Data minimization: Under GDPR, which requirement most directly challenges this plan?
Ingesting attributes with no predictive value conflicts with data minimization, which permits only necessary personal data.
The question
A data science team plans to ingest every available customer field into a churn-prediction model, including many attributes with no demonstrated predictive value. Under GDPR, which requirement most directly challenges this plan?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Data minimization, limiting processing to personal data that is adequate, relevant and necessary for the aim ✓Correct: pulling in unnecessary attributes conflicts with the data-minimization requirement.
- Purpose limitation, requiring that personal data be collected for specified, explicit and legitimate purposesPlausible, but the issue is the volume of unnecessary fields, not whether the churn purpose is legitimate.
- Lawfulness, requiring that each processing activity rest on a valid legal basis such as consent or contractImportant, but a valid legal basis does not by itself justify collecting fields that are not necessary.
- Transparency, requiring that data subjects be clearly informed about how their personal data is processedA genuine duty, yet informing people does not cure the collection of data beyond what is needed.
The trap
Believing that a valid legal basis or a clear notice authorizes collecting more data than is necessary. How to remember it
Ingesting attributes with no predictive value conflicts with data minimization, which permits only necessary personal data.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How Laws, Standards and Frameworks Apply to AI questions
- Purpose limitation: Under GDPR, which principle most directly governs whether this new use is permitted? →
- Carrying out a data protection impact assessment before: Before deployment, which GDPR controller obligation →
- The facial data is a special category: Under GDPR, why does this processing face a stricter standard than →
- All 394 Understanding How Laws, Standards and Frameworks Apply to AI questions →
Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI ·
Every answer, right and wrong, comes with its own explanation.