GDPR Compliance for AI Systems: Complete Guide | QuizBy Eyal Doron / December 6, 2025 / 1 minute of reading GDPR Compliance for AI Systems: Complete Guide | Quiz 1 / 7 1. Why does web scraping public data not eliminate GDPR obligations? 1. Web scraping is exempt from GDPR under the research exception 2. Public availability does not establish lawful basis for processing personal data 3. Only commercial scraping requires GDPR compliance 4. Public data automatically becomes anonymized data Correct! WHY: Public availability does not mean unrestricted use – GDPR still requires lawful basis for processing personal data regardless of how it was obtained. CONTEXT: The Clearview AI enforcement cases demonstrate that scraping publicly available images still violated GDPR. REMEMBER: Public does not mean free to use. 2 / 7 2. Which phase of the AI lifecycle requires conducting Data Protection Impact Assessments for high-risk processing? 1. Phase 4 – Ongoing Operations 2. Phase 1 – Training Data 3. Phase 2 – Model Development 4. Phase 3 – Deployment Correct! WHY: DPIAs must be conducted before model training begins when processing involves high-risk activities – which most AI on personal data qualifies as. CONTEXT: Phase 1 training data is where lawful basis must be documented and risk assessments completed. REMEMBER: Assess risks before you train. 3 / 7 3. What is the best approach when your organization claims their AI model is too complex to explain under GDPR? 1. Implement explainability techniques or use more interpretable models for high-stakes decisions 2. Document that the model is too complex and proceed with automated decisions 3. Apply for a GDPR exemption based on technical limitations 4. Provide technical documentation to satisfy the explanation requirement Correct! WHY: Model complexity is not a valid GDPR defense – if decisions cannot be explained then automated decision-making may not be permitted. CONTEXT: Organizations may need to implement explainability techniques or choose more interpretable model architectures for high-stakes decisions. REMEMBER: If you cannot explain it – you may not be permitted to automate it. 4 / 7 4. What is the relationship between GDPR and the EU AI Act? 1. GDPR only applies if EU AI Act does not 2. They are complementary – organizations must comply with both separately 3. EU AI Act replaces GDPR for AI systems 4. They have identical requirements so compliance with one satisfies both Correct! WHY: GDPR focuses on data protection while the EU AI Act focuses on AI system safety – fairness – and transparency – making them complementary rather than redundant. CONTEXT: An AI system can be EU AI Act compliant yet still violate GDPR and vice versa – organizations must comply with both. REMEMBER: GDPR protects data subjects – EU AI Act regulates AI systems. 5 / 7 5. What percentage of significant GDPR fines stem from inadequate documentation according to enforcement analysis? 1. 67 percent 2. 78 percent 3. 45 percent 4. 92 percent Correct! WHY: Analysis of GDPR enforcement actions shows that 92 percent of significant fines stem from inadequate documentation – making audit trails the primary defense. CONTEXT: Documentation requirements span training data sources – processing activities – model decisions – and compliance procedures. REMEMBER: Document everything – your records are your defense. 6 / 7 6. What does meaningful information about the logic involved require under GDPR transparency obligations? 1. Understandable explanations of how decisions are made and what factors matter 2. A statement that AI was involved in the decision 3. Technical documentation of the neural network structure 4. Providing complete source code and model architecture Correct! WHY: Meaningful information means providing understandable explanations of how AI decisions are made and what factors matter – not technical implementation details. CONTEXT: A loan applicant needs to understand why they were rejected – not review model architecture or source code. REMEMBER: Explain the why – not the how of the code. 7 / 7 7. Why is the right to erasure particularly challenging for AI systems? 1. GDPR exempts AI models from erasure requirements 2. Personal data becomes embedded in model weights making extraction technically difficult 3. AI systems automatically comply with erasure requests through built-in features 4. Erasure only requires removing data from the training dataset Correct! WHY: Once personal data is mixed into model training – extracting one persons contribution is technically difficult – often requiring full model retraining. CONTEXT: This is called the blended smoothie problem – data becomes embedded in model weights rather than stored in deletable records. REMEMBER: Deleting from database does not equal deleting from model. Your score isThe average score is 0% Restart quiz Download PDF Please leave this field empty๐ The AI Security Manager's Newsletter Weekly insights on AI risk management, EU AI Act compliance, and practical security strategies. We donโt spam! Read our privacy policy for more info. Thank you! Please check your inbox to confirm your subscription.