CEC Legal & Regulatory Compliance 4 — Questions and Answers
Question 1: Which US federal law requires companies to notify consumers when their unencrypted personal information may have been accessed in a data breach?
- CCPA
- HIPAA
- There is no single federal breach notification law — it is governed by state laws (Correct answer)
- COPPA
Correct answer: There is no single federal breach notification law — it is governed by state laws
The US has no single federal data breach notification law; instead, all 50 states have enacted their own breach notification statutes with varying requirements.
Question 2: An ecommerce retailer wants to use dynamic pricing that charges different customers different prices. Under US law, this practice is:
- Always illegal under the Robinson-Patman Act
- Generally legal but prohibited if based on protected class characteristics (Correct answer)
- Legal only if disclosed in the terms of service
- Regulated exclusively by the FTC's pricing guidelines
Correct answer: Generally legal but prohibited if based on protected class characteristics
Dynamic pricing is generally legal in the US but becomes unlawful price discrimination when pricing differentials are based on protected class characteristics such as race or national origin.
Question 3: Under GDPR, a 'data processor' differs from a 'data controller' in that the processor:
- Owns the data being processed
- Determines the purpose and means of data processing
- Processes data on behalf of the controller without determining processing purposes (Correct answer)
- Is exempt from GDPR obligations entirely
Correct answer: Processes data on behalf of the controller without determining processing purposes
A data processor acts on the controller's instructions and does not independently determine the purpose or means of processing, though processors still have direct GDPR obligations.
Question 4: A US ecommerce site uses behavioral tracking cookies. Under which regulatory framework must it obtain informed consent before placing non-essential cookies on EU visitors' browsers?
- GDPR only
- CCPA only
- ePrivacy Directive (Cookie Law) and GDPR together (Correct answer)
- CAN-SPAM Act
Correct answer: ePrivacy Directive (Cookie Law) and GDPR together
The ePrivacy Directive requires prior informed consent for non-essential cookies, while GDPR governs the personal data collected through those cookies, making both applicable.
Question 5: The FTC's 'Made in USA' standard for ecommerce product labeling requires that:
- Products only need to be assembled in the US
- All or virtually all of the product must be made in the US (Correct answer)
- At least 50% of the product's content must be domestic
- Only final packaging must be completed in the US
Correct answer: All or virtually all of the product must be made in the US
The FTC's 'Made in USA' standard requires that all or virtually all significant parts, processing, and labor are US-origin, with no or negligible foreign content.
Question 6: Which doctrine allows trademark owners to prevent use of their marks in paid search advertising keyword targeting without authorization?
- Fair use doctrine
- Initial interest confusion doctrine (Correct answer)
- Trademark dilution rule
- First sale doctrine
Correct answer: Initial interest confusion doctrine
The initial interest confusion doctrine holds that using a competitor's trademark as a paid search keyword can constitute infringement by creating confusion that diverts consumers, even if cleared up before purchase.
Question 7: Under the Uniform Electronic Transactions Act (UETA) and E-SIGN Act, electronic signatures on ecommerce contracts are:
- Valid only for transactions under $500
- Generally legally equivalent to handwritten signatures (Correct answer)
- Not valid for consumer contracts involving goods
- Valid only when notarized electronically
Correct answer: Generally legally equivalent to handwritten signatures
Both UETA and the federal E-SIGN Act establish that electronic signatures have the same legal effect as handwritten signatures for most commercial and consumer contracts.
Which US federal law requires companies to notify consumers when their unencrypted personal information may have been accessed in a data breach?