GDPR Compliance for AI Systems: Complete Guide | QuizBy Eyal Doron / December 6, 2025 / 1 minute of reading GDPR Compliance for AI Systems: Complete Guide | Quiz 1 / 7 1. Which phase of the AI lifecycle requires conducting Data Protection Impact Assessments for high-risk processing? 1. Phase 4 – Ongoing Operations 2. Phase 1 – Training Data 3. Phase 3 – Deployment 4. Phase 2 – Model Development Correct! WHY: DPIAs must be conducted before model training begins when processing involves high-risk activities – which most AI on personal data qualifies as. CONTEXT: Phase 1 training data is where lawful basis must be documented and risk assessments completed. REMEMBER: Assess risks before you train. 2 / 7 2. When does GDPR apply to a US company with no EU offices? 1. Only when they have a data processing agreement with an EU company 2. Never – GDPR only applies to EU-based companies 3. When they process personal data of EU residents 4. Only when they have servers physically located in the EU Correct! WHY: GDPRs territorial scope extends to any organization processing data of EU residents regardless of where the company is located. CONTEXT: A US company training models on European customer data must comply with GDPR even without physical EU presence. REMEMBER: Processing EU data triggers GDPR – not your location. 3 / 7 3. Which of the following is a valid approach to machine unlearning when an erasure request arrives? 1. Simply deleting the users record from the database 2. Full retraining without deleted data – machine unlearning techniques – or influence function approximations 3. Informing the user that erasure is not technically possible 4. Waiting for automated model decay to remove the data influence Correct! WHY: Full retraining without the deleted data is effective but expensive – machine unlearning techniques approximate removal – and influence functions estimate contribution for removal. CONTEXT: All approaches have tradeoffs – organizations must decide their methodology before requests arrive. REMEMBER: Plan your unlearning approach before you need it. 4 / 7 4. A financial services company uses AI to automatically approve or deny loan applications. Which GDPR article most likely applies? 1. Article 22 – Automated Decision-Making 2. Article 17 – Right to Erasure 3. Article 25 – Privacy by Design 4. Article 5 – Data Processing Principles Correct! WHY: Article 22 restricts solely automated decisions with legal or significant effects – and loan decisions clearly have significant financial and legal effects on individuals. CONTEXT: Credit decisions are explicitly mentioned in GDPR guidance as triggering Article 22 protections. REMEMBER: High-stakes decisions need human oversight options. 5 / 7 5. What does meaningful information about the logic involved require under GDPR transparency obligations? 1. Understandable explanations of how decisions are made and what factors matter 2. A statement that AI was involved in the decision 3. Providing complete source code and model architecture 4. Technical documentation of the neural network structure Correct! WHY: Meaningful information means providing understandable explanations of how AI decisions are made and what factors matter – not technical implementation details. CONTEXT: A loan applicant needs to understand why they were rejected – not review model architecture or source code. REMEMBER: Explain the why – not the how of the code. 6 / 7 6. Why is the right to erasure particularly challenging for AI systems? 1. Personal data becomes embedded in model weights making extraction technically difficult 2. AI systems automatically comply with erasure requests through built-in features 3. Erasure only requires removing data from the training dataset 4. GDPR exempts AI models from erasure requirements Correct! WHY: Once personal data is mixed into model training – extracting one persons contribution is technically difficult – often requiring full model retraining. CONTEXT: This is called the blended smoothie problem – data becomes embedded in model weights rather than stored in deletable records. REMEMBER: Deleting from database does not equal deleting from model. 7 / 7 7. What does GDPR define as personal data in the context of AI systems? 1. Any information relating to an identified or identifiable person including behavioral patterns and inferences 2. Data that has been anonymized through any method 3. Technical data like IP addresses but not behavioral patterns 4. Only names and email addresses stored in databases Correct! WHY: GDPR defines personal data broadly to include any information relating to an identifiable person – including behavioral patterns and inferred traits. CONTEXT: This broad definition means AI systems that make inferences about individuals are likely processing personal data even without obvious identifiers. REMEMBER: If AI can identify or make inferences about someone – it is personal data. Your score isThe average score is 0% Restart quiz Download PDF Please leave this field empty๐ The AI Security Manager's Newsletter Weekly insights on AI risk management, EU AI Act compliance, and practical security strategies. We donโt spam! Read our privacy policy for more info. Thank you! Please check your inbox to confirm your subscription.