14.1 Federal/State Authority, AGs, and the CPPA
Key Takeaways
- There is still no general federal comprehensive consumer-privacy statute; dual sovereignty lets states enact and enforce their own comprehensive laws unless a sectoral federal statute occupies the field.
- State attorneys general are the default enforcers of comprehensive state privacy laws; most of those statutes create no private right of action.
- The California Privacy Protection Agency is the first dedicated U.S. privacy regulator: a five-member board with rulemaking, investigation, audit, and administrative-fine authority that runs concurrently with the California Attorney General.
- Sectoral federal laws (HIPAA, GLBA, FCRA, COPPA, the Airline Deregulation Act) still preempt contrary state rules in their fields; the FTC Act does not occupy the field of consumer privacy.
- An FTC Section 5 investigation and a state attorney-general investigation of the same incident can proceed in parallel; one sovereign's settlement does not automatically bar the other.
14.1 Federal/State Authority, AGs, and the CPPA
The IAPP CIPP/US Body of Knowledge 2.6.1 (effective 1 September 2025) gives Domain V — State Privacy Laws — 17–21 of the exam's 90 questions. Competency V.A is a single performance indicator, but it is the hinge for everything that follows: know how federal and state authority interact, who enforces the comprehensive state statutes, and what the California Privacy Protection Agency (CPPA) uniquely does. IAPP's 5 January 2026 news item is the official reminder that candidates must know 2026 legal developments even when they modify older textbook treatments. Indiana, Kentucky, and Rhode Island's comprehensive laws became applicable on 1 January 2026, and California's automated-decisionmaking, risk-assessment, and cybersecurity-audit regulations became effective the same day.
Dual sovereignty, not a federal privacy code
The United States is a federal system. Congress may regulate interstate commerce and has used that power to write sectoral privacy statutes — the Federal Trade Commission Act (FTC Act), the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Gramm-Leach-Bliley Act (GLBA), the Fair Credit Reporting Act (FCRA), and the Children's Online Privacy Protection Act (COPPA). Congress has not enacted a generally applicable consumer-privacy code that occupies the field. That gap is why states remain Justice Brandeis's laboratories of democracy. A state legislature may enact a comprehensive privacy statute that applies to businesses that conduct business in the state or target its residents, so long as the statute does not contradict a valid federal rule in a preempted field.
Dual sovereignty means the federal government and a state are separate sovereigns. Each may investigate and penalize the same company for the same incident under its own law. The FTC Act does not silently repeal the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), Virginia's Consumer Data Protection Act (CDPA) (Va. Code §§ 59.1-575–59.1-585), or the Colorado Privacy Act (CPA). A company that is a HIPAA covered entity is still inside California's statute for personal information that is not protected health information. A national retailer can owe duties to the FTC under Section 5 and to a state attorney general under that state's comprehensive law.
State attorneys general are the default enforcers
Most comprehensive state privacy laws give the state attorney general (AG) exclusive or primary civil enforcement. Virginia Code § 59.1-584 is the clean exam model: "The Attorney General shall have exclusive authority to enforce," after a 30-day written cure notice, with civil penalties of up to $7,500 per violation and no private right of action. Maryland's Office of the Attorney General likewise states that it enforces the Maryland Online Data Privacy Act (MODPA), which became applicable on 1 October 2025. Colorado's Attorney General enforces the CPA and has issued detailed implementing rules. Indiana's Attorney General published a Consumer Data Bill of Rights before the state's 1 January 2026 effective date. Rhode Island's Data Transparency and Privacy Protection Act (RIDTPPA) (R.I. Gen. Laws ch. 6-48.1), also effective 1 January 2026, is enforced as a state consumer-protection statute, not by a dedicated privacy commission.
The exam move is to name the enforcer before you name the remedy. For a typical Virginia-, Indiana-, or Kentucky-style statute, a Richmond resident whose data was sold without an opt-out complains to the AG; she does not file a private CDPA class action. California is the exception that proves the rule: the CPPA and the California Attorney General share public enforcement, and Civil Code § 1798.150 adds only a limited security private right of action. Access, deletion, correction, and opt-out failures still go to the agency and the AG, not to a private CCPA plaintiff.
| Actor | What it can do in 2026 | What it cannot do by itself |
|---|---|---|
| State legislature | Enact a comprehensive privacy statute and set thresholds, exemptions, and remedies | Issue an implementing regulation or bring an enforcement action |
| State attorney general | Investigate, issue civil investigative demands, sue for injunctions and civil penalties, coordinate multistate cases | Write a generally applicable regulation unless the statute delegated that power |
| CPPA | Adopt CCPA regulations, investigate, audit, and levy administrative fines, concurrently with the California AG | Displace the FTC or rewrite HIPAA, GLBA, or FCRA |
| FTC | Investigate unfair or deceptive acts under Section 5 and enforce COPPA and other federal rules | Occupy the field of comprehensive consumer privacy or veto a valid state statute |
The CPPA: first dedicated U.S. privacy regulator
Proposition 24 created the CPPA in 2020 and seated a five-member board. The Agency's official FAQ is the text to memorize. The CPPA implements and enforces the CCPA as amended. It promotes public awareness, adopts regulations, investigates, audits businesses, and brings administrative enforcement actions. It also cooperates with other privacy authorities in California, other states, and other countries. Consumers file complaints at the Agency; the Agency does not represent individual complainants as their lawyer.
That combination — a standing privacy agency with rulemaking plus administrative fines — is what makes the CPPA the first dedicated U.S. privacy regulator. Other states still enforce through the AG's consumer-protection shop. The Office of Administrative Law approved the CPPA's automated-decisionmaking-technology (ADMT), risk-assessment, and cybersecurity-audit regulations on 22 September 2025; they became effective 1 January 2026. Administrative fines were CPI-adjusted the prior odd year: Civil Code §§ 1798.155 and 1798.199.90 now authorize not more than $2,663 per violation, or $7,988 for an intentional violation and for a violation involving a consumer the violator actually knows is under 16 (CPPA CPI table effective 1 January 2025).
Concurrent California enforcement is intentional, not a drafting accident. The California AG retains civil-penalty authority and still takes CCPA complaints. A business can face a CPPA administrative proceeding and an AG civil action arising from the same facts. The two offices coordinate, but a letter from one does not immunize the company against the other. Starting 1 July 2023, consumers could file CCPA complaints with either office.
Preemption: sectoral federal law still wins in its field
Absence of a comprehensive federal privacy statute is not absence of federal preemption. Valid federal law still overrides contrary state law under the Supremacy Clause. Use the flavors you already learned in Domain I.
HIPAA is a federal floor. A contrary state medical-privacy rule is preempted, but a more stringent state provision that gives individuals greater rights survives (45 C.F.R. § 160.203(b)). GLBA treats a more protective state financial-privacy law as not inconsistent (15 U.S.C. § 6807). FCRA combines conflict preemption with express subject-matter preemption of listed credit-reporting topics (15 U.S.C. § 1681t). COPPA sets a federal children's-privacy rule; a state law that conflicts with it is preempted, but complementary state children's rules can survive. The Airline Deregulation Act expressly preempts state laws related to a price, route, or service of an air carrier (49 U.S.C. § 41713). Rhode Island's statute even writes that last point into its exemption list (R.I. Gen. Laws § 6-48.1-3(e)(16)).
State comprehensive laws usually avoid the collision by carving out the federal regime. Virginia § 59.1-576 exempts GLBA financial institutions, HIPAA covered entities and business associates, public bodies, nonprofits, and higher-education institutions, and then exempts listed data types (protected health information, FCRA consumer-report activity, FERPA data, DPPA data). That is a scope choice. It is not a holding that the FTC Act preempts the CDPA.
Exam trap. "The FTC Act occupies the field, so a state AG cannot sue a national website" is false. Section 5 is a general UDAP statute. It does not contain a comprehensive-privacy preemption clause and does not displace CCPA, CDPA, CPA, MODPA, or RIDTPPA.
When a state AG and the FTC investigate the same incident
Worked scenario. A national retailer suffers a credential-stuffing incident that exposes account credentials of California, Virginia, and Colorado residents. Dark-pattern cookie banners also ignored Global Privacy Control signals. Three files open in the same quarter: an FTC Section 5 investigation (deceptive "we respect your privacy choices" claim plus unreasonable security), a CPPA inquiry into sale/share and notice-at-collection failures, and a multistate AG investigation led by Virginia and Colorado under their comprehensive statutes and state UDAP laws.
Dual sovereignty lets all three proceed. The company cannot refuse a Virginia civil investigative demand because the FTC has already issued a civil investigative demand. An FTC consent order that names only the FTC as plaintiff does not release the CPPA or a non-signing AG. Double jeopardy does not bar parallel civil enforcement by different sovereigns. Privilege and work-product protections do not vanish because two agencies asked for the same risk assessment; they can be waived if counsel dumps the privileged memo into both productions without a claw-back plan.
The practical exam answer is coordinate, do not pick a favorite sovereign. Tell the same facts to each enforcer. Map each allegation to the statute that actually covers it — Section 5 deception is not a CDPA deletion claim, and a CPPA administrative fine is not an FTC civil-penalty count for violating a prior order. Joint or coordinated settlements are common; they are a negotiation outcome, not a legal merger of the claims.
Exam traps. Do not call the CPPA a federal agency. Do not treat an AG as a rule-writer unless the statute delegated rulemaking (Colorado did; Virginia mostly did not). Do not assume a private right of action exists because the AG can sue. Do not say a federal comprehensive privacy law preempts the 2026 state statutes — that statute has not been enacted.
A national retailer is in scope for Virginia's CDPA and California's CCPA. After a sale-without-opt-out incident, who is the default public enforcer under a typical comprehensive state privacy statute such as Virginia's, and how does California differ?
Which description of the California Privacy Protection Agency matches the official CPPA FAQ and the 2025–2026 rulemaking record?
The FTC and a state attorney general open files on the same retailer's credential-stuffing incident. Which statement correctly applies dual sovereignty and preemption?