nerdexam
Isaca

AAISM · Question #223

Which of the following is the MOST effective approach to mitigate privacy concerns when an organization collects personal data through a third-party AI application?

The correct answer is B. Obtain data subject consent on the end user interface. Obtaining informed consent directly from data subjects at the point of collection is the foundational legal requirement for lawful processing of personal data under privacy regulations.

AI Security Strategy and Governance

Question

Which of the following is the MOST effective approach to mitigate privacy concerns when an organization collects personal data through a third-party AI application?

Options

  • AHave the vendor sign a nondisclosure agreement.
  • BObtain data subject consent on the end user interface.
  • CApply encryption to safeguard personnel data.
  • DConduct a review of applicable data protection regulations.

How the community answered

(35 responses)
  • A
    9% (3)
  • B
    74% (26)
  • C
    14% (5)
  • D
    3% (1)

Why each option

Obtaining informed consent directly from data subjects at the point of collection is the foundational legal requirement for lawful processing of personal data under privacy regulations.

AHave the vendor sign a nondisclosure agreement.

A nondisclosure agreement with the vendor protects organizational information but does not address the rights of individual data subjects or establish a lawful basis for processing their personal data.

BObtain data subject consent on the end user interface.Correct

Obtaining data subject consent on the end user interface directly fulfills the legal basis for personal data collection required by regulations such as GDPR, which mandates that individuals freely, specifically, and informedly agree to how their data is used. Collecting consent at the exact point of interaction ensures transparency and creates an auditable record of lawful basis. This addresses the privacy concern at its source - the moment of collection - rather than through downstream controls.

CApply encryption to safeguard personnel data.

Encryption protects data confidentiality in transit and at rest but does not address the legal or ethical requirement to obtain consent before collecting personal data.

DConduct a review of applicable data protection regulations.

Reviewing data protection regulations is a governance activity that informs policy design but does not itself mitigate the privacy risk to data subjects.

Concept tested: Data subject consent requirements under privacy regulations

Source: https://gdpr.eu/article-7-how-can-we-ask-for-consent/

Topics

#Privacy#Data Subject Consent#Third-Party Data#AI Data Collection

Community Discussion

No community discussion yet for this question.

Full AAISM Practice