โ† All CDPSE Flashcard Decks

Consent Management Flashcards

7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Consent Management flashcards as text
  1. What is 'implied consent' and why is it generally insufficient under modern privacy regulations?

    Answer: Implied consent is inferred from user behavior without explicit agreement; regulations such as GDPR require unambiguous action

    Implied consent assumes agreement from passive behavior (e.g., continued browsing), which fails the unambiguous affirmative action standard required by GDPR and similar laws.

  2. Under COPPA (Children's Online Privacy Protection Act), what is required before collecting personal data from children under 13 in the US?

    Answer: Verifiable parental consent obtained before collection begins

    COPPA mandates verifiable parental consent before any personal information is collected from children under 13, given their limited legal capacity to consent.

  3. Why is maintaining a consent record or audit trail critical for CDPSE professionals?

    Answer: It provides evidence of compliance and enables organizations to demonstrate that valid consent was obtained when challenged

    Consent records serve as proof of compliance; under GDPR Article 7(1), controllers bear the burden of demonstrating that valid consent was obtained.

  4. In the context of cookie consent, what does the ePrivacy Directive require before placing non-essential cookies?

    Answer: Prior informed consent from the user before placing non-essential cookies such as analytics or advertising cookies

    The ePrivacy Directive requires prior informed consent for non-essential cookies (analytics, advertising, tracking), while strictly necessary cookies are exempt.

  5. How does the principle of 'purpose limitation' interact with consent management?

    Answer: Purpose limitation means consent obtained for one specific purpose cannot be used to justify processing for a different purpose without new consent

    Purpose limitation (GDPR Article 5(1)(b)) requires that data collected under consent for purpose A cannot be repurposed for purpose B without obtaining fresh consent.

  6. Which of the following is a lawful basis for processing personal data that does NOT require obtaining consent under GDPR?

    Answer: Processing data that is strictly necessary to fulfill a contract with the data subject

    Contract performance is one of six lawful bases under GDPR Article 6; when processing is necessary to execute a contract, consent is not required as the legal basis.

  7. What is 'dynamic consent' and how does it benefit data subjects in long-term research studies?

    Answer: Dynamic consent allows participants to continuously review, update, or withdraw their consent for specific uses of their data over time via an online platform

    Dynamic consent frameworks give research participants ongoing control by providing an interface to manage and update their consent preferences as study purposes evolve.