The correct answer isAbecause when contracts do not clearly permit the use of client data for a new purpose, the organization should first obtainformal client consentbefore using that aggregated data in an ML model. This is the strongest action because it addresses authorization, transparency, and legal/privacy expectations before the data is repurposed.
The other options are weaker as the next step:
B. Update the organization ' s privacy policyis not enough by itself if contractual permission is unclear.
C. Request internal risk acceptance from senior managementdoes not replace client permission or legal authority.
D. Update the organization ' s data processing agreement templateis useful for future contracts, but it does not solve the issue for current clients.
Exact Extracts supporting the answer:
“Upon learning of a new regulation for safeguarding information in specific transactions an IT manager should first assess whether existing controls meet the regulation.”
“For an enterprise expanded into different regions the major concern is that the employee handbook may violate local laws and regulations.”
“To ensure compliance with a new data protection regulation the risk practitioner should gather risk scenarios with a potential impact on compliance.”
“The MOST important consideration when transmitting personal information across networks is ensuring the privacy of the personal information.”
“A privacy impact assessment can help enterprises weigh the benefits of their data processing activities against risk to determine the appropriate response.”
These extracts support the principle that data use must be aligned with privacy, compliance, and authorized processing conditions. Since the contracts do not clearly allow this use, the next action is to seekformal consentfrom clients.
===========
Submit