Federal sector laws — HIPAA, GLBA, FCRA, COPPA, and ECPA — account for roughly 30–35% of the CIPP/US exam. They are tested through scenario questions that require knowing not just what each law covers, but who it applies to, what the key definitions mean in practice, and how enforcement works. HIPAA and FCRA receive the most granular treatment; COPPA and ECPA are tested at a framework level.
The CIPP/US exam is fundamentally different from the CIPP/E in one structural way: instead of one comprehensive framework (GDPR), it tests a mosaic of sector-specific federal laws, state laws, and constitutional principles. The federal sector laws — the ones passed by Congress for specific industries — account for a substantial portion of Domain II and Domain IV questions.
Candidates who come from EU privacy backgrounds often underestimate this section, assuming that US privacy law is simpler or thinner than GDPR. It is not thinner — it is fragmented. The challenge is that each federal law has its own scope, its own definitions, its own enforcement mechanism, and its own exceptions. This guide covers the five federal laws that generate the most exam questions.
Why Federal Sector Laws Are Hard to Study
Three things make this section harder than it looks:
Each law has a different definition of "covered entity." HIPAA's covered entities are health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically — and their business associates. GLBA's financial institutions are companies that offer financial products or services to individuals. FCRA's consumer reporting agencies are entities that assemble consumer reports for others. Getting the scope wrong means applying the wrong law to a scenario.
The laws have been amended. HIPAA was amended by HITECH (2009) and the 2013 Omnibus Rule, which extended HIPAA obligations directly to Business Associates. GLBA's Safeguards Rule was substantially updated in 2023. FCRA has been amended by FACTA and the FACT Act. The exam tests the current versions — candidates using older study materials may learn outdated rules.
The enforcement models differ. HIPAA is enforced by HHS OCR with civil and criminal penalties. FCRA gives individuals a private right of action alongside FTC enforcement. GLBA is enforced by multiple agencies depending on the type of financial institution. Understanding who enforces what, and what remedies are available, is testable.
HIPAA / HITECH — The Most Tested Federal Law
Protected Health Information (PHI): Individually identifiable health information held or transmitted by a covered entity or business associate in any form — electronic, paper, or oral. The 18 HIPAA identifiers (name, address, dates, SSN, phone, etc.) define when information is individually identifiable. De-identified information (using either the Safe Harbor or Expert Determination method) is not PHI and falls outside HIPAA's restrictions.
Covered Entities vs. Business Associates: Covered entities are health plans, healthcare clearinghouses, and healthcare providers who transmit PHI electronically. Business Associates are persons or entities that perform functions on behalf of a covered entity involving PHI — and HITECH made BAs directly liable for HIPAA compliance, not just contractually obligated. A BA's subcontractor that handles PHI is a subcontractor BA, also directly liable.
The Minimum Necessary Standard: Covered entities must make reasonable efforts to use, disclose, and request only the minimum PHI necessary to accomplish the intended purpose. Treatment disclosures are exempt from the minimum necessary requirement — a treating physician can access the full record.
Breach Notification: Covered entities must notify affected individuals within 60 days of breach discovery. Breaches affecting 500+ individuals in a state require simultaneous prominent media notification. HHS must be notified within 60 days; breaches under 500 can be logged and reported annually. The "harm threshold" — risk of financial, reputational, or other harm — determines whether an impermissible use constitutes a reportable breach.
- Right of Access: individuals have the right to access their own PHI within 30 days (extendable once by 30 days with written notice)
- Notice of Privacy Practices: covered entities must provide NPP at first service delivery
- Authorization vs. Consent: treatment, payment, and operations generally don't require individual authorization; other uses do
HIPAA sets a federal floor. States can and do enact stronger health privacy protections — California's CMIA, for example, provides broader restrictions on disclosure than HIPAA. HIPAA preempts state laws that are less protective; it does not preempt laws that are more protective. The exam tests this preemption principle: when state law and HIPAA conflict, the more protective law generally governs.
GLBA — Financial Services Privacy
Scope — Financial Institutions: GLBA applies to companies "significantly engaged" in financial activities — banks, credit unions, securities firms, insurance companies, mortgage lenders, tax preparers, and payday lenders, among others. The FTC enforces GLBA for non-bank financial institutions.
Nonpublic Personal Information (NPI): Personally identifiable financial information provided by, resulting from, or obtained in connection with a financial product or service to a consumer. Publicly available information is excluded.
Privacy Notice Requirement: Financial institutions must provide a clear and conspicuous privacy notice to customers at the start of the relationship and annually thereafter, describing what NPI they collect, how they share it, and the consumer's right to opt out.
Opt-Out Right: Consumers have the right to opt out of disclosure of their NPI to non-affiliated third parties (subject to exceptions for service providers, joint marketing agreements, and law enforcement). There is no right to opt out of sharing with affiliates — though some state laws add that right.
Safeguards Rule (2023 Update): The 2023 FTC update to the Safeguards Rule significantly strengthened requirements for non-bank financial institutions. Key additions: designated qualified individual to oversee the information security program, periodic risk assessments, penetration testing, access controls, encryption of customer information in transit and at rest, and written incident response plan. Covered institutions with fewer than 5,000 customer records are exempt from some provisions.
FCRA — Credit Reporting and Consumer Information
Consumer Report Definition: Any written, oral, or other communication by a Consumer Reporting Agency (CRA) bearing on a consumer's creditworthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living — used to establish eligibility for credit, employment, housing, or insurance. The definition is broad; a background check firm providing a report for employment screening is a CRA and the report is a consumer report.
Permissible Purpose: A CRA can only furnish a consumer report for enumerated permissible purposes — credit transactions, employment, insurance underwriting, government licensing, and a narrow catch-all for "legitimate business need." Using a consumer report for any other purpose is a cognizable FCRA violation. The exam will give scenarios where someone accesses a consumer report and ask whether the permissible purpose exists.
Adverse Action Requirements: When an employer, lender, or insurer takes adverse action based on a consumer report (declining credit, not hiring, raising premiums), they must: (1) provide pre-adverse action notice with a copy of the report and a summary of rights; (2) allow a reasonable waiting period; (3) provide a final adverse action notice. Missing any step is an FCRA violation with private right of action consequences.
Dispute Process: Consumers have the right to dispute inaccurate or incomplete information in their consumer report. The CRA must investigate within 30 days (45 days if the consumer submits additional information), notify the furnisher, and correct or delete inaccurate information.
- Free annual credit report: consumers are entitled to one free disclosure from each nationwide CRA per year (AnnualCreditReport.com)
- FACTA additions: fraud alerts, credit freezes, identity theft provisions
- Private right of action: consumers can sue for willful or negligent FCRA violations
COPPA — Children's Online Privacy
Scope: Applies to operators of commercial websites and online services directed to children under 13, or operators with actual knowledge they are collecting personal information from children under 13. "Directed to children" is assessed by subject matter, visual content, music, animated characters, and similar indicators — not solely by intent.
Verifiable Parental Consent (VPC): Before collecting personal information from a child under 13, operators must obtain VPC. Acceptable VPC methods include: signed consent form returned by mail or fax, credit card transaction (for fee-based services), video conference with the parent, and similar verification mechanisms. Age-gating alone (asking the user their birthdate) is insufficient — COPPA requires actual verification.
Operator Obligations: Post a clear and comprehensive privacy notice on the site. Provide parents direct notice before collection. Give parents the right to review and delete their child's information. Not condition a child's participation on providing more information than reasonably necessary. Maintain reasonable security for children's data.
FTC Enforcement: The FTC enforces COPPA; civil penalties up to $51,744 per violation. The FTC has brought significant enforcement actions against YouTube ($170M settlement), TikTok ($5.7M settlement), and others for COPPA violations. State AGs can also enforce COPPA.
ECPA — Electronic Communications and Employer Monitoring
Two Distinct Titles: The Wiretap Act (Title I) prohibits intentional interception of wire, oral, or electronic communications in real time. The Stored Communications Act (SCA, Title II) restricts access to stored electronic communications — emails, messages in cloud storage. These are different legal standards; the exam tests whether you know which applies to a given scenario.
Consent Exception: Interception is not unlawful when one party to the communication consents (federal one-party consent standard). Many states require all-party consent — California, Illinois, Michigan, and others. When federal and state law conflict on this point, the more protective state standard governs for intrastate communications. This distinction is heavily tested in employer monitoring scenarios.
Employer Monitoring: Employers can generally monitor workplace communications systems under the business extension exception (monitoring of communications using equipment provided in the ordinary course of business) and the consent exception (employees who are notified and consent to monitoring). The exam tests the limits: monitoring personal emails on a work device may exceed the business extension exception; monitoring a personal device generally requires consent.
Government Access under SCA: Law enforcement seeking stored communications must use a subpoena, court order, or search warrant depending on the content type and age of the communications. Communications stored more than 180 days were historically accessible via subpoena (no warrant needed) under the pre-Carpenter framework — the SCA's complex access rules are testable.
The exam frequently gives you a scenario and asks which federal law applies — or which law does not apply. The discrimination exercise is as important as knowing what each law covers. A question about a bank's employee background check involves FCRA (not HIPAA, not GLBA). A question about a hospital using a cloud EHR vendor involves HIPAA Business Associate rules (not GLBA). Know the scope of each law precisely.
Other Federal Laws Tested on the CIPP/US
Beyond the five covered above, the CIPP/US also tests several additional federal laws at a lighter level:
| Law | Coverage Area | Exam Depth |
|---|---|---|
| FERPA | Student education records; parental rights transferring to students at 18; directory information | Medium — frequently appears in scenario format |
| VPPA | Video rental/streaming service subscriber disclosure; civil liability for unauthorized disclosure of video viewing records | Light — know the scope and what it prohibits |
| CAN-SPAM | Commercial email requirements: identification, opt-out mechanism, honoring opt-outs within 10 days | Medium — specific requirements are testable |
| ADA | Accessibility in employment and public accommodations; limited privacy intersections | Light — appears in employment scenarios |
| Privacy Act of 1974 | Federal agencies' collection and use of personal information about US citizens; individual rights to access and correct records | Medium — Domain III (government access) |
The CIPP/US exam is ultimately about pattern recognition across a broad legal landscape. Once you understand what each law is designed to protect and who it applies to, scenario questions become significantly more tractable — even when the specific fact pattern is unfamiliar. For the current domain weights and overall exam structure, see the CIPP/US 2026 domain and state law overview.