CSC CSC - Cybersecurity Compliance Data Privacy and Breach Notification Laws Questions and Answers 1 — Questions and Answers
Question 1: Which U.S. federal law requires financial institutions to protect consumers' personal financial information and notify customers of privacy policies?
- Gramm-Leach-Bliley Act (GLBA) (Correct answer)
- FERPA
- COPPA
- ECPA
Correct answer: Gramm-Leach-Bliley Act (GLBA)
The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to explain data sharing practices and protect consumers' nonpublic personal information.
Question 2: Under the California Consumer Privacy Act (CCPA), what right allows consumers to request that a business delete their personal information?
- Right to deletion (Correct answer)
- Right to opt-out
- Right to portability
- Right to access
Correct answer: Right to deletion
The CCPA's right to deletion (also called the right to erasure) allows California consumers to request that businesses delete personal information collected about them.
Question 3: Which federal law protects the privacy of students' educational records and applies to schools receiving federal funding?
- FERPA (Correct answer)
- COPPA
- GLBA
- HIPAA
Correct answer: FERPA
The Family Educational Rights and Privacy Act (FERPA) gives parents and eligible students control over educational records and restricts their disclosure.
Question 4: Which U.S. law restricts the online collection of personal information from children under 13 years old?
- COPPA (Correct answer)
- FERPA
- ECPA
- GLBA
Correct answer: COPPA
The Children's Online Privacy Protection Act (COPPA) requires verifiable parental consent before collecting personal data from children under 13.
Question 5: What is the primary federal agency responsible for enforcing data privacy and consumer protection laws in the United States?
- Federal Trade Commission (FTC) (Correct answer)
- Department of Homeland Security
- NIST
- Office of Civil Rights (OCR)
Correct answer: Federal Trade Commission (FTC)
The FTC enforces federal consumer protection laws, including actions against unfair or deceptive data privacy practices under Section 5 of the FTC Act.
Question 6: Which U.S. state first enacted a comprehensive consumer data privacy law modeled partly on GDPR principles, effective January 1, 2020?
- California (CCPA) (Correct answer)
- New York (SHIELD Act)
- Virginia (CDPA)
- Illinois (BIPA)
Correct answer: California (CCPA)
California's Consumer Privacy Act (CCPA) took effect January 1, 2020, and was the first broad U.S. state privacy law granting consumers rights over their personal data.
Which U.S. federal law requires financial institutions to protect consumers' personal financial information and notify customers of privacy policies?