GMC Regulatory Compliance 2 — Questions and Answers
Question 1: Under the CCPA, what is the maximum civil penalty a business can face per intentional violation?
- $2,500
- $7,500 (Correct answer)
- $15,000
- $25,000
Correct answer: $7,500
The CCPA allows the California Attorney General to impose civil penalties of up to $7,500 per intentional violation.
Question 2: A marketer wants to send promotional SMS messages to customers in the US. Which law primarily governs this activity?
- CAN-SPAM Act
- COPPA
- TCPA (Correct answer)
- FCRA
Correct answer: TCPA
The Telephone Consumer Protection Act (TCPA) regulates commercial text messages and requires prior express written consent for marketing SMS.
Question 3: Which of the following best describes a 'legitimate interest' as a legal basis under GDPR?
- Any business reason a company deems important
- Processing necessary for the controller's genuine interests that are not overridden by data subject rights (Correct answer)
- A signed consent form from the data subject
- An official government authorization to process data
Correct answer: Processing necessary for the controller's genuine interests that are not overridden by data subject rights
Under GDPR Article 6(1)(f), legitimate interest requires a balancing test to ensure the controller's interests are not overridden by the data subject's fundamental rights.
Question 4: A growth marketer runs retargeting ads using pixel data. Under GDPR, pixel tracking on a website typically requires:
- Only a privacy policy disclosure
- Prior informed consent from EU visitors before the pixel fires (Correct answer)
- A data processing agreement with only the ad network
- Nothing, as pixels are not personal data
Correct answer: Prior informed consent from EU visitors before the pixel fires
Cookies and tracking pixels that process personal data of EU residents require prior informed consent under GDPR and the ePrivacy Directive.
Question 5: What does the term 'data minimization' require under GDPR?
- Deleting all data after 30 days
- Collecting only data that is adequate, relevant, and limited to what is necessary for the purpose (Correct answer)
- Encrypting all stored personal data
- Storing data only within EU borders
Correct answer: Collecting only data that is adequate, relevant, and limited to what is necessary for the purpose
GDPR Article 5(1)(c) mandates that personal data must be adequate, relevant, and limited to what is necessary in relation to the stated processing purpose.
Question 6: Which FTC Act section is most commonly cited in enforcement actions against deceptive marketing practices?
- Section 5 (Correct answer)
- Section 12
- Section 18
- Section 43
Correct answer: Section 5
FTC Act Section 5 prohibits unfair or deceptive acts or practices in or affecting commerce and is the primary basis for FTC marketing enforcement.
Question 7: Under CAN-SPAM, how quickly must a sender honor an opt-out request from a commercial email recipient?
- Immediately upon receipt
- Within 3 business days
- Within 10 business days (Correct answer)
- Within 30 days
Correct answer: Within 10 business days
CAN-SPAM requires that opt-out requests be honored within 10 business days of receipt, and senders cannot charge a fee or require extra steps to unsubscribe.
Under the CCPA, what is the maximum civil penalty a business can face per intentional violation?