A hospital AI system produces risk scores for patient readmission. A patient asks a nurse why they were flagged as high-risk. The nurse cannot explain the AI's reasoning. What GDPR right and what principle are at issue?
- A.Article 22 right to explanation of automated decision logic and the principle of transparency - the hospital must be able to provide meaningful explanations of AI decisions that significantly affect patients
- B.Article 17 right to erasure - the patient's risk score must be deleted upon request
- C.Article 5(1)(d) accuracy - the hospital must verify the risk score is mathematically correct before disclosure
- D.Article 20 portability - the patient can take the risk score to another hospital
Why A is correct
When automated decisions significantly affect individuals, GDPR Article 22 and the transparency principle require that meaningful explanation of the logic, significance, and consequences be available. A nurse being unable to explain the AI's reasoning indicates the hospital has not implemented explainability capabilities necessary for GDPR compliance. Right to erasure is separate. Accuracy (Article 5(1)(d)) relates to data correctness, not explanation. Portability enables data transfer, not explanation.
Know someone studying for AI Security Fundamentals? Send them this one.