3.3 Federal and State Enforcement Authorities
Key Takeaways
- The FTC is the primary general federal privacy enforcer under Section 5; DOJ handles criminal cases and some civil-penalty litigation; sectoral agencies (HHS, CFPB, FCC, banking regulators) enforce their own statutes
- State attorneys general enforce mini-UDAP statutes and state privacy laws to protect residents of their states, often concurrently with a federal action
- The CPPA is a five-member agency created by Proposition 24 that implements and administratively enforces the CCPA; the California Attorney General retains civil-action authority
- A civil investigative demand gathers documents and testimony in a non-public inquiry; it is not a finding of liability and is not a consent decree
- Civil Code section 1798.199.90 requires the CPPA to stay an administrative action or investigation on the Attorney General's request, forbids the CPPA from limiting AG authority, and provides that a business cannot be required to pay both an administrative fine and a civil penalty for the same violation
Federal and State Enforcement Authorities
Domain I.B performance indicator 4 asks you to understand the purpose of federal and state enforcement actions and to know the authorities the BoK names: federal agencies, the Department of Justice (DOJ), state attorneys general, and the California Privacy Protection Agency (CPPA). The exam is testing the division of labor, not a roster of every U.S. regulator.
Why federal actions exist
A federal privacy action exists to police a national marketplace under a nationwide statute or rule. The Federal Trade Commission (FTC) is the primary general federal privacy and data-security enforcer. Section 5 of the FTC Act reaches unfair or deceptive acts or practices in or affecting commerce. The U.S. SAFE WEB Act amendments confirm that Section 5 can reach foreign commerce that causes or is likely to cause reasonably foreseeable injury in the United States, or that involves material conduct in the United States (15 U.S.C. § 45(a)(4)). The FTC also enforces sectoral statutes assigned to it, including COPPA.
Other federal agencies enforce sectoral statutes the FTC does not own:
- HHS Office for Civil Rights — HIPAA Privacy, Security, and Breach Notification Rules.
- Consumer Financial Protection Bureau (CFPB) — many consumer-financial privacy and unfairness authorities after the Dodd-Frank Act.
- Federal Communications Commission (FCC) — telecommunications privacy and customer proprietary network information.
- Banking regulators (Federal Reserve, Office of the Comptroller of the Currency, FDIC, NCUA) — safety-and-soundness and GLBA duties for the institutions they supervise. The FTC Act generally excludes banks, federal credit unions, and certain common carriers from the Commission's Section 5 jurisdiction.
- Securities and Exchange Commission (SEC) — public-company disclosure and some adviser/cyber rules, not a general consumer-privacy statute.
DOJ is the federal criminal prosecutor. It also files some civil actions — including certain penalty cases — in federal court. The FTC investigates and sues civilly; it does not indict. When a privacy fact pattern includes knowing identity theft, computer fraud, or a criminal HIPAA provision, the federal criminal actor is DOJ (often working with HHS or the FBI), not the Commission sitting as a prosecutor.
Why state AG actions exist
A state attorney general acts for the people of that state. The purpose is to protect residents under that state's mini-UDAP statute and, where one exists, that state's comprehensive or sectoral privacy law. AGs issue their own investigative demands, sue in state or federal court, join multi-state investigations, and settle with consent judgments that can include money, injunctive terms, and assessments. They do not adopt nationwide FTC trade-regulation rules, and an FTC file does not oust them. That is concurrent jurisdiction: the same campaign, notice, or breach can produce an FTC consent order and a group of AG settlements and private UDAP litigation.
California's split: CPPA versus the Attorney General
California is the BoK's named exception to the "AG-only" state model.
Voters approved Proposition 24, the California Privacy Rights Act (CPRA), in 2020. CPRA amended the California Consumer Privacy Act (CCPA); it did not create a second, standalone consumer-privacy statute. The Agency therefore refers to the law as the CCPA, as amended. CPRA amendments generally took effect 1 January 2023. The Agency's administrative enforcement authority began 1 July 2023.
The CPPA is governed by a five-member board. Official Agency materials describe its jobs as promoting public awareness, adopting regulations, administratively enforcing the CCPA, cooperating with other privacy authorities, and advising the Legislature. It can investigate possible violations, audit businesses, and bring administrative enforcement actions. It can impose administrative fines. Statutory amounts are not more than $2,500 per violation or $7,500 for each intentional violation and each violation involving the personal information of minors; California law provides for inflation adjustment of those figures. The Agency does not represent individual consumers as their lawyer. Consumers may complain to the CPPA or to the Attorney General; most CCPA duties have no private right of action (a limited private right exists for certain data breaches).
The California Attorney General retains authority to enforce the CCPA through a civil action seeking an injunction and civil penalties in the name of the people of the State of California. Civil Code section 1798.199.90 is the exam's coordination rule:
- The Agency may not limit the Attorney General's authority to enforce the title.
- Upon the Attorney General's request, the Agency shall stay an administrative action or investigation so the Attorney General can proceed.
- A business shall not be required to pay both an administrative fine and a civil penalty for the same violation.
In short: CPPA = administrative enforcement, audits, and rulemaking. California AG = civil lawsuits. The AG can require the Agency to stand down. There is no double money penalty for the same CCPA violation.
Concurrent jurisdiction in practice
Concurrent jurisdiction means more than one sovereign can proceed from the same facts. Typical stack:
- FTC Section 5 investigation of a nationwide notice or security practice.
- A multi-state AG UDAP investigation of harm to each state's residents.
- In California, a CPPA administrative file or a California AG civil file on the CCPA duties — not both penalties for the same violation.
- Private litigation under a state mini-UDAP statute, a contract, or a tort theory.
No single filing "uses up" the other sovereigns, except where a statute (like California's no-double-penalty rule) says so.
Tools: CIDs, lawsuits, consent decrees, and administrative fines
A civil investigative demand (CID) is compulsory process used in a non-public investigation. The FTC's consumer-protection staff use CIDs under the FTC Act to require documents, written answers, reports, or oral testimony. State AGs have analogous CID or subpoena authority under state law. A CID is not a complaint, not a finding of liability, and not a settlement. The recipient can often negotiate scope; a court can enforce the demand if the company refuses.
A lawsuit is a complaint filed in court (or, for the FTC, sometimes an administrative complaint under Section 5(b) before an administrative law judge). Court actions seek injunctions and, where a statute allows, civil penalties or consumer redress. After AMG Capital Management v. FTC (2021), the Commission cannot obtain equitable monetary relief under Section 13(b) the way it once did. First-time standalone Section 5 counts often settle as conduct relief unless another statute, a rule, or a prior order supplies a penalty hook.
A consent decree (FTC staff more often say consent order or stipulated federal-court order) is a settlement. The respondent typically does not admit liability, waives further litigation, and agrees to injunctive terms — a comprehensive privacy or security program, deletion, vendor oversight, and independent assessments. Historical FTC privacy orders often ran 20 years. Violating the order can support civil penalties even when the original Section 5 count could not.
An administrative fine is a civil money penalty an agency assesses in its own proceeding without first winning a court judgment. The CPPA's CCPA fines are the BoK's clean example. The FTC's first-line Section 5 process is an order, not a same-day administrative fine for a bare deception count.
| Tool | When it appears | What it is not |
|---|---|---|
| CID | Non-public inquiry; documents and testimony | Not a finding of liability |
| Lawsuit / administrative complaint | Agency has "reason to believe" and charges a violation | Not a settlement |
| Consent decree / consent order | Negotiated resolution, usually without admitting liability | Not a criminal conviction |
| Administrative fine | Agency-assessed civil money penalty (e.g., CPPA) | Not the FTC's ordinary first Section 5 remedy |
Scenario. A national retailer receives an FTC CID about a "we do not sell" notice. Two months later three state AGs issue their own demands under mini-UDAP statutes. California's CPPA opens an administrative inquiry into CCPA sale/sharing and opt-out design. None of those filings is a consent decree. The company can still settle with the FTC by consent order, settle with the AGs by state consent judgments, and resolve the California file with either the CPPA or the California AG — not two money penalties for the same CCPA violation.
Exam traps
- Do not say the FTC prosecutes crimes or that DOJ is the general federal privacy regulator under Section 5.
- Do not say an FTC investigation bars state AGs.
- Do not say the CPPA replaced the California Attorney General.
- Do not call a CID a fine or a consent decree.
What is a core purpose of state attorney general privacy enforcement compared with a typical Federal Trade Commission action?
A company receives a legally enforceable demand for documents, written answers, and oral testimony during a non-public inquiry. No complaint has been filed and no settlement has been signed. What tool is that?
Which statement correctly describes the split between the California Privacy Protection Agency and the California Attorney General under the CCPA, as amended?