2.3 Scope, Jurisdiction, Preemption, and Private Rights of Action

Key Takeaways

  • Scope asks who and what a law covers; personal jurisdiction asks whether this court may bind this defendant; subject-matter jurisdiction asks whether this court may hear this kind of case.
  • CCPA/CPRA Civil Code § 1798.150 creates a limited private right of action for certain security failures involving specified unencrypted personal information, with statutory damages of $100 to $750 per consumer per incident or actual damages, whichever is greater.
  • Virginia's Consumer Data Protection Act gives the Attorney General exclusive enforcement authority, expressly creates no private right of action, and authorizes civil penalties of up to $7,500 per violation after a 30-day cure notice.
  • HIPAA generally preempts contrary state law but not a state medical-privacy provision that is more stringent than the HIPAA Privacy Rule (45 C.F.R. § 160.203(b)).
  • Express, conflict, and field preemption are different tools: the Airline Deregulation Act uses broad express preemption of state laws related to price, route, or service; GLBA treats more protective state laws as not inconsistent; FCRA combines conflict preemption with express subject-matter preemption.
Last updated: August 2026

2.3 Scope, Jurisdiction, Preemption, and Private Rights of Action

BoK I.A's third performance indicator is the closest thing CIPP/US has to a legal-method question: know scope and application, jurisdiction, preemption, and private right of action. Almost every scenario item in Domains II and V is an application of these four ideas.

Scope and application

Scope answers who is regulated, what information is covered, what activity is covered, and which exemptions apply. A law can be territorial (it applies to persons who conduct business in the state or target its residents), entity-based (HIPAA covered entities and business associates), activity-based (FCRA consumer reports), or data-based (GLBA nonpublic personal information). Virginia's CDPA, for example, applies to persons that conduct business in the Commonwealth or produce products or services targeted to Virginia residents and that control or process personal data of at least 100,000 consumers in a calendar year, or of at least 25,000 consumers while deriving over 50 percent of gross revenue from sales of personal data (Va. Code § 59.1-576). The same statute then exempts public bodies, GLBA financial institutions, HIPAA covered entities and business associates, nonprofits, and institutions of higher education.

Always separate entity exemptions from data exemptions. A bank may be outside Virginia's CDPA as a GLBA institution and still be inside the CCPA for data that is not nonpublic personal information, depending on California's narrower GLBA exemption. A hospital's protected health information may be HIPAA-covered while the same hospital's website marketing list is not.

Personal jurisdiction and subject-matter jurisdiction

Personal jurisdiction is power over this defendant. Under International Shoe, a court needs minimum contacts such that maintenance of the suit does not offend traditional notions of fair play. Specific jurisdiction is claim-linked (the company targeted the forum's residents and the claim arises from that targeting). General jurisdiction is all-purpose and usually exists where the defendant is at home — place of incorporation or principal place of business. Privacy statutes that reach out-of-state companies typically rely on targeting residents plus a statutory threshold, but a judgment still requires a court with personal jurisdiction.

Subject-matter jurisdiction is power over this kind of case. Federal courts hear federal-question cases (28 U.S.C. § 1331) and certain diversity cases (§ 1332). State courts are courts of general jurisdiction and routinely hear CCPA, CDPA, and common-law privacy claims. A FCRA damages action can be filed in federal or state court. A pure Virginia CDPA enforcement action belongs to the Virginia Attorney General, not to a private plaintiff in any court.

Do not confuse the two. A California resident can have a live CCPA security claim and still lose if she sues an overseas company that has no contacts with California. Conversely, a federal court can have personal jurisdiction over a California defendant and still lack subject-matter jurisdiction if the only claim is a state-law claim that does not meet diversity or supplemental-jurisdiction rules.

Express, conflict, and field preemption

Preemption is the Supremacy Clause in operation: valid federal law overrides contrary state law. CIPP/US expects you to name the flavor.

Express preemption is written into the statute. The Airline Deregulation Act is the clean example. 49 U.S.C. § 41713(b)(1) says a state may not enact or enforce a law related to a price, route, or service of an air carrier. The Supreme Court has read that phrase broadly (Morales, Wolens, Northwest v. Ginsberg), so state consumer-protection and even some common-law claims against airlines are often displaced. The U.S. Department of Transportation is the primary federal consumer-protection authority for airlines. Exam consequence: do not assume a state attorney general can use a state comprehensive privacy statute or UDAP statute to regulate how a scheduled airline provides a service.

Conflict preemption has two branches. Impossibility conflict exists when a party cannot comply with both laws. Obstacle conflict exists when the state law stands as an obstacle to the full purposes of the federal scheme. You use this analysis when the federal statute has no neat preemption clause, or as a backstop when it does.

Field preemption exists when the federal scheme is so pervasive that Congress left no room for states. Do not call HIPAA field preemption. HIPAA is a federal floor for the privacy of individually identifiable health information, with listed exceptions.

Federal sourcePreemption flavor the exam expectsState law that usually survivesState law that is in trouble
HIPAA Privacy Rule, 45 C.F.R. § 160.203Contrary state law is preempted, except more-stringent privacy rules and listed public-health / reporting exceptionsA state medical-privacy statute that gives patients more control or a private right of actionA state rule that requires a disclosure HIPAA forbids
FCRA, 15 U.S.C. § 1681tConflict preemption of inconsistent laws plus express preemption of listed subject matter (including certain affiliate-sharing and consumer-report content rules)A state law on a topic FCRA does not occupyA state law that rewrites what may appear in a consumer report in a preempted category
GLBA, 15 U.S.C. § 6807Inconsistent state law is preempted only to the extent of the inconsistency; a more protective state law is not inconsistentA more demanding state financial-privacy notice or opt-outA state rule that lowers GLBA protections
Airline Deregulation Act, 49 U.S.C. § 41713Broad express preemption of laws related to price, route, or serviceA claim that is truly tenuous or a contract claim limited to the airline's own self-imposed terms (Wolens)A state AG UDAP or privacy theory that regulates airline service

HIPAA's official rule is worth quoting in substance. A HIPAA standard that is contrary to state law preempts that state law unless an exception applies. The privacy exception that appears on the exam is § 160.203(b): the state provision relates to the privacy of individually identifiable health information and is more stringent than the HIPAA Privacy Rule. "More stringent" means the state law gives individuals greater privacy protection or more rights. HHS has said it will not issue general advisory opinions declaring a state law more stringent; covered entities must do that comparison themselves.

FCRA is the opposite instinct on some topics. Congress wanted national uniformity in the credit-reporting system. The statute both displaces inconsistent state laws and expressly forbids state requirements in listed areas. Treat FCRA as not a green light for every state experiment on credit-report content. GLBA is the opposite of the Airline Deregulation Act: it is a floor, and more protective state financial-privacy law is expressly treated as consistent. Many state comprehensive privacy laws then voluntarily exempt GLBA institutions or GLBA data, which is a scope choice, not a federal preemption command.

Private right of action versus agency-only enforcement

A private right of action (PRA) lets an individual (or class) sue. Agency-only enforcement lets a regulator or attorney general sue and usually denies individuals that path. Whether a PRA exists is a statutory question, not a fairness intuition.

Worked scenario — CCPA PRA versus Virginia AG-only. California Civil Code § 1798.150 (as amended effective 1 January 2025) lets a consumer sue if nonencrypted and nonredacted personal information, as defined by cross-reference to § 1798.81.5, or an email address combined with a password or security question that would permit account access, is subject to unauthorized access and exfiltration, theft, or disclosure because the business failed to implement reasonable security procedures appropriate to the nature of the information. Recovery is statutory damages of $100 to $750 per consumer per incident or actual damages, whichever is greater, plus injunctive or declaratory relief. Before suing for statutory damages, the consumer must give 30 days' written notice. Implementing reasonable security after a breach is not a cure of that breach. No notice is required if the consumer seeks only actual pecuniary damages. Critically, § 1798.150(c) says this cause of action applies only to that security violation and shall not be based on violations of any other CCPA section. Access, deletion, and opt-out failures go to the California Privacy Protection Agency and the Attorney General, not to a private plaintiff under the CCPA.

Virginia Code § 59.1-584 is the contrasting model. "The Attorney General shall have exclusive authority to enforce" the CDPA. Before filing, the Attorney General must give 30 days' written notice. A controller or processor that cures and provides an express written statement that no further violations will occur faces no action for the noticed violation. Civil penalties may reach $7,500 for each violation. Subsection E is unequivocal: nothing in the chapter provides a private right of action for violations of the chapter or under any other law.

So a Richmond resident whose data is sold without an opt-out cannot privately sue under the CDPA. A Los Angeles resident whose unencrypted Social Security numbers are exfiltrated after a reasonable-security failure may privately sue under § 1798.150. The same Los Angeles resident cannot privately sue under the CCPA merely because a "Do Not Sell" link was missing.

Worked scenario — HIPAA versus state medical privacy. A California clinic is a HIPAA covered entity. HIPAA itself supplies no general private right of action; OCR investigates complaints, obtains resolution agreements, and may impose civil money penalties. California's Confidentiality of Medical Information Act (CMIA) and related medical-privacy statutes can be more stringent — for example by authorizing a patient to sue. Under § 160.203(b), those more protective provisions are not preempted. The clinic must meet HIPAA and the stricter state duties. If a state law instead required the clinic to post identifiable patient diagnoses on a public website, that law would be contrary to HIPAA and would be preempted.

Other PRA landmarks for later domains. FCRA and TCPA have private rights of action. COPPA and GLBA generally do not. Section 5 of the FTC Act is enforced by the FTC, not by private plaintiffs. When a question asks "who can sue," identify the statute first, then the remedy section — do not generalize from California or from HIPAA.

Exam traps. Scope is not jurisdiction. A PRA is not implied just because harm occurred. HIPAA is a floor, not a ceiling. Airline preemption is express and broad. GLBA preemption is a floor. FCRA preemption is tighter than GLBA on credit-reporting subject matter. California's PRA is a security action, not a general CCPA class-action engine.

Test Your Knowledge

A consumer in Los Angeles and a consumer in Richmond suffer similar data incidents at the same national retailer. Which statement correctly contrasts California's CCPA/CPRA with Virginia's CDPA?

A
B
C
D
Test Your Knowledge

A HIPAA covered clinic operates in a state whose medical-privacy statute gives patients a private right of action and requires a more specific authorization than the HIPAA Privacy Rule. What is the correct preemption result?

A
B
C
D
Test Your Knowledge

Which statement correctly distinguishes express, conflict, and field preemption for CIPP/US analysis?

A
B
C
D