7.3 Privacy Regulations & Compliance Frameworks

Key Takeaways

  • Confidentiality safeguards proprietary corporate information and intellectual property from unauthorized disclosure, whereas Privacy governs the lawful, fair, and transparent collection, processing, retention, and disposal of personal data belonging to living individuals.
  • The EU General Data Protection Regulation (GDPR) enforces extraterritorial jurisdiction, mandates six core data processing principles in Article 5(1) plus a separate accountability obligation in Article 5(2), establishes strict legal bases for processing (Article 6), and imposes severe penalties up to €20 million or 4% of global annual turnover.
  • The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide consumers with explicit rights to opt out of the sale or sharing of personal information, limit the use of Sensitive Personal Information (SPI), and impose statutory breach damages between $100 and $750 per consumer per incident.
  • The HIPAA Security Rule establishes mandatory Administrative, Physical, and Technical safeguards for Electronic Protected Health Information (ePHI), distinguishing between strictly required implementation specifications and addressable specifications that require documented risk evaluation.
  • The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule mandates that financial institutions designate a qualified individual to oversee a formal written Information Security Program, enforce Multi-Factor Authentication, and conduct regular penetration testing and risk assessments.
Last updated: September 2026

Privacy Regulations & Compliance Frameworks

Quick Summary: In modern regulatory compliance and SOC attestation, CPA auditors must maintain a clear distinction between data confidentiality (protecting organizational trade secrets and sensitive intellectual property) and individual privacy (governing personal data rights). This section analyzes major global and domestic privacy frameworks—including GDPR, CCPA/CPRA, HIPAA, and GLBA—detailing regulatory enforcement, statutory consumer rights, technical safeguards, and audit verification procedures under the AICPA Privacy Management Framework.


1. Differentiating Confidentiality and Privacy in Information Security

A frequent trap on the CPA ISC examination is conflating the AICPA Trust Services Criteria for Confidentiality and Privacy:

  • Confidentiality: Protects non-public organizational and business information against unauthorized disclosure. In-scope assets include source code, pending patent applications, financial statement workpapers, corporate acquisition strategies, vendor contracts, and network architecture schemas. Confidentiality agreements (e.g., non-disclosure agreements [NDAs]) are executed between business entities.
  • Privacy: Applies exclusively to Personally Identifiable Information (PII) collected from natural persons (consumers, patients, employees, website visitors). Privacy addresses not merely technical unauthorized access, but whether personal data is collected lawfully, with proper notice and consent, used strictly for stated purposes, maintained accurately, and destroyed when no longer needed.
Criteria DimensionConfidentiality (AICPA TSP CC & C-Series)Privacy (AICPA TSP P-Series)
Subject MatterCorporate intellectual property, trade secrets, financial dataPersonal data / PII of individual living human beings
Governing EntityContractual agreements, corporate policy, trade secret lawsStatutory privacy laws (GDPR, CCPA, HIPAA, GLBA)
Core ProtectionsAccess restriction, encryption, perimeter securityNotice, Choice/Consent, Data Minimization, Access/Deletion
BeneficiaryThe enterprise and its commercial business partnersThe individual consumer, patient, or employee

2. The European Union General Data Protection Regulation (GDPR)

Adopted in April 2016 and applicable from 25 May 2018, Regulation (EU) 2016/679 (GDPR) represents the global benchmark for privacy law, exerting sweeping extraterritorial impact across worldwide corporations. The ISC blueprint limits eligible GDPR content to Articles 4 through 34.

Jurisdictional Reach (Article 3)

GDPR applies not only to entities physically established in the European Economic Area (EEA), but to any organization worldwide that:

  1. Offers goods or services (whether paid or free) to individuals located in the EU.
  2. Monitors the online behavior of individuals located within the EU (e.g., web behavioral tracking, profiling cookies).

The Six Core Processing Principles (Article 5(1)) Plus Accountability (Article 5(2))

The ISC blueprint task reads: "Recall the scope of the GDPR and the six principles and key concepts for personal data." Those six are the principles in Article 5(1). Accountability is set out separately in Article 5(2) as the controller's obligation to demonstrate compliance with the six — which is why some sources count seven. Know the six by name and know that accountability sits one paragraph below them:

  1. Lawfulness, Fairness, and Transparency: Processed lawfully with clear, plain-language notices provided to data subjects.
  2. Purpose Limitation: Collected for specified, explicit, and legitimate purposes; cannot be processed for secondary, incompatible purposes.
  3. Data Minimization: Adequate, relevant, and limited strictly to what is necessary in relation to the stated purposes.
  4. Accuracy: Kept accurate and, where necessary, kept up to date; inaccurate data must be erased or rectified without delay.
  5. Storage Limitation: Kept in a form permitting identification of data subjects for no longer than is necessary for the processing purposes.
  6. Integrity and Confidentiality (Security): Protected by appropriate technical and organizational measures against unauthorized processing, accidental loss, destruction, or damage (e.g., encryption, access control).
  7. Accountability: The controller is responsible for, and must be able to demonstrate compliance with, all principles above.

Legal Bases for Processing (Article 6)

Organizations must establish at least one of six lawful bases prior to processing personal data:

  • Explicit Consent: Freely given, specific, informed, unambiguous agreement indicated by a clear affirmative action (opt-in; pre-ticked boxes are strictly unlawful). Consent can be withdrawn at any time.
  • Contractual Necessity: Necessary to perform a contract with the data subject (e.g., shipping address required to deliver an e-commerce order).
  • Legal Obligation: Necessary to comply with statutory law (e.g., payroll tax reporting).
  • Vital Interests: Necessary to protect the life or physical integrity of an individual.
  • Public Task: Necessary for the performance of a task carried out in the public interest or official authority.
  • Legitimate Interests: Necessary for legitimate business purposes pursued by the controller, provided they do not override the fundamental rights and freedoms of the individual.

Data Subject Rights (Articles 15–22)

Data subjects possess statutory rights that organizations must operationalize within one calendar month:

  • Right of Access (Article 15): Confirmation of processing and copies of personal data.
  • Right to Rectification (Article 16): Correction of inaccurate records.
  • Right to Erasure / "Right to be Forgotten" (Article 17): Permanent deletion of personal data when consent is withdrawn or data is no longer necessary.
  • Right to Data Portability (Article 20): Receiving personal data in a structured, commonly used, machine-readable format (e.g., CSV/JSON).
  • Right to Object (Article 21): Immediate halt of direct marketing and profiling.

Governance & Cross-Border Data Transfers

  • Mandatory Data Protection Officer (DPO): Required if core activities involve regular and systematic monitoring of individuals on a large scale, or large-scale processing of special categories of sensitive data (race, health, biometrics).
  • Data Protection Impact Assessments (DPIAs): Mandatory under Article 35 prior to initiating processing likely to result in high risk (e.g., AI automated decision-making, large-scale surveillance).
  • Cross-Border Transfers: Transfers outside the EEA require an Adequacy Decision by the European Commission, Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or adherence to the EU-U.S. Data Privacy Framework.
  • Penalties: Two tiers of administrative fines: up to €10 million or 2% of global annual turnover for operational infractions; up to €20 million or 4% of global annual turnover (whichever is higher) for core principle violations.

3. California Consumer Privacy Act & California Privacy Rights Act (CCPA / CPRA)

The CCPA (as substantially expanded by the CPRA) is the premier comprehensive state privacy law in the United States.

Applicability Thresholds

Applies to for-profit legal entities doing business in California that meet any one of three criteria:

  1. Annual gross global revenues exceeding the inflation-adjusted revenue threshold — $26,625,000 as adjusted by the CPPA effective January 1, 2025 (the statute still prints the original $25 million baseline, which is updated biennially for CPI).
  2. Annually buys, sells, or shares the personal information of 100,000 or more California consumers or households.
  3. Derives 50% or more of its annual revenues from selling or sharing California consumers' personal information.

Core Consumer Rights & Governance Mandates

  • Right to Opt-Out of Sale and Sharing: Consumers can opt out of the sale or cross-context behavioral advertising sharing of their personal information. Websites must display a clear, conspicuous link titled "Do Not Sell or Share My Personal Information." Organizations must also honor browser-based opt-out preference signals, such as the Global Privacy Control (GPC).
  • Sensitive Personal Information (SPI): CPRA created a heightened classification for SPI (SSNs, driver's licenses, financial account credentials, precise geolocation within 1,850 feet, biometric identifiers, racial origin, health data). Consumers possess the explicit Right to Limit the Use of SPI to necessary services via a link titled "Limit the Use of My Sensitive Personal Information."
  • Private Right of Action for Data Breaches: Consumers can initiate individual or class-action lawsuits if non-encrypted, non-redacted personal information is breached due to an enterprise's failure to maintain reasonable security procedures, awarding statutory damages per consumer per incident within a CPI-adjusted band — currently $107 to $799 against the statutory $100-$750 baseline.
  • Enforcement: Enforced by the dedicated California Privacy Protection Agency (CPPA) with CPI-adjusted administrative fines currently up to $7,988 for an intentional violation and $2,663 for an unintentional one (statutory baselines: $7,500 and $2,500).

4. Health Insurance Portability and Accountability Act (HIPAA)

HIPAA governs Protected Health Information (PHI) across the healthcare ecosystem. It establishes standards through two distinct rules:

Covered Entities (CEs) vs. Business Associates (BAs)

  • Covered Entities: Healthcare providers (hospitals, physicians), health plans (health insurers, HMOs), and healthcare clearinghouses.
  • Business Associates: Third-party vendors that create, receive, maintain, or transmit Electronic Protected Health Information (ePHI) on behalf of a Covered Entity (e.g., cloud hosting providers, claims management software, billing processors, medical transcription services).
  • Business Associate Agreements (BAAs): Legally binding contracts mandating that BAs implement HIPAA-compliant safeguards and report security incidents to the Covered Entity.

Permitted Uses and Disclosures Under the Privacy Rule

The blueprint asks candidates to recall the covered entities and the permitted uses and disclosures. The Privacy Rule's structure is a default prohibition with defined exceptions: a covered entity may not use or disclose protected health information except as the Rule permits or requires, or as the individual authorizes in writing.

Required disclosures (the covered entity must disclose):

  1. To the individual who is the subject of the information, when they request access to or an accounting of disclosures of their own PHI.
  2. To HHS when it is undertaking a compliance investigation, review or enforcement action.

Permitted uses and disclosures without authorization (the covered entity may disclose):

  1. To the individual themselves.
  2. Treatment, payment, and health care operations (TPO) — the core operating exception. Treatment covers care coordination and consultation; payment covers billing, claims, eligibility and collection; operations covers quality assessment, credentialing, training, business planning and general administration.
  3. Opportunity to agree or object — facility directories, and disclosure to family members or others involved in the individual's care, where the individual has been given the chance to object.
  4. Incident to an otherwise permitted use or disclosure, provided reasonable safeguards and the minimum necessary standard are applied.
  5. Twelve public interest and benefit activities, including disclosures required by law; public health activities; victims of abuse, neglect or domestic violence; health oversight activities; judicial and administrative proceedings; law enforcement purposes; decedents, including to coroners and funeral directors; cadaveric organ, eye or tissue donation; research under specified conditions; to avert a serious threat to health or safety; essential government functions; and workers' compensation.
  6. A limited data set for research, public health or health care operations, with direct identifiers removed and a data use agreement in place.

The minimum necessary standard applies to most uses and disclosures: the covered entity must limit PHI to the minimum amount needed for the purpose. It does not apply to disclosures to or requests by a provider for treatment, to the individual, pursuant to the individual's authorization, to HHS for enforcement, or where required by law.

Written authorization is required for anything outside the above — most notably for most uses and disclosures of psychotherapy notes, for marketing, and for any sale of PHI.

Exam trap: candidates commonly assume patient consent is required before a hospital may bill an insurer or consult another physician. It is not. Treatment, payment and health care operations are permitted without authorization, which is exactly why the Rule needs a minimum necessary standard to bound them.

The HIPAA Security Rule: Safeguards Architecture

The Security Rule applies strictly to electronic PHI (ePHI) across three domains. Implementation specifications are designated as either Required (mandatory compliance) or Addressable (must assess whether reasonable and appropriate; if not, implement an equivalent alternative or formally document why):

Safeguard DomainCore FocusKey Implementation Specifications
Administrative SafeguardsPolicies and procedures governing workforce and risk managementSecurity management process (Risk Analysis & Risk Management - Required); Assigned Security Official (Required); Workforce training (Addressable); Contingency plan (Required).
Physical SafeguardsPhysical access restrictions to electronic information systemsFacility access controls (Addressable); Workstation use and security (Required); Device and media controls (Disposal & Media Re-use - Required).
Technical SafeguardsAutomated technology controls protecting data and communicationsAccess control (Unique user ID & Emergency access - Required; Auto logoff - Addressable); Audit controls (Required); Integrity (Addressable); Transmission security (Encryption in transit - Addressable).

5. Gramm-Leach-Bliley Act (GLBA) & The FTC Safeguards Rule

The Gramm-Leach-Bliley Act (GLBA) governs non-public personal information (NPI) held by financial institutions (commercial banks, mortgage lenders, tax preparers, payday lenders, investment advisers).

The Financial Privacy Rule

Mandates that financial institutions deliver clear, initial and annual privacy notices explaining how customer NPI is collected, shared, and protected. Customers must be provided an opt-out mechanism before NPI can be shared with non-affiliated third parties.

The Revised FTC Safeguards Rule Technical Mandates

The modern Safeguards Rule establishes specific technical ITGC controls that financial institutions must enforce:

  1. Qualified Individual: Designate a single qualified individual responsible for overseeing, implementing, and enforcing the information security program.
  2. Multi-Factor Authentication (MFA): Mandatory MFA for any individual accessing customer information systems.
  3. Data Encryption: Mandatory encryption of customer data both at rest and in transit over public networks.
  4. Continuous Monitoring or Testing: Robust monitoring or annual penetration testing coupled with biannual vulnerability assessments.
  5. Board Reporting: The Qualified Individual must provide an annual written report to the Board of Directors detailing overall compliance and incident history.

6. Enterprise Privacy Regulations Comparison Matrix

Regulatory RegimePrimary RegulatorTarget Protected DataMandatory Breach Notification WindowConsumer / Subject Rights ScopeStatutory Non-Compliance Penalties
GDPREU Data Protection Authorities (DPAs)Any personal data relating to identified/identifiable persons72 hours to DPA; without undue delay to subjects if high riskAccess, Rectification, Erasure, Portability, Restriction, ObjectionUp to €20M or 4% of global annual turnover
CCPA / CPRACalifornia Privacy Protection Agency (CPPA)Personal information (PI) and Sensitive PI (SPI) of CA consumersGoverned by CA state breach law (expeditiously without unreasonable delay)Know, Delete, Correct, Opt-Out of Sale/Share, Limit Use of SPICPI-adjusted: up to $7,988 per intentional violation; $107-$799 per consumer private action
HIPAAHHS Office for Civil Rights (OCR)Protected Health Information (PHI / ePHI)60 calendar days from discovery for 500+ individuals (HHS, media, patients)Access records, request accounting of disclosures, request amendmentsTiered civil penalties up to $2+ million annually; criminal penalties for willful fraud
GLBAFTC, SEC, CFPB, State Insurance CommissionersNonpublic Personal Information (NPI) of financial customers30 calendar days to FTC for unauthorized acquisition of 500+ consumersAnnual privacy notice, opt-out of sharing with non-affiliatesFines up to $100,000 per violation for institutions; individual officer liability

7. Auditor Testing of Privacy Controls & AICPA Privacy Criteria

When performing SOC 2 examinations covering the Privacy Trust Services Criteria (or conducting privacy readiness reviews under the AICPA Privacy Management Framework), CPA auditors test specific operational controls:

  • Privacy Notice Accuracy: Inspecting outward-facing privacy policies across websites and mobile apps to confirm that disclosed collection categories, third-party sharing disclosures, and data retention statements align with backend database structures.
  • Choice and Consent Mechanics: Testing consent banners and preference centers to verify that personal data is not collected prior to affirmative opt-in consent (under GDPR), and verifying that Global Privacy Control (GPC) opt-out signals automatically suppress data sharing.
  • Data Subject Request (DSR) Fulfillment: Sampling historical consumer deletion and access requests from ticketing systems to verify that records were scrubbed from production and backup databases within 30-day statutory windows.
  • Third-Party Vendor Oversight: Inspecting executed vendor contracts to verify inclusion of mandatory Data Processing Addendums (DPAs), Standard Contractual Clauses (SCCs), or Business Associate Agreements (BAAs).
Loading diagram...
Privacy Regulatory Governance and Enforcement Architecture
Test Your Knowledge

Under the European Union General Data Protection Regulation (GDPR), which of the following statements accurately characterizes the distinction between a Data Controller and a Data Processor?

A
B
C
D
Test Your Knowledge

Under the HIPAA Security Rule, covered entities and business associates must implement administrative, physical, and technical safeguards. What is the precise regulatory meaning of an implementation specification categorized as "Addressable"?

A
B
C
D
Test Your Knowledge

During a SOC 2 examination, an auditor must evaluate controls under the Trust Services Criteria. Which of the following scenarios describes an audit testing procedure that falls specifically under the Privacy Criteria rather than the Confidentiality Criteria?

A
B
C
D