Data minimization and privacy by design: Which data-protection principles do these two choices reflect?
Collecting only necessary data reflects data minimization; embedding safeguards from the start reflects privacy by design.
The question
A team designing an AI recruitment tool reduces privacy risk by collecting only the applicant data actually needed for the model and by building safeguards into the system from the outset. Which data-protection principles do these two choices reflect?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Data minimization and privacy by design, limiting the data collected and embedding safeguards from the very outset. ✓Correct: collecting only necessary data is minimization, and building in safeguards is privacy by design.
- Data portability and the right to erasure, letting applicants move and later delete their submitted personal data records.Plausible but wrong: these are data-subject rights, not the design principles described.
- Breach notification and record keeping, obliging the team to report and to log any incident affecting the applicant data.Plausible but wrong: these are accountability duties, not the minimization/by-design choices described.
- Cross-border transfer control, ensuring the applicant data leaves the country only under an approved legal mechanism used.Wrong: transfer controls govern data movement, not collecting less data or embedding safeguards.
The trap
Confusing proactive design principles with reactive data-subject rights or transfer rules. How to remember it
Collecting only necessary data reflects data minimization; embedding safeguards from the start reflects privacy by design.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How Laws, Standards and Frameworks Apply to AI questions
- Purpose limitation: Under data-protection law, which principle most directly challenges this secondary use? →
- Conducting a data protection impact assessment: Under GDPR, which obligation is most directly triggered before →
- A valid Article 9 condition: Because fingerprints used to identify people are special-category data, what must →
- All 394 Understanding How Laws, Standards and Frameworks Apply to AI questions →
Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI ·
Every answer, right and wrong, comes with its own explanation.