3.1 Self-Regulatory Models
Key Takeaways
- Self-regulation is industry-written rules adopted by contract, membership, or a public seal — not a statute Congress enacted
- The NAI Framework and DAA Self-Regulatory Principles (AdChoices) are the exam's core advertising codes; BBB National Programs / NAD are the classic U.S. accountability layer
- PCI DSS is a PCI Security Standards Council security standard enforced by card brands and acquirers through merchant agreements, not a federal privacy statute
- A privacy seal or 'we follow the code' claim is a material representation; a broken promise is an FTC Act Section 5 deception case, as in the 2014 TRUSTe recertification action
- A voluntary code becomes enforceable when it is contracted, advertised to consumers, written into a consent order, used as a negligence standard of care, or (rarely) recognized in a statutory safe harbor
Self-Regulatory Models
The CIPP/US Body of Knowledge treats self-regulation as its own source of privacy rules, sitting beside constitutions, statutes, regulations, and common law. Domain I.A performance indicator 5 asks you to understand self-regulatory models. Domain I.B later tests how those models are enforced. This section is the map of the models; later sections in this chapter are the liability and enforcement machinery.
Self-regulation is a system in which industry participants write, adopt, and police their own privacy or security rules. Congress did not enact the code. A state legislature did not pass it. A company typically joins by contract: it pays a fee, signs a membership agreement, displays a seal, or accepts a merchant agreement that incorporates the standard. U.S. privacy law is sectoral. Large parts of commercial data use still have no dedicated federal privacy statute. Self-regulation grew in those gaps — especially online advertising and payment-card security.
Industry codes, NAI, and DAA
An industry code is a written set of practices that members of a trade group promise to follow. Two advertising programs dominate the exam.
The Network Advertising Initiative (NAI) is a nonprofit self-regulatory association of third-party digital advertising companies. Membership requires participation in the NAI Self-Regulatory Framework, which on 1 February 2025 superseded and replaced the 2020 NAI Code of Conduct. The Framework sets baseline privacy standards for interest-based advertising (IBA) / network advertising: notice, choice, limits on sensitive data, and process obligations. NAI — not a federal agency — is the first-line overseer of its members.
The Digital Advertising Alliance (DAA) is the broader, more consumer-facing program. Its Self-Regulatory Principles for Online Behavioral Advertising, plus later guidance on multi-site data, mobile, and cross-device data, are the ruleset behind the YourAdChoices / AdChoices icon. Displaying that icon is a representation to consumers: the company claims to follow DAA principles and to offer a control for interest-based ads. Compliance with the DAA Principles is independently reviewed through accountability programs associated with BBB National Programs (and historically related advertising bodies).
Do not memorize every NAI principle. Know the model: members opt in, the code sets practices the statute may not name, and the association is the first reviewer.
| Program | Who it covers | What it requires | Who first reviews it |
|---|---|---|---|
| NAI Framework | Third-party digital advertising companies that join NAI | Notice, choice, sensitive-data limits, and process duties for interest-based / network advertising | NAI membership and privacy-review program |
| DAA Principles | Broader digital-advertising ecosystem | Transparency and consumer control (AdChoices); multi-site, mobile, and cross-device guidance | Independent accountability through BBB National Programs |
| PCI DSS | Merchants, processors, acquirers, issuers, and service providers that handle card data | Technical and operational security controls for cardholder data | Card brands and acquiring banks via contract |
Seal programs, BBB, and accountability agents
A privacy seal (also called a trust mark) is a logo a site displays to signal that an independent body has reviewed its practices. The company typically pays the seal provider, completes a questionnaire or audit, and agrees to stay in compliance.
An accountability agent is the organization that assesses participants and can suspend or revoke the seal. BBB National Programs is the classic U.S. accountability infrastructure. It also runs the National Advertising Division (NAD), which reviews truth-in-advertising challenges from competitors, consumers, or its own monitoring. NAD is not a court and not a federal agency. If a company refuses to participate or to follow an NAD decision, NAD can refer the matter to the Federal Trade Commission (FTC). That referral is the exam's bridge from "voluntary" self-regulation to government enforcement.
PCI DSS as a contractual security standard
The Payment Card Industry Data Security Standard (PCI DSS) is developed and maintained by the PCI Security Standards Council (PCI SSC). The Council is an industry body created by the major card brands (Visa, Mastercard, American Express, Discover, and JCB). PCI DSS defines baseline technical and operational requirements for environments that store, process, or transmit cardholder data (CHD) or sensitive authentication data (SAD). It applies to merchants, processors, acquirers, issuers, and service providers that can affect the cardholder data environment (CDE).
This is the exam's favorite self-reg example because candidates recast it as a statute.
- PCI DSS is not a federal privacy law and not an FTC trade-regulation rule.
- PCI SSC writes and maintains the standard; it does not send federal investigators or assess statutory civil penalties.
- Card brands and acquiring banks enforce PCI through merchant agreements and brand operating rules.
- Consequences are contractual: fines under the brand rules, higher interchange, a post-breach forensic investigation, or loss of the right to accept cards.
A merchant that never signed a card-acceptance contract is not "under PCI" the way a HIPAA covered entity is under the U.S. Department of Health and Human Services. A merchant that did sign is bound because it promised to comply.
How self-regulation meets FTC deception
Self-regulation becomes a government case when a company says it follows a code or holds a seal and then does not. Section 5 of the Federal Trade Commission Act (15 U.S.C. § 45(a)) makes unfair or deceptive acts or practices in or affecting commerce unlawful. Under the Commission's Policy Statement on Deception, a deceptive practice is a material representation, omission, or practice that is likely to mislead a consumer acting reasonably under the circumstances.
Displaying a privacy seal is a representation. So is "we are NAI members," "we follow DAA principles," or "we are PCI compliant." If that statement would affect a reasonable consumer's decision to share data or click accept, a broken promise is a Section 5 deception case — and usually a state unfair and deceptive acts and practices (UDAP) case as well.
The leading teaching example is the FTC's 2014 action against TRUSTe. The complaint alleged that TRUSTe represented that companies holding its Certified Privacy Seals received annual recertification, but from 2006 until January 2013 TRUSTe failed to conduct annual recertifications in more than 1,000 instances. The case is not "the FTC enforces the TRUSTe code as if it were a statute." The case is "the FTC enforces the truth of statements about the seal program."
When a "voluntary" code becomes enforceable
A code is voluntary only until one of these hooks attaches:
- Contract. Membership agreements, merchant agreements, and vendor terms make the code a private-law obligation. PCI lives here.
- Consumer-facing claim. Advertising the code or displaying the seal is a representation the FTC and state attorneys general can police.
- Consent order. An FTC or state settlement can incorporate specific practices, converting them into a binding order with later civil-penalty exposure.
- Standard of care. In a negligence suit, industry codes can be evidence of what a reasonable company would have done, even if the plaintiff never joined the program.
- Statutory safe harbor (narrow). Congress sometimes recognizes approved self-reg programs. The Children's Online Privacy Protection Act (COPPA) safe-harbor program — tested more fully in Domain II — is the exam's later example. That is a statute using self-regulation, not self-regulation replacing a statute.
Strengths, limits, and a worked scenario
Strengths: industry can update a code faster than Congress; the drafters often have technical expertise statutes lack; a code can cover practices no statute names; and NAD-style review can resolve disputes without consuming FTC resources.
Limits: participation is optional unless a contract or a public claim locks the company in; first-line sanctions are usually expulsion, a required change, or a referral — not a federal fine; consumers are not parties to the membership contract; and a seal can create a false sense of security if the accountability agent does not actually recertify.
Scenario. A fitness-app vendor displays a well-known privacy seal on its download page and states, "Independently certified every year." Marketing later learns the accountability agent moved the vendor to a two-year cycle and skipped last year's review. No comprehensive state privacy law is needed for the analysis. The seal and the "every year" claim are material representations. A reasonable consumer could rely on them when creating an account. The mismatch is a Section 5 deception theory (and a state UDAP theory). The self-reg code itself is not a federal statute the FTC "enforces." The FTC enforces the promise.
Exam traps
- Do not call PCI DSS a federal privacy statute or an FTC rule.
- Do not treat NAI or DAA membership as automatically binding on non-members who never claimed compliance.
- Do not say a privacy seal immunizes a company from FTC review. The opposite is often true: the seal is extra evidence of what the company claimed.
- Do not confuse NAD's referral power with a self-executing federal injunction.
A mobile app displays a well-known privacy seal and states that an independent agent recertifies the company every year. The agent skipped last year's review. No sectoral privacy statute covers the specific collection practice. What is the strongest U.S. government theory on the CIPP/US exam?
How is the Payment Card Industry Data Security Standard (PCI DSS) primarily enforced in the United States?
Which statement best captures a real limit of industry self-regulation?