Legal & Regulatory Compliance Flashcards
7 cards from real CEC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Legal & Regulatory Compliance flashcards as text
An ecommerce retailer operating as a marketplace platform facilitates a sale of counterfeit goods by a third-party seller. Under the DMCA safe harbor provisions, the platform may avoid liability if it:
Answer: Was unaware of the counterfeit listing and removed it promptly upon notification
DMCA safe harbor protects platforms from copyright (and by extension some IP) liability if they had no knowledge of infringement and acted expeditiously to remove infringing content upon notification.
A US ecommerce company collects health-related data through its wellness product store. When does HIPAA apply to this data?
Answer: Only when the company is a covered entity or business associate as defined by HIPAA
HIPAA applies only to covered entities (healthcare providers, insurers, clearinghouses) and their business associates, not to general ecommerce retailers collecting wellness data.
Under US export control law (EAR/ITAR), an ecommerce retailer selling dual-use goods must:
Answer: Screen customers against denied parties lists and comply with export licensing requirements for controlled items
EAR requires exporters to screen against denied/restricted party lists and obtain licenses when exporting controlled dual-use items, regardless of the destination country.
Which principle in contract law determines when an ecommerce purchase contract is formed in a 'browse-wrap' agreement?
Answer: When the customer completes checkout and receives an order confirmation
In most jurisdictions, a contract is formed upon mutual assent, typically at checkout confirmation, though merchants should clearly define the offer and acceptance point in their terms.
A California consumer files a CCPA request to delete their personal data. The ecommerce business must respond within:
Answer: 45 days, with a possible 45-day extension
CCPA requires businesses to respond to verified consumer deletion requests within 45 days, with one 45-day extension allowed if necessary, for a maximum of 90 days total.
Under the Telephone Consumer Protection Act (TCPA), sending SMS marketing messages to consumers requires:
Answer: Prior express written consent from the recipient
TCPA requires prior express written consent for autodialed or prerecorded marketing text messages, and merely providing a phone number at checkout does not constitute consent for marketing SMS.
An ecommerce business discovers a GDPR-covered personal data breach. Under GDPR Article 33, the supervisory authority must be notified within:
Answer: 72 hours of becoming aware of the breach
GDPR Article 33 requires notification to the competent supervisory authority within 72 hours of becoming aware of a personal data breach, where feasible.