2.3 Applicable Regulations, Oversight Agencies & Non-Compliance Impact
Key Takeaways
- Privacy regulations fall into three categories: territorial/omnibus (GDPR, CCPA/CPRA), sectoral (HIPAA, GLBA, COPPA), and voluntary codes/self-certification (CBPR, DPF, ISO 27701)
- GDPR's maximum fine is €20 million or 4% of global annual revenue, whichever is higher — the most severe administrative penalty in privacy law
- Oversight authority is fragmented: EU DPAs enforce GDPR, HHS OCR enforces HIPAA, the FTC enforces COPPA and GLBA, and US state AGs enforce both state privacy laws and federal sectoral laws
- FTC consent decrees can bind an organization to 20 years of biennial third-party assessments — a lasting operational burden far beyond a one-time fine
- Non-compliance can create individual liability: executives may face personal fines or criminal charges for knowing wrongful disclosure or securities misrepresentation
Territorial, Sectoral, and Industry Regulations
Privacy regulations fall into three broad categories that a privacy manager must navigate simultaneously:
- Territorial (omnibus) laws apply to all processing of personal data within a jurisdiction regardless of sector. Examples: GDPR (EU/EEA), CCPA/CPRA (California), PIPEDA (Canada), LGPD (Brazil), PIPL (China).
- Sectoral laws apply to specific industries or data types. Examples: HIPAA (US health), GLBA (US financial services), FERPA (US education), COPPA (US children under 13 online).
- Codes of practice and self-certification mechanisms are voluntary frameworks that organizations adopt to demonstrate compliance. Examples: APEC Cross-Border Privacy Rules (CBPR), EU-US Data Privacy Framework (DPF), ISO/IEC 27701, Binding Corporate Rules (BCRs).
An organization may be subject to all three categories simultaneously. A US health insurer offering services in California and the EU must comply with HIPAA (sectoral), CCPA/CPRA (territorial — to the extent it does not conflict with HIPAA), and GDPR (territorial, extraterritorial reach).
Major Privacy Laws at a Glance
| Law | Scope | Oversight Body | Penalty Type |
|---|---|---|---|
| GDPR (EU, 2018) | All processing of EU/EEA residents' personal data; extraterritorial reach to non-EU organizations targeting EU data subjects | Supervisory Authorities (national DPAs), European Data Protection Board (EDPB) | Administrative fines up to €20M or 4% of global annual revenue, whichever is higher |
| CCPA/CPRA (California, 2020/2023) | Personal information of California residents collected by covered businesses | California Privacy Protection Agency (CPPA), California Attorney General | Administrative/civil penalties; up to ~$2,500 per unintentional violation and ~$7,500 per intentional violation or violations involving minors (CPI-adjusted); private right of action for data breaches (statutory damages $100–$750 per consumer per incident) |
| HIPAA (US, 1996) | Protected Health Information (PHI) held by covered entities and business associates | HHS Office for Civil Rights (OCR), state AGs | Tiered civil penalties based on culpability (up to ~$2M+ per violation category per year for willful neglect not corrected) and criminal penalties for knowing wrongful disclosure |
| GLBA (US, 1999) | Customer financial information held by financial institutions | FTC, federal banking regulators (OCC, FDIC, Fed), state AGs | Civil penalties and enforcement actions; FTC can seek monetary penalties and injunctive relief |
| COPPA (US, 1998) | Personal information collected online from children under 13 | FTC | Civil penalties (CPI-adjusted, per violation) and enforcement actions; consent decrees |
Understanding Oversight Agencies
Data Protection Authorities (DPAs)
Under GDPR, each EU/EEA member state has a supervisory authority (DPA) — for example, the CNIL (France), the ICO (UK), the BfDI (Germany). DPAs have investigative, corrective, and advisory powers. They can issue warnings, reprimands, orders to comply, and fines. The EDPB coordinates cross-border cases under the one-stop-shop mechanism, where the lead supervisory authority (where the organization's main establishment is located) acts as primary contact.
State Attorneys General (US)
In the US, state AGs enforce both state privacy laws (CCPA/CPRA, and comprehensive state laws in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others) and federal sectoral laws. The HITECH Act granted state AGs enforcement authority for HIPAA violations. State AGs can bring civil actions and seek penalties and injunctive relief.
Sector Regulators
- HHS OCR: Enforces HIPAA Privacy, Security, and Breach Notification Rules. Conducts compliance audits and investigates complaints filed by individuals.
- FTC: Enforces COPPA, GLBA, and Section 5 of the FTC Act (prohibiting unfair or deceptive acts or practices). The FTC uses consent decrees — settlements that impose long-term compliance obligations, typically 20 years of biennial assessments by an independent third party.
- SEC: Has increasingly enforced privacy through disclosure requirements and charges related to cybersecurity incident reporting under Reg S-K Item 106.
- Federal banking regulators (OCC, FDIC, Federal Reserve): Enforce GLBA privacy provisions for banks and financial institutions under their supervision.
Impact of Non-Compliance
Non-compliance can affect the organization, individuals, and — in some regimes — individual officers.
Organizational Impact
- Regulatory fines: GDPR fines can reach €20M or 4% of global revenue. CCPA penalties accrue per violation. HIPAA penalties are tiered and compound across violation categories and years.
- Class action lawsuits: In the US, data breaches frequently lead to class action litigation. The CCPA's private right of action allows statutory damages for certain data breaches involving unauthorized access.
- Consent decrees: FTC consent decrees can bind an organization to 20 years of biennial assessments and specific compliance obligations — a lasting operational burden that outlasts the original violation.
- Reputational harm: Public breaches and enforcement actions erode customer trust, which can impact revenue, market position, and employee recruitment.
- Operational disruption: Enforcement orders may require halting processing activities, deleting data, or restructuring systems.
Individual Liability
In some regimes, individual officers face personal consequences:
- Under GDPR, the UK ICO has used its powers to personally fine directors for company data breaches.
- Under HIPAA, criminal penalties for knowing wrongful disclosure of PHI can include imprisonment for individuals.
- Securities fraud charges (SEC) can target executives who misrepresent privacy or cybersecurity posture in filings or public statements.
- Under UK company law, directors can be held personally liable for failures leading to insolvency caused by regulatory fines.
Worked Scenario: Non-Compliance Impact
A US-based health app collects users' health data without adequate HIPAA compliance measures. The company has no Business Associate Agreements (BAAs) with its cloud vendor, has conducted no risk assessment, and has no breach response plan. A breach exposes 100,000 users' health records.
Regulatory Impact
HHS OCR investigates and imposes civil penalties. The penalty tier depends on culpability — if the company acted with willful neglect and did not correct the violation, penalties can reach the highest tier per violation category per year. State AGs may bring separate enforcement actions under HITECH Act authority. The FTC may pursue a case under Section 5 for deceptive privacy practices — the app's privacy policy promised "bank-level security" that was not delivered.
Litigation Impact
A class action lawsuit seeks damages for the 100,000 affected users. Under various state laws, statutory and actual damages may apply. If the company is subject to CCPA (California residents are among the affected users), the private right of action for data breaches may entitle consumers to statutory damages of $100–$750 per consumer per incident.
Individual Impact
If executives knowingly misrepresented the company's security posture in SEC filings or investor communications, they may face personal securities fraud charges. If the CEO or CTO knowingly approved the lack of BAAs despite being informed of the HIPAA requirement, personal liability under HIPAA criminal provisions is theoretically possible for knowing wrongful disclosure.
Operational Impact
The company must halt certain processing, implement a corrective action plan under HHS OCR oversight, and operate under an FTC consent decree for up to 20 years — requiring biennial third-party assessments. The consent decree is perhaps the most lasting impact: it outlasts the original breach, the current executive team, and potentially the company's current business model, requiring privacy compliance infrastructure that the organization may not have been willing to build voluntarily.
Summary of Impact Layers
| Impact Layer | Consequence | Duration |
|---|---|---|
| Regulatory fine (HHS OCR) | Tiered civil penalties per violation category per year | One-time (but potentially recurring) |
| FTC consent decree | 20 years of biennial assessments + specific obligations | ~20 years |
| Class action litigation | Statutory/actual damages for affected users | Multi-year litigation |
| Individual officer liability | Personal fines or criminal charges | Permanent record |
| Reputational harm | Loss of customer trust, churn, brand damage | Years to recover |
Under GDPR, what is the maximum administrative fine a supervisory authority can impose for the most serious violations?
Which enforcement mechanism allows the FTC to impose up to 20 years of biennial privacy assessments and specific compliance obligations on an organization?