OpenAI under the scrutiny of the Polish UODO. Does ChatGPT process data in violation of the law?

The Personal Data Protection Office is considering a complaint about ChatGPT, in which the complainant accuses the tool's creator - OpenAI company, that it processes data in a way that is illegal, unreliable, and the principles on which this takes place are not transparent - we read on the UODO website.

OpenAI under the scrutiny of the Polish UODO. Does ChatGPT process data in violation of the law?
00:00 00:00

Summary

  • The Polish Office for Personal Data Protection (UODO) has initiated proceedings against OpenAI, the creator of ChatGPT, to investigate how it processes personal data.
  • The action follows a complaint from an individual whose requests related to GDPR rights were not fulfilled by OpenAI. The complainant alleges that ChatGPT generated false information about him and OpenAI failed to correct it.
  • UODO President, Jan Nowak, stated that the case involves the violation of many personal data protection regulations and that OpenAI will be asked a series of questions to conduct the administrative proceedings thoroughly.
  • UODO has had doubts about the compliance of ChatGPT's operation with European personal data protection and privacy principles. The European Data Protection Board has set up a special working group on OpenAI to assess the company's compliance with GDPR principles.
  • Jakub Groszkowski, Deputy President of UODO, emphasized that the development of technology, such as large language models (LLM), should respect individual rights arising from the GDPR. UODO plans to scrutinize OpenAI's activities in Poland.
  • The proceedings are expected to be challenging due to OpenAI being located outside the European Union and the novelty of ChatGPT, a tool using generative artificial intelligence.

The Polish Office for Personal Data Protection (UODO) announced the initiation of proceedings against OpenAI, the creator of ChatGPT. In connection with the received complaint, UODO wants to obtain information from the company about how it processes personal data.

The complainant, whose data was not disclosed, turned to UODO after his requests related to the exercise of rights that he is entitled to under the GDPR were not fulfilled by OpenAI. ChatGPT, in response to the inquiry, generated false information about the complainant. The request for their correction was not fulfilled by OpenAI, even though every administrator has an obligation to process correct data. The complainant also failed to find out what data about him is processed by ChatGPT. There is a lot to suggest that the company provided misleading and internally inconsistent responses to these requests.

– The case concerns the violation of many personal data protection regulations, so we will ask Open AI to answer a series of questions in order to conduct the administrative proceedings thoroughly – comments Jan Nowak, President of UODO.

– The Office takes the matter very seriously. UODO has had doubts about the compliance of ChatGPT's operation with European personal data protection and privacy principles for some time, and the European Data Protection Board has set up a special working group on OpenAI, which will also assess the company's activities for compliance with GDPR principles – adds Nowak.

Jakub Groszkowski, Deputy President of UODO, also commented on the matter, pointing out that the development of technology, even as groundbreaking as large language models (LLM), should take place with respect for the rights of individuals arising not only from the GDPR. UODO intends to scrutinize OpenAI's activities in Poland, and will inform about the results of the proceedings in separate announcements.

"The proceedings will certainly be difficult, as they concern a company located outside the borders of the European Union, and ChatGPT itself is a new and really still undiscovered tool using generative artificial intelligence" - we read in the announcement on the UODO website.