CIPP-US - Introduction to the U.S. Privacy Environment - Section 1.2

Describe the roles of the Federal Trade Commission, sector-specific regulators, and state attorneys general in enforcing privacy and security laws.

Describe how the FTC uses Section 5 of the FTC Act to challenge unfair or deceptive data practices and how sector-specific regulators such as the FCC, OCR, and CFPB hold concurrent jurisdiction in their domains. Recognise that state attorneys general can bring independent enforcement actions under both state consumer-protection statutes and sector-specific federal laws.

FTC Act Section 5Unfair or deceptive actsState AG authorityRegulatory enforcement

Practice question for this objective

Free sampleIntroduction to the U.S. Privacy Environmentmedium

State attorneys general are a distinct pillar of US privacy enforcement alongside federal agencies. Which statement best describes the authority a state attorney general typically relies on to bring privacy and data-security enforcement actions?

  • AA state attorney general may enforce only federal privacy statutes that expressly name the office, and has no independent authority under that state's own consumer-protection law.
  • BA state attorney general may use the state's own unfair-or-deceptive-practices statute, and is frequently authorised by specific federal and state privacy laws, to act on behalf of state residents. Correct
  • CA state attorney general can act only after the FTC has first opened a federal case on the same conduct, since state enforcement is purely supplementary to federal action.
  • DA state attorney general enforces privacy law only by prosecuting individuals criminally, with no civil authority to seek injunctions or restitution for consumers.
Recognise that state attorneys general enforce privacy using state unfair-or-deceptive-practices statutes plus authority granted by specific privacy laws. Nearly every state has a consumer-protection statute prohibiting unfair or deceptive acts, and many federal and state privacy laws separately authorise the attorney general to sue on behalf of residents, so the office combines its own state authority with statute-specific grants to pursue civil privacy enforcement.

Why A is wrong: Tempting because some federal statutes do authorise state attorney general suits, but the office also wields independent state consumer-protection authority, so limiting it to expressly named federal statutes understates its powers.

Why B is correct: Correct: most states have a little-FTC act prohibiting unfair or deceptive practices, and many federal and state privacy laws also empower the attorney general to sue on residents' behalf, so the office draws on both state and statute-specific authority.

Why C is wrong: Tempting because state and federal enforcers often coordinate, but a state attorney general can initiate independent actions without waiting on the FTC, so the claim of a mandatory federal predicate is wrong.

Why D is wrong: Tempting because attorneys general do handle criminal matters, but privacy and data-security enforcement is largely civil, seeking injunctions, restitution, and penalties, so restricting the office to criminal prosecution misstates its role.

See more CIPP-US practice questions, answers explained.

More in this domain

Back to all Introduction to the U.S. Privacy Environment objectives, or the CIPP-US cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.