Begin by identifying the federal regulatory and legal privacy controls applicable to your organization, such as the Health Insurance Portability and Accountability Act (HIPAA), the Gramm-Leach-Bliely Act, the Children's Online Privacy Protection Act and the Privacy of Consumer Financial Information Act.