3.2 Contract, Tort, Fiduciary Duty, Negligence, and UDAP

Key Takeaways

  • Contract liability enforces a bargained promise; tort liability enforces a duty the law imposes independent of that bargain; civil enforcement is an agency or attorney general action; criminal liability requires a prosecutor and a higher burden of proof
  • The FTC Act has no private right of action; many state mini-UDAP statutes do, which is why the same privacy-notice mismatch can produce both an FTC case and a private or AG case
  • U.S. law generally does not treat every company that holds personal data as a fiduciary; fiduciary status is limited to recognized relationships of trust such as attorney-client, trustee-beneficiary, or certain advisers
  • Negligence requires duty, breach, causation, and damages — a breach of an industry security practice is not enough without those elements
  • A privacy-notice mismatch is the classic Section 5 deception pattern: the notice is a material representation that is likely to mislead a reasonable consumer
Last updated: August 2026

Contract, Tort, Fiduciary Duty, Negligence, and UDAP

Domain I.B opens with theories of legal liability. The exam is less interested in a long common-law history than in a clean sort: who can sue, for what kind of wrong, and with what remedy. If you cannot tell a contract claim from a tort claim, or a civil FTC case from a criminal prosecution, the rest of U.S. privacy enforcement will blur.

Contract versus tort versus civil enforcement versus criminal

Contract liability enforces a bargained exchange. The plaintiff must show an agreement (offer, acceptance, consideration, and often a writing when the statute of frauds applies), performance or excuse, breach, and damages. Privacy contracts you will see on the exam include website terms, vendor data-processing agreements, employment confidentiality agreements, and merchant agreements that incorporate PCI DSS. A customer who can prove she is a party (or an intended third-party beneficiary) sues for the broken promise — for example, a vendor that contractually promised to delete data in 30 days and did not.

Tort liability enforces a duty the law imposes independent of the bargain. Privacy-relevant torts include intrusion upon seclusion, public disclosure of private facts, appropriation of name or likeness, false light, and — most often in data-security fact patterns — negligence. The plaintiff does not need a signed contract. She needs a legally recognized duty, a breach, causation, and injury.

Civil enforcement is an action by a government authority — the FTC, a state attorney general (AG), the California Privacy Protection Agency (CPPA), or another agency — seeking an injunction, a consent order, restitution, or a civil penalty. The government is not suing as a private contracting party. It is enforcing a public statute or rule. The FTC Act has no private right of action; consumers cannot file their own Section 5 lawsuit in the Commission's name.

Criminal liability is a prosecution by the Department of Justice (DOJ) or a state prosecutor. The burden is beyond a reasonable doubt. Remedies include fines and imprisonment. The same facts can support both a civil case and a criminal case (for example, identity theft, certain knowing Health Insurance Portability and Accountability Act (HIPAA) violations, or computer-fraud statutes). The FTC does not bring criminal cases itself; it can refer matters to DOJ.

TheoryWho typically brings itBurden (civil/criminal)Typical privacy hook
ContractParty to the agreement (or intended beneficiary)PreponderanceBroken DPA, terms, or merchant agreement
Tort (incl. negligence)Injured private plaintiffPreponderanceUnreasonable security, intrusion, disclosure
Civil enforcementFTC, AG, CPPA, other agenciesPreponderance (agency/civil)Section 5, mini-UDAP, CCPA, sectoral statutes
CriminalDOJ or state prosecutorBeyond a reasonable doubtKnowing fraud, identity theft, some HIPAA/computer crimes

Civil versus criminal liability

Keep three contrasts straight.

Who sues. A private plaintiff or a civil agency brings a civil case. Only a prosecutor brings a criminal case.

Burden and intent. Civil privacy cases often turn on what the company represented or whether its security was unreasonable. Criminal cases usually require a mental state the statute names — knowingly, willfully, or with intent to defraud.

Remedy. Civil results are money, injunctions, and compliance programs. Criminal results can include incarceration. A consent decree is not a criminal conviction, even when the press calls it a "penalty."

Fiduciary duty — and its limits

A fiduciary duty is a duty of loyalty and care that arises from a relationship of trust and confidence. The fiduciary must put the beneficiary's interests ahead of its own and must handle the beneficiary's affairs with care. Classic U.S. fiduciaries include attorneys (to clients), trustees (to beneficiaries), many physicians (to patients), Employee Retirement Income Security Act (ERISA) plan fiduciaries, and registered investment advisers (to clients under the Investment Advisers Act).

The exam trap is to treat every data holder as a fiduciary. U.S. law generally does not. Collecting an email address, running a retail site, or holding an employee file does not, by itself, create a fiduciary relationship. Academic "information fiduciary" proposals and some state legislative drafts are policy ideas, not general current law. HIPAA imposes confidentiality and security duties on covered entities and business associates; those duties are statutory and regulatory, not a conversion of every business associate into a common-law fiduciary of every patient. A privacy notice is a representation; it is not automatically a fiduciary appointment.

When fiduciary language does appear in a privacy fact pattern, look for a recognized relationship (lawyer, trustee, adviser) plus misuse of information for the holder's own benefit (loyalty) or careless handling (care). Do not start from "they have our data, therefore they are fiduciaries."

Negligence elements

Negligence is the workhorse tort in breach and insecure-practice questions. The plaintiff must prove four elements:

  1. Duty — a legally recognized obligation to act with reasonable care toward the plaintiff.
  2. Breach — conduct that falls short of that standard.
  3. Causation — actual cause ("but for") and proximate cause (the harm was a foreseeable result, not a wild intervening event).
  4. Damages — a legally cognizable injury, not a purely speculative future risk.

Industry standards such as PCI DSS, National Institute of Standards and Technology (NIST) guidance, or a company's own written policy can be evidence of what reasonable care required. They are not a shortcut around the four elements. Federal courts also frequently test whether the plaintiff has standing — a concrete injury — especially after Spokeo and TransUnion. A candidate who stops at "they failed PCI, so they are negligent" has missed duty, causation, damages, and standing.

Scenario. A retailer stores unencrypted payment data on a server with a default password. Attackers steal the file. A customer whose card was used for fraud can often plead duty (a merchant that takes cards owes reasonable security), breach (default password and no encryption are not reasonable), causation (the stolen file enabled the fraud), and damages (unreimbursed loss, time, and related injury). A customer who suffered no misuse and alleges only a future risk of harm may lose on damages or standing even if the security was poor.

Unfair and deceptive acts and practices

Unfair and deceptive acts and practices (UDAP) is the general U.S. consumer-protection overlay.

At the federal level, FTC Act Section 5 declares unlawful "unfair or deceptive acts or practices in or affecting commerce." Two tests matter:

  • Deception (1983 Policy Statement on Deception): a material representation, omission, or practice that is likely to mislead a consumer acting reasonably under the circumstances. Intent to deceive is not required.
  • Unfairness (15 U.S.C. § 45(n)): the act or practice causes or is likely to cause substantial injury to consumers that is not reasonably avoidable by consumers themselves and is not outweighed by countervailing benefits to consumers or to competition.

Every state has a mini-UDAP / consumer-protection statute. Many of those statutes allow a private right of action and attorneys' fees. That is why the same privacy-notice mismatch can produce an FTC investigation and a state AG case and a consumer class action, even though no one can file a private FTC Act Section 5 claim.

How a privacy-notice mismatch becomes a deception case

Walk the exam's favorite fact pattern in order.

A company publishes a privacy notice that says "we never sell personal information," "we encrypt all health data at rest," or "we delete your account within 30 days of a request." Those sentences are representations to reasonable consumers. Consumers then share data, create accounts, or decline to opt out in reliance on the notice. Internal practice diverges: the company sells marketing lists, stores health data in plaintext, or ignores deletion requests.

The CIPP/US framing is deception, not "they violated a federal privacy code that does not exist." Ask: Was the statement material (would it matter to a reasonable consumer)? Was it likely to mislead? If yes, you have a Section 5 deception theory and, in parallel, a state UDAP theory. If the same conduct also caused substantial, unavoidable injury without countervailing benefits — for example, a reckless failure to secure sensitive data — staff may add an unfairness count. You do not need a fiduciary relationship, and you do not need to prove the company intended to lie.

Exam traps. Do not invent a private FTC Act claim. Do not treat every data holder as a fiduciary. Do not skip negligence elements because a code was broken. Do not re-label a notice mismatch as a criminal case unless the facts supply a criminal statute and a prosecutor.

Loading diagram...
Sorting Privacy Liability Theories
Test Your Knowledge

Which set is the traditional four elements of a negligence claim in a U.S. data-security case?

A
B
C
D
Test Your Knowledge

Which statement about fiduciary duty in U.S. privacy practice is most accurate for the CIPP/US exam?

A
B
C
D
Test Your Knowledge

A retailer's privacy notice states, "We never sell personal information." The retailer sells customer email lists to marketing partners. How should a CIPP/US candidate frame the strongest federal consumer-protection theory?

A
B
C
D