AIGP - Understanding how laws, standards and frameworks apply to AI - Section 2.1

Understand how data privacy law requirements - including transparency, lawful basis, purpose limitation, data minimisation, privacy by design, and automated decision making - apply to AI systems.

Apply GDPR requirements - lawful basis, purpose limitation, data minimisation, privacy by design, and automated decision-making rules - to the design and operation of AI systems. Recognise how these obligations constrain data collection, model training, and profiling.

GDPRpurpose limitationprivacy by designautomated decision making

Practice question for this objective

Free sampleUnderstanding how laws, standards and frameworks apply to AImedium

A bank collected transaction records to detect payment fraud, telling customers at collection that the data was for fraud prevention. A new team now wants to reuse the same records to train a credit-scoring model for marketing loan offers. Under the purpose limitation principle, what must the bank establish before it may reuse the data this way?

  • AThat credit scoring for marketing is compatible with the original fraud-prevention purpose, or that it rests on consent or a separate legal basis Correct
  • BThat the records have been stored securely and encrypted throughout the period since they were first collected for fraud detection
  • CThat the credit-scoring model will be at least as accurate as the existing fraud-detection model before the data is reused
  • DThat customers have not yet objected to any processing of their transaction records since the original fraud-prevention notice was given
Apply purpose limitation by testing whether a new AI use is compatible with the original collection purpose or needs consent or a fresh lawful basis. Purpose limitation requires personal data to be collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those purposes. Moving from fraud prevention to credit scoring for marketing is a materially different aim, so the bank must run a compatibility assessment that weighs the link between purposes, the context of collection, the nature of the data and the likely consequences for customers. If the new use is not compatible, it can only proceed on the basis of consent or another lawful ground, not merely because the data is already held.

Why A is correct: Purpose limitation forbids further processing incompatible with the stated purpose, so the bank must show the new marketing use is compatible using the recognised compatibility factors, or otherwise obtain consent or another valid basis for it.

Why B is wrong: Strong storage security is required in its own right, but it addresses integrity and confidentiality rather than purpose limitation, which governs whether a new use is permitted at all rather than how the data is protected.

Why C is wrong: Model accuracy is an understandable engineering concern, but purpose limitation turns on the relationship between the original and new purposes, not on how well the new model performs once it is built.

Why D is wrong: An absence of objections is tempting because silence can feel like acceptance, but failing to object does not make a fresh, unrelated purpose lawful, and the burden lies on the controller to justify the new use.

See more AIGP practice questions, answers explained.

More in this domain

Back to all Understanding how laws, standards and frameworks apply to AI objectives, or the AIGP cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.