Jason Edwards
Certified - CIPP/US Audio Course
The CIPP/US Audio Course is your complete, audio-first companion for mastering the Certified Information Privacy Professional – United States (CIPP/US) certification. Designed for learners who want structured, on-the-go preparation, this Audio Course transforms the IAPP Body of Knowledge into clear, engaging, and easy-to-follow episodes. Each lesson unpacks the foundations of U.S. privacy law—from federal and state frameworks to workplace regulations and cross-border data principles—helping you connect legal theory to real-world application. Whether you’re commuting, exercising, or reviewing b...
Author
Jason Edwards
Category
Podcast website
Latest episode
Oct 14, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 48 — FERPA: Education Records and Student Rights 08.09.2025 19:41
The Family Educational Rights and Privacy Act (FERPA) governs the privacy of student education records. This episode explains the rights it grants to parents and students, including access, correction, and consent for disclosure. We’ll also review exceptions, such as disclosures to school officials or in cases of health and safety emergencies. We’ll highlight how FERPA applies to both K–12 and hig...
Episode 47 — Corporate Transactions: Privacy in Mergers, Acquisitions, and Divestitures 08.09.2025 21:01
Mergers and acquisitions often involve transferring large volumes of personal data. This episode explains the privacy implications of corporate transactions, including how due diligence identifies risks and how contracts manage ongoing obligations. We’ll also discuss how regulators evaluate whether consumer consent is required when data changes hands. For exam purposes, you should understand how p...
Episode 46 — Online Banking: Biometrics, Third-Party Tracking, and Security 08.09.2025 21:40
Online banking raises unique privacy issues. This episode looks at how institutions use biometrics for authentication, the risks of third-party tracking in financial apps, and the growing security concerns in digital transactions. We’ll explore how these practices intersect with existing financial privacy laws, including GLBA, FCRA, and state breach notification statutes. We’ll also examine how re...
Episode 45 — Dodd-Frank: CFPB Oversight of Consumer Financial Privacy 08.09.2025 20:17
The Dodd-Frank Wall Street Reform and Consumer Protection Act created the Consumer Financial Protection Bureau (CFPB), which plays a central role in financial privacy. This episode explains the CFPB’s authority, its supervision of financial institutions, and its role in enforcing consumer privacy protections. We’ll also cover how Dodd-Frank introduced new requirements for transparency, accountabil...
Episode 44 — Identity Theft Prevention: Red Flags Rule in Practice 08.09.2025 20:32
The Red Flags Rule is designed to help organizations detect, prevent, and mitigate identity theft. This episode explains how financial institutions and certain creditors must develop programs that identify warning signs—or “red flags”—of potential fraud. We’ll review the categories of red flags, from suspicious documents to unusual account activity, and discuss how compliance programs integrate mo...
Episode 43 — GLBA: Privacy Rule, Safeguards Rule, and State Exemptions 08.09.2025 22:59
The Gramm-Leach-Bliley Act (GLBA) governs privacy in the financial services sector. This episode introduces the GLBA Privacy Rule, which requires clear disclosures about data sharing and provides consumers the right to opt out of certain uses. We’ll also cover the Safeguards Rule, mandating administrative, technical, and physical protections for customer data. Importantly, we explore how some stat...
Episode 42 — Financial Privacy: FCRA and FACTA Requirements 08.09.2025 21:08
Financial data is heavily regulated in the U.S., and two major statutes govern its use: the Fair Credit Reporting Act (FCRA) and the Fair and Accurate Credit Transactions Act (FACTA). In this episode, we examine how FCRA establishes accuracy, permissible purpose, and consumer rights to access and correct information. FACTA builds on this by addressing identity theft and credit reporting practices....
Episode 41 — Substance Use Disorder Records: 42 CFR Part 2 Protections 08.09.2025 22:28
Health information involving substance use disorder patients receives special protections under federal law. This episode explains 42 CFR Part 2, which imposes stricter confidentiality standards than HIPAA. We’ll discuss what types of programs and providers are covered, the rules for consent, and the limits on disclosure even to law enforcement and other agencies. These protections aim to reduce s...
Episode 40 — 21st Century Cures: Interoperability and Data Sharing 08.09.2025 22:11
The 21st Century Cures Act sought to promote innovation by improving interoperability and data sharing in healthcare. This episode explains how the Act prohibits “information blocking,” requiring health IT systems to enable secure, authorized data exchange. While designed to empower patients and providers, these provisions also raise privacy and security challenges. We’ll review how regulators bal...
Episode 39 — HITECH: Enforcement and Breach Notification Enhancements 08.09.2025 22:01
The Health Information Technology for Economic and Clinical Health Act (HITECH) strengthened HIPAA enforcement and introduced federal breach notification requirements. This episode explores how HITECH increased penalties, expanded liability to business associates, and mandated reporting of breaches affecting 500 or more individuals. We’ll also examine how it encouraged adoption of electronic healt...
Episode 38 — HIPAA Security Rule: Administrative, Physical, Technical Safeguards 08.09.2025 23:26
Complementing the Privacy Rule, the HIPAA Security Rule sets standards for protecting electronic protected health information (ePHI). This episode breaks down its three safeguard categories: administrative, physical, and technical. Administrative safeguards include policies, risk analyses, and workforce training. Physical safeguards address facility access and workstation security. Technical safeg...
Episode 37 — HIPAA Foundations: Privacy Rule Overview 08.09.2025 25:41
The Health Insurance Portability and Accountability Act (HIPAA) remains one of the most significant federal privacy statutes. This episode explains the Privacy Rule, which establishes protections for protected health information (PHI). We’ll cover covered entities, business associates, permitted uses and disclosures, and the rights of individuals under HIPAA. This foundation is critical for unders...
Episode 36 — Future Priorities: Data Brokers, IoT, AI, and Biometrics 08.09.2025 24:46
Privacy law continues to evolve as technology advances. This episode highlights priority areas identified by regulators and policymakers, including the risks posed by data brokers, the proliferation of Internet of Things devices, the rise of artificial intelligence, and the expanding use of biometric identifiers. We’ll discuss why these areas raise unique concerns and how regulators are responding...
Episode 35 — FTC Enforcement: Case Studies and Settlement Patterns 08.09.2025 25:35
Enforcement brings theory into practice. In this episode, we review major FTC privacy and data security cases, highlighting recurring themes such as inadequate security, deceptive disclosures, and failure to honor stated practices. These case studies illustrate how the FTC frames violations and the remedies it imposes, from fines to compliance monitoring. We’ll also analyze settlement patterns, wh...
Episode 34 — COPPA: Children’s Online Privacy Protections in Services 08.09.2025 26:15
Children’s privacy carries heightened protections in U.S. law. This episode introduces the Children’s Online Privacy Protection Act (COPPA), which governs the collection of personal information from children under 13. We’ll break down requirements such as verifiable parental consent, privacy notice disclosures, and limits on data use and sharing. Enforcement by the FTC has made COPPA one of the mo...
Episode 33 — FTC Authority: Section 5 and Consumer Protection in Privacy 08.09.2025 26:36
The Federal Trade Commission is often described as the nation’s top privacy cop. This episode dives into Section 5 of the FTC Act, which prohibits unfair and deceptive acts or practices. We’ll examine how the FTC uses this authority to address privacy and data security, even without specific statutes. Notable cases have established expectations for transparency in privacy notices, promises about d...
Episode 32 — Domain II Overview: Federal vs. State Sector-Specific Frameworks 08.09.2025 27:01
Domain II focuses on federal and state laws governing specific sectors such as health, finance, education, and telecommunications. This episode introduces the federal “sectoral” approach, where distinct statutes regulate different industries rather than one overarching law. We contrast this with state-level frameworks that increasingly take comprehensive approaches, such as California’s CCPA and C...
Episode 31 — Comparative Analysis: U.S. Privacy vs. GDPR and FADP 08.09.2025 27:05
This episode explores how U.S. privacy frameworks compare to the European Union’s General Data Protection Regulation (GDPR) and Switzerland’s Federal Act on Data Protection (FADP). We’ll review differences in scope, enforcement powers, and individual rights. While U.S. privacy law is fragmented across federal and state systems, GDPR and FADP establish comprehensive regimes that apply broadly acros...
Episode 30 — Multinational Conflicts: E-Discovery vs. EU Data Protection 08.09.2025 27:50
Privacy law collides with other legal obligations when organizations face multinational conflicts. This episode highlights the tension between U.S. e-discovery requirements in litigation and EU data protection laws that restrict data transfers. Companies must navigate competing demands, often under tight timelines, while minimizing the risk of penalties from either jurisdiction. We’ll discuss real...
Episode 29 — International Transfers: Schrems, SCCs, and Data Privacy Framework 08.09.2025 28:56
U.S. companies regularly transfer data across borders, triggering international privacy obligations. This episode introduces the Schrems cases, which invalidated earlier EU-U.S. transfer mechanisms, and explains how Standard Contractual Clauses (SCCs) remain a cornerstone of compliance. We also cover the EU-U.S. Data Privacy Framework, designed to restore lawful transfer channels under stricter sa...
Episode 28 — Online Privacy: Tracking, Profiling, and Consumer Expectations 08.09.2025 30:21
The online environment presents unique privacy risks. This episode examines how tracking technologies, behavioral profiling, and targeted advertising shape consumer experiences and regulatory responses. We’ll explore how cookies, pixels, and mobile identifiers operate, and why transparency and consent requirements are central to online privacy frameworks. We also discuss how consumer expectations...
Episode 27 — Data Retention and Disposal: Lifecycle, Archiving, and Legal Holds 08.09.2025 29:28
Data has a lifecycle, and managing it responsibly is critical for privacy compliance. This episode covers retention schedules that specify how long data must be kept, archival practices for historical or legal purposes, and secure disposal methods to prevent unauthorized access. We also explore the role of legal holds, which suspend deletion when litigation or investigations are pending. Balancing...
Episode 26 — Accountability Models: Demonstrating Compliance and Due Diligence 08.09.2025 29:24
Accountability is the thread connecting all privacy obligations. In this episode, we define accountability models as frameworks for demonstrating compliance through documentation, assessments, and governance structures. Examples include risk assessments, data protection impact assessments, and ongoing monitoring. These models serve as proof that an organization has taken reasonable steps to protec...
Episode 25 — Incident Response Programs: Ransomware and Vendor Incidents 08.09.2025 31:34
Privacy law intersects with cybersecurity when incidents occur. This episode explains how organizations build incident response programs to address threats like ransomware, data breaches, and vendor security failures. We’ll cover the steps of detection, containment, investigation, notification, and remediation, highlighting where privacy law imposes specific obligations. We also look at how regula...
Episode 24 — Cloud and Third-Party Sharing: Processing Agreements and Due Diligence 08.09.2025 29:58
Cloud services and third-party vendors introduce unique privacy challenges. This episode examines how processing agreements define roles and responsibilities between controllers and processors, including clauses on security, breach notification, and sub-processing. Due diligence processes—such as audits, questionnaires, and certifications—help ensure vendors meet contractual and regulatory require...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.