Certified Information Privacy Professional Online Privacy and Technology 2 — Questions and Answers
Question 1: Under COPPA, what are the notice requirements for operators of child-directed websites?
- Post a clear privacy policy and provide direct notice to parents before collecting data (Correct answer)
- Send annual mailings to all parents of users
- Obtain FTC approval for all data collection practices
- Display a COPPA seal of approval on the homepage
Correct answer: Post a clear privacy policy and provide direct notice to parents before collecting data
COPPA requires operators to post a comprehensive privacy policy on their site and provide direct notice to parents, describing data practices, before collecting children's information.
Question 2: What does the Stored Communications Act (SCA), part of ECPA, primarily protect?
- Electronic communications stored by third-party service providers from unauthorized government and private access (Correct answer)
- Computer data stored on personal devices from law enforcement
- All digital records from any third-party access
- Only email stored on company servers
Correct answer: Electronic communications stored by third-party service providers from unauthorized government and private access
The SCA (Title II of ECPA) protects electronic communications held in storage by third-party service providers from unauthorized access by both governments and private parties.
Question 3: Which principle guides cookie consent requirements under US state privacy laws like CCPA?
- Opt-out for non-essential cookies used for cross-context behavioral advertising (Correct answer)
- Opt-in consent required for all cookies
- No US law regulates cookie consent
- Opt-out only applies to health-related cookies
Correct answer: Opt-out for non-essential cookies used for cross-context behavioral advertising
Under CCPA/CPRA, cookies used for cross-context behavioral advertising or sale of personal information trigger opt-out rights, not opt-in consent requirements.
Question 4: What is a 'dark pattern' in the context of online privacy, and why is it a regulatory concern?
- A deceptive UI design that manipulates users into sharing more data or opting into unwanted settings (Correct answer)
- A website's dark color theme that reduces screen brightness
- Encryption techniques that hide data from regulators
- A legitimate UX pattern for presenting privacy notices
Correct answer: A deceptive UI design that manipulates users into sharing more data or opting into unwanted settings
Dark patterns are manipulative UI/UX designs that trick users into choices they would not otherwise make, such as pre-checked consent boxes or confusing opt-out flows.
Question 5: Under the Video Privacy Protection Act (VPPA), what is prohibited?
- Disclosing a person's video rental or purchase records without consent (Correct answer)
- Recording video in public spaces without a permit
- Streaming video content across state lines without a license
- Using cookies to track video viewing habits without notice
Correct answer: Disclosing a person's video rental or purchase records without consent
The VPPA prohibits video tape service providers from knowingly disclosing personally identifiable information about consumers' video rental or purchase records without consent.
Question 6: Which best describes a 'privacy by design' approach in technology development?
- Embedding privacy protections into system design from the start rather than adding them later (Correct answer)
- Designing systems with minimal user interface
- Using privacy-enhancing technologies only in government systems
- Publishing privacy policies before launching any product
Correct answer: Embedding privacy protections into system design from the start rather than adding them later
Privacy by design means proactively embedding privacy into the architecture, design, and operation of systems from inception rather than retrofitting it after development.
Under COPPA, what are the notice requirements for operators of child-directed websites?