User Experience Design Regulatory Frameworks & Compliance 2 — Questions and Answers
Question 1: Under the Americans with Disabilities Act (ADA), which digital accessibility standard have courts most frequently used as the benchmark for website compliance?
- Section 508 of the Rehabilitation Act
- WCAG 2.1 Level AA (Correct answer)
- ISO 9241-171
- EN 301 549
Correct answer: WCAG 2.1 Level AA
US courts have consistently referenced WCAG 2.1 Level AA as the de facto standard for ADA website compliance in landmark rulings.
Question 2: The EU's European Accessibility Act (EAA), which applies from June 2025, requires compliance for which category of products and services?
- Only government websites
- Consumer-facing digital products and services sold in the EU (Correct answer)
- Enterprise software only
- Mobile apps with over 1 million downloads
Correct answer: Consumer-facing digital products and services sold in the EU
The EAA covers a broad range of consumer-facing products and services, including e-commerce, banking, e-books, and transport, sold within the EU.
Question 3: Which principle of GDPR directly impacts UX design by requiring that users understand what data is collected and why before consenting?
- Data minimization
- Storage limitation
- Transparency and informed consent (Correct answer)
- Integrity and confidentiality
Correct answer: Transparency and informed consent
GDPR's transparency principle mandates that privacy information be communicated in a clear, plain language manner so users can give truly informed consent.
Question 4: A UX designer is building a children's educational app for US users. Which law primarily governs how they must handle data collection from children under 13?
- FERPA
- HIPAA
- COPPA (Correct answer)
- CCPA
Correct answer: COPPA
The Children's Online Privacy Protection Act (COPPA) requires verifiable parental consent before collecting personal information from children under 13 in the US.
Question 5: In the context of PCI DSS compliance, what is the primary UX concern for e-commerce checkout flows?
- Ensuring one-click purchasing is available
- Securing cardholder data entry with no client-side storage (Correct answer)
- Using only third-party payment forms
- Displaying security badges on every page
Correct answer: Securing cardholder data entry with no client-side storage
PCI DSS requires that cardholder data (card numbers, CVVs) never be stored on client-side systems, directly affecting how checkout UX handles form data.
Question 6: Which Section 508 provision specifically addresses the accessibility of software and web-based intranet and internet information?
- §1194.21 — Software applications and operating systems
- §1194.22 — Web-based intranet and internet information and applications (Correct answer)
- §1194.23 — Telecommunications products
- §1194.31 — Functional performance criteria
Correct answer: §1194.22 — Web-based intranet and internet information and applications
Section 1194.22 of Section 508 establishes 16 specific requirements for web-based information and applications used by federal agencies.
Question 7: What does 'privacy by design' require UX designers to do during the product development lifecycle?
- Add a privacy policy link in the footer
- Integrate privacy protections into the design from the outset rather than as an afterthought (Correct answer)
- Conduct a privacy audit after launch
- Store all user data on encrypted servers
Correct answer: Integrate privacy protections into the design from the outset rather than as an afterthought
Privacy by design, codified in GDPR Article 25, requires that data protection measures be embedded into products proactively during the design phase.
Under the Americans with Disabilities Act (ADA), which digital accessibility standard have courts most frequently used as the benchmark for website compliance?