A bank collected transaction records to detect payment fraud, telling customers at collection that the data was for fraud prevention. A new team now wants to reuse the same records to train a credit-scoring model for marketing loan offers. Under the purpose limitation principle, what must the bank establish before it may reuse the data this way?
- AThat credit scoring for marketing is compatible with the original fraud-prevention purpose, or that it rests on consent or a separate legal basis Correct
- BThat the records have been stored securely and encrypted throughout the period since they were first collected for fraud detection
- CThat the credit-scoring model will be at least as accurate as the existing fraud-detection model before the data is reused
- DThat customers have not yet objected to any processing of their transaction records since the original fraud-prevention notice was given
Why A is correct: Purpose limitation forbids further processing incompatible with the stated purpose, so the bank must show the new marketing use is compatible using the recognised compatibility factors, or otherwise obtain consent or another valid basis for it.
Why B is wrong: Strong storage security is required in its own right, but it addresses integrity and confidentiality rather than purpose limitation, which governs whether a new use is permitted at all rather than how the data is protected.
Why C is wrong: Model accuracy is an understandable engineering concern, but purpose limitation turns on the relationship between the original and new purposes, not on how well the new model performs once it is built.
Why D is wrong: An absence of objections is tempting because silence can feel like acceptance, but failing to object does not make a fresh, unrelated purpose lawful, and the burden lies on the controller to justify the new use.