Free CIPP/US Privacy Laws & Regulations Questions and Answers — Questions and Answers
Question 1: Which U.S. law governs the privacy of children's personal information online?
- HIPAA
- FERPA
- COPPA (Correct answer)
- GLBA
Correct answer: COPPA
The Children's Online Privacy Protection Act (COPPA) is a landmark U.S. federal law specifically designed to protect the privacy of children under 13 online. It mandates that websites and online services obtain verifiable parental consent before collecting, using, or disclosing personal information from children. COPPA sets strict requirements for operators regarding data collection practices, parental notification, and data security for children's data.
Question 2: What is the primary purpose of the Gramm-Leach-Bliley Act (GLBA)?
- To regulate telecommunication services
- To enforce intellectual property rights
- To ensure data security and transparency in financial institutions (Correct answer)
- To protect public health information
Correct answer: To ensure data security and transparency in financial institutions
The primary purpose of the Gramm-Leach-Bliley Act (GLBA) is to protect the privacy of consumers' personal financial information held by financial institutions. It requires these institutions to explain their information-sharing practices to customers and to safeguard sensitive data. GLBA mandates specific security measures and transparency rules to ensure that financial data is handled responsibly and securely, preventing unauthorized access or disclosure.
Question 3: Which law grants consumers the right to access and delete their personal information in California?
- HIPAA
- CCPA (Correct answer)
- COPPA
- FCRA
Correct answer: CCPA
The California Consumer Privacy Act (CCPA) is a groundbreaking state law that grants California consumers significant rights over their personal information. Among these rights are the ability to know what personal data is being collected about them, to request its deletion, and to opt-out of its sale. The CCPA aims to enhance privacy protections and transparency for consumers regarding how businesses handle their data.
Question 4: What does the acronym HIPAA stand for?
- Health Information Privacy and Access Act
- Healthcare Integrity Protection and Accountability Act
- Health Insurance Portability and Accountability Act (Correct answer)
- Health Industry Professional Accreditation Act
Correct answer: Health Insurance Portability and Accountability Act
HIPAA stands for the Health Insurance Portability and Accountability Act, a federal law enacted in 1996. Its primary purpose is to protect sensitive patient health information from being disclosed without the patient's consent or knowledge. HIPAA establishes national standards for the security of electronic protected health information (ePHI) and sets rules for how healthcare providers, health plans, and other entities handle and transmit patient data.
Question 5: Which organization enforces data privacy laws in the United States?
- IRS
- FTC (Correct answer)
- FDA
- FBI
Correct answer: FTC
The Federal Trade Commission (FTC) is the primary federal agency responsible for enforcing data privacy laws in the United States, particularly those related to consumer protection. The FTC investigates companies for unfair or deceptive practices concerning data collection, use, and security, and it enforces laws like COPPA and sections of the FTC Act that prohibit unfair privacy practices. It plays a crucial role in safeguarding consumer data across various industries.
Question 6: What type of data is protected under the FCRA?
- Medical records
- Student records
- Credit report information (Correct answer)
- Employment history
Correct answer: Credit report information
The Fair Credit Reporting Act (FCRA) is a federal law that primarily protects the privacy and accuracy of information in consumer credit reports. It regulates how consumer reporting agencies collect, disseminate, and use consumer information, granting individuals rights such as accessing their credit files, disputing inaccuracies, and knowing when their credit report has been used. The FCRA aims to ensure fairness and accuracy in credit reporting practices.
Question 7: FERPA primarily protects which type of information?
- Credit card transactions
- Education records (Correct answer)
- Medical records
- Government documents
Correct answer: Education records
The Family Educational Rights and Privacy Act (FERPA) is a federal law that protects the privacy of student education records. It grants parents certain rights with respect to their children's education records, and these rights transfer to the student when he or she reaches 18 years of age or attends a school beyond the high school level. FERPA generally requires schools to obtain written permission from the parent or eligible student before releasing any information from a student's education record.
Question 8: What does a privacy notice typically include?
- Only the organization's mission
- A list of all employees
- Procedures for financial auditing
- Details about data collection and user rights (Correct answer)
Correct answer: Details about data collection and user rights
A privacy notice is a public statement explaining an organization's data handling practices. It typically informs individuals about what personal data is collected, the purposes for collection, how it will be used and shared, and the rights individuals have regarding their data, such as access or deletion. This transparency is fundamental for building trust and complying with privacy regulations.
Question 9: Which concept requires minimizing the collection of personal data?
- Data portability
- Data localization
- Data minimization (Correct answer)
- Data storage
Correct answer: Data minimization
Data minimization is a core privacy principle that dictates organizations should only collect, process, and store the minimum amount of personal data necessary to achieve a specified purpose. This practice reduces the risk of data breaches and misuse, enhances privacy by design, and helps organizations comply with regulations like GDPR and CCPA.
Which U.S. law governs the privacy of children's personal information online?