What Data Is Most Legitimate for a Wellness Smartwatch App to Collect?
An organization is developing a wellness smartwatch application and is considering what information should be collected from the application users. Which of the following is the MOST legitimate information to collect for business reasons in this situation?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests data minimization and purpose limitation; the trap is confusing wellness-related data like sleep or calorie intake with the most legitimate core data needed for a smartwatch's primary function.
In CDPSE exam contexts, the most legitimate data for a wellness smartwatch app is directly tied to its core fitness functionality. Height, weight, and activities are widely accepted as essential, while race, education, and other unrelated or sensitive data should be avoided due to data minimization principles.
Selecting B (sleep schedule and calorie intake) is a common mistake because those seem health-related, but they are not the core data necessary for a wearable's basic operation; height, weight, and activities are more fundamental and less invasive.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option A, 'Height, weight, and activities,' is the most legitimate information because it is directly relevant to the core business purpose of a wellness smartwatch: tracking physical fitness and health metrics. As community comment [2] notes, these data points are 'directly relevant to the core function of a wellness application' and 'essential for tracking fitness and overall health.' Under privacy frameworks like GDPR, personal data collected must be adequate, relevant, and limited to what is necessary for the specified purpose. Height and weight are baseline inputs for calculating calories burned and interpreting activity data, making them permissible business-justified data collection.
Why the Other Options Are Wrong
Option B (sleep schedule and calorie intake) may appear relevant, but these metrics are often optional or secondary features rather than core to the app's basic wellness function; they can also require more explicit consent due to deeper health implications, especially sleep tracking. Option C (education and profession) has no direct connection to wellness app functionality and would violate purpose limitation and data minimization. Option D (race, age, and gender) includes special category data—race and potentially age/gender—that is considered sensitive under privacy regulations and is rarely justified for a general wellness app without a strong, explicit business need and legal basis.
Community Comment Notes
All community comments (100% votes) overwhelmingly support A, with comment [1] simply listing 'A. Height, weight, and activities' and comment [3] echoing the same. Comment [2] provides a clear rationale: these metrics are directly relevant to the core functions of tracking fitness and health. The consensus reinforces that in privacy exam scenarios, collection should be tied to the product's primary purpose and avoid unnecessary or sensitive data. No comments dispute A, suggesting the answer is straightforward in the CDPSE context.
Official Reference
Exam Strategy
When asked which data is 'most legitimate,' always identify the data that is essential to the primary business function and is the least invasive or sensitive. Eliminate options that are unrelated to the product's purpose or involve special-category data, and remember that data minimization is a core principle in privacy certifications.
Related Analysis
Practice All CDPSE Questions
Access 229 questions with complete answers and detailed explanations.
View Full CDPSE Practice Test →