nerdexam
(ISC)2

CCSP · Question #413

Which jurisdiction lacks specific and comprehensive privacy laws at a national or top level of legal authority?

The correct answer is D. United States. The United States does not have a single, comprehensive federal privacy law. Instead, US privacy protection is fragmented across sector-specific statutes (e.g., HIPAA for healthcare, COPPA for children, GLBA for financial data) and a patchwork of state laws (e.g., California's…

Submitted by zhang_li· Apr 18, 2026Legal, Risk and Compliance

Question

Which jurisdiction lacks specific and comprehensive privacy laws at a national or top level of legal authority?

Options

  • AEuropean Union
  • BGermany
  • CRussia
  • DUnited States

How the community answered

(48 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    4% (2)
  • D
    92% (44)

Explanation

The United States does not have a single, comprehensive federal privacy law. Instead, US privacy protection is fragmented across sector-specific statutes (e.g., HIPAA for healthcare, COPPA for children, GLBA for financial data) and a patchwork of state laws (e.g., California's CCPA/CPRA). The European Union has the GDPR - one of the world's most comprehensive privacy frameworks. Germany, as an EU member state, is bound by GDPR and also has robust national privacy laws with a long history predating GDPR. Russia enacted Federal Law No. 152-FZ on Personal Data, a national-level comprehensive privacy law. The lack of a US federal omnibus privacy law is a well-known gap in the global privacy landscape.

Topics

#Privacy laws#Jurisdictions#Data protection#Legal frameworks

Community Discussion

No community discussion yet for this question.

Full CCSP Practice