Web Traffic Regulatory Frameworks & Compliance 4 — Questions and Answers
Question 1: A news website embeds a Facebook 'Like' button on every article. Under GDPR, this is problematic because:
- Facebook's servers are slower than the publisher's
- The button loads Facebook scripts that may track users without their consent before they click (Correct answer)
- Like buttons violate copyright law in the EU
- Social sharing reduces organic search traffic
Correct answer: The button loads Facebook scripts that may track users without their consent before they click
Embedded third-party social buttons load external scripts that can place tracking cookies on visitors even if they never click the button.
Question 2: Under GDPR's 'right to be forgotten,' when can a website legitimately refuse a deletion request?
- When the data is stored in a backup system
- When the data is necessary for compliance with a legal obligation (Correct answer)
- When the user originally provided the data voluntarily
- When the website has fewer than 250 employees
Correct answer: When the data is necessary for compliance with a legal obligation
GDPR allows refusal of deletion requests when retaining data is necessary to comply with a legal obligation, such as tax record retention laws.
Question 3: What is 'referrer spam' and which compliance issue does it create for analytics?
- Legitimate referral traffic that inflates conversion metrics
- Fake traffic that appears as real referrers, polluting analytics data and potentially triggering GDPR issues if bot IPs are logged (Correct answer)
- Traffic from affiliate partners that violates FTC disclosure rules
- Direct traffic misclassified as referral in GA4
Correct answer: Fake traffic that appears as real referrers, polluting analytics data and potentially triggering GDPR issues if bot IPs are logged
Referrer spam sends fake hits to analytics systems, polluting data and potentially causing compliant data retention of non-user bot records.
Question 4: The FTC's endorsement guidelines require influencers driving traffic to a brand's website to:
- Use only organic traffic methods, never paid promotion
- Clearly disclose any material connection to the brand being promoted (Correct answer)
- Register as a licensed advertising agency
- Limit promotional posts to once per month per brand
Correct answer: Clearly disclose any material connection to the brand being promoted
FTC guidelines require influencers to clearly and conspicuously disclose paid partnerships or other material connections that could affect consumer trust.
Question 5: A company wants to retarget website visitors using a pixel. Under GDPR, which step must occur BEFORE the pixel fires for EU visitors?
- The user must be a registered account holder
- Informed consent must be obtained, typically via a cookie consent banner (Correct answer)
- The user must have visited at least three pages on the site
- The pixel must be reviewed by a certified data auditor
Correct answer: Informed consent must be obtained, typically via a cookie consent banner
Retargeting pixels place tracking cookies requiring prior informed consent from EU users before they can be activated.
Question 6: Which US law requires websites in the healthcare sector to safeguard web analytics data that could reveal patient health information?
- FERPA
- COPPA
- HIPAA (Correct answer)
- GLBA
Correct answer: HIPAA
HIPAA requires covered entities to protect Protected Health Information (PHI), which can include analytics data revealing health-related site visits.
Question 7: What is the purpose of a 'privacy by design' approach in web development?
- To make privacy policy pages visually appealing and user-friendly
- To embed privacy protections into systems from the start rather than adding them as an afterthought (Correct answer)
- To encrypt all website traffic using HTTPS
- To limit website functionality to reduce data exposure
Correct answer: To embed privacy protections into systems from the start rather than adding them as an afterthought
Privacy by design means proactively integrating data protection principles into the architecture and development of systems from inception.
A news website embeds a Facebook 'Like' button on every article.
Under GDPR, this is problematic because: