CES Legal, Compliance & Privacy in Ecommerce 1 — Questions and Answers
Question 1: What does GDPR require of ecommerce businesses that sell to customers in the European Union?
- Explicit consent before collecting personal data and the right for users to request data deletion (Correct answer)
- Mandatory registration with EU government bodies before operating online
- Storing all EU customer data on servers physically located in the EU only
- Publishing product prices in euros regardless of the merchant's home currency
Correct answer: Explicit consent before collecting personal data and the right for users to request data deletion
GDPR (General Data Protection Regulation) requires businesses to obtain clear consent for data collection and grants EU residents rights including data access, correction, and erasure.
Question 2: What is the California Consumer Privacy Act (CCPA) most relevant to for ecommerce businesses?
- Giving California residents the right to know what personal data is collected and to opt out of its sale (Correct answer)
- Requiring California businesses to collect sales tax on all online transactions
- Mandating cybersecurity audits for businesses selling to California residents
- Limiting the types of products that can be sold online to California residents
Correct answer: Giving California residents the right to know what personal data is collected and to opt out of its sale
CCPA grants California residents the right to know what personal data businesses collect, the right to delete it, and the right to opt out of having their data sold to third parties.
Question 3: What is a Terms of Service (ToS) agreement on an ecommerce website primarily designed to do?
- Define the legal rules and guidelines that users must agree to in order to use the website and services (Correct answer)
- Guarantee refunds and returns to all customers unconditionally
- Comply with FTC advertising disclosure requirements
- Establish the merchant's shipping rates and delivery timeframes
Correct answer: Define the legal rules and guidelines that users must agree to in order to use the website and services
A ToS agreement outlines the legal relationship between the merchant and the user, covering acceptable use, dispute resolution, limitations of liability, and intellectual property.
Question 4: Under US law, what does the CAN-SPAM Act regulate for ecommerce businesses?
- Commercial email marketing practices including opt-out requirements and prohibitions on deceptive subject lines (Correct answer)
- Spam product listings and counterfeit goods on ecommerce platforms
- Unsolicited text message marketing campaigns
- Automated phone calls to customers for marketing purposes
Correct answer: Commercial email marketing practices including opt-out requirements and prohibitions on deceptive subject lines
The CAN-SPAM Act sets rules for commercial email, requiring honest subject lines, a physical address, and a clear unsubscribe mechanism that must be honored within 10 business days.
Question 5: What is the purpose of a privacy policy on an ecommerce website?
- To inform customers what personal data is collected, how it is used, and how it is protected (Correct answer)
- To outline the merchant's policy on pricing and promotional offers
- To disclose affiliate marketing relationships to customers
- To describe the security certifications the payment processor holds
Correct answer: To inform customers what personal data is collected, how it is used, and how it is protected
A privacy policy is a legal document disclosing how a business collects, uses, stores, and shares customer personal data, and is legally required in most jurisdictions.
Question 6: What is the FTC's role in regulating ecommerce businesses in the United States?
- Enforcing consumer protection laws including preventing deceptive advertising and unfair business practices (Correct answer)
- Setting import duties and tariffs for international ecommerce shipments
- Regulating the technical security standards for payment card processing
- Issuing ecommerce operating licenses to online retailers
Correct answer: Enforcing consumer protection laws including preventing deceptive advertising and unfair business practices
The FTC (Federal Trade Commission) enforces laws against deceptive advertising, fake reviews, undisclosed affiliate relationships, and other unfair ecommerce practices.
What does GDPR require of ecommerce businesses that sell to customers in the European Union?