP materials or legal references.

Page posted 3/22/2026, drawing upon my previous materials. This page updated 08/11/2026.

These pages will always remain a work-in-progress and I cannot guarantee to keep them accurate or updated. Please contact me if you have an update, suggestion, or correction, and if these free resources helped you, please consider this to give back.