The data privacy policy: Which existing policy most directly needs review before proceeding?
Reusing customer data for a new AI purpose raises purpose-limitation and lawful-basis issues, so the data privacy policy must be reviewed first.
The question
A marketing team wants to reuse customer data originally collected for order fulfillment to train a new recommendation model. A governance reviewer flags that this new purpose was not covered when the data was collected. Which existing policy most directly needs review before proceeding?
Preparing for AIGP? Take the free 5-min readiness quiz →
- The physical security policy, because the servers hosting the customer records must be protected against unauthorized physical on-site access attempts.Off-topic; the issue is repurposing personal data, not physical access to servers.
- The business continuity policy, because the recommendation model must remain available to customers if the primary data center suffers an outage.Incorrect; availability planning does not address whether the data may lawfully be reused for a new purpose.
- The data privacy policy, because reusing personal data for a new AI purpose raises purpose-limitation and lawful-basis questions to resolve first. ✓Correct. Repurposing personal data implicates purpose limitation and lawful basis, which the data privacy policy governs.
- The intellectual property policy, because the ownership of the trained recommendation model's outputs must be clarified before any deployment.Almost relevant, since IP matters generally, but the flagged concern is repurposing personal data, which is a privacy matter.
The trap
Overlooking purpose limitation, and treating data repurposing as a security or IP issue rather than a privacy one. How to remember it
Reusing customer data for a new AI purpose raises purpose-limitation and lawful-basis issues, so the data privacy policy must be reviewed first.
How many of these would you get right?
One of 499 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding the Foundations of AI Governance questions
- Because AI risks span legal: Why does effective AI governance typically require collaboration across multiple →
- Transparency and explainability for the understandable: Which responsible-AI principles most directly correspo →
- The provider, which develops or has an AI system made: In common AI-governance terminology distinguishing deve →
- All 104 Understanding the Foundations of AI Governance questions →
Part of the Certsqill AIGP question bank · Understanding the Foundations of AI Governance ·
Every answer, right and wrong, comes with its own explanation.