CEC Legal & Regulatory Compliance 3 — Questions and Answers
Question 1: Under the FTC's Negative Option Rule (updated 2023), what must a seller provide before enrolling a customer in a negative option program?
- Only written notice in the terms of service
- Clear and conspicuous disclosure of all material terms before obtaining consent (Correct answer)
- A 14-day cooling-off period automatically
- A government-issued disclosure form
Correct answer: Clear and conspicuous disclosure of all material terms before obtaining consent
The updated FTC Negative Option Rule requires clear and conspicuous disclosure of all material subscription terms before obtaining the consumer's billing consent.
Question 2: A US-based ecommerce site uses customer testimonials in its advertising. Under FTC Endorsement Guidelines, which disclosure is required when a reviewer received free products?
- No disclosure needed if the review is genuine
- Disclosure only if the product value exceeds $100
- Clear and conspicuous disclosure of the material connection (Correct answer)
- A legal disclaimer in the site footer only
Correct answer: Clear and conspicuous disclosure of the material connection
FTC Endorsement Guidelines require clear and conspicuous disclosure of any material connection between the endorser and the seller, including receiving free products.
Question 3: The Electronic Communications Privacy Act (ECPA) primarily governs which ecommerce activity?
- Online advertising targeting
- Interception and disclosure of electronic communications (Correct answer)
- Cross-border data transfers
- Cookie consent requirements
Correct answer: Interception and disclosure of electronic communications
ECPA prohibits unauthorized interception and disclosure of electronic communications including emails, prohibiting access to stored electronic communications without authorization.
Question 4: When an ecommerce business stores EU customer data on US servers, which mechanism is commonly used to legitimize these cross-border data transfers after the invalidation of Privacy Shield?
- Binding corporate rules only
- Standard Contractual Clauses (SCCs) (Correct answer)
- Data localization mandate
- FTC Safe Harbor certification
Correct answer: Standard Contractual Clauses (SCCs)
Standard Contractual Clauses (SCCs) are the most widely used mechanism for legitimizing EU-to-US data transfers after Privacy Shield was invalidated by the Schrems II ruling.
Question 5: Under the Americans with Disabilities Act (ADA), US courts have increasingly ruled that ecommerce websites must:
- Only comply if they have a physical storefront
- Meet WCAG 2.1 AA accessibility standards (Correct answer)
- Provide phone-based alternatives to online purchasing
- Comply only if annual revenue exceeds $1 million
Correct answer: Meet WCAG 2.1 AA accessibility standards
US courts have broadly applied ADA Title III to ecommerce websites, requiring conformance with WCAG 2.1 AA guidelines to ensure accessibility for people with disabilities.
Question 6: A merchant sells a product online that causes injury to a customer. Under strict product liability doctrine, the merchant:
- Is only liable if they manufactured the product
- May be liable regardless of negligence if the product was defective (Correct answer)
- Is exempt from liability if a disclaimer was included
- Is only liable if the injury occurred during the return window
Correct answer: May be liable regardless of negligence if the product was defective
Strict product liability holds sellers in the distribution chain liable for defective products regardless of fault or negligence, even if they did not manufacture the product.
Question 7: Under the Restore Online Shoppers' Confidence Act (ROSCA), post-transaction third-party sellers that obtain billing information from the initial merchant must:
- Simply include terms in their privacy policy
- Obtain the consumer's billing information directly from the consumer (Correct answer)
- Obtain consent only after a 30-day trial period
- Disclose the sale through a checkout page banner
Correct answer: Obtain the consumer's billing information directly from the consumer
ROSCA prohibits post-transaction sellers from charging consumers using billing data passed from the initial merchant without the consumer's express informed consent and direct billing data entry.
Under the FTC's Negative Option Rule (updated 2023), what must a seller provide before enrolling a customer in a negative option program?