The data privacy policy: Which existing policy most directly | AIGP
7-day money-back guarantee — full refund within 7 days of purchase if you've completed under 20% of the questions. See pricing →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

Language

✓ EnglishDeutschEspañolFrançaisPortuguês
Check readiness — free →

The data privacy policy: Which existing policy most directly needs review before proceeding?

AIGP Understanding the Foundations of AI Governance Medium

Reusing customer data for a new AI purpose raises purpose-limitation and lawful-basis issues, so the data privacy policy must be reviewed first.

The question

A marketing team wants to reuse customer data originally collected for order fulfillment to train a new recommendation model. A governance reviewer flags that this new purpose was not covered when the data was collected. Which existing policy most directly needs review before proceeding?

Preparing for AIGP? Take the free 5-min readiness quiz →

  1. The physical security policy, because the servers hosting the customer records must be protected against unauthorized physical on-site access attempts.
    Off-topic; the issue is repurposing personal data, not physical access to servers.
  2. The business continuity policy, because the recommendation model must remain available to customers if the primary data center suffers an outage.
    Incorrect; availability planning does not address whether the data may lawfully be reused for a new purpose.
  3. The data privacy policy, because reusing personal data for a new AI purpose raises purpose-limitation and lawful-basis questions to resolve first.
    Correct. Repurposing personal data implicates purpose limitation and lawful basis, which the data privacy policy governs.
  4. The intellectual property policy, because the ownership of the trained recommendation model's outputs must be clarified before any deployment.
    Almost relevant, since IP matters generally, but the flagged concern is repurposing personal data, which is a privacy matter.
The trap
Overlooking purpose limitation, and treating data repurposing as a security or IP issue rather than a privacy one.

How to remember it

Reusing customer data for a new AI purpose raises purpose-limitation and lawful-basis issues, so the data privacy policy must be reviewed first.

How many of these would you get right?

One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.

Test your AIGP readiness — free

More Understanding the Foundations of AI Governance questions

Part of the Certsqill AIGP question bank · Understanding the Foundations of AI Governance · Every answer, right and wrong, comes with its own explanation.