MAC Regulatory Compliance 2 — Questions and Answers
Question 1: Under the California Consumer Privacy Act (CCPA), what right allows consumers to stop businesses from selling their personal information to third parties?
- Right to erasure
- Right to opt-out (Correct answer)
- Right to portability
- Right to rectification
Correct answer: Right to opt-out
CCPA's right to opt-out lets California residents direct businesses to stop selling their personal information to third parties.
Question 2: Which FTC Act section forms the primary legal basis for the FTC's authority to regulate unfair or deceptive marketing analytics practices?
- Section 5 (Correct answer)
- Section 12
- Section 18
- Section 21
Correct answer: Section 5
Section 5 of the FTC Act prohibits unfair or deceptive acts or practices in commerce, giving the FTC broad authority over marketing practices.
Question 3: A marketing analyst discovers that email campaign data includes records of minors under 13. Which federal law primarily governs how this data must be handled?
- FERPA
- HIPAA
- COPPA (Correct answer)
- GLBA
Correct answer: COPPA
COPPA (Children's Online Privacy Protection Act) requires verifiable parental consent before collecting personal data from children under 13.
Question 4: What does the term 'pseudonymization' mean in the context of data privacy compliance for marketing analytics?
- Permanently deleting all personal identifiers from a dataset
- Replacing identifying fields with artificial identifiers so data cannot be attributed without additional information (Correct answer)
- Encrypting data so only authorized users can view it
- Aggregating individual records into summary statistics
Correct answer: Replacing identifying fields with artificial identifiers so data cannot be attributed without additional information
Pseudonymization replaces direct identifiers with artificial ones, reducing privacy risk while still allowing data to be re-linked if needed.
Question 5: Which element is NOT typically required in a lawful basis assessment under GDPR for processing marketing analytics data?
- Identifying a valid legal basis such as consent or legitimate interest
- Documenting the assessment in records of processing activities
- Obtaining approval from a national data protection authority for every campaign (Correct answer)
- Balancing organizational interests against individual rights when using legitimate interest
Correct answer: Obtaining approval from a national data protection authority for every campaign
GDPR does not require prior approval from a data protection authority for every campaign; most processing only requires internal documentation of the lawful basis.
Question 6: A company collects browsing data through first-party cookies to personalize ads. Under GDPR, which lawful basis is most commonly relied upon for this processing?
- Legal obligation
- Vital interests
- Consent (Correct answer)
- Public task
Correct answer: Consent
Behavioral advertising based on first-party cookies typically relies on explicit user consent as the lawful basis under GDPR.
Question 7: What is a 'data minimization' principle as applied to marketing analytics?
- Collecting as much data as possible to improve model accuracy
- Encrypting all datasets to minimize exposure risk
- Collecting only the data that is adequate, relevant, and limited to what is necessary for the specified purpose (Correct answer)
- Retaining data for the minimum legally required period before deletion
Correct answer: Collecting only the data that is adequate, relevant, and limited to what is necessary for the specified purpose
Data minimization requires collecting only what is strictly necessary for the defined purpose, reducing privacy risks and compliance exposure.
Under the California Consumer Privacy Act (CCPA), what right allows consumers to stop businesses from selling their personal information to third parties?