Privacy Laws That Shape What You Can and Cannot Find Online
FERPA, HIPAA, and state-level restrictions determine which records are withheld from public view. This explainer maps out the key boundaries.

Photo: searchopenrecords editorial
—— In This Article
Key Takeaways
- HIPAA, FERPA, and the DPPA are the three federal laws most likely to limit what you can find about individuals online.
- State-level privacy statutes add another layer of restrictions that vary significantly by jurisdiction.
- Privacy laws protect categories of data — health, education, driver information — not entire records files.
- Some withheld data can still be accessed with the subject's written consent or through specific legal channels.
- Understanding these limits helps you evaluate why a record search returns partial or redacted results.
Why Some Records Are Off-Limits
Public records systems are built on a principle of transparency: government-held information generally belongs to the public. But that principle has never been absolute. Congress and state legislatures have carved out specific categories of data — health, education, financial, and more — and placed them behind protective statutes that override default disclosure rules.
The result is a layered system. A court case file might be fully public, but if it contains a victim's address, that portion may be redacted under a victim-privacy statute. A government employee's salary is often public, but their personnel medical evaluations are not. Knowing which laws apply to which data categories is the key to understanding why a legitimate record search sometimes returns less than you expected.
For a broader picture of how this balance is struck in practice, see how courts and agencies weigh public interest against personal privacy.
The Three Federal Laws You'll Encounter Most
Three federal statutes account for the majority of information withheld from public searches:
- HIPAA (Health Insurance Portability and Accountability Act): Protects individually identifiable health information held by covered entities — hospitals, insurers, pharmacies, and their business associates. No portion of a patient's medical record is accessible through a standard public records request.
- FERPA (Family Educational Rights and Privacy Act): Shields education records at institutions receiving federal funding. Grades, disciplinary records, transcripts, and enrollment details are protected from third-party disclosure without student consent. Directory information (name, graduation year) may be released unless the student opts out.
- DPPA (Driver's Privacy Protection Act): Restricts state DMVs from releasing personal information — home addresses, Social Security numbers, phone numbers — linked to motor vehicle registrations or driver's licenses. Fourteen enumerated exceptions exist, covering uses like insurance underwriting and law enforcement.
For a complete plain-language breakdown of these and related statutes, the federal privacy laws that shape public records access article covers each in detail.
FOIA Does Not Override Privacy Statutes
A common misconception is that the Freedom of Information Act (FOIA) can be used to obtain any federal government record. In practice, FOIA includes nine exemptions — and Exemption 6 specifically protects personnel, medical, and similar files where disclosure would constitute a clearly unwarranted invasion of personal privacy. HIPAA-protected health records held by federal agencies remain protected even under a FOIA request. See what FOIA does and does not cover for a full breakdown.
State-Level Restrictions Add Another Layer
Federal statutes set a floor, but states are free to build higher walls. California's Consumer Privacy Act (CCPA), for example, gives residents the right to know what personal data businesses collect about them and to request deletion — protections that extend well beyond federal baseline requirements. Illinois, Texas, and Washington have enacted biometric privacy laws that restrict collection of fingerprints and facial recognition data.
Even within traditional public records categories, state law determines what's actually accessible. Arrest records without convictions may be expunged automatically in some states; in others they remain public indefinitely. Court records involving domestic violence may be sealed by default in certain jurisdictions. These differences matter enormously when you're trying to interpret a search result — a missing record may simply reflect the state you're searching in.
The state-by-state breakdown of public records access maps out the key variables across jurisdictions, including timelines, exemptions, and fee structures.
Special Protections for Vulnerable Populations
Privacy protections are strongest where the potential for harm is greatest. Two populations receive particularly robust legal shielding:
Minors: Juvenile court records, child welfare files, and school disciplinary records are sealed in most states. The underlying policy is rehabilitative — a young person's early mistakes should not define their adult record. See which records involving children are shielded and why for more detail.
Crime victims: Many states prohibit disclosure of victims' names, addresses, and testimony in certain case types, particularly sexual assault, domestic violence, and human trafficking. Federal law also imposes restrictions in specific circumstances. The victim privacy laws that restrict access to court records article explains how these rules operate across case types.
When a court record search returns redacted names or sealed case numbers, these protections are likely the reason — not a system error or missing data.
14
Permissible-use exceptions under the DPPA
The Driver's Privacy Protection Act enumerates exactly 14 lawful purposes for which state DMV records may be released, including insurance, law enforcement, and licensed private investigators.
50+
Distinct state public records statutes in force
Every U.S. state and the District of Columbia operates its own public records law, each with unique exemptions, timelines, and fee schedules that affect what is accessible.
$100–$50,000
HIPAA civil penalty range per violation
The HHS Office for Civil Rights can impose civil monetary penalties per HIPAA violation, scaled by culpability level, creating strong institutional incentives to withhold protected health information.
How to Search Smarter Within These Limits
Understanding what's legally withheld changes how you approach a search. Rather than assuming a gap means data doesn't exist, consider whether a privacy statute applies to that record category. A few practical principles:
- Match your request to the right agency. Some protected records can be accessed by the subject themselves through a formal request. The Privacy Act of 1974's role in limiting public records explains how individuals can invoke their own access rights against federal agencies.
- Know the permissible-use exceptions. DPPA, FCRA, and similar statutes allow access under specific, documented purposes — employment screening, insurance underwriting, tenant verification. Using data outside these purposes creates legal exposure.
- Check state law before assuming federal rules apply. For address lookups and people-search queries specifically, FCRA rules and permissible purposes for address lookups walks through the governing framework.
This article is for general informational purposes only and does not constitute legal advice. For questions about your specific rights or obligations under privacy law, consult a licensed attorney.
