OpenAI, the prolific AI company behind ChatGPT, has announced plans to change its official data controller for EU customers to Ireland in a bid to assuage concerns over data protection breaches.
The company, based in California, has already been met with a flurry of data controversy over its collection and use of personal data, not to mention just the tip of the copyright iceberg lurking in the murky waters of AI ethical debate.
The announcement follows the opening of OpenAI’s Dublin offices in September, but also follows a series of concerns from EU member states over its processing and keeping of personal data.
Particularly, data rights specialists and organisations have claimed that OpenAI lacks a justifiable legal basis for its data practices.
A lawsuit based in Poland has accused the company of violating a swath of GDPR violations, including a lack of legal basis, and not being transparent with users on what it does with their data.
But Poland is not the only country questioning OpenAI – Italy initially banned ChatGPT as it was concerned overall on how the product would comply with GDPR.
This also prompted the EU’s overriding data protection board, the EDPB, to create a dedicated task force to regulate the compliance of OpenAI and to foster cooperation with the company.
In their move to Ireland, OpenAI is handing over the EU data supervision tasks to the Irish Data Protection Authority to handle all EU laws, following the likes of other major US companies like Microsoft, Amazon, Meta, and Google, who also have their European headquarters based in Dublin.
Recommended
- EU to Change GDPR Cross-Border Regulations
- OpenAI Faces Lawsuit Over Potential ChatGPT GDPR Violations
- EU Creates ChatGPT Task Force to Keep Up with AI Developments
While this will make it easier for the EU to work closely with the company, the Irish DPC has faces backlash for being lenient on big tech companies in their rulings on data breaches, with the EDPB requiring the Irish authority to increase fines and compliance mandates in past cases.
This leniency is however, a major attraction for foreign companies to base their EU headquarters in Ireland in attempts to lessen the blow of major GDPR fines.
While the move will change regulation to be under the EU, the US-based company will still be headquartered in the US, where data protection laws are notably less strict, which sparked the original EU concerns.





