GDPR & AI — Understanding Data Protection
1. Which GDPR principle states that data may only be used for the specified purpose?
Purpose limitation: collected for X → not to be used for Y.
2. What does GDPR Art. 22 permit?
Art. 22: Right to human oversight in significant automated decisions.
3. How long does a company have to report a data breach to the supervisory authority?
Art. 33: 72 hours — not days, hours.
4. For which data do stricter rules apply under GDPR?
Art. 9: Special categories require explicit consent.
5. Which statement about the DPIA (Data Protection Impact Assessment) is correct? 2 pts
Art. 35: DPIA obligation for large-scale profiling, special categories, etc.
6. What are the information obligations towards data subjects? (Multiple possible) 2 pts
Affected individuals must be informed about: controllers, purpose, duration, rights, automation.