CCPA

CCPA Advanced

Complex CCPA/CPRA scenarios: enforcement risk, cross-border considerations, and interaction with other US privacy laws.

11 questions · 80% to pass · free

eurocompliant.com is not an accredited certification body. This is a self-paced educational assessment; the certificate confirms completion only, not a professional, statutory, or accredited qualification.

Your details

We'll email your certificate here if you pass. We may occasionally follow up about eurocompliant.com - you can unsubscribe any time.

Question 1 of 11

How does the CPPA's rulemaking and enforcement authority relate to the California Attorney General's role under the CCPA?

Question 2 of 11

A business inadvertently sells personal information to a data broker without proper contractual restrictions. What CCPA classification issue does this raise?

Question 3 of 11

Which of the following are examples of 'dark patterns' that CCPA/CPRA rulemaking has specifically sought to prohibit in opt-out/consent flows?

Select all that apply.

Question 4 of 11

A multistate business operates under both the CCPA and a comparable state law (e.g. Virginia's VCDPA). What is a key practical challenge this creates?

Question 5 of 11

Under CCPA regulations, what must a business do if it cannot verify a consumer's identity for a deletion request but the request appears to relate to information the business does hold?

Question 6 of 11

How does the CCPA's 'right to correct' (added by the CPRA) interact with a business's obligation regarding data accuracy?

Question 7 of 11

A business relies on 'aggregate consumer information' and 'de-identified' data to avoid certain CCPA obligations. What condition must generally be met for data to qualify as de-identified?

Question 8 of 11

What is the significance of the CCPA's private right of action being limited primarily to certain data breach scenarios, rather than covering all CCPA violations?

Question 9 of 11

Which of the following are relevant considerations for a business conducting a CPRA-mandated cybersecurity audit or risk assessment for processing that presents significant risk?

Select all that apply.

Question 10 of 11

Contractual flow-down obligations mean a business remains responsible for ensuring its service providers and contractors process personal information consistently with CCPA restrictions, even though the service provider is directly bound by contract.

Question 11 of 11

How should a business approach 'sharing' of personal information for cross-context behavioral advertising under the CPRA, distinct from a traditional 'sale'?

0 of 11 answered