WorksheetsExtracted Worksheet Questions: Privacy laws and AI
Total questions: 40
Worksheet time: 20mins
Why do existing data protection laws play such a dominant role in regulating AI today?
Because AI-specific laws have failed globally
Because most AI systems process personal data, triggering existing legal obligations regardless of technology
Because privacy laws explicitly regulate machine learning architectures
Because AI cannot function without biometric identifiers
The global regulatory trend described in the module prioritises:
Creating entirely new AI-only legal regimes
Applying existing personal data and breach laws before expanding AI-specific regulation
Treating AI systems as exempt until proven harmful
Deferring regulation until model capabilities stabilise
Which transparency obligation most directly applies to AI systems that interact with individuals?
Publishing full source code
Ensuring individuals understand that AI is processing their data and the implications of that interaction
Registering the system with a regulator
Providing a performance benchmark
Why is transparency particularly challenging in AI systems compared to traditional software?
AI systems change jurisdiction frequently
AI decision logic may be opaque, probabilistic and adaptive
AI systems cannot provide logs
AI systems do not process personal data
Which situation best reflects a valid exercise of user choice in AI systems?
Continuing to use a service after seeing a privacy notice
Entering a space with CCTV
Explicitly agreeing to data use for a defined AI function with a clear opt-out
Using a public social media platform
Why is selecting a lawful basis particularly complex for AI systems?
AI systems always require consent
AI often involves secondary uses, long training cycles and evolving outputs
Lawful bases only apply to biometric data
AI processing is exempt from lawful basis requirements
Which scenario most clearly creates a purpose limitation risk in AI?
Using synthetic data for testing
Reusing customer support data to train a general language model without updating notices
Encrypting training data
Logging model outputs
Why does CNIL distinguish learning and production phases of AI?
To exempt learning from regulation
To recognise that different phases may require distinct lawful purposes and disclosures
To prohibit retraining
To require consent in all cases
Which practice best demonstrates data minimisation in AI development?
Collecting broad datasets in case future uses emerge
Using feature selection techniques to limit inputs to those necessary for model performance
Storing all raw data indefinitely
Aggregating data without evaluation
Why is what counts as “adequate and relevant” data case-specific in AI?
Laws do not define the terms
Different AI use cases require different data characteristics and volumes
Only regulators can decide
Data quality is irrelevant to AI performance
Why is collecting “nice to have” data problematic under data minimisation?
It increases storage costs
It expands attack surfaces and legal exposure without necessity
It slows training
It prevents anonymisation
Privacy by design requires privacy measures to be implemented:
After deployment
During regulatory audits
From initial system planning and architecture
Only if sensitive data is involved
Which technical measure most directly supports privacy by design in AI?
Model explainability dashboards
Pseudonymisation of training data
User experience testing
Public transparency reports
What does “by default” most strongly require in AI systems?
No personal data processing
Processing only the minimum personal data necessary for each purpose unless expanded deliberately
Default public access
Default consent
Why does the GDPR significantly influence global AI governance?
It regulates algorithms directly
It establishes enforceable rights and principles applicable to automated systems
It bans profiling
It applies only within the EU
Article 22 applies when a decision:
Uses any automation
Is based solely on automated processing and produces legal or similarly significant effects
Involves profiling only
Uses AI for internal analytics
Why is Article 22 not an outright ban on automated decision-making?
Because enforcement is weak
Because exceptions allow automation under defined conditions
Because consent is implied
Because AI accuracy is assumed
Which element is essential for explicit consent under GDPR?
Silence after notice
Clear affirmative action demonstrating agreement
Public availability of data
Continued service use
Why is implied consent risky for AI processing?
It is faster to obtain
It often fails to meet specificity and transparency thresholds
It applies only to children
It cannot be withdrawn
Once data is truly anonymised:
GDPR obligations remain
GDPR no longer applies
Only breach laws apply
Consent is still required
Why is anonymisation difficult to achieve in AI contexts?
AI models require identifiers
Models may leak training data through outputs or inversion attacks
Regulators prohibit anonymisation
Encryption prevents anonymisation
Why does pseudonymised data remain regulated?
It is encrypted
Re-identification remains possible with additional information
It improves model accuracy
It is temporary
According to the EDPB, an AI model may be considered anonymous only if:
Training data is public
Neither training data nor outputs can be linked back to individuals
The model is open source
The controller claims anonymity
Which step is part of assessing legitimate interest for AI?
Cost-benefit analysis only
Balancing controller interests against individual rights
User survey results
Model accuracy testing
Which factor most influences whether individuals reasonably expect use of their data?
Model size
Context and source of data collection
Compute power
Output format
Why do GDPR obligations persist even when AI processing is outsourced?
AI systems cannot be audited
Controllers remain accountable for processing decisions
Processors assume full liability
Contracts override GDPR
Which situation most likely triggers a DPIA?
Low-risk internal analytics
High-risk AI processing affecting individuals’ rights
Model retraining without personal data
Encrypted storage
Which processor behaviour creates the highest compliance risk?
Using encryption
Sourcing additional personal data without lawful basis
Maintaining audit logs
Limiting data retention
Why are AI training pipelines often cross-border transfer risks?
Models require global deployment
Training, inference and support infrastructure span jurisdictions
Privacy laws do not apply to AI
Transfers are always anonymised
Why are data subject rights harder to fulfil in AI systems?
AI systems are illegal
Data lineage and influence on outputs can be difficult to trace
Rights do not apply to AI
Encryption prevents access
Why is the right to human intervention critical in AI decisions?
To slow down systems
To provide accountability and contestability
To retrain models
To replace automation
Why is automated recruitment specifically highlighted?
It is always prohibited
It affects access to employment and rights, triggering higher safeguards
It uses biometrics
It is experimental
Why can AI incidents be harder to manage than traditional IT breaches?
AI systems cannot be shut down
Data flows and model behaviour may be opaque
Logs are prohibited
Regulators ignore AI
Why should AI procurement contracts address incident management?
To transfer all liability
To ensure cooperation and assistance with investigations and notifications
To avoid audits
To limit transparency
Accurate breach notification depends most on:
Model accuracy
Documentation and testing of AI data flows
Public disclosures
User complaints
Why is record keeping particularly difficult for AI systems?
AI changes jurisdiction
Training data volumes and transformations are complex
Laws do not require records
AI systems self-document
Records of processing activities primarily support:
Marketing optimisation
Accountability, audits and regulatory oversight
Model performance tuning
Data monetisation
Which data type triggers heightened protection obligations?
Email addresses
Biometric identifiers used for identification
IP addresses only
Usernames
Processing special category data generally requires:
Any lawful basis
An additional condition such as explicit consent or legal authorisation
Legitimate interest alone
Implied consent
Why did encryption and access controls strengthen both compliance and trust at Axentis?
They improved model accuracy
They reduced breach risk, legal exposure and audit friction
They eliminated consent requirements
They replaced DPIAs
