AIGP - Understanding how laws, standards and frameworks apply to AI (25% of the exam) - Section 2.1

Understand how data privacy law requirements - including transparency, lawful basis, purpose limitation, data minimisation, privacy by design, and automated decision making - apply to AI systems.

Apply GDPR requirements - lawful basis, purpose limitation, data minimisation, privacy by design, and automated decision-making rules - to the design and operation of AI systems. Recognise how these obligations constrain data collection, model training, and profiling.

GDPRpurpose limitationprivacy by designautomated decision making

Practice question for this objective

Free sampleUnderstanding how laws, standards and frameworks apply to AImedium

A bank collected transaction records to detect payment fraud, telling customers at collection that the data was for fraud prevention. A new team now wants to reuse the same records to train a credit-scoring model for marketing loan offers. Under the purpose limitation principle, what must the bank establish before it may reuse the data this way?

  • AThat credit scoring for marketing is compatible with the original fraud-prevention purpose, or that it rests on consent or a separate legal basis Correct
  • BThat the records have been stored securely and encrypted throughout the period since they were first collected for fraud detection
  • CThat the credit-scoring model will be at least as accurate as the existing fraud-detection model before the data is reused
  • DThat customers have not yet objected to any processing of their transaction records since the original fraud-prevention notice was given
Apply purpose limitation by testing whether a new AI use is compatible with the original collection purpose or needs consent or a fresh lawful basis. Purpose limitation requires personal data to be collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those purposes. Moving from fraud prevention to credit scoring for marketing is a materially different aim, so the bank must run a compatibility assessment that weighs the link between purposes, the context of collection, the nature of the data and the likely consequences for customers. If the new use is not compatible, it can only proceed on the basis of consent or another lawful ground, not merely because the data is already held.

Why A is correct: Purpose limitation forbids further processing incompatible with the stated purpose, so the bank must show the new marketing use is compatible using the recognised compatibility factors, or otherwise obtain consent or another valid basis for it.

Why B is wrong: Strong storage security is required in its own right, but it addresses integrity and confidentiality rather than purpose limitation, which governs whether a new use is permitted at all rather than how the data is protected.

Why C is wrong: Model accuracy is an understandable engineering concern, but purpose limitation turns on the relationship between the original and new purposes, not on how well the new model performs once it is built.

Why D is wrong: An absence of objections is tempting because silence can feel like acceptance, but failing to object does not make a fresh, unrelated purpose lawful, and the burden lies on the controller to justify the new use.

See more AIGP practice questions, answers explained.

Exam traps in Understanding how laws, standards and frameworks apply to AI

Answers that look right on this material and are not. Each one is a distractor from a different question in the AIGP bank for this domain.

  • Collect everything now but anonymise the extra fields, since anonymised data falls outside the scope of data protection law

    Why it is wrong: Anonymisation can remove data from the law's scope, but gathering unnecessary identifiable data first still breaches minimisation, and robust anonymisation is hard to achieve, so this does not resolve the problem at the point of collection.

  • Purpose limitation requires holding personal data for the shortest time necessary, while data minimisation requires recording the legal basis for each processing activity.

    Why it is wrong: This is tempting because storage limitation and accountability are also GDPR principles, but it misnames both: purpose limitation is about why data may be used, not retention period, and data minimisation is about how much data, not documenting the legal basis.

  • Encrypting the stored transcripts at rest and restricting access to them so that only the AI training team can read the retained conversations.

    Why it is wrong: Tempting because encryption and access control are sound security measures, but they protect data that is still being kept indefinitely; they do not address how long the personal data is retained, which is the principle at issue.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.