Approach CIPP/US by building a mapping method: for every fact pattern, identify the data type, the data holder, the relationship between them, and the enforcement authority. Study statutes as decision points rather than as isolated lists, then drill scenarios until assigning the correct law and enforcer becomes automatic.
Why the Sectoral Model, Not a Single Statute, Drives U.S. Privacy Questions
U.S. privacy law is sectoral: obligations attach by industry, data type, and relationship, and are enforced by multiple agencies, while states fill gaps with their own statutes. Mapping facts to the right regime is the central skill.
Unlike an omnibus model, where one law governs most personal data processing, the United States regulates vertically: financial services, healthcare, children's data, credit reporting, and communications each have dedicated statutes. Comprehensive federal legislation does not fill the spaces between them, so state legislatures have enacted their own omnibus and breach laws. A related concept, preemption, determines when a federal rule displaces state law and when state protections operate alongside it or exceed it.
Apply the model with four mapping questions: What kind of data is involved? Who holds it, and in what capacity? What is the relationship between holder and individual? Which agency or attorney general can actually enforce? Practicing this sequence on every practice question converts scattered statutes into one framework. A comparison table of the major federal statutes is a useful anchor for that framework.
- Sectoral model: rules attach to industries and relationships (banking, health, credit, children, telecom) rather than to all personal data.
- Omnibus model: one comprehensive statute with broad scope — the approach several states have adopted even though the federal level has not.
- Preemption: the doctrine deciding whether federal law overrides, coexists with, or leaves room for state rules — a frequent source of exam distinctions.
| Statute | Data or activity | Covered actors | Core obligation | Primary enforcer |
|---|---|---|---|---|
| GLBA | Nonpublic personal financial information | Financial institutions | Notice, opt-out for certain sharing, safeguards | FTC, CFPB, banking regulators |
| HIPAA | Protected health information | Covered entities and business associates | Privacy, Security, and Breach Notification Rules | HHS Office for Civil Rights |
| COPPA | Personal data of children under 13 | Operators of child-directed sites and services | Verifiable parental consent, notice | FTC |
| FCRA | Consumer reports | Consumer reporting agencies and users | Permissible purpose, disclosure, adverse action steps | FTC, CFPB |
| ECPA | Interception and stored communications | Broad, with exceptions | Wiretap Act limits; Stored Communications Act limits | DOJ; civil actions |
| TCPA | Calls and texts via automated equipment | Telemarketers and callers | Prior consent, Do-Not-Call obligations | FCC, FTC |
HIPAA Scope Traps: When Health Data Leaves Covered-Entity Ground
HIPAA covers protected health information held by covered entities and their business associates. Health data collected directly by consumer apps or retailers usually falls outside HIPAA and into FTC authority and state law instead.
The scope question is relationship-based, not data-based. Covered entities are health plans, healthcare providers that transmit certain transactions electronically, and healthcare clearinghouses; business associates are vendors that handle protected health information on their behalf. The same blood-pressure reading can be HIPAA-protected in a hospital system and entirely outside HIPAA when typed into a wellness app. The common mistake is assuming any health-related datum triggers HIPAA; the correct move is to trace who collected it and under what relationship.
Worked scenario: a fitness app collects sleep and heart-rate data from consumers and shares it with an advertiser. A plausible error is answering that the app violated HIPAA's minimum-necessary standard. The better decision: because the app is not a covered entity and not a business associate of one, HIPAA does not attach; the analysis shifts to the FTC's deception and unfairness authority, the agency's health-data notification rule, and any applicable state statutes. Why it matters: the enforcement authority, the obligations, and the remedies all change with that single scoping decision.
Communications and Marketing: Consent Means Different Things in Different Statutes
COPPA, the TCPA, CAN-SPAM, and the ECPA each define consent, notice, and covered conduct differently. Matching the channel, audience, and message type to the correct statute prevents wrong-answer traps.
Compare the consent mechanics directly. COPPA requires verifiable parental consent before collecting personal data from children under 13. The TCPA requires prior consent for calls or texts made with automated equipment for marketing purposes. CAN-SPAM, by contrast, does not require prior consent for commercial email; it requires truthful headers, an opt-out mechanism, and prompt honoring of opt-outs. The same word — consent — carries opposite defaults across these statutes, which is exactly the distinction a question stem can test.
The ECPA adds a second layer by splitting into two named concepts: the Wiretap Act, which addresses real-time interception of communications, and the Stored Communications Act, which addresses access to stored content held by providers. A question describing an employer reviewing an employee's inbox implicates the SCA and its exceptions; a question about a device recording a call as it happens implicates the Wiretap Act. Train yourself to spot the timing cue — live interception versus later retrieval — before choosing a rule.
State Breach Notification: Triggers Vary by State, Not by Judgment Call
Every state has its own breach law with distinct definitions of personal information, trigger events, timing, and exceptions such as encryption. Multi-state incidents demand a resident-by-resident analysis rather than one uniform response.
Most state statutes define personal information as a name combined with specific elements such as a Social Security number, driver's license number, or financial account number with an access code. Key variables to compare across states include whether the risk-of-harm threshold applies, whether encryption renders the data outside the statute, whether substitute notice is permitted for large populations, and whether attorney general or consumer reporting is required. Building a small matrix of these variables is more effective than memorizing any single state's timeline.
Worked scenario: a company loses an unencrypted laptop containing names and account numbers of customers in four states, one of which requires notice to the state attorney general under a lower threshold. A plausible mistake is applying the strictest state's rules to everyone or, worse, applying the home state's law only. The better decision: segment affected individuals by residency and map each cohort against that state's trigger and notice requirements. Why it matters: breach duties run to residents of each enacting state, so a single-instance response under-notifies some cohorts and misstates obligations for others.
Employee Monitoring and Background Checks: Two Compliance Paths in One Workplace
Workplace privacy combines ECPA interception rules and state monitoring-notice statutes with the FCRA whenever a third party supplies a background report. The correct path depends on whether the employer or a consumer reporting agency gathers the data.
When an employer obtains a background report from a consumer reporting agency, the FCRA supplies a defined sequence: a standalone disclosure and written authorization before the report is procured, and before taking an adverse action based on the report, a pre-adverse action notice with a copy of the report and a summary of rights, followed by a reasonable waiting period and a final adverse action notice. Skipping the pre-adverse step, or burying the disclosure inside a job application, is a classic violation pattern.
Direct monitoring follows different rules. The ECPA's exceptions can permit employers to intercept communications on their own systems in ordinary-course business or with consent, and several states impose their own notice requirements for electronic monitoring. Distinguish the two paths with one question: who collected the information? A suggested exercise: draft a single workplace scenario containing both a vendor-supplied background check and internal email monitoring, then split it into two separate data flows and label the governing statute and notice obligations for each flow independently. Practicing that split keeps the two compliance paths from blurring when a stem describes both.
Government Surveillance: Separating the Fourth Amendment, FISA, and the ECPA
Surveillance questions turn on who is acting and under what authority. Constitutional limits on government action, foreign-intelligence statutes, and statutory limits on interception are distinct frameworks with different tests.
The Fourth Amendment protects against unreasonable searches and is commonly analyzed through the reasonable expectation of privacy test; it constrains government actors, not private parties. The Foreign Intelligence Surveillance Act creates a separate regime for foreign intelligence gathering, with a specialized court approving applications, and later reforms reshaped how records are requested and added oversight mechanisms. Executive orders governing intelligence collection operate on yet another plane. Each framework has its own actor, purpose, and approval process.
Use two sorting cues before answering. First, identify the actor: a private citizen recording a call is an ECPA question, while a government investigator is a Fourth Amendment, statutory, or FISA question. Second, distinguish content from non-content metadata, because several authorities treat access to records differently from interception of communications. Fact patterns that mention courts, warrants, or foreign intelligence point toward the surveillance frameworks; patterns without a government actor should route you back to the private-party statutes covered earlier.
A Fact-Pattern Mapping Drill and Readiness Checks to Close Gaps
Convert each domain into a decision tree, then drill short fact patterns against it. Log errors by the misidentified statute or enforcer, not just by topic, and use self-check scores as learning milestones rather than outcome predictions.
Practical exercise: write ten one-paragraph scenarios spanning health apps, telemarketing texts, employee inbox reviews, vendor background checks, and multi-state breaches. For each, record four answers — data type, data holder, statute, enforcer — in under two minutes. Expected observations on a first pass: health-app scenarios get mislabeled as HIPAA matters, marketing scenarios conflate CAN-SPAM's opt-out model with the TCPA's consent model, and breach scenarios ignore resident segmentation. Those three clusters show you exactly which scope rules need another pass.
Self-check rubric: score each drill answer one point for a correct statute, one for a correct enforcer, and one for naming the controlling obligation. Eight or more of ten scenarios with all three points signals strong mapping fluency; below that, return to the comparison table before doing more questions. An adaptable sequence: spend the first phase building the decision trees per domain, the second drilling mixed fact patterns and logging error clusters, and the final phase alternating timed mixed sets with targeted rereading of the statutes your logs flag. Readiness checks: you can state each statute's covered actors from memory, you can explain HIPAA's relationship-based scope in two sentences, and your error log shows no repeated misidentification of an enforcement authority in the last two drill rounds.
References and further reading
Use these references to explore the concepts and check the latest information from the relevant organizations.
