CEC Legal & Regulatory Compliance 5 — Questions and Answers
Question 1: An ecommerce retailer operating as a marketplace platform facilitates a sale of counterfeit goods by a third-party seller. Under the DMCA safe harbor provisions, the platform may avoid liability if it:
- Was unaware of the counterfeit listing and removed it promptly upon notification (Correct answer)
- Earned no revenue from the transaction
- Screened all listings before publication
- Stored products in its own warehouse
Correct answer: Was unaware of the counterfeit listing and removed it promptly upon notification
DMCA safe harbor protects platforms from copyright (and by extension some IP) liability if they had no knowledge of infringement and acted expeditiously to remove infringing content upon notification.
Question 2: A US ecommerce company collects health-related data through its wellness product store. When does HIPAA apply to this data?
- Whenever any health information is collected online
- Only when the company is a covered entity or business associate as defined by HIPAA (Correct answer)
- When more than 500 customer health records are collected
- When the company accepts health insurance as a payment method
Correct answer: Only when the company is a covered entity or business associate as defined by HIPAA
HIPAA applies only to covered entities (healthcare providers, insurers, clearinghouses) and their business associates, not to general ecommerce retailers collecting wellness data.
Question 3: Under US export control law (EAR/ITAR), an ecommerce retailer selling dual-use goods must:
- File an export license for every international sale
- Screen customers against denied parties lists and comply with export licensing requirements for controlled items (Correct answer)
- Only comply when shipping to embargoed countries
- Register annually with the Department of Commerce
Correct answer: Screen customers against denied parties lists and comply with export licensing requirements for controlled items
EAR requires exporters to screen against denied/restricted party lists and obtain licenses when exporting controlled dual-use items, regardless of the destination country.
Question 4: Which principle in contract law determines when an ecommerce purchase contract is formed in a 'browse-wrap' agreement?
- When the customer adds an item to the cart
- When the customer completes checkout and receives an order confirmation (Correct answer)
- When the merchant processes the payment
- When the product ships
Correct answer: When the customer completes checkout and receives an order confirmation
In most jurisdictions, a contract is formed upon mutual assent, typically at checkout confirmation, though merchants should clearly define the offer and acceptance point in their terms.
Question 5: A California consumer files a CCPA request to delete their personal data. The ecommerce business must respond within:
- 30 days, with a possible 30-day extension
- 45 days, with a possible 45-day extension (Correct answer)
- 60 days with no extension
- 10 business days
Correct answer: 45 days, with a possible 45-day extension
CCPA requires businesses to respond to verified consumer deletion requests within 45 days, with one 45-day extension allowed if necessary, for a maximum of 90 days total.
Question 6: Under the Telephone Consumer Protection Act (TCPA), sending SMS marketing messages to consumers requires:
- Only that an opt-out link be included in each message
- Prior express written consent from the recipient (Correct answer)
- A 24-hour cooling-off period after account creation
- Consent implied by the consumer providing their phone number at checkout
Correct answer: Prior express written consent from the recipient
TCPA requires prior express written consent for autodialed or prerecorded marketing text messages, and merely providing a phone number at checkout does not constitute consent for marketing SMS.
Question 7: An ecommerce business discovers a GDPR-covered personal data breach. Under GDPR Article 33, the supervisory authority must be notified within:
- 24 hours of discovery
- 72 hours of becoming aware of the breach (Correct answer)
- 7 calendar days of becoming aware of the breach
- 30 days of becoming aware of the breach
Correct answer: 72 hours of becoming aware of the breach
GDPR Article 33 requires notification to the competent supervisory authority within 72 hours of becoming aware of a personal data breach, where feasible.
An ecommerce retailer operating as a marketplace platform facilitates a sale of counterfeit goods by a third-party seller.
Under the DMCA safe harbor provisions, the platform may avoid liability if it: