Study resourcesCertification Study Guides

The complete study library

Find your next study resource

Search 706 free study resources across CIPP/E, CIPP/US and AIGP. Find a lesson, review a term or choose a practice session.

706 resources

Guide · CIPP/E

CIPP/E exam format and blueprint

Current CIPP/E format, timing and how to use the published IAPP Body of Knowledge and Exam Blueprint.

Guide · CIPP/E

CIPP/E exam questions

How to approach CIPP/E questions using scope, legal basis, rights, accountability and enforcement.

Guide · CIPP/E

CIPP/E practice exam

Independent CIPP/E practice questions, a timed-study method and an evidence-led review routine.

Guide · CIPP/E

CIPP/E study guide

A free CIPP/E study guide structured around the published IAPP outline and active recall.

Guide · CIPP/E

CIPP/E study plan

A four-week CIPP/E study plan using the published outline, retrieval practice and scenario questions.

Practice · CIPP/E

CIPP/E cram sheet

The complete CIPP/E memorisation sheet: key dates, fines and numbers, the principles, lawful bases, rights, transfers, cases and the classic exam traps.

Practice · CIPP/E

Find the CIPP/E areas to study next.

Take a free 10-question CIPP/E diagnostic. Get an immediate domain score and a personalised study plan without creating an account.

Glossary · CIPP/E

CIPP/E glossary

Plain-language definitions for recurring terms in the CIPP/E study guide.

Guide · CIPP/E

How to pass the CIPP/E

How to prepare for the IAPP CIPP/E exam using current format details, a flexible study plan, common mistakes and exam-style practice.

Guide · CIPP/E

Is the CIPP/E exam hard?

Is the CIPP/E exam hard? Format, pass mark, domain weights, where candidates struggle and a practical way to prepare.

Practice · CIPP/E

Free CIPP/E mini mock

Try 25 exam-style CIPP/E practice questions free, with explanations and a domain score. No account or payment required.

Practice · CIPP/E

Which of these is NOT a data-protection consideration for CCTV under the training?

Which of these is NOT a data-protection consideration for CCTV under the training? Answer with a worked explanation and related free lesson.

Lesson · CIPP/E

Accountability and telling the principles apart

The GDPR reinforces every principle by adding accountability: it places the burden of proof on organisations to demonstrate proper implementation, and…

Lesson · CIPP/E

Accuracy

The accuracy principle requires controllers to take reasonable measures to keep personal data accurate and, where necessary, up to date. This means…

Lesson · CIPP/E

Administrative fines: the two tiers and how they are set (Article 83)

The fines regime (Article 83) has two tiers. The lower tier (Art 83(4)) caps fines at €10 million or 2% of total worldwide annual turnover, whichever is…

Lesson · CIPP/E

Adtech legal basis and automated decisions

Adtech relies on either consent or legitimate interest. Consent is hard: it must be informed and demonstrable, and firms without a direct relationship…

Lesson · CIPP/E

Applications on mobile devices

Mobile apps collect large volumes of often intimate data via sensors (location, audio, video) and stored data (contacts, photos). Devices are rarely…

Lesson · CIPP/E

Article 13 vs Article 14 - what must be provided

The primary information duties sit in Article 13 (data collected directly from the data subject) and Article 14 (data obtained from another source). Both…

Lesson · CIPP/E

Article 3(1): EU-established controllers and processors

Under Article 3(1) the GDPR applies to processing 'in the context of the activities of an establishment of a controller or a processor in the Union'…

Lesson · CIPP/E

Article 3(2): the targeting and monitoring tests

Article 3(2) is the long-arm rule for organisations not established in the EU. It catches their processing of personal data of data subjects who are in…

Lesson · CIPP/E

Article 33 - notifying the supervisory authority

Article 33 requires the controller to notify the supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours…

Lesson · CIPP/E

Article 33 vs Article 34 - side-by-side comparison

Both Article 33 and Article 34 are risk-reporting duties on the controller, but they differ on who is told, the threshold , the deadline and the content …

Lesson · CIPP/E

Article 34 - communicating the breach to data subjects

Article 34 requires controllers to inform affected individuals without undue delay where a breach is likely to result in a high risk to their rights and…

Lesson · CIPP/E

Article 9 exceptions - the ten conditions

Article 9's prohibition is lifted by ten conditions. The headline ones: explicit consent (more than ordinary consent); employment/social-security law…

Lesson · CIPP/E

Artificial Intelligence and the EU AI Act

AI systems may process personal data during design, training, testing and deployment, so the GDPR can apply throughout the lifecycle. Articles 13 and 14…

Lesson · CIPP/E

Background - Lisbon Treaty and institutional reform

The Treaty of Lisbon reformed the EU's institutional structure to cut bureaucracy and speed up decision-making after enlargement. Article 13 of the EU…

Lesson · CIPP/E

Background - the rights and their Articles

European data protection law has always given individuals enforceable rights, but the GDPR is far more extensive than the old Data Protection Directive…

Lesson · CIPP/E

Background & the role of consent

The GDPR requires controllers to process personal data lawfully, fairly and in a transparent manner. Article 6 and Article 9 set out the criteria for…

Lesson · CIPP/E

Background to European data protection law

European data protection law grew out of fears that new technologies - phone-tapping, surveillance, large mainframe computers - threatened individual…

Lesson · CIPP/E

Background - why security is an A-list principle

Security is not just one principle among many; it underpins compliance with all the others. Insecurity can trigger unlawful transfers, inaccuracy, data…

Lesson · CIPP/E

Binding corporate rules and conclusion

Binding corporate rules (BCRs) can support an accountability framework. Sometimes called the gold standard of global data protection, they are a single…

Lesson · CIPP/E

Binding corporate rules (BCRs) for intra-group transfers

BCRs are a global set of internal rules based on European privacy standards that a multinational group adopts voluntarily and a regulator approves, to…

Lesson · CIPP/E

Binding corporate rules for processors

Binding corporate rules (BCRs) are internal, legally binding data protection rules adopted by multinationals. The original BCR model applied only where a…

Lesson · CIPP/E

Biometric data as special-category data

Biometric data is defined in Article 4(14) as personal data from specific technical processing of physical, physiological or behavioural characteristics…

Lesson · CIPP/E

Blueprint Check, Domain coverage map (I–III)

A cross-check of the CIPP/E Exam Blueprint against this guide. Every competency in Domains I, II and III is covered by both this guide chapters and the…

Lesson · CIPP/E

Blueprint Check, Domain coverage map (IV–V) & gap analysis

The cross-check for Domains IV (Scope & Accountability) and V (Compliance), plus the short list of items the official training reinforced on top of this…

Lesson · CIPP/E

Brexit and UK data protection

After Brexit, withdrawal legislation repealed the European Communities Act 1972, converted the GDPR into the UK GDPR (retained EU law, amended by the 2019…

Lesson · CIPP/E

Bring your own device (BYOD)

Under BYOD, employees use personal devices for work. The employer remains the controller for work-related personal data processed on the device, yet the…

Lesson · CIPP/E

Channel-by-channel rules: the consent matrix

This is the heart of the chapter for exam purposes. Post is GDPR-only (no ePrivacy), usually consent or legitimate interests. Live phone calls are left to…

Lesson · CIPP/E

Cloud computing: models and applicable law

Cloud computing is IT services delivered over the internet, split into IaaS, PaaS and SaaS by how much the supplier provides. Cloud infrastructure is…

Lesson · CIPP/E

Cloud: controllership issues

In most supply-of-services cases the customer is the controller (it decides purposes and means) and the supplier is a processor. But in cloud this can't…

Lesson · CIPP/E

Cloud: international data transfers

Cloud almost always involves international transfers, and the cloud customer (exporter) is responsible for compliance. Options to provide appropriate…

Lesson · CIPP/E

Cloud service contracts (Article 28)

A GDPR-subject customer must put an Article 28 contract in place with its cloud provider. The GDPR lists mandatory processor terms: processing only on…

Lesson · CIPP/E

Communications data: content, metadata and retention

Electronic communications generate two categories of data: content and metadata (data about data). Metadata splits into traffic data, location data and…

Lesson · CIPP/E

Comparing the transfer mechanisms & the future of restrictions

This pulls the four main routes together - adequacy decision, standard contractual clauses|SCCs, BCRs, and Article 49 derogation|derogations - and this…

Lesson · CIPP/E

Competence, the one-stop shop and the lead supervisory authority

Each DPA is competent in its own territory (Article 55). For cross-border processing, the lead supervisory authority - the DPA of the…

Lesson · CIPP/E

Conclusion: recalibrating responsibilities

The GDPR's biggest change to outsourcing is the recalibration of responsibilities between controllers and processors. Controllers remain primarily…

Lesson · CIPP/E

Consent - definition and the four conditions

Consent is the first Article 6 basis. It is defined as any freely given, specific, informed and unambiguous indication of the data subject's wishes, by a…

Lesson · CIPP/E

Consent vs legitimate interests - choosing correctly

Exam scenarios frequently turn on consent vs legitimate interests. Consent gives the subject control but can be withdrawn at any time, forcing the…

Lesson · CIPP/E

Controller vs Processor - Roles and Liability

A controller is the person or body that alone or jointly determines the purposes and means of processing - the key decision-maker, who carries most GDPR…

Lesson · CIPP/E

Convention 108+

A modernisation protocol - colloquially Convention 108+ - was signed by 21 states on 10 October 2018 after more than seven years of work begun in January…

Lesson · CIPP/E

Convention 108

Convention 108 was opened for signature on 28 January 1981 by the Council of Europe. It was the first legally binding international instrument in data…

Lesson · CIPP/E

Cookies and similar technologies

A cookie is a small text file placed on a device that 'remembers' it. Other tracking tech includes device fingerprinting, tags, pixels, web beacons…

Lesson · CIPP/E

Cooperation, consistency and the EDPB (Articles 60–66, 68–71)

Cross-border cases run through the cooperation procedure (Article 60): the lead authority circulates a draft decision; other concerned DPAs may agree or…

Lesson · CIPP/E

Council of Europe Convention 108

Opened for signature on 28 January 1981, Convention 108 was the first legally binding international instrument in data protection. It rests on data…

Lesson · CIPP/E

Council of the European Union

The Council of the European Union (Council of Ministers) is the EU's main decision-making body and the co-legislator with the Parliament. Do not confuse…

Lesson · CIPP/E

Court of Justice of the European Union (CJEU)

The Court of Justice of the European Union|CJEU, based in Luxembourg, is the EU's judicial body, deciding issues of EU law and enforcing EU decisions. It…

Lesson · CIPP/E

Criminal convictions data (Article 10) & processing without identification (Article 11)

Article 10 data - criminal convictions, offences and related security measures - needs greater protection but is NOT a special category under Article 9…

Lesson · CIPP/E

Data minimisation

Data minimisation means collecting and processing only data that is relevant, necessary and adequate for the purpose - collect only what you really need…

Lesson · CIPP/E

Data protection and direct marketing

Direct marketing is one of the hardest areas of data protection law because it triggers both DP rules and other consumer-protection rules that vary by…

Lesson · CIPP/E

Data protection by design and by default

Article 25 requires data protection by design and data protection by default - the technical and organisational measures a controller builds in to protect…

Lesson · CIPP/E

Data Protection Directive 95/46/EC

Adopted on 24 October 1995, Directive 95/46 was the EU's flagship data protection law, set up as an internal market harmonisation measure under the Treaty…

Lesson · CIPP/E

Data protection impact assessment (DPIA)

A DPIA (also called a PIA) systematically identifies and addresses the data protection impacts of new products, services or activities. Under Article 35…

Lesson · CIPP/E

Data Retention Directive

Directive 2006/24/EC (the Data Retention Directive) aligned national rules on retaining traffic and location data for serious crime and anti-terrorism. In…

Lesson · CIPP/E

Delivering on security - programmes, people, paperwork

A strong security programme is board-endorsed, multidisciplinary, and connects security professionals with data protection and legal staff. Practitioners…

Lesson · CIPP/E

Documentation and records of processing (Article 30)

The GDPR abolished the Directive's notify/register requirement: controllers no longer file processing activities with a DPA. Instead they must keep…

Lesson · CIPP/E

Employee data

Employers process personal data on employees past, present and potential for recruitment, salary, benefits, personnel files, sickness records, monitoring…

Lesson · CIPP/E

Employees, the insider threat, and the controller-processor relationship

Article 32(4) covers employees and other workers acting under the controller's or processor's authority - read with Article 5(1)(f) and Article 28(3)(b)…

Lesson · CIPP/E

Enforcement and conclusion

Enforcement of direct-marketing rules - especially cookies and unsolicited communications - is rising: class actions (Lloyd v Google in the UK…

Lesson · CIPP/E

ePrivacy consent and cookie controllership

Cookie consent must meet GDPR standards. Planet49 confirmed consent is not valid via a pre-ticked box, and users must be told the cookie's duration and…

Lesson · CIPP/E

ePrivacy laws: unsolicited messages and cookies

The ePrivacy Directive adds consent/information rules to digital marketing by phone, fax and electronic mail (incl. SMS, IM, push). The general rule: most…

Lesson · CIPP/E

EU Cloud Code of Conduct

The EU Cloud Code was approved by Belgium's DPA in May 2021 after a positive EDPB opinion. It sets requirements for B2B cloud services where the provider…

Lesson · CIPP/E

European Commission

The European Commission is the EU's executive body but also far more: it holds the right to initiate legislation ('Union legislative acts may only be…

Lesson · CIPP/E

European Council

The European Council gives the EU its political impetus and direction but does not exercise legislative functions. It began as an informal body in 1974…

Lesson · CIPP/E

European Court of Human Rights (ECtHR)

The European Court of Human Rights|ECtHR is not an EU institution. It sits in Strasbourg as part of the Council of Europe, which has 46 member states…

Lesson · CIPP/E

European Parliament

The European Parliament is the only EU institution directly elected by EU citizens, giving it democratic weight. It has four roles: legislative…

Lesson · CIPP/E

Exam Prep, A study plan that actually works

The IAPP advises a minimum of 30 hours of study. But hours alone don't pass exams - active recall and spaced retrieval do. Re-reading and highlighting…

Lesson · CIPP/E

Exam Prep, After the course - next steps to certify

Completing the training is a step, not the finish line. To convert it into a pass, layer on this guide, the blueprint, practice questions and spaced…

Lesson · CIPP/E

Exam Prep, How the questions are written (Bloom's taxonomy)

Not every question is a definition. The IAPP writes questions at different Bloom's taxonomy levels. The verb in a performance indicator (define, identify…

Lesson · CIPP/E

Exam Prep, Test-day strategy & the classic traps

On the day, technique matters. Read the full stem, watch for absolutes ("always", "never"), and pick the best answer, not merely a true one. Most lost…

Lesson · CIPP/E

Exam Prep, The CIPP/E exam at a glance

The CIPP/E exam tests the IAPP Body of Knowledge across five domains. Knowing the weighting tells you where to spend your time: Domain II is the single…

Lesson · CIPP/E

Exemptions to the obligation to provide information

The GDPR has its own exemptions (no national law needed) and permits member states to create more. For Article 13 (direct collection) there is essentially…

Lesson · CIPP/E

Fair processing notices and best practice

Unlike the Directive, the GDPR specifies methods for informing data subjects, so fair processing notices (privacy notices) remain the convenient way to…

Lesson · CIPP/E

Freely given consent - bundling, imbalance, cookie walls

Freely given means a genuine choice and the ability to refuse or withdraw. Consent bundled with other matters (e.g. buying a service) is invalid; under…

Lesson · CIPP/E

How information must be provided (manner and format)

Article 12 governs the manner: information must be concise, transparent, intelligible and easily accessible, using clear and plain language, and language…

Lesson · CIPP/E

Human rights law foundations

European data protection rests on human rights law. The Universal Declaration of Human Rights (1948) set the values: Article 12 protects privacy, Article…

Lesson · CIPP/E

Identifiability, Anonymisation and Pseudonymisation

A person is identifiable when, though not yet identified, it is possible to identify them - directly (by name) or indirectly (by an identifier, or by…

Lesson · CIPP/E

Impact on member states - implementation, enforcement, direct effect

Directives are not directly applicable: states transpose them, so approaches vary - the great challenge of EU privacy law. The Commission can take…

Lesson · CIPP/E

Incident response

Putting in place incident response is an implicit requirement of the security principle and the breach rules. A good incident response plan needs senior…

Lesson · CIPP/E

Independent national regulators and their tasks (Articles 51–57, 59)

Only the DPA|DPAs hold administrative supervisory and enforcement powers under the GDPR. They must be independent public authorities (Articles 51–52) with…

Lesson · CIPP/E

Integrity and confidentiality

Article 5(1)(f) - integrity and confidentiality (the 'security principle') - requires processing in a manner that ensures appropriate security, including…

Lesson · CIPP/E

Internet of Things (IoT)

The IoT is physical objects ('connected objects') that connect, sense and transmit data - wearables, smart meters, connected vehicles, and VVA-paired…

Lesson · CIPP/E

Introduction and background to accountability

The GDPR formally embeds accountability into EU data protection law. Accountability means the obligations an organisation must meet to show and evidence…

Lesson · CIPP/E

Introduction and overview of scope

Chapter 5 sets out two filters that decide whether the GDPR applies at all: territorial scope (which organisations, by location or by who they target) and…

Lesson · CIPP/E

Introduction and scope

Chapter 17 maps how European data protection concepts apply to a range of internet technologies - cloud, cookies, IP addresses, search engines, social…

Lesson · CIPP/E

Introduction and surveillance technology

Surveillance means observing an individual or group, and it is getting cheaper, more capable and more pervasive. The classic concern is the nation state…

Lesson · CIPP/E

Introduction: the toolkit of supervision and enforcement

A regulatory system is only as good as the means by which it is supervised and enforced. The GDPR spreads enforcement firepower across many actors, not…

Lesson · CIPP/E

Introduction to Data Protection Concepts

The core data protection concepts pre-date the GDPR: they were set by the 1995 Data Protection Directive and remain essentially unchanged in the GDPR…

Lesson · CIPP/E

Introduction to outsourcing

Data protection law was born in the early 1970s as computers spread, and early service bureaux (also called computer bureaux) processed data on behalf of…

Lesson · CIPP/E

IP addresses as personal data (Breyer)

An IP address is a numerical label assigned to a device. It can be static IP address|static (always the same) or dynamic IP address|dynamic (changes each…

Lesson · CIPP/E

Joint Controllership

Joint controllership arises where two or more entities jointly determine the purposes and means of processing - either by a common decision or through…

Lesson · CIPP/E

Law Enforcement Directive (LED)

Agreed alongside the GDPR, the Law Enforcement Directive (Directive (EU) 2016/680) governs personal data processed by criminal law enforcement…

Lesson · CIPP/E

Law enforcement, EU institutions, ePrivacy and E-Commerce

Article 2(2)(d) exempts processing by competent authorities for the prevention, investigation, detection or prosecution of criminal offences (and…

Lesson · CIPP/E

Lawfulness, fairness and transparency

The first principle bundles three ideas. Lawfulness means there must be a legal ground (and the processing must comply with all applicable laws). Fairness…

Lesson · CIPP/E

Legal basis for processing employee personal data

Employers usually rely on one of four grounds: consent, necessity for the employment contract, compliance with a legal obligation, or legitimate…

Lesson · CIPP/E

Legal obligation & public interest - extra detail; documenting the basis

For both the legal obligation and public task bases, Recital 45 says the processing must have a basis in EU or member-state law, which may specify the…

Lesson · CIPP/E

Legitimacy and proportionality of monitoring

Monitoring needs a lawful basis - usually the legitimate-interests balancing test, not consent, whose use the WP29 said is very limited for monitoring…

Lesson · CIPP/E

Legitimate interests & the balancing test

Legitimate interests (6(1)(f)) is the most flexible basis and the one on which most processing relies, but public authorities cannot use it for their…

Lesson · CIPP/E

Location-based marketing

Using location data from devices for marketing engages both the GDPR and ePrivacy. ePrivacy Art 9 requires opt-in consent to use location data for a…

Lesson · CIPP/E

Location data and contact tracing

Location-based services (LBS) use location to deliver navigation, advertising, gaming, payments and more, drawn from satellite (GPS/Galileo), cell-based…

Lesson · CIPP/E

Mandatory Article 28(3) contract terms

Processing by a processor must be governed by a written contract (or other binding legal act). Article 28(3) sets out the mandatory terms. From the…

Lesson · CIPP/E

Marketing by electronic mail and the soft opt-in

Email/SMS/MMS marketing needs prior opt-in consent (ePrivacy Art 13(1)) - typically a tick box at data capture. The exception is the soft opt-in…

Lesson · CIPP/E

Material scope: matters outside EU law and the household exemption

Even an in-scope organisation has some processing carved out of the GDPR by Article 2. Article 2(2)(a) excludes activities outside the scope of Union law…

Lesson · CIPP/E

Meaning of an 'adequate level of protection'

Under Article 45(1), the Commission can decide a third country, a territory, a sector, or an international organisation ensures an adequate level of…

Lesson · CIPP/E

Modalities - to whom, how, and when

Article 12(2) requires controllers to facilitate the exercise of rights. Unlike the Directive, the GDPR requires the controller to use all reasonable…

Lesson · CIPP/E

Module 1, Council of Europe vs the EU

A critical exam distinction. The European Union (EU) is an economic and political union of 27 Member States; the Council of Europe (CoE) is an…

Lesson · CIPP/E

Module 1, Directive vs Regulation, the EDPB and ePrivacy

A Directive obliges Member States to implement it in local law; a Regulation is directly applicable with no local implementation needed - the GDPR is a…

Lesson · CIPP/E

Module 1, EU institutions and the legislative process

The EU's institutions split into legislative, policy and judicial roles. The European Commission proposes legislation; the European Parliament (MEPs) and…

Lesson · CIPP/E

Module 1, European data protection timeline

The road to the GDPR: the OECD Guidelines (1980) set harmonised data-flow principles; Convention 108 (1981) was the first binding data protection treaty…

Lesson · CIPP/E

Module 1, Foundations: UDHR and ECHR

European data protection grows from two human-rights instruments. The Universal Declaration of Human Rights (UDHR) was adopted on 10 December 1948 and is…

Lesson · CIPP/E

Module 10, Accountability defined (Article 24)

Article 24(1) makes the controller responsible for implementing appropriate technical and organisational measures to ensure and be able to demonstrate…

Lesson · CIPP/E

Module 10, Data protection by design and by default (Article 25)

Article 25 sets two linked duties. Data protection by design begins before processing and bakes data protection into the planning/design phase. Data…

Lesson · CIPP/E

Module 10, Data protection impact assessment (DPIA, Articles 35 and 36)

A DPIA has two values: incorporate data protection into planning and demonstrate compliance to SAs. A PIA is broader and lighter and can run on any…

Lesson · CIPP/E

Module 10, Data protection policy (Article 24(2))

A data protection policy (Article 24(2)) is an internal tool to train employees and set out what may and may not be done, plus the consequences of breach…

Lesson · CIPP/E

Module 10, Records of processing (Article 30)

Records of processing (Article 30) apply to organisations with 250+ employees, OR - regardless of size - where processing is likely to result in a risk…

Lesson · CIPP/E

Module 10, The data protection officer (DPO, Articles 37–39)

The DPO (formerly the Personal Data Protection Official) advises on and monitors compliance and must be an expert in data protection law and practices…

Lesson · CIPP/E

Module 10, The EU representative (Article 27)

Under Article 27, controllers/processors caught by Article 3(2) - those offering goods/services to, or monitoring, people in the EU while not established…

Lesson · CIPP/E

Module 11, Lead SA, one-stop-shop & cooperation/consistency

For cross-border processing a single lead supervisory authority (LSA) coordinates the concerned supervisory authorities through the one-stop-shop. The LSA…

Lesson · CIPP/E

Module 11, Remedies, liabilities & administrative fines

The GDPR sets two fine tiers: up to €10 million or 2% of worldwide annual turnover (lower) and up to €20 million or 4% (higher), whichever is higher…

Lesson · CIPP/E

Module 11, Supervisory authorities & Article 58 powers

Supervisory authorities (a.k.a. data protection authorities) are the bodies the GDPR tasks with promoting, monitoring and enforcing the regulation. Their…

Lesson · CIPP/E

Module 11, The EDPB & the EDPS

The European Data Protection Board (EDPB) replaced the Article 29 Working Party and ensures consistent application of the GDPR. The 30 EEA SAs each send a…

Lesson · CIPP/E

Module 2, Anonymous vs pseudonymous data

Anonymous data is rendered unidentifiable and is NOT protected by the GDPR, but true anonymisation is hard. Pseudonymous data is NOT fully anonymous -…

Lesson · CIPP/E

Module 2, Defining and identifying personal data

Article 4(1) GDPR defines personal data as "any information relating to an identified or identifiable natural person." The course uses a four-step test…

Lesson · CIPP/E

Module 2, Special categories of personal data (Article 9)

Article 9(1) prohibits processing of special-category data unless an exception applies. The categories cover racial/ethnic origin, political opinions…

Lesson · CIPP/E

Module 3, Controller vs processor

Who decides the purposes and means of processing? Whoever determines the "why" and the "how" is the controller (Article 4(7)); whoever processes on the…

Lesson · CIPP/E

Module 3, Sub-processors and Opinion 22/2024

A sub-processor is an entity engaged by a processor to help carry out the processing. EDPB Opinion 22/2024 makes three things clear: the controller must…

Lesson · CIPP/E

Module 3, Vendor management and the Article 28 contract

Choosing a good processor is part of the controller's accountability - there is a pre-contractual due-diligence duty, and failing it leaves the controller…

Lesson · CIPP/E

Module 4, Consent - the four conditions and children

Valid consent must be freely given, specific, informed and unambiguous - a clear affirmative act, clearly distinguishable and in plain language, with…

Lesson · CIPP/E

Module 4, Data processing principles (OECD + Article 5)

The GDPR's Article 5 principles - lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity…

Lesson · CIPP/E

Module 4, Legitimate interests and the balancing test

Legitimate interests (Art 6(1)(f)) is a flexible "safety net," but it demands a Legitimate Interest Assessment (LIA). EDPB Guidelines 1/2024 set three…

Lesson · CIPP/E

Module 4, Special-category data and Article 9 exceptions

Processing special-category data is prohibited by default. To do it lawfully you need BOTH an Article 6 basis AND an Article 9 exception. The exceptions…

Lesson · CIPP/E

Module 4, Territorial and material scope

Article 3 sets territorial scope - and only one criterion need be met: the establishment criterion (Art 3(1)), the targeting/monitoring criterion (Art…

Lesson · CIPP/E

Module 4, The data processing life cycle

Processing is defined sweepingly in Article 4(2): any operation performed on personal data, automated or not - from collection and storage right through…

Lesson · CIPP/E

Module 4, The six Article 6 lawful bases

Processing personal data needs a lawful basis. Article 6 offers six, and only one is needed: consent, contract, legal obligation, vital interests, public…

Lesson · CIPP/E

Module 5, Access and rectification (Articles 15 & 16)

Two foundational data subject rights. The right of access (Article 15) lets a person obtain confirmation that their data is processed, a copy of their…

Lesson · CIPP/E

Module 5, Automated decision-making and profiling (Article 22)

Article 22 gives the data subject the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal…

Lesson · CIPP/E

Module 5, Data portability (Article 20)

Data portability (Article 20) extends the right of access: the data subject can receive their data in a structured, commonly used, machine-readable format…

Lesson · CIPP/E

Module 5, Erasure / right to be forgotten (Article 17)

Right to erasure (Article 17), also called the right to be forgotten, lets a data subject have their data deleted in defined cases - e.g. data no longer…

Lesson · CIPP/E

Module 5, Restriction of processing (Article 18)

Restriction of processing (Article 18) means marking stored personal data to limit future processing - a kind of legal hold. Per Article 4(3), the data is…

Lesson · CIPP/E

Module 5, Right to object (Article 21)

Right to object (Article 21) applies where processing is for direct marketing (an absolute right - processing must cease, including profiling for…

Lesson · CIPP/E

Module 6, Article 13 vs Article 14 (direct vs indirect collection)

Article 13 governs data collected directly from the data subject - provide the information at the time of collection. Article 14 governs data obtained…

Lesson · CIPP/E

Module 6, Privacy notices and formats

A privacy notice describes how an organisation collects, uses, retains and discloses personal data (a.k.a. privacy statement / fair processing statement /…

Lesson · CIPP/E

Module 6, Transparency (Article 12)

Transparency (Article 12) requires controllers to communicate concisely, transparently, intelligibly and in clear and plain language (adapted for…

Lesson · CIPP/E

Module 7, Adequacy decisions & the Schrems/DPF saga

An adequacy decision is a European Commission finding that a third country's laws provide essentially equivalent protection - so transfers there need no…

Lesson · CIPP/E

Module 7, Appropriate safeguards: SCCs, BCRs & codes

Used when there is no adequacy decision, appropriate safeguards bind the recipient to an EU standard. Standard Contractual Clauses (SCCs) are the most…

Lesson · CIPP/E

Module 7, Derogations & restrictions (Article 49)

Derogations under Article 49 are last-resort exemptions, narrowly interpreted, that allow a transfer in specific situations only when neither adequacy nor…

Lesson · CIPP/E

Module 7, The landscape: three options in order

When personal data leaves the EEA (the EU plus Iceland, Liechtenstein and Norway) it must stay protected to an EU-equivalent standard, and this applies to…

Lesson · CIPP/E

Module 8, CCTV / video surveillance & Guidelines 3/2019

CCTV footage contains personal data and images may be biometric data. Compliance turns on lawfulness (often legitimate interest; consent is usually not…

Lesson · CIPP/E

Module 8, Dark patterns (Guidelines 03/2022), AI & the EU AI Act

Dark patterns are deceptive interface designs that manipulate users about their personal data; EDPB Guidelines 03/2022 set out six categories. AI can make…

Lesson · CIPP/E

Module 8, Direct marketing channel rules & the soft opt-in

Channel rules differ sharply. Postal marketing is outside ePrivacy and can often rely on legitimate interests. Person-to-person phone calls need no…

Lesson · CIPP/E

Module 8, Direct marketing - GDPR vs ePrivacy & the absolute right to object

Direct marketing is a communication, by any advertising means, directed towards specific individuals. It is regulated by both the GDPR and the ePrivacy…

Lesson · CIPP/E

Module 8, Employee data - legal layers, works councils & legal bases

Employee data sits under more than the GDPR: local data-protection AND employment law also apply, and these are not fully harmonised. Article 88 lets…

Lesson · CIPP/E

Module 8, ePrivacy Directive, location data & biometric data

The ePrivacy Directive (2002/58) governs data from terminal equipment over public electronic communications networks - its main basis is consent and it…

Lesson · CIPP/E

Module 8, Lawful employee monitoring & whistleblowing

Lawful employee monitoring must pass four tests - it must be necessary, have a legitimate, lawful basis, be proportionate and be transparent. Monitoring…

Lesson · CIPP/E

Module 8, Online behavioural advertising (OBA) & cloud computing

OBA targets website ads on observed behaviour over time, often via third-party ad networks placing cookies with unique identifiers. OBA data is personal…

Lesson · CIPP/E

Module 8, Search engines, Google Spain & social media targeting

Search engines determine purposes/means, so they are controllers. Google Spain (2014, CJEU) established the right to be forgotten and held search engines…

Lesson · CIPP/E

Module 8, Sensitive employee data, record retention & BYOD

Sensitive employee data needs an Article 9 condition; the employment/social-security exception is the usual route, with explicit consent only as a last…

Lesson · CIPP/E

Module 8, Surveillance framework - Article 23, content vs metadata

Surveillance is observation of individuals - covert or overt, real-time or stored. Article 23 lets EU/Member State law restrict data-subject rights, but…

Lesson · CIPP/E

Module 8, Web cookies, Article 5(3) & the Planet49 ruling

A cookie is a text file on a device; cookie data is personal data (Recital 30) and processing is subject to the GDPR. ePrivacy Article 5(3) requires…

Lesson · CIPP/E

Module 9, Appropriate technical and organisational measures (Article 32)

Security of processing is a prerequisite for compliance - most EU enforcement relates to security incidents, and failures can attract fines up to €20…

Lesson · CIPP/E

Module 9, Data breach notification (Articles 33 and 34)

Article 4(12) defines a personal data breach as a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised…

Lesson · CIPP/E

Module 9, Security controls - the CIAR attributes

Security has four attributes - CIAR: Confidentiality, Integrity, Availability and Resilience. Resilience is new to EU data-protection law via the GDPR…

Lesson · CIPP/E

Module 9, The NIS and NIS2 Directives

The original NIS Directive was the first EU-wide cybersecurity law. The NIS2 Directive entered into force on 16 January 2023. Member States had to…

Lesson · CIPP/E

Natural Person, Deceased Persons and PII

Personal data protects natural persons (living humans) universally, regardless of nationality or residence (subject to Article 3 territorial scope). The…

Lesson · CIPP/E

Necessity and the DPIA

Before monitoring, the employer must be confident it is really necessary and consider less-intrusive methods first. A DPIA is required where monitoring is…

Lesson · CIPP/E

Necessity & the contract, legal obligation and vital interests bases

Every Article 6 basis except consent requires the processing to be necessary. 'Necessary' has an objective meaning - a close and substantial connection…

Lesson · CIPP/E

Need for a harmonised approach & the Data Protection Directive

Leaving implementation of Convention 108 and the OECD Guidelines to member states produced a diverse, fragmented set of regimes, threatening both…

Lesson · CIPP/E

NIS Directive and NIS 2

The original NIS Directive, adopted on 6 July 2016, was the first EU-wide cybersecurity law. The NIS2 Directive, Directive (EU) 2022/2555, replaced it…

Lesson · CIPP/E

OBA, cookies and ePrivacy (Article 5(3))

The key cookie rule is Article 5(3) ePrivacy Directive: storing or accessing information on a user's device (a cookie) needs the user's consent after…

Lesson · CIPP/E

OECD Guidelines

In 1980 the OECD issued Guidelines on the Protection of Privacy and Transborder Flows of Personal Data. They are not legally binding but set out eight…

Lesson · CIPP/E

Offshoring and international transfers

Article 44 limits transfers of personal data outside the EEA unless the transfer meets a Chapter V condition. Available routes include an adequacy…

Lesson · CIPP/E

Online behavioural advertising (OBA)

OBA targets ads at people based on their behaviour observed over time. First-party OBA is run by the publisher itself; the trickier case is third-party ad…

Lesson · CIPP/E

Personal Data and Its Four Building Blocks

Personal data is any information relating to an identified or identifiable natural person (the 'data subject'). The definition is intentionally broad. The…

Lesson · CIPP/E

Postal marketing

Postal marketing is not digital, so the ePrivacy Directive does not apply - only the GDPR. There is no express GDPR requirement to obtain consent for…

Lesson · CIPP/E

Privacy and Electronic Communications (ePrivacy) Directive

Directive 2002/58/EC (the ePrivacy Directive) adds specific rules for electronic communications. It applies to publicly available electronic…

Lesson · CIPP/E

Procedure to designate adequate countries

The Commission designates adequacy by implementing act, guided by the WP29 Adequacy Referential (6 February 2018) on essential equivalence. Each decision…

Lesson · CIPP/E

Processing and Data Subject

Processing is defined extremely broadly: any operation or set of operations on personal data, whether or not automated - collection, recording, storage…

Lesson · CIPP/E

Processing sensitive employee data

Special-category (sensitive) employee data - racial/ethnic origin, political opinions, religious/philosophical beliefs, trade union membership, genetic…

Lesson · CIPP/E

EU Artificial Intelligence Act

The Commission proposed an AI regulation on 21 April 2021. The adopted EU AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 and…

Lesson · CIPP/E

Providing adequate safeguards - SCCs and the transfer impact assessment

Where there is no adequacy decision, controllers/processors must use appropriate safeguards. The GDPR lists several: binding instruments between public…

Lesson · CIPP/E

Providing notice

Whatever lawful basis is used, employers must still give employees a clear notice about how their data is used. It can sit in an employee handbook or a…

Lesson · CIPP/E

Public international law, EU representatives and Brexit

Article 3(3) applies the GDPR where a controller not established in the Union processes in a place where member state law applies by virtue of public…

Lesson · CIPP/E

Public task / official authority basis

Basis 6(1)(e) covers processing necessary for a task carried out in the public interest or in the exercise of official authority vested in the controller…

Lesson · CIPP/E

Purpose limitation

Purpose limitation means data must be collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those…

Lesson · CIPP/E

Rationale for data protection

In the early 1970s, the spread of mainframe computers and telecommunications let governments and large firms build huge data banks, while trade through…

Lesson · CIPP/E

Reference, EDPB & WP29 guidelines and opinions (must-knows)

The Exam Blueprint repeatedly asks you to know "EDPB guidelines and opinions" on a topic. You don't need to memorise document numbers, but you SHOULD…

Lesson · CIPP/E

Reference, Key Articles, thresholds & timeframes cheat-sheet

The single highest-yield recall sheet for the exam: the article numbers, thresholds and timeframes that scenario questions hinge on. Drill these until…

Lesson · CIPP/E

Reference, Landmark CJEU/ECtHR cases & major fines

A handful of cases and fines come up again and again. Know what each one decided and the principle it established - examiners use them as scenario anchors.

Lesson · CIPP/E

Reform of the EU framework and the road to the GDPR

Divergent national measures and new technology pushed the Commission to reform the Directive. In January 2012 it published two proposals: a regulation…

Lesson · CIPP/E

Regulating surveillance: the legal framework

Surveillance by public and state agencies for national security or law enforcement is mostly legislated by member states, with compliance with the Charter…

Lesson · CIPP/E

Regulation by the citizen: rights, remedies, representation and compensation

Citizens are the 'second line of defence' - and the ~500 million citizens across the EU and UK are massive enforcement firepower. The GDPR gives…

Lesson · CIPP/E

Regulators' powers under Article 58: investigatory, corrective, authorisation/advisory

Article 58 grants the DPAs three types of power: investigatory (Art 58(1)), corrective (Art 58(2)), and authorisation and advisory (Art 58(3))…

Lesson · CIPP/E

Related legislation: LED & ePrivacy

Alongside the GDPR, the EU adopted the Law Enforcement Directive for processing by criminal-law authorities. The ePrivacy Directive governs…

Lesson · CIPP/E

'Relating to' - Content, Purpose and Result

For information to be personal data it must be about an individual, but the link is not always obvious. WP29 says one of three elements must apply (they…

Lesson · CIPP/E

Relying on the Article 49 derogations

Where there is neither adequacy nor appropriate safeguards, a transfer may still rely on an Article 49 derogation. The EDPB says these must be interpreted…

Lesson · CIPP/E

Requirements of the ePrivacy Directive

The ePrivacy Directive (2002/58/EC, as amended) adds information requirements for cookies and similar technologies on websites, apps and connected…

Lesson · CIPP/E

Responsibility of the controller

Accountability is first introduced in Article 5: Article 5(1) lists the six principles, and Article 5(2) adds the new duty that the controller must be…

Lesson · CIPP/E

Restrictions of data subject rights

Despite the GDPR's prescriptive nature, Union or member-state law may restrict the scope of the obligations and rights in Articles 12 to 22 (and the…

Lesson · CIPP/E

Right not to be subject to solely automated decision-making

Despite its title, Article 22 is a general prohibition, not a right to be invoked - it applies regardless of the data subject's actions. It is narrow: it…

Lesson · CIPP/E

Right of access (DSAR)

Article 15 is the active counterpart to the passive right to information: on request, a data subject must be told whether their data are processed and, if…

Lesson · CIPP/E

Right to data portability

Article 20 is entirely new to EU data protection law. It lets data subjects receive their own data, which they provided to a controller, in a structured…

Lesson · CIPP/E

Right to erasure ('right to be forgotten')

Article 17 lets a data subject have personal data erased - verbally or in writing - on specified grounds (data no longer needed, consent withdrawn…

Lesson · CIPP/E

Right to object

Article 21(1) lets a data subject object to processing based on the controller's legitimate interests. The objection shifts the burden of proof to the…

Lesson · CIPP/E

Right to opt out of direct marketing

Whatever the lawful basis, the GDPR gives individuals an absolute right to object to direct marketing. On consent, they withdraw consent; on legitimate…

Lesson · CIPP/E

Right to rectification

Article 16 lets data subjects have inaccurate personal data corrected and incomplete data completed. Its scope is largely unchanged from the Directive…

Lesson · CIPP/E

Right to restriction of processing

Article 18 is the GDPR's successor to the Directive's right to 'blocking' - a temporary freezing of data. On listed grounds (accuracy contested, unlawful…

Lesson · CIPP/E

Risk reporting and the meaning of 'personal data breach'

Article 33 requires notifying the regulator and Article 34 requires communicating to data subjects - both only where there is risk (or high risk) to…

Lesson · CIPP/E

Roles of the parties: controller and processor

In a typical outsourcing deal the customer is the controller and the supplier is the processor. A controller determines the purposes and means of…

Lesson · CIPP/E

Scope of data transfers - what counts as a transfer

The GDPR does not define 'transfer'. A key distinction is that a transfer is not the same as mere transit: it is the processing in the third country that…

Lesson · CIPP/E

Search engines and the right to be forgotten

Search engines process IP addresses, cookies, user log files and third-party webpages (which they crawl and index). In Google Spain, the CJEU held a…

Lesson · CIPP/E

Security principle and the risk-based approach (Article 32)

Article 5(1)(f) sets the security principle ('integrity and confidentiality'); Article 32 expands on it, requiring appropriate technical and…

Lesson · CIPP/E

Self-regulation: accountability, DPOs, codes and certification

Self-regulation is arguably the most effective tool because controllers and processors directly control the measures protecting data. The GDPR advances it…

Lesson · CIPP/E

Sensitive data - Article 9 framework

Article 9 prohibits processing of special-category data unless an exception applies. The categories are: racial/ethnic origin, political opinions…

Lesson · CIPP/E

Setting fines, guidelines and the Law Enforcement Directive

The WP29 (adopted by the EDPB) and the EDPB's 2022 guidelines steer how fines are calculated. A fine is not a mere mathematical exercise. Minor…

Lesson · CIPP/E

Situations requiring additional information

Beyond Articles 13/14, the GDPR triggers extra information duties in specific situations, whether or not the data came from the subject: data subject…

Lesson · CIPP/E

Social media: legal basis, special category data, children

SMP processing needs an Article 6 basis, and Article 9 applies to special category data. One Art 9 route is data manifestly made public by the data…

Lesson · CIPP/E

Social media: roles, joint controllership, transparency

Social media platforms (SMPs) collect data users provide, observe, and infer/predict. The SMP is a controller. The pivotal case is Wirtschaftsakademie…

Lesson · CIPP/E

Special Categories of Personal Data

Article 9 identifies special categories (sensitive) of personal data needing extra protection because their processing risks individuals' fundamental…

Lesson · CIPP/E

Specific, informed & unambiguous consent

Consent must be specific to the operation (purpose specification guards against function creep), informed (language the average person understands, not…

Lesson · CIPP/E

Storage limitation

Storage limitation (Article 5(1)(e)) means personal data must not be kept longer than necessary for the purpose; once no longer needed, it must be…

Lesson · CIPP/E

Storage of personnel records

Personnel records span recruitment, sick leave, medical insurance, salary, appraisals, evaluations and severance. They must not be kept longer than…

Lesson · CIPP/E

Subcontracting conditions

Where outsourcing forms a chain, Articles 28(2) and (4) set conditions on engaging a sub-processor. The customer must give prior specific or general…

Lesson · CIPP/E

Suppliers as controllers, AI, and chains of processors

A supplier that goes beyond its mandate and acquires a real role in determining the purposes or essential means of processing becomes a controller in its…

Lesson · CIPP/E

Targeted online advertising: ecosystem and law

Most free internet services are funded by targeted online advertising, which builds profiles and routes ads to people who meet criteria. The adtech…

Lesson · CIPP/E

Telephone marketing

Telemarketing is digital marketing, so both the GDPR and ePrivacy apply. For live person-to-person calls, Art 13(3) lets member states choose opt-in or…

Lesson · CIPP/E

The Article 5 principles overview

Chapter 6 covers the data processing principles now expressly listed in Article 5 of the GDPR. These principles did not start with the GDPR: they were…

Lesson · CIPP/E

The data protection officer (DPO)

Not every company needs a DPO, but Article 37 makes one mandatory in three cases: a public authority; where core activities consist of regular and…

Lesson · CIPP/E

The Five Building Blocks of 'Controller'

EDPB Guidelines 07/2020 break 'controller' into five building blocks: the person/body; 'determines'; 'alone or jointly with others'; 'the purposes and…

Lesson · CIPP/E

The General Data Protection Regulation (GDPR)

The GDPR is a directly applicable regulation with 173 recitals and 99 articles in eleven chapters. Unlike the Directive it binds processors directly…

Lesson · CIPP/E

The General Data Protection Regulation

The Directive could not keep pace with technology and globalisation, so the Commission proposed the GDPR in January 2012. It entered into force May 2016…

Lesson · CIPP/E

The general restriction on transfers outside the EEA

The GDPR lets personal data flow freely between member states, but transfers to any country outside the EEA are restricted. A transfer to a third country…

Lesson · CIPP/E

The NIS Directive (and NIS 2)

The original NIS Directive advanced EU cybersecurity and complemented the GDPR. NIS2, Directive (EU) 2022/2555, replaced that regime from 18 October 2024…

Lesson · CIPP/E

The Processor and the Article 28 Contract

A processor is a separate legal entity that processes personal data on behalf of a controller. Two building blocks: (1) separate legal entity, (2)…

Lesson · CIPP/E

The under-250-employees records exemption

There is an exemption from the Article 30 record-keeping duty for companies with fewer than 250 people. But it is heavily caveated and the chapter says it…

Lesson · CIPP/E

The United States - Privacy Shield, Schrems II and the Data Privacy Framework

Privacy Shield replaced Safe Harbor (adequacy decision 12 July 2016, in force 1 August 2016) with seven strengthened principles and extra safeguards. The…

Lesson · CIPP/E

The United States - Safe Harbor, Snowden and Schrems I

Safe Harbor (Commission decision 26 July 2000) was a self-certification framework treated as adequate for EU-US transfers. Criticised for weak…

Lesson · CIPP/E

Transparency, AUPs and covert monitoring

Transparency both meets the notice requirement and sets expectations: employees told in advance that use is monitored have less scope to claim they didn't…

Lesson · CIPP/E

Transparency principle

The first GDPR processing principle is that personal data must be processed lawfully, fairly and in a transparent manner. Transparency means being open…

Lesson · CIPP/E

Transparent communication and the right to information

Transparency underpins the whole system: individuals cannot protect their privacy if they are not properly informed. Article 12(1) requires information to…

Lesson · CIPP/E

Treaty of Lisbon

The Treaty of Lisbon was signed 13 December 2007 and took effect 1 December 2009. It amends the EU's two core treaties, renaming one the TFEU. Article…

Lesson · CIPP/E

Video surveillance (CCTV): lawful basis and proportionality

CCTV that captures images identifying people is processing personal data and must comply with the GDPR and, if applicable, the LED. The usual lawful basis…

Lesson · CIPP/E

When information must be provided (timing)

Timing is one of the key practical differences between the two Articles. Under Article 13 the information must be given at the time the personal data are…

Lesson · CIPP/E

Whistleblowing schemes

Whistleblowing lets employees report illegal or improper activity with privacy safeguards. SOX (2002) drove their prominence and reaches EU subsidiaries…

Lesson · CIPP/E

Why consent is problematic at work

Consent looks easy but should be a measure of last resort. Valid consent must be freely given, specific, informed and unambiguous - and the imbalance of…

Lesson · CIPP/E

Workplace monitoring: principles, background checks, DLP

An employee does not lose their right to privacy at work; their private sphere is protected but balanced against the employer's right to run its business…

Lesson · CIPP/E

Works councils

Works councils represent employees and have rights under local law over how employee data is used; they often must safeguard employees' data protection…

Guide · CIPP/E

What is location data under the GDPR?

A practical GDPR guide to GPS, IP-address, mobile-network and inferred location data, with Article 4, legal-basis and DPIA exam points.

Guide · CIPP/US

CIPP/US exam format and blueprint

The current CIPP/US exam format, timing, question types and a practical way to use the IAPP Body of Knowledge and blueprint.

Guide · CIPP/US

CIPP/US exam questions explained

CIPP/US practice questions for exam prep: 604 exam-style questions, a 90-question timed set, worked explanations and a free diagnostic.

Guide · CIPP/US

CIPP/US practice questions and practice exam

Take a free CIPP/US diagnostic, then use 604 practice questions and a timed 90-question set with explanations.

Guide · CIPP/US

CIPP/US study guide

CIPP/US study guide with free lessons, a ten-question diagnostic and 604 exam-style practice questions for scenario-based exam prep.

Guide · CIPP/US

CIPP/US study plan

A four-week CIPP/US study plan that turns the published outline into a 30-hour schedule with review and timed practice.

Practice · CIPP/US

CIPP/US cram sheet

The complete CIPP/US memorisation sheet: the timeline, dollar amounts and deadlines, opt-in vs opt-out, who enforces what, the sectoral laws, the Supreme…

Practice · CIPP/US

Find the CIPP/US areas to study next.

Take a free 10-question CIPP/US diagnostic. Get an immediate domain score and a personalised study plan without creating an account.

Guide · CIPP/US

CIPP/US essentials

The essentials tier for the IAPP CIPP/US - the most-tested laws, regulators, opt-in/opt-out rules and distinctions per exam area, condensed to one page…

Guide · CIPP/US

CIPP/US: the whole exam on one page

Every exam-relevant U.S. privacy law, regulator, threshold, opt-in vs opt-out rule, distinction and landmark case for the IAPP CIPP/US - condensed onto…

Glossary · CIPP/US

CIPP/US glossary

Plain-language definitions for recurring terms in the CIPP/US study guide.

Guide · CIPP/US

HIPAA vs FERPA

A practical HIPAA versus FERPA decision guide for school nurses, outside providers, university clinics and mixed student and nonstudent records.

Guide · CIPP/US

How to pass the CIPP/US

How to pass the IAPP CIPP/US exam: what it tests, the format, a study plan, the sectoral-law traps, and free study notes plus the exam-style question set.

Guide · CIPP/US

Is the CIPP/US exam hard?

Is the CIPP/US exam hard? Format, pass mark, domain weights, where candidates struggle and a practical way to prepare.

Practice · CIPP/US

Free CIPP/US mini mock

Try 25 exam-style CIPP/US practice questions free, with explanations and a domain score. No account or payment required.

Practice · CIPP/US

A processor discovers a breach affecting personal data it handles for a controller. What is the processor's obligation under the GDPR?

A processor discovers a breach affecting personal data it handles for a controller. What is the processor's obligation under the GDPR? Answer with a worked…

Lesson · CIPP/US

APEC Privacy Framework (2004)

APEC is a 21-member organization operating under nonbinding agreement. Its 2004 Privacy Framework (updated 2015) sets nine principles that mirror the OECD…

Lesson · CIPP/US

The Four Classes of Privacy

Privacy splits into four classes: information, bodily, territorial, and communications privacy. This book focuses primarily on information privacy.

Lesson · CIPP/US

Co-Regulatory, Self-Regulatory, and Technology Models

Co-regulation (e.g., Australia; U.S. COPPA codes approved by the FTC) pairs industry codes with government law. Self-regulation (e.g., PCI DSS, seal…

Lesson · CIPP/US

Comprehensive Model of Data Protection

Comprehensive laws govern personal data across public and private sectors economy-wide, typically with an oversight DPA. Countries adopt them to remedy…

Lesson · CIPP/US

Council of Europe Convention 108 (1981)

Convention 108 (1981) required its parties to enact data protection provisions in domestic law. It was modernised through the 2018 protocol known as…

Lesson · CIPP/US

Defining Privacy

In 1890, Warren and Brandeis defined privacy as the right to be let alone in the Harvard Law Review. U.S. law calls this field privacy law while the EU…

Lesson · CIPP/US

Fair Information Practices (FIPs) Overview

Since the 1970s, Fair Information Practices (FIPs/FIPPs) have organized individual rights and organizational responsibilities into four categories: rights…

Lesson · CIPP/US

U.S. HEW Fair Information Practices (1973)

The FIPs used widely today trace to a 1973 U.S. Department of Health, Education and Welfare report whose Code of Fair Information Practices set five core…

Lesson · CIPP/US

Historical and Social Origins of Privacy

Privacy roots run from classical Greece and the Bible to England's 1361 Justices of the Peace Act. The U.S. Constitution protects privacy without naming…

Lesson · CIPP/US

Information Technology and the Rise of Data Protection Law

Mainframes in the 1960s spurred privacy fears (Orwell's '1984'). In 1970, Hesse, Germany enacted the first modern data protection law; the same year the…

Lesson · CIPP/US

Madrid Resolution (2009)

The 2009 Madrid Resolution was approved by data protection commissioners themselves, not governments, to define uniform privacy principles and facilitate…

Lesson · CIPP/US

Nonpersonal, Deidentified, and Pseudonymized Information

Remove identifying elements and data becomes nonpersonal (deidentified/anonymized), generally outside privacy laws. Pseudonymized data is only temporarily…

Lesson · CIPP/US

OECD Guidelines (1980)

The 1980 OECD Guidelines (updated 2013) are the most widely recognized FIP framework and have been endorsed by the FTC. They set eight principles, from…

Lesson · CIPP/US

Personal Information and Sensitive Personal Information

In the U.S., personal information and personally identifiable information (PII) cover data that can identify an individual. Sensitive personal information…

Lesson · CIPP/US

The Line Between Personal and Nonpersonal Information

Where personal ends and nonpersonal begins is unclear and varies by regime. The EU generally treats IP addresses as personal data; U.S. agencies under the…

Lesson · CIPP/US

Processing and Data Roles - Subject, Controller, Processor

Processing covers almost anything done with personal data. The data controller decides how and why data is processed and bears most obligations; the data…

Lesson · CIPP/US

Sectoral Model (United States)

The sectoral model (the U.S. approach) protects personal data through laws targeting specific industries. Strengths: tailored, lower burden. Weaknesses…

Lesson · CIPP/US

Sources of Personal Information

The same data can be treated differently by source: public records (held by government, available to the public), publicly available information (broadly…

Lesson · CIPP/US

Sources of Privacy Protection

Privacy protection comes from four sources: markets, technology, law, and self-regulation/co-regulation. Law is the traditional approach but real…

Lesson · CIPP/US

Cybersecurity Requirements in Education

FERPA expects reasonable security but specifies no particular controls; the GLBA Safeguards Rule applies to universities holding financial aid information…

Lesson · CIPP/US

Edtech under COPPA and Self-Regulation

In 2022 the FTC announced it would police edtech through COPPA, prohibiting use of children's data for commercial purposes, barring unreasonable mandatory…

Lesson · CIPP/US

Education Technology and FERPA

Edtech companies that handle student data are subject to FERPA. The 2014 Google Apps for Education lawsuit (with EPIC alleging FERPA violations over email…

Lesson · CIPP/US

Rights to Access, Review, and Correction

FERPA gives students the right to access and review most records within 45 days of a request and the right to seek correction of inaccurate, misleading…

Lesson · CIPP/US

Statutory Exceptions to FERPA Consent

FERPA lists many no-consent disclosure exceptions, including school officials with a legitimate educational interest, transfer schools, financial aid…

Lesson · CIPP/US

Valid Consent and Identity Verification

Valid FERPA consent must be signed, dated, and written, identifying the records, the purpose, and the recipient. When relying on a statutory exception…

Lesson · CIPP/US

Directory Information and Opt-Out

Directory information is data that would not generally be considered harmful if disclosed; each institution defines its own list, and before using it the…

Lesson · CIPP/US

When Disclosure of Education Records Is Permitted

FERPA permits disclosure of education records only if the data is not PII, it is unblocked directory information, the rights holder consents, the…

Lesson · CIPP/US

Education Record and Its Exceptions

An education record is broadly any record directly related to a student and maintained by or on behalf of the school, but FERPA carves out important…

Lesson · CIPP/US

FERPA Enforcement, No Private Right, and Preemption

FERPA is enforced by the Department of Education through the Family Policy Compliance Officer (FPCO); the ultimate penalty is loss of federal funding…

Lesson · CIPP/US

Holder of FERPA Rights

Who holds FERPA rights depends on context: in high school the parent holds rights until the student turns 18; once a student attends only a college or…

Lesson · CIPP/US

FERPA Overview and Scope

The Family Educational Rights and Privacy Act of 1974 (FERPA), also called the Buckley Amendment, gives students control over disclosure of and access to…

Lesson · CIPP/US

Personally Identifiable Information under FERPA

FERPA's PII definition covers names, family member names, addresses, SSNs and student numbers, dates and places of birth, and any information that alone…

Lesson · CIPP/US

FERPA Definition of Student

Under FERPA, a student is anyone who is or has been in attendance at an educational institution, including online attendees, but the term excludes…

Lesson · CIPP/US

Individuals with Disabilities Education Act

IDEA guarantees eligible students aged 3 to 21 a free appropriate public education through an IEP, and protects the privacy of special-education records…

Lesson · CIPP/US

PPRA and the No Child Left Behind Amendments

The PPRA (1978) amended FERPA to protect parents of minors over surveys collecting sensitive information and applies only to K-12 schools, not colleges…

Lesson · CIPP/US

State Student Privacy Laws and SOPIPA

Because FERPA does not preempt state law, states add their own protections. California's SOPIPA was the first U.S. law to prohibit using student data for…

Lesson · CIPP/US

CIPP/US COPPA rule and children's data guide

COPPA requirements and current FTC rule material explained for CIPP/US study.

Lesson · CIPP/US

CIPP/US Epic Games COPPA enforcement guide

Epic Games COPPA enforcement as a CIPP/US scenario review, with primary FTC source material.

Lesson · CIPP/US

The Cable Communications Policy Act of 1984

The Cable Act regulates cable providers' notice, collection, disclosure and retention of subscriber data, and grants a private right of action. Providers…

Lesson · CIPP/US

The CAN-SPAM Act of 2003

CAN-SPAM governs commercial email to or from the U.S. on an opt-out basis: no false headers or deceptive subject lines, a working return address, a clear…

Lesson · CIPP/US

CAN-SPAM Wireless Rules: MSCMs, Express Prior Authorization and the Wireless Domain Registry

The FCC's CAN-SPAM wireless rules require express prior authorization (opt-in) for each mobile service commercial message (MSCM) sent to wireless devices…

Lesson · CIPP/US

CPNI Opt-in/Opt-out Rules, Pretexting and Covered Entities

After U.S. West v. FCC struck a 1998 opt-in rule on First Amendment grounds, carriers' own use of CPNI shifted to opt-out. The 2007 CPNI order requires…

Lesson · CIPP/US

Digital Advertising Ethics: Behavioral Advertising, Dark Patterns and Children

Beyond legal compliance, ethical digital advertising stresses honesty, fairness and transparency. Key concerns: online behavioral advertising (tracking…

Lesson · CIPP/US

Exceptions to the DNC Rules: EBR, Consent and DNC Safe Harbor

DNC rules do not apply to nonprofits calling for themselves, existing-customer calls within 18 months, non-upsell inbound calls, or most B2B calls. An EBR…

Lesson · CIPP/US

Fax Marketing: TCPA and the Junk Fax Prevention Act

The TCPA (enforced by the FCC) bars unsolicited commercial faxes; consent can be explicit or inferred from an EBR. The 2005 Junk Fax Prevention Act…

Lesson · CIPP/US

The National Do Not Call Registry

The National DNC Registry (effective 2003) lets residents register residential and wireless numbers. Sellers/telemarketers must access it before calling…

Lesson · CIPP/US

Robocall Enforcement Actions and State Telemarketing Laws

Regulators have escalated robocall enforcement (a 2021 FCC $225 million record fine for ~1 billion robocalls; a 2019 multistate initiative). Because…

Lesson · CIPP/US

Self-Regulation for Digital Advertising: DAA and NAI

Two voluntary codes govern much online behavioral advertising: the DAA Self-Regulatory Principles and the NAI Code of Conduct, both emphasizing opt-outs…

Lesson · CIPP/US

State Laws on Digital Advertising: CalOPPA, Age-Appropriate Design, and Comprehensive Laws

California leads on digital advertising: CalOPPA (2003) requires website privacy notices and Do Not Track disclosures; the 2022 California Age-Appropriate…

Lesson · CIPP/US

TCPA Updates: Robocalls, Autodialers, Robotexts and Facebook v. Duguid

The FCC's 2012 TCPA revisions require prior express written consent for all robocalls to residential lines, even with an established business…

Lesson · CIPP/US

The Telecommunications Act of 1996 and CPNI

Section 222 of the Telecommunications Act of 1996 restricts how carriers access, use and disclose customer proprietary network information (CPNI) - call…

Lesson · CIPP/US

Telemarketing Regulatory Framework: TCPA, TSR, FCC and FTC

Two coordinated federal regimes govern telemarketing: the FCC enforces the Telephone Consumer Protection Act (TCPA) of 1991, and the FTC enforces the…

Lesson · CIPP/US

TSR abandoned calls. CIPP/US safe harbor guide

TSR abandoned call rules explained with a safe-harbor example and CIPP/US study context.

Lesson · CIPP/US

TSR Rules on How Calls May Be Made

The TSR sets detailed conduct rules: telemarketers may call only between 8 a.m. and 9 p.m., must scrub against the Do Not Call list, display caller ID…

Lesson · CIPP/US

Transmission of Caller ID Information

Telemarketers must transmit accurate caller ID. They may show their own name/number or substitute the seller's name and a customer-service number that is…

Lesson · CIPP/US

TSR Enforcement, Penalties and the Private Right of Action

The TSR is enforced by the FTC and state attorneys general, with civil penalties up to $50,120 per call. A limited private right of action requires…

Lesson · CIPP/US

TSR Misrepresentations, Material Omissions and Payment Authorization

The TSR bars misrepresentations and material omissions across ten categories (cost, restrictions, refund policy, prize/investment terms, etc.). When…

Lesson · CIPP/US

TSR Recordkeeping Requirements

The TSR requires sellers and telemarketers to keep specified records (ads, prize recipients, sales, employees, consent authorizations) for two years from…

Lesson · CIPP/US

TSR required disclosures. CIPP/US telemarketing guide

TSR required call disclosures explained with a practical example and CIPP/US study context.

Lesson · CIPP/US

Prohibition on Unauthorized Billing and Pre-Acquired Account Information

The TSR bars billing without express, informed consent. Where the telemarketer already holds the consumer's account data (pre-acquired account…

Lesson · CIPP/US

The Video Privacy Protection Act of 1988

The VPPA, passed after Robert Bork's video rental records were disclosed, bars videotape service providers from disclosing customer information except…

Lesson · CIPP/US

CIPP/US Section 230 and online content guide

Section 230 and online content issues explained with a source-backed CIPP/US study bridge.

Lesson · CIPP/US

CIPP/US FCC telecom breach notification guide

FCC telecom breach notification rules explained with a source-backed CIPP/US study bridge.

Lesson · CIPP/US

ADA Restrictions on Medical Screening

The ADA covers employers with 15 or more employees. Before an offer, medical exams/inquiries are allowed only if job-related and consistent with business…

Lesson · CIPP/US

After Employment: Access Termination and HR Records

On departure, employers should terminate access (badges, accounts, devices), recover company data, and forward personal mail while reviewing work mail. HR…

Lesson · CIPP/US

Antidiscrimination Laws as Limits on Screening

Federal antidiscrimination laws (Title VII, Equal Pay Act, ADEA, Pregnancy Discrimination Act, ADA, GINA) bar discrimination and indirectly limit what…

Lesson · CIPP/US

Reasons for Background Screening

Employers screen to hire the best candidate, counter false applicant claims, protect brand, and mitigate negligent hiring liability. Some professions…

Lesson · CIPP/US

Biometric, Video, and Mail Monitoring; Union Activity

Three state biometric laws reach employer data: Illinois BIPA (notice, consent, and a private right of action), plus Texas and Washington (no private…

Lesson · CIPP/US

Constitutional Law and the State-Action Limit

Constitutional privacy protections like the Fourth Amendment apply to government (public-sector) employers but not to private-sector employment, because…

Lesson · CIPP/US

The Employment Life Cycle Framework

Workplace privacy issues arise before, during, and after employment: background screening (before); polygraphs, testing, monitoring, social media, and…

Lesson · CIPP/US

FACTA Preemption and Stronger State Credit Laws

FACTA (2003) amended the FCRA and preempted many state laws on credit reporting and identity theft, but the FCRA does not preempt stronger state laws on…

Lesson · CIPP/US

Fair Chance Act and Ban-the-Box Laws

The Fair Chance to Compete on Jobs Act (FCA), enacted in 2019, bars federal agencies and federal contractors from asking about an applicant's criminal…

Lesson · CIPP/US

FCRA Restrictions on Background Checks

The FCRA governs background checks via consumer reports from a CRA - not just credit, but criminal and driving records too. Employers need a permissible…

Lesson · CIPP/US

Federal Laws Affecting Employment Privacy

A cluster of federal laws bears on employment privacy: antidiscrimination laws, benefits laws (HIPAA, COBRA, ERISA, FMLA), and recordkeeping/data laws…

Lesson · CIPP/US

Intercepting Communications: Wiretap Act and ECPA

The Wiretap Act and ECPA generally prohibit intercepting wire, oral, and electronic communications. Two workplace exceptions: consent (party or one party…

Lesson · CIPP/US

Investigating Employee Misconduct: Vail Letter and FACTA Fix

Investigations should be fair, documented, and compliant with CBAs. The FTC's Vail Letter made third-party investigators CRAs, requiring notice and…

Lesson · CIPP/US

LBS, DLP, BYOD, and Teleworking Policies

Monitoring policies must address location-based services (GPS on vehicles generally OK; tracking people themselves is more limited), data loss prevention…

Lesson · CIPP/US

Workplace Privacy: The U.S. Legal Landscape

The U.S. has no overarching law for employment privacy. Federal statutes cover specific areas, state contract and tort law offer narrow protections, and…

Lesson · CIPP/US

Lifestyle Discrimination

Off-duty lifestyle is generally treated as private. Weight-based rules can invite discrimination suits (and obesity from a physiological disability may be…

Lesson · CIPP/US

Workplace Monitoring: Baseline and Policies

U.S. private-sector employees have limited expectations of privacy at work - facilities and equipment belong to the employer, granting broad monitoring…

Lesson · CIPP/US

Polygraphs and the EPPA

The Employee Polygraph Protection Act of 1988 (EPPA), enforced by the DOL, bars private employers from using lie detectors on workers or applicants…

Lesson · CIPP/US

Legal Obligations and Incentives to Monitor

Employers monitor to meet safety laws (OSHA), improve quality (recorded service calls), limit negligent-supervision liability, protect physical security…

Lesson · CIPP/US

Federal Agencies Protecting Employee Privacy

Five federal agencies are central: the DOL (administers FLSA, OSHA, ERISA), the EEOC (Title VII, ADEA, ADA), the FTC and CFPB (unfair/deceptive practices…

Lesson · CIPP/US

Screening Technologies: Social Media and AI

Using social media to screen is generally allowed but risks discrimination claims if protected-class info is used, FCRA exposure for nontraditional…

Lesson · CIPP/US

State Contract, Tort, and Statutory Protections

Contracts (especially collective bargaining agreements) can create enforceable privacy obligations. Three common-law torts - intrusion upon seclusion…

Lesson · CIPP/US

Stored Communications Act and City of Ontario v. Quon

The SCA bars unauthorized access to stored electronic communications, with exceptions for the service provider (often the employer) and an authorized…

Lesson · CIPP/US

Substance Use Testing

There is no federal privacy statute directly governing employer substance testing. The ADA excludes current illegal drug use (a drug test is not a medical…

Lesson · CIPP/US

CIPP/US automated employment decision tool guide

Automated employment decision tools explained with a source-backed CIPP/US study bridge.

Lesson · CIPP/US

CALEA and the Cybersecurity Information Sharing Act

CALEA (1994) requires telecommunications carriers to design interception capability into their products; the FCC extended it to broadband and VoIP. CISA…

Lesson · CIPP/US

Evidence Stored Abroad - CLOUD Act and Budapest Convention

The CLOUD Act (2018) lets the DOJ compel U.S. providers to produce data regardless of where it is stored (mooting the Microsoft Ireland case) and lets…

Lesson · CIPP/US

Disclosures Forbidden by Law and Evidentiary Privileges

Many privacy laws forbid disclosure using opt-in or opt-out rules: HIPAA and COPPA require opt-in consent; GLBA forbids disclosure if the individual has…

Lesson · CIPP/US

Disclosures Permitted by Law

Some laws permit but do not require disclosure. HIPAA requires very few disclosures but permits many (public health, law enforcement, national security)…

Lesson · CIPP/US

Disclosures Required by Law

Certain laws compel disclosure: FDA adverse-event reporting, OSHA injury reporting, state injury and disease reporting, and the BSA. HIPAA permits…

Lesson · CIPP/US

Discovery Under HIPAA and GLBA

Sectoral laws coexist with discovery. HIPAA permits PHI in discovery via patient authorization, a court order, or satisfactory assurances (a qualified…

Lesson · CIPP/US

Electronic Discovery and ESI

Since the 2006 FRCP revisions, electronically stored information (ESI) drives pretrial discovery. Sound data retention (per Sedona Conference guidance)…

Lesson · CIPP/US

FISA, Section 702, Section 215, and FISC

FISA orders issue from the FISC on probable cause that the target is a foreign power or agent, not probable cause of a crime, when foreign intelligence is…

Lesson · CIPP/US

Emerging Fourth Amendment Issues - Abortion Data and Geofence Warrants

Post-Dobbs, states that outlaw abortion may send warrants to companies in states that do not, creating an interstate conflict of law (California bars…

Lesson · CIPP/US

Fourth Amendment Limits on Law Enforcement Searches

The Fourth Amendment bars unreasonable searches; warrants need probable cause, particularity, and a neutral magistrate. Katz created the reasonable…

Lesson · CIPP/US

National Security Letters

An NSL is a subpoena issued by the FBI without judicial involvement for records relevant to terrorism or clandestine intelligence. The PATRIOT Act…

Lesson · CIPP/US

National Security Surveillance - Constitutional Tension and Post-Snowden Reform

National security surveillance pits the president's Article II powers against Article III judicial limits. FISA (1978) balanced both. The PATRIOT Act…

Lesson · CIPP/US

How Disclosures Are Required, Permitted, or Forbidden

When responding to litigation and investigations, the law can require, permit, or forbid disclosure of personal information. The same statute can do all…

Lesson · CIPP/US

Preservation Orders and Pen Register / Trap-and-Trace

Under the SCA, a provider must preserve records on a government request pending a court order, similar to a litigation hold. Pen register and…

Lesson · CIPP/US

Public Court Records, Protective Orders, and Required Redaction

U.S. courts are traditionally open, but online records ended practical obscurity. Litigants use protective orders (FRCP 26(c), three-part test) and HIPAA…

Lesson · CIPP/US

Right to Financial Privacy Act and Privacy Protection Act

RFPA (1978) requires customer authorization or specific legal process for federal access to individuals' financial records, with advance notice and a…

Lesson · CIPP/US

Statutes That Go Beyond Fourth Amendment Requirements

After the Supreme Court held the Fourth Amendment did not protect bank records or dialed numbers, Congress added statutory process. RFPA (1978) covers…

Lesson · CIPP/US

Cross-Border Discovery and the Hague Convention

U.S. broad-discovery rules collide with foreign laws like the GDPR that protect personal data. Courts split on how to resolve the conflict; the Hague…

Lesson · CIPP/US

Wiretap Act, ECPA, and Stored Communications Act

The Wiretap Act (Title III) strictly bars intercepting calls; ECPA extends this to electronic communications. Federal law permits one-party consent, but…

Lesson · CIPP/US

CIPP/US cybersecurity information sharing guide

Cybersecurity information sharing rules explained with a source-backed CIPP/US study bridge.

Lesson · CIPP/US

Breach Notification and Response

A GDPR data breach is broad, covering destruction, loss, alteration, or unauthorized disclosure/access. Controllers must notify the DPA within 72 hours…

Lesson · CIPP/US

Consent Under the GDPR

GDPR consent must be freely given, specific, informed, and an unambiguous indication of the data subject's wishes, expressed by statement or clear…

Lesson · CIPP/US

Controller, Processor, and Data Subject

The controller determines the purposes and means of processing; the processor processes on the controller's behalf under contract. The data subject is the…

Lesson · CIPP/US

Data Subject Rights: Overview and Handling Requests

The GDPR grants individuals control through rights to be informed, access, rectification, erasure, restriction, portability, objection, and freedom from…

Lesson · CIPP/US

Data Protection Authorities and Data Protection Officers

DPAs are independent national authorities that enforce data protection law - one per member state except Germany (federal plus 16 Lander). The DPO is the…

Lesson · CIPP/US

Enforcement: Complaints and Liability

A complaint can be initiated by a data subject or a DPA; where multiple DPAs are involved a lead DPA is determined. Both controllers and processors can be…

Lesson · CIPP/US

Rights to Erasure and Restriction of Processing

The right to erasure (right to be forgotten) applies in defined situations and requires deletion even from backups unless an exemption applies. As an…

Lesson · CIPP/US

GDPR Overview, Scope, and Sanctions

The General Data Protection Regulation (GDPR) is the worldwide template for data protection, applying broadly to companies with EU assets and employees…

Lesson · CIPP/US

Recent Developments in Global Data Flows

Beyond the GDPR's influence, the Global CBPR Forum builds on APEC's Cross-Border Privacy Rules to allow trade with privacy assurances, and the OECD…

Lesson · CIPP/US

Levels of Fines and Criminal Sanctions

The GDPR has two tiers of fines. Higher-level fines (up to four percent of global revenue or €20 million, whichever is greater) target core processing…

Lesson · CIPP/US

Personal Data and Sensitive Personal Data

Personal data is any data relating to an identified or identifiable natural person, directly or indirectly. Sensitive personal data is a special category…

Lesson · CIPP/US

Rights to Portability, to Object, and Against Automated Decision-Making

Portability gives data the subject provided in a machine-readable format, only where processing is by consent or contract and automated. The right to…

Lesson · CIPP/US

Rights to Be Informed, Access, and Rectification

The right to be informed drives privacy notices (layered, just-in-time, dashboards). The right of access underlies the subject access request and is the…

Lesson · CIPP/US

Appropriate Safeguards and Derogations

For third countries, transfers need an appropriate safeguard. The two most common are SCCs (the most widely used) and BCRs (for intra-group transfers…

Lesson · CIPP/US

EU-U.S. Transfers: Schrems I, Schrems II, and the Data Privacy Framework

The CJEU struck down Safe Harbor (Schrems I, 2015) and Privacy Shield (Schrems II, 2020) over U.S. surveillance concerns. The EU-U.S. Data Privacy…

Lesson · CIPP/US

The Seven General Principles

All processing must abide by the GDPR's seven principles: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage…

Lesson · CIPP/US

International Transfers and Adequate Countries

Transfers from the EEA to non-EEA countries are prohibited unless supported by an adequacy decision, an appropriate safeguard, or a derogation. Adequate…

Lesson · CIPP/US

Applying the Framework: California SB 1386 Breach Notification

California SB 1386 was the first breach-notification law. It covers entities doing business in California that hold computerized personal information…

Lesson · CIPP/US

Case Law, Common Law, and Stare Decisis

Case law is judges' final decisions; courts follow precedent under stare decisis. Common law is principles built over time in judicial decisions…

Lesson · CIPP/US

Consent Decrees

A consent decree is a judge-approved settlement where the defendant agrees to stop alleged illegal activity, typically without admitting guilt. Once…

Lesson · CIPP/US

Constitutions as a Source of Privacy Law

The U.S. Constitution never uses the word privacy, but the Fourth Amendment limits government searches and the Supreme Court recognized a penumbra of…

Lesson · CIPP/US

Contract Law and Privacy Notices

A contract needs offer, acceptance, and consideration. Privacy obligations often live in vendor contracts, and a privacy notice can itself be a contract…

Lesson · CIPP/US

Key Definitions: Person, Jurisdiction, Authority, Preemption, Private Right of Action

Core terms for U.S. privacy law: person (natural or legal), jurisdiction (subject-matter and personal), general vs. specific authority, preemption, and…

Lesson · CIPP/US

Six Keys to Understanding Any Law

Analyze any privacy law with six questions: who is covered, what information/uses, what is required/prohibited, who enforces, what happens if you don't…

Lesson · CIPP/US

Legislation and Federal Preemption

Both Congress and state legislatures enact privacy laws. The key question is whether a federal law preempts state law: HIPAA lets states pass stricter…

Lesson · CIPP/US

Notice, Choice, and Access (Opt-In vs. Opt-Out)

Notice describes information practices; choice lets individuals control collection/use - opt-in is an affirmative yes, opt-out implies consent unless the…

Lesson · CIPP/US

Regulations, Rules, and Agency Guidance

Some statutes direct agencies like the FTC or FCC to issue regulations carrying compliance force - e.g., CAN-SPAM rules on the opt-out mechanism. Agencies…

Lesson · CIPP/US

Federal and State Regulatory Authorities for Private-Sector Privacy

The FTC has general authority over unfair/deceptive practices plus specific authority in areas like children's privacy; sector regulators include banking…

Lesson · CIPP/US

Self-Regulation in Privacy

Self-regulatory regimes govern many industries' privacy practices - examples include the NAI, the Association of National Advertisers (formerly the DMA)…

Lesson · CIPP/US

Sources of Law in the United States

U.S. law flows from many sources: constitutions, legislation, case law, contract law, tort law, agency regulations, and consent decrees. Privacy…

Lesson · CIPP/US

The Three Branches of U.S. Government

The U.S. Constitution creates three branches - legislative makes laws, executive enforces them, judicial interprets them - with checks and balances. This…

Lesson · CIPP/US

Tort Law and Privacy Torts

Torts are civil wrongs in three categories: intentional, negligent, and strict liability. Privacy torts (intrusion on seclusion, public disclosure of…

Lesson · CIPP/US

The Adversarial Mindset: STRIDE, Zero Trust and Least Privilege

Cybersecurity adopts the adversarial mindset and threat modeling (e.g. the STRIDE framework and MITRE ATT&CK). Key principles include zero trust, least…

Lesson · CIPP/US

Cybersecurity Foundations: The CIA Triad

Security underpins privacy. The CIA triad - confidentiality, integrity, and availability - frames cybersecurity. A useful first approximation: privacy…

Lesson · CIPP/US

Client-Server Architecture: Front End and Back End

In the client-server model a client requests a service from a server. The browser-facing front end is separated from the back end databases; separating…

Lesson · CIPP/US

Cloud Computing: SaaS, PaaS and IaaS

Cloud computing is on-demand availability of computing resources, replacing on-premises computing. The three models - Software as a service (SaaS)…

Lesson · CIPP/US

Deep Packet Inspection

Deep packet inspection examines packet contents beyond the header, useful for malware detection and data-leak prevention but also enabling tracking and…

Lesson · CIPP/US

Deidentification: Anonymous vs Pseudonymous and Identifiers

When data cannot be traced to a person, privacy law no longer applies. Anonymization removes identifiability; pseudonymization masks identity with a…

Lesson · CIPP/US

Deidentification Standards: HIPAA Methods and FTC Guidance

The longest-standing U.S. deidentification rules are under HIPAA: the safe harbor method removes 18 identifiers and the expert determination method relies…

Lesson · CIPP/US

Approaches to Deidentification: Suppression, Generalization, Noise Addition

Three core techniques hide identity: suppression removes values, generalization replaces detail with a broader category, and noise addition substitutes…

Lesson · CIPP/US

Edge Computing and Latency

Edge computing processes data at the network periphery, close to the source. Driven by the growth of IoT sensors, it reduces the cost of centralized…

Lesson · CIPP/US

How Emails and Texts Work: SMTP, IMAP, POP, SMS and OTT

SMTP sends email; IMAP (which leaves mail on the server) is overtaking POP (which deletes it). Texts use SMS (160-character limit, works without internet)…

Lesson · CIPP/US

Tracking Email Recipients and Cross-Device Tracking

HTML email can track opens via a unique tracking pixel; reading in plain text defeats it. Cross-device tracking links a user across devices using…

Lesson · CIPP/US

Encryption: Symmetric, Asymmetric, Certificates and PKI

Encryption shields data by converting plaintext to ciphertext using a key. Symmetric key cryptography uses one shared key (fast but sharing is hard)…

Lesson · CIPP/US

First-Party Data Collection and Data Brokers

First parties collect data via cookies, user-generated content (UGC), and account terms of use; in California and the EU they give notice before setting…

Lesson · CIPP/US

Hashing, Salt and Digital Signatures

Hashing is a one-way function producing an output that does not reveal the input, used for pseudonyms and integrity checks. Plain hashes can be defeated…

Lesson · CIPP/US

HTTP Cookies: Session vs Persistent, First vs Third Party

Because HTTP/HTTPS are stateless, HTTP cookies maintain continuity. Session cookies last until the browser closes; persistent cookies can last…

Lesson · CIPP/US

Basics of the Internet: TCP/IP and Packet Switching

The internet is a network of networks descended from the ARPANET. Transmission control protocol (TCP) establishes reliable connections and breaks data…

Lesson · CIPP/US

Key Web Infrastructure: Servers, Proxies, VPNs, ISPs and IP Addresses

Web content lives on web servers; a proxy server and Virtual private network (VPN) act as gateways that can mask activity. An Internet service provider…

Lesson · CIPP/US

Location Tracking: Technologies and Carpenter

Location is tracked via cell-tower/Wi-Fi triangulation, GPS, and photo metadata. The U.S. has historically had few restrictions, but Carpenter v. United…

Lesson · CIPP/US

Internet Monitoring by Employers, Schools and Parents

U.S. employers may generally monitor internet use and emails on company networks/devices. The Children's Internet Protection Act (CIPA) requires public…

Lesson · CIPP/US

The NIST Cybersecurity Framework

The NIST Cybersecurity Framework (CSF), first published in 2014, is guidance rather than law and popularized five Framework Core Functions: Identify…

Lesson · CIPP/US

Privacy by Design and Limits of Technical Measures

Privacy by design embeds privacy from the onset and is legally required in California and the EU. Privacy-enhancing technologies altering or shielding…

Lesson · CIPP/US

Reidentification Risk and Differential Privacy

Computer scientists have repeatedly re-identified supposedly anonymized data. Differential privacy is a mathematical definition of privacy that adds…

Lesson · CIPP/US

Surveillance by Audio, Video and Other Sensors

Devices' microphones and cameras can be hijacked by remote access trojan (RAT) malware, or activated by employers/police. Government video surveillance is…

Lesson · CIPP/US

Spyware and Phishing Variants

Spyware (including keylogging) covertly surveils a device, often delivered by phishing social engineering. Variants include spear phishing, whaling…

Lesson · CIPP/US

Third-Party Data Collection and the Decline of Third-Party Cookies

Ad networks long used third-party cookies to track users across sites. Market and regulatory changes are shrinking this: the CPRA (effective January 2023)…

Lesson · CIPP/US

URLs, URIs, URNs and Hyperlinks

A Uniform resource locator (URL) is a web address with a protocol prefix, optional www, a domain name and a top-level domain. URLs are a subset of Uniform…

Lesson · CIPP/US

Web Infrastructure: HTTP, HTML, HTTPS and XML

The web is narrower than the internet. Hypertext transfer protocol (HTTP) and Hypertext markup language (HTML), invented by Tim Berners-Lee, drive the…

Lesson · CIPP/US

Wireless Eavesdropping and Defenses

On unencrypted Wi-Fi, packet sniffing can capture traffic, a risk in shared public hotspots. Defenses include encrypted Wi-Fi (per-user keys), VPNs (which…

Lesson · CIPP/US

Data Breach Readiness Assessments

A data breach readiness assessment examines the risk of a breach plus the likelihood and severity of a personal data breach, weighing data type, technical…

Lesson · CIPP/US

The Business Case for Privacy and the Cost of Mishandling Data

Privacy compliance carries real cost, but mishandling personal data can be far more expensive in fines, breach costs, and lost consumer trust. Privacy is…

Lesson · CIPP/US

Responding to User Requests and Consumer Rights

Many federal and state laws grant rights of control: access, correction, deletion, portability, against automated decision-making, and nondiscrimination…

Lesson · CIPP/US

Data Accountability - Controllers, Processors, and Encryption

Accountability questions cover where/how/how long data is stored, sensitivity, encryption, cross-border transfer, and who sets the rules. A controller…

Lesson · CIPP/US

Data Flow Mapping - Top-Down and Bottom-Up

After inventory and classification, data flows are mapped and documented (what, where, and why data is processed). The top-down approach used for…

Lesson · CIPP/US

Data Inventory and Data Classification

An organization should inventory all PI it collects, stores, uses, or discloses (customer and employee), then classify it by sensitivity to set access…

Lesson · CIPP/US

The Data Life Cycle

Data should be managed across its life cycle - creation, storage, sharing and usage, archival, and deletion - because privacy-protecting approaches at one…

Lesson · CIPP/US

Global Perspective and Cross-Border Data Transfer Mechanisms

More than 160 nations have significant privacy laws; the GDPR draws the most attention, with fines based on worldwide revenue. Cross-border trust…

Lesson · CIPP/US

Information Management and the Privacy Professional's Role

Information management establishes, implements, and monitors the organization's privacy program under a senior leader such as the CPO, drawing on legal…

Lesson · CIPP/US

Information Security - CIA Triad and Control Types

Information security protects information per three attributes - confidentiality, integrity, availability (CIA) - using physical, administrative, and…

Lesson · CIPP/US

Managing User Preferences and Dark Patterns

Managing preferences raises challenges of scope, mechanism, linking across channels, time period, and third-party vendors. Good practice: the channel for…

Lesson · CIPP/US

Opt-In, Opt-Out, and No Option

U.S. laws differ on consent: opt-in (COPPA parental consent, HIPAA PHI disclosure, FCRA credit report release); opt-out (GLBA third-party transfers, VPPA…

Lesson · CIPP/US

DPIA vs PIA: What Is the Difference? CIPP/US Guide

DPIA vs PIA explained: what each assessment is, when the GDPR requires a DPIA, what a U.S. PIA covers and how CIPP/US questions test the difference.

Lesson · CIPP/US

Delivering Privacy Notices - Layered, Just-in-Time, and Mobile

Notices should be accessible online and in-person, with training for staff. Common techniques include the layered notice (short top layer plus full bottom…

Lesson · CIPP/US

Privacy Operational Life Cycle - Assess, Protect, Sustain, Respond

The privacy operational life cycle continuously improves the program through four stages: assess, protect, sustain, and respond - from baselining and…

Lesson · CIPP/US

Drafting, Updating, and Versioning the Privacy Policy

Policies need legal review and executive approval, periodic review (at least annually), and version control. The FTC says express affirmative consent…

Lesson · CIPP/US

Privacy Policy vs Privacy Notice: The Difference for CIPP/US

Privacy policy vs privacy notice explained: the policy is the internal rulebook, the notice is the external statement to consumers, and the exam tests…

Lesson · CIPP/US

The Privacy Program and Four Business Risks

A privacy program establishes accountability and compliance, and should balance four business risks: legal, reputational, operational, and strategic. The…

Lesson · CIPP/US

Privacy Program Framework and Metrics

A privacy program framework operationalizes controls and should begin with a privacy mission statement/vision aligned to the organization. Building it…

Lesson · CIPP/US

Privacy Risk Management and Privacy Harms

Privacy risk management identifies and mitigates risks to information assets. Privacy risk is the likelihood individuals will experience problems from…

Lesson · CIPP/US

Privacy Team Roles - CPO, DPO, and Others

A privacy team may include a CPO, DPO, chief legal officer, privacy engineer, privacy manager, and privacy analyst, plus informal privacy champions and…

Lesson · CIPP/US

Vendor and Third-Party Risk Assessments

Companies remain responsible for vendor actions and must use contract protections (confidentiality, no further use, subcontractor flow-down, breach…

Lesson · CIPP/US

Additional FTC Authority: COPPA, HITECH, FCRA, CAN-SPAM

Beyond Section 5 the FTC enforces COPPA (children under 13, parental consent), shares HITECH breach authority with HHS, has historic FCRA/FACTA authority…

Lesson · CIPP/US

Additional State Protections: Torts, BIPA, and the AADC Act

States add protection via constitutions, common-law privacy torts, and contract theories. Illinois's BIPA (2008) requires notice and consent for…

Lesson · CIPP/US

Deceptive Trade Practices and Broken Privacy Promises

A deceptive practice is a material statement or omission likely to mislead reasonable consumers. Breaking a privacy-notice promise is deceptive under…

Lesson · CIPP/US

Federal Privacy Enforcement Outside the FTC

Many federal agencies enforce privacy depending on the statute violated: OCR/HHS for HIPAA, CFPB and bank regulators for GLBA, Dept. of Education for…

Lesson · CIPP/US

The Federal and State Regulatory Landscape

In the U.S., privacy is regulated at both federal and state level. Federal regulators are largely sectoral (medical, financial, education), the FTC is the…

Lesson · CIPP/US

FTC Enforcement Process and Consent Decrees

Most FTC privacy actions end in a consent decree: the respondent does not admit fault but promises to change practices. Decrees are public, may require…

Lesson · CIPP/US

FTC Enforcement Tools and the AMG Decision

The FTC uses Section 5(l) for administrative cease-and-desist enforcement and Sections 13(b) and 19 for judicial relief. The Supreme Court in AMG Capital…

Lesson · CIPP/US

The FTC, Section 5, and Jurisdictional Limits

Section 5 of the FTC Act bars unfair or deceptive acts or practices in or affecting commerce and is the single most important piece of U.S. privacy law…

Lesson · CIPP/US

The Future of FTC Enforcement

FTC priorities track technology: a 2023 Office of Technology, 2022 proposed commercial surveillance rules (under Magnuson-Moss), a 2020 data portability…

Lesson · CIPP/US

FTC Rulemaking Under Magnuson-Moss

The FTC's UDAP rulemaking does not use ordinary APA notice-and-comment. It must follow the complex Magnuson-Moss (Section 18) procedures, showing the…

Lesson · CIPP/US

Other Federal Privacy Actors and the DOJ's Criminal Role

Beyond sector regulators, agencies like State, Commerce, Transportation, OMB, IRS/Treasury, DHS, and DOE touch privacy. OMB interprets the Privacy Act of…

Lesson · CIPP/US

Self-Regulation and Enforcement

Self-regulation spans legislation, enforcement, and adjudication. Under Section 5/UDAP it is only quasi-legislative (a government agency still enforces)…

Lesson · CIPP/US

State Attorneys General and UDAP Statutes

State AGs are the primary privacy enforcers in most states and may join federal actions under HIPAA, GLBA, and CAN-SPAM. All 50 states have UDAP statutes…

Lesson · CIPP/US

State Breach Notification, SSN Protections, and Identity Theft Laws

California enacted the first breach law in 2002; all 50 states now have one. Breach-law personal information centers on name + SSN, driver's license/ID…

Lesson · CIPP/US

State Comprehensive Laws and Federal Sectoral Exemptions

By end of 2022, five states had comprehensive laws: California, Colorado, Connecticut, Utah, Virginia. They reference COPPA for children and exempt…

Lesson · CIPP/US

Types of Litigation and Enforcement

Three main categories of legal action: civil litigation (private plaintiff seeks damages or an injunction), criminal prosecution (government, can mean…

Lesson · CIPP/US

Unfair Trade Practices

An unfair practice causes or is likely to cause substantial injury that is not reasonably avoidable by consumers and not outweighed by countervailing…

Lesson · CIPP/US

Court Confirmation of FTC Authority: Wyndham and LabMD

FTC v. Wyndham (2015, Third Circuit) confirmed the FTC's unfairness authority extends to cybersecurity. FTC v. LabMD (2018, Eleventh Circuit) recognized…

Lesson · CIPP/US

Access, Correction, and Deletion Rights

All five states grant access and deletion; the right to correction is provided by everyone except Utah. Deletion scope differs: Colorado, Connecticut…

Lesson · CIPP/US

Defining Business - Applicability Thresholds

Which companies are covered turns on the definition of business (called controller in the four non-California states). California is broadest ($25M…

Lesson · CIPP/US

Which Entities Are Excluded from Business

All five states exempt governments, nonprofits, and FCRA-covered entities. But the states diverge on higher education, securities associations, and…

Lesson · CIPP/US

CCPA vs CPRA: What Changed? CIPP/US California Guide

CCPA vs CPRA explained: the CPRA amended the CCPA rather than replacing it. What changed, what the exam tests and how to answer California questions.

Lesson · CIPP/US

Opt-In Default for Children's Data

Age-based opt-in rules vary: California requires opt-in to sell/share data of consumers under 16; Connecticut requires opt-in for ages 13-16 to sell or…

Lesson · CIPP/US

Defining Consumer - Who Is Protected

All five laws protect their state residents, and the term is NOT limited to purchasers. The key distinction: California includes employees in its…

Lesson · CIPP/US

Consumer Rights Overview and Response Timelines

These laws grant GDPR-like rights (access, correction, deletion, portability, opt-outs, etc.). Response times: Colorado, Connecticut, Utah, Virginia allow…

Lesson · CIPP/US

Cure Periods and the Private Right of Action

Cure periods split: California's expired; Colorado and Connecticut's sunset Dec 31, 2024; Utah and Virginia have a 30-day cure with no end date. No state…

Lesson · CIPP/US

Enforcement - Penalties and Enforcers

The state attorney general has sole or joint enforcement power in every state; California adds the CPPA. Penalty caps vary: California $2,500 (up to…

Lesson · CIPP/US

Entity-Level vs Data-Based Exemptions

State comprehensive laws use two exemption types: entity-level exemptions (a whole organization is exempt) and data-based exemptions (only a class of data…

Lesson · CIPP/US

The U.S. Has No Federal Comprehensive Privacy Law

The United States regulates privacy sectorally (HIPAA, GLBA, COPPA) and as of this writing has no federal comprehensive privacy law, unlike most countries…

Lesson · CIPP/US

Business Obligation - Notice and Transparency

All five states require a privacy notice and a notice of the right to opt out. Only California requires notice at the point of collection, and California…

Lesson · CIPP/US

Opt-Out Rights - Sales, Targeted Advertising, Automated Decisions

All five states allow opt out of sales; California also lets consumers opt out of sharing. For targeting/cross-context behavioral advertising, Colorado…

Lesson · CIPP/US

Personal Information and Its Exclusions

All five define personal information as data linkable to an individual, going beyond breach-notification definitions. California uniquely includes…

Lesson · CIPP/US

Federal Preemption and Private Right of Action Debates

The two most contested issues in any U.S. national privacy bill are preemption (would it override stricter state laws?) and a private right of action…

Lesson · CIPP/US

Purpose Limits, Risk Assessments, and Security

California, Colorado, Connecticut, Virginia impose purpose/processing limitations and require risk assessments for heightened-risk processing; Utah lacks…

Lesson · CIPP/US

Sale and California's Unique Sharing Regulation

Each state regulates the sale of personal data, but the definition splits: Utah and Virginia limit sale to monetary compensation, while California…

Lesson · CIPP/US

Rights Concerning Sensitive Data and Nondiscrimination

Sensitive-data handling splits sharply: Colorado, Connecticut, Virginia require opt-in consent; Utah requires only notice and opt-out; California uses a…

Lesson · CIPP/US

Sensitive Personal Information

All five states treat citizenship, genetic/biometric data, physical/mental health, race/ethnicity, religion, and sexual orientation as sensitive. States…

Lesson · CIPP/US

The Five State Laws in Effect in 2023

This chapter focuses on the five state comprehensive laws in effect in 2023: California, plus the CPA (Colorado), CTDPA (Connecticut), UCPA (Utah), and…

Lesson · CIPP/US

CIPP/US Global Privacy Control and opt-out signals

Global Privacy Control and California opt-out handling explained for CIPP/US study.

Lesson · CIPP/US

Notification: Attorney General and State Agency Notice

About two-thirds of states require notice to the attorney general/state agency, often above a numeric threshold (commonly 250 to 1,000 people). Vermont's…

Lesson · CIPP/US

Common Structure of State Breach Laws

Despite differences, state breach laws share three building blocks: key terms (personal information, covered entities, security breach), notification…

Lesson · CIPP/US

California Statutory Damages (CCPA/CPRA)

In 2020 California became the first state to let consumers recover statutory damages for breaches: $100 to $750 per incident where the breach resulted…

Lesson · CIPP/US

State Breach, Security, and Destruction Laws: The Landscape

All 50 states have data breach notification laws, and many states layer on data security laws and data destruction laws. With no comprehensive federal…

Lesson · CIPP/US

Breach Laws: Covered Entities

Most states cover entities that conduct business in the state and maintain computerized data containing personal information. Georgia is a notable…

Lesson · CIPP/US

Notification: Consumer Reporting Agencies

About two-thirds of states require notice to nationwide CRAs, often above a 250 to 1,000 threshold. The common timing standard is without unreasonable…

Lesson · CIPP/US

Notification: Free Credit Monitoring

When SSNs are exposed, the FTC suggests offering at least a year of free credit monitoring. Three states - California, Delaware, and Massachusetts -…

Lesson · CIPP/US

When Notification May Be Delayed

When a breach is suspected to involve criminal activity, all states allow delay if law enforcement determines notice would impede a criminal…

Lesson · CIPP/US

Enforcement: Penalties and Private Rights of Action

All 50 states impose civil penalties; about one-third let the attorney general levy fines, often capped per breach ($750,000 being the highest noted, in…

Lesson · CIPP/US

Exceptions to Notification

Three exceptions excuse notice: an entity subject to a more stringent law (e.g., HIPAA or the GLBA Safeguards Rule), an entity following its own…

Lesson · CIPP/US

Notification: Method and Substitute Notice

The default method is written notice by postal mail. Email or phone are usually allowed only if the person previously and explicitly chose that channel…

Lesson · CIPP/US

The Absence of a Federal Breach Law

Calls for a uniform federal breach law go back to 2003, but no comprehensive federal data breach notification law has been enacted. The deadlock turns on…

Lesson · CIPP/US

Notification: Content of the Letter

About half of states mandate specific content (incident description, approximate date, data types, steps taken, contact phone, identity-theft steps, CRA…

Lesson · CIPP/US

Breach Laws: Defining Personal Information

In most states, personal information means a person's first name or first initial and last name combined with at least one of: SSN, driver's license/state…

Lesson · CIPP/US

Breach Laws: Security Breach and Risk-of-Harm

A security breach is generally unauthorized access to or acquisition of computerized personal data that compromises its confidentiality, security, or…

Lesson · CIPP/US

State Data Destruction Laws

About two-thirds of states have data destruction (disposal) laws requiring personal information to be disposed of so it is no longer readable or…

Lesson · CIPP/US

State Data Security Laws

About two-thirds of states require data security measures. Roughly 20 states use a 'reasonable security' standard (e.g., California's AB 1950); about 10…

Lesson · CIPP/US

US Approach in Context

The lack of comprehensive federal breach, security, and destruction requirements leads some to call the US less stringent than jurisdictions like Europe…

Lesson · CIPP/US

Notification: Timing to Affected Parties

The most common timing standard is as expeditiously as possible and without unreasonable delay. Where a specific cap is set, 45 days after discovery is…

Lesson · CIPP/US

Notification: Whom to Notify

Breach laws commonly require notice to three audiences: affected residents (all 50 states), state attorneys general/agencies (about two-thirds), and…

Lesson · CIPP/US

CIPP/US data broker registration and deletion guide

California data broker registration and deletion mechanisms explained for CIPP/US study.

Lesson · CIPP/US

CIPP/US biometric privacy law and facial data guide

State biometric privacy law concepts explained with a source-backed CIPP/US study bridge.

Lesson · CIPP/US

CIPP/US Illinois genetic privacy law guide

Illinois genetic privacy law explained with a direct answer and CIPP/US study context.

Lesson · CIPP/US

CIPP/US Washington consumer health data law guide

Washington consumer health data law explained with a source-backed CIPP/US study bridge.

Lesson · CIPP/US

CIPP/US state AI and employment decision guide

Automated employment decision tool rules explained with a source-backed CIPP/US study bridge.

Lesson · CIPP/US

Business Associates and BAAs

A business associate performs services for a covered entity involving the use or disclosure of PHI. Before HITECH they were bound only by contract; after…

Lesson · CIPP/US

Covered Entities Under HIPAA

HIPAA directly covers health care providers conducting certain electronic transactions, health plans, and health care clearinghouses. Cash-only providers…

Lesson · CIPP/US

21st Century Cures Act and Information Blocking

The Cures Act (2016) promotes EHI interoperability by prohibiting information blocking - activity likely to interfere with access, exchange, or use of…

Lesson · CIPP/US

Cures Act: API Portability and Other Privacy Provisions

The Cures Act requires certified health IT developers to publish APIs so patients can move EHI to apps of their choosing - raising the concern that data…

Lesson · CIPP/US

GINA Preemption and State Genetic Laws

GINA is a floor and does not preempt stricter state law. Because GINA leaves life insurers, mortgage lenders, and schools untouched, states like…

Lesson · CIPP/US

Genetic Information Nondiscrimination Act (GINA)

GINA (2008) bars health insurers from discriminating on genetic predisposition absent manifest symptoms and bars employers from using genetic information…

Lesson · CIPP/US

HIPAA Enforcement and Penalties

The OCR enforces both rules with civil penalties up to roughly $2 million per year per violation type and audits entities. HIPAA has no private right of…

Lesson · CIPP/US

HIPAA Origins and Purpose

HIPAA became law in 1996 to improve health care efficiency, requiring electronic reimbursement formats for Medicare and Medicaid. Recognizing the privacy…

Lesson · CIPP/US

HIPAA Preemption and State Laws

HIPAA does not preempt stricter state laws. Practitioners must review state law for added patient rights, extra disclosures, and shorter deadlines, and…

Lesson · CIPP/US

Health Information Is Protected Differently by Setting

HIPAA only applies to covered entities and their business associates. The same health-related data held by a bookstore, website, or smartwatch maker…

Lesson · CIPP/US

HITECH and Breach Notification

HITECH (2009) strengthened HIPAA and created breach notification. A breach is presumed unless a risk assessment shows low probability of compromise…

Lesson · CIPP/US

HITECH: Penalties, Limited Data, and EHRs

HITECH increased penalties (up to $2 million for willful violations, even without knowledge) and extended criminal liability to individuals. It encourages…

Lesson · CIPP/US

Medical Technology: FTC Act, FDCA, and State Laws

For medtech outside HIPAA, Section 5 of the FTC Act is the primary federal tool against deceptive and unfair practices (e.g., the 2021 Flo Health action)…

Lesson · CIPP/US

PHI and ePHI Defined

PHI is individually identifiable health information held by a covered entity or business associate relating to a person's health, care, or payment. ePHI…

Lesson · CIPP/US

Limits and Exceptions to the Privacy Rule

The Privacy Rule does not apply to deidentified information and offers flexibility for research. Other exceptions allow disclosure without consent for…

Lesson · CIPP/US

The HIPAA Privacy Rule and the FIPPs

The Privacy Rule is HIPAA's most detailed implementation of Fair Information Privacy Practices: privacy notices, authorizations, minimum necessary limits…

Lesson · CIPP/US

The HIPAA Security Rule

Finalized in 2003, the Security Rule covers only ePHI and binds both covered entities and business associates. It requires administrative, physical, and…

Lesson · CIPP/US

Confidentiality of Substance Use Disorder Patient Records Rule

Rooted in 1970s laws, this rule protects patient-identifying information held by federally funded substance abuse treatment programs. It requires written…

Lesson · CIPP/US

Temporary COVID-19 telehealth measures

During the COVID-19 public health emergency, OCR temporarily allowed nonpublic-facing videoconferencing even when it did not fully meet HIPAA rules. That…

Lesson · CIPP/US

Why Medical Privacy Gets Special Protection

Health information is treated as especially sensitive because it relates to one's body and mind, encourages candor with doctors, and protects against…

Lesson · CIPP/US

CIPP/US FTC health breach notification rule guide

The FTC Health Breach Notification Rule explained with a source-backed CIPP/US study bridge.

Lesson · CIPP/US

CIPP/US 42 CFR Part 2 confidentiality guide

42 CFR Part 2 explained with a source-backed CIPP/US study bridge.

Lesson · CIPP/US

CIPP/US HIPAA online tracking technology guide

HIPAA online tracking technology issues explained with a source-backed CIPP/US study bridge.

Lesson · CIPP/US

Anti-Money-Laundering: The Bank Secrecy Act

The Bank Secrecy Act (1970) imposes recordkeeping and reporting on financial institutions, requiring reports of currency transactions over $10,000 to the…

Lesson · CIPP/US

The Disposal Rule

The Disposal Rule requires anyone using a consumer report for business to dispose of that information reasonably to prevent unauthorized access. It…

Lesson · CIPP/US

Dodd-Frank and the CFPB's Authority

Dodd-Frank (2010) created the CFPB within the Federal Reserve. The CFPB has rulemaking authority over the FCRA, GLBA and Fair Debt Collection Practices…

Lesson · CIPP/US

FACTA Amendments and Consumer Protections

FACTA (2003) amended the FCRA, preempting stricter state laws in most areas (states keep some identity-theft powers). It required truncation of card…

Lesson · CIPP/US

Adverse Action Notices

An adverse action is any negative business, credit or employment decision. When a user acts adversely based even in part on a consumer report, it must…

Lesson · CIPP/US

CRAs and Consumer Reports Defined

A consumer reporting agency (CRA) compiles or evaluates personal information to furnish consumer reports to third parties for a fee. The FCRA's…

Lesson · CIPP/US

CRA Core Requirements: Access, Accuracy, Obsolescence

CRAs must give consumers access and the right to dispute, take reasonable steps for maximum possible accuracy, and not report outdated negatives…

Lesson · CIPP/US

Consumer Reports for Employment

Employers using consumer reports must give a clear written stand-alone notice, get prior written authorization, certify compliance to the CRA (including…

Lesson · CIPP/US

FCRA Enforcement and Penalties

FCRA enforcement runs through dispute resolution, private litigation (including class actions), and government action by the FTC, CFPB and state attorneys…

Lesson · CIPP/US

Furnisher Duties and the Furnisher Rule

Furnishers must provide accurate data, correct and update it, give notice of disputes to CRAs, and respond to identity-theft information. The Furnisher…

Lesson · CIPP/US

Misconduct Investigations and Investigative Consumer Reports

Internal misconduct investigations are not consumer reports if the employer follows the act's procedures, uses no credit information, and gives a summary…

Lesson · CIPP/US

Medical Information and Prescreened Lists Under FCRA

FCRA limits use of medical information from CRAs, generally requiring consent or coding for insurance, employment or credit uses. Prescreened lists let…

Lesson · CIPP/US

Permissible Purpose and Certification

A user may obtain a consumer report only with a permissible purpose and must certify that purpose to the CRA, plus certify the report will not be used for…

Lesson · CIPP/US

FCRA Purpose, History and Preemption

Enacted in 1970, the FCRA was the first federal law to regulate private businesses' use of personal information. It mandates accurate, relevant data…

Lesson · CIPP/US

Risk-Based Pricing and Credit Score Disclosures

Under the Risk-Based Pricing Rule, lenders must notify consumers who receive less favorable terms because of their credit report. Anyone using credit…

Lesson · CIPP/US

Users and Furnishers Under the FCRA

Beyond CRAs, the FCRA binds users (lenders, insurers, employers who use reports) and furnishers (lenders, retailers who supply data to CRAs). Users need a…

Lesson · CIPP/US

Financial Privacy Landscape and Regulators

U.S. financial privacy is governed mainly by the FCRA (1970), GLBA (1999), and the Dodd-Frank Act (2010), which created the CFPB. Financial institutions…

Lesson · CIPP/US

Future of Financial Regulation and Cryptocurrency Privacy

Cryptocurrency privacy depends on whether governments take a high- or low-regulation approach. Under low regulation, privacy depends on market and…

Lesson · CIPP/US

GLBA Overview and Privacy Provisions

GLBA (Title V of the 1999 Financial Services Modernization Act) produced a Privacy Rule and a Safeguards Rule. Spurred by the U.S. Bancorp/MemberWorks…

Lesson · CIPP/US

The GLBA Privacy Rule

The Privacy Rule requires initial and annual privacy notices and processing of opt-outs within 30 days. Institutions may freely share with affiliates and…

Lesson · CIPP/US

The GLBA Safeguards Rule

The Safeguards Rule (effective 2003, updated by the FTC in 2021) requires a written information security program with administrative, technical and…

Lesson · CIPP/US

GLBA Scope, NPI and Enforcement

GLBA covers financial institutions significantly engaged in financial activities and regulates nonpublic personal information (NPI). Enforcement runs…

Lesson · CIPP/US

USA PATRIOT Act, KYC, FATCA and the AML Act of 2020

The International Money Laundering Abatement and Anti-Terrorist Financing Act (2001), part of the USA PATRIOT Act, expanded the BSA and added Know Your…

Lesson · CIPP/US

The Red Flags Rule

The Red Flags Rule requires financial institutions and creditors to maintain written identity-theft detection programs that spot and respond to red flags…

Lesson · CIPP/US

Regulation E and EFTA. CIPP/US transfer rules guide

Regulation E and the EFTA explained with coverage, consumer protections and CIPP/US study context.

Lesson · CIPP/US

Suspicious Activity Reports and BSA Enforcement

Institutions must file a Suspicious Activity Report (SAR) with FinCEN for insider crimes regardless of amount, crimes of $5,000+ with a suspect, crimes of…

Lesson · CIPP/US

State Financial Privacy: California (CFIPA) and New York (NYDFS)

Because GLBA does not preempt states, California's CFIPA (SB-1) adds opt-in consent for sharing with nonaffiliated third parties, and New York's NYDFS…

Lesson · CIPP/US

CIPP/US Bank Secrecy Act and merger privacy guide

Bank Secrecy Act and merger privacy issues explained with a CIPP/US study bridge.

Lesson · CIPP/US

CIPP/US GLBA annual privacy notice guide

GLBA annual privacy notices explained with a source-backed CIPP/US study bridge.

Guide

CIPP/E, CIPP/US or AIGP?

Compare CIPP/E, CIPP/US and AIGP. See what each certification covers, who it suits and where to begin independent study.

Guide · AIGP

AIGP Body of Knowledge 2026 explained

The four domains in the 2026 IAPP AIGP Body of Knowledge, translated into a practical study plan and exam-scenario checklist.

Guide · AIGP

AIGP exam format and blueprint

Current AIGP format, timing and how to use the published IAPP Body of Knowledge and Exam Blueprint.

Guide · AIGP

AIGP exam questions

How to approach AIGP questions using context, risk, governance controls and accountability.

Guide · AIGP

AIGP practice exam

Independent AIGP practice questions, a timed-study method and an evidence-led review routine.

Guide · AIGP

AIGP study guide

Free AIGP notes and study lessons arranged around four current knowledge areas, with retrieval practice and scenario review.

Guide · AIGP

AIGP study plan

A four-week AIGP study plan using the published outline, retrieval practice and scenario questions.

Practice · AIGP

Find the AIGP areas to study next.

Take a free 10-question AIGP diagnostic. Get an immediate domain score and a personalised study plan without creating an account.

Glossary · AIGP

AIGP glossary

AIGP glossary with key AI governance terms, linked lessons and a practical way to review exam vocabulary.

Guide · AIGP

How to pass the AIGP

How to prepare for the IAPP AIGP exam using current format details, a flexible study plan, common mistakes and exam-style practice.

Guide · AIGP

Is the AIGP exam hard?

Is the AIGP exam hard? Format, pass mark, the four domain weights, where candidates struggle and a practical way to prepare.

Practice · AIGP

Free AIGP mini mock

Try 25 exam-style AIGP practice questions free, with explanations and a domain score. No account or payment required.

Practice · AIGP

Instead of 'provider' and 'deployer', what term does South Korea's AI Basic Act use?

Instead of 'provider' and 'deployer', what term does South Korea's AI Basic Act use? Answer with a worked explanation and related free lesson.

Lesson · AIGP

The AI system development life cycle

Seven stages from plan/design to decommissioning, with governance hooks at each. The life cycle is iterative, not linear and building AI is never a…

Lesson · AIGP

The AI family tree

Each layer is a subset of the one above: GenAI ⊂ DL ⊂ ML ⊂ AI. Agentic AI is the odd one out - it can be comprised of all categories of AI, leveraging…

Lesson · AIGP

Architectures and the buzzwords that matter

Governance pros must hold a credible conversation about architectures: transformer models (process inputs in parallel), multimodal models/LMMs (WHO 2024…

Lesson · AIGP

Four building-block terms

Data, algorithm, model and system nest inside each other and the exam tests them exactly. An algorithm produces the model; the model applies algorithms to…

Lesson · AIGP

Expert systems

An older flavour of AI that mimics a human expert in one field via a knowledge base, inference engine and user interface. The canonical example is a…

Lesson · AIGP

Five algorithms to recognise on sight

Governance pros must recognise five algorithms to talk risk: linear regression, logistic regression (binary outcome), decision trees, random forests (an…

Lesson · AIGP

The four ways machines learn

Four ML approaches: supervised (labelled), unsupervised (unlabelled), semi-supervised (small labelled + large unlabelled) and reinforcement (agent learns…

Lesson · AIGP

The intelligence ladder: ANI to ASI

Four levels of AI capability, only ANI fully real today. Broad AI is the intermediate step; AGI and ASI do not currently exist. If a question describes a…

Lesson · AIGP

Model face-offs the exam loves

Four head-to-head comparisons straight from the performance indicator: classic vs generative, proprietary vs open source, small vs large LMs, and language…

Lesson · AIGP

OECD Framework for the Classification of AI Systems

A user-friendly framework that classifies AI systems and examines their risks across five dimensions (mnemonic PEDMT). Privacy sits under People and…

Lesson · AIGP

Tech megatrends and AI

Some megatrends fuel AI, some are fuelled by it, and some raise the governance stakes. AI drives the need for PETs; blockchain is not universally…

Lesson · AIGP

Use cases and benefits

The course groups AI uses into 7 buckets: Recognition, Event detection, Forecasting, Personalisation, Interaction support, Goal-driven optimisation and…

Lesson · AIGP

What is AI

There is no single definition of AI; the exam wants the common elements that recur across definitions. AI is not a specific technology, but a branch of…

Lesson · AIGP

Why AI needs a comprehensive governance approach

Seven unique characteristics (mnemonic A COD SHiP) make AI harder to govern than ordinary software. The central governance challenge is balancing…

Lesson · AIGP

Three AI harms taxonomies

AI-specific frameworks. The Sociotechnical Harms taxonomy has five themes; the CSET AI Harm Taxonomy defines AI harm with four elements, all four must be…

Lesson · AIGP

Environmental harms

Four quantified facts - the numbers are the exam bait. Training a large model can emit over 626,000 pounds of CO₂ (~five times the lifetime emissions of…

Lesson · AIGP

Creating ethical AI in practice

The operational checklist for deciding which use cases meet an organisation's ethical principles - spanning legal review, equitable design, transparency…

Lesson · AIGP

Seven ethical issues and three foundational controls

The Seven ethical issues responsible AI must address - lawfulness, safety, bias protection, transparency, choice, human intervention, security - and the…

Lesson · AIGP

Ethics by design

Ethics by design is the sibling of privacy by design: ethical issues are resolved at the start and reassessed during deployment because risks change. The…

Lesson · AIGP

The FIPs: where all of this started

AI ethics frameworks descend from the FIPs (Fair Information Practices), originated in 1980 by the OECD Guidelines on the Protection of Privacy and…

Lesson · AIGP

Who gets harmed: the five targets

The exam frames every harm question around who is affected. The Five harm targets are individuals, groups, society, organisations and ecosystems - and…

Lesson · AIGP

Group and societal harms

Group harm is discrimination against a population subgroup; societal harm is damage to the democratic process and participation. Examples include group…

Lesson · AIGP

Harms taxonomies 101

A Harms taxonomy is a list of negative consequences that could befall a data subject or organisation - an ontological map breaking harms into constituent…

Lesson · AIGP

Individual harms and the anatomy of bias

Individual harms hit civil liberties, safety or economic opportunity, and bias is the engine. Know Implicit bias, Sampling bias and Temporal bias on…

Lesson · AIGP

AI impacts and responsible AI

Before deploying AI, governance professionals must grasp the harms it can cause. AI poses risks already understood in existing sectors, but the scale…

Lesson · AIGP

The five OECD AI Principles

The OECD AI Principles are the base layer many organisations copy into their governance frameworks. Know all five (mnemonic: Inclusive Humans Trust Robust…

Lesson · AIGP

Organisational harms

Five harm types every organisation deploying AI must price in: reputational, cultural, economic, Acceleration risk and legal. Acceleration risk is the odd…

Lesson · AIGP

Three privacy harms taxonomies

Match the name to the structure. MITRE PANOPTIC combines contextual domains and privacy activities; the Ryan Calo taxonomy splits harm into subjective vs…

Lesson · AIGP

Trustworthy AI: the HAT test

The HAT test characterises trustworthy AI as Human-centric, Accountable, Transparent, operating in an expected, legal and fair manner. Explainability and…

Lesson · AIGP

AI impact assessments and ISO 42005

The AI impact assessment (AIIA) is the severity lens: it gauges how bad mapped risks are, while a risk assessment flags which systems need extra…

Lesson · AIGP

Aligning risk strategies

New AI risk processes must slot into existing risk machinery. Determine whether AI increases existing risks or introduces new ones, decide who is…

Lesson · AIGP

Business, regulatory and legal risks

Six direct business risks: bias & discrimination, job displacement, vendor dependence, liability & accountability, lack of transparency, IP infringement…

Lesson · AIGP

Calculating risk

The working Risk formula is probability × severity. High: avoid or change; medium: explore and mitigate. Plus the four technical assessment categories and…

Lesson · AIGP

Culture and operationalising responsible AI

Six culture moves (customer value, cultural variation, responsible AI as a discipline, HR engagement, common taxonomy, knowledge resources), then the…

Lesson · AIGP

The four AI risk categories

Operational, legal, security, privacy. The Security risk card carries the most testable vocabulary: Adversarial attacks, Hallucinations, Deepfakes and…

Lesson · AIGP

The four roles: developers, providers, deployers, users

Governance responsibilities shift across the AI life cycle. Know each role's signature duties: and the terminology trap that the Colorado AI Act says…

Lesson · AIGP

Governance structure: build it, then pick a model

Five build principles (leverage existing structures, foster community, clear roles, incentivise responsible AI, evolve the programme), then the three…

Lesson · AIGP

ISO 42001 and HUDERIA

Two frameworks with different DNA: ISO/IEC 42001:2023 is an AI management system standard for any size and industry, while HUDERIA is the Council of…

Lesson · AIGP

Life cycle policies and the use case assessment

Policies must create oversight across nine areas of the AI life cycle. The Use case assessment is the front door, running NIST's Map (NIST), Measure…

Lesson · AIGP

NIST AI RMF: the full kit

The NIST AI RMF has four pieces (framework, Core, Playbook, GenAI Profile) plus NIST ARIA. Keep the two quartets separate: the NIST Core functions are…

Lesson · AIGP

Risk assessment mechanics

Greatest resources go to the highest-risk areas. The 3×3 harms matrix multiplies severity × probability for a score, tolerances vary by organisation, and…

Lesson · AIGP

Stakeholders: who sits at the table

Cross-functional collaboration is a tested performance indicator. Privacy, security, accessibility and digital safety personnel are crucial first…

Lesson · AIGP

Tailoring governance: six differentiators

There is no universal AI governance design. Six organisational factors drive the differences: company size, maturity, industry/sector, products &…

Lesson · AIGP

Training, awareness and AI literacy

Training targets the organisation's own AI use and governance, not general AI expertise, across three focus areas. AI literacy is a legal obligation under…

Lesson · AIGP

What AI governance actually is

AI governance is an organisation's approach to using laws, policies, frameworks, practices and processes at international, national and organisational…

Lesson · AIGP

Winning leadership support

Gain leadership support at the earliest opportunity. The course gives a five-step path: understand context, find champions, frame responsible AI as a…

Lesson · AIGP

China, Japan and the rest of the world

China runs a multi-layered, use-case-specific network overseen by the CAC, requiring security reviews and algorithm registration. Japan takes…

Lesson · AIGP

Conformity assessments, registration and notification

The Conformity assessment (CA) is how compliance is demonstrated for high-risk AI, underpinned by technical documentation. CAs borrow from DPIAs and…

Lesson · AIGP

Deployers, importers and distributors

Deployer obligations are fewer than a provider's but broader, centred on transparency and monitoring (EU six-month minimum log retention; FRIA in the EU…

Lesson · AIGP

The eight requirements for high-risk AI

Major AI laws converge on eight obligations for high-risk AI: risk management, data governance, technical documentation, record-keeping, transparency…

Lesson · AIGP

Enforcement and penalties

Enforcement runs through central authorities (EU AI Office, SK Ministry of Science & ICT, China's CAC), sectoral regulators and advisory bodies, using…

Lesson · AIGP

The EU AI Act and the Digital Omnibus

The EU AI Act is a risk-based regulation with extraterritorial reach. The AI Omnibus entered into force on 27 July 2026. Most of the Act applied from 2…

Lesson · AIGP

The four regulated roles

Regulation distributes duties across the supply chain: a Provider builds the system, an Importer brings it in, a Distributor passes it on, and a Deployer…

Lesson · AIGP

General-purpose AI models

General-Purpose AI (GPAI) models are trained for broad tasks and adapt into many downstream systems. EU AI Act Chapter V sets two tiers: baseline duties…

Lesson · AIGP

High risk - where most regulation lives

High risk / high-impact AI significantly affects rights, safety or access to essential services. It is allowed but under strict obligations, and the…

Lesson · AIGP

AI regulation across jurisdictions

Global AI laws share a common regulatory DNA of risk-based classification, role-based responsibilities and transparency requirements; what differs is how…

Lesson · AIGP

Limited risk and minimal risk

Limited / transparency risk means disclosure or labelling duties only - inform users they are interacting with AI, label or watermark generated content…

Lesson · AIGP

Prohibited risk and the banned list

Prohibited risk AI is inherently harmful and restricted or banned in many jurisdictions. Six categories recur, including social scoring, manipulation…

Lesson · AIGP

High-risk provider obligations

Providers carry the heaviest load because they build the system and put it on the market, so duties span the whole life cycle. Eight converging global…

Lesson · AIGP

The risk classification framework

Risk-based legislation classifies AI into four tiers - Prohibited, High, Limited, Minimal (mnemonic 'Please Handle Laws Mindfully') - and scales the…

Lesson · AIGP

South Korea's AI Basic Act

The AI Basic Act is the second comprehensive national AI law, effective January 2026. It applies duties uniformly to Business operators (Development and…

Lesson · AIGP

The United States - orders, guidance and state laws

There is no single federal AI statute. Instead: executive orders (EO 14179 replaced the rescinded EO 14110, then America's AI Action Plan), federal…

Lesson · AIGP

Anonymisation, Pseudonymisation and PETs

Recital 26 territory: anonymisation removes data from the GDPR entirely, while pseudonymisation is still personal information so GDPR obligations apply…

Lesson · AIGP

Article 22 and Automated Decision-Making

Article 22 is a general prohibition with three exceptions, never an outright ban: automated decision-making is allowed only when necessary for a Contract…

Lesson · AIGP

Consumer Protection Laws and AI

The FTC's broad authority over "unfair or deceptive" practices already covers algorithms, and the agency will keep applying it to AI. Several US laws…

Lesson · AIGP

Obligations on Data Controllers

Controllers decide what and how personal data is processed - whether a human or an AI does the processing, the GDPR still applies. Nine duty areas span…

Lesson · AIGP

The EDPB Opinion on AI Models (2024)

Prompted by the Irish DPA, the European Data Protection Board harmonised how the GDPR treats AI models in three answers: when a model is anonymous, when…

Lesson · AIGP

The GDPR and AI

In effect since 2018, the GDPR is the global baseline for data protection, deliberately technology-agnostic so it can evolve alongside AI. Three…

Lesson · AIGP

Intellectual Property and AI

IP is creations of the human mind protected by patents, copyright and trademarks - and generative AI stretches every part of that definition. Key anchors…

Lesson · AIGP

The Lay of the Land

AI may dodge a dedicated statute, but it lives in the same legal context as every other technology: ALL existing laws for a sector or jurisdiction still…

Lesson · AIGP

Licensing AI Models and Data

The contract is where IP risk gets managed. Traditional IP indemnities break down for AI because they exclude modifications, combinations and out-of-scope…

Lesson · AIGP

Nondiscrimination Laws Across Five Sectors

Sector nondiscrimination laws still apply to AI across healthcare, insurance, hiring, credit and housing. Key anchors: Section 1557 (healthcare), NYC…

Lesson · AIGP

Privacy Principles That Govern AI

GDPR, CCPA/CPRA, US state privacy laws, biometrics laws like Illinois BIPA and breach laws all reach consumer-facing AI. Seven principles do the heavy…

Lesson · AIGP

Product Liability Foundations

Who answers when AI causes harm? Two regimes: fault liability (prove an action/inaction caused harm) and strict liability (no-fault - prove only defect…

Lesson · AIGP

The Revised Product Liability Directive

Directive 2024/2853, effective December 2026, makes it easier for victims of AI-caused harm to prove liability and get compensated. It expands "products"…

Lesson · AIGP

Sensitive and Special Categories of Data

Special categories of data need extra protection under the GDPR and Brazil's LGPD - eight types captured by the mnemonic "Really Private Records Take…

Lesson · AIGP

Building, Training and the Three Lines of Defence

Development is iterative - train, test, fine-tune, then prove the model generalises on new data beyond the training set. Human oversight uses the 3LOD…

Lesson · AIGP

Data Formats and the Five V's

Know the three structure types (structured, unstructured, semi-structured), the static/streaming split, and the five V's of data preparation: Volume…

Lesson · AIGP

Governing the AI Data Life Cycle

Data governance spans ingestion to decommissioning with cross-functional stewardship. The data life cycle runs Collection: Use: Disclosure: Retention…

Lesson · AIGP

Data Questions, Quality, Jurisdiction and Lineage

Without the right, enough and accurate data the system won't perform - garbage in, garbage out. Anticipate jurisdiction (data localisation laws, KYC), and…

Lesson · AIGP

Documentation, Communication and Decommissioning

Document every decision with model cards, counterfactual explanations and remediation owners; communicate by audience; and retire systems via ten…

Lesson · AIGP

Features and Feature Engineering

A feature is a specific measurable aspect or characteristic. Feature engineering decides which ones matter, with three purposes - improve performance (the…

Lesson · AIGP

Impact Assessments in the Design Phase

An impact assessment is a risk management tool assessing an AI system's benefits, risks and limitations across the life cycle. The AIA covers data issues…

Lesson · AIGP

The AI Development Life Cycle Revisited

AI development mirrors the software life cycle plus a data obsession and continuous monitoring. Policies, procedures, best practices and ethics apply at…

Lesson · AIGP

Metrics, Thresholds, Audits and Monitoring

Establish measures (e.g. the Adverse Impact Ratio), set thresholds, baseline, then monitor over time. Audits assess performance, reliability and safety…

Lesson · AIGP

Operational Controls - Five Owners to Name

Controls are only real when someone owns them. The memorable owner is the kill switch - a named person with authority to shut the system down when an AI…

Lesson · AIGP

Planning Essentials - The Five Moves

Define objectives, pick use cases, scope, check the data, stand up governance - in that order. Scope is prioritised via Impact, Effort and Fit, and…

Lesson · AIGP

The Six Risk Assessment Strategies, In Order

A repeatable sequence - Use Smart Methods, Handle Big Projects - to identify, evaluate, treat and mitigate risk: use case evaluation, stakeholder mapping…

Lesson · AIGP

Stakeholders - Who, What, and the Hard Calls

Engage stakeholders early, agree the goal, and decide who owns the failures. When values clash - e.g. more accuracy than privacy - the organisation must…

Lesson · AIGP

Testing and Validation

Testing is continuous, risk-tailored and documented - test for accuracy, robustness, reliability, privacy, interpretability, safety, security and bias…

Lesson · AIGP

Wrangling the Data

Five considerations turn raw data into model-ready data without trampling privacy: cleansing, labelling, anonymisation and minimisation. Master the two…

Lesson · AIGP

Adapting existing policies for AI

Review the current policy framework for gaps first, then tailor what exists and add what's missing across five areas - data privacy, security…

Lesson · AIGP

Agentic AI - what it is

Agentic systems engage, interact and influence rather than sit passively. AI agents focus on specific tasks with simple workflows; Agentic AI involves…

Lesson · AIGP

The agentic risk landscape

Autonomy brings four new risk families: goal misalignment (right goal, wrong way), compounded systemic impact (errors spread across departments and…

Lesson · AIGP

Where the model lives - three environments

The deployment environment depends on budget, IT expertise, model purpose and data type. Cloud scales, on-prem controls, edge localises - each buys one…

Lesson · AIGP

GenAI choices and the pre-launch checklist

Generative deployments add their own questions - fine-tuning, retrieval-augmented generation, vector/graph databases and agentic architectures…

Lesson · AIGP

Incidents, consequences and accountability

Treat every occurrence as an incident, keep records in an AI registrar, and know the five usual causes - brittleness, lack of robustness, lack of quality…

Lesson · AIGP

Governing AI deployment

Whatever was built, bought or customised, every organisation deploys AI as the final step before use. Deployment is the transition from a development and…

Lesson · AIGP

Monitoring, maintenance and drift

Watch for deviations in accuracy and model drift - when the relationship between input data and output predictions changes over time. Model cards document…

Lesson · AIGP

Periodic assessment - performance, reliability, safety

Three assessment lanes keep an ageing model in check: performance, reliability and safety. Four definitions recur: red teaming (simulated adversarial…

Lesson · AIGP

Deploying a proprietary model

Developing AND deploying your own model creates a dual role with heightened liability from both providing and using the technology. It brings five…

Lesson · AIGP

Public disclosures and transparency obligations

One notice never fits all, but one rule is near-universal: almost all AI laws worldwide require disclosure that AI is in place, treated by the FTC as a…

Lesson · AIGP

Release readiness

A readiness assessment decides whether the system goes to production. Well-Tested Code Deserves Model-cards - Works as intended, Testing turned out well…

Lesson · AIGP

Third-party products and risk

Less visibility never means less responsibility. Third-party AI splits into two contexts - integrated into business operations (needs the more…

Lesson · AIGP

The three-tier guardrail framework

Guardrails scale with use-case risk: Foundation: Risk: Society. Tier 1 foundational guardrails apply to every system and follow ISO/IEC 42001 and the NIST…

Lesson · AIGP

The vendor / open-source agreement checklist

Eight areas to evaluate before signing a vendor or open-source agreement: data considerations, security/safety, bias metrics, product type, technical…

Lesson · AIGP

Core AI concepts

The foundation layer of the AIGP vocabulary: what AI is, what it runs on, and its classic forms. Artificial intelligence is defined as machine-based…

Lesson · AIGP

Data terms

Everything the model eats, before and after cooking. Know which dataset does which job: training data teaches, validation data tunes and checks…

Lesson · AIGP

Generative AI

The GenAI stack from foundation model to prompt - architecture names matter here. RAG is defined by retrieving from a knowledge base beyond the training…

Lesson · AIGP

Governance, assurance and oversight

The accountability vocabulary - who answers, who checks, who can challenge. Conformity assessment is the EU AI Act gate for high-risk systems before…

Lesson · AIGP

Learning techniques and methods

The named techniques and model types that show up as one-line scenario answers - including federated learning (data never leaves the site), transfer…

Lesson · AIGP

Machine learning families

The four learning paradigms plus the architecture they run on. Label availability is the sorting key: supervised uses labelled pairs, unsupervised finds…

Lesson · AIGP

Model mechanics and performance

What is inside the model and how its behaviour is measured and goes wrong. Variables live in the data; parameters and weights live in the model - and…

Lesson · AIGP

Risks, security and harms

The attack surface and the falsehood family. Intent is the dividing line: disinformation is deliberate, misinformation is not - and data poisoning is an…

Lesson · AIGP

Trust attributes and safeguards

The qualities systems must show and the artifacts and controls that prove or protect them. Reliability is consistency over time; robustness is resilience…

Looking for AI governance? Explore the AIGP study guide.