Collect only the personal data that is adequate: Which practice | AIGP
7-day money-back guarantee — full refund within 7 days of purchase if you've completed under 20% of the questions. See pricing →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

Language

✓ EnglishDeutschEspañolFrançaisPortuguês
Check readiness — free →

Collect only the personal data that is adequate: Which practice best reflects the data minimization and

AIGP Understanding How Laws, Standards and Frameworks Apply to AI Easy

Data minimization and privacy by design require collecting only data that is adequate, relevant and limited to the stated purpose, designed in from the start.

The question

A team is scoping a new AI model and wants to align its data collection with privacy law from the outset. Which practice best reflects the data minimization and privacy-by-design expectations that apply when personal data is used to train AI?

Preparing for AIGP? Take the free 5-min readiness quiz →

  1. Gather the widest possible dataset first and later delete any fields that the model proves it did not need during tuning.
    Plausible because more data often helps accuracy, but collecting beyond need first inverts minimization, which restricts collection up front.
  2. Collect only the personal data that is adequate, relevant and limited to what the model's stated purpose actually requires.
    Correct: data minimization means limiting collection to what is necessary for the defined purpose, and building that limit in by design and by default.
  3. Retain all collected personal data indefinitely so the model can be retrained on the full history whenever its accuracy drifts.
    Plausible for retraining convenience, but indefinite retention conflicts with storage limitation and minimization principles.
  4. Rely on encrypting the training data at rest as the principal means of satisfying minimization and privacy-by-design duties.
    Plausible since encryption is a real safeguard, but it is a security measure and does not reduce how much data is collected or held.
The trap
Believing that encrypting or securing personal data satisfies data minimization, when minimization is about limiting collection and retention.

How to remember it

Data minimization and privacy by design require collecting only data that is adequate, relevant and limited to the stated purpose, designed in from the start.

How many of these would you get right?

One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.

Test your AIGP readiness — free

More Understanding How Laws, Standards and Frameworks Apply to AI questions

Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI · Every answer, right and wrong, comes with its own explanation.