CIPP/US Technology & Online Privacy 2 — Questions and Answers
Question 1: Under most U.S. state data breach notification laws, notification obligations are triggered when:
- Any employee accesses data outside normal hours
- Personal information of state residents is compromised by unauthorized access or acquisition (Correct answer)
- A company experiences any cybersecurity incident regardless of data exposure
- A federal agency independently discovers the breach
Correct answer: Personal information of state residents is compromised by unauthorized access or acquisition
State breach notification laws are generally triggered when personal information of state residents is acquired or accessed by an unauthorized party, creating a risk of harm.
Question 2: The California Consumer Privacy Act (CCPA) grants California consumers the right to do which of the following?
- Delete all data held by any company worldwide
- Know, delete, and opt out of the sale of their personal information (Correct answer)
- Access all government databases containing their information
- Prohibit any collection of personal data by businesses
Correct answer: Know, delete, and opt out of the sale of their personal information
The CCPA grants consumers the right to know what personal information is collected, the right to delete it, and the right to opt out of its sale to third parties.
Question 3: Which federal law restricts the government's ability to compel disclosure of stored electronic communications held by service providers?
- ECPA Stored Communications Act (Correct answer)
- COPPA
- CAN-SPAM Act
- FERPA
Correct answer: ECPA Stored Communications Act
The Stored Communications Act (Title II of ECPA) restricts voluntary disclosure by service providers and limits the government's ability to compel access to stored electronic communications.
Question 4: Under the Computer Fraud and Abuse Act (CFAA), unauthorized access to a protected computer system is classified as:
- A civil matter subject only to private lawsuits
- A federal crime subject to criminal and civil liability (Correct answer)
- An issue governed solely by state law
- Not regulated unless financial data is stolen
Correct answer: A federal crime subject to criminal and civil liability
The CFAA makes unauthorized access to protected computers a federal crime and also provides a civil cause of action for victims.
Question 5: Social media platforms have COPPA obligations when they have:
- More than one million active users
- Actual knowledge that a particular user is under 13 years of age (Correct answer)
- Advertising revenue exceeding a federal threshold
- Offices in more than one U.S. state
Correct answer: Actual knowledge that a particular user is under 13 years of age
COPPA applies to general audience sites and apps when the operator has actual knowledge that a user is under 13, even if the platform is not directed at children.
Question 6: Which principle requires that personal data collected online be limited to what is directly relevant and necessary for the specific stated purpose?
- Purpose specification
- Data minimization (Correct answer)
- Consent management
- Access control
Correct answer: Data minimization
Data minimization is the principle that organizations should collect only the minimum amount of personal data necessary to fulfill the stated purpose.
Under most U.S. state data breach notification laws, notification obligations are triggered when: