Site navigation

OpenAI Faces Lawsuit Over Potential ChatGPT GDPR Violations

Elizabeth Greenberg

,

chatgpt gdpr
OpenAI’s ChatGPT has come under fire in Poland for potentially breaching GDPR, the EU’s data protection and digital privacy regulations.

A new lawsuit has been submitted to the Polish Data Protection Agency (DPA), alleging that the AI company is infringing on the privacy rights of EU citizens as it does not disclose how it processes personal data.

According to the initial reporting by TechCruch, the 17 page complaint alleges that OpenAI is in breach of a swath of GDPR rules, including having a lawful basis for the collection of personal data, transparency, fairness, privacy by design, and data rights.

The compliant was filed by Lukasz Olejnik, a privacy researcher based in Poland, who is represented by GP Partners, a law firm based in Warsaw.

According to reporting from TechCrunch, Olejnik first discovered a problem when using the website itself to generate a bibliography, and noticed some errors. He got in touch with OpenAI to report the errors and asked to get them corrected.

During the interaction, Olejnik also issued the company a Subject Access Request – under EU law, any EU subject has the right to issue this to a company which processes their data, and the company is obliged to then provide said data to the subject.

Olejnik said that, while OpenAI did disclose some data, the information provided has notable exclusions, such as information about how it processed personal data it used for AI model training. This information must be provided for under law, as part of EU data transparency regulations.

Further, this omittance brings into question OpenAI’s legal basis for processing personal data – in order to process data, a data controller is required to have a formal legal basis under EU law, and part of this formality is the transparent communication of it. In addition, the EU law applies a level of fairness to this basis, meaning that if companies make their legal basis unfairly difficult to understand or to access, they can also be outwith the law.

The lawsuit specifically brings up the issue of personal data used in training the AI, for which OpenAI notably did not ask individuals for permission to use. The company’s AI models has already come under fire for using copyrighted material without specific permissions to train its AI, and there is already a similar lawsuit taking place in the US, which accused the company of data scraping their personal data of millions of people, even children, to use for its AI model.

It even faced a temporary ban in Italy for suspected GDPR non-compliance, but the ban was lifted once OpenAI allowed users to submit to remove their personal data from the chatbot, and that the tool would perform age verification before allowing users to access it. But the lawsuit based in Poland goes much deeper into ChatGPT’s creation and functionality.

“Although OpenAI indicates that the data used to train the [AI] models includes personal data, OpenAI does not actually provide any information about the processing operations involving this data. OpenAI thus violates a fundamental element of the right under Article 15 GDPR, i.e., the obligation to confirm that personal data is being processed,” a portion of the complaint as translated and quoted by Techcrunch read.

“Notably, OpenAI did not include the processing of personal data in connection with model training in the information on categories of personal data or categories of data recipients. Providing a copy of the data also did not include personal data processed for training language models. As it seems, the fact of processing personal data for model training OpenAI hides or at least camouflages intentionally. This is also apparent from OpenAI’s Privacy Policy, which omits in the substantive part the processes involved in processing personal data for training language models.

“OpenAI reports that it does not use so-called ‘training’ data to identify individuals or remember their information, and is working to reduce the amount of personal data processed in the ‘training’ dataset. Although these mechanisms positively affect the level of protection of personal data and comply with the principle of minimization (Article 5(1)(c) of the GDPR), their application does not change the fact that ‘training’ data are processed and include personal data. The provisions of GDPR apply to the processing operations of such data, including the obligation to grant the data subject access to the data and provide the information indicated in Article 15(1) of GDPR,” the report continued.

Based on this, the lawsuit would find OpenAI in violation of transparency terms and fairness key to legally processing personal data, even without the overriding issue of getting individuals consent prior to data processing.


Recommended


Olejnik’s complaint does not stop there, actually, but his original interaction with OpenAI turned out to open a can of pernicious, data privacy-violating, worms.

He is also suing the company for not rectifying incorrect personal information regarding him and his research, which he first discovered when asking ChatGPT to create a bibliography. After his initial complaint, OpenAI only offered to block prompts or requests mentioning him, and then told him it was unable to make the corrections.

Under GDPR, individuals have the right to rectify incorrect personal data on the internet, and companies are liable to provide appropriate channels to do so. This is not the first time ChatGPT has gotten something wrong, however. The AI chatbot is known to have ‘hallucinations’ – in other words, dispel completely false information as facts. The chatbot provided a fake legal suit which claimed a man in Georgia was guilty of fraud and embezzlement, which he was not.

“Given the general and vague description of ChatGPT’s data validity mechanisms, it is highly likely that the inability to correct data is a systemic phenomenon in OpenAI’s data processing, and not just in limited cases,” the complaint read.

The entire lawsuit goes for ChatGPT’s jugular, reading: “OpenAI seems to accept that the ChatGPT tool model that has been developed is simply incompatible with the provisions of GDPR, and it agrees to this state of affairs. This shows a complete disregard for the goals behind the principle of data protection by design.”

Essentially, based on ChatGPT’s original training on personal data, OpenAI’s refusal to disclose how this was done, its incomplete transparency on data processing, and its inability or refusal to comply with the right to rectify, leaves the landmark AI chatbot at the mercy of GDPR regulators.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data