The Italian Data Protection Authority (DPA) has claimed that OpenAI is in breach of GDPR, the EU’s data protection laws, in a new announcement.
This follows the initial ban the Italian authority placed on the creator of ChatGPT in March 2023, following concerns it did not uphold the EU’s onerous data regulations.
Though the ban was swiftly lifted after only four weeks, an investigation lead to the Italian DPA concluding that OpenAI had been in breach of provisions in the EU GDPR.
Prior to this, Italy’s DPA had said they were happy with the ‘measures’ OpenAI had claimed to take in order to meet GDPR compliance.
After their “fact-finding activity”, however, the authority has confirmed their suspicions and claims that OpenAI is in breach of GDPR.
If found in breach of GDPR, companies risk being fined up to €20M, or up to 4% of their global annual turnover, whichever amount is higher.
But more risky to OpenAI is that GDPR can force them to change their data handling practices to come under compliance, or risk being banned from the European market altogether.
While the Italian DPA did not disclose the exact provisions OpenAI was found in breach of, they did provide a list of concerns which lead them to the initial ban.
This included a lack of legal basis for collecting personal data to train their AI models, concerns over the AI models’ quirk to hallucinate false information, and child safety concerns.
Most detrimental, and potentially most pertinent, to OpenAI’s model is the legal basis they use to collect and process personal data.
In order to run their ChatGPT and other GPT models, OpenAI has essentially scrapped the internet of data, including potentially personal data.
The company made no attempt to ask for consent from web users before scraping the data of millions across the web.
Recommended
- OpenAI Changes Data Controller in Bid to Adhere to GDPR
- OpenAI Faces Lawsuit Over Potential ChatGPT GDPR Violations
- EU Creates ChatGPT Task Force to Keep Up with AI Developments
It is increasingly difficult to track where ChatGPT got all this data from, and so it would also be rather difficult to prove that ChatGPT’s data harvesting was of legitimate interest, a legal basis which would also allow users to object to.
If these do get challenged, it could confound the very function of ChatGPT and other large language models (LLMs).
OpenAI will have thirty days to produce a counterclaim against the alleged breaches, and the Italian DPA will take into account the work in progress with the EU task force formed to monitor AI.





