Skip to main content

Department of Education and Early Development Alaska State Libraries, Archives, and Museums

Search in:

Digital Discretion: Federal Law

Privacy and confidentiality, especially in the digital arena

Some Federal Statutes and Regulations

There is no single overarching federal statute governing the acquisition, use, and handling of someone's personal information by any and all businesses and institutions; however, laws applicable to certain types of information or institutions, including Federal government agencies, do exist.  Some of these follow.

Find the text of these statutes and regulations in the Federal Digital System at (for the United States Code) and (for the Code of Federal Regulations).

Children's Online Privacy Protection Act (COPPA) and Rule - 15 USC §§ 6501-6506 and 16 CFR Part 312 “Applies to operators of commercial Web sites and online services (including mobile apps) directed to children under 13 that collect, use, or disclose personal information from children, and operators of general audience Web sites or online services with actual knowledge that they are collecting, using, or disclosing personal information from children under 13.”  Requires privacy policies and notice and parental consent before collection of personal information from children.   Personal information includes, for example, name, address, email address, user name, phone number, SSN, photos, videos, and audiofiles.  See's-online-privacy and

Driver's Privacy Protection Act of 1994 - 18 USC §§ 2721-2725 - Limits disclosure of personal information in state motor vehicle records.  Personal information includes a driver’s license number, name, address, and telephone number, but not accidents, violations, or status as a driver.

Electronic Communications Privacy Act - 18 USC §§ 2510-2522, 2701-2712, 3121-3127, 1367 – Prohibits interception of wire, oral, or electronic communications, including emails, and prohibits disclosure of such information obtained illegally.  Also prohibits intentional access to stored communications, such as emails on a server.  The level of protection given depends on a number of factors.  Exceptions include consent and law enforcement purposes, and with respect to employee and employer relationships, the consent is often given in a blanket.  In general, employers can often access their employees’ communications on employer-provided devices.  See,, and

Fair Credit Reporting Act (FCRA) – 15 USC §§ 1681-1693r - regulates how consumer reporting companies can collect, use and disseminate information about consumers.  See and

Family Educational Rights and Privacy Act of 1974 (FERPA) - 20 USC  § 1232g - regulations at 34 CFR Part 99 - prohibits educational institutions receiving federal funding from disclosing student personally identifiable information absent written parental consent.  Information such as a name, address, and telephone number may be disclosed if the institution provides notice of the type of such information it may publish, and permits a parent or student to opt-out of publication.  See

Federal Privacy Act of 1974 - 5 USC § 552a - regulates how federal agencies handle records containing personally identifying information (like names, photographs, and SSNs of individuals), prohibits disclosure of such records without consent (with some exceptions), and permits individuals to access and request correction of records containing their personal information.  See

Freedom of Information Act (FOIA) – 5 USC § 552 mandates disclosure of Federal government records upon request, absent an exemption or exclusion.  One of the exemptions consists of “personnel and medical files and similar files the disclosure of which would constitute a clearly unwarranted invasion of personal privacy.”  See and

Gramm-Leach-Bliley Act (GLBA) – 15 USC §§ 6801-6809 - regulations regarding privacy and safegurads at 12 CFR Parts 313, 314, and 364 App. B - limits financial institutions’ ability to share a person’s personal financial information and describes how financial institutions must respond to data security breaches.  See

Health Insurance Portability and Accountability Act of 1996 (HIPAA) - Standards for Privacy of Individually Identifiable Health Information and Security Standards for the Protection of Electronic Protected Health Information -  45 CFR Parts 160 & 164 - protects the security and confidentiality of individually identifiable health information. Covers health plans, health care clearinghouse and health care providers who conduct certain financial and administrative transactions electronically.  Requires notice of privacy policies and security breaches.  See

Section 5 of the Federal Trade Commission Act – 15 USC § 45 - prohibits unfair or deceptive acts or practices.  Failure to provide adequate security for sensitive customer information and a resulting security breach causing harm could constitute a violation of the Act.   See  See page 24 of the FTC report titled Protecting Consumer Privacy in an Era of Rapid Change: Recommendations For Businesses and Policymakers, available at

This summary was prepared by librarians for informational purposes only, and is not intended to provide legal advice.