Join the discussion
Question 91/136
Which of the following state laws has an entity exemption for organizations subject to the Gramm- Leach-Bliley Act (GLBA)?
Correct Answer: B
The Virginia Consumer Data Protection Act (VCDPA) is a state law that provides comprehensive privacy rights and obligations for consumers and businesses in Virginia. The VCDPA applies to any entity that conducts business in Virginia or produces products or services that are targeted to residents of Virginia and that either: (a) controls or processes personal data of at least 100,000 consumers; or (b) controls or processes personal data of at least 25,000 consumers and derives over 50% of gross revenue from the sale of personal data. However, the VCDPA also provides several exemptions for certain types of entities and data, including an entity exemption for financial institutions or data subject to the Gramm-Leach-Bliley Act (GLBA). This means that organizations that are regulated by the GLBA are not subject to the VCDPA, regardless of the type or source of data they collect or process. The GLBA is a federal law that regulates the collection, use, and disclosure of personal financial information by financial institutions and their affiliates. The GLBA applies to any business that is significantly engaged in financial activities, such as banks, credit unions, securities firms, insurance companies, and certain fintech companies. The GLBA requires financial institutions to provide notice and choice to consumers about their privacy practices, to safeguard the security and confidentiality of consumer information, and to limit the sharing of consumer information with third parties. The GLBA also preempts state laws only to the extent that they are inconsistent with the GLBA, unless the state law provides greater protection to consumers. The other state laws listed in the question do not have an entity exemption for organizations subject to the GLBA, but they may have partial or data exemptions for certain types of information that are regulated by the GLBA. For example, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) are state laws that provide comprehensive privacy rights and obligations for consumers and businesses in California. The CCPA and the CPRA apply to any business that collects or sells the personal information of California residents and that meets one or more of the following thresholds: (a) has annual gross revenues in excess of $25 million; (b) alone or in combination, annually buys, receives for the business's commercial purposes, sells, or shares for commercial purposes, the personal information of 50,000 or more consumers, households, or devices; or ?derives 50% or more of its annual revenues from selling consumers' personal information. However, the CCPA and the CPRA also provide several exemptions for certain types of entities and data, including a data exemption for personal information collected, processed, sold, or disclosed pursuant to the GLBA, if it is in conflict with the GLBA. This means that information that is subject to the GLBA is exempt from the privacy requirements of the CCPA and the CPRA, but not from the data breach liability provisions. The CCPA and the CPRA do not exempt financial institutions or other entities that are regulated by the GLBA from their scope, unless they only collect or process information that is subject to the GLBA.
The Nevada Privacy Law is a state law that provides privacy rights and obligations for consumers and operators of websites or online services in Nevada. The Nevada Privacy Law applies to any person who owns or operates an Internet website or online service for commercial purposes that collects and maintains covered information from consumers who reside in Nevada and use or visit the Internet website or online service. Covered information includes any one or more of the following items of personally identifiable information about a consumer collected by an operator through an Internet website or online service and maintained by the operator in an accessible form: (a) a first and last name; (b) a home or other physical address which includes the name of a street and the name of a city or town; ?an electronic mail address; (d) a telephone number; (e) a social security number; (f) an identifier that allows a specific person to be contacted either physically or online; or (g) any other information concerning a person collected from the person through the Internet website or online service of the operator and maintained by the operator in combination with an identifier in a form that makes the information personally identifiable.
However, the Nevada Privacy Law also provides several exemptions for certain types of entities and data, including a data exemption for any data that is subject to the GLBA. This means that information that is regulated by the GLBA is exempt from the Nevada Privacy Law, regardless of the type or source of data. The Nevada Privacy Law does not exempt financial institutions or other entities that are subject to the GLBA from its scope, unless they only collect or process information that is subject to the GLBA.
The Nevada Privacy Law is a state law that provides privacy rights and obligations for consumers and operators of websites or online services in Nevada. The Nevada Privacy Law applies to any person who owns or operates an Internet website or online service for commercial purposes that collects and maintains covered information from consumers who reside in Nevada and use or visit the Internet website or online service. Covered information includes any one or more of the following items of personally identifiable information about a consumer collected by an operator through an Internet website or online service and maintained by the operator in an accessible form: (a) a first and last name; (b) a home or other physical address which includes the name of a street and the name of a city or town; ?an electronic mail address; (d) a telephone number; (e) a social security number; (f) an identifier that allows a specific person to be contacted either physically or online; or (g) any other information concerning a person collected from the person through the Internet website or online service of the operator and maintained by the operator in combination with an identifier in a form that makes the information personally identifiable.
However, the Nevada Privacy Law also provides several exemptions for certain types of entities and data, including a data exemption for any data that is subject to the GLBA. This means that information that is regulated by the GLBA is exempt from the Nevada Privacy Law, regardless of the type or source of data. The Nevada Privacy Law does not exempt financial institutions or other entities that are subject to the GLBA from its scope, unless they only collect or process information that is subject to the GLBA.
Add Comments
- Other Question (136q)
- Q1. More than half of U S. states require telemarketers to do which of the following?...
- Q2. A student has left high school and is attending a public postsecondary institution. Under ...
- Q3. Under the Fair and Accurate Credit Transactions Act (FACTA), what is the most appropriate ...
- Q4. According to Section 5 of the FTC Act, self-regulation primarily involves a company's righ...
- Q5. Which of the following best describes private-sector workplace monitoring in the United St...
- Q6. Which federal act does NOT contain provisions for preempting stricter state laws?...
- Q7. Under Section 702 of FISA, which surveillance program allows data requests of Internet Ser...
- Q8. The Video Privacy Protection Act of 1988 restricted which of the following?...
- Q9. SCENARIO Please use the following to answer the next QUESTION When there was a data breach...
- Q10. Which entities must comply with the Telemarketing Sales Rule?...
- Q11. SCENARIO Please use the following to answer the next QUESTION Felicia has spent much of he...
- Q12. SCENARIO Please use the following to answer the next QUESTION: Declan has just started a j...
- Q13. What information did the Red Flag Program Clarification Act of 2010 add to the original Re...
- Q14. SCENARIO Please use the following to answer the next QUESTION When there was a data breach...
- Q15. Smith Memorial Healthcare (SMH) is a hospital network headquartered in New York and operat...
- Q16. SCENARIO Please use the following to answer the next QUESTION : A US-based startup company...
- Q17. Which of the following best describes how federal anti-discrimination laws protect the pri...
- Q18. Which federal agency plays a role in privacy policy, but does NOT have regulatory authorit...
- Q19. Read this notice: Our website uses cookies. Cookies allow us to identify the computer or d...
- Q20. SCENARIO Please use the following to answer the next QUESTION : Matt went into his son's b...
- Q21. SCENARIO Please use the following to answer the next QUESTION: A US-based startup company ...
- Q22. What is an exception to the Electronic Communications Privacy Act of 1986 ban on intercept...
- Q23. What was the original purpose of the Foreign Intelligence Surveillance Act?...
- Q24. Which of the following best describes an employer's privacy-related responsibilities to an...
- Q25. Which federal agency plays a role in privacy policy, but does NOT have regulatory authorit...
- Q26. Which of the following definitions best defines privacy as cited in the text and related t...
- Q27. What type of material is exempt from an individual's right to disclosure under the Privacy...
- Q28. Global Manufacturing Co's Human Resources department recently purchased a new software too...
- Q29. Most states with data breach notification laws indicate that notice to affected individual...
- Q30. According to the Family Educational Rights and Privacy Act (FERPA). when can a school disc...
- Q31. According to the Children's Online Privacy Protection Rule, all the following would be con...
- Q32. Which of the following best describes private-sector workplace monitoring in the United St...
- Q33. A financial services company install "bossware" software on its employees' remote computer...
- Q34. What was unique about the action that the Federal Trade Commission took against B.J.'s Who...
- Q35. What do the Civil Rights Act, Pregnancy Discrimination Act, Americans with Disabilities Ac...
- Q36. When does the Telemarketing Sales Rule require an entity to share a do-not-call request ac...
- Q37. Which was NOT one of the five priority areas listed by the Federal Trade Commission in its...
- Q38. Under the Fair and Accurate Credit Transactions Act (FACTA), what is the most appropriate ...
- Q39. A financial services company install "bossware" software on its employees' remote computer...
- Q40. The concept of data portability refers to what?...
- Q41. SCENARIO Please use the following to answer the next question: Declan has just started a j...
- Q42. In 2012, the White House and the FTC both issued reports advocating a new approach to priv...
- Q43. Your company, an online store selling digital keys to video games, has received a data acc...
- Q44. The U.S. Supreme Court has recognized an individual's right to privacy over personal issue...
- Q45. SCENARIO Please use the following to answer the next question: Cheryl is the sole owner of...
- Q46. Under the Fair Credit Reporting Act (FCRA), what must a person who is denied employment ba...
- Q47. Mega Corp. is a U.S.-based business with employees in California, Virginia, and Colorado. ...
- Q48. Which of the following best describes the ASIA-Pacific Economic Cooperation (APEC) princip...
- Q49. John, a California resident, receives notification that a major corporation with $500 mill...
- Q50. What is a legal document approved by a judge that formalizes an agreement between a govern...
- Q51. Privacy Is Hiring Inc., a CA-based company, is an online specialty recruiting firm focusin...
- Q52. SCENARIO Please use the following to answer the next QUESTION: A US-based startup company ...
- Q53. All of the following organizations are specified as covered entities under the Health Insu...
- Q54. SCENARIO Please use the following to answer the next QUESTION: Cheryl is the sole owner of...
- Q55. When developing a company privacy program, which of the following relationships will most ...
- Q56. Which of these organizations would be required to provide its customers with an annual pri...
- Q57. Which of the following practices is NOT a key component of a data ethics framework?...
- Q58. Which of the following would NOT constitute an exception to the authorization requirement ...
- Q59. What is the main purpose of the CAN-SPAM Act?
- Q60. The concept of data portability refers to what?...
- Q61. In 2012, the White House and the FTC both issued reports advocating a new approach to priv...
- Q62. Sarah lives in San Francisco, California. Based on a dramatic increase in unsolicited comm...
- Q63. SCENARIO Please use the following to answer the next QUESTION: A US-based startup company ...
- Q64. What practice does the USA FREEDOM Act NOT authorize?...
- Q65. What is the main purpose of requiring marketers to use the Wireless Domain Registry?...
- Q66. Which of the following describes the most likely risk for a company developing a privacy p...
- Q67. Which two FCRA rules were added with the Fair and Accurate Credit Transitions Act in 2003?...
- Q68. What privacy concept grants a consumer the right to view and correct errors on his or her ...
- Q69. Which of the following statements is most accurate in regard to data breach notifications ...
- Q70. What is the main purpose of the Global Privacy Enforcement Network?...
- Q71. The "Consumer Privacy Bill of Rights" presented in a 2012 Obama administration report is g...
- Q72. In March 2012, the FTC released a privacy report that outlined three core principles for c...
- Q73. Which of the following conditions would NOT be sufficient to excuse an entity from providi...
- Q74. SCENARIO Please use the following to answer the next QUESTION : Matt went into his son's b...
- Q75. The rules for "e-discovery" mainly prevent which of the following?...
- Q76. In a case of civil litigation, what might a defendant who is being sued for distributing a...
- Q77. Which was NOT one of the five priority areas listed by the Federal Trade Commission in its...
- Q78. The Cable Communications Policy Act of 1984 requires which activity?...
- Q79. When may a financial institution share consumer information with non-affiliated third part...
- Q80. What role does the U.S. Constitution play in the area of workplace privacy?...
- Q81. According to the FTC Report of 2012, what is the main goal of Privacy by Design?...
- Q82. Which action is prohibited under the Electronic Communications Privacy Act of 1986?...
- Q83. Which law provides employee benefits, but often mandates the collection of medical informa...
- Q84. Which federal agency plays a role in privacy policy, but does NOT have regulatory authorit...
- Q85. Sarah lives in San Francisco, California. Based on a dramatic increase in unsolicited comm...
- Q86. When does the Telemarketing Sales Rule require an entity to share a do-not-call request ac...
- Q87. Which of the following accurately describes the purpose of a particular federal enforcemen...
- Q88. SCENARIO Please use the following to answer the next question: Otto is preparing a report ...
- Q89. SCENARIO Please use the following to answer the next QUESTION: Declan has just started a j...
- Q90. SCENARIO Please use the following to answer the next QUESTION Matt went into his son's bed...
- Q91. Which of the following state laws has an entity exemption for organizations subject to the...
- Q92. SCENARIO Please use the following to answer the next QUESTION: Larry has become increasing...
- Q93. A covered entity suffers a ransomware attack that affects the personal health information ...
- Q94. John, a California resident, receives notification that a major corporation with $500 mill...
- Q95. What are banks required to do under the Gramm-Leach-Bliley Act (GLBA)?...
- Q96. In March 2012, the FTC released a privacy report that outlined three core principles for c...
- Q97. What is the main purpose of the CAN-SPAM Act?
- Q98. Which of the following would NOT constitute an exception to the authorization requirement ...
- Q99. Which entity within the Department of Health and Human Services (HHS) is the primary enfor...
- Q100. What does the Massachusetts Personal Information Security Regulation require as it relates...
- Q101. SCENARIO Please use the following to answer the next QUESTION: Declan has just started a j...
- Q102. If an organization certified under Privacy Shield wants to transfer personal data to a thi...
- Q103. California's SB 1386 was the first law of its type in the United States to do what?...
- Q104. Privacy Is Hiring Inc., a CA-based company, is an online specialty recruiting firm focusin...
- Q105. SCENARIO Please use the following to answer the next question: Matt went into his son's be...
- Q106. Who has rulemaking authority for the Fair Credit Reporting Act (FCRA) and the Fair and Acc...
- Q107. SCENARIO Please use the following to answer the next QUESTION Otto is preparing a report t...
- Q108. SCENARIO Please use the following to answer the next QUESTION Felicia has spent much of he...
- Q109. SCENARIO Please use the following to answer the next QUESTION When there was a data breach...
- Q110. Which of the following would NOT be regulated by the Illinois Biometnc Information Pnvacy ...
- Q111. What was the original purpose of the Foreign Intelligence Surveillance Act?...
- Q112. In which of the following laws is disclosure forbidden unless a person has expressly opted...
- Q113. Which is an exception to the general prohibitions on telephone monitoring that exist under...
- Q114. What consumer protection did the Fair and Accurate Credit Transactions Act (FACTA) require...
- Q115. What important action should a health care provider take if the she wants to qualify for f...
- Q116. Which of the following is NOT one of three broad categories of products offered by data br...
- Q117. SuperMart is a large Nevada-based business that has recently determined it sells what cons...
- Q118. A company's employee wellness portal offers an app to track exercise activity via users' m...
- Q119. SCENARIO Please use the following to answer the next QUESTION When there was a data breach...
- Q120. U.S. federal laws protect individuals from employment discrimination based on all of the f...
- Q121. Which of the following types of information would an organization generally NOT be require...
- Q122. Based on the 2012 Federal Trade Commission report "Protecting Consumer Privacy in an Era o...
- Q123. SCENARIO Please use the following to answer the next question: Matt went into his son's be...
- Q124. Which of the following statements is most accurate in regard to data breach notifications ...
- Q125. The rules for "e-discovery" mainly prevent which of the following?...
- Q126. What is a key way that the Gramm-Leach-Bliley Act (GLBA) prevents unauthorized access into...
- Q127. Under GLBA. which of these organizations would not be required to provide its customers wi...
- Q128. Which of the following best describes how federal anti-discrimination laws protect the pri...
- Q129. When may a financial institution share consumer information with non-affiliated third part...
- Q130. What is a key way that the Gramm-Leach-Bliley Act (GLBA) prevents unauthorized access into...
- Q131. Which of the following scenarios would NOT be covered under HIPAA?...
- Q132. SCENARIO - Please use the following to answer the next question: Miraculous Healthcare is ...
- Q133. What information did the Red Flag Program Clarification Act of 2010 add to the original Re...
- Q134. If an organization maintains data classified as high sensitivity in the same system as dat...
- Q135. SCENARIO Please use the following to answer the next question; Miraculous Healthcare is a ...
- Q136. Based on the 2012 Federal Trade Commission report "Protecting Consumer Privacy in an Era o...
