CCAR-P - Governance, Safety & Risk Management (14% of the exam) - Section 5.4

Ensure compliance with regulations (e.g., GDPR, HIPAA, FedRAMP).

Designing for regulatory obligations: data minimisation and residency, handling personal and health data, audit trails, and choosing a deployment platform whose compliance posture fits the regulator. Candidates should map a stated regulatory requirement to the architectural control that meets it.

GDPRHIPAAFedRAMPdata residencyaudit trails

Practice question for this objective

Free sampleGovernance, Safety & Risk Managementhard

A UK university is adding a Claude-based assistant that drafts formative feedback on student essays against a marking rubric. The current integration sends each essay with the student's full record: name, student number, date of birth, disability adjustments and prior grades. The data protection officer cites the UK GDPR data minimisation principle and requires that each request carry only the personal data needed to produce rubric feedback, while tutors must still see each piece of feedback against the right student. Which change best meets that requirement?

  • AKeep the full record in each request and add a system prompt telling the model to ignore every field except the essay.
  • BSend only the essay text and rubric with an opaque submission ID, and re-link feedback to the student on the server side. Correct
  • CKeep the full record in each request but encrypt it end to end and cut the retention of request logs to seven days.
  • DSend the essay with a hashed student number, date of birth and prior grades, so the model can personalise its feedback.
Data minimisation is met by removing unneeded personal data from what is sent to the model and re-linking identity in systems you control. Data minimisation in UK GDPR Article 5 limits personal data to what is adequate, relevant and necessary for the purpose. Producing rubric feedback needs the essay and the rubric, so every other field is excess. Sending an opaque submission ID and keeping the mapping to the student in the university's own system removes that excess at source while still letting tutors see feedback against the right student. Encryption, retention limits and prompt instructions act on data that should never have been sent.

Why A is wrong: Telling the model to ignore fields can stop them shaping the feedback, which is tempting, but the personal data is still transmitted and processed, so it does nothing for minimisation, which concerns what is collected and sent.

Why B is correct: Correct: rubric feedback needs only the essay and the rubric, so the request carries no other personal data, and the university's own system holds the mapping from submission ID to student so tutors still see the feedback in the right place.

Why C is wrong: Encryption and shorter retention are sound security and storage-limitation measures, but they protect data that should not be sent in the first place, so the minimisation requirement on each request is still unmet.

Why D is wrong: Hashing the student number looks like pseudonymisation, but date of birth and prior grades are not needed to apply a marking rubric, and personalisation was not the stated purpose, so excess personal data is still sent.

See more CCAR-P practice questions, answers explained.

Exam traps in Governance, Safety & Risk Management

Answers that look right on this material and are not. Each one is a distractor from a different question in the CCAR-P bank for this domain.

  • Keep the US endpoint and put standard contractual clauses in place, so the transfer of patient data is lawful under GDPR.

    Why it is wrong: Standard contractual clauses are a real mechanism for lawful transfers, which makes this tempting, but the requirement here is residency of processing, and a lawful transfer still sends the data to be processed outside the EU.

  • The model has absorbed diagnosis text from earlier member sessions and now emits it into unrelated conversations

    Why it is wrong: Blaming the model is tempting when sensitive text turns up somewhere unexpected. It is wrong because the model does not learn from inference traffic, the model is stated as unchanged, and leaking text into replies would still not explain how it came to be stored by a separate monitoring vendor.

  • Add a query-time filter that drops any retrieved chunk belonging to an erased resident before it reaches the model's context.

    Why it is wrong: A filter would stop the passages appearing in answers, which is what the test caught, but the data would still be held in the index and the cache, so the requirement to remove it from every store is not met.

Examworthy is not affiliated with or endorsed by Anthropic. Original, blueprint-aligned practice material only.