CDPSE Consent Management 2 — Questions and Answers
Question 1: What is 'implied consent' and why is it generally insufficient under modern privacy regulations?
- Implied consent is documented consent stored in an encrypted log; regulators prefer verbal consent instead
- Implied consent is inferred from user behavior without explicit agreement; regulations such as GDPR require unambiguous action (Correct answer)
- Implied consent refers to consent given by a legal guardian; most laws now require direct consent from the individual
- Implied consent is consent obtained through a third party; regulations require first-party consent only
Correct answer: Implied consent is inferred from user behavior without explicit agreement; regulations such as GDPR require unambiguous action
Implied consent assumes agreement from passive behavior (e.g., continued browsing), which fails the unambiguous affirmative action standard required by GDPR and similar laws.
Question 2: Under COPPA (Children's Online Privacy Protection Act), what is required before collecting personal data from children under 13 in the US?
- Consent from the child using an age-appropriate interface
- Verifiable parental consent obtained before collection begins (Correct answer)
- A signed data processing agreement with the school the child attends
- Consent from a court-appointed privacy guardian
Correct answer: Verifiable parental consent obtained before collection begins
COPPA mandates verifiable parental consent before any personal information is collected from children under 13, given their limited legal capacity to consent.
Question 3: Why is maintaining a consent record or audit trail critical for CDPSE professionals?
- It improves website load time by caching consent decisions closer to the user
- It provides evidence of compliance and enables organizations to demonstrate that valid consent was obtained when challenged (Correct answer)
- It allows marketing teams to segment audiences based on their consent history
- It is required solely for financial data under Sarbanes-Oxley regulations
Correct answer: It provides evidence of compliance and enables organizations to demonstrate that valid consent was obtained when challenged
Consent records serve as proof of compliance; under GDPR Article 7(1), controllers bear the burden of demonstrating that valid consent was obtained.
Question 4: In the context of cookie consent, what does the ePrivacy Directive require before placing non-essential cookies?
- Disclosure of cookie use in the site's terms of service, which users implicitly accept
- Prior informed consent from the user before placing any type of cookie
- Prior informed consent from the user before placing non-essential cookies such as analytics or advertising cookies (Correct answer)
- Encryption of all cookie data and notification within 72 hours of placement
Correct answer: Prior informed consent from the user before placing non-essential cookies such as analytics or advertising cookies
The ePrivacy Directive requires prior informed consent for non-essential cookies (analytics, advertising, tracking), while strictly necessary cookies are exempt.
Question 5: How does the principle of 'purpose limitation' interact with consent management?
- Purpose limitation allows an organization to reuse consent for any future processing that benefits the user
- Purpose limitation means consent obtained for one specific purpose cannot be used to justify processing for a different purpose without new consent (Correct answer)
- Purpose limitation requires deleting data after the initially consented purpose is fulfilled within 30 days
- Purpose limitation is a financial regulation unrelated to privacy consent
Correct answer: Purpose limitation means consent obtained for one specific purpose cannot be used to justify processing for a different purpose without new consent
Purpose limitation (GDPR Article 5(1)(b)) requires that data collected under consent for purpose A cannot be repurposed for purpose B without obtaining fresh consent.
Question 6: Which of the following is a lawful basis for processing personal data that does NOT require obtaining consent under GDPR?
- Sending promotional newsletters to existing customers
- Processing biometric data for employee time tracking
- Processing data that is strictly necessary to fulfill a contract with the data subject (Correct answer)
- Sharing personal data with advertising partners for behavioral targeting
Correct answer: Processing data that is strictly necessary to fulfill a contract with the data subject
Contract performance is one of six lawful bases under GDPR Article 6; when processing is necessary to execute a contract, consent is not required as the legal basis.
Question 7: What is 'dynamic consent' and how does it benefit data subjects in long-term research studies?
- Dynamic consent is a one-time consent that automatically renews every year without user action
- Dynamic consent allows participants to continuously review, update, or withdraw their consent for specific uses of their data over time via an online platform (Correct answer)
- Dynamic consent is consent granted by a data subject's attorney that adapts to regulatory changes
- Dynamic consent is a machine-learning model that predicts whether a user would consent to a new data use
Correct answer: Dynamic consent allows participants to continuously review, update, or withdraw their consent for specific uses of their data over time via an online platform
Dynamic consent frameworks give research participants ongoing control by providing an interface to manage and update their consent preferences as study purposes evolve.
What is 'implied consent' and why is it generally insufficient under modern privacy regulations?