IAPP CIPP/US Practice Exam

Category - Professional

Under California law, consumers may initiate a private civil action to recover damages in which of the following instances?

  1. An organization violates the CCPA and encrypted personal information is breached.
  2. The consumer’s unencrypted and unredacted personal information is breached due to an organization’s noncompliance with security rules as set forth by CCPA.
  3. Only if the consumer suffers actual damages from the organization’s violation of CCPA
  4. The consumer’s personal information is breached although the organization complied with CCPA and laws about data protection and security.
Explanation
Answer: B

While a consumer is not permitted to sue a business for its noncompliance with its obligations under the CCPA, such as disclosing or deleting personal information, Section 1798.81.5 requires businesses to take certain steps to protect the security of personal information they have on file. A consumer may initiate a private civil action to recover damages if the consumer’s unencrypted and unredacted personal information is breached due to an organization’s noncompliance with CCPA.

This type of private right of action may be pursued even if the consumer did not suffer actual damages from the organization’s violations of CCPA. Consumers may recover between $100 and $750 per incident or actual damages under this type of private right of action. 

Was this helpful? Upvote!
Login to contribute your own answer or details

Top questions

Related questions

Most popular on PracticeQuiz