Security and privacy
OpenAI under the scrutiny of the Polish UODO. Does ChatGPT process data in violation of the law?
The Personal Data Protection Office is considering a complaint about ChatGPT, in which the complainant accuses the tool's creator - OpenAI company, that it processes data in a way that is illegal, unreliable, and the principles on which this takes place are not transparent - we read on the UODO website.
The Polish Office for Personal Data Protection (UODO) announced the initiation of proceedings against OpenAI, the creator of ChatGPT. In connection with the received complaint, UODO wants to obtain information from the company about how it processes personal data.
The complainant, whose data was not disclosed, turned to UODO after his requests related to the exercise of rights that he is entitled to under the GDPR were not fulfilled by OpenAI. ChatGPT, in response to the inquiry, generated false information about the complainant. The request for their correction was not fulfilled by OpenAI, even though every administrator has an obligation to process correct data. The complainant also failed to find out what data about him is processed by ChatGPT. There is a lot to suggest that the company provided misleading and internally inconsistent responses to these requests.
– The case concerns the violation of many personal data protection regulations, so we will ask Open AI to answer a series of questions in order to conduct the administrative proceedings thoroughly – comments Jan Nowak, President of UODO.
– The Office takes the matter very seriously. UODO has had doubts about the compliance of ChatGPT's operation with European personal data protection and privacy principles for some time, and the European Data Protection Board has set up a special working group on OpenAI, which will also assess the company's activities for compliance with GDPR principles – adds Nowak.
Jakub Groszkowski, Deputy President of UODO, also commented on the matter, pointing out that the development of technology, even as groundbreaking as large language models (LLM), should take place with respect for the rights of individuals arising not only from the GDPR. UODO intends to scrutinize OpenAI's activities in Poland, and will inform about the results of the proceedings in separate announcements.
"The proceedings will certainly be difficult, as they concern a company located outside the borders of the European Union, and ChatGPT itself is a new and really still undiscovered tool using generative artificial intelligence" - we read in the announcement on the UODO website.