CIPP/US Glossary
57 terms defined · Last reviewed: · By Victor Humenhuk (CIPP/US certified)
This glossary defines the terms that carry weight on the CIPP/US exam and in day-to-day U.S. privacy practice: the federal sectoral statutes, the state comprehensive laws, the defined terms inside those laws that decide whether an obligation applies, and the technical vocabulary the exam assumes you already have. Each entry says what the term means, which law or framework it comes from, and where the line falls against the terms it is most often confused with.
The definitions are not scraped from other sites. They come from the CIPP/US study notes behind this site, written by Victor Humenhuk, who holds the CIPP/E, CIPP/US and AIGP certifications, and they use the same wording as the chapter topics you will study elsewhere on the site. Where a term is defined differently by different statutes, the entry says so rather than picking one definition and hiding the conflict, because that difference is usually the point being tested.
Use it two ways. Early in your preparation, read the entry and then follow the link to the chapter topic it comes from, so the term sits inside its statutory context instead of floating free. Closer to the exam, work in reverse: cover the definition, state it from memory, and check yourself. If you can define a term but cannot say which law it comes from, who enforces it, and what changes when it applies, you do not know it well enough yet.
A
- Adverse action - Any business, credit or employment action with a negative impact on a consumer, such as denying or cancelling credit/ins…
- Automated decision-making - Fully automated processing, including profiling, that has a legal or similarly significant effect, generally prohibited …
B
- BIPA - Illinois Biometric Information Privacy Act; requires employers to notify employees of biometric practices and obtain inf…
- Business associate - Any person or organization, other than a covered entity's workforce member, that performs services for or on behalf of a…
C
- California Age-Appropriate Design Code Act - A 2022 California law - the first U.S. age-appropriate design law - requiring online platforms to consider the best inte…
- CAN-SPAM Act - The Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003, governing commercial email directed …
- CCPA - California Consumer Privacy Act; its private right of action created statutory damages for breaches caused by failure to…
- Consent decree - A judgment entered by consent of the parties in which the defendant agrees to stop alleged illegal activity, usually wit…
- Consumer report - Any communication by a CRA bearing on a person's creditworthiness, character, reputation or mode of living, used in whol…
- Consumer reporting agency (CRA) - Any person or entity that compiles or evaluates personal information to furnish consumer reports to third parties for a …
- COPPA - The Children's Online Privacy Protection Act, applying to operators of sites or services directed to children under 13, …
- Covered entity - Under HIPAA, an organization such as a health plan, clearinghouse, or provider conducting standard transactions, which i…
- CPNI - Customer proprietary network information - subscription and service data, network and billing information, phone feature…
- CPPA - The California Privacy Protection Agency, a dedicated privacy regulator created by the CPRA, seen as analogous to an EU …
- CPRA - The California Privacy Rights Act, a ballot initiative that passed in late 2020, amended and extended the CCPA, and beca…
- Cross-context behavioral advertising - Advertising targeted to a consumer based on personal information collected over time across different online contexts.
D
- Dark patterns - Sophisticated design practices that trick or manipulate consumers into buying or giving up personal information, examine…
- Data breach notification law - A state law requiring entities to disclose to affected individuals (and often regulators) when personal information is a…
- Data minimization - The principle that data should be kept only as long as necessary to fulfill its purpose; secure destruction also reduces…
- Deidentified data - Data that cannot reasonably be associated or linked with a particular individual; excluded by all five states.
- Directory information - Information FERPA treats as not generally harmful if disclosed, such as name, address, email, phone, field of study, and…
- Disposal Rule - FACTA rule requiring any entity using a consumer report for a business purpose to dispose of the information in a way th…
- DPPA - The Driver's Privacy Protection Act of 1994, barring state DMVs from releasing drivers' personal information without per…
E
- ECPA - Electronic Communications Privacy Act; with the Wiretap Act, restricts interception of communications such as emails and…
- EPPA - Employee Polygraph Protection Act of 1988; prohibits most private employers from using lie detectors on employees or app…
F
- FACTA - Fair and Accurate Credit Transactions Act of 2003; amended the FCRA and preempted many state laws, but left employment c…
- Fair Information Practices (FIPs) - The foundational privacy principles, originating with the U.S. government in the 1970s, on which the first wave of moder…
- FCRA - Fair Credit Reporting Act of 1970, the first federal law to regulate private businesses' use of personal information, go…
- FERPA - The Family Educational Rights and Privacy Act of 1974, a federal statute giving students control over disclosure and acc…
- FTC - The Federal Trade Commission, with general authority over unfair and deceptive trade practices, able to bring deception …
G
- GINA - The Genetic Information Nondiscrimination Act of 2008, limiting use of genetic information in health insurance and emplo…
- GLBA - Gramm-Leach-Bliley Act of 1999, supplying the general framework for confidentiality of records in the financial services…
- GLBA Safeguards Rule - The Gramm-Leach-Bliley Act rule requiring financial institutions to maintain an information security program, conduct ri…
H
- HIPAA - Health Insurance Portability and Accountability Act of 1996; its privacy and security rules regulate protected health in…
- HITECH - The Health Information Technology for Economic and Clinical Health Act; the FTC shares breach-notification authority wit…
I
- Investigative consumer report - A report on a consumer's character, reputation, personal characteristics or mode of living obtained through personal int…
O
- Opt-in - An affirmative indication of choice through an express act; failure to answer means the information is NOT used or share…
- Opt-out - Choice implied by a person's failure to object; failure to answer means the information IS used or shared.
P
- Permissible purpose - An FCRA requirement that a consumer report be obtained only for an allowed reason; 'employment purposes' include preempl…
- Personal information - Any data that can be associated or linked with a particular individual; California also covers household and employment …
- PHI - Protected health information: individually identifiable health information held by a covered entity or business associat…
- Preemption - When federal law overrides state law; HIPAA sets a federal floor and does NOT preempt stricter state protections.
- Privacy Act of 1974 - Federal law applying to federal agencies and their private-sector contractors, interpreted by the OMB.
- Privacy notice - A required disclosure of data practices (categories, purposes, sales/opt-out, third-party sharing, how to exercise right…
- Privacy Rule - The HIPAA rule (finalized December 2000, revised 2002 and 2013) governing the use and disclosure of PHI by covered entit…
- Privacy torts - Common-law claims: intrusion upon seclusion, appropriation of name or likeness, publicity given to private life, and fal…
- Private right of action - A statutory right allowing harmed individuals to sue directly; granted by nearly 15 states' breach laws, with recovery o…
- Pseudonymization - Distinguishing individuals in a dataset using a unique identifier that does not reveal their real-world identity (UK ICO…
R
- Red Flags Rule - FACTA rule requiring financial institutions and creditors to develop written programs to detect, prevent and mitigate id…
S
- Section 5 of the FTC Act - The provision letting the FTC pursue unfair and deceptive trade practices; the primary federal statute for medtech compa…
- Security Rule - The HIPAA rule (finalized 2003, modified 2013) setting minimum security requirements for ePHI.
- Sensitive personal information - An important subset of personal information (e.g., SSNs, financial info, driver's license numbers, health information) r…
- Statutory damages - A set amount fixed by statute (in California, $100 to $750 per incident) that consumers can recover without proving actu…
T
- TCPA - The Telephone Consumer Protection Act of 1991, enforced by the FCC, restricting unsolicited advertising by telephone, fa…
- TSR - The Telemarketing Sales Rule, first issued by the FTC in 1995 to implement the Telemarketing and Consumer Fraud and Abus…
V
- VPPA - The Video Privacy Protection Act of 1988, restricting disclosure of consumers' video viewing/rental records by videotape…
W
- Wiretap Act - Federal statute prohibiting interception of wire, oral, and electronic communications unless an exception applies; provi…
Keep going
The full CIPP/US study guide · Free practice questions · All study notes
Commonly confused pairs
Side-by-side breakdowns of the distinctions this exam tests most often.