State attorneys general are a distinct pillar of US privacy enforcement alongside federal agencies. Which statement best describes the authority a state attorney general typically relies on to bring privacy and data-security enforcement actions?
- AA state attorney general may enforce only federal privacy statutes that expressly name the office, and has no independent authority under that state's own consumer-protection law.
- BA state attorney general may use the state's own unfair-or-deceptive-practices statute, and is frequently authorised by specific federal and state privacy laws, to act on behalf of state residents. Correct
- CA state attorney general can act only after the FTC has first opened a federal case on the same conduct, since state enforcement is purely supplementary to federal action.
- DA state attorney general enforces privacy law only by prosecuting individuals criminally, with no civil authority to seek injunctions or restitution for consumers.
Why A is wrong: Tempting because some federal statutes do authorise state attorney general suits, but the office also wields independent state consumer-protection authority, so limiting it to expressly named federal statutes understates its powers.
Why B is correct: Correct: most states have a little-FTC act prohibiting unfair or deceptive practices, and many federal and state privacy laws also empower the attorney general to sue on residents' behalf, so the office draws on both state and statute-specific authority.
Why C is wrong: Tempting because state and federal enforcers often coordinate, but a state attorney general can initiate independent actions without waiting on the FTC, so the claim of a mandatory federal predicate is wrong.
Why D is wrong: Tempting because attorneys general do handle criminal matters, but privacy and data-security enforcement is largely civil, seeking injunctions, restitution, and penalties, so restricting the office to criminal prosecution misstates its role.