FIPPs

Also known as: Fair Information Practice Principles

framework · governance and compliance · organizing-schema

Foundational set of principles (notice, choice, access, security, accountability) underlying most privacy regimes.

The Fair Information Practice Principles articulate the foundational normative architecture underlying virtually all modern data protection law, beginning with the 1973 US Department of Health, Education, and Welfare report Records, Computers, and the Rights of Citizens which proposed a Code of Fair Information Practice. The 1980 OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data internationalized and codified the principles, and subsequent expressions appear in the EU Data Protection Directive, GDPR, US sectoral laws, the APEC Privacy Framework, and most national privacy regimes. Common formulations differ in number and naming but share a core: limits on collection and use, transparency to individuals, individual rights of access and correction, security obligations, and organizational accountability for principle-conformant processing.

Originators

US Department of Health, Education, and Welfare (1973 HEW Report); Organisation for Economic Co-operation and Development (1980 OECD Guidelines) high

Year / Decade

1973 (HEW Report); 1980 (OECD Guidelines) high

Primary sources

US Department of Health, Education, and Welfare (1973). Records, Computers, and the Rights of Citizens, OECD (1980, revised 2013). Guidelines on the Protection of Privacy and Transborder Flows of Personal Data high

Core components

Primary use case

Foundational normative framework for privacy law and policy globally; reference principles in sectoral and comprehensive data protection regimes; basis for privacy-by-design and privacy engineering.

Common criticisms

Lineage

Parent of
GDPR, CCPA, HIPAA
Siblings
GDPR, CCPA, HIPAA