OpenAI – Violation Found (Italy, 2023)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
OpenAI was investigated for not providing clear information about how it collects and uses personal data in its ChatGPT service. This is significant because it shows that companies must be transparent about their data practices. Website operators should ensure they communicate clearly with users about their data usage.
What happened
OpenAI did not provide adequate information about data processing and failed to verify user ages for its ChatGPT service.
Who was affected
Users of ChatGPT and individuals whose data was collected online without proper notice.
What the authority found
The Garante per la protezione dei dati personali found that OpenAI did not comply with its obligations under data protection laws.
Why this matters
This investigation underscores the importance of transparency in data practices. Website operators should clearly inform users about how their data is used and ensure compliance with age verification requirements.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The Italian DPA after receiving complaint from Inder Kahlon on 24th February 2023 (Numero protocollo: 0033835) opened an investigation concerning ChatGPT, an AI service offered by the American company OpenAI. The investigation focused on three main areas. First, the controller did not provide the data subjects whose personal data had been collected through the Internet with appropriate information about the processing. Second, the DPA found that ChatGPT final outcome – its “answers” – despite based also on personal data and thus often containing personal data, did not always represent reality in an accurate way. Finally, the investigation showed that OpenAI did not adopt any measure to check that users were above the minimum age requirement of 13 years. The Italian DPA held that the controller did not comply with its obligation to provide data subjects with a privacy policy pursuant to Article 13 GDPR. Moreover, the collection of personal data and their use in the training of ChatGPT algorithms were undertaken in lack of a proper legal basis,in violation of Article 5 and 6 GDPR. Concerning specifically data of people other than the users, namely those data subjects whose data were collected on the internet, the DPA found that the algorithms behind the functioning of ChatGPT did not guarantee the principle of accuracy as enshrined in Article 5(1)(d). Finally, the DPA also considered that the lack of any mechanism to check the age of the users entailed a violation of Article 8 GDPR. In light of the above and in the context of an urgency procedure, the DPA imposed on OpenAI a temporary limitation of processing pursuant to Article 58(2)(f) GDPR. Such limitation concerns all processing operations involving data subjects on the Italian territory.
Outcome
Violation Found
The DPA found a violation but did not impose a fine.
Related Enforcement Actions (1)
Other enforcement actions involving OpenAI in IT
Details
Decision Date
30 March 2023
Authority
Garante per la protezione dei dati personali
GDPRhub ID
gdprhub-5777About this data
Cite as: Cookie Fines. OpenAI - Italy (2023). Retrieved from cookiefines.eu
Last updated: