CPA (ISC) • SECURITY AND CONFIDENTIALITY

Apply Data Privacy Principles And Regulations

Understanding how organizations safeguard personal data through regulatory compliance, privacy frameworks, and systematic controls.

Historical Context & Motivation

The concept of data privacy did not emerge in a vacuum; it evolved over more than a century as technological capabilities outpaced society's ability to protect personal information. The earliest legal articulation of a privacy right appeared in 1890 when Samuel Warren and Louis Brandeis published their seminal Harvard Law Review article arguing that individuals possess a 'right to be let alone.' While that framing was fundamentally about tort law rather than data governance, it established the philosophical bedrock upon which every modern data privacy regulation rests. For CPA candidates working in the Information Systems and Controls (ISC) discipline, understanding this trajectory is essential because audit and assurance engagements increasingly require evaluating whether an organization's controls satisfy overlapping—and sometimes conflicting—privacy mandates.

As mainframe computing became prevalent in the 1960s and 1970s, governments recognized that large-scale data processing posed new threats to individual autonomy. The Fair Information Practice Principles (FIPPs) were codified in 1973 by the U.S. Department of Health, Education, and Welfare, providing a framework that still underpins many contemporary regulations. Europe took a more prescriptive route, adopting the OECD Privacy Guidelines in 1980 and later the EU Data Protection Directive in 1995. The explosion of internet commerce and cloud computing in the early 2000s created enormous repositories of personally identifiable information, magnifying risk and prompting a new generation of laws—most notably the General Data Protection Regulation (GDPR) in 2018 and the California Consumer Privacy Act (CCPA), which took effect January 1, 2020 (with enforcement beginning July 1, 2020).

1973
Fair Information Practice Principles (FIPPs)
The U.S. HEW Advisory Committee published FIPPs, establishing core tenets—notice, consent, access, security, and accountability—that remain foundational to privacy law worldwide.
1980
OECD Privacy Guidelines
The Organisation for Economic Co-operation and Development issued guidelines on transborder data flows, creating the first internationally recognized privacy framework and heavily influencing European legislation.
1996
HIPAA Enacted
The Health Insurance Portability and Accountability Act introduced sector-specific privacy and security rules for protected health information (PHI) in the United States, setting a precedent for industry-specific regulation.
2018
EU GDPR Takes Effect
The General Data Protection Regulation replaced the 1995 Directive, introducing extraterritorial scope, data subject rights, mandatory breach notification, and fines up to 4% of global annual revenue.
2020
CCPA / CPRA Era
California's Consumer Privacy Act took effect January 1, 2020 (enforcement began July 1, 2020), granting consumers rights to know, delete, and opt out of data sales. The California Privacy Rights Act (CPRA) was passed as a ballot initiative in November 2020 and took effect January 1, 2023, significantly expanding CCPA protections and catalyzing similar legislation in over a dozen U.S. states.

The central question this lesson addresses is both practical and strategic: how does a CPA or information systems professional design, evaluate, and attest to privacy controls that satisfy a complex web of overlapping regulations while still enabling the organization to derive legitimate business value from data? Answering that question requires mastering the foundational principles, mapping them to specific regulatory requirements, and understanding how privacy-related controls integrate with broader internal control frameworks such as SOC 2®.

Core Privacy Principles & Definitions

Data privacy principles are not merely abstract ideals; they form the operational backbone of every privacy program and directly map to controls that CPAs evaluate during SOC 2® engagements and regulatory compliance audits. The AICPA Trust Services Criteria (TSC) organizes the Privacy category around the Generally Accepted Privacy Principles (GAPP), which distill decades of regulatory thinking into ten principles: (1) Management, (2) Notice, (3) Choice and Consent, (4) Collection, (5) Use, Retention and Disposal, (6) Access, (7) Disclosure to Third Parties, (8) Security for Privacy, (9) Quality, and (10) Monitoring and Enforcement. These ten principles are directly examinable on the ISC section. The five cards below highlight key groupings; all ten principles are elaborated in the surrounding discussion.

1

Notice & Choice and Consent (GAPP 2 & 3)

Organizations must inform data subjects about what personal data is collected, how it will be used, and with whom it will be shared before or at the time of collection (Notice). Choice and Consent means individuals can opt in or opt out of specific processing activities.
2

Collection, Use, Retention and Disposal (GAPP 4 & 5)

Data should only be collected for specified, legitimate purposes and limited to what is necessary (purpose limitation and data minimization). Use must conform to the stated purposes, and data must be retained only as long as needed before secure disposal. Under GDPR's Article 5, these are enforceable legal obligations; under GAPP, they are guiding design principles for internal controls.
3

Access & Disclosure to Third Parties (GAPP 6 & 7)

Individuals have the right to access their personal data, request corrections, and—under some laws—demand erasure (the 'right to be forgotten'). Organizations must also manage and disclose what personal data is shared with third parties and ensure those parties provide equivalent protections.
4

Security for Privacy & Quality (GAPP 8 & 9)

Personal data must be protected against unauthorized access, disclosure, alteration, and destruction through administrative, technical, and physical controls (Security for Privacy). Quality requires that personal data be accurate, complete, and relevant for its intended purpose.
5

Management & Monitoring and Enforcement (GAPP 1 & 10)

A designated individual (e.g., Data Protection Officer) must be accountable for the privacy program (Management). The organization must monitor compliance, conduct privacy impact assessments, maintain documentation sufficient for audit, and enforce privacy policies and procedures (Monitoring and Enforcement).
KEY TAKEAWAY
Think of privacy principles like the terms of a landlord-tenant lease agreement. The landlord (the organization) can only enter the apartment (use personal data) for stated purposes, must give advance notice, and must keep the unit secure. If the tenant (data subject) asks for an inspection or wants to move out, the landlord must honor those requests. Violating the lease results in penalties—just as violating privacy regulations triggers fines and reputational damage.

Key definitions that CPA candidates must internalize include Personally Identifiable Information (PII), which is any data that can identify a specific individual—name, Social Security number, biometric data, or even an IP address when combined with other data elements. Data controller refers to the entity that determines the purposes and means of processing, while the data processor processes data on behalf of the controller. The distinction matters enormously for compliance because controllers bear primary regulatory liability, and the CPA must evaluate whether the organization has adequate vendor management controls over its processors.

The AICPA Trust Services Criteria (TSC) Privacy category—drawn from the 2017 TSC framework (updated 2022)—maps each of the ten GAPP principles to numbered P-series criteria (P1 through P8) that are directly tested in SOC 2® engagements. The eight P-criteria and their GAPP alignments are: P1 — Privacy Notice (GAPP: Notice); P2 — Choice and Consent (GAPP: Choice and Consent); P3 — Collection (GAPP: Collection); P4 — Use, Retention and Disposal (GAPP: Use, Retention and Disposal); P5 — Access (GAPP: Access); P6 — Disclosure and Notification (GAPP: Disclosure to Third Parties; also addresses breach notification obligations); P7 — Quality (GAPP: Quality); and P8 — Monitoring and Enforcement (GAPP: Monitoring and Enforcement; encompasses Management and Security for Privacy governance elements). When performing or reviewing a SOC 2® examination that includes the Privacy category, the CPA must evaluate the entity's controls against each applicable P-criterion, document the criteria addressed, and conclude on whether controls are suitably designed and operating effectively.

Visual Explanation — The Data Privacy Control Framework

The following diagram illustrates how privacy principles translate into a layered control framework. At the top, regulatory requirements from multiple jurisdictions feed into the organization's privacy governance layer. The governance layer, overseen by a Data Protection Officer or equivalent, establishes policies and procedures that cascade into three categories of controls—administrative, technical, and physical. Each control category ultimately protects the data lifecycle from collection through disposal.

The framework shows how multiple regulatory inputs (GDPR, CCPA, HIPAA, GLBA) converge into a unified privacy governance layer. The governance layer distributes requirements to three control categories—administrative, technical, and physical—which collectively safeguard the data lifecycle from collection through disposal.

Notice how the regulatory layer at the top is jurisdiction-specific, while the control categories below are universal. This architecture is deliberate: a well-designed privacy program abstracts regulatory requirements into common control objectives so that a single set of controls can satisfy multiple regulations simultaneously. The CPA's role during an ISC engagement is to test whether each control is designed effectively (addresses the relevant criteria) and operating effectively (functions as intended over the examination period).

How Privacy Regulations Work — Mechanisms & Requirements

While data privacy is not inherently a mathematical discipline, CPA candidates must understand the quantitative dimensions of privacy risk management. Organizations use Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) to evaluate whether a new processing activity creates unacceptable risk. These assessments follow a structured methodology that, at its core, resembles the risk assessment frameworks familiar from audit theory.

PRIVACY RISK SCORE
Risk Score = Likelihood of Privacy Incident × Impact Severity × Data Sensitivity Weight
Where Likelihood is scored 1–5 based on threat frequency and vulnerability, Impact Severity is scored 1–5 considering regulatory fines, reputational harm, and harm to individuals, and Data Sensitivity Weight ranges from 1.0 (non-sensitive) to 3.0 (special categories such as health or biometric data under GDPR Article 9).
MAXIMUM GDPR FINE CALCULATION
Maximum Fine = max(€20,000,000, 0.04 × Annual Global Revenue)
GDPR Article 83(5) prescribes the greater of €20 million or 4% of worldwide annual turnover for the most serious infringements (e.g., violating data subject rights or lawful basis requirements). The notation 'max(A, B)' means whichever value is larger applies — so the fine equals €20,000,000 if that exceeds 4% of global revenue, and equals 4% of global revenue if that amount is larger. Lower-tier violations (Article 83(4)) cap at €10 million or 2% of turnover, whichever is greater.

Beyond risk scoring, the mechanism by which regulations operate involves several procedural requirements that CPAs must evaluate. Lawful basis for processing under GDPR requires that every data processing activity be justified by one of six legal grounds: consent, contractual necessity, legal obligation, vital interests, public task, or legitimate interests. The CPA examines whether the organization has documented its lawful basis for each processing activity in a Record of Processing Activities (ROPA) as mandated by GDPR Article 30. Failure to maintain an adequate ROPA is itself a compliance deficiency.

Breach notification requirements illustrate another operational mechanism. Under GDPR, a data controller must notify the supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to individuals' rights. The CCPA does not prescribe a specific notification window but requires notification 'in the most expedient time possible.' HIPAA's Breach Notification Rule has a tiered notification structure: covered entities must notify affected individuals and the HHS Secretary within 60 days of discovering the breach. For breaches affecting 500 or more residents of a state or jurisdiction, the covered entity must also notify prominent media outlets in that state or jurisdiction within the same 60-day window. For smaller breaches involving fewer than 500 individuals, covered entities may report to HHS on an annual basis (within 60 days of the end of the calendar year in which the breach was discovered) rather than immediately — a critical distinction for compliance planning. For the CPA, the audit procedure involves examining the organization's incident response plan and testing whether prior incidents were escalated and reported within the required timeframes for each applicable regulatory tier.

💡 CPA Exam Tip
On the ISC section, you may encounter scenarios requiring you to identify which regulation applies based on the type of data, the data subject's location, and the organization's industry. Remember: GDPR applies to any entity processing data of EU residents regardless of where the entity is located (extraterritorial scope), whereas HIPAA applies specifically to covered entities and business associates handling protected health information.

Detailed Regulatory Breakdown & Classification

CPA candidates must navigate a complex regulatory landscape where multiple laws may apply to a single organization simultaneously. A multinational bank, for example, could be subject to GDPR for its European customers, CCPA for California residents, Gramm-Leach-Bliley Act (GLBA) requirements for nonpublic personal financial information, and various state breach notification statutes. The table below provides a comparative classification of the major regulations most relevant to finance professionals.

Comparison of major privacy and data protection regulations relevant to finance professionals
RegulationJurisdiction / ScopeKey Data TypesEnforcement / Penalties
GDPREU / EEA residents; extraterritorial reachAll personal data; special categories (health, biometric, racial)Up to €20M or 4% global revenue; supervisory authorities
CCPA / CPRACalifornia residents; businesses meeting revenue/data thresholdsPersonal information broadly defined; includes household data$2,500 per violation (unintentional); $7,500 per violation (intentional); private right of action for breaches
HIPAAU.S. covered entities and business associatesProtected Health Information (PHI)$100–$50,000 per violation; max $1.5M/year per category; criminal penalties possible
GLBAU.S. financial institutionsNonpublic personal financial information (NPI)FTC, OCC, SEC enforcement; institution fines up to $100,000 per violation; individual fines up to $10,000 per violation (note: these figures reflect statutory baselines and may be adjusted upward by regulators under inflation-adjustment authority)
SOX (Section 302/404)U.S. publicly traded companiesFinancial data integrity; indirectly protects PII in financial systemsSEC enforcement; criminal penalties for executives certifying false statements
This decision tree helps determine which regulation(s) apply to a given data processing activity. In practice, multiple branches may be triggered simultaneously—for instance, an EU resident's health data processed by a U.S. financial institution could invoke GDPR, HIPAA, and GLBA simultaneously.

A critical distinction for finance professionals is the difference between sectoral and comprehensive privacy regulation. The United States primarily uses a sectoral approach—HIPAA for healthcare, GLBA for finance, FERPA for education, COPPA for children's data—meaning that gaps exist where no specific law governs a particular data type or industry. In contrast, the GDPR and CCPA adopt a comprehensive approach that covers all personal data regardless of sector. The CPA evaluating an organization's compliance posture must identify all applicable regulations through a regulatory mapping exercise and verify that the control environment addresses each requirement.

Worked Example — Privacy Compliance Assessment

Consider the following scenario: Pinnacle Financial Services, a U.S.-based fintech company, offers digital lending products to consumers in California, New York, and Germany. Pinnacle collects Social Security numbers, credit scores, income data, and device identifiers. The company uses a third-party cloud provider to host its application and shares anonymized loan performance data with a credit analytics firm. You are engaged to assess Pinnacle's privacy compliance as part of a SOC 2® Type II examination.

Privacy Compliance Assessment for Pinnacle Financial Services
1
Step 1 — Identify Applicable RegulationsBecause Pinnacle processes data of California residents, the CCPA/CPRA applies (assuming Pinnacle meets the revenue or data-volume thresholds). As a financial institution, Pinnacle is subject to the GLBA Safeguards Rule and Privacy Rule. Because it processes personal data of German residents, GDPR applies under its extraterritorial reach (Article 3). State breach notification laws in California and New York also apply.
Applicable: CCPA/CPRA, GLBA, GDPR, state breach notification laws
2
Step 2 — Map Data Flows and Identify PIICreate a data inventory documenting each category of personal data collected (SSNs, credit scores, income, device IDs), the lawful basis for processing under each regulation, the data flow from collection through the cloud provider to the analytics firm, and retention periods. Under GDPR, device identifiers are personal data; the 'anonymized' data shared with the analytics firm must be tested to confirm true anonymization versus mere pseudonymization—if re-identification is possible, GDPR processing requirements still apply.
Data inventory and flow map completed; pseudo-anonymized data flagged for additional testing
3
Step 3 — Evaluate Privacy Notices and Consent MechanismsReview Pinnacle's privacy policy for completeness: Does it disclose all categories of PII collected? Does it identify the purposes and legal bases? For GDPR data subjects, is consent obtained via affirmative opt-in (not pre-checked boxes)? For CCPA, does the 'Do Not Sell or Share My Personal Information' link appear on the homepage? Under GLBA, has Pinnacle provided initial and annual privacy notices to all customers?
Finding: Privacy notice lacks GDPR-required lawful basis disclosure for German users — remediation recommended
4
Step 4 — Test Security SafeguardsExamine the technical and administrative controls protecting PII: Is data encrypted at rest (AES-256) and in transit (TLS 1.2+)? Is role-based access control implemented for SSN and income fields? Does the cloud provider agreement include GDPR-compliant data processing terms (Article 28)? Has Pinnacle conducted a DPIA for its high-risk lending algorithm? Review access logs to confirm that only authorized personnel accessed sensitive fields during the audit period.
Controls tested: encryption, RBAC, vendor DPA, DPIA — DPIA not yet completed for lending algorithm
5
Step 5 — Assess Data Subject Rights Processes and Breach ResponseVerify that Pinnacle has operationalized data subject rights: Can consumers submit access, deletion, and opt-out requests? Is the identity verification process adequate to prevent unauthorized disclosures? Review the incident response plan for compliance with GDPR's 72-hour notification requirement and California's expedient notification standard. Test a sample of prior requests and incidents for timeliness and completeness. Calculate the privacy risk score for the organization: if Likelihood = 3, Impact = 4, and Data Sensitivity Weight = 2.0 (financial PII), the Risk Score = 3 × 4 × 2.0 = 24, indicating a high-risk profile requiring enhanced monitoring.
Risk Score = 24 (High); incident response plan adequate but DPIA gap must be remediated

Strengths, Limitations & Comparative Analysis

No privacy framework is perfect, and the CPA must understand both the strengths and limitations of different regulatory approaches to provide informed advice. The comprehensive model (exemplified by GDPR) offers broad protection but creates significant compliance overhead, particularly for multinational organizations. The sectoral model (characteristic of U.S. law) allows tailored requirements but leaves regulatory gaps and creates a fragmented compliance landscape. The table below summarizes key strengths and limitations.

Comprehensive vs. Sectoral privacy regulation approaches
DimensionComprehensive Approach (e.g., GDPR)Sectoral Approach (e.g., U.S. model)
Coverage BreadthAll personal data types covered uniformly; no gaps by sectorTargeted protection for specific sectors; potential gaps for unregulated industries
Compliance CostHigh—requires DPO, DPIAs, ROPA, broad consent mechanismsVariable—lower for non-regulated sectors; high for entities subject to multiple laws
Regulatory ConsistencySingle framework simplifies cross-border compliance within the EUFragmented—different definitions, thresholds, and penalties across statutes
Enforcement StrengthStrong—supervisory authorities with significant penalty powerMixed—strong in finance (GLBA/SOX) and health (HIPAA); weaker in other areas
FlexibilityLess flexible—prescriptive requirements may not fit all business modelsMore flexible—industry-specific rules can adapt to sector needs
KEY TAKEAWAY
Think of privacy regulation like building codes for a city. A comprehensive code (GDPR) sets uniform standards for every building—residential, commercial, industrial—ensuring consistent safety. A sectoral code (U.S. model) might have strict rules for hospitals and banks but leave warehouses unregulated. The CPA's job is akin to the building inspector: you must know which codes apply to which structures and verify that the construction meets or exceeds the applicable standard. Neither approach is inherently superior; the CPA must work within the regulatory reality of each engagement.

Connection to Advanced Theory — Privacy by Design & Emerging Trends

The foundational principles and regulatory mechanisms discussed in earlier sections represent the current state of data privacy compliance. However, the field is evolving rapidly, and CPA candidates should be aware of advanced concepts that are increasingly appearing in professional practice and on examinations. Privacy by Design (PbD), originally articulated by Dr. Ann Cavoukian in the 1990s and now codified in GDPR Article 25, requires organizations to embed privacy protections into the architecture of systems and business processes from the outset rather than retrofitting controls after deployment. This proactive approach represents a paradigm shift from compliance-driven privacy to engineering-driven privacy.

Current vs. emerging practices in data privacy
ConceptCurrent PracticeEmerging / Advanced Practice
Consent ManagementCookie banners, privacy policy acknowledgments, opt-out linksConsent orchestration platforms, preference centers with granular opt-in/out, machine-readable consent signals (Global Privacy Control)
Data ProtectionEncryption at rest and in transit, access controls, pseudonymizationDifferential privacy, homomorphic encryption, secure multi-party computation enabling analytics without exposing raw PII
Cross-Border TransfersStandard Contractual Clauses (SCCs), Privacy Shield (invalidated)EU-U.S. Data Privacy Framework, Transfer Impact Assessments, data localization requirements
AI & Automated DecisionsGDPR Article 22 right not to be subject to solely automated decisionsEU AI Act risk classifications, algorithmic auditing requirements, explainability standards for AI-driven credit decisions

For CPA candidates specializing in the ISC discipline, the intersection of artificial intelligence and privacy is particularly significant. Financial institutions increasingly use machine learning models for credit scoring, fraud detection, and customer segmentation. Under GDPR Article 22, data subjects have the right not to be subject to decisions based solely on automated processing that produce legal effects. The forthcoming EU AI Act will impose additional requirements on 'high-risk' AI systems, including those used in creditworthiness assessments. CPAs will need to evaluate whether organizations have conducted algorithmic impact assessments and implemented human-in-the-loop safeguards. These developments underscore that data privacy is not a static compliance exercise but a continuously evolving discipline.

🔮 Looking Ahead
As of 2024, over 15 U.S. states have enacted comprehensive privacy laws (Texas, Oregon, Montana, and others joining California, Virginia, Colorado, Connecticut, and Utah). A federal privacy bill remains under discussion. CPA professionals should monitor the American Data Privacy and Protection Act (ADPPA) and similar proposals, as federal preemption could fundamentally reshape the compliance landscape.

Practice Problems

1
Which of the following best describes the principle of 'data minimization' as it relates to data privacy regulations?
2
Under the General Data Protection Regulation (GDPR), organizations must notify the relevant supervisory authority of a personal data breach within a specified time frame after becoming aware of the breach. An organization discovers a data breach on Monday at 2:00 PM. What is the latest deadline by which the organization must report the breach to the supervisory authority?
3
A CPA firm provides tax preparation services and collects clients' Social Security numbers, income information, and banking details. Under which circumstance would the firm most likely be required to conduct a Data Protection Impact Assessment (DPIA)?
4
A publicly traded company subject to both the California Consumer Privacy Act (CCPA) and SOC 2 Trust Services Criteria receives a verified consumer request to delete all personal information. The company determines that certain personal information is needed to complete an ongoing financial audit. Which of the following is the most appropriate course of action?
5
A multinational corporation headquartered in the United States has subsidiaries in the European Union. The company transfers personal data of EU employees to its U.S. headquarters for payroll processing. Following the invalidation of the EU-U.S. Privacy Shield framework, the company implemented Standard Contractual Clauses (SCCs) as its data transfer mechanism. During a routine compliance review, the company discovers that U.S. government surveillance laws may allow access to the transferred personal data without adequate safeguards equivalent to those in the EU. Which of the following actions best demonstrates the company's compliance with GDPR cross-border data transfer requirements?

Lesson Summary

Data privacy is a multifaceted discipline that requires CPA professionals to master both foundational principles and specific regulatory requirements. The core principles—notice, choice and consent, collection, use/retention/disposal, access, disclosure to third parties, security for privacy, quality, management, and monitoring and enforcement—represent the ten GAPP principles that originate from the Fair Information Practice Principles (FIPPs) and are operationalized through the AICPA's Generally Accepted Privacy Principles (GAPP) and the Trust Services Criteria Privacy criteria P1–P8. Key regulations include GDPR (extraterritorial, comprehensive, fines up to 4% of global revenue), CCPA/CPRA (CCPA effective January 1, 2020; CPRA passed November 2020 and effective January 1, 2023), HIPAA (health data; tiered breach notification with 60-day window for individuals and HHS, plus media notice for breaches affecting 500+ state residents, and annual HHS reporting for smaller breaches), and GLBA (financial data).

The CPA's role is to evaluate whether an organization's administrative, technical, and physical controls are both designed and operating effectively to protect the data lifecycle from collection through disposal. This involves conducting regulatory mapping, testing privacy risk assessments, verifying breach notification compliance, and evaluating data subject rights processes. As the field advances toward Privacy by Design, AI governance, and emerging state and federal legislation, the CPA must remain current to deliver meaningful assurance over privacy controls.

Varsity Tutors • CPA (ISC) • Apply Data Privacy Principles And Regulations