Site navigation

Italian DPA Says OpenAI in Breach of GDPR

Elizabeth Greenberg

,

openAI gdpr
The new ruling could challenge the very foundation of how large language models are able to function and process data. 

The Italian Data Protection Authority (DPA) has claimed that OpenAI is in breach of GDPR, the EU’s data protection laws, in a new announcement.

This follows the initial ban the Italian authority placed on the creator of ChatGPT in March 2023, following concerns it did not uphold the EU’s onerous data regulations.

Though the ban was swiftly lifted after only four weeks, an investigation lead to the Italian DPA concluding that OpenAI had been in breach of provisions in the EU GDPR.

Prior to this, Italy’s DPA had said they were happy with the ‘measures’ OpenAI had claimed to take in order to meet GDPR compliance.

After their “fact-finding activity”, however, the authority has confirmed their suspicions and claims that OpenAI is in breach of GDPR.

If found in breach of GDPR, companies risk being fined up to €20M, or up to 4% of their global annual turnover, whichever amount is higher.

But more risky to OpenAI is that GDPR can force them to change their data handling practices to come under compliance, or risk being banned from the European market altogether.

While the Italian DPA did not disclose the exact provisions OpenAI was found in breach of, they did provide a list of concerns which lead them to the initial ban.

This included a lack of legal basis for collecting personal data to train their AI models, concerns over the AI models’ quirk to hallucinate false information, and child safety concerns.

Most detrimental, and potentially most pertinent, to OpenAI’s model is the legal basis they use to collect and process personal data.

In order to run their ChatGPT and other GPT models, OpenAI has essentially scrapped the internet of data, including potentially personal data.

The company made no attempt to ask for consent from web users before scraping the data of millions across the web.


Recommended


It is increasingly difficult to track where ChatGPT got all this data from, and so it would also be rather difficult to prove that ChatGPT’s data harvesting was of legitimate interest, a legal basis which would also allow users to object to.

If these do get challenged, it could confound the very function of ChatGPT and other large language models (LLMs).

OpenAI will have thirty days to produce a counterclaim against the alleged breaches, and the Italian DPA will take into account the work in progress with the EU task force formed to monitor AI.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data