FIPPs
Also known as: Fair Information Practice Principles
Foundational set of principles (notice, choice, access, security, accountability) underlying most privacy regimes.
The Fair Information Practice Principles articulate the foundational normative architecture underlying virtually all modern data protection law, beginning with the 1973 US Department of Health, Education, and Welfare report Records, Computers, and the Rights of Citizens which proposed a Code of Fair Information Practice. The 1980 OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data internationalized and codified the principles, and subsequent expressions appear in the EU Data Protection Directive, GDPR, US sectoral laws, the APEC Privacy Framework, and most national privacy regimes. Common formulations differ in number and naming but share a core: limits on collection and use, transparency to individuals, individual rights of access and correction, security obligations, and organizational accountability for principle-conformant processing.
Core components
- Collection limitation
- Data quality
- Purpose specification
- Use limitation
- Security safeguards
- Openness/transparency
- Individual participation (access, correction)
- Accountability (OECD 1980 formulation
- specific enumerations vary across instruments)
Primary use case
Foundational normative framework for privacy law and policy globally; reference principles in sectoral and comprehensive data protection regimes; basis for privacy-by-design and privacy engineering.
Common criticisms
- Notice-and-consent model criticized as ineffective in the face of complex data flows and consent fatigue
- individual control assumption is largely fictional given information asymmetries
- principles are abstract and translate inconsistently into concrete obligations
- aging in the face of AI/ML training data, ambient sensing, and inference
- collection limitation in tension with modern observational data economics.
Lineage
- Parent of
- GDPR, CCPA, HIPAA
- Siblings
- GDPR, CCPA, HIPAA