Federal and State Regulators and Enforcement of Privacy Law Flashcards
Governance of the FTC
Independent agency governed by 1 chairperson and 4 commissioners; not under US president’s control
Who is responsible for enforcement of HIPAA?
Office of Civil Rights in Dept of Health and Human Services
Who is responsible for enforcement of the Gramm-Leach-Bliley Act (GLBA)?
Federal Reserve and Office of Comptroller of the Currency
Who is responsible for enforcement of financial consumer protection issues generally?
CFPB
Who is responsible for enforcement of Telephone Consumer Protection Act and other telemarketing and marketing privacy statutes?
FCC Commission, together with FTC
Who is responsible for enforcement of the Americans with Disabilities Act and other workplace antidiscrimination statutes?
EEOC
Who is responsible for enforcement of the Fair Credit Reporting Act?
FTC
Who is responsible for enforcing the Children’s Online Privacy Protection Act (COPPA)?
FTC
Who is responsible for enforcing the Controlling the Assualt of Non-Solicited Pornography and Marketing (CAN-SPAM) Act of 2003?
FTC
Source of FTC’s power re: “unfair and deceptive acts or practices in or affecting commerce”
Section 5 of FTC Act
Section 5 of FTC Act –> limitations on FTC’s power
Does not extend to non-profits (because not “in commerce”)
Does not extend to banks or other federally regulated financial institutitons
Does not extend to comon carriers like transportation and communications industries
Who is responsible for enforcement of Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009?
FTC and HHS share rulemaking and enforcement power re: data breaches
FTC’s “notice and choice” approach
- FTC method of enforcement in late 1990s
- Companies encouraged to provide privacy notices on their websites and to offer choice to consumers about whether info would be shared with third parties
- Enforcement action for violation
Unfair and Deceptive Acts and Practices (UDAP) Statutes
- Each state has one of these
- Similar to Section 5 of FTC Act
- Some statutes also allow enforcement against “unconscionable” practices (range of harsh seller practices)
- Enforced by state attorneys general
OECD Recommendation on Cross-Border-Cooperation in the Enforcement of Laws Protecting Privacy (2007)
Calls on member countries to
- Discuss practical aspects of privacy law enforcement cooperation
- Share best practices in addressing cross-border challenges
- Work to develop shared enforcement priorities
- Support joint enforcement initiatives and awareness campaigns