GDPR Compliance for AI Systems: Complete Guide | QuizBy Eyal Doron / December 6, 2025 / 1 minute of reading GDPR Compliance for AI Systems: Complete Guide | Quiz 1 / 7 1. Why does web scraping public data not eliminate GDPR obligations? 1. Public data automatically becomes anonymized data 2. Public availability does not establish lawful basis for processing personal data 3. Only commercial scraping requires GDPR compliance 4. Web scraping is exempt from GDPR under the research exception Correct! WHY: Public availability does not mean unrestricted use – GDPR still requires lawful basis for processing personal data regardless of how it was obtained. CONTEXT: The Clearview AI enforcement cases demonstrate that scraping publicly available images still violated GDPR. REMEMBER: Public does not mean free to use. 2 / 7 2. Which phase of the AI lifecycle requires conducting Data Protection Impact Assessments for high-risk processing? 1. Phase 2 – Model Development 2. Phase 3 – Deployment 3. Phase 1 – Training Data 4. Phase 4 – Ongoing Operations Correct! WHY: DPIAs must be conducted before model training begins when processing involves high-risk activities – which most AI on personal data qualifies as. CONTEXT: Phase 1 training data is where lawful basis must be documented and risk assessments completed. REMEMBER: Assess risks before you train. 3 / 7 3. Which of the following is a valid approach to machine unlearning when an erasure request arrives? 1. Full retraining without deleted data – machine unlearning techniques – or influence function approximations 2. Waiting for automated model decay to remove the data influence 3. Informing the user that erasure is not technically possible 4. Simply deleting the users record from the database Correct! WHY: Full retraining without the deleted data is effective but expensive – machine unlearning techniques approximate removal – and influence functions estimate contribution for removal. CONTEXT: All approaches have tradeoffs – organizations must decide their methodology before requests arrive. REMEMBER: Plan your unlearning approach before you need it. 4 / 7 4. Your AI model has been shown to reproduce verbatim text from training data. Which GDPR challenge does this represent? 1. Model memorization creating privacy leakage risks 2. Automated decision-making restriction 3. Data minimization failure 4. Purpose limitation violation Correct! WHY: Model memorization occurs when AI models store and can reproduce specific training examples – creating privacy leakage risks. CONTEXT: Large language models and image models have been demonstrated to reproduce training data – violating confidentiality even after source data is deleted. REMEMBER: Models can memorize and leak training data. 5 / 7 5. What does meaningful information about the logic involved require under GDPR transparency obligations? 1. Technical documentation of the neural network structure 2. A statement that AI was involved in the decision 3. Understandable explanations of how decisions are made and what factors matter 4. Providing complete source code and model architecture Correct! WHY: Meaningful information means providing understandable explanations of how AI decisions are made and what factors matter – not technical implementation details. CONTEXT: A loan applicant needs to understand why they were rejected – not review model architecture or source code. REMEMBER: Explain the why – not the how of the code. 6 / 7 6. Why is the right to erasure particularly challenging for AI systems? 1. GDPR exempts AI models from erasure requirements 2. AI systems automatically comply with erasure requests through built-in features 3. Personal data becomes embedded in model weights making extraction technically difficult 4. Erasure only requires removing data from the training dataset Correct! WHY: Once personal data is mixed into model training – extracting one persons contribution is technically difficult – often requiring full model retraining. CONTEXT: This is called the blended smoothie problem – data becomes embedded in model weights rather than stored in deletable records. REMEMBER: Deleting from database does not equal deleting from model. 7 / 7 7. What rights do individuals have under GDPR Article 22 when subject to solely automated decisions with legal or significant effects? 1. Right to automatic compensation if the decision is wrong 2. Only the right to be informed that AI made the decision 3. Right to human intervention – right to contest – and right to explanation 4. Right to see the source code of the algorithm Correct! WHY: Article 22 grants individuals the right to human intervention – the ability to contest decisions – and meaningful explanations of the decision logic. CONTEXT: These protections apply to consequential automated decisions like credit scoring – hiring decisions – and insurance pricing. REMEMBER: Human oversight is mandatory for high-stakes AI decisions. Your score isThe average score is 0% Restart quiz Download PDF Please leave this field empty๐ The AI Security Manager's Newsletter Weekly insights on AI risk management, EU AI Act compliance, and practical security strategies. We donโt spam! Read our privacy policy for more info. Thank you! Please check your inbox to confirm your subscription.