{"id":5636,"date":"2023-04-17T08:47:17","date_gmt":"2023-04-17T08:47:17","guid":{"rendered":"https:\/\/www.ubiscore.com\/?p=5636"},"modified":"2023-04-19T18:33:42","modified_gmt":"2023-04-19T18:33:42","slug":"are-the-gdpr-walls-closing-in-on-openai-no-italy-did-not-ban-chatgpt","status":"publish","type":"post","link":"https:\/\/www.ubiscore.com\/de\/blog\/are-the-gdpr-walls-closing-in-on-openai-no-italy-did-not-ban-chatgpt\/","title":{"rendered":"Are the GDPR Walls Closing in on OpenAI? (NO, Italy did not ban ChatGPT!)"},"content":{"rendered":"<p><img fetchpriority=\"high\" decoding=\"async\" class=\"wp-image-5631 aligncenter\" src=\"https:\/\/www.ubiscore.com\/wp-content\/uploads\/2023\/04\/are-the-gdpr-walls-closing-in-on-open-ai-no-italy-did-not-ban-chat-gpt-300x158.png\" alt=\"are-the-gdpr-walls-closing-in-on-open-ai-no-italy-did-not-ban-chat-gpt\" width=\"815\" height=\"429\" srcset=\"https:\/\/www.ubiscore.com\/wp-content\/uploads\/2023\/04\/are-the-gdpr-walls-closing-in-on-open-ai-no-italy-did-not-ban-chat-gpt-300x158.png 300w, https:\/\/www.ubiscore.com\/wp-content\/uploads\/2023\/04\/are-the-gdpr-walls-closing-in-on-open-ai-no-italy-did-not-ban-chat-gpt-1024x538.png 1024w, https:\/\/www.ubiscore.com\/wp-content\/uploads\/2023\/04\/are-the-gdpr-walls-closing-in-on-open-ai-no-italy-did-not-ban-chat-gpt-768x403.png 768w, https:\/\/www.ubiscore.com\/wp-content\/uploads\/2023\/04\/are-the-gdpr-walls-closing-in-on-open-ai-no-italy-did-not-ban-chat-gpt.png 1200w\" sizes=\"(max-width: 815px) 100vw, 815px\" \/><\/p>\n<p><span data-contrast=\"auto\">OpenAI began as a non-profit that trained open-source AI models on unpublished books. Eight years later, fueled by billion dollars of investment from Microsoft, the company faces allegations of violating European data protection law\u2014and compliance demands that might be impossible to meet.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"auto\">\u2018A Good Outcome for All\u2019<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:360,&quot;335559739&quot;:120,&quot;335559740&quot;:276}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">OpenAI started in 2015, funded by donations from entrepreneurs including Sam Altman (now the company\u2019s CEO), Elon Musk, and Peter Thiel\u2014plus corporations such as Amazon Web Services (AWS), Infosys, and Microsoft.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">OpenAI\u2019s <\/span><a href=\"https:\/\/openai.com\/blog\/introducing-openai\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">stated goal<\/span><\/a><span data-contrast=\"auto\"> was to \u201cadvance digital intelligence in the way that is most likely to benefit humanity as a whole, unconstrained by a need to generate financial return.\u201d<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">It&#8217;s hard to predict when human-level AI might come within reach,\u201d an early OpenAI press release states. \u201cWhen it does, it&#8217;ll be important to have a leading research institution which can prioritise a good outcome for all over its own self-interest\u201d.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">Semi-Supervised Learning<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:320,&quot;335559739&quot;:80,&quot;335559740&quot;:276}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">OpenAI\u2019s most significant work is its GPT series (short for \u201cGenerative Pre-trained Transformer\u201d) of AI models.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">GPT was the first \u201ctransformer\u201d-type AI to receive \u201csemi-supervised\u201d training. Whereas earlier transformers required a lot of costly and time-consuming human intervention, GPT could <\/span><a href=\"https:\/\/cdn.openai.com\/research-covers\/language-unsupervised\/language_understanding_paper.pdf\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">learn from<\/span><\/a><span data-contrast=\"auto\"> large amounts of raw, unlabelled data.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The <\/span><a href=\"https:\/\/openai.com\/research\/language-unsupervised\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">first GPT model<\/span><\/a><span data-contrast=\"auto\"> was trained on literature\u20147,000 unpublished books comprising 4.5 GB of text.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">With GTP\u2019s successor, GPT-2, OpenAI began integrating text scraped from the open web. The model\u2019s training set <\/span><a href=\"https:\/\/cdn.openai.com\/better-language-models\/language_models_are_unsupervised_multitask_learners.pdf\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">included<\/span><\/a><span data-contrast=\"auto\"> \u201call outbound links from Reddit\u2026 which received at least three karma\u201d. As a result, GPT-2 produced more convincing, \u201chuman-like\u201d outputs.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">After some initial reluctance to publicly release the model\u2014supposedly due to concern over its potential to produce disinformation\u2014OpenAI eventually published GPT-2\u2019s source code in February 2019.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">Common Crawl<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:320,&quot;335559739&quot;:80,&quot;335559740&quot;:276}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Shortly before releasing GPT-2, OpenAI <\/span><a href=\"https:\/\/techcrunch.com\/2019\/03\/11\/openai-shifts-from-nonprofit-to-capped-profit-to-attract-capital\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">announced<\/span><\/a><span data-contrast=\"auto\"> that was switching from a non-profit to a \u201ccapped\u201d private company whose profits would never exceed an amount 100 times higher than its original investment.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The following year, OpenAI <\/span><a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2020-06-11\/trillions-of-words-analyzed-openai-sets-loose-ai-language-colossus\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">announced<\/span><\/a><span data-contrast=\"auto\"> GPT-3\u2014a version of which would later power OpenAI\u2019s leading commercial product, ChatGPT.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">GPT-3 was trained on a much larger corpus of data than previous GPT models. Around 60% of GPT-3\u2019s training set came from <\/span><a href=\"https:\/\/commoncrawl.org\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">Common Crawl<\/span><\/a><span data-contrast=\"auto\">, a non-profit that \u201cscrapes\u201d the web each month and provides free access to the resulting dataset.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Common Crawl, a non-profit, has been largely left alone by US authorities and rightsholders. The organisation has <\/span><a href=\"https:\/\/www.forbes.com\/sites\/kalevleetaru\/2017\/09\/28\/common-crawl-and-unlocking-web-archives-for-research\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">defended<\/span><\/a><span data-contrast=\"auto\"> the legality of its operations against allegations of copyright abuse.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Under US law, web scraping is <\/span><a href=\"https:\/\/techcrunch.com\/2022\/04\/18\/web-scraping-legal-court\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">protected by the first amendment<\/span><\/a><span data-contrast=\"auto\">. The legal situation is different in Europe, where a \u201clegal basis\u201d is required for most activities involving personal data (which will inevitably appear in a large enough set of web-scraped data).<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">The Closing of OpenAI<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:320,&quot;335559739&quot;:80,&quot;335559740&quot;:276}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Although OpenAI <\/span><a href=\"https:\/\/openai.com\/blog\/openai-api\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">allowed<\/span><\/a><span data-contrast=\"auto\"> limited third-party access to the GPT-3 API, enabling others to integrate GPT-3 into their products, the company declined to release the model\u2019s source code.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">\u201cIn addition to being a revenue source to help us cover costs in pursuit of our mission, the API has pushed us to sharpen our focus on general-purpose AI technology.\u201d OpenAI <\/span><a href=\"https:\/\/openai.com\/blog\/openai-api\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">said<\/span><\/a><span data-contrast=\"auto\"> in a June 2020 blog post.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">In January, the company received a <\/span><a href=\"https:\/\/www.cnbc.com\/2023\/01\/10\/microsoft-to-invest-10-billion-in-chatgpt-creator-openai-report-says.html\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">$10 billion<\/span><\/a><span data-contrast=\"auto\"> funding injection from Microsoft, which subsequently announced it would integrate OpenAI\u2019s model into the Bing search engine.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">On releasing its most recent GPT model, GPT-4, this March, OpenAI did not publish any information about the model\u2019s size, architecture, or training data, <\/span><a href=\"https:\/\/arxiv.org\/pdf\/2303.08774v3.pdf\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">citing<\/span><\/a><span data-contrast=\"auto\"> the \u201ccompetitive landscape\u201d and \u201csafety implications\u201d.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"3\"><span data-contrast=\"none\">\u2018Plausible-Sounding But Incorrect\u2019<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:320,&quot;335559739&quot;:80,&quot;335559740&quot;:276}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">ChatGPT, the chatbot released by OpenAI last October, runs on GPT-3.5\u2014a fine-tuned version of GPT-3 whose training data includes information published as recently as June 2021.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">ChatGPT\u2019s user-friendly design helped it <\/span><a href=\"https:\/\/www.reuters.com\/technology\/chatgpt-sets-record-fastest-growing-user-base-analyst-note-2023-02-01\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">reportedly<\/span><\/a><span data-contrast=\"auto\"> become history\u2019s fastest-growing app, attracting over 100 million users within a few months of its launch.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Despite the program\u2019s impressively human-like outputs, OpenAI <\/span><a href=\"https:\/\/openai.com\/blog\/chatgpt\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">admitted<\/span><\/a><span data-contrast=\"auto\"> that ChatGPT would sometimes \u201crespond to harmful instructions\u201d, \u201cexhibit biased behaviour\u201d, and produce \u201cplausible-sounding but incorrect or nonsensical answers\u201d.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">OpenAI\u2019s GDPR compliance efforts have been relatively slow. The company published its <\/span><a href=\"https:\/\/openai.com\/policies\/terms-of-use\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">data processing agreement<\/span><\/a><span data-contrast=\"auto\">, a mandatory contract for companies using \u201cdata processors\u201d under the GDPR, on 14 March\u2014some five months after ChatGPT\u2019s launch.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The following week, OpenAI <\/span><a href=\"https:\/\/openai.com\/blog\/march-20-chatgpt-outage\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">notified<\/span><\/a><span data-contrast=\"auto\"> users of a security breach that exposed some users\u2019 private chat topics, names, email addresses, billing addresses, and limited payment information. It was this relatively minor incident that led to OpenAI\u2019s first reckoning under the GDPR.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"2\"><span data-contrast=\"auto\">OpenAI\u2019s GDPR Reckoning<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:360,&quot;335559739&quot;:120,&quot;335559740&quot;:276}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Italy\u2019s data protection authority (DPA), the Garante, was the first regulator to directly challenge OpenAI, announcing <\/span><a href=\"https:\/\/www.garanteprivacy.it\/web\/guest\/home\/docweb\/-\/docweb-display\/docweb\/9870832\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">action<\/span><\/a><span data-contrast=\"auto\"> against the company on 31 March.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">While the Garante\u2019s intervention was triggered by ChatGPT\u2019s security incident, the regulator issued an emergency order addressing a much broader set of issues. The Garante alleged that OpenAI:<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<ul>\n<li data-leveltext=\"\u25cf\" data-font=\"Calibri\" data-listid=\"2\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Was not sufficiently transparent about how ChatGPT used personal data.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\u25cf\" data-font=\"Calibri\" data-listid=\"2\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span data-contrast=\"auto\">Had no legal basis for collecting personal data to train its algorithms.<\/span><\/li>\n<li data-leveltext=\"\u25cf\" data-font=\"Calibri\" data-listid=\"2\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span data-contrast=\"auto\">Processed inaccurate personal data about people via ChatGPT.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\u25cf\" data-font=\"Calibri\" data-listid=\"2\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span data-contrast=\"auto\">Had no age verification system in place to stop children from using ChatGPT.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><span data-contrast=\"auto\">The regulator cited violations of Articles 5, 6, 8, 13, and 25 of the GDPR\u2014provisions relating to the GDPR\u2019s principles, its legal bases, the rules on delivering online services to children, transparency obligations, and the concept of \u201cdata protection by design\u201d.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The Garante\u2019s order against OpenAI required the \u201ctemporary limitation of the processing of personal data of data subjects established in the Italian territory\u201d. The company had 20 days to explain how it would address the compliance issues alleged by the regulator.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">In <\/span><a href=\"https:\/\/twitter.com\/sama\/status\/1641897800236687360\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">response<\/span><\/a><span data-contrast=\"auto\">, OpenAI \u201cceased offering ChatGPT in Italy\u201d.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">Not a Block or a Ban<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:320,&quot;335559739&quot;:80,&quot;335559740&quot;:276}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Italy\u2019s action against OpenAI provoked headlines such as \u201c<\/span><a href=\"https:\/\/www.cnn.com\/2023\/03\/31\/tech\/chatgpt-blocked-italy\/index.html\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">Italy blocks ChatGPT over privacy concerns<\/span><\/a><span data-contrast=\"auto\">\u201d and \u201c<\/span><a href=\"https:\/\/www.bbc.co.uk\/news\/technology-65139406\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">ChatGPT banned in Italy<\/span><\/a><span data-contrast=\"auto\">\u201d.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">But rather than having been \u201cblocked\u201d or \u201cbanned\u201d by Italy, OpenAI chose to restrict Italian users\u2019 access as a means to comply with the regulator\u2019s order.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">In an <\/span><a href=\"https:\/\/www.youtube.com\/watch?v=EnGiAbwjtUE\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">interview<\/span><\/a><span data-contrast=\"auto\"> following OpenAI\u2019s decision, a Garante representative said the company could, in theory, have continued offering ChatGPT\u2014if it could do so without processing any personal data about people in Italy.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">On a technical level, it would be impossible to offer ChatGPT in Italy without processing personal data about Italians. In fact, it\u2019s unclear how OpenAI could have limited all processing of such data\u2014regardless of whether the company blocked ChatGPT.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><span data-contrast=\"auto\">Processing\u201d is defined broadly in the GDPR, covering \u201cany operation\u201d performed on personal data.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">As such, whatever OpenAI did in response to the Garante would have constituted \u201cprocessing\u201d\u2014including deleting personal data in its training set, continuing to store that data, or providing refunds to Italian customers.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">And despite the geo-restriction of ChatGPT, the chatbot would continue to generate inaccurate personal data about people in Italy (which was one of the Garante\u2019s key concerns). There is no clear solution to the \u201caccuracy\u201d problem short of closing down the app altogether.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">Further Investigations<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:320,&quot;335559739&quot;:80,&quot;335559740&quot;:276}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">On 12 April, a week before OpenAI\u2019s original deadline, the Garante <\/span><a href=\"https:\/\/www.garanteprivacy.it\/home\/docweb\/-\/docweb-display\/docweb\/9874751#english\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">announced<\/span><\/a><span data-contrast=\"auto\"> that OpenAI had a further 18 days to bring its operations into compliance with the GDPR.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">By the end of April, OpenAI must:<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<ul>\n<li><span data-contrast=\"auto\">Create a new privacy notice describing the \u201clogic involved\u201d in ChatGPT, plus information about the rights of users and non-users.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\u25cf\" data-font=\"Calibri\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Adopt a new \u201clegal basis\u201d for processing personal data, based either on consent or the company\u2019s \u201clegitimate interests\u201d.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\u25cf\" data-font=\"Calibri\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span data-contrast=\"auto\">Implement a system enabling people to request the correction or erasure of inaccurate personal data, and to object to the use of their personal data in training sets.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\u25cf\" data-font=\"Calibri\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span data-contrast=\"auto\">Prohibit children from using ChatGPT, and, by the end of September, filter out children under 13 and children aged 13-18 whose parents have not provided consent.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\u25cf\" data-font=\"Calibri\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Conduct an awareness-raising campaign across TV, radio, and print media, informing people about the use of personal data in training algorithms.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span data-contrast=\"auto\">The following day, at the <\/span><a href=\"https:\/\/www.reuters.com\/technology\/spains-data-regulator-asks-eu-data-protection-committee-evaluate-chatgpt-issues-2023-04-11\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">request<\/span><\/a><span data-contrast=\"auto\"> of the Spanish regulator, the European Data Protection Board (EDPB) <\/span><a href=\"https:\/\/edpb.europa.eu\/news\/news\/2023\/edpb-resolves-dispute-transfers-meta-and-creates-task-force-chat-gpt_en\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">announced<\/span><\/a><span data-contrast=\"auto\"> a new \u201cdedicated task force\u201d to \u201cfoster cooperation\u201d and \u201cexchange information on possible enforcement actions\u201d against OpenAI.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The next OpenAI enforcement action could come from France, where the country\u2019s regulator is apparently <\/span><a href=\"https:\/\/www.reuters.com\/technology\/french-privacy-watchdog-investigating-complaints-about-chatgpt-2023-04-11\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">investigating complaints<\/span><\/a><span data-contrast=\"auto\"> about the company.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"3\"><span data-contrast=\"none\">The End of the Beginning<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:320,&quot;335559739&quot;:80,&quot;335559740&quot;:276}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">Even if OpenAI manages to satisfy Italy\u2019s demands, the company\u2019s compliance issues are unlikely to go away.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Data protection experts have been highlighting <\/span><a href=\"https:\/\/www.ubiscore.com\/de\/blog\/openais-gpt-4-improved-performance-same-privacy-issues\/\"><span data-contrast=\"none\">conflicts<\/span><\/a><span data-contrast=\"auto\"> between the GDPR\u2019s requirements and the large-scale processing of data that powers large language models like GPT.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">In a 2018 paper titled \u201c<\/span><a href=\"https:\/\/royalsocietypublishing.org\/doi\/10.1098\/rsta.2018.0083\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">Algorithms that remember<\/span><\/a><span data-contrast=\"auto\">\u201d, academics Michael Veale, Lilian Edwards, and Reuben Binns argued that AI models themselves\u2014not only the datasets used to train the models\u2014constitute \u201cpersonal data\u201d under the GDPR.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><span data-contrast=\"auto\">This would mean that AI models are personal data \u201call the way down\u201d\u2014they are trained on personal data, process personal data as inputs, produce personal data as outputs, and, according to the above interpretation, are themselves personal data.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">A recent Oxford University paper <\/span><a href=\"https:\/\/blogs.law.ox.ac.uk\/blog-post\/2023\/03\/regulating-chatgpt-and-other-large-generative-ai-models\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">argues<\/span><\/a><span data-contrast=\"auto\"> that European regulators are \u201cill-prepared for the emergence of this new generation of AI models\u201d\u2014and will remain so even after the passing of the EU\u2019s upcoming <\/span><a href=\"https:\/\/artificialintelligenceact.eu\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">AI Act<\/span><\/a><span data-contrast=\"auto\">.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The GDPR\u2019s principles of fairness, transparency, data minimisation, data accuracy, and its rules on automated decision-making all apply to the training and operation of AI models.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">But full GDPR compliance could seriously undermine OpenAI\u2019s data-hungry operations, and it might be easier for the company to leave Europe altogether.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p>We hope this guide was helpful. Thank you for reading and we wish you the best of luck with improving your company\u2019s privacy practices! Stay tuned for more helpful articles and tips about growing your business and earning trust through data-protection compliance. Test your company\u2019s privacy practices, <a href=\"https:\/\/www.ubiscore.com\/de\/testversion\/\"><span class=\"s2\"><b>CLICK HERE<\/b><\/span><\/a> to receive your instant privacy score now!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>OpenAI began as a non-profit that trained open-source AI models on unpublished books. Eight years later, fueled by billion dollars of investment from Microsoft, the company faces allegations of violating European data protection law\u2014and compliance demands that might be impossible to meet. <\/p>\n","protected":false},"author":9,"featured_media":5632,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_themeisle_gutenberg_block_has_review":false,"footnotes":""},"categories":[35,7],"tags":[],"class_list":["post-5636","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-expertenmeinung","category-unkategorisiert"],"_links":{"self":[{"href":"https:\/\/www.ubiscore.com\/de\/wp-json\/wp\/v2\/posts\/5636","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ubiscore.com\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ubiscore.com\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ubiscore.com\/de\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ubiscore.com\/de\/wp-json\/wp\/v2\/comments?post=5636"}],"version-history":[{"count":4,"href":"https:\/\/www.ubiscore.com\/de\/wp-json\/wp\/v2\/posts\/5636\/revisions"}],"predecessor-version":[{"id":5679,"href":"https:\/\/www.ubiscore.com\/de\/wp-json\/wp\/v2\/posts\/5636\/revisions\/5679"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.ubiscore.com\/de\/wp-json\/wp\/v2\/media\/5632"}],"wp:attachment":[{"href":"https:\/\/www.ubiscore.com\/de\/wp-json\/wp\/v2\/media?parent=5636"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ubiscore.com\/de\/wp-json\/wp\/v2\/categories?post=5636"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ubiscore.com\/de\/wp-json\/wp\/v2\/tags?post=5636"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}