Courseiva

AI0-001 AI Implementation and Operations Practice Question

Which TWO actions should be taken to ensure an AI model complies with GDPR requirements when processing personal data?

⚠ Common exam trap

CompTIA often tests the misconception that anonymization is always required before any AI processing of personal data, but GDPR allows processing under lawful bases without anonymization, making Option D a tempting but incorrect choice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Limit data collection to only what is necessary for the model

Option A is correct because GDPR's data minimization principle (Article 5(1)(c)) requires that personal data be adequate, relevant, and limited to what is necessary for the purposes for which it is processed, so restricting collection to only what the model needs directly supports compliance. Option E is correct because GDPR grants data subjects the right to erasure (Article 17, the 'right to be forgotten'), so implementing user data deletion upon request is a mandatory capability for any system processing personal data. Option B is not required by GDPR, which focuses on transparency about processing purposes and logic rather than mandating a full explanation of every model prediction (that concern relates more to interpretability and AI-specific regulation). Option C is wrong because GDPR's storage limitation principle requires data to be kept no longer than necessary, so a 10-year minimum retention period would violate the regulation. Option D is not strictly required because GDPR permits processing of personal data with a lawful basis; anonymization is one way to reduce risk but is not a universal prerequisite, and true anonymization is often impractical for model training.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Limit data collection to only what is necessary for the model

    Why this is correct

    Data minimisation is a core GDPR principle, so restricting collection to what the model genuinely needs satisfies the lawfulness and storage-limitation requirements. This directly limits the volume of personal data processed, reducing exposure and helping demonstrate accountability under the regulation.

  • ✗

    Provide a full explanation of model predictions

    Why it's wrong here

    GDPR requires transparency about automated decision-making logic, not a full explanation of every prediction, which is neither technically feasible for deep models nor mandated. It is tempting because explainability supports the right to meaningful information, and it would be correct where decisions are solely automated and significantly affect the data subject.

  • ✗

    Store all user data for a minimum of 10 years

    Why it's wrong here

    GDPR's storage limitation principle requires deleting personal data once its purpose is fulfilled, so a fixed ten-year minimum retention contradicts the regulation. It is tempting because retention periods feel like governance, and a defined retention schedule would be correct where a lawful basis and necessity justify keeping data for that specific period.

  • ✗

    Anonymize all personal data before use

    Why it's wrong here

    Anonymisation removes data from GDPR's scope entirely, so it cannot be a compliance action for processing that must remain personal data. It is tempting because anonymisation is a strong safeguard, and it would be correct where the processing purpose genuinely does not require identifying individuals, unlike training on identifiable records.

  • ✓

    Implement user data deletion upon request

    Why this is correct

    GDPR grants data subjects the right to erasure, so the pipeline must delete personal data on request, including from training sets and model artefacts where feasible. This satisfies the data subject rights constraint and prevents unlawful retention of personal data.

About these practice questions

Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.