Courseiva
mediumMultiple Choice

Generative AI Leader Practice Question: A financial institution wants to ensure…

A financial institution wants to ensure compliance with GDPR when using a generative AI service that processes EU user data. Which measure is most directly required?

⚠ Common exam trap

The trap is focusing on data residency or training data origin as the primary GDPR requirement, when the exam expects recognition that a lawful basis — most commonly consent — is the foundational obligation for processing EU personal data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a mechanism to obtain user consent before processing data

GDPR requires a lawful basis for processing personal data, and consent is one of the most common bases, especially for marketing or non-contractual processing. Implementing a mechanism to obtain user consent before processing EU user data directly satisfies GDPR Article 6 and Article 7 requirements for lawful processing. This is the most directly required measure among the options.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable logging of all interactions to minimize data retention

    Why it's wrong here

    GDPR permits processing and logging where a lawful basis, retention limits and data subject rights are satisfied; blanket disabling of logging is not required and can defeat audit and security obligations. It is tempting because data minimisation is a genuine GDPR principle, but the directly required measure is a lawful basis with appropriate safeguards.

  • ✓

    Implement a mechanism to obtain user consent before processing data

    Why this is correct

    GDPR requires a lawful basis for processing personal data, and consent is one such basis. Obtaining user consent before processing EU user data directly satisfies that obligation, making it the measure most directly required for the described generative AI service.

  • ✗

    Store all prompts and responses in a US-based data center

    Why it's wrong here

    GDPR governs processing of EU residents' data and does not mandate US storage; transferring personal data outside the EEA requires an adequacy decision or appropriate safeguards such as standard contractual clauses. It is tempting because residency feels like a compliance control, but location alone neither satisfies nor breaches the regulation.

  • ✗

    Use a model trained only on non-EU data

    Why it's wrong here

    GDPR governs lawful processing, data minimisation and transfers, not the training corpus's geography; an EU-data-trained model can still be compliant with the right legal basis. Training only on non-EU data is tempting as a transfer-avoidance tactic, but it neither satisfies GDPR's other obligations nor prevents EU personal data entering prompts at inference.

About these practice questions

Courseiva writes every Generative AI Leader question from scratch — 1,008 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.