CIPP-US - Limits on Private-Sector Collection and Use of Data (31% of the exam) - Section 2.1

Apply the FTC's cross-sector authority to identify unfair or deceptive privacy practices and the role of COPPA in protecting children's online data.

Apply the FTC Act's prohibition on unfair or deceptive acts to privacy scenarios and recognise that the FTC treats broken privacy promises and inadequate data security as violations. Describe COPPA's requirements for verifiable parental consent, notice, and data deletion for operators of websites and online services directed at children under 13.

FTC ActCOPPAUnfair practicesChildren's online privacy

Practice question for this objective

Free sampleLimits on Private-Sector Collection and Use of Datamedium

A homework-help website directed at children lets a child type in a question and provide an email address so the site can email a single answer back, after which the email is deleted and never used again. The site collects no other information and makes no further contact. The operator wants to know whether COPPA still forces it to obtain verifiable parental consent before this one-time email exchange. Counsel must identify the governing rule. Which assessment is correct?

  • ACOPPA always requires verifiable parental consent before any collection of a child's email, so the operator must obtain consent even for this one-time reply.
  • BCOPPA provides a limited exception allowing collection of a child's online contact details to respond once to a specific request, so no prior verifiable parental consent is required for this single response. Correct
  • CCOPPA does not apply, because a child's email address is not online contact information and therefore is never personal information under the statute.
  • DCOPPA permits the collection only if the operator first posts a notice and obtains the child's own affirmative agreement in place of parental consent.
Apply COPPA's one-time response exception, which permits collecting a child's online contact information to answer a single request without prior verifiable parental consent. The COPPA Rule lets an operator collect a child's online contact information solely to respond once to a specific request and then delete it, so a homework site emailing a single answer back falls within that exception and does not need prior verifiable parental consent, even though an email address is otherwise personal information.

Why A is wrong: Tempting because consent is COPPA's general rule, but the Rule carves out specific exceptions, and a one-time response to a child's own request is one of them, so the absolute framing here is wrong.

Why B is correct: Correct: the COPPA Rule includes a narrow exception permitting an operator to collect a child's online contact information solely to respond on a one-time basis to a specific request and then delete it, so prior verifiable parental consent is not required for this single email reply.

Why C is wrong: Tempting because the exception leads to no consent here, but the right reason is the one-time response exception, not that email is excluded; an email address is online contact information and is personal information under COPPA.

Why D is wrong: Tempting because a notice sounds protective, but COPPA does not let a child substitute their own agreement for parental consent, and the one-time response exception turns on the limited purpose and deletion, not on the child's consent.

See more CIPP-US practice questions, answers explained.

Exam traps in Limits on Private-Sector Collection and Use of Data

Answers that look right on this material and are not. Each one is a distractor from a different question in the CIPP-US bank for this domain.

  • The FTC cannot act at all, because without a broken promise or a specific privacy statute there is no legal basis for an enforcement action against the company's security failures.

    Why it is wrong: Tempting because no statement was broken, but Section 5 reaches unfair practices independent of any promise or sectoral statute, so the absence of a misrepresentation does not deprive the FTC of authority here.

  • The Gramm-Leach-Bliley Act privacy rule, because that statute is the only authority that can address a financial firm's false privacy statements to applicants.

    Why it is wrong: Tempting because GLBA governs financial privacy, but it does not displace the FTC's general power over deceptive statements, and the question asks for the source the FTC most directly relies on, which is its own cross-sector authority, not GLBA.

  • The unfairness prong, because the sale causes substantial injury that consumers cannot reasonably avoid and that is not outweighed by countervailing benefits

    Why it is wrong: Unfairness is a real Section 5 theory and could be argued in some data cases, but where the company made an explicit promise it then broke, the cleaner and primary theory is deception, so this is the weaker fit.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.