Collect only data necessary for the recommendation purpose: Which distinction is decisive before collection?
The stated objective needs limited fields, so collection should exclude biographies, addresses, and unrelated social histories.
The question
A media company subject to the EU GDPR wants to collect full employee biographies, home addresses, and private social-media histories to personalize internal video recommendations. The recommendation objective only requires role, department, and viewing history. Which distinction is decisive before collection?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Collect all available profiles, then encrypt the recommendation datasetEncryption supports security but does not cure excessive collection unrelated to the specified recommendation purpose.
- Collect only data necessary for the recommendation purpose ✓Data minimization requires limiting collection to information necessary and relevant for the stated personalization objective.
- Collect biographies first, then remove addresses during deploymentRemoving unnecessary fields later does not justify collecting excessive personal data initially under the minimization principle.
- Collect complete histories because broader data improves personalizationMore data need not improve fitness and cannot override purpose-based necessity and minimization requirements.
The trap
Identify the minimum fields needed for the stated purpose before considering security or model performance. How to remember it
The stated objective needs limited fields, so collection should exclude biographies, addresses, and unrelated social histories.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How Laws, Standards and Frameworks Apply to AI questions
- A non-consent basis must still satisfy GDPR conditions: What is the decisive distinction? →
- Pseudonymized personal data: How should the records be classified for GDPR purposes? →
- The authority is controller and provider processor under: Which role allocation follows actual purposes and →
- All 394 Understanding How Laws, Standards and Frameworks Apply to AI questions →
Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI ·
Every answer, right and wrong, comes with its own explanation.