What Data Is Most Legitimate for a Wellness Smartwatch App to Collect?

An organization is developing a wellness smartwatch application and is considering what information should be collected from the application users. Which of the following is the MOST legitimate information to collect for business reasons in this situation?

  1. Height, weight, and activities Source Reference Answer
  2. Sleep schedule and calorie intake
  3. Education and profession
  4. Race, age, and gender

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests data minimization and purpose limitation; the trap is confusing wellness-related data like sleep or calorie intake with the most legitimate core data needed for a smartwatch's primary function.

In CDPSE exam contexts, the most legitimate data for a wellness smartwatch app is directly tied to its core fitness functionality. Height, weight, and activities are widely accepted as essential, while race, education, and other unrelated or sensitive data should be avoided due to data minimization principles.

Selecting B (sleep schedule and calorie intake) is a common mistake because those seem health-related, but they are not the core data necessary for a wearable's basic operation; height, weight, and activities are more fundamental and less invasive.

Community Discussion (3 comments)

4dfe785 👍 2 Selected: A
Height, weight, and activities are directly relevant to the core function of a wellness application. These data points are essential for tracking fitness and overall health.
Craigp990i 👍 1 Selected: A
A. Height, weight, and activities
shiowbah 👍 4
A. Height, weight, and activities

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option A, 'Height, weight, and activities,' is the most legitimate information because it is directly relevant to the core business purpose of a wellness smartwatch: tracking physical fitness and health metrics. As community comment [2] notes, these data points are 'directly relevant to the core function of a wellness application' and 'essential for tracking fitness and overall health.' Under privacy frameworks like GDPR, personal data collected must be adequate, relevant, and limited to what is necessary for the specified purpose. Height and weight are baseline inputs for calculating calories burned and interpreting activity data, making them permissible business-justified data collection.

Why the Other Options Are Wrong

Option B (sleep schedule and calorie intake) may appear relevant, but these metrics are often optional or secondary features rather than core to the app's basic wellness function; they can also require more explicit consent due to deeper health implications, especially sleep tracking. Option C (education and profession) has no direct connection to wellness app functionality and would violate purpose limitation and data minimization. Option D (race, age, and gender) includes special category data—race and potentially age/gender—that is considered sensitive under privacy regulations and is rarely justified for a general wellness app without a strong, explicit business need and legal basis.

Community Comment Notes

All community comments (100% votes) overwhelmingly support A, with comment [1] simply listing 'A. Height, weight, and activities' and comment [3] echoing the same. Comment [2] provides a clear rationale: these metrics are directly relevant to the core functions of tracking fitness and health. The consensus reinforces that in privacy exam scenarios, collection should be tied to the product's primary purpose and avoid unnecessary or sensitive data. No comments dispute A, suggesting the answer is straightforward in the CDPSE context.

Official Reference

Exam Strategy

When asked which data is 'most legitimate,' always identify the data that is essential to the primary business function and is the least invasive or sensitive. Eliminate options that are unrelated to the product's purpose or involve special-category data, and remember that data minimization is a core principle in privacy certifications.

Related Analysis

Practice All CDPSE Questions

Access 229 questions with complete answers and detailed explanations.

View Full CDPSE Practice Test →

← Back to CDPSE Study Guide