Consent Management Flashcards
7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Consent Management flashcards as text
What is 'consent fatigue' and what risk does it pose to effective privacy management?
Answer: Consent fatigue describes users routinely clicking 'accept all' without reading consent notices due to an overwhelming number of consent requests, undermining informed consent
When users are bombarded with constant consent dialogs, they habitually accept everything without reading, defeating the purpose of informed consent as a privacy safeguard.
Which elements must a valid consent notice include to meet GDPR requirements?
Answer: The controller's identity, processing purposes, data types, right to withdraw, and any third-party sharing
A valid GDPR consent notice must clearly identify the controller, state the specific purposes, describe the data involved, disclose third-party sharing, and inform users of their right to withdraw.
When sharing personal data with third-party vendors, what consent-related obligation does the data controller bear?
Answer: The controller must ensure the original consent obtained from data subjects explicitly covered sharing with those third parties or obtain new consent
Controllers must ensure that consent collected from individuals actually covered the intended third-party sharing; transferring data to undisclosed parties violates the specificity requirement of valid consent.
What is the role of a Data Protection Officer (DPO) with respect to consent management programs?
Answer: The DPO advises on consent mechanisms, monitors compliance, and serves as a point of contact for data subjects exercising their rights
Under GDPR Article 39, the DPO advises the controller on consent obligations, monitors lawfulness of processing, and acts as a contact point for regulators and data subjects.
What is 'bundled consent' and why do data protection authorities consider it invalid under GDPR?
Answer: Bundled consent combines unrelated processing purposes into a single checkbox, making it impossible for users to consent selectively, thus violating the specificity and freely given requirements
Bundled consent packages consent for multiple purposes (e.g., marketing, profiling, sharing) into a single accept-all action, denying users the ability to accept some and decline others as required by GDPR.
Under GDPR Article 7(3), which statement best describes the right to withdraw consent?
Answer: The data subject may withdraw consent at any time, the withdrawal must be as easy as giving consent, and prior processing remains lawful
GDPR Article 7(3) states that data subjects can withdraw consent at any time with ease, but lawful processing carried out before withdrawal is not retroactively invalidated.
How does the US CCPA's consent approach for opt-out of data sale differ from GDPR's opt-in consent model?
Answer: CCPA gives consumers the right to opt out of the sale of their data via a 'Do Not Sell My Personal Information' link, whereas GDPR requires affirmative opt-in consent before processing
CCPA uses an opt-out model for data sales — processing is allowed by default and consumers must actively opt out — while GDPR's consent basis requires prior affirmative opt-in.