2.2 Sources of U.S. Privacy Law

Key Takeaways

  • The Fourth Amendment limits government searches and seizures; it does not, by itself, constrain a purely private employer that is not a state actor.
  • The four common-law privacy torts are intrusion upon seclusion, public disclosure of private facts, false light, and appropriation of name or likeness.
  • In a privacy program, the hierarchy is Constitution, then statute, then valid regulation or rule, then nonbinding guidance; contracts and common-law duties can still apply alongside those public-law sources.
  • A privacy notice or vendor contract can create independently enforceable promises, and breaking a public privacy promise can also be a deceptive practice under FTC Act Section 5.
  • Case law interprets statutes and the Constitution and develops common law; it is not a substitute for an enacted statute or a generally applicable regulation.
Last updated: August 2026

2.2 Sources of U.S. Privacy Law

BoK 2.6.1 I.A tells you to understand constitutions, legislation, regulations and rules, case law, common law, and contract law. The exam move is not reciting the list. It is ranking the sources when they pull in different directions and knowing which source even applies to a private company.

Constitutions, especially the Fourth Amendment

The U.S. Constitution is the supreme federal law. For privacy professionals, the provision that appears most often is the Fourth Amendment, which protects the people against unreasonable searches and seizures by the government and generally requires a warrant supported by probable cause when a search occurs. Landmark cases you should be able to place — Katz v. United States (reasonable expectation of privacy), Carpenter v. United States (cell-site location information) — are judicial interpretations of that constitutional text.

The exam trap is audience. The Fourth Amendment binds government actors: police, public universities, public hospitals, and other state actors. It does not, by itself, require a purely private employer to get a warrant before reviewing work email, badge logs, or a company laptop. A private retailer that reads an employee's Slack messages is not conducting a Fourth Amendment search. A city police department that seizes the same laptop is. Public employers can face Fourth Amendment workplace-search claims under a reasonableness standard (O'Connor v. Ortega), but that is still government action.

State constitutions can be more protective than the federal floor. California's constitutional privacy clause, for example, has been applied more broadly than the Fourth Amendment. A privacy program for a government contractor or a public university must therefore read both constitutions. A purely private employer still looks first to statutes, rules, contracts, and common-law torts — not to the Fourth Amendment.

Legislation, regulations, and rules

Legislation is the enacted statute. Federal examples include the FTC Act, HIPAA, GLBA, FCRA, COPPA, and TCPA. State examples include the CCPA/CPRA and Virginia's CDPA. Statutes define coverage, exemptions, remedies, and preemption.

Regulations and rules are the executive branch's implementing text, issued under a statutory delegation and usually through APA notice and comment. HIPAA's Privacy, Security, and Breach Notification Rules live in 45 C.F.R. Parts 160 and 164. The CFPB's Regulation P implements the GLBA Privacy Rule for many financial institutions. The FTC's COPPA Rule implements COPPA. A valid regulation has the force of law for covered parties, but it cannot contradict the statute that authorized it, and a court may set it aside.

Guidance, advisory opinions, FAQs, and staff blogs are not regulations. They tell you how an agency is likely to exercise discretion. They help a privacy program, and ignoring them is often unwise, but they do not outrank a conflicting statute or a contrary holding from a court of appeals. If an HHS OCR FAQ and the HIPAA regulatory text diverge, the regulation wins unless a court says otherwise.

Case law and common law

Case law is the body of judicial opinions that interpret constitutions, statutes, and regulations and that resolve disputes. A Supreme Court privacy decision binds every federal court. A federal court of appeals decision binds district courts in that circuit. State high-court decisions bind lower state courts on state-law questions. Case law is how you know that HIPAA has no general private right of action, that the Fourth Amendment does not reach a private employer, and that the Airline Deregulation Act can sweep in generally applicable consumer-protection claims.

Common law is judge-made law that does not start as a statute. U.S. privacy common law is organized around Dean William Prosser's four torts, later reflected in the Restatement (Second) of Torts:

TortCore elementsClassic privacy-program fact pattern
Intrusion upon seclusionIntentional intrusion into a private place, conversation, or matter that would be highly offensive to a reasonable personHidden camera in an employee changing room; secretly recording a private medical call
Public disclosure of private factsPublicity of private facts that are not of legitimate public concern and that would be highly offensivePosting an employee's medical diagnosis to a public blog
False lightPublicity that places the person in a false light that would be highly offensive (not recognized in every state)A marketing page that pairs a customer's photo with a fabricated testimonial
AppropriationUse of another's name or likeness for commercial advantage without consentSelling a customer face scan to advertise a product the customer never endorsed

These torts matter on the exam because sectoral federal statutes do not occupy every fact pattern. A company that is not a HIPAA covered entity can still commit intrusion. A company that complied with a thin privacy notice can still face public-disclosure liability if it broadcasts medical details. False light is the trap option: several states have rejected it, so a national program cannot assume it exists everywhere.

Contract law

Contract law turns promises into duties. Privacy programs live on contracts: website terms and privacy notices (when they are actually bargained or incorporated), employee handbook acknowledgments, vendor data processing agreements, service-level commitments, and clickwrap consents. A contract can be more protective than the background statute. It can also create liability where no statute gives a private right of action.

Two exam connections follow. First, breaking a public privacy promise — "we never sell your data" — can be a deceptive practice under FTC Act Section 5 even if no customer sues in contract. Second, a vendor contract is often the only practical way to pass through HIPAA business associate, GLBA, or state-processor duties. The contract does not repeal the statute; it allocates and operationalizes the statute.

Hierarchy and how the sources interact in a program

Use this stack when two documents disagree:

  1. Constitution (federal, then more protective state constitutions for government actors).
  2. Statute (federal, then state, subject to preemption analysis in the next section).
  3. Valid regulation or rule implementing that statute.
  4. Case law interpreting 1–3, including common-law torts.
  5. Contractual commitments the organization actually made.
  6. Guidance, codes of conduct, and playbooks — operationally important, legally last.

A privacy program therefore maps each processing activity to every applicable layer. A hospital that is a HIPAA covered entity still reads more-stringent state medical-privacy statutes, still honors its notice of privacy practices as a set of promises, and still faces common-law intrusion if a nurse secretly records a patient. A private software employer does not start with the Fourth Amendment; it starts with state workplace-privacy statutes, the Electronic Communications Privacy Act if it intercepts communications, its employee notice, and intrusion/public-disclosure risk.

Worked scenario. A private fitness-app company posts, "We will never share health metrics with advertisers." Engineering later sends identifiable heart-rate streams to an ad platform. There is no Fourth Amendment claim — the company is not the government. There may be a contract claim if the notice formed a promise, a Section 5 deception theory at the FTC, a public-disclosure or intrusion theory if the facts are highly offensive and private, and, if the company is in scope, a state comprehensive privacy statute enforced by an attorney general. None of those sources cancels the others. The program must satisfy the most demanding applicable duty on each element — notice, sharing, security, and individual rights.

Exam traps. Do not apply the Fourth Amendment to a private employer's ordinary monitoring. Do not treat an OCR FAQ as if it repealed a regulation. Do not assume a privacy policy is "just a statement" with no legal effect. Do not collapse common law into a single "privacy tort" — the exam can ask which of the four fits the facts.

Loading diagram...
Hierarchy of U.S. Privacy-Law Sources
Test Your Knowledge

A purely private retailer reads an employee's work email on a company server after giving notice that workplace systems are monitored. The employee claims a Fourth Amendment violation. What is the best CIPP/US analysis?

A
B
C
D
Test Your Knowledge

Counsel is classifying possible common-law claims after a company used a customer's photograph in a national advertisement without consent. Which statement correctly identifies the Prosser privacy torts?

A
B
C
D
Test Your Knowledge

A privacy program finds a conflict among a federal statute, an agency staff FAQ, a vendor contract, and a court of appeals decision interpreting the statute. Which ranking reflects the U.S. sources-of-law hierarchy?

A
B
C
D