CEC Legal & Regulatory Compliance 2 — Questions and Answers
Question 1: Under the CAN-SPAM Act, what is the maximum penalty per individual violation for sending non-compliant commercial emails?
- $500
- $5,000
- $51,744 (Correct answer)
- $100,000
Correct answer: $51,744
The CAN-SPAM Act allows civil penalties of up to $51,744 per individual email that violates its provisions.
Question 2: An ecommerce site collects data from users in the EU. Under GDPR, what is the maximum fine for the most serious violations?
- €10 million or 2% of global annual turnover
- €20 million or 4% of global annual turnover (Correct answer)
- €50 million or 5% of global annual turnover
- €100 million or 10% of global annual turnover
Correct answer: €20 million or 4% of global annual turnover
GDPR's highest tier of fines is €20 million or 4% of global annual turnover, whichever is greater.
Question 3: Which US law specifically regulates the online collection of personal information from children under 13?
- FERPA
- CCPA
- COPPA (Correct answer)
- HIPAA
Correct answer: COPPA
COPPA (Children's Online Privacy Protection Act) requires verifiable parental consent before collecting personal data from children under 13.
Question 4: A US ecommerce merchant selling to California residents must comply with CCPA. Which of the following is NOT a right granted to consumers under CCPA?
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt out of the sale of personal information
- Right to receive monetary compensation for all data collected (Correct answer)
Correct answer: Right to receive monetary compensation for all data collected
CCPA grants rights to know, delete, and opt out of data sales, but does not provide a blanket right to monetary compensation for data collection.
Question 5: When displaying prices to international customers, which regulatory principle requires that the final price shown (including mandatory fees) be the price charged?
- Price parity rule
- All-in pricing requirement (Correct answer)
- Dynamic pricing disclosure
- Currency conversion mandate
Correct answer: All-in pricing requirement
All-in pricing requirements, enforced by agencies like the FTC, mandate that advertised prices include all mandatory fees to prevent deceptive pricing.
Question 6: An ecommerce store uses a pre-checked opt-in box to enroll customers in a recurring subscription. Under US FTC guidelines, this practice is considered:
- Acceptable if disclosed in the terms of service
- A dark pattern that may constitute deceptive practice (Correct answer)
- Legal provided a 30-day free trial is offered
- Standard industry practice that requires no special disclosure
Correct answer: A dark pattern that may constitute deceptive practice
Pre-checked subscription boxes are classified as dark patterns by the FTC and may constitute deceptive or unfair practices under Section 5 of the FTC Act.
Question 7: Which regulation requires ecommerce businesses that accept payment cards to adhere to data security standards for cardholder data protection?
- SOX
- PCI DSS (Correct answer)
- GLBA
- ISO 27001
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) is the industry-mandated standard for protecting cardholder data in payment processing.
Under the CAN-SPAM Act, what is the maximum penalty per individual violation for sending non-compliant commercial emails?