What Should Be Done First When Tracking Consumer Web Browser Activity?
An organization is planning a new implementation for tracking consumer web browser activity. Which of the following should be done FIRST?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the correct sequence in the privacy lifecycle: a PIA must come before consent, cookie policy updates, and regulatory approvals because it defines what risks need to be mitigated and informs all downstream decisions.
When an organization plans to track consumer web browser activity, the first step is to conduct a privacy impact assessment (PIA), not to seek consent or regulatory approval. Community consensus clearly favors the PIA option, as it helps the organization understand the scope, purpose, and risks before any other privacy action is taken.
The most common wrong answer is C: Obtain consent from the organization’s clients. Test-takers often think consent is the first privacy requirement, but consent language and mechanisms cannot be designed correctly until the PIA has identified what data is collected, why it is collected, and the risks involved.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A privacy impact assessment is the foundational step for evaluating the purpose, necessity, and risks of processing personal data before implementation begins. Tracking consumer web browser activity is a high-risk monitoring activity, so the organization needs a PIA to identify the legal basis, data minimization principles, and required safeguards. As comment [2] points out, the organization must first fully understand the scope, purpose, and risks before taking any other action, including obtaining consent.Why the Other Options Are Wrong
Option A is incorrect because regulatory approval would depend on the findings of the PIA and cannot be obtained intelligently before risks are assessed. Option C is premature because the PIA must first determine whether consent is the appropriate legal basis and exactly what the consent should cover. Option D is also a later step: the cookie policy should be reviewed and updated only after the PIA's conclusions reveal what information needs to be disclosed and what technical measures must be implemented.Community Comment Notes
All three provided comments select B, showing a strong consensus. Comment [2] gives the clearest reasoning: before obtaining consent, the organization must first understand the full scope, purpose, and risks of the tracking activity. Comments [1] and [3] simply vote for B, and no dissenting view appears, confirming B as the expected CDPSE answer.Official Reference
Exam Strategy
When a CDPSE question asks 'which should be done FIRST' and involves new processing or tracking, always look for the privacy/risk assessment option — PIA or DPIA — because it precedes consent, notices, and regulatory conversations. Memorize this sequence: assess risk first, then update policies and consent mechanisms, and engage regulators only when required by law.
Related Analysis
Practice All CDPSE Questions
Access 229 questions with complete answers and detailed explanations.
View Full CDPSE Practice Test →