IAPP AIGP Exam Prep
Artificial Intelligence Governance Professional (Page 7 )

Updated On: 10-Sep-2026

According to the GDPR’s transparency principle, when an AI system processes personal data in automated decision-making, controllers are required to provide data subjects specific information on?

  1. The existence of automated decision-making and meaningful information on its logic and consequences.
  2. The personal data used during processing, including inferences drawn by the AI system about the data.
  3. The data protection impact assessments carried out on the AI system and legal bases for processing.
  4. The contact details of the data protection officer and the data protection national authority.

Answer(s): A

Explanation:

The correct answer, A, directly aligns with the GDPR's emphasis on transparency in automated decision-making involving personal data. The GDPR's Article 13 and 14 require controllers to inform data subjects when their personal data is processed using automated means. Crucially, the "meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject" (Recital 71) is paramount. This empowers data subjects to understand how decisions impacting them are being made and to potentially exercise their rights, such as the right to obtain human intervention or to challenge the decision.
Option B is partially correct, as data subjects have the right to access their personal data. However, the GDPR's focus in the context of automated decision-making is less about all data used and more about understanding the logic of the AI system. Option C involves aspects of compliance but doesn't directly address the core transparency requirement of explaining the decision-making process to the data subject.
While DPIAs and legal bases are relevant to processing, they are not the primary information data subjects need to understand the how and why of automated decisions. Option D is also important for data protection compliance, but it focuses on who to contact for issues, not the decision-making logic itself.
In essence, the GDPR mandates demystifying automated decision-making so that individuals can grasp how AI is affecting them. This is achieved through clear explanations of the automated processes at play. The provision of this "meaningful information" enables data subjects to exercise their rights and fosters trust in AI systems processing their data.
Authoritative links for further research:
GDPR Article 13 and 14 (Information to be provided where personal data are collected): https://gdpr-info.eu/art-13-gdpr/ , https://gdpr-info.eu/art-14-gdpr/ GDPR Recital 71 (Automated individual decision-making): https://gdpr-info.eu/recitals/no-71/
Article 29 Working Party Guidelines on Automated decision-making and Profiling: (Although this is superseded, it still provides valuable insight): https://ec.europa.eu/newsroom/article29/items/612053



A company subject to GDPR is building its governance framework for how it will collect data to be used for training of AI models. The most important thing the company can do to ensure GDPR compliance is:

  1. Include the requirement to fully anonymize data used to train its models.
  2. Establish a data retention schedule for data used to train its models.
  3. Source training data from a reputable company to train its models.
  4. Minimize the amount of data used to train its models.

Answer(s): D

Explanation:

The correct answer is D. Minimize the amount of data used to train its models.
Under GDPR, data minimization is a core principle, stating that personal data should be adequate, relevant, and limited to what is necessary for the purposes for which they are processed.
When training AI models, collecting vast amounts of data without carefully considering its necessity can lead to compliance breaches. More data increases the risk of infringing individuals' rights and requires greater resources for data protection, storage, and security.
Option A, while beneficial, is difficult to guarantee in practice. Complete anonymization is often challenging to achieve, and even anonymized data can sometimes be re-identified. It also might hinder the model's performance, as some useful information is lost.
Option B, establishing a data retention schedule, is important but not the most important.
While a retention schedule addresses data storage duration, it doesn't inherently ensure that only necessary data is collected in the first place.
Option C, sourcing training data from a reputable company, is insufficient on its own. The company building the AI model remains responsible for ensuring GDPR compliance regardless of the data source. Due diligence is crucial, but the data still needs to adhere to GDPR principles, and the company building the model must be able to demonstrate compliance. Minimizing the data collected in the first place reduces the risk irrespective of the data source's reputation.
Therefore, adhering to the principle of data minimization is the cornerstone of GDPR compliance when collecting data for AI model training. Limiting the data to what's genuinely necessary for the specific purpose is the most impactful action the company can take.
Further research:
GDPR Article 5(1)(c) - Data Minimization: https://gdpr-info.eu/art-5-gdpr/ Information Commissioner's Office (ICO) - Data Minimisation: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/principles/data-minimisation/



Under the EU AI Act, which of the following compliance actions applies only to General Purpose AI models with systemic risk?

  1. Publishing a detailed summary of the data used to train the model.
  2. Maintaining up-to-date technical documentation, including testing details.
  3. Implementing an intellectual property policy to comply with EU copyright laws.
  4. Making information available to downstream providers who integrate the model into their AI systems.

Answer(s): A

Explanation:

The correct answer is A: Publishing a detailed summary of the data used to train the model. This requirement specifically targets General Purpose AI (GPAI) models with systemic risk under the EU AI Act due to the inherent potential for these models to impact various downstream applications and society at large. Understanding the training data characteristics is crucial for assessing biases, limitations, and potential harms stemming from the model's foundations.
While options B, C, and D are also compliance actions within the EU AI Act, they are not exclusive to GPAI models with systemic risk. Maintaining technical documentation (B) is a fundamental requirement for many AI systems to ensure transparency and accountability. Intellectual property compliance (C), particularly concerning EU copyright laws, is a broader obligation applicable across different types of AI models, particularly those trained on copyrighted material. Providing information to downstream providers (D) is important for enabling responsible integration of AI models into various applications, irrespective of whether the upstream model is deemed systemically risky.
The EU AI Act is tiered, with obligations scaling based on the risk level of the AI system. GPAI models with systemic risk, due to their potential for widespread impact, face the strictest scrutiny and associated obligations. Publishing data summaries provides regulators, downstream providers, and the public with the means to evaluate the model's potential impact. Such transparency facilitates identification of potential harms and proactive mitigation measures. This data summary helps understand data provenance, volume, and the possible biases ingrained in the model. This contrasts with other obligations, which are more generally applicable to ensure safety, legal compliance, and responsible use of AI, but not specifically aimed at mitigating the higher risks posed by GPAI models deemed systemic. Think of the model's data as its foundation; understanding that foundation is key to understanding potential structural problems, particularly for high-impact constructions.
Authoritative Links:
EU AI Act - Full Text: This will be available once the legislation is finalized, but searching the European Parliament or Commission websites for "EU AI Act" will lead to the most current drafts and official documentation. European Commission - Artificial Intelligence: https://digital-strategy.ec.europa.eu/en/policies/artificial-intelligence (Provides overview of the EU AI strategy and related regulations)



Which of the following situations would be least likely to raise concerns under existing consumer protection laws?

  1. An AI algorithm being used in a credit decision making process by a financial institution.
  2. An AI customer service system claiming that it is as accurate as a human support agent.
  3. An AI tool using scraped digital content to generate news summaries on a publishing website.
  4. An online platform offering recommendations to its users by displaying user specific content and targeted advertisements.

Answer(s): D

Explanation:

The answer, D (An online platform offering recommendations to its users by displaying user-specific content and targeted advertisements), is the least likely to raise immediate concerns under existing consumer protection laws compared to the other options. Here's why:
Consumer protection laws generally focus on deceptive practices, unfair terms, discrimination, and data privacy. Option A, involving AI in credit decisions, is highly scrutinized due to potential for discriminatory outcomes based on protected characteristics like race or gender, violating fair lending laws. Financial institutions are heavily regulated regarding transparency and fairness in lending.
Option B, an AI customer service system claiming human-level accuracy, raises concerns about false advertising and misleading claims. If the AI's performance doesn't match the claim, it constitutes deception, violating advertising standards and consumer rights.
Option C, an AI using scraped digital content to generate news summaries, faces potential copyright infringement and plagiarism issues. Unauthorized use of copyrighted material without proper attribution or licensing is a legal violation.
Option D, offering personalized recommendations, is a common practice in online platforms.
While data privacy concerns exist regarding how these recommendations are generated, the core functionality itself is usually governed by privacy policies and terms of service, which users typically agree to. This activity, while raising transparency concerns, doesn't automatically trigger consumer protection violations unless the recommendations are harmful, misleading, or discriminatory. The use of algorithms to suggest content and ads is a fundamental part of how online platforms operate, as long as users are informed (through privacy policies, for example) that their data is being used to personalize their experience. Personalization is less likely to raise immediate concerns than direct harm or deception like discrimination or false advertising. Cloud computing facilitates this process through data analytics and machine learning tools that enable personalization at scale, but the legality comes down to compliance with data privacy and consumer protection laws.
Here are some links for more information:
FTC Consumer Protection: https://www.ftc.gov/about-ftc/bureaus-offices/bureau-consumer-protection CFPB (Consumer Financial Protection Bureau): https://www.consumerfinance.gov/ Copyright Law: https://www.copyright.gov/



What is the primary reason the EU is considering updates to its Product Liability Directive?

  1. To increase the minimum warranty level for defective goods.
  2. To define new liability exemptions for defective products.
  3. To address digital services and connected products.
  4. To address free and open-source software.

Answer(s): C

Explanation:

The EU's proposed revisions to the Product Liability Directive (PLD) are primarily driven by the increasing prevalence of digital services and connected products, encompassing IoT devices, AI systems, and other software-dependent technologies. Existing product liability frameworks, originally designed for tangible goods, struggle to address the unique risks posed by these digitally-integrated products. The complexity of software updates, AI algorithms, and cybersecurity vulnerabilities introduces new challenges in determining liability when harm occurs. For instance, a self-driving car accident attributed to a faulty AI algorithm raises questions about who is responsible – the manufacturer, the software developer, or the AI system itself?
The updates aim to clarify liability rules for software-driven products, particularly where AI is involved, by considering aspects like data dependence, cybersecurity risks, and the potential for remote updates causing harm. They seek to establish clear pathways for victims to seek redress when these products malfunction or cause damage. The existing PLD focuses on tangible products and does not adequately capture the nuances of digital products and their constant evolution through software updates, making it difficult to apply traditional liability concepts. The EU recognizes the need to adapt the legislation to reflect the current technological landscape and ensure consumer protection in the age of connected devices and AI-powered systems. This involves modernizing definitions of "product" and "defect" to encompass software and digital services, and considering factors beyond physical defects. The goal is to foster innovation in these technologies while upholding safety standards and accountability for harm caused by defective products incorporating digital elements.
Addressing free and open-source software, increasing minimum warranty levels, or defining new liability exemptions are not the primary, overarching drivers of this specific update to the PLD. While these aspects might be considered in broader discussions about product safety and consumer protection, the core impetus for revising the PLD is the rise of digital services and connected products.
Authoritative Links:
European Commission - Product Liability Directive: https://single-market-economy.ec.europa.eu/single-market/goods/liability-and-safety-rules/liability-new-technologies/product-liability-directive_en European Parliament - MEPs want clearer liability rules for AI-driven damage: https://www.europarl.europa.eu/news/en/press-room/20201016IPR89563/meps-want-clearer-liability-rules-for-ai-driven-damage



Viewing page 7 of 46
Viewing questions 31 - 35 out of 222 questions


Post your Comments and Discuss IAPP AIGP exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!