Co-Regulatory, Self-Regulatory, and Technology Models
Last reviewed:
Co-regulation (e.g., Australia; U.S. COPPA codes approved by the FTC) pairs industry codes with government law. Self-regulation (e.g., PCI DSS, seal programs) needs no general law. A technology model (e.g., encryption) reduces reliance on administrative measures.
Co-regulation (e.g., Australia, closer to comprehensive) emphasizes industry-developed enforceable codes against the backdrop of government law. A U.S. example is COPPA, where FTC-approved codes can satisfy the statute.
Self-regulation (e.g., the U.S.) creates codes of practice with no generally applicable data protection law behind them. A prominent example is PCI DSS for credit card data, and seal programs are another form.
| Model | Relation to government law | Example |
|---|---|---|
| Co-regulatory | Industry codes backed by government legal requirements | COPPA codes approved by the FTC; Australia |
| Self-regulatory | Codes may exist with no general data protection law | PCI DSS; seal programs |
Critics worry about adequacy and enforcement: industry codes may under-protect consumers, and penalties or enforcement authority can be weak. A technology-based model (e.g., provider encryption) can reduce reliance on administrative measures.
Key terms - quick answers
What is “Co-regulatory model”?
What is “Self-regulatory model”?
What is “PCI DSS”?
What is “Seal programs”?
Keep going - free
Every study note on this site is free. So are these: