The data privacy policy: Which existing policy most directly needs review before proceeding?
Reusing customer data for a new AI purpose raises purpose-limitation and lawful-basis issues, so the data privacy policy must be reviewed first.
The question
A marketing team wants to reuse customer data originally collected for order fulfillment to train a new recommendation model. A governance reviewer flags that this new purpose was not covered when the data was collected. Which existing policy most directly needs review before proceeding?
Preparing for AIGP? Take the free 5-min readiness quiz →
- The physical security policy, because the servers hosting the customer records must be protected against unauthorized physical on-site access attempts.Off-topic; the issue is repurposing personal data, not physical access to servers.
- The business continuity policy, because the recommendation model must remain available to customers if the primary data center suffers an outage.Incorrect; availability planning does not address whether the data may lawfully be reused for a new purpose.
- The data privacy policy, because reusing personal data for a new AI purpose raises purpose-limitation and lawful-basis questions to resolve first. ✓Correct. Repurposing personal data implicates purpose limitation and lawful basis, which the data privacy policy governs.
- The intellectual property policy, because the ownership of the trained recommendation model's outputs must be clarified before any deployment.Almost relevant, since IP matters generally, but the flagged concern is repurposing personal data, which is a privacy matter.
The trap
Overlooking purpose limitation, and treating data repurposing as a security or IP issue rather than a privacy one. How to remember it
Reusing customer data for a new AI purpose raises purpose-limitation and lawful-basis issues, so the data privacy policy must be reviewed first.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding the Foundations of AI Governance questions
- At ethics by design: At which lifecycle stage should the governing policy require this ethical evaluation to →
- Conduct a vendor due-diligence assessment covering: Which action best reflects sound third-party AI risk →
- Generative AI: Which type of AI does this capability best exemplify? →
- All 337 Understanding the Foundations of AI Governance questions →
Part of the Certsqill AIGP question bank · Understanding the Foundations of AI Governance ·
Every answer, right and wrong, comes with its own explanation.