Site navigation

OpenAI Changes Data Controller in Bid to Adhere to GDPR

Elizabeth Greenberg

,

openai gdpr
The move comes as the AI company faces a lawsuit over alleged breaches in GDPR. 

OpenAI, the prolific AI company behind ChatGPT, has announced plans to change its official data controller for EU customers to Ireland in a bid to assuage concerns over data protection breaches.

The company, based in California, has already been met with a flurry of data controversy over its collection and use of personal data, not to mention just the tip of the copyright iceberg lurking in the murky waters of AI ethical debate.

The announcement follows the opening of OpenAI’s Dublin offices in September, but also follows a series of concerns from EU member states over its processing and keeping of personal data.

Particularly, data rights specialists and organisations have claimed that OpenAI lacks a justifiable legal basis for its data practices.

A lawsuit based in Poland has accused the company of violating a swath of GDPR violations, including a lack of legal basis, and not being transparent with users on what it does with their data.

But Poland is not the only country questioning OpenAI – Italy initially banned ChatGPT as it was concerned overall on how the product would comply with GDPR.

This also prompted the EU’s overriding data protection board, the EDPB, to create a dedicated task force to regulate the compliance of OpenAI and to foster cooperation with the company.

In their move to Ireland, OpenAI is handing over the EU data supervision tasks to the Irish Data Protection Authority to handle all EU laws, following the likes of other major US companies like Microsoft, Amazon, Meta, and Google, who also have their European headquarters based in Dublin.


Recommended


While this will make it easier for the EU to work closely with the company, the Irish DPC  has faces backlash for being lenient on big tech companies in their rulings on data breaches, with the EDPB requiring the Irish authority to increase fines and compliance mandates in past cases.

This leniency is however, a major attraction for foreign companies to base their EU headquarters in Ireland in attempts to lessen the blow of major GDPR fines.

While the move will change regulation to be under the EU, the US-based company will still be headquartered in the US, where data protection laws are notably less strict, which sparked the original EU concerns.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data