Legal & Regulatory Compliance Flashcards
7 cards from real CEC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Legal & Regulatory Compliance flashcards as text
Under the CAN-SPAM Act, what is the maximum penalty per individual violation for sending non-compliant commercial emails?
Answer: $51,744
The CAN-SPAM Act allows civil penalties of up to $51,744 per individual email that violates its provisions.
An ecommerce site collects data from users in the EU. Under GDPR, what is the maximum fine for the most serious violations?
Answer: €20 million or 4% of global annual turnover
GDPR's highest tier of fines is €20 million or 4% of global annual turnover, whichever is greater.
Which US law specifically regulates the online collection of personal information from children under 13?
Answer: COPPA
COPPA (Children's Online Privacy Protection Act) requires verifiable parental consent before collecting personal data from children under 13.
A US ecommerce merchant selling to California residents must comply with CCPA. Which of the following is NOT a right granted to consumers under CCPA?
Answer: Right to receive monetary compensation for all data collected
CCPA grants rights to know, delete, and opt out of data sales, but does not provide a blanket right to monetary compensation for data collection.
When displaying prices to international customers, which regulatory principle requires that the final price shown (including mandatory fees) be the price charged?
Answer: All-in pricing requirement
All-in pricing requirements, enforced by agencies like the FTC, mandate that advertised prices include all mandatory fees to prevent deceptive pricing.
An ecommerce store uses a pre-checked opt-in box to enroll customers in a recurring subscription. Under US FTC guidelines, this practice is considered:
Answer: A dark pattern that may constitute deceptive practice
Pre-checked subscription boxes are classified as dark patterns by the FTC and may constitute deceptive or unfair practices under Section 5 of the FTC Act.
Which regulation requires ecommerce businesses that accept payment cards to adhere to data security standards for cardholder data protection?
Answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) is the industry-mandated standard for protecting cardholder data in payment processing.