General Privacy
Student Records
Health Information
Health Information Technology for Economic and Clinical Health Act (HITECH) – Passed as part of American Recovery and Reinvestment Act of 2009 (ARRA), HITECH revises and expands the HIPAA Privacy and Security Rules, adds new breach notification requirements for covered entities and business associates, strengthens the government's enforcement powers, and makes related changes.
Human Subjects Research
Common Rule – The Federal Policy for the Protection of Human Subjects outlines the basic provisions for Institutional Review Boards (IRBs), informed consent, and Assurances of Compliance.
HHS Human Subject Protection Regulations 45 CFR part 46 – The Code of Federal Regulations provides for the protection of human research subjects including that, in order to approve such research, there are adequate provisions to protect the privacy of subjects and to maintain the confidentiality of data.
Financial Information
Gramm-Leach-Bliley Act (GLBA) – This Federal Trade Commission (FTC) law requires financial institutions – companies that offer consumers financial products or services like loans, financial or investment advice, or insurance – to explain their information sharing practices to their customers and to safeguard sensitive data.
Personal Identity Information
Red Flags Rule – This Federal Trade Commission (FTC) Rule requires organizations to develop, document and implement an Identity Theft Prevention Program designed to detect the warning signs (“red flags”) of identity theft in their day-to-day operations.
Electronic Commerce
Online Privacy Protection Act of 2003 – California Business and Professions Code sections 22575-22579. This law requires operators of commercial web sites or online services that collect personal information on California residents through a web site to conspicuously post a privacy policy on the site and to comply with its policy.