Web Analytics Data Privacy and Compliance in Analytics 1 β Questions and Answers
Question 1: What does GDPR stand for, and which region does it primarily govern?
- General Data Rights Protocol β United States
- General Data Protection Regulation β European Union (Correct answer)
- Global Data Privacy Regulation β worldwide
- Government Data Processing Rules β United Kingdom
Correct answer: General Data Protection Regulation β European Union
GDPR stands for General Data Protection Regulation and is the EU's primary data protection law governing how organizations collect and process personal data.
Question 2: What does the California Consumer Privacy Act (CCPA) grant to California residents?
- The right to block all website cookies automatically
- The right to know, delete, and opt out of the sale of their personal data (Correct answer)
- The right to receive compensation for data collection
- The right to annual privacy audits
Correct answer: The right to know, delete, and opt out of the sale of their personal data
CCPA gives California residents rights to know what personal data is collected, request deletion, and opt out of the sale of their data to third parties.
Question 3: In analytics compliance, what is 'data minimization'?
- Compressing analytics data files to reduce storage
- Collecting only the personal data that is strictly necessary for the specified purpose (Correct answer)
- Anonymizing all analytics data before storage
- Limiting data collection to mobile users only
Correct answer: Collecting only the personal data that is strictly necessary for the specified purpose
Data minimization is a GDPR principle requiring that organizations collect only the personal data that is adequate, relevant, and limited to what is necessary.
Question 4: What is 'cookie consent' in the context of web analytics compliance?
- A browser setting that accepts all cookies automatically
- Obtaining explicit user permission before placing non-essential tracking cookies (Correct answer)
- A server-side agreement between analytics vendors
- A cookie that stores GDPR consent preferences
Correct answer: Obtaining explicit user permission before placing non-essential tracking cookies
Cookie consent laws (ePrivacy Directive, GDPR) require sites to obtain freely given, informed, and explicit user consent before setting non-essential cookies like analytics trackers.
Question 5: What is 'IP anonymization' in Google Analytics, and why is it used?
- Blocking certain IPs from appearing in reports
- Truncating the last octet of a user's IP address to reduce personally identifiable information (Correct answer)
- Encrypting all IP data in transit
- Replacing IP addresses with random identifiers
Correct answer: Truncating the last octet of a user's IP address to reduce personally identifiable information
IP anonymization (anonymize_ip) removes the last octet of a visitor's IP address before it is stored, reducing the risk of tracking identifiable individuals.
Question 6: Under GDPR, what is a 'Data Processing Agreement' (DPA)?
- A user-facing privacy policy on a website
- A contract between a data controller and a data processor outlining how personal data may be processed (Correct answer)
- A technical specification for data encryption
- An agreement between EU member states on data sharing
Correct answer: A contract between a data controller and a data processor outlining how personal data may be processed
A DPA is a legally required contract between a business (controller) and a vendor (processor) that specifies the purpose, scope, and conditions for processing personal data.
What does GDPR stand for, and which region does it primarily govern?