Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IAPP Exam CIPP-E Topic 2 Question 101 Discussion

Actual exam question for IAPP's CIPP-E exam
Question #: 101
Topic #: 2
[All CIPP-E Questions]

Start-up company MagicAI is developing an AI system that will be part of a medical device that detects skin cancer. To take measures against potential bias in its AI system, the IT Team decides to collect data about users' ethnic origin, nationality, and gender.

Which would be the most appropriate legal basis for this processing under the GDPR, Article 9 (Processing of special categories of personal data)?

Show Suggested Answer Hide Answer
Suggested Answer: A

Article 9 of the GDPR outlines strict conditions for processing special categories of personal data, which includes data revealing racial or ethnic origin. While options B, C, and D might seem relevant, they don't fully align with the core purpose of MagicAI's data collection.

Here's why option A is the most appropriate:

Scientific Research: MagicAI aims to improve the accuracy and fairness of its AI system by understanding how it performs across different ethnicities, nationalities, and genders. This directly ties into scientific research aimed at improving healthcare and reducing bias in medical technology.

It's important to note that even with 'scientific research' as the legal basis, MagicAI must still adhere to strict safeguards, such as:

Data Minimization: Collecting only the data absolutely necessary for the research.

Purpose Limitation: Using the data solely for the defined scientific purpose.

Appropriate Security Measures: Protecting the data against unauthorized access or disclosure.

Ethical Review: Ideally, obtaining ethical approval for the research project.


GDPR Article 9 - Processing of special categories of personal data

GDPR Recital 159 - Conditions for processing special categories of data for scientific research purposes

IAPP CIPP/E textbook, Chapter 2: Key Data Protection Principles (specifically, sections on special categories of data)

Contribute your Thoughts:

Cathern
7 days ago
C all the way! Gotta love some good old preventive medicine. Although, I wonder if the AI system will also have a sense of humor built-in. You know, for when the dermatologists need a laugh.
upvoted 0 times
...
Marget
9 days ago
This is a tricky one. I can see the logic behind all the answers, but C just feels the most appropriate given the medical context. Although, I do enjoy a good 'legal claims' joke. ????
upvoted 0 times
...
Kimberlie
10 days ago
Hmm, I'm not sure. D sounds like it could be relevant too, in case there are any legal claims down the line. But I agree C is the best option here.
upvoted 0 times
...
Lina
11 days ago
A would also work, since this data collection is for scientific purposes. But C is probably the better fit.
upvoted 0 times
...
Rosalind
22 days ago
But wouldn't A) Processing necessary for scientific or statistical purposes also be a valid option in this case?
upvoted 0 times
...
Ettie
23 days ago
I agree with Elouise, collecting data for medical purposes seems to align with that option.
upvoted 0 times
...
Tatum
23 days ago
I think the correct answer is C. Processing necessary for purposes of preventive or occupational medicine. This seems like the most relevant legal basis for collecting data to develop a medical device.
upvoted 0 times
Barrie
9 days ago
Yes, it makes sense to collect data for preventive or occupational medicine purposes in this case.
upvoted 0 times
...
Jeniffer
13 days ago
I agree, option C seems to be the most appropriate for collecting data for a medical device.
upvoted 0 times
...
...
Elouise
1 months ago
I think the most appropriate legal basis would be C) Processing necessary for purposes of preventive or occupational medicine.
upvoted 0 times
...

Save Cancel