A university lecturer asks which GDPR principle is violated when an AI system trained on HR data for performance reviews is repurposed to predict employee health conditions without additional legal basis.
- A.Purpose limitation (Article 5(1)(b)) - data collected for performance review cannot be repurposed for health prediction without a separate compatible purpose assessment and new legal basis
- B.Data minimization (Article 5(1)(c)) - the system processes too much data for health prediction
- C.Storage limitation (Article 5(1)(e)) - the HR data has been retained beyond its original purpose retention period
- D.Accuracy (Article 5(1)(d)) - health predictions from HR data are likely inaccurate
Why A is correct
Purpose limitation (Article 5(1)(b)) prohibits using personal data for purposes incompatible with those for which it was collected without a new legal basis. Repurposing HR performance data for health prediction is a clear purpose limitation violation, compounded by Article 9 (processing special category health data requires a separate explicit legal basis). Data minimization concerns data volume, not repurposing. Storage limitation concerns retention time. Accuracy is an important principle but not the primary violation here.
Know someone studying for AI Security Fundamentals? Send them this one.