OpenAI – €15,000,000 Fine (Italy, 2024)
OpenAI was fined for a data breach that exposed users' personal information, including names and credit card details. This incident occurred due to a technical error that allowed users to see each other's chat histories. This case is significant as it shows the importance of promptly reporting data breaches and protecting user data.
What happened
OpenAI experienced a data breach that exposed users' personal information due to a technical bug.
Who was affected
Users of the ChatGPT service whose personal information was exposed were affected.
What the authority found
The authority found that OpenAI failed to notify the data breach within the required timeframe under GDPR rules.
Why this matters
This ruling serves as a reminder for companies to have robust data protection measures and to act quickly in reporting breaches to protect user privacy.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
On 20 March 2023, a technical bug on the ChatGPT service caused users to view the chat history of other users instead of their own for a limited amount of time. The controller, OpenAI, publicly acknowledged the issue and confirmed that the exposed data included names, surnames, email addresses, and the last four digits and expiration dates of credit cards used for the ChatGPT Plus (the paid version of the service). Following this data breach, the Italian DPA started an ex officio investigation. First, the DPA considered whether the one-stop-shop mechanism would apply. More specifically, the DPA considered that, at the time of the alleged violations, the controller was established in California and did not have any indicated establishment in the EU. In fact, ChatGPT has been available in the EU since 30 November 2022, as also confirmed by the controller. The controller had an establishment in Ireland only from the 15 February 2024. Therefore, the DPA found that, for every alleged violation of the GDPR happened before the 15 February 2024, the one-stop-shop mechanism does not apply and the DPA has jurisdiction to rule on the matter. Second, the Italian DPA concluded its investigation and held that: Violation of Article 33(1) GDPR The controller is under the obligation to notify any data breach to the DPA within 72 hours according to Article 33(1) GDPR. The controller states that it notified the data breach to the Irish DPA, as it was in the process of setting up its Irish registered office when the breach happened. The DPA considered that, during the breach, the controller was based in the U.S.A and did not have any establishment in the EU. The DPA highlighted that, where a proprietor does not have an establishment in the EU, Article 56 GDPR does not apply in favour of the general rule laid out in Article 55(1) GDPR, according to which each supervisory authority is competent to execute the tasks assigned to it and to exercise the powers conferred upon it under the
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (1)
Other enforcement actions involving OpenAI in IT
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
20 December 2024
Authority
Garante per la protezione dei dati personali
Fine Amount
€15,000,000
GDPRhub ID
gdprhub-8679About this data
Cite as: Cookie Fines. OpenAI - Italy (2024). Retrieved from cookiefines.eu
Last updated: