MAC Regulatory Compliance 3 — Questions and Answers
Question 1: Under CAN-SPAM Act, within how many business days must a sender honor an opt-out request from an email recipient?
- 3 business days
- 5 business days
- 10 business days (Correct answer)
- 30 calendar days
Correct answer: 10 business days
CAN-SPAM requires senders to process opt-out requests within 10 business days of receipt and stop sending to that address.
Question 2: Which of the following scenarios would most likely constitute a GDPR data breach requiring notification to the supervisory authority?
- A marketing analyst accidentally sends a report to the wrong internal team member
- An encrypted laptop containing customer email addresses is stolen (Correct answer)
- An employee views customer records as part of normal campaign analysis
- A third-party vendor updates its privacy policy
Correct answer: An encrypted laptop containing customer email addresses is stolen
Loss of a device containing personal data—even encrypted—may qualify as a breach requiring assessment and potential supervisory authority notification within 72 hours.
Question 3: What is the primary purpose of a Data Processing Agreement (DPA) between a marketing platform and its analytics vendor?
- To establish revenue-sharing terms between the two parties
- To define how the vendor processes personal data on behalf of the controller, ensuring GDPR compliance (Correct answer)
- To grant the vendor ownership rights over collected data
- To set out the technical specifications of API integrations
Correct answer: To define how the vendor processes personal data on behalf of the controller, ensuring GDPR compliance
A DPA legally binds the processor to handle personal data only as instructed by the controller, a requirement under GDPR Article 28.
Question 4: A marketer uses lookalike audience modeling by sharing hashed email lists with a social media platform. Which compliance consideration is most critical?
- Ensuring the hash algorithm used is SHA-256 or stronger
- Verifying that users consented to their data being shared with third-party platforms for advertising (Correct answer)
- Confirming the social media platform is located in the same country
- Checking that the audience size exceeds 1,000 to avoid re-identification
Correct answer: Verifying that users consented to their data being shared with third-party platforms for advertising
Sharing hashed emails with third parties for ad targeting requires a valid legal basis—typically consent—especially under GDPR and CCPA.
Question 5: Which US state law introduced the concept of 'sensitive personal information' with additional restrictions, including data about precise geolocation?
- California Privacy Rights Act (CPRA) (Correct answer)
- Virginia Consumer Data Protection Act (VCDPA)
- Colorado Privacy Act (CPA)
- Utah Consumer Privacy Act (UCPA)
Correct answer: California Privacy Rights Act (CPRA)
CPRA, which amended CCPA, created a new category of 'sensitive personal information' with heightened protections including precise geolocation data.
Question 6: In marketing analytics, what is a 'legitimate interest' assessment (LIA) used for?
- Documenting that a business has achieved revenue targets to justify data spend
- Evaluating whether an organization's interest in processing personal data overrides the individual's privacy rights (Correct answer)
- Assessing the financial legitimacy of a marketing vendor before signing a contract
- Determining whether a dataset is large enough to yield statistically significant results
Correct answer: Evaluating whether an organization's interest in processing personal data overrides the individual's privacy rights
An LIA is a three-part test under GDPR that weighs the business purpose, necessity of processing, and impact on individual rights before relying on legitimate interest.
Question 7: Which regulation requires companies to disclose the categories of personal information collected and the purposes for which it is used, specifically in the context of US marketing analytics?
- Gramm-Leach-Bliley Act (GLBA)
- California Consumer Privacy Act (CCPA) (Correct answer)
- Health Insurance Portability and Accountability Act (HIPAA)
- Electronic Communications Privacy Act (ECPA)
Correct answer: California Consumer Privacy Act (CCPA)
CCPA requires businesses to disclose at or before data collection what categories of personal information are collected and the business purposes for collection.
Under CAN-SPAM Act, within how many business days must a sender honor an opt-out request from an email recipient?