FTC and COPPA Flashcards

Learn how the Federal Trade Commission enforces privacy through Section 5 and how COPPA protects children’s online data. (47 cards)

1
Q

What is the mission of the FTC?

A

Protect the public from deceptive or unfair business practices and unfair competition.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is considered ‘unfair’ under FTC authority?

A
  • Causes substantial injury
  • Not offset by benefits
  • Not reasonably avoidable by consumers
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What makes a practice ‘deceptive’?

A

Material misstatement or omission likely to mislead consumers.

Examples: false statements, misrepresentations, failure to comply with privacy notices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the FTC’s role in privacy enforcement?

A

Enforces sector-specific laws and considers breaches of notice as deceptive practices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What law falls under FTC’s sole jurisdiction?

A

Children’s Online Privacy Protection Act

(COPPA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What laws does the FTC share jurisdiction over?

A
  • FCRA
  • FACTA
  • CAN-SPAM
  • TSR
  • HITECH
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Section 5 of the FTC Act?

A

Allows regulation of unfair or deceptive acts or practices (UDAP).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Section 6 of the FTC Act?

A

Grants investigative authority to the FTC.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does Section 5(L) authorize?

A

Administrative proceedings for cease-and-desist orders and penalties for repeat violations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a regulatory authority?

A

A federal or state agency authorized to implement and enforce legislation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How does the FTC learn about UDAP violations?

A
  • Company filings
  • Journalism
  • Market competition
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the steps in an FTC enforcement action?

A
  • Investigation
  • Subpoena/testimony
  • Administrative trial
  • Decision
  • Appeal to commissioners/federal court
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What additional actions can courts take beyond fines?

A

Order redress for consumers and issue injunctions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a consent decree?

A
  • Settlement with FTC
  • No admission of fault
  • Company agrees to change practices
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Why are consent decrees published?

A

To guide other companies on acceptable practices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Who monitors violations of consent decrees?

A
  • FTC Division of Enforcement
  • U.S. Dept. of Justice
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What might a consent decree require?

A
  • Specific actions
  • Compliance proof
  • Audits
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Why do companies agree to consent decrees?

A
  • Avoid court
  • Reduce costs
  • Prevent bad press
  • Protect practices
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What happens if a consent decree is violated?

A

Easier penalty assessment and enforcement.

20
Q

Who else enforces UDAP beyond the FTC?

A

State-level authorities and self-regulation bodies.

21
Q

What law governs FTC rulemaking instead of the APA?

A

Magnuson-Moss FTC Improvements Act (1975).

22
Q

What was the impact of West Virginia v. EPA?

A

SCOTUS invoked the ‘major questions doctrine’ to limit agency power

May constrain FTC rulemaking.

23
Q

What is the ‘major questions doctrine’?

A

Regulatory agencies need clear Congressional authority to issue significant rules.

24
Q

How does the FTC define commercial surveillance?

A
  • collection
  • aggregation
  • analysis
  • retention
  • transfer
  • monetization of commercial data and derivatives
25
What are **dark patterns**?
Designs that **manipulate users** into disclosing PII or making purchases. ## Footnote e.g., hidden fees, hard cancellations
26
Who typically enforces UDAP **at the state level**?
State Attorneys General | (AGs)
27
What is meant by '**unconscionable practices**'?
**Harsh seller practices** that some states enforce under UDAP.
28
What is **HIPAA's impact** on state privacy laws?
Many states **exempt HIPAA-regulated entities** and data.
29
How does **GLBA affect state** privacy enforcement?
States like CO, CT, UT, and VA **exempt GLBA-regulated entities** and data.
30
How is the **FCRA treated in state** privacy laws?
Many states **exempt FCRA-regulated entities** and data.
31
What does the **DPPA** regulate?
Driver's personal data.
32
What does the **Social Security Number Confidentiality Act** prohibit?
SSN **visibility through envelope windows** from the Treasury.
33
How does DPPA **protect SSNs**?
* Treats them as highly restricted information * Limits DMV disclosures
34
What does **COPPA** stand for?
Children's Online Privacy Protection Act
35
Who does COPPA **protect**?
Children **under 13** in the U.S.
36
What **services are covered** by COPPA?
**Websites** and **online services** that target children.
37
Who **enforces** COPPA?
FTC and State Attorneys General
38
What are **key requirements** under **COPPA**?
* Parental opt-in before collecting data * Privacy policy must explain collection * Link to privacy policy on every page collecting data
39
What is **co-regulation** in COPPA?
Once FTC certifies a program, compliance with it is **sufficient to meet the statute**.
40
What are examples of **COPPA seal programs**?
* Aristotle * CARU * ESRB * iKeepSafe * kidSAFE * PRIVO * TrustArc
41
What is **DOPPA** and how does it differ from COPPA?
* Delaware law for **minors** under 18 * Bans ads for **illegal products** and limits some PII use
42
How does **CCPA** address children's data?
* Bans sale of data under 16 without consent * 13-15-year-olds may opt-in themselves
43
What is **Moore's Law**?
Computing power **doubles every 18-24 months** due to increased transistor density.
44
Who **proposed** Moore's Law and **when**?
**Gordon Moore**, co-founder of Intel, in **1965**.
45
What is the **First Law** of Asimov's Robotics?
A robot must **not harm a human** or allow harm through inaction.
46
What is the **Second Law** of Asimov's Robotics?
A robot must **obey humans** unless this conflicts with the First Law.
47
What is the **Third Law** of Asimov's Robotics?
A robot **must protect its own existence** unless this conflicts with the First or Second Law.