Web Traffic Regulatory Frameworks & Compliance 2 — Questions and Answers
Question 1: Under GDPR, what is the maximum fine for the most serious violations?
- €10 million or 2% of global annual turnover
- €20 million or 4% of global annual turnover (Correct answer)
- €50 million or 10% of global annual turnover
- €5 million or 1% of global annual turnover
Correct answer: €20 million or 4% of global annual turnover
GDPR's highest tier of fines is €20 million or 4% of global annual turnover, whichever is higher.
Question 2: Which US law specifically governs the collection of personal data from children under 13 online?
- FERPA
- HIPAA
- COPPA (Correct answer)
- CCPA
Correct answer: COPPA
COPPA (Children's Online Privacy Protection Act) requires parental consent before collecting data from children under 13.
Question 3: A website using Google Analytics must disclose this in its privacy policy primarily because Analytics collects:
- Server-side logs
- User-submitted form data
- Personal data via cookies and tracking pixels (Correct answer)
- Payment card information
Correct answer: Personal data via cookies and tracking pixels
Google Analytics collects personal data through cookies and tracking technologies, triggering privacy disclosure requirements under GDPR and similar laws.
Question 4: What does 'data minimization' mean under GDPR?
- Compressing data files to save storage
- Only collecting data that is adequate, relevant, and limited to what is necessary (Correct answer)
- Deleting all data after 30 days
- Encrypting data to minimize breach risk
Correct answer: Only collecting data that is adequate, relevant, and limited to what is necessary
Data minimization is a GDPR principle requiring organizations to collect only the data strictly necessary for the specified purpose.
Question 5: Under the California Consumer Privacy Act (CCPA), which of the following rights do California residents have?
- Right to delete personal information held by a business (Correct answer)
- Right to receive monetary compensation for all data collected
- Right to prevent websites from using SSL certificates
- Right to opt into data collection before visiting a site
Correct answer: Right to delete personal information held by a business
CCPA grants California residents the right to request deletion of their personal information, among other rights.
Question 6: A web analytics tool is considered 'privacy-friendly' primarily when it:
- Uses only server-side tracking with no client-side code
- Anonymizes IP addresses and does not use persistent cross-site cookies (Correct answer)
- Requires users to log in before tracking begins
- Stores data exclusively on EU servers
Correct answer: Anonymizes IP addresses and does not use persistent cross-site cookies
Privacy-friendly analytics tools anonymize IPs and avoid persistent cross-site tracking cookies, reducing personal data collection.
Question 7: Which regulation introduced the concept of a 'Data Protection Officer' (DPO) as a mandatory role for certain organizations?
- CCPA
- HIPAA
- GDPR (Correct answer)
- SOX
Correct answer: GDPR
GDPR introduced the mandatory DPO role for public authorities and organizations that engage in large-scale systematic monitoring of individuals.
Under GDPR, what is the maximum fine for the most serious violations?