TechNuggets Academy

State Privacy Laws

Free Certified Information Privacy Professional/United States practice — 6 questions on State Privacy Laws, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 5: State Privacy Laws
A California retailer collects customers' precise geolocation data via its mobile app and uses that geolocation to serve targeted advertisements across third-party websites and apps (cross-context behavioral advertising). This use falls outside the permitted business purposes listed in the CCPA regulations for sensitive personal information (SPI). Which specific CCPA/CPRA consumer right is MOST directly implicated by this use, requiring the retailer to provide a 'Limit the Use of My Sensitive Personal Information' link?
The CCPA regulations require businesses to offer a right to limit when SPI is used or disclosed for purposes beyond the enumerated permitted purposes (e.g., providing the requested service, security, short-term use, internal quality improvement). Cross-context behavioral advertising using precise geolocation (a defined SPI category) exceeds those permitted purposes, triggering the specific 'Limit the Use of My Sensitive Personal Information' obligation and link.
Question 2 of 6 · Domain 5: State Privacy Laws
Effective July 1, 2024, a controller subject to the Colorado Privacy Act (CPA) detects an incoming browser signal indicating the consumer's preference to opt out of the sale of personal data and targeted advertising. The consumer has not separately emailed the company or submitted a form. Under the CPA, what is the controller's obligation?
Colorado was the first state to make recognition of a universal opt-out mechanism (UOOM) mandatory, effective July 1, 2024. Controllers must treat a valid UOOM signal (such as Global Privacy Control) as a legitimate opt-out request for sale and targeted advertising without requiring further consumer action or identity verification for that opt-out.
Question 3 of 6 · Domain 5: State Privacy Laws
A social media platform doing business in Connecticut knows that a registered user is 15 years old. Under the amendments to the Connecticut Data Privacy Act effective October 1, 2024, what must the platform obtain before processing this user's personal data for purposes of targeted advertising or sale?
The 2023 CTDPA amendments (effective Oct. 1, 2024) require controllers who have actual knowledge, or willfully disregard, that a consumer is between 13 and 16 years old to obtain the consumer's own affirmative opt-in consent before processing their data for targeted advertising, sale, or certain profiling — distinct from COPPA's parental-consent model for under-13s.
Question 4 of 6 · Domain 5: State Privacy Laws
In Rosenbach v. Six Flags Entertainment Corp. (2019), the Illinois Supreme Court addressed standing to sue under the Biometric Information Privacy Act (BIPA). What did the court hold regarding a plaintiff's ability to bring a private right of action?
The Illinois Supreme Court held that a technical or procedural violation of BIPA (such as failing to provide required disclosures or obtain consent before collecting a fingerprint) is sufficient by itself to make a plaintiff an 'aggrieved person' entitled to sue and seek BIPA's liquidated damages — no separate actual injury, like identity theft or financial loss, needs to be shown.
Question 5 of 6 · Domain 5: State Privacy Laws
A company determines that a security breach compromised the personal information of Florida residents. No law enforcement delay request has been made. Under the Florida Information Protection Act (FIPA), absent an approved extension, within how many days after determining the breach occurred must the company provide notice to affected individuals?
FIPA requires notice to affected individuals as expeditiously as practicable and without unreasonable delay, but no later than 30 days after determination of the breach (or reason to believe a breach occurred), subject to a possible additional 15-day extension for good cause shown — capping the maximum window at 45 days, but the baseline statutory deadline is 30 days.
Question 6 of 6 · Domain 5: State Privacy Laws
California's Delete Act (SB 362) amended the state's data broker registration law. Beginning January 1, 2026, in addition to annual registration with the California Privacy Protection Agency (CPPA), what new obligation must registered data brokers meet regarding consumer deletion requests?
The Delete Act requires the CPPA to build and, beginning in 2026, requires registered data brokers to check and comply with deletion requests made through a single, centralized mechanism (DROP), allowing consumers to submit one deletion request that applies across all registered data brokers rather than contacting each broker individually.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →