Use pseudonymization with separately protected: Which approach best satisfies both constraints?
Pseudonymization preserves controlled reidentification for rights and corrections while limiting the vendor’s access to applicant identities.
The question
Under the GDPR in the European Union, a housing administrator must correct applicant records later and provide the vendor only data needed for current administration. The administrator can retain a separately protected reidentification key, but the vendor cannot receive it. Which approach best satisfies both constraints?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Use pseudonymization with separately protected reidentification controls. ✓Pseudonymization supports operational separation while preserving controlled reidentification for correction, rights handling, and accountable administration under GDPR requirements.
- Anonymize records before every administrative processing activity.Anonymization would impede required correction and rights handling when the administrator must connect records back to applicants.
- Remove names but retain unrestricted identifying attributes for vendors.Removing direct identifiers does not anonymize data when remaining attributes can support reidentification or expose excessive personal information.
- Encrypt identifiable records while giving vendors the decryption key.Encryption protects confidentiality but leaves vendors able to access identifiable data, failing the specified separation and minimization constraint.
The trap
Ask whether authorized reidentification remains necessary; if so, anonymization is not the fitting approach. How to remember it
Pseudonymization preserves controlled reidentification for rights and corrections while limiting the vendor’s access to applicant identities.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How Laws, Standards and Frameworks Apply to AI questions
- Collect only fields necessary for itinerary assistance: Which approach satisfies data minimization? →
- Controller processing for the supplier’s independent reuse: How should the supplier’s reuse be characterized? →
- An Article 28 processor agreement: Which contract feature is decisive? →
- All 394 Understanding How Laws, Standards and Frameworks Apply to AI questions →
Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI ·
Every answer, right and wrong, comes with its own explanation.