Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Extracted Worksheet Questions: Privacy laws and AI

Total questions: 40

Worksheet time: 20mins

Name
Class
Date
1.

Why do existing data protection laws play such a dominant role in regulating AI today?

a)

Because AI-specific laws have failed globally

b)

Because most AI systems process personal data, triggering existing legal obligations regardless of technology

c)

Because privacy laws explicitly regulate machine learning architectures

d)

Because AI cannot function without biometric identifiers

2.

The global regulatory trend described in the module prioritises:

a)

Creating entirely new AI-only legal regimes

b)

Applying existing personal data and breach laws before expanding AI-specific regulation

c)

Treating AI systems as exempt until proven harmful

d)

Deferring regulation until model capabilities stabilise

3.

Which transparency obligation most directly applies to AI systems that interact with individuals?

a)

Publishing full source code

b)

Ensuring individuals understand that AI is processing their data and the implications of that interaction

c)

Registering the system with a regulator

d)

Providing a performance benchmark

4.

Why is transparency particularly challenging in AI systems compared to traditional software?

a)

AI systems change jurisdiction frequently

b)

AI decision logic may be opaque, probabilistic and adaptive

c)

AI systems cannot provide logs

d)

AI systems do not process personal data

5.

Which situation best reflects a valid exercise of user choice in AI systems?

a)

Continuing to use a service after seeing a privacy notice

b)

Entering a space with CCTV

c)

Explicitly agreeing to data use for a defined AI function with a clear opt-out

d)

Using a public social media platform

6.

Why is selecting a lawful basis particularly complex for AI systems?

a)

AI systems always require consent

b)

AI often involves secondary uses, long training cycles and evolving outputs

c)

Lawful bases only apply to biometric data

d)

AI processing is exempt from lawful basis requirements

7.

Which scenario most clearly creates a purpose limitation risk in AI?

a)

Using synthetic data for testing

b)

Reusing customer support data to train a general language model without updating notices

c)

Encrypting training data

d)

Logging model outputs

8.

Why does CNIL distinguish learning and production phases of AI?

a)

To exempt learning from regulation

b)

To recognise that different phases may require distinct lawful purposes and disclosures

c)

To prohibit retraining

d)

To require consent in all cases

9.

Which practice best demonstrates data minimisation in AI development?

a)

Collecting broad datasets in case future uses emerge

b)

Using feature selection techniques to limit inputs to those necessary for model performance

c)

Storing all raw data indefinitely

d)

Aggregating data without evaluation

10.

Why is what counts as “adequate and relevant” data case-specific in AI?

a)

Laws do not define the terms

b)

Different AI use cases require different data characteristics and volumes

c)

Only regulators can decide

d)

Data quality is irrelevant to AI performance

11.

Why is collecting “nice to have” data problematic under data minimisation?

a)

It increases storage costs

b)

It expands attack surfaces and legal exposure without necessity

c)

It slows training

d)

It prevents anonymisation

12.

Privacy by design requires privacy measures to be implemented:

a)

After deployment

b)

During regulatory audits

c)

From initial system planning and architecture

d)

Only if sensitive data is involved

13.

Which technical measure most directly supports privacy by design in AI?

a)

Model explainability dashboards

b)

Pseudonymisation of training data

c)

User experience testing

d)

Public transparency reports

14.

What does “by default” most strongly require in AI systems?

a)

No personal data processing

b)

Processing only the minimum personal data necessary for each purpose unless expanded deliberately

c)

Default public access

d)

Default consent

15.

Why does the GDPR significantly influence global AI governance?

a)

It regulates algorithms directly

b)

It establishes enforceable rights and principles applicable to automated systems

c)

It bans profiling

d)

It applies only within the EU

16.

Article 22 applies when a decision:

a)

Uses any automation

b)

Is based solely on automated processing and produces legal or similarly significant effects

c)

Involves profiling only

d)

Uses AI for internal analytics

17.

Why is Article 22 not an outright ban on automated decision-making?

a)

Because enforcement is weak

b)

Because exceptions allow automation under defined conditions

c)

Because consent is implied

d)

Because AI accuracy is assumed

18.

Which element is essential for explicit consent under GDPR?

a)

Silence after notice

b)

Clear affirmative action demonstrating agreement

c)

Public availability of data

d)

Continued service use

19.

Why is implied consent risky for AI processing?

a)

It is faster to obtain

b)

It often fails to meet specificity and transparency thresholds

c)

It applies only to children

d)

It cannot be withdrawn

20.

Once data is truly anonymised:

a)

GDPR obligations remain

b)

GDPR no longer applies

c)

Only breach laws apply

d)

Consent is still required

21.

Why is anonymisation difficult to achieve in AI contexts?

a)

AI models require identifiers

b)

Models may leak training data through outputs or inversion attacks

c)

Regulators prohibit anonymisation

d)

Encryption prevents anonymisation

22.

Why does pseudonymised data remain regulated?

a)

It is encrypted

b)

Re-identification remains possible with additional information

c)

It improves model accuracy

d)

It is temporary

23.

According to the EDPB, an AI model may be considered anonymous only if:

a)

Training data is public

b)

Neither training data nor outputs can be linked back to individuals

c)

The model is open source

d)

The controller claims anonymity

24.

Which step is part of assessing legitimate interest for AI?

a)

Cost-benefit analysis only

b)

Balancing controller interests against individual rights

c)

User survey results

d)

Model accuracy testing

25.

Which factor most influences whether individuals reasonably expect use of their data?

a)

Model size

b)

Context and source of data collection

c)

Compute power

d)

Output format

26.

Why do GDPR obligations persist even when AI processing is outsourced?

a)

AI systems cannot be audited

b)

Controllers remain accountable for processing decisions

c)

Processors assume full liability

d)

Contracts override GDPR

27.

Which situation most likely triggers a DPIA?

a)

Low-risk internal analytics

b)

High-risk AI processing affecting individuals’ rights

c)

Model retraining without personal data

d)

Encrypted storage

28.

Which processor behaviour creates the highest compliance risk?

a)

Using encryption

b)

Sourcing additional personal data without lawful basis

c)

Maintaining audit logs

d)

Limiting data retention

29.

Why are AI training pipelines often cross-border transfer risks?

a)

Models require global deployment

b)

Training, inference and support infrastructure span jurisdictions

c)

Privacy laws do not apply to AI

d)

Transfers are always anonymised

30.

Why are data subject rights harder to fulfil in AI systems?

a)

AI systems are illegal

b)

Data lineage and influence on outputs can be difficult to trace

c)

Rights do not apply to AI

d)

Encryption prevents access

31.

Why is the right to human intervention critical in AI decisions?

a)

To slow down systems

b)

To provide accountability and contestability

c)

To retrain models

d)

To replace automation

32.

Why is automated recruitment specifically highlighted?

a)

It is always prohibited

b)

It affects access to employment and rights, triggering higher safeguards

c)

It uses biometrics

d)

It is experimental

33.

Why can AI incidents be harder to manage than traditional IT breaches?

a)

AI systems cannot be shut down

b)

Data flows and model behaviour may be opaque

c)

Logs are prohibited

d)

Regulators ignore AI

34.

Why should AI procurement contracts address incident management?

a)

To transfer all liability

b)

To ensure cooperation and assistance with investigations and notifications

c)

To avoid audits

d)

To limit transparency

35.

Accurate breach notification depends most on:

a)

Model accuracy

b)

Documentation and testing of AI data flows

c)

Public disclosures

d)

User complaints

36.

Why is record keeping particularly difficult for AI systems?

a)

AI changes jurisdiction

b)

Training data volumes and transformations are complex

c)

Laws do not require records

d)

AI systems self-document

37.

Records of processing activities primarily support:

a)

Marketing optimisation

b)

Accountability, audits and regulatory oversight

c)

Model performance tuning

d)

Data monetisation

38.

Which data type triggers heightened protection obligations?

a)

Email addresses

b)

Biometric identifiers used for identification

c)

IP addresses only

d)

Usernames

39.

Processing special category data generally requires:

a)

Any lawful basis

b)

An additional condition such as explicit consent or legal authorisation

c)

Legitimate interest alone

d)

Implied consent

40.

Why did encryption and access controls strengthen both compliance and trust at Axentis?

a)

They improved model accuracy

b)

They reduced breach risk, legal exposure and audit friction

c)

They eliminated consent requirements

d)

They replaced DPIAs