Treat the coded records as personal data: Which control most directly reflects the correct classification?
Pseudonymization separates identifiers but preserves possible reidentification; anonymization requires a genuinely irreversible loss of identifiability.
The question
Under the GDPR in the European Union, a customer-service system replaces names with customer codes, while the company retains a separate lookup table. All other privacy prerequisites are satisfied. Which control most directly reflects the correct classification?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Treat the coded records as personal data. ✓Because the organization retains reidentification information, pseudonymized records remain personal data under GDPR analysis.
- Declare the records anonymous after removing direct identifiers.Removing names alone does not establish anonymization when a separate lookup table can reconnect records to individuals.
- Apply retention controls only if the lookup table remains accessible.Personal-data status does not depend solely on current lookup access; pseudonymized information remains within privacy governance.
- Publish the codes because they no longer identify customers directly.Indirect identifiability still matters; publishing coded records can disclose personal data despite removing direct identifiers.
The trap
Look for retained keys, linkage data, or realistic reidentification paths before treating records as anonymous. How to remember it
Pseudonymization separates identifiers but preserves possible reidentification; anonymization requires a genuinely irreversible loss of identifiability.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How Laws, Standards and Frameworks Apply to AI questions
- Define only necessary fields: Before collection, which missing control most directly implements data →
- Map each processing purpose to its GDPR role: What is the most direct missing control? →
- Execute an Article 28-compliant processor arrangement: Which missing control is most direct? →
- All 394 Understanding How Laws, Standards and Frameworks Apply to AI questions →
Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI ·
Every answer, right and wrong, comes with its own explanation.