mediumMultiple Choice
Generative AI Leader Practice Question: A financial institution wants to ensure…
A financial institution wants to ensure compliance with GDPR when using a generative AI service that processes EU user data. Which measure is most directly required?
⚠ Common exam trap
The trap is focusing on data residency or training data origin as the primary GDPR requirement, when the exam expects recognition that a lawful basis — most commonly consent — is the foundational obligation for processing EU personal data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a mechanism to obtain user consent before processing data
GDPR requires a lawful basis for processing personal data, and consent is one of the most common bases, especially for marketing or non-contractual processing. Implementing a mechanism to obtain user consent before processing EU user data directly satisfies GDPR Article 6 and Article 7 requirements for lawful processing. This is the most directly required measure among the options.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable logging of all interactions to minimize data retention
Why it's wrong here
GDPR permits processing and logging where a lawful basis, retention limits and data subject rights are satisfied; blanket disabling of logging is not required and can defeat audit and security obligations. It is tempting because data minimisation is a genuine GDPR principle, but the directly required measure is a lawful basis with appropriate safeguards.
- ✓
Implement a mechanism to obtain user consent before processing data
Why this is correct
GDPR requires a lawful basis for processing personal data, and consent is one such basis. Obtaining user consent before processing EU user data directly satisfies that obligation, making it the measure most directly required for the described generative AI service.
- ✗
Store all prompts and responses in a US-based data center
Why it's wrong here
GDPR governs processing of EU residents' data and does not mandate US storage; transferring personal data outside the EEA requires an adequacy decision or appropriate safeguards such as standard contractual clauses. It is tempting because residency feels like a compliance control, but location alone neither satisfies nor breaches the regulation.
- ✗
Use a model trained only on non-EU data
Why it's wrong here
GDPR governs lawful processing, data minimisation and transfers, not the training corpus's geography; an EU-data-trained model can still be compliant with the right legal basis. Training only on non-EU data is tempting as a transfer-avoidance tactic, but it neither satisfies GDPR's other obligations nor prevents EU personal data entering prompts at inference.
About these practice questions
Courseiva writes every Generative AI Leader question from scratch — 1,008 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.