GDPR Compliance for AI Systems: Complete Guide | QuizBy Eyal Doron / December 6, 2025 / 1 minute of reading GDPR Compliance for AI Systems: Complete Guide | Quiz 1 / 7 1. Why does web scraping public data not eliminate GDPR obligations? 1. Public availability does not establish lawful basis for processing personal data 2. Public data automatically becomes anonymized data 3. Only commercial scraping requires GDPR compliance 4. Web scraping is exempt from GDPR under the research exception Correct! WHY: Public availability does not mean unrestricted use – GDPR still requires lawful basis for processing personal data regardless of how it was obtained. CONTEXT: The Clearview AI enforcement cases demonstrate that scraping publicly available images still violated GDPR. REMEMBER: Public does not mean free to use. 2 / 7 2. Which phase of the AI lifecycle requires conducting Data Protection Impact Assessments for high-risk processing? 1. Phase 3 – Deployment 2. Phase 1 – Training Data 3. Phase 4 – Ongoing Operations 4. Phase 2 – Model Development Correct! WHY: DPIAs must be conducted before model training begins when processing involves high-risk activities – which most AI on personal data qualifies as. CONTEXT: Phase 1 training data is where lawful basis must be documented and risk assessments completed. REMEMBER: Assess risks before you train. 3 / 7 3. Which of the following is a valid approach to machine unlearning when an erasure request arrives? 1. Waiting for automated model decay to remove the data influence 2. Informing the user that erasure is not technically possible 3. Full retraining without deleted data – machine unlearning techniques – or influence function approximations 4. Simply deleting the users record from the database Correct! WHY: Full retraining without the deleted data is effective but expensive – machine unlearning techniques approximate removal – and influence functions estimate contribution for removal. CONTEXT: All approaches have tradeoffs – organizations must decide their methodology before requests arrive. REMEMBER: Plan your unlearning approach before you need it. 4 / 7 4. What percentage of significant GDPR fines stem from inadequate documentation according to enforcement analysis? 1. 92 percent 2. 78 percent 3. 67 percent 4. 45 percent Correct! WHY: Analysis of GDPR enforcement actions shows that 92 percent of significant fines stem from inadequate documentation – making audit trails the primary defense. CONTEXT: Documentation requirements span training data sources – processing activities – model decisions – and compliance procedures. REMEMBER: Document everything – your records are your defense. 5 / 7 5. Why is the right to erasure particularly challenging for AI systems? 1. GDPR exempts AI models from erasure requirements 2. AI systems automatically comply with erasure requests through built-in features 3. Personal data becomes embedded in model weights making extraction technically difficult 4. Erasure only requires removing data from the training dataset Correct! WHY: Once personal data is mixed into model training – extracting one persons contribution is technically difficult – often requiring full model retraining. CONTEXT: This is called the blended smoothie problem – data becomes embedded in model weights rather than stored in deletable records. REMEMBER: Deleting from database does not equal deleting from model. 6 / 7 6. Under GDPR Article 5 – what does the purpose limitation principle require for AI training data? 1. Training data is exempt from purpose limitation if anonymized 2. Data collected for one purpose cannot be repurposed for AI training without additional justification 3. Any data can be used for training as long as it improves the model 4. Purpose limitation only applies to data stored longer than 30 days Correct! WHY: Purpose limitation means data collected for one purpose cannot be repurposed for AI training without additional legal justification. CONTEXT: Customer data collected for service delivery does not automatically authorize using that data to train machine learning models. REMEMBER: Original consent does not equal training consent. 7 / 7 7. What does GDPR define as personal data in the context of AI systems? 1. Only names and email addresses stored in databases 2. Technical data like IP addresses but not behavioral patterns 3. Any information relating to an identified or identifiable person including behavioral patterns and inferences 4. Data that has been anonymized through any method Correct! WHY: GDPR defines personal data broadly to include any information relating to an identifiable person – including behavioral patterns and inferred traits. CONTEXT: This broad definition means AI systems that make inferences about individuals are likely processing personal data even without obvious identifiers. REMEMBER: If AI can identify or make inferences about someone – it is personal data. Your score isThe average score is 0% Restart quiz Download PDF Please leave this field empty๐ The AI Security Manager's Newsletter Weekly insights on AI risk management, EU AI Act compliance, and practical security strategies. We donโt spam! Read our privacy policy for more info. Thank you! Please check your inbox to confirm your subscription.