The complete study library
Find your next study resource
Search 706 free study resources across CIPP/E, CIPP/US and AIGP. Find a lesson, review a term or choose a practice session.
706 resources
No matching resources
Try a broader term or reset the search to see the complete library.
CIPP/E exam format and blueprint
Current CIPP/E format, timing and how to use the published IAPP Body of Knowledge and Exam Blueprint.
Guide · CIPP/ECIPP/E exam questions
How to approach CIPP/E questions using scope, legal basis, rights, accountability and enforcement.
Guide · CIPP/ECIPP/E practice exam
Independent CIPP/E practice questions, a timed-study method and an evidence-led review routine.
Guide · CIPP/ECIPP/E study guide
A free CIPP/E study guide structured around the published IAPP outline and active recall.
Guide · CIPP/ECIPP/E study plan
A four-week CIPP/E study plan using the published outline, retrieval practice and scenario questions.
Practice · CIPP/ECIPP/E cram sheet
The complete CIPP/E memorisation sheet: key dates, fines and numbers, the principles, lawful bases, rights, transfers, cases and the classic exam traps.
Practice · CIPP/EFind the CIPP/E areas to study next.
Take a free 10-question CIPP/E diagnostic. Get an immediate domain score and a personalised study plan without creating an account.
Glossary · CIPP/ECIPP/E glossary
Plain-language definitions for recurring terms in the CIPP/E study guide.
Guide · CIPP/EHow to pass the CIPP/E
How to prepare for the IAPP CIPP/E exam using current format details, a flexible study plan, common mistakes and exam-style practice.
Guide · CIPP/EIs the CIPP/E exam hard?
Is the CIPP/E exam hard? Format, pass mark, domain weights, where candidates struggle and a practical way to prepare.
Practice · CIPP/EFree CIPP/E mini mock
Try 25 exam-style CIPP/E practice questions free, with explanations and a domain score. No account or payment required.
Practice · CIPP/EWhich of these is NOT a data-protection consideration for CCTV under the training?
Which of these is NOT a data-protection consideration for CCTV under the training? Answer with a worked explanation and related free lesson.
Lesson · CIPP/EAccountability and telling the principles apart
The GDPR reinforces every principle by adding accountability: it places the burden of proof on organisations to demonstrate proper implementation, and…
Lesson · CIPP/EAccuracy
The accuracy principle requires controllers to take reasonable measures to keep personal data accurate and, where necessary, up to date. This means…
Lesson · CIPP/EAdministrative fines: the two tiers and how they are set (Article 83)
The fines regime (Article 83) has two tiers. The lower tier (Art 83(4)) caps fines at €10 million or 2% of total worldwide annual turnover, whichever is…
Lesson · CIPP/EAdtech legal basis and automated decisions
Adtech relies on either consent or legitimate interest. Consent is hard: it must be informed and demonstrable, and firms without a direct relationship…
Lesson · CIPP/EApplications on mobile devices
Mobile apps collect large volumes of often intimate data via sensors (location, audio, video) and stored data (contacts, photos). Devices are rarely…
Lesson · CIPP/EArticle 13 vs Article 14 - what must be provided
The primary information duties sit in Article 13 (data collected directly from the data subject) and Article 14 (data obtained from another source). Both…
Lesson · CIPP/EArticle 3(1): EU-established controllers and processors
Under Article 3(1) the GDPR applies to processing 'in the context of the activities of an establishment of a controller or a processor in the Union'…
Lesson · CIPP/EArticle 3(2): the targeting and monitoring tests
Article 3(2) is the long-arm rule for organisations not established in the EU. It catches their processing of personal data of data subjects who are in…
Lesson · CIPP/EArticle 33 - notifying the supervisory authority
Article 33 requires the controller to notify the supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours…
Lesson · CIPP/EArticle 33 vs Article 34 - side-by-side comparison
Both Article 33 and Article 34 are risk-reporting duties on the controller, but they differ on who is told, the threshold , the deadline and the content …
Lesson · CIPP/EArticle 34 - communicating the breach to data subjects
Article 34 requires controllers to inform affected individuals without undue delay where a breach is likely to result in a high risk to their rights and…
Lesson · CIPP/EArticle 9 exceptions - the ten conditions
Article 9's prohibition is lifted by ten conditions. The headline ones: explicit consent (more than ordinary consent); employment/social-security law…
Lesson · CIPP/EArtificial Intelligence and the EU AI Act
AI systems may process personal data during design, training, testing and deployment, so the GDPR can apply throughout the lifecycle. Articles 13 and 14…
Lesson · CIPP/EBackground - Lisbon Treaty and institutional reform
The Treaty of Lisbon reformed the EU's institutional structure to cut bureaucracy and speed up decision-making after enlargement. Article 13 of the EU…
Lesson · CIPP/EBackground - the rights and their Articles
European data protection law has always given individuals enforceable rights, but the GDPR is far more extensive than the old Data Protection Directive…
Lesson · CIPP/EBackground & the role of consent
The GDPR requires controllers to process personal data lawfully, fairly and in a transparent manner. Article 6 and Article 9 set out the criteria for…
Lesson · CIPP/EBackground to European data protection law
European data protection law grew out of fears that new technologies - phone-tapping, surveillance, large mainframe computers - threatened individual…
Lesson · CIPP/EBackground - why security is an A-list principle
Security is not just one principle among many; it underpins compliance with all the others. Insecurity can trigger unlawful transfers, inaccuracy, data…
Lesson · CIPP/EBinding corporate rules and conclusion
Binding corporate rules (BCRs) can support an accountability framework. Sometimes called the gold standard of global data protection, they are a single…
Lesson · CIPP/EBinding corporate rules (BCRs) for intra-group transfers
BCRs are a global set of internal rules based on European privacy standards that a multinational group adopts voluntarily and a regulator approves, to…
Lesson · CIPP/EBinding corporate rules for processors
Binding corporate rules (BCRs) are internal, legally binding data protection rules adopted by multinationals. The original BCR model applied only where a…
Lesson · CIPP/EBiometric data as special-category data
Biometric data is defined in Article 4(14) as personal data from specific technical processing of physical, physiological or behavioural characteristics…
Lesson · CIPP/EBlueprint Check, Domain coverage map (I–III)
A cross-check of the CIPP/E Exam Blueprint against this guide. Every competency in Domains I, II and III is covered by both this guide chapters and the…
Lesson · CIPP/EBlueprint Check, Domain coverage map (IV–V) & gap analysis
The cross-check for Domains IV (Scope & Accountability) and V (Compliance), plus the short list of items the official training reinforced on top of this…
Lesson · CIPP/EBrexit and UK data protection
After Brexit, withdrawal legislation repealed the European Communities Act 1972, converted the GDPR into the UK GDPR (retained EU law, amended by the 2019…
Lesson · CIPP/EBring your own device (BYOD)
Under BYOD, employees use personal devices for work. The employer remains the controller for work-related personal data processed on the device, yet the…
Lesson · CIPP/EChannel-by-channel rules: the consent matrix
This is the heart of the chapter for exam purposes. Post is GDPR-only (no ePrivacy), usually consent or legitimate interests. Live phone calls are left to…
Lesson · CIPP/ECloud computing: models and applicable law
Cloud computing is IT services delivered over the internet, split into IaaS, PaaS and SaaS by how much the supplier provides. Cloud infrastructure is…
Lesson · CIPP/ECloud: controllership issues
In most supply-of-services cases the customer is the controller (it decides purposes and means) and the supplier is a processor. But in cloud this can't…
Lesson · CIPP/ECloud: international data transfers
Cloud almost always involves international transfers, and the cloud customer (exporter) is responsible for compliance. Options to provide appropriate…
Lesson · CIPP/ECloud service contracts (Article 28)
A GDPR-subject customer must put an Article 28 contract in place with its cloud provider. The GDPR lists mandatory processor terms: processing only on…
Lesson · CIPP/ECommunications data: content, metadata and retention
Electronic communications generate two categories of data: content and metadata (data about data). Metadata splits into traffic data, location data and…
Lesson · CIPP/EComparing the transfer mechanisms & the future of restrictions
This pulls the four main routes together - adequacy decision, standard contractual clauses|SCCs, BCRs, and Article 49 derogation|derogations - and this…
Lesson · CIPP/ECompetence, the one-stop shop and the lead supervisory authority
Each DPA is competent in its own territory (Article 55). For cross-border processing, the lead supervisory authority - the DPA of the…
Lesson · CIPP/EConclusion: recalibrating responsibilities
The GDPR's biggest change to outsourcing is the recalibration of responsibilities between controllers and processors. Controllers remain primarily…
Lesson · CIPP/EConsent - definition and the four conditions
Consent is the first Article 6 basis. It is defined as any freely given, specific, informed and unambiguous indication of the data subject's wishes, by a…
Lesson · CIPP/EConsent vs legitimate interests - choosing correctly
Exam scenarios frequently turn on consent vs legitimate interests. Consent gives the subject control but can be withdrawn at any time, forcing the…
Lesson · CIPP/EController vs Processor - Roles and Liability
A controller is the person or body that alone or jointly determines the purposes and means of processing - the key decision-maker, who carries most GDPR…
Lesson · CIPP/EConvention 108+
A modernisation protocol - colloquially Convention 108+ - was signed by 21 states on 10 October 2018 after more than seven years of work begun in January…
Lesson · CIPP/EConvention 108
Convention 108 was opened for signature on 28 January 1981 by the Council of Europe. It was the first legally binding international instrument in data…
Lesson · CIPP/ECookies and similar technologies
A cookie is a small text file placed on a device that 'remembers' it. Other tracking tech includes device fingerprinting, tags, pixels, web beacons…
Lesson · CIPP/ECooperation, consistency and the EDPB (Articles 60–66, 68–71)
Cross-border cases run through the cooperation procedure (Article 60): the lead authority circulates a draft decision; other concerned DPAs may agree or…
Lesson · CIPP/ECouncil of Europe Convention 108
Opened for signature on 28 January 1981, Convention 108 was the first legally binding international instrument in data protection. It rests on data…
Lesson · CIPP/ECouncil of the European Union
The Council of the European Union (Council of Ministers) is the EU's main decision-making body and the co-legislator with the Parliament. Do not confuse…
Lesson · CIPP/ECourt of Justice of the European Union (CJEU)
The Court of Justice of the European Union|CJEU, based in Luxembourg, is the EU's judicial body, deciding issues of EU law and enforcing EU decisions. It…
Lesson · CIPP/ECriminal convictions data (Article 10) & processing without identification (Article 11)
Article 10 data - criminal convictions, offences and related security measures - needs greater protection but is NOT a special category under Article 9…
Lesson · CIPP/EData minimisation
Data minimisation means collecting and processing only data that is relevant, necessary and adequate for the purpose - collect only what you really need…
Lesson · CIPP/EData protection and direct marketing
Direct marketing is one of the hardest areas of data protection law because it triggers both DP rules and other consumer-protection rules that vary by…
Lesson · CIPP/EData protection by design and by default
Article 25 requires data protection by design and data protection by default - the technical and organisational measures a controller builds in to protect…
Lesson · CIPP/EData Protection Directive 95/46/EC
Adopted on 24 October 1995, Directive 95/46 was the EU's flagship data protection law, set up as an internal market harmonisation measure under the Treaty…
Lesson · CIPP/EData protection impact assessment (DPIA)
A DPIA (also called a PIA) systematically identifies and addresses the data protection impacts of new products, services or activities. Under Article 35…
Lesson · CIPP/EData Retention Directive
Directive 2006/24/EC (the Data Retention Directive) aligned national rules on retaining traffic and location data for serious crime and anti-terrorism. In…
Lesson · CIPP/EDelivering on security - programmes, people, paperwork
A strong security programme is board-endorsed, multidisciplinary, and connects security professionals with data protection and legal staff. Practitioners…
Lesson · CIPP/EDocumentation and records of processing (Article 30)
The GDPR abolished the Directive's notify/register requirement: controllers no longer file processing activities with a DPA. Instead they must keep…
Lesson · CIPP/EEmployee data
Employers process personal data on employees past, present and potential for recruitment, salary, benefits, personnel files, sickness records, monitoring…
Lesson · CIPP/EEmployees, the insider threat, and the controller-processor relationship
Article 32(4) covers employees and other workers acting under the controller's or processor's authority - read with Article 5(1)(f) and Article 28(3)(b)…
Lesson · CIPP/EEnforcement and conclusion
Enforcement of direct-marketing rules - especially cookies and unsolicited communications - is rising: class actions (Lloyd v Google in the UK…
Lesson · CIPP/EePrivacy consent and cookie controllership
Cookie consent must meet GDPR standards. Planet49 confirmed consent is not valid via a pre-ticked box, and users must be told the cookie's duration and…
Lesson · CIPP/EePrivacy laws: unsolicited messages and cookies
The ePrivacy Directive adds consent/information rules to digital marketing by phone, fax and electronic mail (incl. SMS, IM, push). The general rule: most…
Lesson · CIPP/EEU Cloud Code of Conduct
The EU Cloud Code was approved by Belgium's DPA in May 2021 after a positive EDPB opinion. It sets requirements for B2B cloud services where the provider…
Lesson · CIPP/EEuropean Commission
The European Commission is the EU's executive body but also far more: it holds the right to initiate legislation ('Union legislative acts may only be…
Lesson · CIPP/EEuropean Council
The European Council gives the EU its political impetus and direction but does not exercise legislative functions. It began as an informal body in 1974…
Lesson · CIPP/EEuropean Court of Human Rights (ECtHR)
The European Court of Human Rights|ECtHR is not an EU institution. It sits in Strasbourg as part of the Council of Europe, which has 46 member states…
Lesson · CIPP/EEuropean Parliament
The European Parliament is the only EU institution directly elected by EU citizens, giving it democratic weight. It has four roles: legislative…
Lesson · CIPP/EExam Prep, A study plan that actually works
The IAPP advises a minimum of 30 hours of study. But hours alone don't pass exams - active recall and spaced retrieval do. Re-reading and highlighting…
Lesson · CIPP/EExam Prep, After the course - next steps to certify
Completing the training is a step, not the finish line. To convert it into a pass, layer on this guide, the blueprint, practice questions and spaced…
Lesson · CIPP/EExam Prep, How the questions are written (Bloom's taxonomy)
Not every question is a definition. The IAPP writes questions at different Bloom's taxonomy levels. The verb in a performance indicator (define, identify…
Lesson · CIPP/EExam Prep, Test-day strategy & the classic traps
On the day, technique matters. Read the full stem, watch for absolutes ("always", "never"), and pick the best answer, not merely a true one. Most lost…
Lesson · CIPP/EExam Prep, The CIPP/E exam at a glance
The CIPP/E exam tests the IAPP Body of Knowledge across five domains. Knowing the weighting tells you where to spend your time: Domain II is the single…
Lesson · CIPP/EExemptions to the obligation to provide information
The GDPR has its own exemptions (no national law needed) and permits member states to create more. For Article 13 (direct collection) there is essentially…
Lesson · CIPP/EFair processing notices and best practice
Unlike the Directive, the GDPR specifies methods for informing data subjects, so fair processing notices (privacy notices) remain the convenient way to…
Lesson · CIPP/EFreely given consent - bundling, imbalance, cookie walls
Freely given means a genuine choice and the ability to refuse or withdraw. Consent bundled with other matters (e.g. buying a service) is invalid; under…
Lesson · CIPP/EHow information must be provided (manner and format)
Article 12 governs the manner: information must be concise, transparent, intelligible and easily accessible, using clear and plain language, and language…
Lesson · CIPP/EHuman rights law foundations
European data protection rests on human rights law. The Universal Declaration of Human Rights (1948) set the values: Article 12 protects privacy, Article…
Lesson · CIPP/EIdentifiability, Anonymisation and Pseudonymisation
A person is identifiable when, though not yet identified, it is possible to identify them - directly (by name) or indirectly (by an identifier, or by…
Lesson · CIPP/EImpact on member states - implementation, enforcement, direct effect
Directives are not directly applicable: states transpose them, so approaches vary - the great challenge of EU privacy law. The Commission can take…
Lesson · CIPP/EIncident response
Putting in place incident response is an implicit requirement of the security principle and the breach rules. A good incident response plan needs senior…
Lesson · CIPP/EIndependent national regulators and their tasks (Articles 51–57, 59)
Only the DPA|DPAs hold administrative supervisory and enforcement powers under the GDPR. They must be independent public authorities (Articles 51–52) with…
Lesson · CIPP/EIntegrity and confidentiality
Article 5(1)(f) - integrity and confidentiality (the 'security principle') - requires processing in a manner that ensures appropriate security, including…
Lesson · CIPP/EInternet of Things (IoT)
The IoT is physical objects ('connected objects') that connect, sense and transmit data - wearables, smart meters, connected vehicles, and VVA-paired…
Lesson · CIPP/EIntroduction and background to accountability
The GDPR formally embeds accountability into EU data protection law. Accountability means the obligations an organisation must meet to show and evidence…
Lesson · CIPP/EIntroduction and overview of scope
Chapter 5 sets out two filters that decide whether the GDPR applies at all: territorial scope (which organisations, by location or by who they target) and…
Lesson · CIPP/EIntroduction and scope
Chapter 17 maps how European data protection concepts apply to a range of internet technologies - cloud, cookies, IP addresses, search engines, social…
Lesson · CIPP/EIntroduction and surveillance technology
Surveillance means observing an individual or group, and it is getting cheaper, more capable and more pervasive. The classic concern is the nation state…
Lesson · CIPP/EIntroduction: the toolkit of supervision and enforcement
A regulatory system is only as good as the means by which it is supervised and enforced. The GDPR spreads enforcement firepower across many actors, not…
Lesson · CIPP/EIntroduction to Data Protection Concepts
The core data protection concepts pre-date the GDPR: they were set by the 1995 Data Protection Directive and remain essentially unchanged in the GDPR…
Lesson · CIPP/EIntroduction to outsourcing
Data protection law was born in the early 1970s as computers spread, and early service bureaux (also called computer bureaux) processed data on behalf of…
Lesson · CIPP/EIP addresses as personal data (Breyer)
An IP address is a numerical label assigned to a device. It can be static IP address|static (always the same) or dynamic IP address|dynamic (changes each…
Lesson · CIPP/EJoint Controllership
Joint controllership arises where two or more entities jointly determine the purposes and means of processing - either by a common decision or through…
Lesson · CIPP/ELaw Enforcement Directive (LED)
Agreed alongside the GDPR, the Law Enforcement Directive (Directive (EU) 2016/680) governs personal data processed by criminal law enforcement…
Lesson · CIPP/ELaw enforcement, EU institutions, ePrivacy and E-Commerce
Article 2(2)(d) exempts processing by competent authorities for the prevention, investigation, detection or prosecution of criminal offences (and…
Lesson · CIPP/ELawfulness, fairness and transparency
The first principle bundles three ideas. Lawfulness means there must be a legal ground (and the processing must comply with all applicable laws). Fairness…
Lesson · CIPP/ELegal basis for processing employee personal data
Employers usually rely on one of four grounds: consent, necessity for the employment contract, compliance with a legal obligation, or legitimate…
Lesson · CIPP/ELegal obligation & public interest - extra detail; documenting the basis
For both the legal obligation and public task bases, Recital 45 says the processing must have a basis in EU or member-state law, which may specify the…
Lesson · CIPP/ELegitimacy and proportionality of monitoring
Monitoring needs a lawful basis - usually the legitimate-interests balancing test, not consent, whose use the WP29 said is very limited for monitoring…
Lesson · CIPP/ELegitimate interests & the balancing test
Legitimate interests (6(1)(f)) is the most flexible basis and the one on which most processing relies, but public authorities cannot use it for their…
Lesson · CIPP/ELocation-based marketing
Using location data from devices for marketing engages both the GDPR and ePrivacy. ePrivacy Art 9 requires opt-in consent to use location data for a…
Lesson · CIPP/ELocation data and contact tracing
Location-based services (LBS) use location to deliver navigation, advertising, gaming, payments and more, drawn from satellite (GPS/Galileo), cell-based…
Lesson · CIPP/EMandatory Article 28(3) contract terms
Processing by a processor must be governed by a written contract (or other binding legal act). Article 28(3) sets out the mandatory terms. From the…
Lesson · CIPP/EMarketing by electronic mail and the soft opt-in
Email/SMS/MMS marketing needs prior opt-in consent (ePrivacy Art 13(1)) - typically a tick box at data capture. The exception is the soft opt-in…
Lesson · CIPP/EMaterial scope: matters outside EU law and the household exemption
Even an in-scope organisation has some processing carved out of the GDPR by Article 2. Article 2(2)(a) excludes activities outside the scope of Union law…
Lesson · CIPP/EMeaning of an 'adequate level of protection'
Under Article 45(1), the Commission can decide a third country, a territory, a sector, or an international organisation ensures an adequate level of…
Lesson · CIPP/EModalities - to whom, how, and when
Article 12(2) requires controllers to facilitate the exercise of rights. Unlike the Directive, the GDPR requires the controller to use all reasonable…
Lesson · CIPP/EModule 1, Council of Europe vs the EU
A critical exam distinction. The European Union (EU) is an economic and political union of 27 Member States; the Council of Europe (CoE) is an…
Lesson · CIPP/EModule 1, Directive vs Regulation, the EDPB and ePrivacy
A Directive obliges Member States to implement it in local law; a Regulation is directly applicable with no local implementation needed - the GDPR is a…
Lesson · CIPP/EModule 1, EU institutions and the legislative process
The EU's institutions split into legislative, policy and judicial roles. The European Commission proposes legislation; the European Parliament (MEPs) and…
Lesson · CIPP/EModule 1, European data protection timeline
The road to the GDPR: the OECD Guidelines (1980) set harmonised data-flow principles; Convention 108 (1981) was the first binding data protection treaty…
Lesson · CIPP/EModule 1, Foundations: UDHR and ECHR
European data protection grows from two human-rights instruments. The Universal Declaration of Human Rights (UDHR) was adopted on 10 December 1948 and is…
Lesson · CIPP/EModule 10, Accountability defined (Article 24)
Article 24(1) makes the controller responsible for implementing appropriate technical and organisational measures to ensure and be able to demonstrate…
Lesson · CIPP/EModule 10, Data protection by design and by default (Article 25)
Article 25 sets two linked duties. Data protection by design begins before processing and bakes data protection into the planning/design phase. Data…
Lesson · CIPP/EModule 10, Data protection impact assessment (DPIA, Articles 35 and 36)
A DPIA has two values: incorporate data protection into planning and demonstrate compliance to SAs. A PIA is broader and lighter and can run on any…
Lesson · CIPP/EModule 10, Data protection policy (Article 24(2))
A data protection policy (Article 24(2)) is an internal tool to train employees and set out what may and may not be done, plus the consequences of breach…
Lesson · CIPP/EModule 10, Records of processing (Article 30)
Records of processing (Article 30) apply to organisations with 250+ employees, OR - regardless of size - where processing is likely to result in a risk…
Lesson · CIPP/EModule 10, The data protection officer (DPO, Articles 37–39)
The DPO (formerly the Personal Data Protection Official) advises on and monitors compliance and must be an expert in data protection law and practices…
Lesson · CIPP/EModule 10, The EU representative (Article 27)
Under Article 27, controllers/processors caught by Article 3(2) - those offering goods/services to, or monitoring, people in the EU while not established…
Lesson · CIPP/EModule 11, Lead SA, one-stop-shop & cooperation/consistency
For cross-border processing a single lead supervisory authority (LSA) coordinates the concerned supervisory authorities through the one-stop-shop. The LSA…
Lesson · CIPP/EModule 11, Remedies, liabilities & administrative fines
The GDPR sets two fine tiers: up to €10 million or 2% of worldwide annual turnover (lower) and up to €20 million or 4% (higher), whichever is higher…
Lesson · CIPP/EModule 11, Supervisory authorities & Article 58 powers
Supervisory authorities (a.k.a. data protection authorities) are the bodies the GDPR tasks with promoting, monitoring and enforcing the regulation. Their…
Lesson · CIPP/EModule 11, The EDPB & the EDPS
The European Data Protection Board (EDPB) replaced the Article 29 Working Party and ensures consistent application of the GDPR. The 30 EEA SAs each send a…
Lesson · CIPP/EModule 2, Anonymous vs pseudonymous data
Anonymous data is rendered unidentifiable and is NOT protected by the GDPR, but true anonymisation is hard. Pseudonymous data is NOT fully anonymous -…
Lesson · CIPP/EModule 2, Defining and identifying personal data
Article 4(1) GDPR defines personal data as "any information relating to an identified or identifiable natural person." The course uses a four-step test…
Lesson · CIPP/EModule 2, Special categories of personal data (Article 9)
Article 9(1) prohibits processing of special-category data unless an exception applies. The categories cover racial/ethnic origin, political opinions…
Lesson · CIPP/EModule 3, Controller vs processor
Who decides the purposes and means of processing? Whoever determines the "why" and the "how" is the controller (Article 4(7)); whoever processes on the…
Lesson · CIPP/EModule 3, Sub-processors and Opinion 22/2024
A sub-processor is an entity engaged by a processor to help carry out the processing. EDPB Opinion 22/2024 makes three things clear: the controller must…
Lesson · CIPP/EModule 3, Vendor management and the Article 28 contract
Choosing a good processor is part of the controller's accountability - there is a pre-contractual due-diligence duty, and failing it leaves the controller…
Lesson · CIPP/EModule 4, Consent - the four conditions and children
Valid consent must be freely given, specific, informed and unambiguous - a clear affirmative act, clearly distinguishable and in plain language, with…
Lesson · CIPP/EModule 4, Data processing principles (OECD + Article 5)
The GDPR's Article 5 principles - lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity…
Lesson · CIPP/EModule 4, Legitimate interests and the balancing test
Legitimate interests (Art 6(1)(f)) is a flexible "safety net," but it demands a Legitimate Interest Assessment (LIA). EDPB Guidelines 1/2024 set three…
Lesson · CIPP/EModule 4, Special-category data and Article 9 exceptions
Processing special-category data is prohibited by default. To do it lawfully you need BOTH an Article 6 basis AND an Article 9 exception. The exceptions…
Lesson · CIPP/EModule 4, Territorial and material scope
Article 3 sets territorial scope - and only one criterion need be met: the establishment criterion (Art 3(1)), the targeting/monitoring criterion (Art…
Lesson · CIPP/EModule 4, The data processing life cycle
Processing is defined sweepingly in Article 4(2): any operation performed on personal data, automated or not - from collection and storage right through…
Lesson · CIPP/EModule 4, The six Article 6 lawful bases
Processing personal data needs a lawful basis. Article 6 offers six, and only one is needed: consent, contract, legal obligation, vital interests, public…
Lesson · CIPP/EModule 5, Access and rectification (Articles 15 & 16)
Two foundational data subject rights. The right of access (Article 15) lets a person obtain confirmation that their data is processed, a copy of their…
Lesson · CIPP/EModule 5, Automated decision-making and profiling (Article 22)
Article 22 gives the data subject the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal…
Lesson · CIPP/EModule 5, Data portability (Article 20)
Data portability (Article 20) extends the right of access: the data subject can receive their data in a structured, commonly used, machine-readable format…
Lesson · CIPP/EModule 5, Erasure / right to be forgotten (Article 17)
Right to erasure (Article 17), also called the right to be forgotten, lets a data subject have their data deleted in defined cases - e.g. data no longer…
Lesson · CIPP/EModule 5, Restriction of processing (Article 18)
Restriction of processing (Article 18) means marking stored personal data to limit future processing - a kind of legal hold. Per Article 4(3), the data is…
Lesson · CIPP/EModule 5, Right to object (Article 21)
Right to object (Article 21) applies where processing is for direct marketing (an absolute right - processing must cease, including profiling for…
Lesson · CIPP/EModule 6, Article 13 vs Article 14 (direct vs indirect collection)
Article 13 governs data collected directly from the data subject - provide the information at the time of collection. Article 14 governs data obtained…
Lesson · CIPP/EModule 6, Privacy notices and formats
A privacy notice describes how an organisation collects, uses, retains and discloses personal data (a.k.a. privacy statement / fair processing statement /…
Lesson · CIPP/EModule 6, Transparency (Article 12)
Transparency (Article 12) requires controllers to communicate concisely, transparently, intelligibly and in clear and plain language (adapted for…
Lesson · CIPP/EModule 7, Adequacy decisions & the Schrems/DPF saga
An adequacy decision is a European Commission finding that a third country's laws provide essentially equivalent protection - so transfers there need no…
Lesson · CIPP/EModule 7, Appropriate safeguards: SCCs, BCRs & codes
Used when there is no adequacy decision, appropriate safeguards bind the recipient to an EU standard. Standard Contractual Clauses (SCCs) are the most…
Lesson · CIPP/EModule 7, Derogations & restrictions (Article 49)
Derogations under Article 49 are last-resort exemptions, narrowly interpreted, that allow a transfer in specific situations only when neither adequacy nor…
Lesson · CIPP/EModule 7, The landscape: three options in order
When personal data leaves the EEA (the EU plus Iceland, Liechtenstein and Norway) it must stay protected to an EU-equivalent standard, and this applies to…
Lesson · CIPP/EModule 8, CCTV / video surveillance & Guidelines 3/2019
CCTV footage contains personal data and images may be biometric data. Compliance turns on lawfulness (often legitimate interest; consent is usually not…
Lesson · CIPP/EModule 8, Dark patterns (Guidelines 03/2022), AI & the EU AI Act
Dark patterns are deceptive interface designs that manipulate users about their personal data; EDPB Guidelines 03/2022 set out six categories. AI can make…
Lesson · CIPP/EModule 8, Direct marketing channel rules & the soft opt-in
Channel rules differ sharply. Postal marketing is outside ePrivacy and can often rely on legitimate interests. Person-to-person phone calls need no…
Lesson · CIPP/EModule 8, Direct marketing - GDPR vs ePrivacy & the absolute right to object
Direct marketing is a communication, by any advertising means, directed towards specific individuals. It is regulated by both the GDPR and the ePrivacy…
Lesson · CIPP/EModule 8, Employee data - legal layers, works councils & legal bases
Employee data sits under more than the GDPR: local data-protection AND employment law also apply, and these are not fully harmonised. Article 88 lets…
Lesson · CIPP/EModule 8, ePrivacy Directive, location data & biometric data
The ePrivacy Directive (2002/58) governs data from terminal equipment over public electronic communications networks - its main basis is consent and it…
Lesson · CIPP/EModule 8, Lawful employee monitoring & whistleblowing
Lawful employee monitoring must pass four tests - it must be necessary, have a legitimate, lawful basis, be proportionate and be transparent. Monitoring…
Lesson · CIPP/EModule 8, Online behavioural advertising (OBA) & cloud computing
OBA targets website ads on observed behaviour over time, often via third-party ad networks placing cookies with unique identifiers. OBA data is personal…
Lesson · CIPP/EModule 8, Search engines, Google Spain & social media targeting
Search engines determine purposes/means, so they are controllers. Google Spain (2014, CJEU) established the right to be forgotten and held search engines…
Lesson · CIPP/EModule 8, Sensitive employee data, record retention & BYOD
Sensitive employee data needs an Article 9 condition; the employment/social-security exception is the usual route, with explicit consent only as a last…
Lesson · CIPP/EModule 8, Surveillance framework - Article 23, content vs metadata
Surveillance is observation of individuals - covert or overt, real-time or stored. Article 23 lets EU/Member State law restrict data-subject rights, but…
Lesson · CIPP/EModule 8, Web cookies, Article 5(3) & the Planet49 ruling
A cookie is a text file on a device; cookie data is personal data (Recital 30) and processing is subject to the GDPR. ePrivacy Article 5(3) requires…
Lesson · CIPP/EModule 9, Appropriate technical and organisational measures (Article 32)
Security of processing is a prerequisite for compliance - most EU enforcement relates to security incidents, and failures can attract fines up to €20…
Lesson · CIPP/EModule 9, Data breach notification (Articles 33 and 34)
Article 4(12) defines a personal data breach as a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised…
Lesson · CIPP/EModule 9, Security controls - the CIAR attributes
Security has four attributes - CIAR: Confidentiality, Integrity, Availability and Resilience. Resilience is new to EU data-protection law via the GDPR…
Lesson · CIPP/EModule 9, The NIS and NIS2 Directives
The original NIS Directive was the first EU-wide cybersecurity law. The NIS2 Directive entered into force on 16 January 2023. Member States had to…
Lesson · CIPP/ENatural Person, Deceased Persons and PII
Personal data protects natural persons (living humans) universally, regardless of nationality or residence (subject to Article 3 territorial scope). The…
Lesson · CIPP/ENecessity and the DPIA
Before monitoring, the employer must be confident it is really necessary and consider less-intrusive methods first. A DPIA is required where monitoring is…
Lesson · CIPP/ENecessity & the contract, legal obligation and vital interests bases
Every Article 6 basis except consent requires the processing to be necessary. 'Necessary' has an objective meaning - a close and substantial connection…
Lesson · CIPP/ENeed for a harmonised approach & the Data Protection Directive
Leaving implementation of Convention 108 and the OECD Guidelines to member states produced a diverse, fragmented set of regimes, threatening both…
Lesson · CIPP/ENIS Directive and NIS 2
The original NIS Directive, adopted on 6 July 2016, was the first EU-wide cybersecurity law. The NIS2 Directive, Directive (EU) 2022/2555, replaced it…
Lesson · CIPP/EOBA, cookies and ePrivacy (Article 5(3))
The key cookie rule is Article 5(3) ePrivacy Directive: storing or accessing information on a user's device (a cookie) needs the user's consent after…
Lesson · CIPP/EOECD Guidelines
In 1980 the OECD issued Guidelines on the Protection of Privacy and Transborder Flows of Personal Data. They are not legally binding but set out eight…
Lesson · CIPP/EOffshoring and international transfers
Article 44 limits transfers of personal data outside the EEA unless the transfer meets a Chapter V condition. Available routes include an adequacy…
Lesson · CIPP/EOnline behavioural advertising (OBA)
OBA targets ads at people based on their behaviour observed over time. First-party OBA is run by the publisher itself; the trickier case is third-party ad…
Lesson · CIPP/EPersonal Data and Its Four Building Blocks
Personal data is any information relating to an identified or identifiable natural person (the 'data subject'). The definition is intentionally broad. The…
Lesson · CIPP/EPostal marketing
Postal marketing is not digital, so the ePrivacy Directive does not apply - only the GDPR. There is no express GDPR requirement to obtain consent for…
Lesson · CIPP/EPrivacy and Electronic Communications (ePrivacy) Directive
Directive 2002/58/EC (the ePrivacy Directive) adds specific rules for electronic communications. It applies to publicly available electronic…
Lesson · CIPP/EProcedure to designate adequate countries
The Commission designates adequacy by implementing act, guided by the WP29 Adequacy Referential (6 February 2018) on essential equivalence. Each decision…
Lesson · CIPP/EProcessing and Data Subject
Processing is defined extremely broadly: any operation or set of operations on personal data, whether or not automated - collection, recording, storage…
Lesson · CIPP/EProcessing sensitive employee data
Special-category (sensitive) employee data - racial/ethnic origin, political opinions, religious/philosophical beliefs, trade union membership, genetic…
Lesson · CIPP/EEU Artificial Intelligence Act
The Commission proposed an AI regulation on 21 April 2021. The adopted EU AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 and…
Lesson · CIPP/EProviding adequate safeguards - SCCs and the transfer impact assessment
Where there is no adequacy decision, controllers/processors must use appropriate safeguards. The GDPR lists several: binding instruments between public…
Lesson · CIPP/EProviding notice
Whatever lawful basis is used, employers must still give employees a clear notice about how their data is used. It can sit in an employee handbook or a…
Lesson · CIPP/EPublic international law, EU representatives and Brexit
Article 3(3) applies the GDPR where a controller not established in the Union processes in a place where member state law applies by virtue of public…
Lesson · CIPP/EPublic task / official authority basis
Basis 6(1)(e) covers processing necessary for a task carried out in the public interest or in the exercise of official authority vested in the controller…
Lesson · CIPP/EPurpose limitation
Purpose limitation means data must be collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those…
Lesson · CIPP/ERationale for data protection
In the early 1970s, the spread of mainframe computers and telecommunications let governments and large firms build huge data banks, while trade through…
Lesson · CIPP/EReference, EDPB & WP29 guidelines and opinions (must-knows)
The Exam Blueprint repeatedly asks you to know "EDPB guidelines and opinions" on a topic. You don't need to memorise document numbers, but you SHOULD…
Lesson · CIPP/EReference, Key Articles, thresholds & timeframes cheat-sheet
The single highest-yield recall sheet for the exam: the article numbers, thresholds and timeframes that scenario questions hinge on. Drill these until…
Lesson · CIPP/EReference, Landmark CJEU/ECtHR cases & major fines
A handful of cases and fines come up again and again. Know what each one decided and the principle it established - examiners use them as scenario anchors.
Lesson · CIPP/EReform of the EU framework and the road to the GDPR
Divergent national measures and new technology pushed the Commission to reform the Directive. In January 2012 it published two proposals: a regulation…
Lesson · CIPP/ERegulating surveillance: the legal framework
Surveillance by public and state agencies for national security or law enforcement is mostly legislated by member states, with compliance with the Charter…
Lesson · CIPP/ERegulation by the citizen: rights, remedies, representation and compensation
Citizens are the 'second line of defence' - and the ~500 million citizens across the EU and UK are massive enforcement firepower. The GDPR gives…
Lesson · CIPP/ERegulators' powers under Article 58: investigatory, corrective, authorisation/advisory
Article 58 grants the DPAs three types of power: investigatory (Art 58(1)), corrective (Art 58(2)), and authorisation and advisory (Art 58(3))…
Lesson · CIPP/ERelated legislation: LED & ePrivacy
Alongside the GDPR, the EU adopted the Law Enforcement Directive for processing by criminal-law authorities. The ePrivacy Directive governs…
Lesson · CIPP/E'Relating to' - Content, Purpose and Result
For information to be personal data it must be about an individual, but the link is not always obvious. WP29 says one of three elements must apply (they…
Lesson · CIPP/ERelying on the Article 49 derogations
Where there is neither adequacy nor appropriate safeguards, a transfer may still rely on an Article 49 derogation. The EDPB says these must be interpreted…
Lesson · CIPP/ERequirements of the ePrivacy Directive
The ePrivacy Directive (2002/58/EC, as amended) adds information requirements for cookies and similar technologies on websites, apps and connected…
Lesson · CIPP/EResponsibility of the controller
Accountability is first introduced in Article 5: Article 5(1) lists the six principles, and Article 5(2) adds the new duty that the controller must be…
Lesson · CIPP/ERestrictions of data subject rights
Despite the GDPR's prescriptive nature, Union or member-state law may restrict the scope of the obligations and rights in Articles 12 to 22 (and the…
Lesson · CIPP/ERight not to be subject to solely automated decision-making
Despite its title, Article 22 is a general prohibition, not a right to be invoked - it applies regardless of the data subject's actions. It is narrow: it…
Lesson · CIPP/ERight of access (DSAR)
Article 15 is the active counterpart to the passive right to information: on request, a data subject must be told whether their data are processed and, if…
Lesson · CIPP/ERight to data portability
Article 20 is entirely new to EU data protection law. It lets data subjects receive their own data, which they provided to a controller, in a structured…
Lesson · CIPP/ERight to erasure ('right to be forgotten')
Article 17 lets a data subject have personal data erased - verbally or in writing - on specified grounds (data no longer needed, consent withdrawn…
Lesson · CIPP/ERight to object
Article 21(1) lets a data subject object to processing based on the controller's legitimate interests. The objection shifts the burden of proof to the…
Lesson · CIPP/ERight to opt out of direct marketing
Whatever the lawful basis, the GDPR gives individuals an absolute right to object to direct marketing. On consent, they withdraw consent; on legitimate…
Lesson · CIPP/ERight to rectification
Article 16 lets data subjects have inaccurate personal data corrected and incomplete data completed. Its scope is largely unchanged from the Directive…
Lesson · CIPP/ERight to restriction of processing
Article 18 is the GDPR's successor to the Directive's right to 'blocking' - a temporary freezing of data. On listed grounds (accuracy contested, unlawful…
Lesson · CIPP/ERisk reporting and the meaning of 'personal data breach'
Article 33 requires notifying the regulator and Article 34 requires communicating to data subjects - both only where there is risk (or high risk) to…
Lesson · CIPP/ERoles of the parties: controller and processor
In a typical outsourcing deal the customer is the controller and the supplier is the processor. A controller determines the purposes and means of…
Lesson · CIPP/EScope of data transfers - what counts as a transfer
The GDPR does not define 'transfer'. A key distinction is that a transfer is not the same as mere transit: it is the processing in the third country that…
Lesson · CIPP/ESearch engines and the right to be forgotten
Search engines process IP addresses, cookies, user log files and third-party webpages (which they crawl and index). In Google Spain, the CJEU held a…
Lesson · CIPP/ESecurity principle and the risk-based approach (Article 32)
Article 5(1)(f) sets the security principle ('integrity and confidentiality'); Article 32 expands on it, requiring appropriate technical and…
Lesson · CIPP/ESelf-regulation: accountability, DPOs, codes and certification
Self-regulation is arguably the most effective tool because controllers and processors directly control the measures protecting data. The GDPR advances it…
Lesson · CIPP/ESensitive data - Article 9 framework
Article 9 prohibits processing of special-category data unless an exception applies. The categories are: racial/ethnic origin, political opinions…
Lesson · CIPP/ESetting fines, guidelines and the Law Enforcement Directive
The WP29 (adopted by the EDPB) and the EDPB's 2022 guidelines steer how fines are calculated. A fine is not a mere mathematical exercise. Minor…
Lesson · CIPP/ESituations requiring additional information
Beyond Articles 13/14, the GDPR triggers extra information duties in specific situations, whether or not the data came from the subject: data subject…
Lesson · CIPP/ESocial media: legal basis, special category data, children
SMP processing needs an Article 6 basis, and Article 9 applies to special category data. One Art 9 route is data manifestly made public by the data…
Lesson · CIPP/ESocial media: roles, joint controllership, transparency
Social media platforms (SMPs) collect data users provide, observe, and infer/predict. The SMP is a controller. The pivotal case is Wirtschaftsakademie…
Lesson · CIPP/ESpecial Categories of Personal Data
Article 9 identifies special categories (sensitive) of personal data needing extra protection because their processing risks individuals' fundamental…
Lesson · CIPP/ESpecific, informed & unambiguous consent
Consent must be specific to the operation (purpose specification guards against function creep), informed (language the average person understands, not…
Lesson · CIPP/EStorage limitation
Storage limitation (Article 5(1)(e)) means personal data must not be kept longer than necessary for the purpose; once no longer needed, it must be…
Lesson · CIPP/EStorage of personnel records
Personnel records span recruitment, sick leave, medical insurance, salary, appraisals, evaluations and severance. They must not be kept longer than…
Lesson · CIPP/ESubcontracting conditions
Where outsourcing forms a chain, Articles 28(2) and (4) set conditions on engaging a sub-processor. The customer must give prior specific or general…
Lesson · CIPP/ESuppliers as controllers, AI, and chains of processors
A supplier that goes beyond its mandate and acquires a real role in determining the purposes or essential means of processing becomes a controller in its…
Lesson · CIPP/ETargeted online advertising: ecosystem and law
Most free internet services are funded by targeted online advertising, which builds profiles and routes ads to people who meet criteria. The adtech…
Lesson · CIPP/ETelephone marketing
Telemarketing is digital marketing, so both the GDPR and ePrivacy apply. For live person-to-person calls, Art 13(3) lets member states choose opt-in or…
Lesson · CIPP/EThe Article 5 principles overview
Chapter 6 covers the data processing principles now expressly listed in Article 5 of the GDPR. These principles did not start with the GDPR: they were…
Lesson · CIPP/EThe data protection officer (DPO)
Not every company needs a DPO, but Article 37 makes one mandatory in three cases: a public authority; where core activities consist of regular and…
Lesson · CIPP/EThe Five Building Blocks of 'Controller'
EDPB Guidelines 07/2020 break 'controller' into five building blocks: the person/body; 'determines'; 'alone or jointly with others'; 'the purposes and…
Lesson · CIPP/EThe General Data Protection Regulation (GDPR)
The GDPR is a directly applicable regulation with 173 recitals and 99 articles in eleven chapters. Unlike the Directive it binds processors directly…
Lesson · CIPP/EThe General Data Protection Regulation
The Directive could not keep pace with technology and globalisation, so the Commission proposed the GDPR in January 2012. It entered into force May 2016…
Lesson · CIPP/EThe general restriction on transfers outside the EEA
The GDPR lets personal data flow freely between member states, but transfers to any country outside the EEA are restricted. A transfer to a third country…
Lesson · CIPP/EThe NIS Directive (and NIS 2)
The original NIS Directive advanced EU cybersecurity and complemented the GDPR. NIS2, Directive (EU) 2022/2555, replaced that regime from 18 October 2024…
Lesson · CIPP/EThe Processor and the Article 28 Contract
A processor is a separate legal entity that processes personal data on behalf of a controller. Two building blocks: (1) separate legal entity, (2)…
Lesson · CIPP/EThe under-250-employees records exemption
There is an exemption from the Article 30 record-keeping duty for companies with fewer than 250 people. But it is heavily caveated and the chapter says it…
Lesson · CIPP/EThe United States - Privacy Shield, Schrems II and the Data Privacy Framework
Privacy Shield replaced Safe Harbor (adequacy decision 12 July 2016, in force 1 August 2016) with seven strengthened principles and extra safeguards. The…
Lesson · CIPP/EThe United States - Safe Harbor, Snowden and Schrems I
Safe Harbor (Commission decision 26 July 2000) was a self-certification framework treated as adequate for EU-US transfers. Criticised for weak…
Lesson · CIPP/ETransparency, AUPs and covert monitoring
Transparency both meets the notice requirement and sets expectations: employees told in advance that use is monitored have less scope to claim they didn't…
Lesson · CIPP/ETransparency principle
The first GDPR processing principle is that personal data must be processed lawfully, fairly and in a transparent manner. Transparency means being open…
Lesson · CIPP/ETransparent communication and the right to information
Transparency underpins the whole system: individuals cannot protect their privacy if they are not properly informed. Article 12(1) requires information to…
Lesson · CIPP/ETreaty of Lisbon
The Treaty of Lisbon was signed 13 December 2007 and took effect 1 December 2009. It amends the EU's two core treaties, renaming one the TFEU. Article…
Lesson · CIPP/EVideo surveillance (CCTV): lawful basis and proportionality
CCTV that captures images identifying people is processing personal data and must comply with the GDPR and, if applicable, the LED. The usual lawful basis…
Lesson · CIPP/EWhen information must be provided (timing)
Timing is one of the key practical differences between the two Articles. Under Article 13 the information must be given at the time the personal data are…
Lesson · CIPP/EWhistleblowing schemes
Whistleblowing lets employees report illegal or improper activity with privacy safeguards. SOX (2002) drove their prominence and reaches EU subsidiaries…
Lesson · CIPP/EWhy consent is problematic at work
Consent looks easy but should be a measure of last resort. Valid consent must be freely given, specific, informed and unambiguous - and the imbalance of…
Lesson · CIPP/EWorkplace monitoring: principles, background checks, DLP
An employee does not lose their right to privacy at work; their private sphere is protected but balanced against the employer's right to run its business…
Lesson · CIPP/EWorks councils
Works councils represent employees and have rights under local law over how employee data is used; they often must safeguard employees' data protection…
Guide · CIPP/EWhat is location data under the GDPR?
A practical GDPR guide to GPS, IP-address, mobile-network and inferred location data, with Article 4, legal-basis and DPIA exam points.
Guide · CIPP/USCIPP/US exam format and blueprint
The current CIPP/US exam format, timing, question types and a practical way to use the IAPP Body of Knowledge and blueprint.
Guide · CIPP/USCIPP/US exam questions explained
CIPP/US practice questions for exam prep: 604 exam-style questions, a 90-question timed set, worked explanations and a free diagnostic.
Guide · CIPP/USCIPP/US practice questions and practice exam
Take a free CIPP/US diagnostic, then use 604 practice questions and a timed 90-question set with explanations.
Guide · CIPP/USCIPP/US study guide
CIPP/US study guide with free lessons, a ten-question diagnostic and 604 exam-style practice questions for scenario-based exam prep.
Guide · CIPP/USCIPP/US study plan
A four-week CIPP/US study plan that turns the published outline into a 30-hour schedule with review and timed practice.
Practice · CIPP/USCIPP/US cram sheet
The complete CIPP/US memorisation sheet: the timeline, dollar amounts and deadlines, opt-in vs opt-out, who enforces what, the sectoral laws, the Supreme…
Practice · CIPP/USFind the CIPP/US areas to study next.
Take a free 10-question CIPP/US diagnostic. Get an immediate domain score and a personalised study plan without creating an account.
Guide · CIPP/USCIPP/US essentials
The essentials tier for the IAPP CIPP/US - the most-tested laws, regulators, opt-in/opt-out rules and distinctions per exam area, condensed to one page…
Guide · CIPP/USCIPP/US: the whole exam on one page
Every exam-relevant U.S. privacy law, regulator, threshold, opt-in vs opt-out rule, distinction and landmark case for the IAPP CIPP/US - condensed onto…
Glossary · CIPP/USCIPP/US glossary
Plain-language definitions for recurring terms in the CIPP/US study guide.
Guide · CIPP/USHIPAA vs FERPA
A practical HIPAA versus FERPA decision guide for school nurses, outside providers, university clinics and mixed student and nonstudent records.
Guide · CIPP/USHow to pass the CIPP/US
How to pass the IAPP CIPP/US exam: what it tests, the format, a study plan, the sectoral-law traps, and free study notes plus the exam-style question set.
Guide · CIPP/USIs the CIPP/US exam hard?
Is the CIPP/US exam hard? Format, pass mark, domain weights, where candidates struggle and a practical way to prepare.
Practice · CIPP/USFree CIPP/US mini mock
Try 25 exam-style CIPP/US practice questions free, with explanations and a domain score. No account or payment required.
Practice · CIPP/USA processor discovers a breach affecting personal data it handles for a controller. What is the processor's obligation under the GDPR?
A processor discovers a breach affecting personal data it handles for a controller. What is the processor's obligation under the GDPR? Answer with a worked…
Lesson · CIPP/USAPEC Privacy Framework (2004)
APEC is a 21-member organization operating under nonbinding agreement. Its 2004 Privacy Framework (updated 2015) sets nine principles that mirror the OECD…
Lesson · CIPP/USThe Four Classes of Privacy
Privacy splits into four classes: information, bodily, territorial, and communications privacy. This book focuses primarily on information privacy.
Lesson · CIPP/USCo-Regulatory, Self-Regulatory, and Technology Models
Co-regulation (e.g., Australia; U.S. COPPA codes approved by the FTC) pairs industry codes with government law. Self-regulation (e.g., PCI DSS, seal…
Lesson · CIPP/USComprehensive Model of Data Protection
Comprehensive laws govern personal data across public and private sectors economy-wide, typically with an oversight DPA. Countries adopt them to remedy…
Lesson · CIPP/USCouncil of Europe Convention 108 (1981)
Convention 108 (1981) required its parties to enact data protection provisions in domestic law. It was modernised through the 2018 protocol known as…
Lesson · CIPP/USDefining Privacy
In 1890, Warren and Brandeis defined privacy as the right to be let alone in the Harvard Law Review. U.S. law calls this field privacy law while the EU…
Lesson · CIPP/USFair Information Practices (FIPs) Overview
Since the 1970s, Fair Information Practices (FIPs/FIPPs) have organized individual rights and organizational responsibilities into four categories: rights…
Lesson · CIPP/USU.S. HEW Fair Information Practices (1973)
The FIPs used widely today trace to a 1973 U.S. Department of Health, Education and Welfare report whose Code of Fair Information Practices set five core…
Lesson · CIPP/USHistorical and Social Origins of Privacy
Privacy roots run from classical Greece and the Bible to England's 1361 Justices of the Peace Act. The U.S. Constitution protects privacy without naming…
Lesson · CIPP/USInformation Technology and the Rise of Data Protection Law
Mainframes in the 1960s spurred privacy fears (Orwell's '1984'). In 1970, Hesse, Germany enacted the first modern data protection law; the same year the…
Lesson · CIPP/USMadrid Resolution (2009)
The 2009 Madrid Resolution was approved by data protection commissioners themselves, not governments, to define uniform privacy principles and facilitate…
Lesson · CIPP/USNonpersonal, Deidentified, and Pseudonymized Information
Remove identifying elements and data becomes nonpersonal (deidentified/anonymized), generally outside privacy laws. Pseudonymized data is only temporarily…
Lesson · CIPP/USOECD Guidelines (1980)
The 1980 OECD Guidelines (updated 2013) are the most widely recognized FIP framework and have been endorsed by the FTC. They set eight principles, from…
Lesson · CIPP/USPersonal Information and Sensitive Personal Information
In the U.S., personal information and personally identifiable information (PII) cover data that can identify an individual. Sensitive personal information…
Lesson · CIPP/USThe Line Between Personal and Nonpersonal Information
Where personal ends and nonpersonal begins is unclear and varies by regime. The EU generally treats IP addresses as personal data; U.S. agencies under the…
Lesson · CIPP/USProcessing and Data Roles - Subject, Controller, Processor
Processing covers almost anything done with personal data. The data controller decides how and why data is processed and bears most obligations; the data…
Lesson · CIPP/USSectoral Model (United States)
The sectoral model (the U.S. approach) protects personal data through laws targeting specific industries. Strengths: tailored, lower burden. Weaknesses…
Lesson · CIPP/USSources of Personal Information
The same data can be treated differently by source: public records (held by government, available to the public), publicly available information (broadly…
Lesson · CIPP/USSources of Privacy Protection
Privacy protection comes from four sources: markets, technology, law, and self-regulation/co-regulation. Law is the traditional approach but real…
Lesson · CIPP/USCybersecurity Requirements in Education
FERPA expects reasonable security but specifies no particular controls; the GLBA Safeguards Rule applies to universities holding financial aid information…
Lesson · CIPP/USEdtech under COPPA and Self-Regulation
In 2022 the FTC announced it would police edtech through COPPA, prohibiting use of children's data for commercial purposes, barring unreasonable mandatory…
Lesson · CIPP/USEducation Technology and FERPA
Edtech companies that handle student data are subject to FERPA. The 2014 Google Apps for Education lawsuit (with EPIC alleging FERPA violations over email…
Lesson · CIPP/USRights to Access, Review, and Correction
FERPA gives students the right to access and review most records within 45 days of a request and the right to seek correction of inaccurate, misleading…
Lesson · CIPP/USStatutory Exceptions to FERPA Consent
FERPA lists many no-consent disclosure exceptions, including school officials with a legitimate educational interest, transfer schools, financial aid…
Lesson · CIPP/USValid Consent and Identity Verification
Valid FERPA consent must be signed, dated, and written, identifying the records, the purpose, and the recipient. When relying on a statutory exception…
Lesson · CIPP/USDirectory Information and Opt-Out
Directory information is data that would not generally be considered harmful if disclosed; each institution defines its own list, and before using it the…
Lesson · CIPP/USWhen Disclosure of Education Records Is Permitted
FERPA permits disclosure of education records only if the data is not PII, it is unblocked directory information, the rights holder consents, the…
Lesson · CIPP/USEducation Record and Its Exceptions
An education record is broadly any record directly related to a student and maintained by or on behalf of the school, but FERPA carves out important…
Lesson · CIPP/USFERPA Enforcement, No Private Right, and Preemption
FERPA is enforced by the Department of Education through the Family Policy Compliance Officer (FPCO); the ultimate penalty is loss of federal funding…
Lesson · CIPP/USHolder of FERPA Rights
Who holds FERPA rights depends on context: in high school the parent holds rights until the student turns 18; once a student attends only a college or…
Lesson · CIPP/USFERPA Overview and Scope
The Family Educational Rights and Privacy Act of 1974 (FERPA), also called the Buckley Amendment, gives students control over disclosure of and access to…
Lesson · CIPP/USPersonally Identifiable Information under FERPA
FERPA's PII definition covers names, family member names, addresses, SSNs and student numbers, dates and places of birth, and any information that alone…
Lesson · CIPP/USFERPA Definition of Student
Under FERPA, a student is anyone who is or has been in attendance at an educational institution, including online attendees, but the term excludes…
Lesson · CIPP/USIndividuals with Disabilities Education Act
IDEA guarantees eligible students aged 3 to 21 a free appropriate public education through an IEP, and protects the privacy of special-education records…
Lesson · CIPP/USPPRA and the No Child Left Behind Amendments
The PPRA (1978) amended FERPA to protect parents of minors over surveys collecting sensitive information and applies only to K-12 schools, not colleges…
Lesson · CIPP/USState Student Privacy Laws and SOPIPA
Because FERPA does not preempt state law, states add their own protections. California's SOPIPA was the first U.S. law to prohibit using student data for…
Lesson · CIPP/USCIPP/US COPPA rule and children's data guide
COPPA requirements and current FTC rule material explained for CIPP/US study.
Lesson · CIPP/USCIPP/US Epic Games COPPA enforcement guide
Epic Games COPPA enforcement as a CIPP/US scenario review, with primary FTC source material.
Lesson · CIPP/USThe Cable Communications Policy Act of 1984
The Cable Act regulates cable providers' notice, collection, disclosure and retention of subscriber data, and grants a private right of action. Providers…
Lesson · CIPP/USThe CAN-SPAM Act of 2003
CAN-SPAM governs commercial email to or from the U.S. on an opt-out basis: no false headers or deceptive subject lines, a working return address, a clear…
Lesson · CIPP/USCAN-SPAM Wireless Rules: MSCMs, Express Prior Authorization and the Wireless Domain Registry
The FCC's CAN-SPAM wireless rules require express prior authorization (opt-in) for each mobile service commercial message (MSCM) sent to wireless devices…
Lesson · CIPP/USCPNI Opt-in/Opt-out Rules, Pretexting and Covered Entities
After U.S. West v. FCC struck a 1998 opt-in rule on First Amendment grounds, carriers' own use of CPNI shifted to opt-out. The 2007 CPNI order requires…
Lesson · CIPP/USDigital Advertising Ethics: Behavioral Advertising, Dark Patterns and Children
Beyond legal compliance, ethical digital advertising stresses honesty, fairness and transparency. Key concerns: online behavioral advertising (tracking…
Lesson · CIPP/USExceptions to the DNC Rules: EBR, Consent and DNC Safe Harbor
DNC rules do not apply to nonprofits calling for themselves, existing-customer calls within 18 months, non-upsell inbound calls, or most B2B calls. An EBR…
Lesson · CIPP/USFax Marketing: TCPA and the Junk Fax Prevention Act
The TCPA (enforced by the FCC) bars unsolicited commercial faxes; consent can be explicit or inferred from an EBR. The 2005 Junk Fax Prevention Act…
Lesson · CIPP/USThe National Do Not Call Registry
The National DNC Registry (effective 2003) lets residents register residential and wireless numbers. Sellers/telemarketers must access it before calling…
Lesson · CIPP/USRobocall Enforcement Actions and State Telemarketing Laws
Regulators have escalated robocall enforcement (a 2021 FCC $225 million record fine for ~1 billion robocalls; a 2019 multistate initiative). Because…
Lesson · CIPP/USSelf-Regulation for Digital Advertising: DAA and NAI
Two voluntary codes govern much online behavioral advertising: the DAA Self-Regulatory Principles and the NAI Code of Conduct, both emphasizing opt-outs…
Lesson · CIPP/USState Laws on Digital Advertising: CalOPPA, Age-Appropriate Design, and Comprehensive Laws
California leads on digital advertising: CalOPPA (2003) requires website privacy notices and Do Not Track disclosures; the 2022 California Age-Appropriate…
Lesson · CIPP/USTCPA Updates: Robocalls, Autodialers, Robotexts and Facebook v. Duguid
The FCC's 2012 TCPA revisions require prior express written consent for all robocalls to residential lines, even with an established business…
Lesson · CIPP/USThe Telecommunications Act of 1996 and CPNI
Section 222 of the Telecommunications Act of 1996 restricts how carriers access, use and disclose customer proprietary network information (CPNI) - call…
Lesson · CIPP/USTelemarketing Regulatory Framework: TCPA, TSR, FCC and FTC
Two coordinated federal regimes govern telemarketing: the FCC enforces the Telephone Consumer Protection Act (TCPA) of 1991, and the FTC enforces the…
Lesson · CIPP/USTSR abandoned calls. CIPP/US safe harbor guide
TSR abandoned call rules explained with a safe-harbor example and CIPP/US study context.
Lesson · CIPP/USTSR Rules on How Calls May Be Made
The TSR sets detailed conduct rules: telemarketers may call only between 8 a.m. and 9 p.m., must scrub against the Do Not Call list, display caller ID…
Lesson · CIPP/USTransmission of Caller ID Information
Telemarketers must transmit accurate caller ID. They may show their own name/number or substitute the seller's name and a customer-service number that is…
Lesson · CIPP/USTSR Enforcement, Penalties and the Private Right of Action
The TSR is enforced by the FTC and state attorneys general, with civil penalties up to $50,120 per call. A limited private right of action requires…
Lesson · CIPP/USTSR Misrepresentations, Material Omissions and Payment Authorization
The TSR bars misrepresentations and material omissions across ten categories (cost, restrictions, refund policy, prize/investment terms, etc.). When…
Lesson · CIPP/USTSR Recordkeeping Requirements
The TSR requires sellers and telemarketers to keep specified records (ads, prize recipients, sales, employees, consent authorizations) for two years from…
Lesson · CIPP/USTSR required disclosures. CIPP/US telemarketing guide
TSR required call disclosures explained with a practical example and CIPP/US study context.
Lesson · CIPP/USProhibition on Unauthorized Billing and Pre-Acquired Account Information
The TSR bars billing without express, informed consent. Where the telemarketer already holds the consumer's account data (pre-acquired account…
Lesson · CIPP/USThe Video Privacy Protection Act of 1988
The VPPA, passed after Robert Bork's video rental records were disclosed, bars videotape service providers from disclosing customer information except…
Lesson · CIPP/USCIPP/US Section 230 and online content guide
Section 230 and online content issues explained with a source-backed CIPP/US study bridge.
Lesson · CIPP/USCIPP/US FCC telecom breach notification guide
FCC telecom breach notification rules explained with a source-backed CIPP/US study bridge.
Lesson · CIPP/USADA Restrictions on Medical Screening
The ADA covers employers with 15 or more employees. Before an offer, medical exams/inquiries are allowed only if job-related and consistent with business…
Lesson · CIPP/USAfter Employment: Access Termination and HR Records
On departure, employers should terminate access (badges, accounts, devices), recover company data, and forward personal mail while reviewing work mail. HR…
Lesson · CIPP/USAntidiscrimination Laws as Limits on Screening
Federal antidiscrimination laws (Title VII, Equal Pay Act, ADEA, Pregnancy Discrimination Act, ADA, GINA) bar discrimination and indirectly limit what…
Lesson · CIPP/USReasons for Background Screening
Employers screen to hire the best candidate, counter false applicant claims, protect brand, and mitigate negligent hiring liability. Some professions…
Lesson · CIPP/USBiometric, Video, and Mail Monitoring; Union Activity
Three state biometric laws reach employer data: Illinois BIPA (notice, consent, and a private right of action), plus Texas and Washington (no private…
Lesson · CIPP/USConstitutional Law and the State-Action Limit
Constitutional privacy protections like the Fourth Amendment apply to government (public-sector) employers but not to private-sector employment, because…
Lesson · CIPP/USThe Employment Life Cycle Framework
Workplace privacy issues arise before, during, and after employment: background screening (before); polygraphs, testing, monitoring, social media, and…
Lesson · CIPP/USFACTA Preemption and Stronger State Credit Laws
FACTA (2003) amended the FCRA and preempted many state laws on credit reporting and identity theft, but the FCRA does not preempt stronger state laws on…
Lesson · CIPP/USFair Chance Act and Ban-the-Box Laws
The Fair Chance to Compete on Jobs Act (FCA), enacted in 2019, bars federal agencies and federal contractors from asking about an applicant's criminal…
Lesson · CIPP/USFCRA Restrictions on Background Checks
The FCRA governs background checks via consumer reports from a CRA - not just credit, but criminal and driving records too. Employers need a permissible…
Lesson · CIPP/USFederal Laws Affecting Employment Privacy
A cluster of federal laws bears on employment privacy: antidiscrimination laws, benefits laws (HIPAA, COBRA, ERISA, FMLA), and recordkeeping/data laws…
Lesson · CIPP/USIntercepting Communications: Wiretap Act and ECPA
The Wiretap Act and ECPA generally prohibit intercepting wire, oral, and electronic communications. Two workplace exceptions: consent (party or one party…
Lesson · CIPP/USInvestigating Employee Misconduct: Vail Letter and FACTA Fix
Investigations should be fair, documented, and compliant with CBAs. The FTC's Vail Letter made third-party investigators CRAs, requiring notice and…
Lesson · CIPP/USLBS, DLP, BYOD, and Teleworking Policies
Monitoring policies must address location-based services (GPS on vehicles generally OK; tracking people themselves is more limited), data loss prevention…
Lesson · CIPP/USWorkplace Privacy: The U.S. Legal Landscape
The U.S. has no overarching law for employment privacy. Federal statutes cover specific areas, state contract and tort law offer narrow protections, and…
Lesson · CIPP/USLifestyle Discrimination
Off-duty lifestyle is generally treated as private. Weight-based rules can invite discrimination suits (and obesity from a physiological disability may be…
Lesson · CIPP/USWorkplace Monitoring: Baseline and Policies
U.S. private-sector employees have limited expectations of privacy at work - facilities and equipment belong to the employer, granting broad monitoring…
Lesson · CIPP/USPolygraphs and the EPPA
The Employee Polygraph Protection Act of 1988 (EPPA), enforced by the DOL, bars private employers from using lie detectors on workers or applicants…
Lesson · CIPP/USLegal Obligations and Incentives to Monitor
Employers monitor to meet safety laws (OSHA), improve quality (recorded service calls), limit negligent-supervision liability, protect physical security…
Lesson · CIPP/USFederal Agencies Protecting Employee Privacy
Five federal agencies are central: the DOL (administers FLSA, OSHA, ERISA), the EEOC (Title VII, ADEA, ADA), the FTC and CFPB (unfair/deceptive practices…
Lesson · CIPP/USScreening Technologies: Social Media and AI
Using social media to screen is generally allowed but risks discrimination claims if protected-class info is used, FCRA exposure for nontraditional…
Lesson · CIPP/USState Contract, Tort, and Statutory Protections
Contracts (especially collective bargaining agreements) can create enforceable privacy obligations. Three common-law torts - intrusion upon seclusion…
Lesson · CIPP/USStored Communications Act and City of Ontario v. Quon
The SCA bars unauthorized access to stored electronic communications, with exceptions for the service provider (often the employer) and an authorized…
Lesson · CIPP/USSubstance Use Testing
There is no federal privacy statute directly governing employer substance testing. The ADA excludes current illegal drug use (a drug test is not a medical…
Lesson · CIPP/USCIPP/US automated employment decision tool guide
Automated employment decision tools explained with a source-backed CIPP/US study bridge.
Lesson · CIPP/USCALEA and the Cybersecurity Information Sharing Act
CALEA (1994) requires telecommunications carriers to design interception capability into their products; the FCC extended it to broadband and VoIP. CISA…
Lesson · CIPP/USEvidence Stored Abroad - CLOUD Act and Budapest Convention
The CLOUD Act (2018) lets the DOJ compel U.S. providers to produce data regardless of where it is stored (mooting the Microsoft Ireland case) and lets…
Lesson · CIPP/USDisclosures Forbidden by Law and Evidentiary Privileges
Many privacy laws forbid disclosure using opt-in or opt-out rules: HIPAA and COPPA require opt-in consent; GLBA forbids disclosure if the individual has…
Lesson · CIPP/USDisclosures Permitted by Law
Some laws permit but do not require disclosure. HIPAA requires very few disclosures but permits many (public health, law enforcement, national security)…
Lesson · CIPP/USDisclosures Required by Law
Certain laws compel disclosure: FDA adverse-event reporting, OSHA injury reporting, state injury and disease reporting, and the BSA. HIPAA permits…
Lesson · CIPP/USDiscovery Under HIPAA and GLBA
Sectoral laws coexist with discovery. HIPAA permits PHI in discovery via patient authorization, a court order, or satisfactory assurances (a qualified…
Lesson · CIPP/USElectronic Discovery and ESI
Since the 2006 FRCP revisions, electronically stored information (ESI) drives pretrial discovery. Sound data retention (per Sedona Conference guidance)…
Lesson · CIPP/USFISA, Section 702, Section 215, and FISC
FISA orders issue from the FISC on probable cause that the target is a foreign power or agent, not probable cause of a crime, when foreign intelligence is…
Lesson · CIPP/USEmerging Fourth Amendment Issues - Abortion Data and Geofence Warrants
Post-Dobbs, states that outlaw abortion may send warrants to companies in states that do not, creating an interstate conflict of law (California bars…
Lesson · CIPP/USFourth Amendment Limits on Law Enforcement Searches
The Fourth Amendment bars unreasonable searches; warrants need probable cause, particularity, and a neutral magistrate. Katz created the reasonable…
Lesson · CIPP/USNational Security Letters
An NSL is a subpoena issued by the FBI without judicial involvement for records relevant to terrorism or clandestine intelligence. The PATRIOT Act…
Lesson · CIPP/USNational Security Surveillance - Constitutional Tension and Post-Snowden Reform
National security surveillance pits the president's Article II powers against Article III judicial limits. FISA (1978) balanced both. The PATRIOT Act…
Lesson · CIPP/USHow Disclosures Are Required, Permitted, or Forbidden
When responding to litigation and investigations, the law can require, permit, or forbid disclosure of personal information. The same statute can do all…
Lesson · CIPP/USPreservation Orders and Pen Register / Trap-and-Trace
Under the SCA, a provider must preserve records on a government request pending a court order, similar to a litigation hold. Pen register and…
Lesson · CIPP/USPublic Court Records, Protective Orders, and Required Redaction
U.S. courts are traditionally open, but online records ended practical obscurity. Litigants use protective orders (FRCP 26(c), three-part test) and HIPAA…
Lesson · CIPP/USRight to Financial Privacy Act and Privacy Protection Act
RFPA (1978) requires customer authorization or specific legal process for federal access to individuals' financial records, with advance notice and a…
Lesson · CIPP/USStatutes That Go Beyond Fourth Amendment Requirements
After the Supreme Court held the Fourth Amendment did not protect bank records or dialed numbers, Congress added statutory process. RFPA (1978) covers…
Lesson · CIPP/USCross-Border Discovery and the Hague Convention
U.S. broad-discovery rules collide with foreign laws like the GDPR that protect personal data. Courts split on how to resolve the conflict; the Hague…
Lesson · CIPP/USWiretap Act, ECPA, and Stored Communications Act
The Wiretap Act (Title III) strictly bars intercepting calls; ECPA extends this to electronic communications. Federal law permits one-party consent, but…
Lesson · CIPP/USCIPP/US cybersecurity information sharing guide
Cybersecurity information sharing rules explained with a source-backed CIPP/US study bridge.
Lesson · CIPP/USBreach Notification and Response
A GDPR data breach is broad, covering destruction, loss, alteration, or unauthorized disclosure/access. Controllers must notify the DPA within 72 hours…
Lesson · CIPP/USConsent Under the GDPR
GDPR consent must be freely given, specific, informed, and an unambiguous indication of the data subject's wishes, expressed by statement or clear…
Lesson · CIPP/USController, Processor, and Data Subject
The controller determines the purposes and means of processing; the processor processes on the controller's behalf under contract. The data subject is the…
Lesson · CIPP/USData Subject Rights: Overview and Handling Requests
The GDPR grants individuals control through rights to be informed, access, rectification, erasure, restriction, portability, objection, and freedom from…
Lesson · CIPP/USData Protection Authorities and Data Protection Officers
DPAs are independent national authorities that enforce data protection law - one per member state except Germany (federal plus 16 Lander). The DPO is the…
Lesson · CIPP/USEnforcement: Complaints and Liability
A complaint can be initiated by a data subject or a DPA; where multiple DPAs are involved a lead DPA is determined. Both controllers and processors can be…
Lesson · CIPP/USRights to Erasure and Restriction of Processing
The right to erasure (right to be forgotten) applies in defined situations and requires deletion even from backups unless an exemption applies. As an…
Lesson · CIPP/USGDPR Overview, Scope, and Sanctions
The General Data Protection Regulation (GDPR) is the worldwide template for data protection, applying broadly to companies with EU assets and employees…
Lesson · CIPP/USRecent Developments in Global Data Flows
Beyond the GDPR's influence, the Global CBPR Forum builds on APEC's Cross-Border Privacy Rules to allow trade with privacy assurances, and the OECD…
Lesson · CIPP/USLevels of Fines and Criminal Sanctions
The GDPR has two tiers of fines. Higher-level fines (up to four percent of global revenue or €20 million, whichever is greater) target core processing…
Lesson · CIPP/USPersonal Data and Sensitive Personal Data
Personal data is any data relating to an identified or identifiable natural person, directly or indirectly. Sensitive personal data is a special category…
Lesson · CIPP/USRights to Portability, to Object, and Against Automated Decision-Making
Portability gives data the subject provided in a machine-readable format, only where processing is by consent or contract and automated. The right to…
Lesson · CIPP/USRights to Be Informed, Access, and Rectification
The right to be informed drives privacy notices (layered, just-in-time, dashboards). The right of access underlies the subject access request and is the…
Lesson · CIPP/USAppropriate Safeguards and Derogations
For third countries, transfers need an appropriate safeguard. The two most common are SCCs (the most widely used) and BCRs (for intra-group transfers…
Lesson · CIPP/USEU-U.S. Transfers: Schrems I, Schrems II, and the Data Privacy Framework
The CJEU struck down Safe Harbor (Schrems I, 2015) and Privacy Shield (Schrems II, 2020) over U.S. surveillance concerns. The EU-U.S. Data Privacy…
Lesson · CIPP/USThe Seven General Principles
All processing must abide by the GDPR's seven principles: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage…
Lesson · CIPP/USInternational Transfers and Adequate Countries
Transfers from the EEA to non-EEA countries are prohibited unless supported by an adequacy decision, an appropriate safeguard, or a derogation. Adequate…
Lesson · CIPP/USApplying the Framework: California SB 1386 Breach Notification
California SB 1386 was the first breach-notification law. It covers entities doing business in California that hold computerized personal information…
Lesson · CIPP/USCase Law, Common Law, and Stare Decisis
Case law is judges' final decisions; courts follow precedent under stare decisis. Common law is principles built over time in judicial decisions…
Lesson · CIPP/USConsent Decrees
A consent decree is a judge-approved settlement where the defendant agrees to stop alleged illegal activity, typically without admitting guilt. Once…
Lesson · CIPP/USConstitutions as a Source of Privacy Law
The U.S. Constitution never uses the word privacy, but the Fourth Amendment limits government searches and the Supreme Court recognized a penumbra of…
Lesson · CIPP/USContract Law and Privacy Notices
A contract needs offer, acceptance, and consideration. Privacy obligations often live in vendor contracts, and a privacy notice can itself be a contract…
Lesson · CIPP/USKey Definitions: Person, Jurisdiction, Authority, Preemption, Private Right of Action
Core terms for U.S. privacy law: person (natural or legal), jurisdiction (subject-matter and personal), general vs. specific authority, preemption, and…
Lesson · CIPP/USSix Keys to Understanding Any Law
Analyze any privacy law with six questions: who is covered, what information/uses, what is required/prohibited, who enforces, what happens if you don't…
Lesson · CIPP/USLegislation and Federal Preemption
Both Congress and state legislatures enact privacy laws. The key question is whether a federal law preempts state law: HIPAA lets states pass stricter…
Lesson · CIPP/USNotice, Choice, and Access (Opt-In vs. Opt-Out)
Notice describes information practices; choice lets individuals control collection/use - opt-in is an affirmative yes, opt-out implies consent unless the…
Lesson · CIPP/USRegulations, Rules, and Agency Guidance
Some statutes direct agencies like the FTC or FCC to issue regulations carrying compliance force - e.g., CAN-SPAM rules on the opt-out mechanism. Agencies…
Lesson · CIPP/USFederal and State Regulatory Authorities for Private-Sector Privacy
The FTC has general authority over unfair/deceptive practices plus specific authority in areas like children's privacy; sector regulators include banking…
Lesson · CIPP/USSelf-Regulation in Privacy
Self-regulatory regimes govern many industries' privacy practices - examples include the NAI, the Association of National Advertisers (formerly the DMA)…
Lesson · CIPP/USSources of Law in the United States
U.S. law flows from many sources: constitutions, legislation, case law, contract law, tort law, agency regulations, and consent decrees. Privacy…
Lesson · CIPP/USThe Three Branches of U.S. Government
The U.S. Constitution creates three branches - legislative makes laws, executive enforces them, judicial interprets them - with checks and balances. This…
Lesson · CIPP/USTort Law and Privacy Torts
Torts are civil wrongs in three categories: intentional, negligent, and strict liability. Privacy torts (intrusion on seclusion, public disclosure of…
Lesson · CIPP/USThe Adversarial Mindset: STRIDE, Zero Trust and Least Privilege
Cybersecurity adopts the adversarial mindset and threat modeling (e.g. the STRIDE framework and MITRE ATT&CK). Key principles include zero trust, least…
Lesson · CIPP/USCybersecurity Foundations: The CIA Triad
Security underpins privacy. The CIA triad - confidentiality, integrity, and availability - frames cybersecurity. A useful first approximation: privacy…
Lesson · CIPP/USClient-Server Architecture: Front End and Back End
In the client-server model a client requests a service from a server. The browser-facing front end is separated from the back end databases; separating…
Lesson · CIPP/USCloud Computing: SaaS, PaaS and IaaS
Cloud computing is on-demand availability of computing resources, replacing on-premises computing. The three models - Software as a service (SaaS)…
Lesson · CIPP/USDeep Packet Inspection
Deep packet inspection examines packet contents beyond the header, useful for malware detection and data-leak prevention but also enabling tracking and…
Lesson · CIPP/USDeidentification: Anonymous vs Pseudonymous and Identifiers
When data cannot be traced to a person, privacy law no longer applies. Anonymization removes identifiability; pseudonymization masks identity with a…
Lesson · CIPP/USDeidentification Standards: HIPAA Methods and FTC Guidance
The longest-standing U.S. deidentification rules are under HIPAA: the safe harbor method removes 18 identifiers and the expert determination method relies…
Lesson · CIPP/USApproaches to Deidentification: Suppression, Generalization, Noise Addition
Three core techniques hide identity: suppression removes values, generalization replaces detail with a broader category, and noise addition substitutes…
Lesson · CIPP/USEdge Computing and Latency
Edge computing processes data at the network periphery, close to the source. Driven by the growth of IoT sensors, it reduces the cost of centralized…
Lesson · CIPP/USHow Emails and Texts Work: SMTP, IMAP, POP, SMS and OTT
SMTP sends email; IMAP (which leaves mail on the server) is overtaking POP (which deletes it). Texts use SMS (160-character limit, works without internet)…
Lesson · CIPP/USTracking Email Recipients and Cross-Device Tracking
HTML email can track opens via a unique tracking pixel; reading in plain text defeats it. Cross-device tracking links a user across devices using…
Lesson · CIPP/USEncryption: Symmetric, Asymmetric, Certificates and PKI
Encryption shields data by converting plaintext to ciphertext using a key. Symmetric key cryptography uses one shared key (fast but sharing is hard)…
Lesson · CIPP/USFirst-Party Data Collection and Data Brokers
First parties collect data via cookies, user-generated content (UGC), and account terms of use; in California and the EU they give notice before setting…
Lesson · CIPP/USHashing, Salt and Digital Signatures
Hashing is a one-way function producing an output that does not reveal the input, used for pseudonyms and integrity checks. Plain hashes can be defeated…
Lesson · CIPP/USHTTP Cookies: Session vs Persistent, First vs Third Party
Because HTTP/HTTPS are stateless, HTTP cookies maintain continuity. Session cookies last until the browser closes; persistent cookies can last…
Lesson · CIPP/USBasics of the Internet: TCP/IP and Packet Switching
The internet is a network of networks descended from the ARPANET. Transmission control protocol (TCP) establishes reliable connections and breaks data…
Lesson · CIPP/USKey Web Infrastructure: Servers, Proxies, VPNs, ISPs and IP Addresses
Web content lives on web servers; a proxy server and Virtual private network (VPN) act as gateways that can mask activity. An Internet service provider…
Lesson · CIPP/USLocation Tracking: Technologies and Carpenter
Location is tracked via cell-tower/Wi-Fi triangulation, GPS, and photo metadata. The U.S. has historically had few restrictions, but Carpenter v. United…
Lesson · CIPP/USInternet Monitoring by Employers, Schools and Parents
U.S. employers may generally monitor internet use and emails on company networks/devices. The Children's Internet Protection Act (CIPA) requires public…
Lesson · CIPP/USThe NIST Cybersecurity Framework
The NIST Cybersecurity Framework (CSF), first published in 2014, is guidance rather than law and popularized five Framework Core Functions: Identify…
Lesson · CIPP/USPrivacy by Design and Limits of Technical Measures
Privacy by design embeds privacy from the onset and is legally required in California and the EU. Privacy-enhancing technologies altering or shielding…
Lesson · CIPP/USReidentification Risk and Differential Privacy
Computer scientists have repeatedly re-identified supposedly anonymized data. Differential privacy is a mathematical definition of privacy that adds…
Lesson · CIPP/USSurveillance by Audio, Video and Other Sensors
Devices' microphones and cameras can be hijacked by remote access trojan (RAT) malware, or activated by employers/police. Government video surveillance is…
Lesson · CIPP/USSpyware and Phishing Variants
Spyware (including keylogging) covertly surveils a device, often delivered by phishing social engineering. Variants include spear phishing, whaling…
Lesson · CIPP/USThird-Party Data Collection and the Decline of Third-Party Cookies
Ad networks long used third-party cookies to track users across sites. Market and regulatory changes are shrinking this: the CPRA (effective January 2023)…
Lesson · CIPP/USURLs, URIs, URNs and Hyperlinks
A Uniform resource locator (URL) is a web address with a protocol prefix, optional www, a domain name and a top-level domain. URLs are a subset of Uniform…
Lesson · CIPP/USWeb Infrastructure: HTTP, HTML, HTTPS and XML
The web is narrower than the internet. Hypertext transfer protocol (HTTP) and Hypertext markup language (HTML), invented by Tim Berners-Lee, drive the…
Lesson · CIPP/USWireless Eavesdropping and Defenses
On unencrypted Wi-Fi, packet sniffing can capture traffic, a risk in shared public hotspots. Defenses include encrypted Wi-Fi (per-user keys), VPNs (which…
Lesson · CIPP/USData Breach Readiness Assessments
A data breach readiness assessment examines the risk of a breach plus the likelihood and severity of a personal data breach, weighing data type, technical…
Lesson · CIPP/USThe Business Case for Privacy and the Cost of Mishandling Data
Privacy compliance carries real cost, but mishandling personal data can be far more expensive in fines, breach costs, and lost consumer trust. Privacy is…
Lesson · CIPP/USResponding to User Requests and Consumer Rights
Many federal and state laws grant rights of control: access, correction, deletion, portability, against automated decision-making, and nondiscrimination…
Lesson · CIPP/USData Accountability - Controllers, Processors, and Encryption
Accountability questions cover where/how/how long data is stored, sensitivity, encryption, cross-border transfer, and who sets the rules. A controller…
Lesson · CIPP/USData Flow Mapping - Top-Down and Bottom-Up
After inventory and classification, data flows are mapped and documented (what, where, and why data is processed). The top-down approach used for…
Lesson · CIPP/USData Inventory and Data Classification
An organization should inventory all PI it collects, stores, uses, or discloses (customer and employee), then classify it by sensitivity to set access…
Lesson · CIPP/USThe Data Life Cycle
Data should be managed across its life cycle - creation, storage, sharing and usage, archival, and deletion - because privacy-protecting approaches at one…
Lesson · CIPP/USGlobal Perspective and Cross-Border Data Transfer Mechanisms
More than 160 nations have significant privacy laws; the GDPR draws the most attention, with fines based on worldwide revenue. Cross-border trust…
Lesson · CIPP/USInformation Management and the Privacy Professional's Role
Information management establishes, implements, and monitors the organization's privacy program under a senior leader such as the CPO, drawing on legal…
Lesson · CIPP/USInformation Security - CIA Triad and Control Types
Information security protects information per three attributes - confidentiality, integrity, availability (CIA) - using physical, administrative, and…
Lesson · CIPP/USManaging User Preferences and Dark Patterns
Managing preferences raises challenges of scope, mechanism, linking across channels, time period, and third-party vendors. Good practice: the channel for…
Lesson · CIPP/USOpt-In, Opt-Out, and No Option
U.S. laws differ on consent: opt-in (COPPA parental consent, HIPAA PHI disclosure, FCRA credit report release); opt-out (GLBA third-party transfers, VPPA…
Lesson · CIPP/USDPIA vs PIA: What Is the Difference? CIPP/US Guide
DPIA vs PIA explained: what each assessment is, when the GDPR requires a DPIA, what a U.S. PIA covers and how CIPP/US questions test the difference.
Lesson · CIPP/USDelivering Privacy Notices - Layered, Just-in-Time, and Mobile
Notices should be accessible online and in-person, with training for staff. Common techniques include the layered notice (short top layer plus full bottom…
Lesson · CIPP/USPrivacy Operational Life Cycle - Assess, Protect, Sustain, Respond
The privacy operational life cycle continuously improves the program through four stages: assess, protect, sustain, and respond - from baselining and…
Lesson · CIPP/USDrafting, Updating, and Versioning the Privacy Policy
Policies need legal review and executive approval, periodic review (at least annually), and version control. The FTC says express affirmative consent…
Lesson · CIPP/USPrivacy Policy vs Privacy Notice: The Difference for CIPP/US
Privacy policy vs privacy notice explained: the policy is the internal rulebook, the notice is the external statement to consumers, and the exam tests…
Lesson · CIPP/USThe Privacy Program and Four Business Risks
A privacy program establishes accountability and compliance, and should balance four business risks: legal, reputational, operational, and strategic. The…
Lesson · CIPP/USPrivacy Program Framework and Metrics
A privacy program framework operationalizes controls and should begin with a privacy mission statement/vision aligned to the organization. Building it…
Lesson · CIPP/USPrivacy Risk Management and Privacy Harms
Privacy risk management identifies and mitigates risks to information assets. Privacy risk is the likelihood individuals will experience problems from…
Lesson · CIPP/USPrivacy Team Roles - CPO, DPO, and Others
A privacy team may include a CPO, DPO, chief legal officer, privacy engineer, privacy manager, and privacy analyst, plus informal privacy champions and…
Lesson · CIPP/USVendor and Third-Party Risk Assessments
Companies remain responsible for vendor actions and must use contract protections (confidentiality, no further use, subcontractor flow-down, breach…
Lesson · CIPP/USAdditional FTC Authority: COPPA, HITECH, FCRA, CAN-SPAM
Beyond Section 5 the FTC enforces COPPA (children under 13, parental consent), shares HITECH breach authority with HHS, has historic FCRA/FACTA authority…
Lesson · CIPP/USAdditional State Protections: Torts, BIPA, and the AADC Act
States add protection via constitutions, common-law privacy torts, and contract theories. Illinois's BIPA (2008) requires notice and consent for…
Lesson · CIPP/USDeceptive Trade Practices and Broken Privacy Promises
A deceptive practice is a material statement or omission likely to mislead reasonable consumers. Breaking a privacy-notice promise is deceptive under…
Lesson · CIPP/USFederal Privacy Enforcement Outside the FTC
Many federal agencies enforce privacy depending on the statute violated: OCR/HHS for HIPAA, CFPB and bank regulators for GLBA, Dept. of Education for…
Lesson · CIPP/USThe Federal and State Regulatory Landscape
In the U.S., privacy is regulated at both federal and state level. Federal regulators are largely sectoral (medical, financial, education), the FTC is the…
Lesson · CIPP/USFTC Enforcement Process and Consent Decrees
Most FTC privacy actions end in a consent decree: the respondent does not admit fault but promises to change practices. Decrees are public, may require…
Lesson · CIPP/USFTC Enforcement Tools and the AMG Decision
The FTC uses Section 5(l) for administrative cease-and-desist enforcement and Sections 13(b) and 19 for judicial relief. The Supreme Court in AMG Capital…
Lesson · CIPP/USThe FTC, Section 5, and Jurisdictional Limits
Section 5 of the FTC Act bars unfair or deceptive acts or practices in or affecting commerce and is the single most important piece of U.S. privacy law…
Lesson · CIPP/USThe Future of FTC Enforcement
FTC priorities track technology: a 2023 Office of Technology, 2022 proposed commercial surveillance rules (under Magnuson-Moss), a 2020 data portability…
Lesson · CIPP/USFTC Rulemaking Under Magnuson-Moss
The FTC's UDAP rulemaking does not use ordinary APA notice-and-comment. It must follow the complex Magnuson-Moss (Section 18) procedures, showing the…
Lesson · CIPP/USOther Federal Privacy Actors and the DOJ's Criminal Role
Beyond sector regulators, agencies like State, Commerce, Transportation, OMB, IRS/Treasury, DHS, and DOE touch privacy. OMB interprets the Privacy Act of…
Lesson · CIPP/USSelf-Regulation and Enforcement
Self-regulation spans legislation, enforcement, and adjudication. Under Section 5/UDAP it is only quasi-legislative (a government agency still enforces)…
Lesson · CIPP/USState Attorneys General and UDAP Statutes
State AGs are the primary privacy enforcers in most states and may join federal actions under HIPAA, GLBA, and CAN-SPAM. All 50 states have UDAP statutes…
Lesson · CIPP/USState Breach Notification, SSN Protections, and Identity Theft Laws
California enacted the first breach law in 2002; all 50 states now have one. Breach-law personal information centers on name + SSN, driver's license/ID…
Lesson · CIPP/USState Comprehensive Laws and Federal Sectoral Exemptions
By end of 2022, five states had comprehensive laws: California, Colorado, Connecticut, Utah, Virginia. They reference COPPA for children and exempt…
Lesson · CIPP/USTypes of Litigation and Enforcement
Three main categories of legal action: civil litigation (private plaintiff seeks damages or an injunction), criminal prosecution (government, can mean…
Lesson · CIPP/USUnfair Trade Practices
An unfair practice causes or is likely to cause substantial injury that is not reasonably avoidable by consumers and not outweighed by countervailing…
Lesson · CIPP/USCourt Confirmation of FTC Authority: Wyndham and LabMD
FTC v. Wyndham (2015, Third Circuit) confirmed the FTC's unfairness authority extends to cybersecurity. FTC v. LabMD (2018, Eleventh Circuit) recognized…
Lesson · CIPP/USAccess, Correction, and Deletion Rights
All five states grant access and deletion; the right to correction is provided by everyone except Utah. Deletion scope differs: Colorado, Connecticut…
Lesson · CIPP/USDefining Business - Applicability Thresholds
Which companies are covered turns on the definition of business (called controller in the four non-California states). California is broadest ($25M…
Lesson · CIPP/USWhich Entities Are Excluded from Business
All five states exempt governments, nonprofits, and FCRA-covered entities. But the states diverge on higher education, securities associations, and…
Lesson · CIPP/USCCPA vs CPRA: What Changed? CIPP/US California Guide
CCPA vs CPRA explained: the CPRA amended the CCPA rather than replacing it. What changed, what the exam tests and how to answer California questions.
Lesson · CIPP/USOpt-In Default for Children's Data
Age-based opt-in rules vary: California requires opt-in to sell/share data of consumers under 16; Connecticut requires opt-in for ages 13-16 to sell or…
Lesson · CIPP/USDefining Consumer - Who Is Protected
All five laws protect their state residents, and the term is NOT limited to purchasers. The key distinction: California includes employees in its…
Lesson · CIPP/USConsumer Rights Overview and Response Timelines
These laws grant GDPR-like rights (access, correction, deletion, portability, opt-outs, etc.). Response times: Colorado, Connecticut, Utah, Virginia allow…
Lesson · CIPP/USCure Periods and the Private Right of Action
Cure periods split: California's expired; Colorado and Connecticut's sunset Dec 31, 2024; Utah and Virginia have a 30-day cure with no end date. No state…
Lesson · CIPP/USEnforcement - Penalties and Enforcers
The state attorney general has sole or joint enforcement power in every state; California adds the CPPA. Penalty caps vary: California $2,500 (up to…
Lesson · CIPP/USEntity-Level vs Data-Based Exemptions
State comprehensive laws use two exemption types: entity-level exemptions (a whole organization is exempt) and data-based exemptions (only a class of data…
Lesson · CIPP/USThe U.S. Has No Federal Comprehensive Privacy Law
The United States regulates privacy sectorally (HIPAA, GLBA, COPPA) and as of this writing has no federal comprehensive privacy law, unlike most countries…
Lesson · CIPP/USBusiness Obligation - Notice and Transparency
All five states require a privacy notice and a notice of the right to opt out. Only California requires notice at the point of collection, and California…
Lesson · CIPP/USOpt-Out Rights - Sales, Targeted Advertising, Automated Decisions
All five states allow opt out of sales; California also lets consumers opt out of sharing. For targeting/cross-context behavioral advertising, Colorado…
Lesson · CIPP/USPersonal Information and Its Exclusions
All five define personal information as data linkable to an individual, going beyond breach-notification definitions. California uniquely includes…
Lesson · CIPP/USFederal Preemption and Private Right of Action Debates
The two most contested issues in any U.S. national privacy bill are preemption (would it override stricter state laws?) and a private right of action…
Lesson · CIPP/USPurpose Limits, Risk Assessments, and Security
California, Colorado, Connecticut, Virginia impose purpose/processing limitations and require risk assessments for heightened-risk processing; Utah lacks…
Lesson · CIPP/USSale and California's Unique Sharing Regulation
Each state regulates the sale of personal data, but the definition splits: Utah and Virginia limit sale to monetary compensation, while California…
Lesson · CIPP/USRights Concerning Sensitive Data and Nondiscrimination
Sensitive-data handling splits sharply: Colorado, Connecticut, Virginia require opt-in consent; Utah requires only notice and opt-out; California uses a…
Lesson · CIPP/USSensitive Personal Information
All five states treat citizenship, genetic/biometric data, physical/mental health, race/ethnicity, religion, and sexual orientation as sensitive. States…
Lesson · CIPP/USThe Five State Laws in Effect in 2023
This chapter focuses on the five state comprehensive laws in effect in 2023: California, plus the CPA (Colorado), CTDPA (Connecticut), UCPA (Utah), and…
Lesson · CIPP/USCIPP/US Global Privacy Control and opt-out signals
Global Privacy Control and California opt-out handling explained for CIPP/US study.
Lesson · CIPP/USNotification: Attorney General and State Agency Notice
About two-thirds of states require notice to the attorney general/state agency, often above a numeric threshold (commonly 250 to 1,000 people). Vermont's…
Lesson · CIPP/USCommon Structure of State Breach Laws
Despite differences, state breach laws share three building blocks: key terms (personal information, covered entities, security breach), notification…
Lesson · CIPP/USCalifornia Statutory Damages (CCPA/CPRA)
In 2020 California became the first state to let consumers recover statutory damages for breaches: $100 to $750 per incident where the breach resulted…
Lesson · CIPP/USState Breach, Security, and Destruction Laws: The Landscape
All 50 states have data breach notification laws, and many states layer on data security laws and data destruction laws. With no comprehensive federal…
Lesson · CIPP/USBreach Laws: Covered Entities
Most states cover entities that conduct business in the state and maintain computerized data containing personal information. Georgia is a notable…
Lesson · CIPP/USNotification: Consumer Reporting Agencies
About two-thirds of states require notice to nationwide CRAs, often above a 250 to 1,000 threshold. The common timing standard is without unreasonable…
Lesson · CIPP/USNotification: Free Credit Monitoring
When SSNs are exposed, the FTC suggests offering at least a year of free credit monitoring. Three states - California, Delaware, and Massachusetts -…
Lesson · CIPP/USWhen Notification May Be Delayed
When a breach is suspected to involve criminal activity, all states allow delay if law enforcement determines notice would impede a criminal…
Lesson · CIPP/USEnforcement: Penalties and Private Rights of Action
All 50 states impose civil penalties; about one-third let the attorney general levy fines, often capped per breach ($750,000 being the highest noted, in…
Lesson · CIPP/USExceptions to Notification
Three exceptions excuse notice: an entity subject to a more stringent law (e.g., HIPAA or the GLBA Safeguards Rule), an entity following its own…
Lesson · CIPP/USNotification: Method and Substitute Notice
The default method is written notice by postal mail. Email or phone are usually allowed only if the person previously and explicitly chose that channel…
Lesson · CIPP/USThe Absence of a Federal Breach Law
Calls for a uniform federal breach law go back to 2003, but no comprehensive federal data breach notification law has been enacted. The deadlock turns on…
Lesson · CIPP/USNotification: Content of the Letter
About half of states mandate specific content (incident description, approximate date, data types, steps taken, contact phone, identity-theft steps, CRA…
Lesson · CIPP/USBreach Laws: Defining Personal Information
In most states, personal information means a person's first name or first initial and last name combined with at least one of: SSN, driver's license/state…
Lesson · CIPP/USBreach Laws: Security Breach and Risk-of-Harm
A security breach is generally unauthorized access to or acquisition of computerized personal data that compromises its confidentiality, security, or…
Lesson · CIPP/USState Data Destruction Laws
About two-thirds of states have data destruction (disposal) laws requiring personal information to be disposed of so it is no longer readable or…
Lesson · CIPP/USState Data Security Laws
About two-thirds of states require data security measures. Roughly 20 states use a 'reasonable security' standard (e.g., California's AB 1950); about 10…
Lesson · CIPP/USUS Approach in Context
The lack of comprehensive federal breach, security, and destruction requirements leads some to call the US less stringent than jurisdictions like Europe…
Lesson · CIPP/USNotification: Timing to Affected Parties
The most common timing standard is as expeditiously as possible and without unreasonable delay. Where a specific cap is set, 45 days after discovery is…
Lesson · CIPP/USNotification: Whom to Notify
Breach laws commonly require notice to three audiences: affected residents (all 50 states), state attorneys general/agencies (about two-thirds), and…
Lesson · CIPP/USCIPP/US data broker registration and deletion guide
California data broker registration and deletion mechanisms explained for CIPP/US study.
Lesson · CIPP/USCIPP/US biometric privacy law and facial data guide
State biometric privacy law concepts explained with a source-backed CIPP/US study bridge.
Lesson · CIPP/USCIPP/US Illinois genetic privacy law guide
Illinois genetic privacy law explained with a direct answer and CIPP/US study context.
Lesson · CIPP/USCIPP/US Washington consumer health data law guide
Washington consumer health data law explained with a source-backed CIPP/US study bridge.
Lesson · CIPP/USCIPP/US state AI and employment decision guide
Automated employment decision tool rules explained with a source-backed CIPP/US study bridge.
Lesson · CIPP/USBusiness Associates and BAAs
A business associate performs services for a covered entity involving the use or disclosure of PHI. Before HITECH they were bound only by contract; after…
Lesson · CIPP/USCovered Entities Under HIPAA
HIPAA directly covers health care providers conducting certain electronic transactions, health plans, and health care clearinghouses. Cash-only providers…
Lesson · CIPP/US21st Century Cures Act and Information Blocking
The Cures Act (2016) promotes EHI interoperability by prohibiting information blocking - activity likely to interfere with access, exchange, or use of…
Lesson · CIPP/USCures Act: API Portability and Other Privacy Provisions
The Cures Act requires certified health IT developers to publish APIs so patients can move EHI to apps of their choosing - raising the concern that data…
Lesson · CIPP/USGINA Preemption and State Genetic Laws
GINA is a floor and does not preempt stricter state law. Because GINA leaves life insurers, mortgage lenders, and schools untouched, states like…
Lesson · CIPP/USGenetic Information Nondiscrimination Act (GINA)
GINA (2008) bars health insurers from discriminating on genetic predisposition absent manifest symptoms and bars employers from using genetic information…
Lesson · CIPP/USHIPAA Enforcement and Penalties
The OCR enforces both rules with civil penalties up to roughly $2 million per year per violation type and audits entities. HIPAA has no private right of…
Lesson · CIPP/USHIPAA Origins and Purpose
HIPAA became law in 1996 to improve health care efficiency, requiring electronic reimbursement formats for Medicare and Medicaid. Recognizing the privacy…
Lesson · CIPP/USHIPAA Preemption and State Laws
HIPAA does not preempt stricter state laws. Practitioners must review state law for added patient rights, extra disclosures, and shorter deadlines, and…
Lesson · CIPP/USHealth Information Is Protected Differently by Setting
HIPAA only applies to covered entities and their business associates. The same health-related data held by a bookstore, website, or smartwatch maker…
Lesson · CIPP/USHITECH and Breach Notification
HITECH (2009) strengthened HIPAA and created breach notification. A breach is presumed unless a risk assessment shows low probability of compromise…
Lesson · CIPP/USHITECH: Penalties, Limited Data, and EHRs
HITECH increased penalties (up to $2 million for willful violations, even without knowledge) and extended criminal liability to individuals. It encourages…
Lesson · CIPP/USMedical Technology: FTC Act, FDCA, and State Laws
For medtech outside HIPAA, Section 5 of the FTC Act is the primary federal tool against deceptive and unfair practices (e.g., the 2021 Flo Health action)…
Lesson · CIPP/USPHI and ePHI Defined
PHI is individually identifiable health information held by a covered entity or business associate relating to a person's health, care, or payment. ePHI…
Lesson · CIPP/USLimits and Exceptions to the Privacy Rule
The Privacy Rule does not apply to deidentified information and offers flexibility for research. Other exceptions allow disclosure without consent for…
Lesson · CIPP/USThe HIPAA Privacy Rule and the FIPPs
The Privacy Rule is HIPAA's most detailed implementation of Fair Information Privacy Practices: privacy notices, authorizations, minimum necessary limits…
Lesson · CIPP/USThe HIPAA Security Rule
Finalized in 2003, the Security Rule covers only ePHI and binds both covered entities and business associates. It requires administrative, physical, and…
Lesson · CIPP/USConfidentiality of Substance Use Disorder Patient Records Rule
Rooted in 1970s laws, this rule protects patient-identifying information held by federally funded substance abuse treatment programs. It requires written…
Lesson · CIPP/USTemporary COVID-19 telehealth measures
During the COVID-19 public health emergency, OCR temporarily allowed nonpublic-facing videoconferencing even when it did not fully meet HIPAA rules. That…
Lesson · CIPP/USWhy Medical Privacy Gets Special Protection
Health information is treated as especially sensitive because it relates to one's body and mind, encourages candor with doctors, and protects against…
Lesson · CIPP/USCIPP/US FTC health breach notification rule guide
The FTC Health Breach Notification Rule explained with a source-backed CIPP/US study bridge.
Lesson · CIPP/USCIPP/US 42 CFR Part 2 confidentiality guide
42 CFR Part 2 explained with a source-backed CIPP/US study bridge.
Lesson · CIPP/USCIPP/US HIPAA online tracking technology guide
HIPAA online tracking technology issues explained with a source-backed CIPP/US study bridge.
Lesson · CIPP/USAnti-Money-Laundering: The Bank Secrecy Act
The Bank Secrecy Act (1970) imposes recordkeeping and reporting on financial institutions, requiring reports of currency transactions over $10,000 to the…
Lesson · CIPP/USThe Disposal Rule
The Disposal Rule requires anyone using a consumer report for business to dispose of that information reasonably to prevent unauthorized access. It…
Lesson · CIPP/USDodd-Frank and the CFPB's Authority
Dodd-Frank (2010) created the CFPB within the Federal Reserve. The CFPB has rulemaking authority over the FCRA, GLBA and Fair Debt Collection Practices…
Lesson · CIPP/USFACTA Amendments and Consumer Protections
FACTA (2003) amended the FCRA, preempting stricter state laws in most areas (states keep some identity-theft powers). It required truncation of card…
Lesson · CIPP/USAdverse Action Notices
An adverse action is any negative business, credit or employment decision. When a user acts adversely based even in part on a consumer report, it must…
Lesson · CIPP/USCRAs and Consumer Reports Defined
A consumer reporting agency (CRA) compiles or evaluates personal information to furnish consumer reports to third parties for a fee. The FCRA's…
Lesson · CIPP/USCRA Core Requirements: Access, Accuracy, Obsolescence
CRAs must give consumers access and the right to dispute, take reasonable steps for maximum possible accuracy, and not report outdated negatives…
Lesson · CIPP/USConsumer Reports for Employment
Employers using consumer reports must give a clear written stand-alone notice, get prior written authorization, certify compliance to the CRA (including…
Lesson · CIPP/USFCRA Enforcement and Penalties
FCRA enforcement runs through dispute resolution, private litigation (including class actions), and government action by the FTC, CFPB and state attorneys…
Lesson · CIPP/USFurnisher Duties and the Furnisher Rule
Furnishers must provide accurate data, correct and update it, give notice of disputes to CRAs, and respond to identity-theft information. The Furnisher…
Lesson · CIPP/USMisconduct Investigations and Investigative Consumer Reports
Internal misconduct investigations are not consumer reports if the employer follows the act's procedures, uses no credit information, and gives a summary…
Lesson · CIPP/USMedical Information and Prescreened Lists Under FCRA
FCRA limits use of medical information from CRAs, generally requiring consent or coding for insurance, employment or credit uses. Prescreened lists let…
Lesson · CIPP/USPermissible Purpose and Certification
A user may obtain a consumer report only with a permissible purpose and must certify that purpose to the CRA, plus certify the report will not be used for…
Lesson · CIPP/USFCRA Purpose, History and Preemption
Enacted in 1970, the FCRA was the first federal law to regulate private businesses' use of personal information. It mandates accurate, relevant data…
Lesson · CIPP/USRisk-Based Pricing and Credit Score Disclosures
Under the Risk-Based Pricing Rule, lenders must notify consumers who receive less favorable terms because of their credit report. Anyone using credit…
Lesson · CIPP/USUsers and Furnishers Under the FCRA
Beyond CRAs, the FCRA binds users (lenders, insurers, employers who use reports) and furnishers (lenders, retailers who supply data to CRAs). Users need a…
Lesson · CIPP/USFinancial Privacy Landscape and Regulators
U.S. financial privacy is governed mainly by the FCRA (1970), GLBA (1999), and the Dodd-Frank Act (2010), which created the CFPB. Financial institutions…
Lesson · CIPP/USFuture of Financial Regulation and Cryptocurrency Privacy
Cryptocurrency privacy depends on whether governments take a high- or low-regulation approach. Under low regulation, privacy depends on market and…
Lesson · CIPP/USGLBA Overview and Privacy Provisions
GLBA (Title V of the 1999 Financial Services Modernization Act) produced a Privacy Rule and a Safeguards Rule. Spurred by the U.S. Bancorp/MemberWorks…
Lesson · CIPP/USThe GLBA Privacy Rule
The Privacy Rule requires initial and annual privacy notices and processing of opt-outs within 30 days. Institutions may freely share with affiliates and…
Lesson · CIPP/USThe GLBA Safeguards Rule
The Safeguards Rule (effective 2003, updated by the FTC in 2021) requires a written information security program with administrative, technical and…
Lesson · CIPP/USGLBA Scope, NPI and Enforcement
GLBA covers financial institutions significantly engaged in financial activities and regulates nonpublic personal information (NPI). Enforcement runs…
Lesson · CIPP/USUSA PATRIOT Act, KYC, FATCA and the AML Act of 2020
The International Money Laundering Abatement and Anti-Terrorist Financing Act (2001), part of the USA PATRIOT Act, expanded the BSA and added Know Your…
Lesson · CIPP/USThe Red Flags Rule
The Red Flags Rule requires financial institutions and creditors to maintain written identity-theft detection programs that spot and respond to red flags…
Lesson · CIPP/USRegulation E and EFTA. CIPP/US transfer rules guide
Regulation E and the EFTA explained with coverage, consumer protections and CIPP/US study context.
Lesson · CIPP/USSuspicious Activity Reports and BSA Enforcement
Institutions must file a Suspicious Activity Report (SAR) with FinCEN for insider crimes regardless of amount, crimes of $5,000+ with a suspect, crimes of…
Lesson · CIPP/USState Financial Privacy: California (CFIPA) and New York (NYDFS)
Because GLBA does not preempt states, California's CFIPA (SB-1) adds opt-in consent for sharing with nonaffiliated third parties, and New York's NYDFS…
Lesson · CIPP/USCIPP/US Bank Secrecy Act and merger privacy guide
Bank Secrecy Act and merger privacy issues explained with a CIPP/US study bridge.
Lesson · CIPP/USCIPP/US GLBA annual privacy notice guide
GLBA annual privacy notices explained with a source-backed CIPP/US study bridge.
GuideCIPP/E, CIPP/US or AIGP?
Compare CIPP/E, CIPP/US and AIGP. See what each certification covers, who it suits and where to begin independent study.
Guide · AIGPAIGP Body of Knowledge 2026 explained
The four domains in the 2026 IAPP AIGP Body of Knowledge, translated into a practical study plan and exam-scenario checklist.
Guide · AIGPAIGP exam format and blueprint
Current AIGP format, timing and how to use the published IAPP Body of Knowledge and Exam Blueprint.
Guide · AIGPAIGP exam questions
How to approach AIGP questions using context, risk, governance controls and accountability.
Guide · AIGPAIGP practice exam
Independent AIGP practice questions, a timed-study method and an evidence-led review routine.
Guide · AIGPAIGP study guide
Free AIGP notes and study lessons arranged around four current knowledge areas, with retrieval practice and scenario review.
Guide · AIGPAIGP study plan
A four-week AIGP study plan using the published outline, retrieval practice and scenario questions.
Practice · AIGPFind the AIGP areas to study next.
Take a free 10-question AIGP diagnostic. Get an immediate domain score and a personalised study plan without creating an account.
Glossary · AIGPAIGP glossary
AIGP glossary with key AI governance terms, linked lessons and a practical way to review exam vocabulary.
Guide · AIGPHow to pass the AIGP
How to prepare for the IAPP AIGP exam using current format details, a flexible study plan, common mistakes and exam-style practice.
Guide · AIGPIs the AIGP exam hard?
Is the AIGP exam hard? Format, pass mark, the four domain weights, where candidates struggle and a practical way to prepare.
Practice · AIGPFree AIGP mini mock
Try 25 exam-style AIGP practice questions free, with explanations and a domain score. No account or payment required.
Practice · AIGPInstead of 'provider' and 'deployer', what term does South Korea's AI Basic Act use?
Instead of 'provider' and 'deployer', what term does South Korea's AI Basic Act use? Answer with a worked explanation and related free lesson.
Lesson · AIGPThe AI system development life cycle
Seven stages from plan/design to decommissioning, with governance hooks at each. The life cycle is iterative, not linear and building AI is never a…
Lesson · AIGPThe AI family tree
Each layer is a subset of the one above: GenAI ⊂ DL ⊂ ML ⊂ AI. Agentic AI is the odd one out - it can be comprised of all categories of AI, leveraging…
Lesson · AIGPArchitectures and the buzzwords that matter
Governance pros must hold a credible conversation about architectures: transformer models (process inputs in parallel), multimodal models/LMMs (WHO 2024…
Lesson · AIGPFour building-block terms
Data, algorithm, model and system nest inside each other and the exam tests them exactly. An algorithm produces the model; the model applies algorithms to…
Lesson · AIGPExpert systems
An older flavour of AI that mimics a human expert in one field via a knowledge base, inference engine and user interface. The canonical example is a…
Lesson · AIGPFive algorithms to recognise on sight
Governance pros must recognise five algorithms to talk risk: linear regression, logistic regression (binary outcome), decision trees, random forests (an…
Lesson · AIGPThe four ways machines learn
Four ML approaches: supervised (labelled), unsupervised (unlabelled), semi-supervised (small labelled + large unlabelled) and reinforcement (agent learns…
Lesson · AIGPThe intelligence ladder: ANI to ASI
Four levels of AI capability, only ANI fully real today. Broad AI is the intermediate step; AGI and ASI do not currently exist. If a question describes a…
Lesson · AIGPModel face-offs the exam loves
Four head-to-head comparisons straight from the performance indicator: classic vs generative, proprietary vs open source, small vs large LMs, and language…
Lesson · AIGPOECD Framework for the Classification of AI Systems
A user-friendly framework that classifies AI systems and examines their risks across five dimensions (mnemonic PEDMT). Privacy sits under People and…
Lesson · AIGPTech megatrends and AI
Some megatrends fuel AI, some are fuelled by it, and some raise the governance stakes. AI drives the need for PETs; blockchain is not universally…
Lesson · AIGPUse cases and benefits
The course groups AI uses into 7 buckets: Recognition, Event detection, Forecasting, Personalisation, Interaction support, Goal-driven optimisation and…
Lesson · AIGPWhat is AI
There is no single definition of AI; the exam wants the common elements that recur across definitions. AI is not a specific technology, but a branch of…
Lesson · AIGPWhy AI needs a comprehensive governance approach
Seven unique characteristics (mnemonic A COD SHiP) make AI harder to govern than ordinary software. The central governance challenge is balancing…
Lesson · AIGPThree AI harms taxonomies
AI-specific frameworks. The Sociotechnical Harms taxonomy has five themes; the CSET AI Harm Taxonomy defines AI harm with four elements, all four must be…
Lesson · AIGPEnvironmental harms
Four quantified facts - the numbers are the exam bait. Training a large model can emit over 626,000 pounds of CO₂ (~five times the lifetime emissions of…
Lesson · AIGPCreating ethical AI in practice
The operational checklist for deciding which use cases meet an organisation's ethical principles - spanning legal review, equitable design, transparency…
Lesson · AIGPSeven ethical issues and three foundational controls
The Seven ethical issues responsible AI must address - lawfulness, safety, bias protection, transparency, choice, human intervention, security - and the…
Lesson · AIGPEthics by design
Ethics by design is the sibling of privacy by design: ethical issues are resolved at the start and reassessed during deployment because risks change. The…
Lesson · AIGPThe FIPs: where all of this started
AI ethics frameworks descend from the FIPs (Fair Information Practices), originated in 1980 by the OECD Guidelines on the Protection of Privacy and…
Lesson · AIGPWho gets harmed: the five targets
The exam frames every harm question around who is affected. The Five harm targets are individuals, groups, society, organisations and ecosystems - and…
Lesson · AIGPGroup and societal harms
Group harm is discrimination against a population subgroup; societal harm is damage to the democratic process and participation. Examples include group…
Lesson · AIGPHarms taxonomies 101
A Harms taxonomy is a list of negative consequences that could befall a data subject or organisation - an ontological map breaking harms into constituent…
Lesson · AIGPIndividual harms and the anatomy of bias
Individual harms hit civil liberties, safety or economic opportunity, and bias is the engine. Know Implicit bias, Sampling bias and Temporal bias on…
Lesson · AIGPAI impacts and responsible AI
Before deploying AI, governance professionals must grasp the harms it can cause. AI poses risks already understood in existing sectors, but the scale…
Lesson · AIGPThe five OECD AI Principles
The OECD AI Principles are the base layer many organisations copy into their governance frameworks. Know all five (mnemonic: Inclusive Humans Trust Robust…
Lesson · AIGPOrganisational harms
Five harm types every organisation deploying AI must price in: reputational, cultural, economic, Acceleration risk and legal. Acceleration risk is the odd…
Lesson · AIGPThree privacy harms taxonomies
Match the name to the structure. MITRE PANOPTIC combines contextual domains and privacy activities; the Ryan Calo taxonomy splits harm into subjective vs…
Lesson · AIGPTrustworthy AI: the HAT test
The HAT test characterises trustworthy AI as Human-centric, Accountable, Transparent, operating in an expected, legal and fair manner. Explainability and…
Lesson · AIGPAI impact assessments and ISO 42005
The AI impact assessment (AIIA) is the severity lens: it gauges how bad mapped risks are, while a risk assessment flags which systems need extra…
Lesson · AIGPAligning risk strategies
New AI risk processes must slot into existing risk machinery. Determine whether AI increases existing risks or introduces new ones, decide who is…
Lesson · AIGPBusiness, regulatory and legal risks
Six direct business risks: bias & discrimination, job displacement, vendor dependence, liability & accountability, lack of transparency, IP infringement…
Lesson · AIGPCalculating risk
The working Risk formula is probability × severity. High: avoid or change; medium: explore and mitigate. Plus the four technical assessment categories and…
Lesson · AIGPCulture and operationalising responsible AI
Six culture moves (customer value, cultural variation, responsible AI as a discipline, HR engagement, common taxonomy, knowledge resources), then the…
Lesson · AIGPThe four AI risk categories
Operational, legal, security, privacy. The Security risk card carries the most testable vocabulary: Adversarial attacks, Hallucinations, Deepfakes and…
Lesson · AIGPThe four roles: developers, providers, deployers, users
Governance responsibilities shift across the AI life cycle. Know each role's signature duties: and the terminology trap that the Colorado AI Act says…
Lesson · AIGPGovernance structure: build it, then pick a model
Five build principles (leverage existing structures, foster community, clear roles, incentivise responsible AI, evolve the programme), then the three…
Lesson · AIGPISO 42001 and HUDERIA
Two frameworks with different DNA: ISO/IEC 42001:2023 is an AI management system standard for any size and industry, while HUDERIA is the Council of…
Lesson · AIGPLife cycle policies and the use case assessment
Policies must create oversight across nine areas of the AI life cycle. The Use case assessment is the front door, running NIST's Map (NIST), Measure…
Lesson · AIGPNIST AI RMF: the full kit
The NIST AI RMF has four pieces (framework, Core, Playbook, GenAI Profile) plus NIST ARIA. Keep the two quartets separate: the NIST Core functions are…
Lesson · AIGPRisk assessment mechanics
Greatest resources go to the highest-risk areas. The 3×3 harms matrix multiplies severity × probability for a score, tolerances vary by organisation, and…
Lesson · AIGPStakeholders: who sits at the table
Cross-functional collaboration is a tested performance indicator. Privacy, security, accessibility and digital safety personnel are crucial first…
Lesson · AIGPTailoring governance: six differentiators
There is no universal AI governance design. Six organisational factors drive the differences: company size, maturity, industry/sector, products &…
Lesson · AIGPTraining, awareness and AI literacy
Training targets the organisation's own AI use and governance, not general AI expertise, across three focus areas. AI literacy is a legal obligation under…
Lesson · AIGPWhat AI governance actually is
AI governance is an organisation's approach to using laws, policies, frameworks, practices and processes at international, national and organisational…
Lesson · AIGPWinning leadership support
Gain leadership support at the earliest opportunity. The course gives a five-step path: understand context, find champions, frame responsible AI as a…
Lesson · AIGPChina, Japan and the rest of the world
China runs a multi-layered, use-case-specific network overseen by the CAC, requiring security reviews and algorithm registration. Japan takes…
Lesson · AIGPConformity assessments, registration and notification
The Conformity assessment (CA) is how compliance is demonstrated for high-risk AI, underpinned by technical documentation. CAs borrow from DPIAs and…
Lesson · AIGPDeployers, importers and distributors
Deployer obligations are fewer than a provider's but broader, centred on transparency and monitoring (EU six-month minimum log retention; FRIA in the EU…
Lesson · AIGPThe eight requirements for high-risk AI
Major AI laws converge on eight obligations for high-risk AI: risk management, data governance, technical documentation, record-keeping, transparency…
Lesson · AIGPEnforcement and penalties
Enforcement runs through central authorities (EU AI Office, SK Ministry of Science & ICT, China's CAC), sectoral regulators and advisory bodies, using…
Lesson · AIGPThe EU AI Act and the Digital Omnibus
The EU AI Act is a risk-based regulation with extraterritorial reach. The AI Omnibus entered into force on 27 July 2026. Most of the Act applied from 2…
Lesson · AIGPThe four regulated roles
Regulation distributes duties across the supply chain: a Provider builds the system, an Importer brings it in, a Distributor passes it on, and a Deployer…
Lesson · AIGPGeneral-purpose AI models
General-Purpose AI (GPAI) models are trained for broad tasks and adapt into many downstream systems. EU AI Act Chapter V sets two tiers: baseline duties…
Lesson · AIGPHigh risk - where most regulation lives
High risk / high-impact AI significantly affects rights, safety or access to essential services. It is allowed but under strict obligations, and the…
Lesson · AIGPAI regulation across jurisdictions
Global AI laws share a common regulatory DNA of risk-based classification, role-based responsibilities and transparency requirements; what differs is how…
Lesson · AIGPLimited risk and minimal risk
Limited / transparency risk means disclosure or labelling duties only - inform users they are interacting with AI, label or watermark generated content…
Lesson · AIGPProhibited risk and the banned list
Prohibited risk AI is inherently harmful and restricted or banned in many jurisdictions. Six categories recur, including social scoring, manipulation…
Lesson · AIGPHigh-risk provider obligations
Providers carry the heaviest load because they build the system and put it on the market, so duties span the whole life cycle. Eight converging global…
Lesson · AIGPThe risk classification framework
Risk-based legislation classifies AI into four tiers - Prohibited, High, Limited, Minimal (mnemonic 'Please Handle Laws Mindfully') - and scales the…
Lesson · AIGPSouth Korea's AI Basic Act
The AI Basic Act is the second comprehensive national AI law, effective January 2026. It applies duties uniformly to Business operators (Development and…
Lesson · AIGPThe United States - orders, guidance and state laws
There is no single federal AI statute. Instead: executive orders (EO 14179 replaced the rescinded EO 14110, then America's AI Action Plan), federal…
Lesson · AIGPAnonymisation, Pseudonymisation and PETs
Recital 26 territory: anonymisation removes data from the GDPR entirely, while pseudonymisation is still personal information so GDPR obligations apply…
Lesson · AIGPArticle 22 and Automated Decision-Making
Article 22 is a general prohibition with three exceptions, never an outright ban: automated decision-making is allowed only when necessary for a Contract…
Lesson · AIGPConsumer Protection Laws and AI
The FTC's broad authority over "unfair or deceptive" practices already covers algorithms, and the agency will keep applying it to AI. Several US laws…
Lesson · AIGPObligations on Data Controllers
Controllers decide what and how personal data is processed - whether a human or an AI does the processing, the GDPR still applies. Nine duty areas span…
Lesson · AIGPThe EDPB Opinion on AI Models (2024)
Prompted by the Irish DPA, the European Data Protection Board harmonised how the GDPR treats AI models in three answers: when a model is anonymous, when…
Lesson · AIGPThe GDPR and AI
In effect since 2018, the GDPR is the global baseline for data protection, deliberately technology-agnostic so it can evolve alongside AI. Three…
Lesson · AIGPIntellectual Property and AI
IP is creations of the human mind protected by patents, copyright and trademarks - and generative AI stretches every part of that definition. Key anchors…
Lesson · AIGPThe Lay of the Land
AI may dodge a dedicated statute, but it lives in the same legal context as every other technology: ALL existing laws for a sector or jurisdiction still…
Lesson · AIGPLicensing AI Models and Data
The contract is where IP risk gets managed. Traditional IP indemnities break down for AI because they exclude modifications, combinations and out-of-scope…
Lesson · AIGPNondiscrimination Laws Across Five Sectors
Sector nondiscrimination laws still apply to AI across healthcare, insurance, hiring, credit and housing. Key anchors: Section 1557 (healthcare), NYC…
Lesson · AIGPPrivacy Principles That Govern AI
GDPR, CCPA/CPRA, US state privacy laws, biometrics laws like Illinois BIPA and breach laws all reach consumer-facing AI. Seven principles do the heavy…
Lesson · AIGPProduct Liability Foundations
Who answers when AI causes harm? Two regimes: fault liability (prove an action/inaction caused harm) and strict liability (no-fault - prove only defect…
Lesson · AIGPThe Revised Product Liability Directive
Directive 2024/2853, effective December 2026, makes it easier for victims of AI-caused harm to prove liability and get compensated. It expands "products"…
Lesson · AIGPSensitive and Special Categories of Data
Special categories of data need extra protection under the GDPR and Brazil's LGPD - eight types captured by the mnemonic "Really Private Records Take…
Lesson · AIGPBuilding, Training and the Three Lines of Defence
Development is iterative - train, test, fine-tune, then prove the model generalises on new data beyond the training set. Human oversight uses the 3LOD…
Lesson · AIGPData Formats and the Five V's
Know the three structure types (structured, unstructured, semi-structured), the static/streaming split, and the five V's of data preparation: Volume…
Lesson · AIGPGoverning the AI Data Life Cycle
Data governance spans ingestion to decommissioning with cross-functional stewardship. The data life cycle runs Collection: Use: Disclosure: Retention…
Lesson · AIGPData Questions, Quality, Jurisdiction and Lineage
Without the right, enough and accurate data the system won't perform - garbage in, garbage out. Anticipate jurisdiction (data localisation laws, KYC), and…
Lesson · AIGPDocumentation, Communication and Decommissioning
Document every decision with model cards, counterfactual explanations and remediation owners; communicate by audience; and retire systems via ten…
Lesson · AIGPFeatures and Feature Engineering
A feature is a specific measurable aspect or characteristic. Feature engineering decides which ones matter, with three purposes - improve performance (the…
Lesson · AIGPImpact Assessments in the Design Phase
An impact assessment is a risk management tool assessing an AI system's benefits, risks and limitations across the life cycle. The AIA covers data issues…
Lesson · AIGPThe AI Development Life Cycle Revisited
AI development mirrors the software life cycle plus a data obsession and continuous monitoring. Policies, procedures, best practices and ethics apply at…
Lesson · AIGPMetrics, Thresholds, Audits and Monitoring
Establish measures (e.g. the Adverse Impact Ratio), set thresholds, baseline, then monitor over time. Audits assess performance, reliability and safety…
Lesson · AIGPOperational Controls - Five Owners to Name
Controls are only real when someone owns them. The memorable owner is the kill switch - a named person with authority to shut the system down when an AI…
Lesson · AIGPPlanning Essentials - The Five Moves
Define objectives, pick use cases, scope, check the data, stand up governance - in that order. Scope is prioritised via Impact, Effort and Fit, and…
Lesson · AIGPThe Six Risk Assessment Strategies, In Order
A repeatable sequence - Use Smart Methods, Handle Big Projects - to identify, evaluate, treat and mitigate risk: use case evaluation, stakeholder mapping…
Lesson · AIGPStakeholders - Who, What, and the Hard Calls
Engage stakeholders early, agree the goal, and decide who owns the failures. When values clash - e.g. more accuracy than privacy - the organisation must…
Lesson · AIGPTesting and Validation
Testing is continuous, risk-tailored and documented - test for accuracy, robustness, reliability, privacy, interpretability, safety, security and bias…
Lesson · AIGPWrangling the Data
Five considerations turn raw data into model-ready data without trampling privacy: cleansing, labelling, anonymisation and minimisation. Master the two…
Lesson · AIGPAdapting existing policies for AI
Review the current policy framework for gaps first, then tailor what exists and add what's missing across five areas - data privacy, security…
Lesson · AIGPAgentic AI - what it is
Agentic systems engage, interact and influence rather than sit passively. AI agents focus on specific tasks with simple workflows; Agentic AI involves…
Lesson · AIGPThe agentic risk landscape
Autonomy brings four new risk families: goal misalignment (right goal, wrong way), compounded systemic impact (errors spread across departments and…
Lesson · AIGPWhere the model lives - three environments
The deployment environment depends on budget, IT expertise, model purpose and data type. Cloud scales, on-prem controls, edge localises - each buys one…
Lesson · AIGPGenAI choices and the pre-launch checklist
Generative deployments add their own questions - fine-tuning, retrieval-augmented generation, vector/graph databases and agentic architectures…
Lesson · AIGPIncidents, consequences and accountability
Treat every occurrence as an incident, keep records in an AI registrar, and know the five usual causes - brittleness, lack of robustness, lack of quality…
Lesson · AIGPGoverning AI deployment
Whatever was built, bought or customised, every organisation deploys AI as the final step before use. Deployment is the transition from a development and…
Lesson · AIGPMonitoring, maintenance and drift
Watch for deviations in accuracy and model drift - when the relationship between input data and output predictions changes over time. Model cards document…
Lesson · AIGPPeriodic assessment - performance, reliability, safety
Three assessment lanes keep an ageing model in check: performance, reliability and safety. Four definitions recur: red teaming (simulated adversarial…
Lesson · AIGPDeploying a proprietary model
Developing AND deploying your own model creates a dual role with heightened liability from both providing and using the technology. It brings five…
Lesson · AIGPPublic disclosures and transparency obligations
One notice never fits all, but one rule is near-universal: almost all AI laws worldwide require disclosure that AI is in place, treated by the FTC as a…
Lesson · AIGPRelease readiness
A readiness assessment decides whether the system goes to production. Well-Tested Code Deserves Model-cards - Works as intended, Testing turned out well…
Lesson · AIGPThird-party products and risk
Less visibility never means less responsibility. Third-party AI splits into two contexts - integrated into business operations (needs the more…
Lesson · AIGPThe three-tier guardrail framework
Guardrails scale with use-case risk: Foundation: Risk: Society. Tier 1 foundational guardrails apply to every system and follow ISO/IEC 42001 and the NIST…
Lesson · AIGPThe vendor / open-source agreement checklist
Eight areas to evaluate before signing a vendor or open-source agreement: data considerations, security/safety, bias metrics, product type, technical…
Lesson · AIGPCore AI concepts
The foundation layer of the AIGP vocabulary: what AI is, what it runs on, and its classic forms. Artificial intelligence is defined as machine-based…
Lesson · AIGPData terms
Everything the model eats, before and after cooking. Know which dataset does which job: training data teaches, validation data tunes and checks…
Lesson · AIGPGenerative AI
The GenAI stack from foundation model to prompt - architecture names matter here. RAG is defined by retrieving from a knowledge base beyond the training…
Lesson · AIGPGovernance, assurance and oversight
The accountability vocabulary - who answers, who checks, who can challenge. Conformity assessment is the EU AI Act gate for high-risk systems before…
Lesson · AIGPLearning techniques and methods
The named techniques and model types that show up as one-line scenario answers - including federated learning (data never leaves the site), transfer…
Lesson · AIGPMachine learning families
The four learning paradigms plus the architecture they run on. Label availability is the sorting key: supervised uses labelled pairs, unsupervised finds…
Lesson · AIGPModel mechanics and performance
What is inside the model and how its behaviour is measured and goes wrong. Variables live in the data; parameters and weights live in the model - and…
Lesson · AIGPRisks, security and harms
The attack surface and the falsehood family. Intent is the dividing line: disinformation is deliberate, misinformation is not - and data poisoning is an…
Lesson · AIGPTrust attributes and safeguards
The qualities systems must show and the artifacts and controls that prove or protect them. Reliability is consistency over time; robustness is resilience…
Looking for AI governance? Explore the AIGP study guide.