Enforcement Mechanisms & Penalties Flashcards
5 cards from real PLC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 5 Enforcement Mechanisms & Penalties flashcards as text
Under the GDPR, what is the maximum administrative fine for severe violations?
Answer: €20 million or 4% of annual global turnover
The GDPR imposes a two-tiered system for administrative fines. For the most severe violations, such as infringements of data subjects' rights or principles for processing, the maximum fine can be up to €20 million or 4% of the company's total worldwide annual turnover from the preceding financial year, whichever is higher. This significant penalty underscores the importance of strict adherence to GDPR requirements.
Which U.S. agency is primarily responsible for enforcing consumer privacy laws?
Answer: Federal Trade Commission (FTC)
In the United States, the Federal Trade Commission (FTC) is the primary agency responsible for enforcing consumer privacy laws. The FTC uses its authority under Section 5 of the FTC Act, which prohibits unfair and deceptive practices, to take action against companies that fail to protect consumer data or misrepresent their privacy practices. It also enforces specific privacy laws like COPPA (Children's Online Privacy Protection Act).
What is a common consequence for companies that fail to comply with data protection regulations?
Answer: Financial penalties and legal actions
Companies that fail to comply with data protection regulations face severe consequences, including significant financial penalties imposed by regulatory authorities. Beyond fines, non-compliance can lead to legal actions from affected individuals, class-action lawsuits, and mandatory audits. These outcomes can severely impact a company's financial stability, reputation, and operational continuity.
Which of the following is a potential penalty under the CCPA for intentional violations?
Answer: $7,500 per violation
The California Consumer Privacy Act (CCPA) and its successor, the California Privacy Rights Act (CPRA), specify penalties for violations. For intentional violations, the California Attorney General can impose civil penalties of up to $7,500 per violation. For unintentional violations, the penalty is $2,500 per violation, provided the business fails to cure the violation within 30 days after being notified.
What enforcement action can the FTC take against companies violating privacy agreements?
Answer: Issue consent decrees
When the FTC finds that a company has violated privacy agreements or engaged in deceptive privacy practices, it often resolves the matter by issuing a consent decree. A consent decree is a legally binding agreement that outlines specific actions the company must take to remedy the violation and prevent future occurrences, often including regular privacy audits and reporting requirements. Failure to comply with a consent decree can result in additional, significant penalties.