CIPM CIPM Consent Management 2 — Questions and Answers
Question 1: What is the fundamental difference between opt-in and opt-out consent models?
- Opt-in requires active agreement before processing; opt-out assumes consent exists unless the individual declines (Correct answer)
- Opt-in is only required for marketing; opt-out is required for all processing activities
- Opt-in is a US regulatory requirement; opt-out is the GDPR standard
- Opt-in requires a written signature; opt-out can be communicated verbally
Correct answer: Opt-in requires active agreement before processing; opt-out assumes consent exists unless the individual declines
Opt-in models require individuals to actively indicate consent before processing occurs, while opt-out models assume consent exists unless the individual takes action to decline.
Question 2: Under GDPR, how must organizations handle a request to withdraw consent?
- Process the withdrawal within 90 days of receipt
- Make withdrawal as easy as giving consent was (Correct answer)
- Require written supervisor confirmation before acting on withdrawal
- Accept withdrawal only through official regulatory forms
Correct answer: Make withdrawal as easy as giving consent was
GDPR Article 7(3) requires that withdrawing consent be as easy as giving it, ensuring individuals can effectively revoke consent without undue burden.
Question 3: Which CAN-SPAM Act requirement relates most directly to email consent management?
- Senders must obtain affirmative opt-in before sending any commercial email
- Recipients must be given a clear and conspicuous way to opt out of future emails (Correct answer)
- All commercial emails must be pre-approved by the FTC before sending
- Senders must retain consent records for a minimum of ten years
Correct answer: Recipients must be given a clear and conspicuous way to opt out of future emails
The CAN-SPAM Act requires commercial email senders to include a clear opt-out mechanism and honor opt-out requests within 10 business days.
Question 4: What does 'granular consent' mean in the context of privacy management?
- Collecting the minimum data necessary to reduce consent complexity
- Providing separate consent choices for each distinct processing purpose (Correct answer)
- Storing all consent records within a single centralized database
- Requiring individual consent for every data field collected
Correct answer: Providing separate consent choices for each distinct processing purpose
Granular consent means individuals are offered separate choices for distinct processing purposes rather than one bundled consent for all activities.
Question 5: Under GDPR, what determines how long a previously obtained consent record remains valid?
- Consents expire after one year automatically
- Consents expire after two years by regulation
- Consent remains valid until the purpose is fulfilled or the individual withdraws it (Correct answer)
- Consent is valid forever unless the controller chooses to refresh it
Correct answer: Consent remains valid until the purpose is fulfilled or the individual withdraws it
Consent remains valid only as long as the processing purpose exists and the individual has not withdrawn it; organizations should periodically review consent records.
Question 6: What is a 'consent receipt' in privacy management practice?
- A payment acknowledgment for privacy compliance services
- A record provided to individuals confirming the terms of their consent (Correct answer)
- A government-issued document authorizing specific data processing activities
- A technical specification standard for cookie consent management
Correct answer: A record provided to individuals confirming the terms of their consent
A consent receipt is a record given to individuals at the time of consent documenting what they agreed to, supporting transparency, accountability, and auditability.
What is the fundamental difference between opt-in and opt-out consent models?