Part 3 of John's CIPP/US Privacy Materials
Federal Privacy and Cybersecurity Laws, BoK II
by John Bandler
This is Part 3 of my U.S. law, privacy and CIPP/US learning materials (aligning with CIPP/US BoK Domain II).
+ This page is greatly updated and mostly comprehensive after a recent revamp in August 2026 +
1. To navigate John's CIPP/US pages
2. Topics covered
Here we cover federal privacy laws, meaning federal laws that relate to privacy, cybersecurity, and data breach notifications. Or "federal civil data law".
We don't cover issues relating to privacy from law enforcement here (that's in the next domain, Part 4, BoK III). We don't cover state data laws (that's BoK V, Part 6).
Still I try to weave in comparisons or mentions about each, so you get used to the difference.
IAPP renamed the title of this domain, and I'm glad they did, but the basic content remains very similar. The current name is "Federal Privacy Law", the prior name was "Limits on Private-sector Collection and Use of Data". That old name never sat well for me. "Limits" really meant "laws", and the domain was always primarily about federal laws, and state laws are the subject of an entirely different domain (BoK V).
This area of "privacy law" is also called "data law", encompassing privacy, cybersecurity, and data breach notifications. My short articles and videos on cyberlaw, data law, and privacy lay that out, but remember there's differing terminology and understandings out there.
In this domain it is about privacy from private companies.
If we want to learn about privacy from government, that's in a different domain and in my Fourth Amendment resources.
This is an important domain, since federal law is important. We see how the U.S. does things sector-by-sector for many areas of privacy (also known as the sectoral model). This domain essentially covers:
- Federal Trade Commission (FTC), authority (FTC Act) and their role in privacy and cybersecurity consumer protection and enforcement
- Much privacy is across various sectors
- Privacy for children: Children’s Online Privacy Protection Act of 1998 (COPPA)
- Healthcare and Medical Sector Privacy Laws and Regulations
- Health Insurance Portability and Accountability Act of 1996 (HIPAA)
- Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009
- Health Insurance Portability and Accountability Act of 1996 (HIPAA)
- Financial Sector Privacy Laws and Regulations
- The Fair Credit Reporting Act of 1970 (FCRA)
- The Fair and Accurate Credit Transactions Act of 2003 (FACTA)
- The Financial Services Modernization Act of 1999 (“Gramm-Leach-Bliley” or GLBA)
- Education Sector Privacy Laws and Regulations
- Family Educational Rights and Privacy Act of 1974 (FERPA)
- Telecommunications and Marketing Privacy and Laws
- Telephone Consumer Protection Act of 1991 (TCPA)
- Telemarketing sales rule (TSR)
- The Do-Not-Call registry (DNC)
- Combating the Assault of Non-solicited Pornography and Marketing Act of 2003 (CAN-SPAM)
- The Junk Fax Prevention Act of 2005 (JFPA)
Federal enforcement and priorities can change significantly with different administrations, and it is fair to say the changes have been unprecedented since early 2025. There have been extensive layoffs in most federal agencies, consumer protection has been deprioritized and reduced, there are plans to disband the Department of Education, which oversees FERPA.
3. Don't forget the overall references for CIPP/US and my courses
- See my Part 1 webpage for the overall references and additional reading (including IAPP resources)
- My online courses provide priority coverage of important areas, so if you are in my online course, listen to those first.
- I have created two online courses to help people learn about privacy and prepare for this certification exam.
- My Udemy CIPP/US course was originally geared for lawyers and law students, but many non-lawyers have taken it too. It is on the Udemy learning platform, and you can purchase it for under $20, including with my coupon code.
- Another course is geared for information security professionals on the Infosec Skills subscription based learning platform (Infosec Skills was bought by online education behemoth Cengage).
- If you are taking one of my online courses and want to dig deeper into the materials, I provide resources and references here. Prioritize your time, start by learning the basics before digging into the weeds.
- If you are not taking one of my online courses, that's OK too, I hope they help you, and please consider this.
4. Part 3 specific references
- See my Part 1 course for the overall references and additional reading (including IAPP resources, the coursebook, etc.)
- My courses provide priority coverage of important areas. If you want to dig deeper (or are not taking one of my courses) see these resources.
Part 3 prioritization: As always, start with the basics. There are a lot of federal regulators and laws, so become familiar with them through repetition to achieve understanding. Obtain reliable information on current events, especially regarding actions by the federal executive branch, since there have been many changes since January 2025, and continues to evolve rapidly. Keep your focus on the solid core of federal privacy laws. There are some obscure laws (e.g., end of the health section) so skip over my detailed research and links.
Key Cyberlaw book parts and chapters relating to this domain include:
- Part 6: Civil Cyberlaw II: Data Law, Cybersecurity Law, and Privacy Law (Chapters 29-34)
- Chapter 29, Data law introduced
- Ch 29 resource page, https://johnbandler.com/cyberlawbook-resources-ch29/
- Chapter 30, Data breach notification laws
- Ch 30 resource page, https://johnbandler.com/cyberlawbook-resources-ch30/
- Chapter 31, Cybersecurity and data protection laws
- Ch 31 resource page, https://johnbandler.com/cyberlawbook-resources-ch31/
- Chapter 32, Privacy and privacy laws
- Ch 32 resource page, https://johnbandler.com/cyberlawbook-resources-ch32/
- Chapter 33, Artificial intelligence
- Ch 33 resource page, https://johnbandler.com/cyberlawbook-resources-ch33/
- Chapter 34, Data laws comprehensively
- Ch 34 resource page, https://johnbandler.com/cyberlawbook-resources-ch34/
- Chapter 29, Data law introduced
4.1 FTC, FTC Act, COPPA
- FTC and FTC Act
- FTC Act (article), https://johnbandler.com/ftc-act/
- FTC Act § 5(a), 15 U.S.C. § 45(a)(1). https://www.law.cornell.edu/uscode/text/15/45
- FTC main: https://www.ftc.gov/
- FTC, What we do, https://www.ftc.gov/about-ftc/what-we-do
- FTC, Enforcement Authority, https://www.ftc.gov/about-ftc/what-we-do/enforcement-authority
- FTC, Privacy and Security, https://www.ftc.gov/business-guidance/privacy-security
- FTC, Consumer Privacy, https://www.ftc.gov/business-guidance/privacy-security/consumer-privacy
- FTC, Children's Privacy, https://www.ftc.gov/business-guidance/privacy-security/childrens-privacy
- FTC, Data Security, https://www.ftc.gov/business-guidance/privacy-security/data-security
- FTC Legal Library, Cases and Proceedings, https://www.ftc.gov/legal-library/browse/cases-proceedings
- FTC and privacy and security, https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement
- FTC, Protecting Personal Information, A Guide for Business, https://www.ftc.gov/system/files/documents/plain-language/pdf-0136_proteting-personal-information.pdf
- COPPA
- The Children’s Online Privacy Protection Act of 1998 (COPPA)
- COPPA Act, 15 U.S.C. § 6501-6506, https://www.law.cornell.edu/uscode/text/15/chapter-91
- COPPA regulations 16 C.F.R. § 312, https://www.law.cornell.edu/cfr/text/16/part-312
- FTC, Children's Privacy, https://www.ftc.gov/business-guidance/privacy-security/childrens-privacy
4.2 Health (medical) sector privacy, HIPAA, HITECH
- Health Sector Cyber Laws and Regulations, https://johnbandler.com/health-sector-laws-and-regulations/
- Department of Health and Human Services (HHS), https://www.hhs.gov/ (federal regulator)
- HHS on HIPAA, https://www.hhs.gov/hipaa/index.html
- HHS: Summary of the HIPAA Security Rule, https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html
- The HIPAA regulations (Rules)
- 45 CFR Part 160 - General Administrative Requirements, https://www.law.cornell.edu/cfr/text/45/part-160
- 45 CFR Part 164 - Security and Privacy [and notification] https://www.law.cornell.edu/cfr/text/45/part-164
- Security Rule: See 45 CFR 164 Subparts A and C
- Privacy Rule: See 45 CFR 164 Subparts A and E
- Breach Notification Rule: See 45 CFR 164 Subpart D
- Health Insurance Portability and Accountability Act (HIPAA) of 1996, Public Law 104-191, Aug 21, 1996, 104th Congress (PDF) https://www.govinfo.gov/content/pkg/PLAW-104publ191/pdf/PLAW-104publ191.pdf
- Also available at:
- Public Law 104-191, Aug 21, 1996, 104th Congress (text) https://www.govinfo.gov/content/pkg/PLAW-104publ191/html/PLAW-104publ191.htm
- S. Statutes at Large, 110 Stat. 1936, https://www.govinfo.gov/content/pkg/STATUTE-110/pdf/STATUTE-110-Pg1936.pdf#page=1
- Hippocratic Oath on Wikipedia, https://en.wikipedia.org/wiki/Hippocratic_Oath
For these next health related subcategories, don’t go down a rabbit hole, just understand the basics of them, skip most of my links.
Substance abuse confidentiality
- Confidentiality of Substance Use Disorder Patient Records Rule, 42 CFR Part 2, https://www.law.cornell.edu/cfr/text/42/part-2
- 1970 Comprehensive Alcohol Abuse and Alcoholism Prevention, Treatment and Rehabilitation Act
- 1972 Drug Abuse Prevention, Treatment and Rehabilitation Act
- Regulations (rules)
21st Century Cures Act of 2016
This is an enormous law with some privacy provisions, so learn the basic privacy provisions but don’t read the law.
- Links to the law (don’t go there,
- 21st CCA at GovInfo as amended, https://www.govinfo.gov/content/pkg/COMPS-13005/uslm/COMPS-13005.xml
- 21st CCA as originally passed, https://www.govinfo.gov/content/pkg/PLAW-114publ255/uslm/PLAW-114publ255.xml
- 21st CCA rule (regulation) at 45 CFR Parts 170 and 171
- 45 CFR Part 170 - Health Information Technology Standards, Implementation Specifications, and Certification Criteria and Certification Programs for Health Information Technology, https://www.law.cornell.edu/cfr/text/45/part-170
- 45 CFR Part 171 - Information Blocking, https://www.law.cornell.edu/cfr/text/45/part-171
2008 Genetic Information Nondiscrimination Act (GINA)
- U.S. Equal Employment Opportunity Commission (EEOC), https://www.eeoc.gov/
- EEOC on GINA, https://www.eeoc.gov/gina-genetic-information-nondiscrimination
- EEOC What You Should Know on GINA..., https://www.eeoc.gov/laws/guidance/what-you-should-know-questions-and-answers-about-genetic-information
- EEOC, Genetic Information Discrimination, https://www.eeoc.gov/genetic-information-discrimination
- 42 U.S. Code Chapter 21F - Prohibiting Employment Discrimination on the Basis Of Genetic Information, https://www.law.cornell.edu/uscode/text/42/chapter-21F
- 29 C.F.R. Part 1635 [regulation regarding] Genetic Information Nondiscrimination Act of 2008, https://www.law.cornell.edu/cfr/text/29/part-1635
- S. Department of Labor (DoL), https://www.dol.gov
- DoL, The Genetic Information Nondiscrimination Act of 2008: "GINA", https://www.dol.gov/agencies/oasam/centers-offices/civil-rights-center/statutes/genetic-information-nondiscrimination-act-of-2008/guidance
- GINA Law text, https://www.govinfo.gov/content/pkg/PLAW-110publ233/pdf/PLAW-110publ233.pdf
4.3 Financial sector, GLBA, Red Flags, FACTA, AML
- Financial Sector Laws and Regulations, https://johnbandler.com/financial-sector-cyber-laws-regulations/
Financial sector laws and regulations include:
- The Fair Credit Reporting Act of 1970 (FCRA)
- The Fair and Accurate Credit Transactions Act of 2003 (FACTA)
- Disposal Rule
- Red Flags Rule (2013 ID Theft Red Flags Rule from SEC and CFTC)
- The Financial Services Modernization Act of 1999 (“Gramm-Leach-Bliley” or GLBA), and the GLBA Privacy Rule and GLBA Safeguards (security) Rule.
- Red Flags Rule
- Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010
- Consumer Financial Protection Bureau (CFPB)
- Bank Secrecy Act (BSA) of 1970 and amendments
- USA PATRIOT Act of 2001 and amendments
Financial sector federal regulators include:
- Consumer Financial Protection Bureau (CFPB), https://www.consumerfinance.gov/
- Federal Reserve Board (FRB or “the Fed”), https://www.federalreserve.gov/
- Federal Deposit Insurance Corporation (FDIC), https://www.fdic.gov/
- Office of Comptroller of the Currency (OCC), https://www.occ.treas.gov/
- National Credit Union Administration (NCUA), https://ncua.gov/
- Securities and Exchange Commission (SEC), https://www.sec.gov/ (for publicly held companies, securities, stocks, etc.)
- Public Company Accounting Oversight Board (PCAOB), https://pcaobus.org/
- Commodity Futures Trading Commission (CFTC), https://www.cftc.gov/
- Financial Industry Regulatory Authority (FINRA), https://www.finra.org/
- Federal Financial Institutions Examination Council (FFIEC), https://www.ffiec.gov/ (not a regulator per se, but a body of federal financial regulators that establishes common federal standards)
- Financial Crimes Enforcement Network (FinCEN), https://www.fincen.gov/
- Federal Trade Commission (FTC), https://www.ftc.gov/
GLBA
- GLBA: The Financial Services Modernization Act of 1999 (“Gramm-Leach-Bliley” or GLBA), 15 U.S. Code Chapter 94, Privacy, https://www.law.cornell.edu/uscode/text/15/chapter-94
- GLBA "Privacy Rule": 16 CFR Part 313 - Privacy of Consumer Financial Information, https://www.law.cornell.edu/cfr/text/16/part-313
- GLBA "Safeguards Rule": 16 CFR Part 314 - Standards for Safeguarding Customer Information, https://www.law.cornell.edu/cfr/text/16/part-314
- FTC, FTC Amends Safeguards Rule to Require Non-Banking Financial Institutions to Report Data Security Breaches, https://www.ftc.gov/news-events/news/press-releases/2023/10/ftc-amends-safeguards-rule-require-non-banking-financial-institutions-report-data-security-breaches
- FTC, Privacy and Security Enforcement, https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement
FCRA
- The Fair Credit Reporting Act of 1970 (FCRA), including The Fair and Accurate Credit Transactions Act of 2003 (FACTA), 15 USC 1681 et seq, https://www.law.cornell.edu/uscode/text/15/chapter-41
- FTC on FACTA, https://www.ftc.gov/legal-library/browse/statutes/fair-accurate-credit-transactions-act-2003
- FTC on FCRA, https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act
- The Red Flags Rule published at 16 C.F.R. § 681.1, Duties regarding the detection, prevention, and mitigation of identity theft, https://www.law.cornell.edu/cfr/text/16/681.1
- FTC on Red Flags Rule, https://www.ftc.gov/business-guidance/privacy-security/red-flags-rule
AML, CTF, BSA, financial investigation
- See Cyberlaw, Chapter 19, Western Express Cybercrime Case, and Chapter 22, Virtual currency and money laundering
- See Cybercrime Investigations Chapter 15, Financial Investigation, Following the Cybercrime Money
- Money Laundering, https://johnbandler.com/money-laundering/
- Virtual Currency and Cryptocurrency References, https://johnbandler.com/virtual-currency-references/
- See Part 4, Domain III
4.4 Education – FERPA
- U.S. Department of Education, https://www.ed.gov/
- Family Educational Rights and Privacy Act of 1974 (FERPA)
- 20 US Code § 1232g, Family Educational and Privacy Rights, https://www.law.cornell.edu/uscode/text/20/1232g
- 34 CFR Part 99 - Family Educational Rights and Privacy, https://www.law.cornell.edu/cfr/text/34/part-99
- ED FERPA resource, Protecting Student Privacy https://studentprivacy.ed.gov/node/548/
- AI Tools Will Not do it All for You, https://johnbandler.com/ai-tools-will-not-do-it-all-for-you/
- AI's promise and problem for law and learning, February 21, 2024 (Reuters), https://johnbandler.com/ai-promise-and-problem/
- Protection of Pupil Rights Amendment (PPRA) of 1978 to FERPA
- No Child Left Behind Act of 2001
- Every Student Succeeds Act (2015)
- See COPPA
- AI in education: do your research, see my thoughts
- AI Tools Will Not do it All for You, https://johnbandler.com/ai-tools-will-not-do-it-all-for-you/
- AI's promise and problem for law and learning, February 21, 2024 (Reuters), https://johnbandler.com/ai-promise-and-problem/
- Cyberlaw (2025) Chapter 3.
4.5 Telecommunications and marketing privacy and laws
- Federal Trade Commission (FTC), https://www.ftc.gov/
- Federal Communications Commission (FCC), https://www.fcc.gov/
- Telephone Consumer Protection Act of 1991 (TCPA)
- 15 US Code Chapter 87, Telemarketing and Consumer Fraud and Abuse Prevention, https://www.law.cornell.edu/uscode/text/15/chapter-87
- Telemarketing and Consumer Fraud and Abuse Prevention Act of 1994
- 15 U.S.C. §§ 6101-6108, https://www.law.cornell.edu/uscode/text/15/6101
- Telemarketing Sales Rule (TSR)
- 16 CFR Part 310, Telemarketing Sales Rule, https://www.law.cornell.edu/cfr/text/16/part-310
- FTC Do Not Call Registry, https://www.donotcall.gov/
- Junk Fax Prevention Act of 2005 (JFPA)
- 47 CFR Part 64 - Subpart L - Restrictions on Telemarketing, Telephone Solicitation, and Facsimile Advertising, https://www.law.cornell.edu/cfr/text/47/part-64/subpart-L
- Controlling the Assault of Non-solicited Pornography and Marketing Act of 2003 (CAN-SPAM), 15 U.S.C §§ 7701-7713, https://www.law.cornell.edu/uscode/text/15/7701
- 15 U.S. Code Chapter 103, Controlling the Assault of Non-Solicited Pornography and Marketing, https://www.law.cornell.edu/uscode/text/15/chapter-103
- Telecommunications Act of 1996
- Cable Communications Privacy Act of 1984
- Video Privacy Protection Act of 1988 (VPPA)
- Video Privacy Protection Act Amendments Act of 2012 (H.R. 6671)
- Driver's Privacy Protection Act of 1994 (DPPA)
- FCC broadband privacy rule (short lived. 2015 rule, 2016 court decision, rescinded 2017 by act of Congress)
Digital advertising, data ethics
- Digital advertising, online tracking, webscraping
- Data ethics: Do your research and consider these too
- Ethics, https://johnbandler.com/ethics/
- S. Federal Data Strategy 2020 Action Plan (likely not to be followed by current administration)
- data.gov, U.S. Office of Management and Budget, https://resources.data.gov/
- Federal Data Strategy Data Ethics Framework (2020 or so), https://resources.data.gov/assets/documents/fds-data-ethics-framework.pdf
- Chief Data Officers Council, https://www.councils.gov/cdoc/
- Wikipedia, Big data ethics, https://en.wikipedia.org/wiki/Big_data_ethics
- Dataversity, https://www.dataversity.net/what-are-data-ethics/
- Alan Turing Institute, https://www.turing.ac.uk/research/publications/what-data-ethics
AI: Do your research and consider these
- Cyberlaw Ch 33 resources, https://johnbandler.com/cyberlawbook-resources-ch33/
- Biden White House AI policy statements and executive orders (2022ish, later rescinded by Trump administration) (emphasizing safety, anti-discrimination, privacy, notice, human alternatives and fallbacks)
- Trump White House AI policy 2025ish (rescinding Biden policies, “eliminating barriers” “preventing woke AI” “pro-innovation” “rather than...risk-averse”),
- Trump White House AI June 2026 (more concerns about security and safety), https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/
5. Conclusion
Remember, don't let the size of this references page intimidate you, and you don't have to visit all the links nor read them all.
I'm just sharing my research for those who want to dive deeper in a particular area.
This lets you start your research where I left off. Do your own research and I don't promise to keep this updated.
This page is hosted at https://johnbandler.com/cippus/part3. Copyright John Bandler, all rights reserved. No claim to IAPP materials or legal references.
Page posted 3/22/2026, drawing upon my previous materials. This page updated 08/11/2026.
These pages will always remain a work-in-progress and I cannot guarantee to keep them accurate or updated. Please contact me if you have an update, suggestion, or correction, and if these free resources helped you, please consider this to give back.

