Data minimization and privacy by design: Which data-protection concept does this approach most directly implem
Limiting collected fields and embedding protective defaults from the start exemplifies data minimization and privacy by design.
The question
During early design of an AI feature, a team decides to train on aggregated and pseudonymized data, collecting only the fields shown to improve accuracy, and bakes these defaults into the pipeline. Which data-protection concept does this approach most directly implement?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Automated decision-making safeguards, because pseudonymizing the training data gives each affected individual the right to obtain human intervention in the model's later outputs.Almost plausible but human-intervention rights concern solely-automated decisions, not the upfront design choice to minimize and pseudonymize training data.
- Cross-border transfer safeguards, because aggregating the data before training is the mechanism that legitimizes sending the resulting model to processors in other jurisdictions.Plausible-sounding but aggregation is not a transfer mechanism, and the design choice described is about minimization, not international transfers.
- Breach notification readiness, because pseudonymization is primarily a way to shorten the deadline for reporting incidents to the supervisory authority.Plausible but pseudonymization here serves upfront minimization and design, not as a tool whose main purpose is easing post-incident reporting timelines.
- Data minimization and privacy by design, because the team limits collection to what is necessary and embeds protective defaults into the system architecture from the outset. ✓Correct: restricting fields to what is necessary and building protections into the design from the start is exactly data minimization coupled with privacy by design and by default.
The trap
Reframing upfront data minimization as automated-decision or breach-response tooling. How to remember it
Limiting collected fields and embedding protective defaults from the start exemplifies data minimization and privacy by design.
How many of these would you get right?
One of 499 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How Laws, Standards and Frameworks Apply to AI questions
- The vendor is the provider responsible for conformity: Under the EU AI Act, how are the roles and their core d →
- Substantiate or drop the lowest-price claim: Under consumer protection law, which governance step is most defe →
- Establish a risk-management system and maintain technical: Under the EU AI Act, which requirement is a core ob →
- All 125 Understanding How Laws, Standards and Frameworks Apply to AI questions →
Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI ·
Every answer, right and wrong, comes with its own explanation.