[1] "Sudoval" "Trotta" "Hayes" "Spadea" "Rious" "Bennett"
[7] "Imperati" "Ricket" "Rossi" "Wadsworth" "DiSandro" "Possamai"
[13] "Santosh" "Gentile"
8 Data Dissemination: Part 1
This week focuses on the data dissemination stage of the data lifecycle. You will learn how to:
- Explain the major U.S. data privacy laws and regulations governing the collection, sharing, dissemination, and protection of confidential information, including CIPSEA, Title 13, Title 26, the Privacy Act, FERPA, HIPAA, CCPA, and emerging state privacy laws.
- Assess the strengths and limitations of the United States’ patchwork approach to data privacy and discuss how it affects research, evidence-based policymaking, and the responsible use of administrative and survey data.
8.1 Quick recap on week 4
8.1.1 Privacy-utility tradeoff
The privacy-utility tradeoff describes the relationship between the amount of privacy protection applied to a dataset and the utility (or usefulness) of that data for analysis.
Privacy loss is often referred to as the risk that confidential or sensitive information about individuals, records, or entities being directly observed or inferred from the release of public data and statistics.
Utility can be defined as the quality, qunatity, ease of access, permitted use and dissemination, and more (e.g., research, policy analysis, public reporting).
Data utility, quality, accuracy, or usefulness is how useful or accurate the data are for research and analysis purposes.
8.1.2 Assessing utility
Generally there are three ways to measure utility of the data:
General utility, sometimes called global utility, measures the univariate and multivariate distributional similarity between the confidential data and the public data (e.g., sample means, sample variances, and the variance-covariance matrix).
Specific utility or analysis-specific utility metrics measure differences between public data and confidential data for pre-specified use cases.
Fit-for-purpose, are something in between the previous two utility metric types to quickly assess the quality of the public data compared to the confidential data. They are not global measures, because they focus on certain features of the data, but may not be specific to an analysis that data users and stakeholders are interested in like analysis-specific utility metrics.
8.1.3 Assessing disclosure risk
Note that most thresholds for acceptable disclosure risk are often determined by law.
There are generally three kinds of disclosure risk:
Identity disclosure metrics evaluate how often we correctly re-identify confidential records in the public data.
Note: These metrics require major assumptions about attacker information.
Attribute disclosure occurs if the data intruder determines new characteristics (or attributes) of an individual based on the information available through public data or statistics (e.g., if a dataset shows that all people age 50 or older in a city are on Medicaid, then the data adversary knows that any person in that city above age 50 is on Medicaid). This information is learned without idenfying a specific individual in the data!
Inferential disclosure occurs if the data intruder predicts the value of some characteristic from an individual more accurately with the public data or statistic than would otherwise have been possible (e.g., if a public homeownership dataset reports a high correlation between the purchase price of a home and family income, a data adversary could infer another person’s income based on purchase price listed on Redfin or Zillow).
8.1.5 Week 5 Assignment
Read
- Chapter 6: What Data Privacy Laws Exist?
- A Day in the Life with Federal Government Data
Watch
Optional read
Write (600 to 1200 words)
Find a news analysis story* published within the last year (2025-2026) that relies on data, research findings, surveys, administrative records, or statistical analysis. Evaluate how data were analyzed and used to support the story’s conclusions.
- What are the main findings or claims of the article?
- What data sources were used to support those claims?
- How were the data analyzed or interpreted?
- What assumptions, limitations, biases, or uncertainties might affect the conclusions?
- How do the privacy, security, and ethical considerations surrounding the data affect the analysis?
- Would the story’s conclusions change if more data, less data, or different data were available? Why or why not? (Reflect on your week 3 assignment.)
- Do you agree with the article’s claims?
Cite all references using APA format, including the article you picked.
*“An article written to inform readers about recent events. The author reports and attempts to deepen understanding of recent events—for example, by providing background information and other kinds of additional context.” – CSUSM Library
AI Reflection (Prepare to discuss in class): Use any generative AI tool to identify:
- The article’s main claims
- The evidence supporting those claims
- Potential limitations, biases, or weaknesses in the analysis
- Whether the conclusions appear justified Compare the AI’s response to your own assessment.
8.2 U.S. Data Privacy Laws
Prior to releasing any information (e.g., data and statistics), you must review the legal requirements. As you learned from the book and the questionnaire in the first week of class, the United States has no federal law regulating how personal data can be collected, stored, and used. A privacy policy does not equate to data privacy protections.
The laws governing data collection and dissemination are limited to specific federal agencies (e.g., U.S. Census Bureau) or specific data types (e.g., education).
8.2.1 CIPSEA
What is CIPSEA?
CIPSEA establishes uniform confidentiality protections for information collected for statistical purposes by U.S. statistical agencies, and it allows some data sharing between the Bureau of Labor Statistics, Bureau of Economic Analysis, and Census Bureau. The agencies report to Office of Management and Budget on particular actions related to confidentiality and data sharing.
The law gives the agencies standardized approaches to protecting information from respondents so that it will not be exposed in ways that lead to inappropriate or surprising identification of the respondent. By default the respondent’s data is used for statistical purposes only. If the respondent gives informed consent, the data can be put to some other use.
From Wiki.
A reauthorization of CIPSEA in 2018-19 gave the statistical agencies more opportunities to use administrative data for statistical purposes, and required them to more deeply analyze risks to privacy and confidentiality of respondents.
Foundations for Evidence-Based Policymaking Act of 2018 is often referred to as the Evidence Act and updated CIPSEA.
What data falls under CIPSEA?
- Information collected under a pledge of confidentiality
- Business, household, and individual data collected solely for statistical purposes
- Administrative records used within approved statistical programs
What does “statistical purpose” mean?
- Producing aggregate statistics (e.g., estimating or analyzing a group); not about specific individuals or entities
- Research and analysis intended to describe populations or trends
What are the restrictions?
- Cannot use protected data for administrative, enforcement, tax, benefits, or regulatory actions
- Cannot disclose respondent identities
- Cannot use data in a manner inconsistent with the confidentiality pledge
What are the penalties?
- Fines up to $250,000 and up to 5 years imprisonment
8.2.2 Title 13, U.S. Code of 1953
What is Title 13?
The Census Bureau is bound by Title 13 of the United States Code. These laws not only provide authority for the work we do, but also provide strong protection for the information we collect from individuals and businesses.
Title 13 provides the following protections to individuals and businesses:
- Private information is never published. It is against the law to disclose or publish any private information that identifies an individual or business such, including names, addresses (including GPS coordinates), Social Security Numbers, and telephone numbers.
- The Census Bureau collects information to produce statistics. Personal information cannot be used against respondents by any government agency or court.
- Census Bureau employees are sworn to protect confidentiality. People sworn to uphold Title 13 are legally required to maintain the confidentiality of your data. Every person with access to your data is sworn for life to protect your information and understands that the penalties for violating this law are applicable for a lifetime.
- Violating the law is a serious federal crime. Anyone who violates this law will face severe penalties, including a federal prison sentence of up to five years, a fine of up to $250,000, or both.
From the U.S. Census Bureau
- The law authorizing Census Bureau operations
- Establishes confidentiality protections for Census-collected information
What data falls under Title 13?
- All Census Bureau data, such as decennial census and survey responses for the Census Bureau
What are the restrictions?
- “Disclose or publish any private information that identifies an individual or business such, including names, addresses (including GPS coordinates), Social Security Numbers, and telephone numbers.”
- Limits use to authorized statistical purposes
What are the penalties?
- Fines up to $250,000 and up to 5 years imprisonment
8.2.3 Title 26, U.S. Code of 1939
What is Title 26?
The Internal Revenue Code (IRC) is the body of law that codifies all federal tax laws, including income, estate, gift, excise, alcohol, tobacco, and employment taxes. U.S. tax laws began to be codified in 1874, but there was no central, comprehensive source for them at that time. The IRC was originally compiled in 1939 and overhauled in 1954 and 1986. This code is the definitive source of all tax laws in the United States and has the force of law in and of itself.
These laws constitute Title 26 of the U.S. Code (26 U.S.C.A. § 1 et seq. [1986]) and are implemented by the Internal Revenue Service (IRS) through its Treasury Regulations and Revenue Rulings.
Congress made major statutory changes to Title 26 in 1939, 1954, and 1986. Because of the extensive revisions made in the Tax Reform Act of 1986, Title 26 is now known as the Internal Revenue Code of 1986 (Pub. L. No. 99-514, § 2, 100 Stat. 2095 [Oct. 22, 1986]).
From the U.S. Census Bureau
- Federal tax code that enforces strict confidentiality requirements governing tax-return information
What data falls under Title 26?
- All administrative tax data, such as individual tax returns, business tax returns, and other tax return information
What are the restrictions?
- No disclosure of any tax records
What are the penalties?
- Depends on the type of tax record disclosure, but all penalties include some form of criminal, civil, and administrative penalties, such as jail time and fines of up to $500,000
8.2.4 Privacy Act of 1974
What is the Privacy Act?
The Privacy Act of 1974 a United States federal law, establishes a Code of Fair Information Practice that governs the collection, maintenance, use, and dissemination of personally identifiable information about individuals that is maintained in systems of records by federal agencies.
From Wiki.
- The Privacy Act of 1974 is a “…foundational federal privacy law, providing guardrails for when and how personal data is handled and shared by the federal government.” - APDU’s Data Privacy Resources.
What data falls under the Privacy Act?
- Protects natural, living individuals, which are defined as “a citizen of the United States or an alien lawfully admitted for permanent residence”
- U.S. persons definition excludes deceased persons, non-US persons (e.g., vistors), and organizations (i.e., both for-profit and non-profit entities)
What are SORNs?
- SORNs (system of records notices) are how federal agencies tell the public when they collect personal information that meets certain conditions.
- “Think of a SORN as a public rulebook. Once an agency publishes a SORN in the Federal Register, they must follow it.” - How to Review a Privacy Act System of Records Notice
What are the penalties?
- “If any officer or employee of a government agency knowingly and willfully discloses personally identifiable information will be found guilty of a misdemeanor and fined a maximum of $5,000. Also, if any agency employee or official willfully maintains a system of records without disclosing its existence and relevant details as specified above can be fined a maximum of $5,000. The same misdemeanor penalty (and $5,000 maximum fine) can be applied to anyone who knowingly and willfully requests an individual’s record from an agency under false pretenses.” - EPIC
Any recent developments?
8.2.5 The Family Educational Rights and Privacy Act (FERPA) of 1974
What is FERPA?
The FERPA is a federal law that affords parents the right to have access to their children’s education records, the right to seek to have the records amended, and the right to have some control over the disclosure of personally identifiable information from the education records. When a student turns 18 years old, or enters a postsecondary institution at any age, the rights under FERPA transfer from the parents to the student (“eligible student”). The FERPA statute is found at 20 U.S.C. § 1232g and the FERPA regulations are found at 34 CFR Part 99.
From the U.S. Department of Education
- Federal law protecting the privacy of student education records and applies to all educational institutions that receive funding from the U.S. government
What data falls under FERPA?
Protects parents and students and related to any information associated with a student record, such as…
- academic transcripts
- disciplinary record
- enrollment information
- other PII associated with the student record
What are the restrictions?
- Generally prohibits disclosure of PII education records without consent unless an exception applies
- Limits who may access student records
What are the penalties?
- Withdrawal of U.S. Department of Education funds from the institution or agency that has violated the law (e.g., schools, school districts, and state education agencies)
- “A third party who improperly discloses personally identifiable information from student records can be prohibited from receiving access to records at the education agency or institution for at least 5 years. State laws on privacy may also apply penalties.” - NCES
8.2.6 The Health Insurance Portability and Accountability Act (HIPAA) of 1996
What is HIPAA?
The HIPAA Privacy Rule establishes national standards to protect individuals’ medical records and other individually identifiable health information (collectively defined as “protected health information”) and applies to health plans, health care clearinghouses, and those health care providers that conduct certain health care transactions electronically. The Rule requires appropriate safeguards to protect the privacy of protected health information and sets limits and conditions on the uses and disclosures that may be made of such information without an individual’s authorization. The Rule also gives individuals rights over their protected health information, including rights to examine and obtain a copy of their health records, to direct a covered entity to transmit to a third party an electronic copy of their protected health information in an electronic health record, and to request corrections.
From the The HIPAA Privacy Rule from U.S. Department of Human and Health Services.
On June 25, 2024: HIPAA Privacy Rule To Support Reproductive Health Care Privacy will “…strengthen privacy protections for medical records and health information for women.”
Effective as of June 18, 2025: HIPAA Privacy Rule Final Rule to Support Reproductive Health Care Privacy: Fact Sheet states that “…the U.S. District Court for the Northern District of Texas issued an order declaring unlawful and vacating most of the HIPAA Privacy Rule to Support Reproductive Health Care Privacy at 89 Federal Register 32976 (April 26, 2024).”
- Federal law establishing privacy and security protections for health information as it relates to certain health records
What data falls under HIPAA?
Protected health information (PHI), from HIPAA Journal:
- Is created or received by a health care provider, health plan, public health authority, employer, life insurer, school or university, or health care clearinghouse; and
- Relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to an individual.
HIPAA does not protect health data from apps like fitness trackers or businesses/schools (e.g., student health data from a nurse’s office is protected under FERPA and not HIPAA).
What are the restrictions?
- Generally prohibits disclosure of PHI
- Limits who may access PHI records
What are the penalties?
- “The penalties for HIPAA violations include civil monetary penalties ranging from $145 to $2,190,294 per violation, depending on the level of culpability. Criminal penalties can also be imposed for intentional HIPAA violations, leading to fines and potential imprisonment.” - HIPAA Journal
8.2.7 State privacy laws
The International Association of Privacy Professionals (IAPP)1 has a great U.S. State Privacy Legislation Tracker.
State-level momentum for comprehensive privacy bills is at an all-time high. The IAPP Westin Research Center actively tracks the proposed and enacted comprehensive privacy bills from across the U.S. to help our members stay informed of the changing state privacy landscape. This information is compiled into a chart, map , and a directory with information specific to states with enacted laws.
This tracker only includes bills intended to be comprehensive approaches to governing the use of personal information. If a bill does not appear, it does not qualify due to its scope, coverage or rights. Industry-specific, information-specific and narrowly scoped bills, e.g., data security bills, are not included. The IAPP published an article outlining its current stance concerning which state privacy laws are considered comprehensive. The IAPP may adjust this position in the future in light of new information, bills, stakeholders or member feedback.
If you are aware of a comprehensive bill absent from the tracker, please share it with us at research@iapp.org. The IAPP additionally hosts a US State AI Governance Legislation Tracker, which focuses on cross-sectoral state AI governance bills that apply to private sector organizations, and a US Federal Privacy Legislation Tracker, which informs of developments within the federal privacy landscape.
The state privacy law chart tracks U.S. state comprehensive consumer privacy bills across the legislative process, identifying and mapping out fourteen provisions that commonly appear in comprehensive privacy laws. If a bill includes a provision, an “X” is placed in the corresponding column. The provisions are broken into two categories — consumer rights and business obligations — and are described more fully in the chart. Although many of the proposed bills will fail to become law, comparing the key provisions helps break down how privacy is developing in the U.S.
The map tracks the status of statutes and bills that are enacted or in the legislative process.
8.2.8 California Consumer Privacy Act of 2018
What is CCPA?
From the State of California Department of Justice:
The California Consumer Privacy Act (CCPA) gives consumers more control over the personal information that businesses collect about them, with accompanying regulations that provide guidance on how to implement the law, which includes:
- The right to know about the personal information a business collects about them and how it is used and shared;
- The right to delete personal information collected from them (with some exceptions);
- The right to opt-out of the sale or sharing of their personal information; and
- The right to non-discrimination for exercising their CCPA rights.
In November 2020, California voters approved Proposition 24, the California Privacy Rights Act, which amended the CCPA and added additional privacy protections that took effect on January 1, 2023. As of this date, consumers have new rights in addition to those above, such as:
- The right to correct inaccurate personal information that a business has about them; and
- The right to limit the use and disclosure of sensitive personal information collected about them.
Businesses subject to the CCPA have several responsibilities, including responding to consumer requests to exercise these rights and providing consumers with certain notices explaining their privacy practices. The CCPA applies to many businesses, including data brokers.
8.3 Patchwork of Data Privacy Laws
Always consult your organization’s legal counsel before collecting, storing, sharing, analyzing, disseminating, archiving, or destroying confidential, restricted, protected health information (PHI), personally identifiable information (PII), or other sensitive data. The United States has a patchwork of federal, state, local, tribal, and sector-specific privacy laws and regulations that may overlap, supersede, or impose additional requirements depending on the type of data, who collected it, how it is used, and where it is stored, shared, or transferred.
This is especially important when data are shared or transferred between organizations. Each organization is responsible for complying with its own legal and regulatory obligations, and legal counsel for different organizations may interpret applicable laws, regulations, contracts, or data-sharing agreements differently (e.g., MOU, MOA, DUA, NDA). As a result, negotiating a data-sharing agreement can be as much a legal and policy exercise as it is a technical one.
8.3.1 Data Sharing Legal Challenges
This patchwork of laws and interpretations is one reason why data sharing is often more difficult than many people expect. Even when linking datasets could substantially improve research, program administration, or evidence-based policymaking, organizations may be unable (or unwilling) to share data because of legal restrictions, differing interpretations of those restrictions, or concerns about privacy, confidentiality, and liability.
For example, a state education agency may wish to link student records with health and human services data, such as SNAP or TANF participation, to evaluate program effectiveness or better understand student outcomes. However, differences in governing privacy laws (e.g., FERPA, HIPAA, state privacy laws), agency authorities, and legal interpretations may make such data sharing difficult or, in some cases, impossible.
8.3.2 Gaps in the Patchwork of Data Privacy Laws
The following from Part 2: Is Data Privacy Dead? The Answer Must be No:
Although new technologies and associated risks are rapidly evolving, such as the widespread use of AI, there is no single federal law that comprehensively covers data privacy and confidentiality. While the Privacy Act of 1974 serves as a backbone, there is a patchwork of laws in the United States that each attempt to address an aspect of privacy, confidentiality, and security of personal data. The laws we have are often limited to specific federal agencies (e.g., Title 13 confidentiality protections for data at the U.S. Census Bureau) or specific data types (e.g., Family Educational Rights and Privacy Act privacy and confidentiality protections for education records).
Gaps in the patchwork, including the lack of a federal-level consumer data privacy law, have allowed the multibillion-dollar data broker industry to flourish with little to no regulation. Furthermore, our foundational laws, like the Privacy Act of 1974, were created long before personal computers, the internet, smartphones, and social media. In fact, more than a decade ago the Government Accountability Office noted that advances in technology had “rendered some of the provisions of the Privacy Act and the E-Government Act of 2002 inadequate to fully protect all personally identifiable information collected, used, and maintained by the federal government.” (U.S. Government Accountability Office 2012) And yet, despite some amendments, the Privacy Act of 1974 has remained substantially the same for more than 50 years. Some states have worked to bolster their state data privacy laws, but those laws don’t cover every state and may be preempted by federal law.
8.4 References
The International Association of Privacy Professionals is a nonprofit, non-advocacy membership association founded in 2000.↩︎