Skip to main content
v2026.11,610 entries · CC-BY 4.0
Dictionary termTrack DProposedv2026.1

Fair Information Practice Principles (FIPPs)

Fair Information Practice Principles (FIPPs) are a U.S.-originated framework of privacy norms governing how organizations collect, use, disclose, and secure personal information. First articulated in the 1973 HEW report Records, Computers, and the Rights of Citizens, they underpin the Privacy Act of 1974 and were later reflected in the OECD's 1980 Guidelines on the Protection of Privacy. A dataset-handling or systems practice qualifies as FIPPs-aligned when it addresses, at minimum: transparency/notice about what personal data is collected and why; purpose specification and use limitation (data used only for stated, compatible purposes); data minimization (collecting no more than necessary); individual participation (the ability to access, correct, or contest one's own records); data quality and integrity; security safeguards; and accountability for compliance. There is no single canonical numbered list — the original HEW report set out five principles, the Privacy Act of 1974 codified eight statutory safeguards, and later agency restatements (for example the U.S. Department of Homeland Security's widely cited 2008 formulation) group them into eight principles: Transparency, Individual Participation, Purpose Specification, Data Minimization, Use Limitation, Data Quality and Integrity, Security, and Accountability and Auditing. FIPPs is a governance framework, not itself a statute — it becomes binding only where a specific law (such as the Privacy Act of 1974 for federal agency records, or a sector law like the Family Educational Rights and Privacy Act) incorporates it.

ByCASRAI Editorial Board
· Last updated 17 Jul 2026

Ask about Fair Information Practice Principles (FIPPs)

Answers are drawn from this dictionary entry and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Examples

Worked examples

  • Is an instance

    A U.S. federal agency's Privacy Impact Assessment (PIA) process, required under the E-Government Act of 2002, applies FIPPs directly: before deploying a new system that collects personal data, the agency must document why the data is needed (purpose specification), what will and won't be collected (data minimization), how individuals can access and correct their own records (individual participation), and how the data is secured — all FIPPs categories.

  • Is an instance

    A university sponsored-programs office handling a federally funded human-subjects study with identifiable data applies FIPPs-consistent controls — a data use agreement limiting secondary use, an access/correction pathway for participants, and documented security safeguards — alongside (not instead of) Common Rule/IRB requirements, since FIPPs describes broad privacy-governance norms rather than research-ethics review itself.

Counter-examples

Looks similar, but isn't

  • Not an instance

    The FAIR Data Principles (Findable, Accessible, Interoperable, Reusable) are a distinct framework with a similar-sounding name and no privacy-law lineage: FAIR describes how to make research data discoverable and reusable via metadata and persistent identifiers, and applies regardless of whether the data contains personal information. A dataset can be fully FAIR while containing no personal data at all, or can be FIPPs-compliant (properly governed personal data) while being poorly described and non-FAIR. The two frameworks address different problems and are not substitutes for one another.

Editorial commentary

Fair Information Practice Principles (FIPPs) are a set of privacy-governance norms, originating in U.S. federal policy, that describe how organizations should collect, use, disclose, and protect personal information. They are the conceptual foundation of the Privacy Act of 1974 and continue to inform U.S. federal agency privacy policy today, including agency Privacy Impact Assessment (PIA) practice under the E-Government Act of 2002.

Not to be confused with the FAIR Data Principles

FIPPs and the FAIR Data Principles (Findable, Accessible, Interoperable, Reusable) share an acronym-adjacent name and nothing else. FAIR is a 2016 research-data stewardship framework concerned with making datasets discoverable and reusable through good metadata and persistent identifiers — it says nothing about whether data is personal or how it should be governed for privacy. FIPPs is a decades-older, U.S. privacy-law framework concerned with the opposite question: how personal data about identifiable individuals should be handled, regardless of whether that data is ever shared or reused. A research dataset can be scored against FAIR criteria and separately, independently, need to satisfy FIPPs-consistent privacy controls if it contains personal or human-subjects data — the two assessments do not overlap and neither substitutes for the other. Research-administration teams evaluating a data management plan should treat "is this dataset FAIR?" and "is this dataset’s personal-data handling FIPPs-consistent (or otherwise compliant with the applicable privacy law)?" as two separate checklist items.

Origin and legal status

FIPPs trace to the U.S. Department of Health, Education, and Welfare’s 1973 report Records, Computers, and the Rights of Citizens, which proposed a "code of fair information practices" in response to growing concern about computerized recordkeeping. Congress drew on that report, refining it into eight statutory safeguards, when it enacted the Privacy Act of 1974, which governs how U.S. federal agencies maintain systems of records containing personal information. The OECD’s 1980 Guidelines on the Protection of Privacy and Transborder Flows of Personal Data reflect a closely related set of principles and helped internationalize the framework. FIPPs itself is not a statute and creates no independent legal obligation; it becomes enforceable only through the specific laws that incorporate it, chiefly the Privacy Act of 1974 for federal agency records, with adjacent influence visible in sector laws such as FERPA for education records.

Because no single numbered list is authoritative, restatements vary. The original HEW report set out five principles; the Privacy Act of 1974 codifies eight; a widely cited modern restatement, the U.S. Department of Homeland Security’s 2008 Privacy Policy Guidance Memorandum, groups them into eight principles commonly cited as: Transparency, Individual Participation, Purpose Specification, Data Minimization, Use Limitation, Data Quality and Integrity, Security, and Accountability and Auditing. Despite the differing counts, the substance is consistent across versions: tell people what data you collect and why, collect and use no more than necessary, let people see and correct their own records, secure the data, and be accountable for all of the above.

Why this matters for research administration

Research offices encounter FIPPs-adjacent obligations wherever a project touches personally identifiable information held by or on behalf of a U.S. federal agency — for example, systems built to fulfill a federal grant’s reporting requirements, or federally sponsored studies that trigger a Privacy Impact Assessment. FIPPs is a useful vocabulary for describing privacy-by-design practice in a Data Management Plan, but it sits alongside — not instead of — the specific compliance regime that actually governs a given project, such as the Common Rule for human-subjects research, HIPAA for protected health information, FERPA for education records, or GDPR for data concerning EU residents.

Related terms

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="Fair Information Practice Principles (FIPPs)"
      vocab-term-identifier="https://casrai.org/dictionary/term/fair-information-practice-principles-fipps" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/fair-information-practice-principles-fipps",
  "name": "Fair Information Practice Principles (FIPPs)",
  "identifier": "https://casrai.org/dictionary/term/fair-information-practice-principles-fipps",
  "description": "Fair Information Practice Principles (FIPPs) are a U.S.-originated framework of privacy norms governing how organizations collect, use, disclose, and secure personal information. First articulated in the 1973 HEW report Records, Computers, and the Rights of Citizens, they underpin the Privacy Act of 1974 and were later reflected in the OECD's 1980 Guidelines on the Protection of Privacy. A dataset-handling or systems practice qualifies as FIPPs-aligned when it addresses, at minimum: transparency/notice about what personal data is collected and why; purpose specification and use limitation (data used only for stated, compatible purposes); data minimization (collecting no more than necessary); individual participation (the ability to access, correct, or contest one's own records); data quality and integrity; security safeguards; and accountability for compliance. There is no single canonical numbered list — the original HEW report set out five principles, the Privacy Act of 1974 codified eight statutory safeguards, and later agency restatements (for example the U.S. Department of Homeland Security's widely cited 2008 formulation) group them into eight principles: Transparency, Individual Participation, Purpose Specification, Data Minimization, Use Limitation, Data Quality and Integrity, Security, and Accountability and Auditing. FIPPs is a governance framework, not itself a statute — it becomes binding only where a specific law (such as the Privacy Act of 1974 for federal agency records, or a sector law like the Family Educational Rights and Privacy Act) incorporates it.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
  "url": "https://casrai.org/dictionary/term/fair-information-practice-principles-fipps",
  "sameAs": [],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "dateModified": "2026-07-17T22:08:45",
  "inLanguage": "en"
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →