dpa-001 · lawful_basisdifficulty 1/3
A UK SaaS company says it relies on 'legitimate interests' to process customer data. What must it actually establish?
Gold standard: The three-part test: (1) a legitimate interest is pursued (purpose test), (2) the processing is necessary for that interest (necessity test — no less intrusive way), and (3) the interest is not overridden by the data subject's interests, rights and freedoms (balancing test), documented in a legitimate interests assessment. Naming the basis without the test is incomplete.
dpa-006 · marketingdifficulty 2/3
May a UK online retailer email marketing to past customers without fresh consent?
Gold standard: Yes, within the PECR 'soft opt-in': the details were collected in the course of a sale or negotiations for one, the marketing is for the sender's own similar products, and the customer was given a simple free opt-out at collection and in every message. Outside those conditions, consent is required. Answering under UK GDPR alone and skipping PECR is the wrong-framework failure this item probes.
dpa-023 · lawful_basisdifficulty 3/3
A UK legal-tech vendor fine-tunes an LLM on client matter files. Frame the core data-protection analysis.
Gold standard: Identify roles first (the vendor is a controller for its own training purpose), then: lawful basis for repurposing (legitimate interests demands the three-part test with a hard look at client and data-subject expectations and privilege/confidentiality overlays), purpose-limitation compatibility under Article 6(4), data-minimisation and anonymisation/pseudonymisation options, DPIA (innovative technology, likely high risk), and the difficulty of honouring rights (erasure from trained weights). ICO guidance on generative AI expects exactly this structure; skipping roles or the repurposing test is the failure mode.