hardMultiple Choice
Generative AI Leader Practice Question: A global company deploys a generative AI chatbot…
A global company deploys a generative AI chatbot in the European Union. They must ensure compliance with GDPR regarding user data used for fine-tuning the model. What is the MOST important requirement they must fulfill?
⚠ Common exam trap
The Generative AI Leader exam often tests the misconception that technical measures like anonymization or data localization can substitute for a proper lawful basis under GDPR, when in fact the lawful basis (such as explicit consent) is the foundational requirement that must be established before any processing begins.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Obtain explicit consent from data subjects for using their data in fine-tuning
Under GDPR, using personal data for fine-tuning a generative AI model constitutes a new processing purpose that requires a lawful basis. Explicit consent (Article 7 and Article 9) is the most robust basis when relying on consent, as it must be freely given, specific, informed, and unambiguous. Without explicit consent, the company risks violating data minimization and purpose limitation principles, even if other anonymization or storage measures are applied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use only synthetic data for fine-tuning to avoid GDPR issues
Why it's wrong here
Synthetic-only fine-tuning does not by itself satisfy GDPR; the regulation governs lawfulness, purpose limitation and transparency for personal data, and synthetic data can still be personal data if derived from identifiable individuals. It is tempting because synthetic data reduces exposure, and would suit minimisation where real data is unnecessary.
- ✗
Store all fine-tuned models only on US-based servers
Why it's wrong here
US-only storage does not satisfy GDPR's Chapter V transfer rules; transfers outside the EEA require an adequacy decision or appropriate safeguards such as Standard Contractual Clauses. It is tempting because consolidating servers simplifies operations, and would suit a purely domestic US deployment outside EU scope.
- ✗
Anonymize all data before fine-tuning, regardless of consent
Why it's wrong here
Anonymisation is not a blanket substitute for a lawful basis; if data is genuinely anonymised, GDPR no longer applies, but pseudonymised data remains personal data and consent or another Article 6 basis is still needed. It is tempting because anonymisation removes identifiability, and would suit irreversible de-identification where re-identification is truly impossible.
- ✓
Obtain explicit consent from data subjects for using their data in fine-tuning
Why this is correct
Explicit consent provides a lawful basis under GDPR for processing personal data in fine-tuning, satisfying the requirement that data subjects authorise this specific purpose. It also supports transparency and purpose limitation, giving the global company a defensible compliance position for EU chatbot users.
Go deeper
Related to this question
About these practice questions
This Generative AI Leader question is part of Courseiva's 1,008-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.