Map each processing purpose to its GDPR role: What is the most direct missing control?
Separate purposes must be mapped because GDPR roles follow actual decision-making, not the vendor’s label.
The question
Under the EU GDPR, a university selects an AI vendor to rank applicants. The university determines the ranking purpose, while the vendor also analyzes applicant logs for its own product analytics. Lawful basis, transparency, security, and rights processes are otherwise complete. What is the most direct missing control?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Map each processing purpose to its GDPR role ✓The university’s ranking may involve a processor relationship, while the vendor’s own analytics may make it a controller for that activity; the purposes must be separated and assigned accordingly.
- Accept the vendor’s processor label for every processing activityA supplier label cannot override the actual purposes the vendor independently determines for its analytics activity.
- Require the vendor to stop all applicant-log analyticsStopping analytics may change the facts, but the organization must still classify and govern the remaining ranking processing correctly.
- Add ranking-service processor clauses to the contractProcessor clauses may address ranking on the university’s behalf, but they do not classify or govern the vendor’s separate analytics purpose.
The trap
Split the processing into activities and ask who determines the purpose and essential means of each. How to remember it
Separate purposes must be mapped because GDPR roles follow actual decision-making, not the vendor’s label.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How Laws, Standards and Frameworks Apply to AI questions
- Treat the coded records as personal data: Which control most directly reflects the correct classification? →
- Execute an Article 28-compliant processor arrangement: Which missing control is most direct? →
- Complete and document a GDPR Article 35 DPIA first: Which missing control is required before processing when →
- All 394 Understanding How Laws, Standards and Frameworks Apply to AI questions →
Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI ·
Every answer, right and wrong, comes with its own explanation.