US data privacy essentials: CCPA and state privacy laws

For employees who handle personal data, especially customer service and marketing teams: understand US privacy laws, recognize and route consumer requests, and keep everyday data practices lawful.

For: All employees who handle customer or employee personal data, with a focus on customer service, marketing, product, HR and sales teams in businesses that serve US consumers.

  • 2 contact hours
  • 8 modules
  • 9 interactives
  • 4 job aids
  • Updated October 11, 2026

What you will be able to do

  • Explain the US privacy patchwork of sector-specific federal laws, FTC Act Section 5 and comprehensive state privacy laws, and why it matters in everyday jobs.
  • Describe CCPA/CPRA consumer rights, required notices, opt-out of sale and sharing, sensitive personal information, Global Privacy Control, and the phased 2025 CPPA regulations.
  • Compare common principles across other state comprehensive privacy laws, such as Texas and Colorado, and identify when HIPAA, GLBA, FERPA and COPPA apply.
  • Recognize, log, verify and route consumer privacy requests correctly and on time, without disclosing data to unverified people or retaliating.
  • Apply CAN-SPAM, TCPA, data minimization and retention rules in daily work, and escalate new data uses, children's data and purchased lists to the privacy team.

US privacy law is a patchwork: sector laws such as HIPAA, GLBA, FERPA and COPPA, marketing rules such as CAN-SPAM and the TCPA, the FTC's power to stop unfair or deceptive practices, and a fast-growing set of comprehensive state privacy laws led by California's CCPA. This course explains how the pieces fit, what rights consumers have, and what businesses must do, in plain language.

You will learn the CCPA's rights and notices, how opt-outs, sensitive data and Global Privacy Control work, what California's 2025 regulations on automated decisionmaking, risk assessments and cybersecurity audits require and when, and how Texas, Colorado and other states compare. You will practice recognizing plain-language privacy requests, verifying identity safely, routing requests on time, and keeping marketing, children's data and retention practices lawful.

Scenarios from an online apparel company, a gym chain, a meal-kit startup and a children's learning app make the rules concrete. Interactive tools include a request-routing decision tree, a state look-up, a branching chat-desk scenario and spot-the-problem exercises, plus a checklist, a request procedure starter, a scenario worksheet and a state quick reference.

What you’ll be able to do Monday morning

  1. Recognize privacy requests written in everyday words and log and route them the same day.
  2. Answer questions about data practices only with approved wording and the privacy policy link.
  3. Refuse to share any person's information with a caller you cannot verify, and log the attempt.
  4. Check with your privacy team before adding tracking tools, using data in a new way or launching automated decision features.
  5. Include ad disclosure, a postal address and a working opt-out in marketing emails, and honor opt-outs within 10 business days.
  6. Delete personal data you no longer need, following your retention schedule.

Curriculum

8 modules · 32 lessons · about 2 contact hours

01Why is US privacy law a patchwork, and why does it matter at work?Free preview15 min
  1. Is there a single US privacy law?
  2. What do comprehensive state privacy laws have in common?
  3. What does FTC Section 5 mean for everyday privacy promises?
  4. Why does this matter to people who are not lawyers?
  • Self-assessment: How privacy-ready am I?

Diagram · In practice checklist · 2-question knowledge check

02What rights does the CCPA give Californians?16 min
  1. What is the CCPA, and who must comply?
  2. What rights do California consumers have?
  3. What notices must businesses give?
  4. What happens with Kaiya's deletion request?
  • Matching activity: CCPA rights

Diagram · In practice checklist · 2-question knowledge check

03How do opt-outs, sensitive data and Global Privacy Control work?15 min
  1. What do 'sale' and 'sharing' mean?
  2. What is Global Privacy Control, and must businesses honor it?
  3. What is sensitive personal information?
  4. What everyday practices reduce opt-out and sensitive-data risk?
  • Sort activity: Sensitive or not?

Diagram · In practice checklist · 2-question knowledge check

04What do the 2025 California regulations and other state laws add?15 min
  1. What did the 2025 California regulations change?
  2. How do other state laws compare?
  3. Why do companies often apply one high standard everywhere?
  4. What should employees take from this?
  • State rules selector: State privacy law look-up (verified examples)

Diagram · In practice checklist · 2-question knowledge check

05When do HIPAA, GLBA, FERPA and COPPA apply?15 min
  1. Which sector laws matter most, and when?
  2. What does the updated COPPA Rule require?
  3. What about teens and children under state laws?
  4. How do HIPAA and GLBA show up in ordinary jobs?
  • Decision tree: Privacy message routing tool

Diagram · In practice checklist · 2-question knowledge check

06How do you recognize, verify and route privacy requests?16 min
  1. What do privacy requests look like in real life?
  2. Why is verification so important?
  3. What are the steps and deadlines?
  4. How should the Monday requests be handled?
  • Branching scenario: A morning on the customer chat desk

Diagram · In practice checklist · 2-question knowledge check

07How do marketing rules, minimization and retention shape everyday work?15 min
  1. What does CAN-SPAM require for marketing email?
  2. What does the TCPA mean for calls and texts?
  3. Why do data minimization and retention matter?
  4. How do you keep privacy promises true?
  • Spot the issue: Spot the problems in a draft marketing email
  • Spot the issue: Review a sign-up form
  • Ethics dilemma: The regional manager's idea

Diagram · In practice checklist · 2-question knowledge check

08How do privacy principles apply to employee and applicant data?14 min
  1. Which privacy rules cover workers and applicants?
  2. What does fair handling of background checks look like?
  3. How should HR answer an applicant's privacy request?
  4. What privacy habits matter most for managers and HR?

Diagram · In practice checklist · 2-question knowledge check

Final assessment: 23 questions, 75% to pass, then your certificate

Try it now, no account needed

A morning on the customer chat desk

A branching scenario from this course. Your choices are not saved.

Free sample activity

A morning on the customer chat desk

You are Kaiya Bluehorse, a chat agent for an online outdoor apparel company in San Luis Obispo, California. The company meets the CCPA's thresholds and offers core privacy rights to all US customers.

Inside the course

Practice activities

  • Self-assessment1
  • Matching activity1
  • Sort activity1
  • State rules selector1
  • Decision tree1
  • Branching scenario1
  • Spot the issue2
  • Ethics dilemma1

Job aids you keep

  • Privacy at Work ChecklistChecklist
  • Consumer Privacy Request Procedure (Starter)Policy starter
  • Privacy Scenario WorksheetWorksheet
  • State Privacy Law Quick Reference (verified examples)Reference sheet

Credit and approval status

Certificate of completion

This course awards a certificate of completion for 2 contact hours of instruction. It is not currently approved or accredited by the IAPP, NASBA, IACET or any state agency, and it does not provide CPE or privacy certification credit. Employers decide whether to accept it toward internal training requirements. It is general awareness training, not legal advice.

Pathways we may pursue include IAPP continuing privacy education credit, IACET-aligned continuing education units and NASBA-registered CPE, if approval is obtained. None of these approvals exists today; the course page will show an approval only after it is granted.

Our full approvals list

State notes

Comprehensive state privacy laws differ in thresholds, rights, deadlines, sensitive-data rules, opt-out signal requirements, cure periods and enforcement. Verified examples:

  • California: CCPA as amended by the CPRA (Civil Code 1798.100 et seq.); thresholds include over $25 million revenue (adjusted), 100,000+ residents or households, or 50%+ revenue from selling PI; rights to know, delete, opt out of sale/sharing, correct and limit sensitive PI; 45-day response (one 45-day extension); GPC must be honored; employees and B2B contacts covered since 2023; CPPA regulations effective January 1, 2026 with ADMT compliance from January 1, 2027 and audit certifications from April 1, 2028.
  • Texas: Texas Data Privacy and Security Act, effective July 1, 2024; 45-day response with one extension; appeal process; consent for sensitive data; exclusive AG enforcement with a 30-day cure period.
  • Colorado: Colorado Privacy Act; universal opt-out mechanism required from July 1, 2024, with GPC the only recognized mechanism.
  • Newest: Kentucky, Indiana and Rhode Island laws effective January 1, 2026.

What to check locally: which states your customers and employees live in, whether your business meets each state's thresholds, whether your company extends rights to all US customers, and current statutes and regulations, which change every year.

Questions about this course

Is this course approved for IAPP or other professional credit?

No. It awards a certificate of completion for 2 contact hours and is not approved by the IAPP, NASBA, IACET or any state agency. It is designed as practical workplace training; ask your employer whether it meets internal requirements, and check with any credentialing body before relying on it for credit.

Does it cover every state's privacy law?

No. It explains the common model, covers California in depth, gives verified details for Texas and Colorado, and notes the laws effective in Kentucky, Indiana and Rhode Island on January 1, 2026. State laws change every year, so check current law with your privacy team.

Who should take this course?

Anyone who handles personal data about customers or employees, especially customer service, marketing, product and engineering, HR and sales staff. Supervisors who approve campaigns or new data uses benefit too.

Does it cover data breaches?

Only briefly. Breach prevention and notification laws are covered in depth in the CE Courses Hub course Data Breach Prevention and Notification. This course focuses on privacy rights, notices, consent, marketing and everyday data handling.

How long does it take, and how am I assessed?

Plan on about 2 hours for eight modules with interactive exercises, then a final assessment of 23 questions drawn from a larger bank. You need 75% to pass, and you receive a certificate of completion for 2 contact hours.

How current is the content?

It was checked against official sources in October 2026, including California's regulations effective January 1, 2026, the CalPrivacy DROP timeline, the amended COPPA Rule (compliance by April 22, 2026) and the FTC's current CAN-SPAM penalty amount. It is reviewed at least every 12 months.

This course is general education and training awareness from CE Courses Hub on US data privacy laws. It is not legal or professional advice and does not replace your employer's policies, your licensing board's rules, or advice from a qualified attorney or privacy professional. Completing it earns a certificate of completion for the stated contact hours; it is not approved or accredited by any licensing board, state agency or accreditor unless an approval is shown on the course page. Check with your board, employer or state agency whether this course meets your specific requirement.