US Privacy in Practice
An audio course on the privacy law that applies to US businesses, with a guide, a one-page map and a self-check for each of its four parts, and a glossary. Written as review material after our classroom course. Study material, not legal advice.
Listen while driving or commuting: subscribers of the podcast's paid tier get every episode in their podcast app.
4 parts, 13 episodes, 3 h 28 min of audio. Each part also has a guide, a one-page map and a self-check, and the course has a glossary.
Sample: the opening of Part I
The opening of the series and its first scene, in which a fictional company asks its new privacy lead which privacy law it has to follow.
about 2 min
Premium Content
Subscribe to unlock this course and all premium privacy training content.
Part I
Who makes the rules?
Covers: Privacy concepts, the sources of US law, the sectoral model, the FTC and Section 5, state attorneys general, self-regulation.
Episode 1. What privacy means
What privacy means, and the vocabulary you need before any law makes sense.
22:09Episode 2. Where US law comes from
Where US law comes from, how federal and state law fit together, and the different ways a company can end up in court.
19:33Episode 3. Who enforces the rules
Who enforces the law, how, and where enforcement is heading.
30:06
- Part I guide (PDF)
- Part I one-page map (PDF)
- Part I self-check (PDF)
Part II
Which law applies to this data?
Covers: Health, financial and credit, children, students, calls and messages, employees, and the records with their own law.
Episode 1. Finding the law and health data
How to find the law that applies to a set of data in front of you, and then health data.
18:09Episode 2. Money, credit and identity
The financial laws: reports about people, customer data at financial institutions, and the reporting rules that require disclosure rather than restrict it.
14:42Episode 3. Children, students and marketing
Children online, student records, and the rules that follow the marketing channel.
14:21Episode 4. Employees and other records
Privacy at work, then a short tour of four laws that attach to particular records, and the recap for Part II.
20:12
- Part II guide (PDF)
- Part II one-page map (PDF)
- Part II self-check (PDF)
Part III
What do the states require?
Covers: The twenty comprehensive state laws, breach notification, security, disposal and the state sector laws.
Episode 1. The comprehensive state laws
The comprehensive state laws: the layer where most American privacy work now happens.
13:49Episode 2. When data is lost
What counts as a breach, who must be told, by when, how, and what happens if you are late.
10:16Episode 3. Security, disposal and the state sector laws
Two quiet families of state law, security and disposal, then the sector laws that have produced the largest privacy payments in American history.
10:42
- Part III guide (PDF)
- Part III one-page map (PDF)
- Part III self-check (PDF)
Part IV
When pressure comes
Covers: The privacy programme, vendors, incidents, government and court demands, and data leaving the country.
Episode 1. Running the privacy programme
What a privacy professional does with the law, on ordinary days and on bad ones.
11:57Episode 2. When the government or a court asks
How to read a demand for data from the government or a court: what kind of paper it is, and what the law says about it.
12:39Episode 3. Data leaving the country
The few bases on which European law lets personal data leave for the United States, and the close of the series.
9:20
- Part IV guide (PDF)
- Part IV one-page map (PDF)
- Part IV self-check (PDF)
Glossary
The terms used across the course, each tagged with the part where it is explained.
- Glossary (PDF)