IAPP AIGP · Domain II · Laws, Standards & Frameworks
Know the Law, Map the Rules
Domain II is the legal layer of the AIGP: which rules bind an AI system, who owes what duty, and which assessment proves you did the homework. GDPR, the EU AI Act, the US patchwork, ISO 42001, OECD, UNESCO, Singapore — each with a plain-words example so the law stops being jargon.
GDPR Art. 22 · 35 · Recital 26EU AI Act fine tiers + datesNIST G-M-M-M · ISO PDCASG PDPA · MGF · FEAT20 flip cards · 8 traps
How to use this module: read each section, then flip the cards and run the trap quiz. The compare tables at §7 are the highest-yield revision — the exam loves blurring GDPR vs PDPA, DPIA vs FRIA, and provider vs deployer. Every topic carries an IN PLAIN WORDS example, because the exam asks you to explain these rules to a non-technical person.
Scroll to begin ↓
0
The territory at a glance
Domain II Mindmap
Eight branches, one exam domain. Trace each line: the law, its structure, and the exam tell that identifies it.
1
BoK Domain II.A — The EU privacy baseline
GDPR: The Rules AI Must Live With
The GDPR is the privacy law the AIGP assumes you know cold. The exam tests four things: automated decisions (Art. 22), impact assessments (Art. 35), what counts as personal data (Recital 26), and who owes what duty (controller vs processor).
1.1 Automated decision-making — Art. 22
Exam anchor — Art. 22Article 22 gives a data subject the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects them. Three exceptions: (a) necessary for a contract, (b) authorised by law, (c) based on explicit consent. For the first two exceptions, the controller must provide suitable safeguards — including the right to human intervention, to express views, and to contest the decision.[GDPR Art. 22]
In plain words: a bank's AI denies your loan application with no human involved. Under Art. 22 you can demand a human re-look at the decision, explain your side, and challenge it. The bank must have a human-review path built in — not as a favour, but as a legal requirement.
Exam trap — "solely"Art. 22 only bites when the decision is solely automated. If a human meaningfully reviews the decision before it takes effect, Art. 22 does not apply. The exam loves a scenario where a human clicks "approve" without reading — that is still solely automated in substance, because the human adds no real judgement.
1.2 DPIA — Art. 35
When a DPIA is requiredA Data Protection Impact Assessment is mandatory where processing is likely to result in a high risk to individuals' rights and freedoms — especially new technologies, systematic evaluation/profiling, large-scale special-category data, or large-scale public monitoring. The DPIA must describe the processing, assess necessity and proportionality, and identify and mitigate risks.[GDPR Art. 35]
In plain words: a hospital wants an AI that screens all patient records for clinical-trial eligibility. That is large-scale special-category data — a DPIA is legally required before the system touches real records. The DPIA is the paperwork that proves the hospital thought about the risks before building.
Exam anchor — the DPIA checklistWhat a DPIA must contain: (1) a systematic description of the processing and its purposes; (2) an assessment of necessity and proportionality; (3) an assessment of risks to individuals; (4) the measures to address those risks. If the residual risk stays high, the controller must consult the supervisory authority before processing (Art. 36).
1.3 Personal data & Recital 26
Concept
Definition
Plain-words example
Personal data
Any information relating to an identified or identifiable natural person
A customer's name, email, location, purchase history, or voice recording — alone or combined
Identifiable
Can be identified directly or indirectly, using means reasonably likely to be used
A pseudonymised user ID is still personal data if the company holds the key
Anonymised (Recital 26)
Information that no longer relates to an identifiable person — GDPR does not apply
Aggregated statistics with no way back to individuals are outside the GDPR
Pseudonymised (Art. 4(5))
Data that can no longer be attributed without additional information kept separately
Replacing names with codes — still personal data, but a strong safeguard
Exam trap — pseudonymised ≠ anonymisedPseudonymised data is still personal data under the GDPR. Only true anonymisation takes data out of scope. The exam asks this directly — if the key exists anywhere, it is pseudonymised, not anonymised.[GDPR Recital 26; Art. 4(5)]
A hospital decides to deploy a diagnostic AI and how patient data will be used — the hospital is the controller
Processor
Processes data on the controller's behalf
Acts only on documented instructions; must have a contract (Art. 28)
The cloud vendor hosting the hospital's data — it cannot use the data for its own purposes
Joint controllers
Two or more jointly determine purposes and means
Must arrange responsibilities transparently between them
A hospital and a university jointly design a research AI — both decide how data is used, so both are controllers
Why this matters for AI: when a company buys an AI tool from a vendor, the vendor is usually the processor and the buyer the controller — but if the vendor trains the model on the buyer's data for its own benefit, the vendor becomes a controller too. The exam tests who carries the breach-notification duty: the controller.
1.5 Data subject rights the exam tests
Right of access (Art. 15)
Individuals can ask what data is processed, why, and who it is shared with.
Example: a customer asks the bank what the credit model knows about them — the bank must answer within one month.
Right to rectification & erasure (Art. 16-17)
Correct inaccurate data; erase data when grounds apply (the "right to be forgotten").
Example: a job applicant asks a recruiter to delete their profile after a failed application.
Right to object (Art. 21)
Object to processing based on legitimate interests or for direct marketing.
Example: a user opts out of a retailer's AI-driven personalised ads.
Right to data portability (Art. 20)
Receive data in a machine-readable format and transfer it to another provider.
Example: a fitness-app user exports their health data to switch to a rival app.
Right not to be subject to automated decisions (Art. 22)
Human intervention, express views, contest decisions made solely by automation.
Example: an AI denies a loan — the applicant demands a human review.
Right to lodge a complaint (Art. 77)
Complain to a supervisory authority in the member state of residence, work, or alleged infringement.
Example: a data subject whose AI-rejected claim was never reviewed files a complaint with the DPA.
2
BoK Domain II.A — Exam-relevant summary only
EU AI Act: The Fines, The Bans, The Dates
You have the deep EU module — this is the exam-ready skeleton: fine tiers, the eight prohibited practices, the key dates (including the Digital Omnibus shifts), and the traps that separate a pass from a fail.
2.1 Fine tiers — Art. 99
Tier
Violation
Fine
Mnemonic
Top tier
Prohibited practices (Art. 5)
€35M or 7% of total worldwide annual turnover
"7% for the seven deadly practices"
Middle tier
Most operator obligations, incl. Art. 50 transparency
€15M or 3%
"3% for the three letters of Art. 50"
Lower tier
Supplying incorrect/incomplete/misleading info to authorities
€7.5M or 1%
"1% for the one thing you should have told them"
Exam anchor — the SME lower-of rule (Art. 99(6))For SMEs and start-ups, the fine is the lower of the fixed amount or the percentage of turnover — not the higher. For everyone else it is the higher. The exam tests this with a small company and a big turnover figure: pick the smaller number.[EU AI Act Art. 99(6)]
In plain words: a big bank runs a prohibited social-scoring system — fine is the higher of €35M or 7% of its global turnover. A 20-person startup does the same — the fine is the lower of the two. The law protects small players from being wiped out.
2.2 The eight prohibited practices — Art. 5(a)-(h)
(a) Subliminal manipulation
Techniques that distort behaviour and cause harm, exploiting vulnerabilities.
Example: an app flashes hidden cues to push a vulnerable user into harmful purchases.
(b) Vulnerability exploitation
Exploiting age, disability, or socio-economic situation to distort behaviour.
Example: a toy chatbot manipulates a child into revealing family details.
(c) Social scoring
Public or private social scoring leading to detrimental treatment.
Example: a government scores citizens' "trustworthiness" and denies benefits based on the score.
(d) Individual predictive policing
Predicting a person's risk of offending based solely on profiling.
Example: police flag a person as a future criminal based on their profile alone — banned; crime-pattern analysis is a different, high-risk category.
(e) Untargeted facial scraping
Scraping the internet or CCTV for facial images to build or expand databases.
Example: a company harvests social-media photos to train a facial-recognition database.
(f) Emotion inference at work/school
Inferring emotions in workplaces and education.
Example: a call-centre AI reads agents' emotions from their voices to score performance — banned in the workplace.
(g) Sensitive biometric categorisation
Categorising people by race, religion, sexual orientation, etc., from biometrics.
Example: a system classifies faces by presumed sexual orientation — banned.
(h) Real-time remote biometric ID in public
Real-time identification in public spaces, with three narrow exceptions (terrorism, serious crime, search for victims) and judicial authorisation.
Example: police may use live facial recognition to find a kidnapped child — but only with a court order and time/place limits.
Exam trap — emotion recognition in retailEmotion recognition in a retail store is limited-risk (Art. 50 transparency duty), NOT prohibited. Only emotion inference in workplaces and education is banned under Art. 5(f). The exam sets this trap deliberately — read the context before you pick "prohibited".
2.3 Key dates — including the Digital Omnibus shifts
Obligation
Original date
Omnibus shift
Prohibitions (Art. 5)
2 Feb 2025
Unchanged
GPAI transparency (Art. 50)
2 Aug 2025
Unchanged
General application + Art. 50
2 Aug 2026
Unchanged
Annex III high-risk obligations
2 Aug 2026
→ 2 Dec 2027
Annex I (embedded in regulated products)
2 Aug 2027
→ 2 Aug 2028
Exam memory hook — "timeline relief, not repeal"The Digital Omnibus (in force 27 Jul 2026) delayed the Annex III and Annex I obligations but did not remove them. If a question says the EU "dropped" or "scrapped" high-risk rules, that is wrong — the obligations still land, just later.[Digital Omnibus, Council final approval 29 Jun 2026]
2.4 Systemic-risk GPAI & the 10^25 threshold
Exam anchor — Art. 51A general-purpose AI model is presumed to pose systemic risk when its training compute exceeds 10^25 FLOPs. Systemic-risk models face extra duties: risk assessment, adversarial testing, incident reporting, and cybersecurity protection.[EU AI Act Art. 51]
In plain words: a frontier lab trains a model on a massive cluster — past the 10^25 FLOPs line, the model is presumed dangerous enough to need extra testing and reporting. The number is the exam tell: 10 to the power of 25.
3
BoK Domain II.A — The US patchwork
The US: Sectoral Laws, No Federal Omnibus
The US has no single federal AI law. Instead, a patchwork of sectoral statutes, state laws, and voluntary frameworks. The exam tests which law covers which activity — and the fact that NIST's framework is voluntary, not mandatory.
3.1 The sectoral statutes
Law
What it covers
Plain-words example
HIPAA
Health data — privacy, security, breach notification for covered entities
A hospital's AI that reads patient records must follow HIPAA's security rules for that data
FCRA
Credit reporting and consumer reports — accuracy, disputes, adverse-action notices
An AI that scores a loan applicant is a "consumer report" — the applicant must be told and given a dispute path
ECPA
Wiretapping and electronic communications interception
An AI that records and analyses customer-service calls must respect consent rules for interception
FTC Act §5
Unfair or deceptive acts or practices
An AI chatbot that hides it is a bot, or a model that silently discriminates, can be an FTC enforcement target
ADA
Disability discrimination
An AI hiring tool that filters out candidates with disabilities can violate the ADA
Title VII
Employment discrimination
An AI resume screener with disparate impact on protected groups faces Title VII liability
Exam anchor — FCRA and AIWhen an AI system produces a consumer report used for credit, employment, or insurance decisions, the FCRA's adverse-action notice duty applies: the consumer must be told the decision and the reasons, and given a chance to dispute. The exam pairs this with GDPR Art. 22 — same idea, different statute.
3.2 State laws
CCPA / CPRA (California)
Consumer privacy rights: access, deletion, opt-out of sale/sharing, and (CPRA) opt-out of automated decision-making in some cases.
Example: a Californian user asks a retailer's AI to stop using their data for personalised pricing.
BIPA (Illinois)
Biometric privacy — written consent before collecting biometric identifiers.
Example: a gym's facial-recognition check-in must get written consent from members first.
State AI laws (2024-2026 wave)
Colorado AI Act, Utah AI Policy Act, California AI transparency bills — a growing patchwork with notice, disclosure, and risk-assessment duties.
Example: a Colorado chatbot must disclose it is AI; a California deepfake must be labelled.
3.3 NIST AI RMF 1.0 — the voluntary framework
Exam anchor — G-M-M-MNIST AI RMF 1.0 (Jan 2023) has four functions: Govern – Map – Measure – Manage. Govern is the core that wraps the other three. It is voluntary — the exam contrasts it with the EU AI Act's mandatory compliance.[NIST AI RMF 1.0]
Function
What it does
Plain-words example
Govern
Risk-management culture, policies, roles, accountability — the core
The board approves an AI risk appetite and names an AI governance officer
Map
Understand context: use case, stakeholders, benefits, risks
The team documents who the hiring model affects and what could go wrong for each group
Measure
Test and evaluate: metrics, bias testing, red-teaming, baselines
Model accuracy is measured per demographic group, not just overall
Manage
Act on findings: mitigate, implement controls, monitor
A bias finding triggers retraining with rebalanced data and a new threshold
Exam trap — voluntary vs mandatoryNIST AI RMF is voluntary. The EU AI Act is mandatory. A question that implies NIST compliance is legally required is wrong — unless a specific law (like a state statute) incorporates it.
4
BoK Domain II.B — The standards layer
ISO 42001, OECD Principles, UNESCO
Three international instruments, three different legal natures: a certifiable management standard, a set of non-binding principles, and an ethics recommendation. The exam tests which is which.
4.1 ISO/IEC 42001:2023 — the certifiable AI management system
Exam anchor — PDCA + certifiableISO/IEC 42001:2023 is the first certifiable AI management-system standard. It follows the Plan – Do – Check – Act (PDCA) cycle, like ISO 27001 for information security. Annex A lists controls across the AI lifecycle — from data acquisition to model deployment and monitoring.[ISO/IEC 42001:2023]
PDCA phase
What happens
Plain-words example
Plan
Set the AI policy, objectives, risk appetite, and scope of the management system
A consultancy writes its AI policy and decides which systems the management system covers
Do
Run the AI lifecycle with the controls: risk assessments, data governance, documentation
The team builds a credit model with documented data lineage and bias tests
Check
Audit, measure, and review performance against objectives
An internal audit finds the model's monitoring thresholds were never set
Act
Correct, improve, and feed findings back into the system
The team fixes the thresholds and updates the policy so it cannot recur
In plain words: ISO 42001 is like a quality-management badge for AI. A company that gets certified proves it has a working system of policies, risk assessments, and audits — not just a one-off checklist. The exam tell: "certification" and "management system" point to ISO 42001.
4.2 OECD AI Principles
Exam anchor — five principles, non-bindingThe OECD AI Principles (2019, updated 2024) are non-binding recommendations: (1) inclusive growth and sustainable development; (2) human-centred values and fairness; (3) transparency and explainability; (4) robustness, security and safety; (5) accountability. They are the international baseline most other frameworks reference.[OECD AI Principles]
In plain words: when a government writes its national AI strategy, it usually starts by saying "we follow the OECD principles" — a shared vocabulary for trustworthy AI. They are guidance, not law: no regulator fines you for breaching an OECD principle.
4.3 UNESCO Recommendation on the Ethics of AI
Exam anchor — the ethics layerUNESCO's Recommendation on the Ethics of AI (2021) is the first global normative instrument on AI ethics. It sets values and principles — human dignity, human rights, transparency, fairness, accountability — and asks member states to implement them through law, policy, and education. Like the OECD principles, it is non-binding but influential.[UNESCO Recommendation on the Ethics of AI, 2021]
In plain words: UNESCO is the "ethics charter" layer — the values that laws and standards are supposed to operationalise. If a question asks which instrument is about ethics values rather than enforceable rules, the answer is UNESCO.
5
BoK Domain II.A — The Singapore stack
Singapore: PDPA, MGF, AI Verify, FEAT
Singapore's approach is framework-first: a privacy law (PDPA), two governance frameworks (MGF 2020 + GenAI 2024), a testing toolkit (AI Verify), and a sectoral fairness guide for finance (FEAT).
5.1 PDPA — the privacy law
Exam anchor — PDPA basicsThe Personal Data Protection Act (PDPA) governs personal data in Singapore: consent (or deemed consent / legitimate interests), purpose limitation, notification, access and correction, retention limits, and transfer restrictions. The PDPC enforces it. Unlike the GDPR, the PDPA has no general right to object to automated decisions — but the PDPC's advisory guidelines address AI and automated decision-making.[PDPA 2012, as amended]
In plain words: a Singapore retailer's AI loyalty engine must tell customers what data it collects and why, get consent where needed, and delete data when the purpose ends. The PDPC can fine for breaches — up to 10% of annual turnover in Singapore (or S$1M, whichever is higher) for serious breaches.
5.2 Model AI Governance Framework (MGF) 2020 + GenAI 2024
Framework
Structure
Plain-words example
MGF 2nd ed. (2020)
Four areas: internal governance, human oversight, operations management, stakeholder interaction
A fintech sets human oversight by weighing harm severity × probability against commercial considerations
GenAI Framework (2024)
Nine dimensions: accountability, safety, transparency, fairness, data governance, security, incident reporting, testing, international cooperation
A chatbot vendor documents its model's limitations, tests for jailbreaks, and publishes an incident-reporting channel
Exam anchor — risk-weighted human oversightThe MGF's signature concept: the level of human oversight should be proportional to the risk — severity × probability of harm. High-risk, high-impact AI gets human-in-the-loop; low-risk gets lighter oversight. The exam contrasts this with the EU's fixed risk tiers.
5.3 AI Verify & MAS FEAT
AI Verify
Singapore's testing toolkit and governance framework for AI — a self-assessment and testing suite covering transparency, explainability, fairness, robustness, and safety.
Example: a company runs AI Verify's tests on its hiring model and publishes the results as a transparency artefact.
MAS FEAT
The Monetary Authority of Singapore's principles for Fairness, Ethics, Accountability, and Transparency in financial AI — aimed at banks and insurers.
Example: a bank's credit-scoring AI must be explainable to customers and fair across demographic groups, per FEAT.
Why this matters: Singapore is the exam's "framework-first" jurisdiction — voluntary frameworks plus a privacy law, rather than a dedicated AI statute. If a question asks which Singapore instrument is legally binding, the answer is the PDPA; the MGF, AI Verify, and FEAT are guidance.
6
BoK Domain II.C — The surrounding law
Other Laws That Touch AI
AI does not live in a privacy bubble. Copyright, trade secrets, consumer protection, employment, and sectoral rules all apply — and the exam tests which law answers which problem.
6.1 IP & copyright
Issue
The rule
Plain-words example
Training on copyrighted works
Depends on jurisdiction: fair use (US), text-and-data-mining exceptions (EU), or licence requirements
A generative-AI vendor must confirm its training corpus is licensed or within an exception — or face infringement claims
AI-generated output
Copyright in AI output is unsettled; human authorship is usually required
A company cannot assume its AI-generated marketing images are copyrightable — check the jurisdiction's authorship rules
Trade secrets
Protecting model weights, training data, and prompts as confidential information
A vendor's model weights are its crown jewels — the licence must restrict reverse engineering and disclosure
Exam anchor — the IP governance angleBoK v2.1 added IP governance: organisations need policies for what AI may ingest, what it may output, and who owns the rights. The exam tests the practical question — "which clause matters in this AI vendor contract?" — and the answer is usually data ownership and IP indemnities.
6.2 Consumer protection & product liability
Consumer protection
Unfair or deceptive practices, product safety, and advertising rules apply to AI products and services.
Example: an AI "health coach" that makes unverified medical claims is a consumer-protection problem, not just a privacy one.
Product liability
Who is liable when an AI product causes harm — the manufacturer, the software vendor, or the deployer?
Example: a defective AI-assisted medical device injures a patient — the liability chain runs through the manufacturer and the deployer's duties.
Liability reform
New rules (e.g., EU AI Liability Directive proposals) change how damages from AI systems are allocated.
Example: a proposed EU directive shifts the burden of proof so a harmed consumer does not have to explain the AI's inner workings.
6.3 Employment & sectoral law
Area
How it applies
Plain-words example
Employment law
Hiring, monitoring, and termination decisions by AI must not discriminate; notice and transparency duties apply
An AI that screens resumes must be tested for disparate impact on protected groups
Workplace monitoring
Recording and analysing workers (calls, keystrokes, emotion) is restricted by privacy and labour rules
A call-centre AI that scores agents' emotions may breach workplace-privacy rules
Sectoral regulators
Finance (MAS, SEC, FCA), health (HSA, FDA, EMA), and other regulators impose their own AI expectations
A bank's credit model must satisfy the MAS's FEAT principles on top of the PDPA
In plain words: the same AI system can trip five different laws at once — privacy (PDPA/GDPR), discrimination (employment law), consumer protection, IP, and a sectoral rule. The exam asks you to pick which law answers a specific harm, so learn the mapping, not just the names.
7
Easily confused — exam differentiators
Compare & Contrast
Four comparison tables that decide Domain II questions. If you can fill these from memory, the legal layer is largely yours.
7.1 GDPR vs PDPA vs US
GDPR (EU)
PDPA (SG)
US (federal)
Nature
Comprehensive privacy regulation
Comprehensive privacy regulation
Sectoral statutes + state laws; no omnibus
Automated decisions
Art. 22 right not to be subject to solely automated decisions
No general right; PDPC guidelines address AI
FCRA adverse-action notice; state laws (e.g., CPRA opt-out)
Impact assessment
DPIA where high risk (Art. 35)
DPIA-style assessments encouraged; PDPC guidance
No general federal DPIA; state AI laws add risk assessments
Enforcement
DPAs; fines up to €20M/4%
PDPC; fines up to 10% of turnover or S$1M
FTC, sectoral agencies, state AGs
Exam tell
"solely automated", "DPIA", "Art. 22"
"consent", "PDPC", "notification"
"sectoral", "FCRA", "no federal omnibus"
7.2 DPIA vs FRIA vs AIA
DPIA (GDPR Art. 35)
FRIA (fundamental rights)
AIA (algorithmic impact assessment)
Focus
Personal-data protection risks
Fundamental rights and freedoms
Algorithmic/systemic risks and impacts
Trigger
High risk to individuals' rights from processing
High-risk AI per EU AI Act (Art. 27)
Organisational policy or law (e.g., NYC Local Law 144)
Who
Controller
Deployer of high-risk AI
Deployer / organisation
Exam tell
"personal data", "Art. 35"
"fundamental rights", "Art. 27"
"algorithmic", "bias audit"
7.3 ISO 42001 vs NIST RMF
ISO/IEC 42001
NIST AI RMF
Type
Management-system standard (certifiable)
Risk-management framework (voluntary)
Structure
Plan–Do–Check–Act
Govern–Map–Measure–Manage
Best for
Formal certification and audits
Designing risk processes
Exam tell
"certification", "management system"
"functions", "GMMM"
7.4 Provider vs deployer obligations
Provider
Deployer
Who
Develops the AI system and places it on the market
Use per instructions, human oversight, monitoring, data governance, transparency to users, incident reporting
Exam tell
"developed", "placed on the market", "conformity"
"uses", "oversight", "monitoring", "instructions"
Exam trap — the distributor is not the providerUnder the EU AI Act, a distributor or importer is a separate operator role in the supply chain — not the provider. The provider is the entity that developed the system and placed it on the market. If a question says "the provider is the company and its distribution network", that is wrong.[EU AI Act Art. 3]
8
Active recall · 20 cards
Flip Cards: The Legal Layer
Front = term. Back = definition + exam tip. Click to flip; keyboard Enter/Space works too. Best score persists in this browser.
9
Self-test · Exam traps
Eight Exam Traps
TRUE / FALSE — instant feedback per question, score tallied at the bottom. Best score persists in this browser.
10
Exam-day readiness
Before Thursday — The Checklist
Tap each item as you master it. The goal: fill every box from memory, not recognition.
✓Recite the GDPR Art. 22 rule: no decisions based solely on automated processing with legal/significant effects — with the three exceptions and the human-intervention right.
✓Recite the DPIA trigger (Art. 35): processing likely to result in high risk — new tech, profiling, large-scale special data, public monitoring — and the four required contents.
✓Explain why pseudonymised ≠ anonymised (Recital 26) with a destroy-the-key example.
✓Recite the three fine tiers (€35M/7% · €15M/3% · €7.5M/1%) and the SME lower-of rule.
✓List the eight prohibited practices (Art. 5(a)-(h)) — and the retail emotion-recognition trap.
✓Recite the key dates: prohibitions 2 Feb 2025, GPAI transparency 2 Aug 2025, general application 2 Aug 2026, Annex III → 2 Dec 2027, Annex I → 2 Aug 2028.
✓Name the US sectoral map: HIPAA (health), FCRA (credit), ECPA (interception), FTC Act §5 (deceptive), ADA/Title VII (employment) — and why there is no federal omnibus.
✓Recite NIST G-M-M-M (voluntary) vs ISO 42001 PDCA (certifiable) — and which exam tell points to which.
✓Recite the Singapore stack: PDPA (binding), MGF 2020 + GenAI 2024 (frameworks), AI Verify (testing), MAS FEAT (finance).
✓Distinguish DPIA vs FRIA vs AIA and provider vs deployer — and why a distributor is not a provider.
§
Citation ledger
Sources
IAPP AIGP Body of Knowledge v2.1 — Domain II (Laws, Standards & Frameworks)Primary exam syllabus anchor: GDPR, EU AI Act, US, ISO, OECD, UNESCO, Singapore, other laws, roles, assessments
EU AI Act (Regulation (EU) 2024/1689) — Art. 3, 5, 27, 50, 51, 99Definitions, prohibited practices, FRIA, transparency, systemic risk, fines
Digital Omnibus (Regulation (EU) 2026/XXXX) — Council final approval 29 Jun 2026, in force 27 Jul 2026Annex III → 2 Dec 2027; Annex I → 2 Aug 2028; prohibitions/GPAI/general application unchanged
NIST AI Risk Management Framework 1.0 (January 2023)Govern–Map–Measure–Manage; voluntary
ISO/IEC 42001:2023 — AI management systemsPDCA cycle; certifiable; Annex A controls
OECD AI Principles (2019, updated 2024)Five non-binding principles; international baseline
UNESCO Recommendation on the Ethics of AI (2021)First global normative instrument on AI ethics; non-binding