Jason Edwards
Certified - CIPP/US Audio Course
The CIPP/US Audio Course is your complete, audio-first companion for mastering the Certified Information Privacy Professional – United States (CIPP/US) certification. Designed for learners who want structured, on-the-go preparation, this Audio Course transforms the IAPP Body of Knowledge into clear, engaging, and easy-to-follow episodes. Each lesson unpacks the foundations of U.S. privacy law—from federal and state frameworks to workplace regulations and cross-border data principles—helping you connect legal theory to real-world application. Whether you’re commuting, exercising, or reviewing b...
Author
Jason Edwards
Category
Podcast website
Latest episode
Oct 14, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 97 — Cross-Domain Comparison: Federal, State, and International Overlaps 08.09.2025 26:50
The final episode ties everything together by comparing U.S. federal privacy laws, state-level frameworks, and international regimes like the GDPR. We’ll highlight how similar principles—such as data subject rights, accountability, and security safeguards—take different forms across jurisdictions. We’ll also explore where overlaps create synergies and where conflicts require careful navigation, su...
Episode 96 — Recent Changes: Pennsylvania SB 696 and Utah S.B. 127 08.09.2025 28:22
State privacy laws continue to evolve. This episode reviews recent changes, such as Pennsylvania SB 696, which updated breach notification requirements, and Utah S.B. 127, which amended cybersecurity provisions. These examples show how states adapt their frameworks to address new threats and policy priorities. For exam purposes, understanding recent changes demonstrates that privacy law is a movin...
Episode 95 — State Variations: Comparing Notification Timelines and Duties 08.09.2025 21:52
Even within the common framework of breach notification, state differences matter. This episode compares notification timelines, which can range from “without unreasonable delay” to fixed deadlines like 30 or 45 days. We’ll also examine variations in whom to notify, from affected consumers to regulators and credit reporting agencies. Understanding these nuances is critical for compliance and for a...
Episode 94 — Breach Notification: Definitions, Triggers, and Scope 08.09.2025 22:25
State breach notification laws form one of the most uniform yet varied areas of privacy law. This episode reviews the common elements—definitions of personal information, what constitutes a breach, and when notification is required. We’ll also explore differences across states, such as timelines, thresholds, and required content of notices. We’ll also highlight consumer remedies like credit monito...
Episode 93 — Enforcement Mechanics: Cure Periods and Penalties 08.09.2025 22:32
Enforcement provisions determine how state privacy laws are applied in practice. This episode explains cure periods, which give businesses time to fix violations before penalties are imposed, and how these provisions differ across states. We’ll also examine penalties, remedies, and enforcement authority, often vested in state attorneys general or privacy agencies. We’ll highlight how enforcement d...
Episode 92 — Other State Acts: Emerging Comprehensive Privacy Laws 08.09.2025 23:42
Beyond California, Virginia, and Colorado, many states are adopting or considering comprehensive privacy laws. This episode surveys these developments, highlighting features of statutes in states like Connecticut, Utah, and others. We’ll discuss how they generally follow the same model of applicability thresholds, consumer rights, and controller/processor duties, while introducing state-specific v...
Episode 91 — Colorado Privacy Act: Rights, Duties, and Insurance Bias Provisions 08.09.2025 24:35
Colorado’s Privacy Act builds on the momentum from California and Virginia, offering a comprehensive framework with unique twists. This episode reviews its applicability standards, consumer rights, and controller/processor obligations, including data protection assessments. We’ll also cover Colorado’s focus on fairness in insurance, with rules addressing discriminatory practices tied to algorithmi...
Episode 90 — Virginia CDPA: Consumer Data Protection Act Essentials 08.09.2025 23:12
Virginia’s Consumer Data Protection Act (CDPA) established one of the first comprehensive state privacy frameworks outside California. This episode reviews its applicability thresholds, consumer rights, and obligations for controllers and processors. We’ll also discuss how the CDPA balances business flexibility with consumer protections. We’ll highlight how the CDPA differs from California’s laws,...
Episode 89 — California Delete Act: Data Broker Registration and Rights 08.09.2025 22:19
The California Delete Act introduces obligations for data brokers, requiring them to register and enabling consumers to request deletion of their data from all registered brokers at once. This episode explores the mechanics of the Act, its impact on the data broker industry, and how it expands consumer control. We’ll also review enforcement provisions and potential national ripple effects. Exam qu...
Episode 88 — California AADC: Age-Appropriate Design Code Protections 08.09.2025 25:28
Children’s privacy receives special attention in California’s Age-Appropriate Design Code Act (AADC). This episode explains its requirements for online services likely to be accessed by minors, including risk assessments, high privacy default settings, and restrictions on profiling. The law reflects growing concern about children’s digital wellbeing. We’ll also discuss how the AADC interacts with...
Episode 87 — California CCPA/CPRA: Comprehensive Consumer Privacy Framework 08.09.2025 27:13
California remains the leader in state privacy law. This episode reviews the California Consumer Privacy Act (CCPA) and its amendment through the California Privacy Rights Act (CPRA). We’ll explore applicability thresholds, data subject rights, notice obligations, and enforcement by the California Privacy Protection Agency. We’ll also highlight how the CCPA/CPRA compares to other state laws, often...
Episode 86 — AI Bias and ADM: NAIC AIS Guidelines, NYC AEDT, and State Rules 08.09.2025 26:43
Automated decision-making (ADM) and artificial intelligence raise fairness and discrimination concerns. This episode introduces the NAIC Artificial Intelligence Governance Guidelines, New York City’s Automated Employment Decision Tools (AEDT) law, and state-level rules in California and Colorado. We’ll examine requirements for transparency, testing, and bias audits. We’ll also discuss how ADM inte...
Episode 85 — Biometric Privacy: IL BIPA, WA, TX, and Related Statutes 08.09.2025 28:14
Biometric privacy laws impose strict requirements on collecting and using data such as fingerprints, facial recognition, and iris scans. This episode covers the Illinois Biometric Information Privacy Act (BIPA), which requires consent, disclosure, and safeguards, as well as similar statutes in Washington and Texas. We’ll also review the growing number of lawsuits and settlements under BIPA, which...
Episode 84 — Cookies and Tracking: Online Privacy Regulations 08.09.2025 27:24
State laws increasingly regulate cookies, pixels, and online tracking. This episode explains how transparency, consent, and opt-out obligations apply to digital advertising technologies. We’ll discuss requirements for cookie banners, preference signals, and global opt-out mechanisms. We’ll also highlight enforcement actions where regulators targeted companies for noncompliance with cookie disclosu...
Episode 83 — Health Data Rules: WA MHMD, NV Health Data Act, and IL GIPA 08.09.2025 25:57
Beyond HIPAA, states have introduced new health data privacy statutes. This episode explores Washington’s My Health My Data Act (MHMD), Nevada’s Consumer Health Data Privacy Act, and Illinois’ Genetic Information Privacy Act (GIPA). We’ll review how these laws define consumer health data, impose consent requirements, and establish rights for deletion and access. We’ll also discuss enforcement patt...
Episode 82 — State Security Requirements: Common Controls Across Jurisdictions 08.09.2025 22:06
Most state privacy laws include explicit security requirements. This episode reviews common obligations such as implementing reasonable safeguards, risk-based controls, encryption, and access restrictions. While states vary in language, the underlying expectation is that businesses adopt practices proportional to the sensitivity of data. We’ll also cover how state security requirements overlap wit...
Episode 81 — Data Protection Agreements: Contracts and Assessments 08.09.2025 21:33
Contracts are central to ensuring compliance with state privacy laws. This episode explains how data protection agreements define the obligations between controllers and processors, including rules for data use, security, subcontracting, and breach notification. We’ll also review assessment requirements, where organizations must conduct and document evaluations of high-risk data processing activit...
Episode 80 — Privacy Notices: Transparency and Consumer Disclosures 08.09.2025 21:41
Transparency is a cornerstone of state privacy laws. This episode covers the requirements for privacy notices, including disclosures about data collection, use, sharing, and consumer rights. We’ll examine layered notices, just-in-time disclosures, and special statements for sensitive data or financial incentives. We’ll also highlight enforcement trends, where regulators penalize vague or misleadin...
Episode 79 — Data Subject Rights: Access, Deletion, Portability, and Consent 08.09.2025 22:14
State laws grant individuals a suite of rights over their personal data. This episode explains the rights to access, correct, delete, and port data, as well as opt-out and consent requirements. We’ll highlight how these rights compare across major state frameworks like California’s CCPA/CPRA, Virginia’s CDPA, and Colorado’s Privacy Act. We’ll also cover how organizations must respond to rights req...
Episode 78 — Applicability Tests: Resident Thresholds, Revenue, and Exemptions 08.09.2025 21:40
Comprehensive state privacy laws often hinge on applicability thresholds. This episode explores the criteria that determine whether a business must comply, such as number of state residents, annual revenue, or percentage of revenue from selling personal information. We’ll also cover common exemptions, including nonprofit entities, small businesses, and data already regulated under federal statutes...
Episode 77 — State Authority: Attorneys General and CPPA Oversight 08.09.2025 22:59
State enforcement has become increasingly influential in privacy regulation. This episode examines the role of state attorneys general, who bring actions under both state privacy laws and general consumer protection statutes. We’ll also focus on the California Privacy Protection Agency, which has broad authority under the CCPA and CPRA to issue regulations and enforce compliance. We’ll highlight h...
Episode 76 — Domain V Overview: Role of States in the U.S. Privacy Framework 08.09.2025 23:18
Domain V introduces state privacy laws, which increasingly shape the U.S. privacy landscape. This episode provides an overview of how state authority interacts with federal law, highlighting the roles of state attorneys general, legislatures, and agencies like the California Privacy Protection Agency. We’ll also discuss how states serve as “laboratories of democracy,” pioneering comprehensive priv...
Episode 75 — Post-Employment: Records, References, and Retention Duties 08.09.2025 23:39
Privacy obligations continue even after employment ends. This episode reviews how employers manage personnel records after termination, including requirements for retention and eventual disposal. We’ll also cover privacy issues in providing references, balancing truthfulness with obligations to protect sensitive information. We’ll discuss how state and federal rules shape post-employment practices...
Episode 74 — ECPA at Work: Employer Obligations and Exceptions 08.09.2025 23:14
The Electronic Communications Privacy Act (ECPA) plays a major role in regulating workplace privacy. This episode explains how the Act governs the interception and access of electronic communications, including email and phone calls, in the employment context. We’ll cover key exceptions that permit monitoring, such as the consent of at least one party or business-use exceptions. We’ll also examine...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.