The vendor processes data only on the hospital’s behalf: Which prior assumption no longer holds?
The vendor’s new independent model-improvement purpose conflicts with processor-only treatment for the hospital’s routing purpose.
The question
A hospital administration office uses a vendor model to route appointment inquiries, not provide clinical advice. The vendor now proposes using inquiry text to improve its general model, while the hospital still determines the routing purpose. Under the GDPR in the European Union, the contract labels the vendor a processor but does not address this new reuse. Which prior assumption no longer holds?
Preparing for AIGP? Take the free 5-min readiness quiz →
- The absence of clinical advice removes privacy-role analysis.Nonclinical routing still involves personal-data processing, and the vendor’s independent purpose requires role analysis under the stated GDPR facts.
- The vendor’s technical operation determines the GDPR role.Technical operation alone does not determine roles; purposes and means, including the vendor’s independent reuse, matter under the stated GDPR scope.
- The hospital’s routing purpose remains documented.The hospital’s routing purpose may remain documented, but that does not resolve the vendor’s separate purpose for reuse.
- The vendor processes data only on the hospital’s behalf. ✓Independent reuse for the vendor’s general model purpose contradicts the assumption that processing occurs solely on the hospital’s behalf.
The trap
Compare actual purposes with contract labels; a supplier’s own purpose may alter the role analysis. How to remember it
The vendor’s new independent model-improvement purpose conflicts with processor-only treatment for the hospital’s routing purpose.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How to Govern AI Deployment and Use questions
- Combine vendor evidence with a local pilot and documented: Which approach is most defensible? →
- A breach-only clause covers material model incidents: Which prior assumption no longer holds? →
- The vendor acts solely for the company’s documented: Which prior assumption no longer holds? →
- All 424 Understanding How to Govern AI Deployment and Use questions →
Part of the Certsqill AIGP question bank · Understanding How to Govern AI Deployment and Use ·
Every answer, right and wrong, comes with its own explanation.