SimplyCPA
CPA/ISC/Privacy & Regulatory Frameworks

Privacy & Regulatory Frameworks

Privacy principles, key regulations, and the frameworks used to structure IT controls.

Medium 50 minArea II: Security, Confidentiality and Privacy

Confidentiality vs. privacy

IMPORTANT: Confidentiality protects information designated as confidential by agreement — it could be trade secrets, pricing, or contract terms. Privacy deals specifically with personal information and the rights of the individuals it describes. All personal information should be kept confidential, but not all confidential information is personal.

Core privacy principles

  • Notice — tell people what you collect and why
  • Choice and consent — allow individuals to agree or opt out
  • Collection limitation — collect only what's needed for the stated purpose
  • Use, retention, and disposal — use only for disclosed purposes; keep only as long as needed
  • Access — individuals can view and correct their data
  • Disclosure to third parties — only with consent or legal basis
  • Security, quality, and monitoring and enforcement

Notable regulations

RegulationScope
GDPR (EU)Broad personal data rights: access, rectification, erasure ("right to be forgotten"), portability; large potential fines; applies extraterritorially to entities serving EU residents
HIPAA (US)Protected health information; privacy and security rules; breach notification
GLBA (US)Financial institutions' handling of customer information; safeguards rule
PCI DSSContractual, not a law — payment card data security standard
State privacy laws (e.g., CCPA/CPRA)Consumer rights to know, delete, and opt out of sale of personal information

Control frameworks

  • COSO Internal Control — Integrated Framework — the general internal control model (five components)
  • COSO ERM — enterprise-wide risk management
  • COBIT — governance and management of enterprise IT
  • NIST Cybersecurity Framework — Identify, Protect, Detect, Respond, Recover (plus Govern in the updated version)
  • ISO/IEC 27001 — certifiable information security management system standard

EXAM TIP: Frameworks are not interchangeable. COSO is about internal control broadly; COBIT is specifically about IT governance; NIST CSF is about cybersecurity risk; ISO 27001 is a certifiable management system.