2.4 Major Regulatory Authorities

Key Takeaways

  • The FTC enforces Section 5 of the FTC Act and COPPA against most commercial actors, but FTC Act Section 6(a) excepts banks, savings-and-loan institutions, federal credit unions, and common carriers from that investigative authority.
  • HHS OCR enforces the HIPAA Privacy, Security, and Breach Notification Rules through complaint investigations, compliance reviews, resolution agreements, corrective action, and civil money penalties.
  • The FCC administers Communications Act Section 222 customer proprietary network information rules; the Department of Commerce hosts NTIA privacy policy work and ITA administration of Data Privacy Framework self-certification, not a general Section 5-style enforcement docket.
  • The OCC supervises national banks, the Federal Reserve supervises bank holding companies and state member banks, the FDIC supervises state nonmember banks, and the CFPB administers the GLBA Privacy Rule (Regulation P) and other consumer-financial privacy authorities.
  • State attorneys general enforce state UDAP and comprehensive privacy statutes; state insurance departments, under McCarran-Ferguson, enforce GLBA Title V privacy rules against insurers.
Last updated: August 2026

2.4 Major Regulatory Authorities

BoK 2.6.1 I.A asks you to know the roles, functions, and documents issued by the major authorities: the Federal Trade Commission (FTC), the Federal Communications Commission (FCC), the Department of Commerce (DoC), the Department of Health and Human Services (HHS), banking regulators such as the Federal Reserve Board and the Comptroller of the Currency, state attorneys general, and state departments of insurance. The exam question is almost always a matching problem: who owns this statute, and is the document in front of you a rule, a consent order, or mere guidance?

Federal Trade Commission

The FTC is the default U.S. consumer-privacy cop for commercial entities that are not carved out. Section 5 of the FTC Act is the general unfair or deceptive acts or practices statute. The Commission also enforces COPPA and the COPPA Rule, the GLBA Safeguards Rule for many non-bank financial institutions, the Telemarketing Sales Rule, and other specific consumer-protection statutes. Documents you will see: administrative complaints, consent orders (no admission of liability; 30-day comment; bind the respondent), stipulated federal-court orders filed with the Department of Justice, Section 6(b) reports, policy statements (including the Deception and Unfairness statements), staff guidance, and, when Magnuson-Moss / Section 18 procedures are used, trade regulation rules.

Two jurisdiction traps are official. First, FTC Act Section 6(a) authorizes investigations of persons engaged in commerce excepting banks, savings and loan institutions, federal credit unions, and common carriers. Those actors have other supervisors. The common-carrier exemption is activity-based: a telecommunications company can still face the FTC for non-common-carrier lines of business (FTC v. AT&T, Ninth Circuit en banc). Second, the FTC is not the HIPAA cop and not the prudential bank examiner.

Federal Communications Commission

The FCC implements the Communications Act, including Section 222 restrictions on telecommunications carriers' use and disclosure of customer proprietary network information (CPNI) — information that relates to the quantity, technical configuration, type, destination, location, and amount of use of a telecommunications service. The FCC also administers substantial pieces of the Telephone Consumer Protection Act (TCPA) (with a shared FTC role on telemarketing) and historically the Cable Communications Policy Act privacy provisions. Documents: reports and orders, notices of proposed rulemaking, declaratory rulings, forfeiture orders, and consent decrees. If the data is CPNI in the hands of a carrier, start with the FCC, not OCR and not a state insurance department.

Department of Commerce

Commerce is a policy and program department, not a general privacy-enforcement agency. Three bureaus matter. The International Trade Administration (ITA) administers the EU-U.S. Data Privacy Framework (DPF) self-certification program; participating companies attest to Commerce that they comply with the DPF Principles, and a failure to keep those public commitments can be a Section 5 deception case at the FTC. The National Telecommunications and Information Administration (NTIA) is the President's principal adviser on telecommunications and information policy and runs multistakeholder privacy processes. The National Institute of Standards and Technology (NIST), also in Commerce, publishes the Privacy Framework and Cybersecurity Framework. Those frameworks are voluntary tools, not statutes. Commerce documents include DPF listings, NTIA reports, and NIST publications — not HIPAA civil money penalties.

HHS Office for Civil Rights

HHS OCR is the law-enforcement component that "secures health information privacy and security." OCR enforces the HIPAA Privacy, Security, and Breach Notification Rules (45 C.F.R. Parts 160 and 164) against covered entities and business associates. It investigates complaints, conducts compliance reviews, requires corrective action, issues guidance, and may impose civil money penalties or enter resolution agreements with corrective action plans. OCR became responsible for Security Rule enforcement on 27 July 2009. Beginning in February 2026, OCR also announced a civil enforcement program for 42 C.F.R. Part 2 substance-use-disorder records, using mechanisms aligned with HIPAA penalties. OCR does not enforce Section 5 against ordinary retailers and does not administer the DPF list.

HIPAA still has no general private right of action. A patient files with OCR. A resolution agreement is a settlement document with that entity, not a regulation rewriting 45 C.F.R. Part 164 for everyone else.

Banking regulators and the CFPB

GLBA Title V split supervision by charter. Memorize the map:

AuthorityWho it supervisesPrivacy statutes / documents
Office of the Comptroller of the Currency (OCC) / Comptroller of the CurrencyNational banks and federal savings associationsGLBA Safeguards examinations, Comptroller's Handbook, bulletins, interpretive letters
Federal Reserve BoardBank holding companies and state member banksInteragency safeguards guidelines, supervision manuals, enforcement orders
Federal Deposit Insurance Corporation (FDIC)State nonmember banks; deposit insuranceGLBA examinations, consent orders, financial-institution letters
Consumer Financial Protection Bureau (CFPB)Many consumer-financial firms, including large banks for consumer-financial productsGLBA Privacy Rule (Regulation P), FCRA/FACTA, UDAAP, official interpretations
FTC (for contrast)Non-bank financial institutions not assigned elsewhereGLBA Safeguards Rule, Section 5
State insurance departmentsInsurers licensed in the stateGLBA Title V privacy rules under McCarran-Ferguson; NAIC model privacy regulation

The CFPB was created by the Dodd-Frank Wall Street Reform and Consumer Protection Act. It inherited the GLBA Privacy Rule (annual notices, opt-out of certain sharing) as Regulation P. The GLBA Safeguards Rule for banks stays with the prudential regulators; the FTC keeps Safeguards for many non-banks. UDAAP (unfair, deceptive, or abusive acts or practices) is the CFPB's cousin of FTC UDAP — note the extra abusive prong. The CFPB issues rules, official interpretations, civil investigative demands, consent orders, and advisory opinions. In October 2025 it also issued a new interpretive rule on FCRA preemption; interpretive rules are the agency's legal reading, but courts decide whether that reading is correct.

State attorneys general and state insurance departments

State attorneys general are the workhorses of U.S. privacy enforcement outside the sectoral federal statutes. They enforce state unfair and deceptive acts and practices (UDAP) statutes, state comprehensive privacy laws (exclusive AG enforcement in Virginia; shared AG / California Privacy Protection Agency enforcement in California), state breach-notification statutes, and, under some federal laws such as COPPA, they have a parallel enforcement role. Documents: civil investigative demands, assurances of voluntary compliance, consent judgments, multistate settlements, and guidance. Fifty-plus AGs coordinating through the National Association of Attorneys General can produce a settlement that feels national even though each judgment is a state-law instrument.

State insurance departments exist because the McCarran-Ferguson Act generally leaves the business of insurance to the states. Insurers are financial institutions under GLBA, but their GLBA privacy supervisor is the state insurance commissioner, not the OCC. Departments issue regulations (often based on the National Association of Insurance Commissioners (NAIC) model Privacy of Consumer Financial and Health Information Regulation), bulletins, market-conduct examination reports, and consent orders. If the entity is a licensed insurer and the data is insurance-customer information, start with the state insurance department — not OCR (unless the insurer is also a HIPAA covered health plan, in which case both regimes can apply) and not the FCC.

Documents versus statutes — the matching drill

DocumentWho issues itLegal force
StatuteCongress or a state legislatureGenerally applicable law
Regulation / ruleAgency with delegated authority, usually after APA notice and commentGenerally applicable to covered parties; cannot contradict the statute
Consent order / consent decree / stipulated judgmentFTC, FCC, banking agency, AG, insurance department, or a courtBinds the named respondent; violation can trigger penalties
Resolution agreementHHS OCRSettlement plus corrective action for that covered entity or business associate
Guidance, FAQ, advisory opinion, bulletin, NIST frameworkAny of the above, plus Commerce / NISTExplains discretion; not a statute; persuasive but last in the hierarchy
Executive orderPresidentDirects the executive branch; not a private-sector statute

Worked scenario. A national bank, a wireless carrier, a hospital, a social-media app, and a life insurer each have a similar "we will not share your data" claim on their homepage, and each later shares the data. The bank's GLBA Privacy Rule issues sit with the CFPB and its safeguards exam with the OCC or Federal Reserve, depending on charter; the FTC is the wrong prudential supervisor. The carrier's CPNI sharing sits with the FCC under Section 222; non-carrier app lines of business can still draw the FTC. The hospital's protected health information sits with OCR. The social-media app sits with the FTC under Section 5 (and COPPA if children are involved) and with state AGs. The life insurer sits with state insurance departments under GLBA Title V, and with OCR if it is also a HIPAA covered health plan.

Exam traps. Do not send a national bank's GLBA exam to the FTC. Do not send CPNI to OCR. Do not treat Commerce as a Section 5 enforcer — it runs DPF certification and policy. Do not treat a NIST framework or an NTIA report as binding law. Do not confuse an FTC consent order (respondent-specific) with a HIPAA regulation (generally applicable). Do not forget state insurance departments when the entity is an insurer.

Loading diagram...
Who Owns Which Privacy Statute
Test Your Knowledge

A privacy manager is mapping each statute to its primary federal owner. Which matching is correct?

A
B
C
D
Test Your Knowledge

After an investigation, the FTC accepts an agreement containing a consent order and places it on the public record. What is the best description of that document's legal status?

A
B
C
D
Test Your Knowledge

A bank holding company, a nationally chartered bank, and a state-chartered nonmember bank all need a GLBA supervisor map. Which statement is accurate?

A
B
C
D