An Ars Technica reader has raised concerns about potential data leakage from ChatGPT, an AI-powered chatbot developed by OpenAI.
Screenshots submitted to the publication on Monday suggest the unauthorised disclosure of sensitive information from private conversations, including login credentials, personal details, and other confidential information.
Following the article’s release, OpenAI has said currently investigating the matter.
What was Leaked and how?
The submitted screenshots provide insight into a troubling breach of privacy within ChatGPT. Two instances, in particular, reveal compromised login credentials and personal details. One screenshot captures a conversation between an employee and the AI chatbot, expressing frustration over technical issues with a pharmacy prescription drug portal. The conversation inadvertently led to the disclosure of usernames and passwords.
The leaked conversations reveal a pattern of data exposure extending beyond login credentials. Identifying information, such as the application’s name and store number associated with the reported problem, are potentially catastrophic with regards to security to data protection.
More Questions Raised about ChatGPT
The Ars Technica report isn’t the first time OpenAI’s LLMs have raised concerns. ChatGPT came under fire late last year in Poland for potentially breaching GDPR, the EU’s data protection and digital privacy regulations.
A lawsuit was been submitted to the Polish Data Protection Agency (DPA), alleging that the AI company is infringing on the privacy rights of EU citizens as it does not disclose how it processes personal data.
According to the initial reportingby TechCruch, the 17 page complaint alleges that OpenAI is in breach of a swath of GDPR rules, including having a lawful basis for the collection of personal data, transparency, fairness, privacy by design, and data rights.
Recommended
- OpenAI Changes Data Controller in Bid to Adhere to GDPR
- OpenAI Faces Lawsuit Over Potential ChatGPT GDPR Violations
- EU Creates ChatGPT Task Force to Keep Up with AI Developments
Much more recently, the Italian Data Protection Authority (DPA) has also claimed that OpenAI is in breach of GDPR.
This follows the initial ban the Italian authority placed on the creator of ChatGPT in March 2023, following concerns it did not uphold the EU’s onerous data regulations.
Though the ban was swiftly lifted after only four weeks, an investigation lead to the Italian DPA concluding that OpenAI had been in breach of provisions in the EU GDPR.





