Jason Edwards

Certified - CIPP/US Audio Course

Education EN ↓ 98 episodes

The CIPP/US Audio Course is your complete, audio-first companion for mastering the Certified Information Privacy Professional – United States (CIPP/US) certification. Designed for learners who want structured, on-the-go preparation, this Audio Course transforms the IAPP Body of Knowledge into clear, engaging, and easy-to-follow episodes. Each lesson unpacks the foundations of U.S. privacy law—from federal and state frameworks to workplace regulations and cross-border data principles—helping you connect legal theory to real-world application. Whether you’re commuting, exercising, or reviewing b...

Author

Jason Edwards

Category

Education

Podcast website

baremetalcyber.com

Latest episode

Oct 14, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 23 — Privacy Program Development: Workforce Training and Vendor Management 08.09.2025

Building a privacy program is more than drafting policies—it requires embedding privacy into operations. In this episode, we cover workforce training, including how to tailor content for different roles and ensure employees understand their responsibilities. Vendor management is another core element, requiring organizations to assess risks, negotiate processing agreements, and monitor compliance....

Episode 22 — Data Flow Mapping: Transfers, Sharing, and Accountability Controls 08.09.2025

Data doesn’t stay put—it flows across systems, organizations, and borders. This episode explains how to map those flows, identify points of transfer, and implement controls that ensure compliance. We’ll discuss intra-organizational transfers, such as between departments or subsidiaries, and external flows to vendors, partners, or regulators. Accountability mechanisms, such as contractual clauses a...

Episode 21 — Information Management: Data Inventory and Classification Practices 08.09.2025

Strong privacy programs begin with knowing what data you have. This episode covers how organizations build and maintain a data inventory, cataloging personal information across systems, applications, and vendors. We’ll explore how classification frameworks distinguish between sensitive and non-sensitive categories, and why these distinctions matter for regulatory compliance, contractual obligation...

Episode 20 — Self-Regulatory Enforcement: PCI, Trust Marks, and Seal Programs 08.09.2025

Building on our earlier discussion of self-regulation, this episode focuses specifically on enforcement mechanisms. We’ll look at how programs such as the Payment Card Industry Data Security Standard (PCI DSS) enforce compliance through contractual obligations, and how privacy seals or trust marks maintain credibility through audits and monitoring. While not legally binding, these mechanisms often...

Episode 19 — Cross-Border Enforcement: GPEN and International Cooperation 08.09.2025

Privacy enforcement is increasingly global. This episode introduces the Global Privacy Enforcement Network (GPEN), a collaboration of regulators worldwide who share information and coordinate investigations. We’ll explore how cross-border cooperation arises in cases involving multinational companies, data transfers, or online services with global reach. We also highlight the challenges of aligning...

Episode 18 — Federal and State Enforcement: DOJ, CPPA, and State AGs 08.09.2025

This episode focuses on the interplay of federal and state enforcement bodies. We begin with the Department of Justice, which prosecutes criminal violations and litigates civil cases on behalf of federal agencies. We then turn to state actors such as the California Privacy Protection Agency and attorneys general, who often lead privacy investigations and lawsuits. These layers of enforcement creat...

Episode 17 — Negligence and UDAP: Unfair and Deceptive Acts in Enforcement 08.09.2025

Negligence and unfair or deceptive acts and practices (UDAP) are core theories of liability in privacy enforcement. This episode explains how negligence involves failure to meet a standard of reasonable care, such as not securing personal data. UDAP, meanwhile, captures misrepresentations or omissions in consumer-facing statements, even if no breach has occurred. Together, these frameworks give re...

Episode 16 — Fiduciary Duty: Duties of Care, Loyalty, and Good Faith in Privacy Contexts 08.09.2025

Fiduciary duty, long established in corporate and financial contexts, is increasingly applied to data stewardship. This episode introduces the three core fiduciary duties: care, loyalty, and good faith. We discuss how these principles require organizations to protect personal data responsibly, avoid conflicts of interest, and act transparently. While not always codified in privacy law, fiduciary c...

Episode 15 — Enforcement Framework: Civil vs. Criminal Liability in Privacy Law 08.09.2025

Liability is the heart of enforcement. In this episode, we distinguish between civil liability, such as damages from consumer lawsuits or regulatory penalties, and criminal liability, which may arise from intentional misconduct like fraud or unauthorized access. We explore how negligence, fiduciary duty, and unfair or deceptive acts and practices (UDAP) form the backbone of many civil cases. At th...

Episode 14 — Self-Regulatory Models: Industry Codes and Voluntary Frameworks 08.09.2025

Not all privacy enforcement comes from government. This episode introduces self-regulatory models such as industry codes of conduct, seal programs, and voluntary frameworks. Examples include PCI standards in the payments sector, TRUSTe privacy seals, and the role of trade associations in setting best practices. These models often operate in partnership with regulators but also act as competitive d...

Episode 13 — State Oversight: Attorneys General and Insurance Departments 08.09.2025

While federal agencies are powerful, state-level enforcement often drives privacy practice in the U.S. This episode highlights the role of state attorneys general, who bring enforcement actions under state privacy laws, consumer protection statutes, and data breach notification acts. We’ll also explore the growing influence of specialized bodies like the California Privacy Protection Agency, which...

Episode 12 — Regulatory Authorities: FTC, FCC, DoC, HHS, and Banking Regulators 08.09.2025

U.S. privacy law cannot be understood without recognizing the regulators that enforce it. This episode surveys the Federal Trade Commission’s broad Section 5 authority, the Federal Communications Commission’s oversight of telecom privacy, and the Department of Commerce’s role in international frameworks like the Data Privacy Framework. The Department of Health and Human Services administers HIPAA...

Episode 11 — Legal Analysis: Jurisdiction, Scope, Preemption, and Private Right of Action 08.09.2025

This episode dives into the analytical tools used to interpret and apply privacy laws. We’ll break down jurisdiction—who has authority over a particular dispute—and how state and federal powers often overlap. Scope is another key concept, determining which organizations, data types, and individuals fall within a law’s reach. Preemption is examined as the legal principle that federal law overrides...

Episode 10 — Sources of Law: Constitutions, Statutes, Case Law, and Contracts 08.09.2025

Understanding sources of law is critical to mastering the CIPP/US. In this episode, we unpack the U.S. Constitution’s role in privacy, including federal preemption, the Bill of Rights, and state constitutional guarantees. We then cover how statutes like HIPAA, GLBA, and CCPA provide legislative frameworks, while case law refines their application through judicial interpretation. Contracts are also...

Episode 9 — U.S. Legal Framework: Branches of Government and Privacy Roles 08.09.2025

This episode examines how the structure of U.S. government influences the development and enforcement of privacy law. We look at the distinct roles of the legislative, executive, and judicial branches, and how statutes, regulations, and case law interact to shape privacy obligations. You’ll also learn how contracts and common law principles add another layer of enforceability, making the U.S. fram...

Episode 8 — Domain I Overview: Scope, Structure, and Enforcement Themes 08.09.2025

Domain I introduces the U.S. privacy environment at its broadest level. In this episode, we review how the branches of government shape privacy law, the sources of law that contribute to the framework, and the roles of regulatory authorities such as the FTC, FCC, and HHS. We also explore how accountability models, compliance obligations, and data subject rights are embedded into U.S. privacy manag...

Episode 7 — Glossary Deep Dive: Domain V and Cross-Cutting Terms 08.09.2025

The third glossary episode covers Domain V and other cross-cutting terms that frequently surface across multiple sections of the exam. Here we explain concepts such as opt-out rights, cure periods, breach notification triggers, and the mechanics of comprehensive state laws like the CCPA and CPRA. You’ll also encounter terms that link U.S. laws with international frameworks, including Schrems decis...

Episode 6 — Glossary Deep Dive: Domains III–IV Terms 08.09.2025

Our second glossary session turns to Domains III and IV, covering government access to private-sector information and workplace privacy. These domains introduce terminology around subpoenas, national security powers, and workplace monitoring practices. You’ll learn the meaning and implications of terms such as ECPA, FISA, and Section 702, along with employment-related concepts like reasonable expe...

Episode 5 — Glossary Deep Dive: Domains I–II Terms 08.09.2025

The glossary is more than a list of definitions—it’s a map of the exam’s language. In this first glossary deep dive, we focus on terms from Domains I and II, which cover the U.S. privacy environment and federal sector-specific laws. You’ll learn how core concepts like jurisdiction, preemption, and private right of action appear in multiple contexts, and why recognizing precise definitions can be t...

Episode 4 — Exam Mindset & Retention Strategy: Flashcards, Audio Learning, and Note Cycles 08.09.2025

Memorization alone won’t get you through the CIPP/US exam—you need a strategy for long-term retention. This episode explores proven study methods such as spaced repetition with flashcards, active recall exercises, and audio reinforcement. We’ll discuss how layering these approaches strengthens memory and makes complex statutes and case law easier to recall under pressure. For audio-first learners,...

Episode 3 — Exam Format & Test Taking Skills: Question Types, Scoring, and Breaks Explained 08.09.2025

Knowing what to expect on exam day is half the battle. In this episode, we break down the structure of the CIPP/US exam, including the multiple-choice question types, how scenario-based items are framed, and the scoring model used by the IAPP. You’ll learn how the 100–500 scale is determined, why the passing score is set at 300, and how to avoid wasting energy trying to back-calculate percentages....

Episode 2 — Study Strategy: Building a Prep Timeline and Pacing Plan 08.09.2025

Preparation is as much about organization as it is about knowledge. This episode walks you through how to create a structured study timeline that balances your daily commitments with the demands of the CIPP/US Body of Knowledge. We cover how to break down the content into manageable portions, determine the number of hours per week you should realistically allocate, and identify milestones that kee...

Episode 1 — Exam Orientation: Purpose of the CIPP/US Credential 08.09.2025

This opening episode introduces you to the Certified Information Privacy Professional/United States credential and why it has become the gold standard for privacy expertise in the U.S. market. We’ll set the context by explaining how the certification validates your knowledge of laws, regulations, and enforcement structures, and why employers, clients, and colleagues recognize it as a meaningful pr...

Listen to the Certified - CIPP/US Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.