Certified Information Privacy Professional Online Privacy and Technology 1 — Questions and Answers
Question 1: Under COPPA, what must operators of child-directed websites obtain before collecting personal information from children under 13?
- Verifiable parental consent (Correct answer)
- Written school permission
- State department of education approval
- FTC pre-clearance
Correct answer: Verifiable parental consent
COPPA requires operators to obtain verifiable parental consent before collecting, using, or disclosing personal information from children under 13.
Question 2: Which law regulates the interception of electronic communications during transmission in the United States?
- Electronic Communications Privacy Act (ECPA) — Wiretap Act (Correct answer)
- Computer Fraud and Abuse Act (CFAA)
- CAN-SPAM Act
- Stored Communications Act
Correct answer: Electronic Communications Privacy Act (ECPA) — Wiretap Act
Title I of ECPA, known as the Wiretap Act, prohibits the intentional interception of wire, oral, or electronic communications during transmission.
Question 3: What standard does the CAN-SPAM Act establish for commercial email senders?
- Opt-out framework requiring unsubscribe mechanisms and accurate sender information (Correct answer)
- Opt-in consent required before any commercial email
- Prohibition on all unsolicited commercial email
- Email marketing governed solely by state law
Correct answer: Opt-out framework requiring unsubscribe mechanisms and accurate sender information
CAN-SPAM establishes an opt-out framework, requiring accurate headers, functioning unsubscribe mechanisms, and physical address disclosure but not prior consent.
Question 4: Under the Computer Fraud and Abuse Act (CFAA), what is a core prohibited activity?
- Accessing a computer without authorization or exceeding authorized access (Correct answer)
- Using strong encryption without government approval
- Collecting personal data without a privacy policy
- Sending commercial email without prior consent
Correct answer: Accessing a computer without authorization or exceeding authorized access
The CFAA's core prohibition targets unauthorized access to computers and accessing computers in excess of authorization.
Question 5: Which FTC Act provision is primarily used to regulate unfair or deceptive online privacy practices?
- Section 5 prohibiting unfair or deceptive acts or practices (Correct answer)
- Section 7 prohibiting anti-competitive mergers
- Section 12 prohibiting false advertisements for food
- Section 2 defining the FTC's jurisdiction
Correct answer: Section 5 prohibiting unfair or deceptive acts or practices
FTC Section 5, prohibiting unfair or deceptive acts or practices, is the primary authority the FTC uses to enforce privacy commitments and challenge deceptive privacy practices.
Question 6: What is 'behavioral advertising' and why does it raise privacy concerns?
- Targeting ads based on tracking user browsing behavior across sites, raising concerns about covert data collection without meaningful consent (Correct answer)
- Advertising that changes based on the user's mood detected via camera
- Advertising limited to users who have opted into a loyalty program
- Display advertising that uses only aggregated demographic data
Correct answer: Targeting ads based on tracking user browsing behavior across sites, raising concerns about covert data collection without meaningful consent
Behavioral advertising tracks users across websites to build profiles for targeted ads, raising concerns about lack of transparency, meaningful consent, and potential for sensitive inferences.
Under COPPA, what must operators of child-directed websites obtain before collecting personal information from children under 13?