CIPP-US - Limits on Private-Sector Collection and Use of Data - Section 2.1

Apply the FTC's cross-sector authority to identify unfair or deceptive privacy practices and the role of COPPA in protecting children's online data.

Apply the FTC Act's prohibition on unfair or deceptive acts to privacy scenarios and recognise that the FTC treats broken privacy promises and inadequate data security as violations. Describe COPPA's requirements for verifiable parental consent, notice, and data deletion for operators of websites and online services directed at children under 13.

FTC ActCOPPAUnfair practicesChildren's online privacy

Practice question for this objective

Free sampleLimits on Private-Sector Collection and Use of Datamedium

A homework-help website directed at children lets a child type in a question and provide an email address so the site can email a single answer back, after which the email is deleted and never used again. The site collects no other information and makes no further contact. The operator wants to know whether COPPA still forces it to obtain verifiable parental consent before this one-time email exchange. Counsel must identify the governing rule. Which assessment is correct?

  • ACOPPA always requires verifiable parental consent before any collection of a child's email, so the operator must obtain consent even for this one-time reply.
  • BCOPPA provides a limited exception allowing collection of a child's online contact details to respond once to a specific request, so no prior verifiable parental consent is required for this single response. Correct
  • CCOPPA does not apply, because a child's email address is not online contact information and therefore is never personal information under the statute.
  • DCOPPA permits the collection only if the operator first posts a notice and obtains the child's own affirmative agreement in place of parental consent.
Apply COPPA's one-time response exception, which permits collecting a child's online contact information to answer a single request without prior verifiable parental consent. The COPPA Rule lets an operator collect a child's online contact information solely to respond once to a specific request and then delete it, so a homework site emailing a single answer back falls within that exception and does not need prior verifiable parental consent, even though an email address is otherwise personal information.

Why A is wrong: Tempting because consent is COPPA's general rule, but the Rule carves out specific exceptions, and a one-time response to a child's own request is one of them, so the absolute framing here is wrong.

Why B is correct: Correct: the COPPA Rule includes a narrow exception permitting an operator to collect a child's online contact information solely to respond on a one-time basis to a specific request and then delete it, so prior verifiable parental consent is not required for this single email reply.

Why C is wrong: Tempting because the exception leads to no consent here, but the right reason is the one-time response exception, not that email is excluded; an email address is online contact information and is personal information under COPPA.

Why D is wrong: Tempting because a notice sounds protective, but COPPA does not let a child substitute their own agreement for parental consent, and the one-time response exception turns on the limited purpose and deletion, not on the child's consent.

See more CIPP-US practice questions, answers explained.

More in this domain

Back to all Limits on Private-Sector Collection and Use of Data objectives, or the CIPP-US cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.