WordPress Regulatory Frameworks & Compliance 2 — Questions and Answers
Question 1: Under the California Consumer Privacy Act (CCPA), what right allows California residents to request that a business delete their personal information?
- Right to Access
- Right to Deletion (Correct answer)
- Right to Portability
- Right to Rectification
Correct answer: Right to Deletion
The CCPA grants California residents the Right to Deletion, allowing them to request that businesses delete personal information collected about them.
Question 2: Which WordPress plugin feature helps site owners display a cookie consent banner to comply with ePrivacy Directive requirements?
- Cookie Notice (Correct answer)
- WP Rocket
- Yoast SEO
- Jetpack
Correct answer: Cookie Notice
Cookie Notice and similar plugins display consent banners that inform visitors about cookie usage as required by the ePrivacy Directive.
Question 3: What does PCI DSS stand for in the context of WordPress e-commerce compliance?
- Payment Card Industry Data Security Standard (Correct answer)
- Personal Credit Information Digital Security System
- Private Customer Identity Digital Standard
- Payment Compliance Information Data System
Correct answer: Payment Card Industry Data Security Standard
PCI DSS stands for Payment Card Industry Data Security Standard, which governs how payment card data must be handled on e-commerce sites.
Question 4: When implementing GDPR compliance on a WordPress membership site, what must happen before collecting a user's email address?
- Send a welcome email first
- Obtain explicit informed consent (Correct answer)
- Verify the email address format
- Store the email in plain text
Correct answer: Obtain explicit informed consent
GDPR requires explicit informed consent before collecting personal data such as email addresses.
Question 5: Which HTTP header helps WordPress sites comply with security best practices by preventing clickjacking attacks?
- Content-Security-Policy
- X-Frame-Options (Correct answer)
- Strict-Transport-Security
- X-Content-Type-Options
Correct answer: X-Frame-Options
The X-Frame-Options header prevents a site from being embedded in iframes, protecting against clickjacking attacks.
Question 6: A WordPress site serving users in the EU must comply with GDPR. Which of the following is NOT a valid legal basis for processing personal data?
- User consent
- Legitimate interests
- Contractual necessity
- Business convenience (Correct answer)
Correct answer: Business convenience
Business convenience is not a recognized legal basis under GDPR; valid bases include consent, legitimate interests, and contractual necessity.
Question 7: What is the maximum fine for the most serious GDPR violations that can be imposed on a business?
- €10 million or 2% of global annual turnover
- €20 million or 4% of global annual turnover (Correct answer)
- €50 million or 10% of global annual turnover
- €5 million or 1% of global annual turnover
Correct answer: €20 million or 4% of global annual turnover
The most serious GDPR violations carry fines of up to €20 million or 4% of global annual turnover, whichever is higher.
Under the California Consumer Privacy Act (CCPA), what right allows California residents to request that a business delete their personal information?