Privacy

Poland opens privacy probe of ChatGPT following GDPR complaint

Comment

OpenAI logo is being displayed on a mobile phone screen in front of computer screen with the logo of ChatGPT
Image Credits: Didem Mente/Anadolu Agency / Getty Images

OpenAI is facing another investigation into whether its generative AI chatbot, ChatGPT, complies with European Union privacy laws.

Last month a complaint was filed against ChatGPT and OpenAI in Poland, accusing the company of a string of breaches of the EU’s General Data Protection Regulation (GDPR). Yesterday the Polish authority took the unusual step of making a public announcement to confirm it has opened an investigation.

“The Office for Personal Data Protection [UODO] is investigating a complaint about ChatGPT, in which the complainant accuses the tool’s creator, OpenAI, of, among other things, processing data in an unlawful, unreliable manner, and the rules under which this is done are opaque,” the UODO wrote in a press release [translated from Polish to English using DeepL].

The authority said it’s anticipating a “difficult” investigation — noting OpenAI is located outside the EU and flagging the novelty of the generative AI chatbot technology whose compliance it will be examining.

“The case concerns the violation of many provisions of the protection of personal data, so we will ask OpenAI to answer a number of questions in order to thoroughly conduct the administrative proceedings,” said Jan Nowak, president of the UODO, in a statement.

Deputy president, Jakub Groszkowski, added a warning to the authority’s press release — writing that new technologies do not operate outside the legal framework and must respect the GDPR. He said the complaint contains allegations that raise doubts about OpenAI’s systemic approach to European data protection principles, adding that the authority would “clarify these doubts, in particular against the background of the fundamental principle of privacy by design contained in the GDPR”.

The complaint, which was filed by local privacy and security researcher Lukasz Olejnik, accuses OpenAI of a string of breaches of the pan-EU regulation — spanning lawful basis, transparency, fairness, data access rights, and privacy by design.

It focuses on OpenAI’s response to a request by Olejnik to correct incorrect personal data in a biography ChatGPT generated about him — but which OpenAI told him it was unable to do. He also accuses the AI giant of failing to properly respond to his subject access request — and of providing evasive, misleading and internally contradictory answers when he sought to exercise his legal rights to data access.

The tech underlying ChatGPT is a so-called large language model (LLM) — a type of generative AI model that’s trained on masses of natural language data so it can both respond in a human like manner. But also, given the general purpose utility of the tool, it’s evidently been trained on all sorts of types of information so it can respond to different questions and asks — including, in many cases, being fed data about living people.

OpenAI’s scraping of the public Internet for training data, without people’s knowledge or consent, is one of the big factors that’s landed ChatGPT in regulatory hot water in the EU. Its apparent inability to articulate exactly how it’s processing personal data; or to correct mistakes when its AI “hallucinates” and produces false information about named individuals are others.

The bloc regulates how personal data is processed, requiring a processor has a lawful basis to collect and use people’s information. Processors must also meet transparency and fairness requirements. Plus a suite of data access rights are afforded to people in the EU — meaning EU individuals have (among other things) a right to ask for incorrect data about them to be rectified.

Olejnik’s complaint tests OpenAI’s GDPR compliance across a number of those dimensions. So any enforcement could be significant in shaping how generative AI develops.

Reacting to the UODO’s confirmation it’s investigating the ChatGPT complaint, Olejnik told TechCrunch: “Focusing on privacy by design/data protection by design is absolutely critical and I expected this to be the main aspect. So this sounds reasonable. It would concern the design and deployment aspects of LLM systems.”

He previously described the experience of trying to get answers from OpenAI about its processing of his information as feeling like Josef K, in Kafka’s book “The Trial.” “If this may be the Josef K. moment for AI/LLM, let’s hope that it may shed light on the processes involved,” he added now.

The relative speed with which the Polish authority is moving in response to the complaint, as well as its openness about the investigation, does look notable.

It adds to growing regulatory issues OpenAI is facing the European Union. The Polish investigation follows an intervention by Italy’s DPA earlier this year — which led to a temporary suspension of ChatGPT in the country. The scrutiny by the Garante continues, also looking into GDPR compliance concerns attached to factors like lawful basis and data access rights.

Elsewhere, Spain’s DPA has opened a probe. While a taskforce set up via the European Data Protection Board earlier this year is looking at how data protection authorities should respond to the AI chatbot tech with the goal of pushing to find some consensus among the bloc’s privacy watchdogs on how to regulate such novel tech.

The taskforce does not supplant investigations by individual authorities. But, in the future, it may lead to some harmonization in how DPAs approach regulating cutting edge AI. That said, divergence is also possible if there are strong and varied views among DPAs. And it remains to be seen what further enforcement actions the bloc’s watchdogs could take on tools like ChatGPT. (Or, indeed, how quickly they may act.)

In the UODO’s press release — which nods to the existence of the taskforce — its president says the authority is taking the ChatGPT investigation “very seriously”. He also notes the complaint’s allegations are not the first doubts vis-a-vis ChatGPT’s compliance with European data protection and privacy rules.

Discussing the authority’s openness and pace, Maciej Gawronski of law firm GP Partners, which is representing Olejnik for the complaint, told TechCrunch: “UODO is becoming more and more vocal about privacy, data protection, technology and human rights. So, I think, our complaint creates an opportunity for [it] to work on reconciling digital and societal progress with individual agency and human rights.

“Mind that Poland is a very advanced country regarding IT. I would expect UODO to be very reasonable in their approach and proceedings. Of course, as long as OpenAI remains open, for discussion.”

Asked if he’s expecting a quick decision on the complaint, Gawronski added: “The authority is monitoring technology advancements pretty closely. I am at UODO’s conference on new technologies at the moment. UODO has already been approached re AI by various actors. However, I do not expect a fast decision. Nor it is my intention to conclude the proceedings prematurely. I would prefer to have an honest and insightful discussion with OpenAI on what, when, how, and how much, regarding ChatGPT’s GDPR compliance, and in particular how to satisfy rights of the data subject.”

OpenAI was contacted for comment on the Polish DPA’s investigation but did not send any response.

The AI giant is not sitting still in response to an increasingly complex regulatory picture in the EU. It recently announced opening an office in Dublin, Ireland — likely with an eye on building towards streamlining its regulatory situation for data protection if it can funnel any GDPR complaints via Ireland.

However, for now, the US company is not considered “main established” in any EU Member State (including Ireland) for GDPR purposes, since decisions affecting local users continue to be taken at its US HQ in California. So far, the Dublin office is just a tiny satellite. This means data protection authorities across the bloc remain competent to investigate concerns about ChatGPT that arise on their patch. So more investigations could follow.

Complaints which predate any future main establishment status change for OpenAI could also still be filed anywhere in the EU.

ChatGPT-maker OpenAI accused of string of data protection breaches in GDPR complaint filed by privacy researcher

Italy gives OpenAI initial to-do list for lifting ChatGPT suspension order

Sam Altman’s big European tour

More TechCrunch

All cars suffer when the mercury drops, but electric vehicles suffer more than most as heaters draw more power and batteries charge more slowly as the liquid electrolyte inside thickens.…

Porsche invests in battery startup South 8 to boost cold-weather EV performance

Scale AI has raised a $1 billion Series F round from a slew of big-name institutional and corporate investors including Amazon and Meta.

Data-labeling startup Scale AI raises $1B as valuation doubles to $13.8B

The new coalition, Tech Against Scams, will work together to find ways to fight back against the tools used by scammers and to better educate the public against financial scams.

Meta, Match, Coinbase and others team up to fight online fraud and crypto scams

It’s a wrap: European Union lawmakers have given the final approval to set up the bloc’s flagship, risk-based regulations for artificial intelligence.

EU Council gives final nod to set up risk-based regulations for AI

London-based fintech Vitesse has closed a $93 million Series C round of funding led by investment giant KKR.

Vitesse, a payments and treasury management platform for insurers, raises $93M to fuel US expansion

Zen Educate, an online marketplace that connects schools with teachers, has raised $37 million in a Series B round of funding. The raise comes amid a growing teacher shortage crisis…

Zen Educate raises $37M and acquires Aquinas Education as it tries to address the teacher shortage

“When I heard the released demo, I was shocked, angered and in disbelief that Mr. Altman would pursue a voice that sounded so eerily similar to mine.”

Scarlett Johansson says that OpenAI approached her to use her voice

A new self-driving truck — manufactured by Volvo and loaded with autonomous vehicle tech developed by Aurora Innovation — could be on public highways as early as this summer.  The…

Aurora and Volvo unveil self-driving truck designed for a driverless future

The European venture capital firm raised its fourth fund as fund as climate tech “comes of age.”

ETF Partners raises €285M for climate startups that will be effective quickly — not 20 years down the road

Copilot, Microsoft’s brand of generative AI, will soon be far more deeply integrated into the Windows 11 experience.

Microsoft wants to make Windows an AI operating system, launches Copilot+ PCs

Hello and welcome back to TechCrunch Space. For those who haven’t heard, the first crewed launch of Boeing’s Starliner capsule has been pushed back yet again to no earlier than…

TechCrunch Space: Star(side)liner

When I attended Automate in Chicago a few weeks back, multiple people thanked me for TechCrunch’s semi-regular robotics job report. It’s always edifying to get that feedback in person. While…

These 81 robotics companies are hiring

The top vehicle safety regulator in the U.S. has launched a formal probe into an April crash involving the all-electric VinFast VF8 SUV that claimed the lives of a family…

VinFast crash that killed family of four now under federal investigation

When putting a video portal in a public park in the middle of New York City, some inappropriate behavior will likely occur. The Portal, the vision of Lithuanian artist and…

NYC-Dublin real-time video portal reopens with some fixes to prevent inappropriate behavior

Longtime New York-based seed investor, Contour Venture Partners, is making progress on its latest flagship fund after lowering its target. The firm closed on $42 million, raised from 64 backers,…

Contour Venture Partners, an early investor in Datadog and Movable Ink, lowers the target for its fifth fund

Meta’s Oversight Board has now extended its scope to include the company’s newest platform, Instagram Threads, and has begun hearing cases from Threads.

Meta’s Oversight Board takes its first Threads case

The company says it’s refocusing and prioritizing fewer initiatives that will have the biggest impact on customers and add value to the business.

SeekOut, a recruiting startup last valued at $1.2 billion, lays off 30% of its workforce

The U.K.’s self-proclaimed “world-leading” regulations for self-driving cars are now official, after the Automated Vehicles (AV) Act received royal assent — the final rubber stamp any legislation must go through…

UK’s autonomous vehicle legislation becomes law, paving the way for first driverless cars by 2026

ChatGPT, OpenAI’s text-generating AI chatbot, has taken the world by storm. What started as a tool to hyper-charge productivity through writing essays and code with short text prompts has evolved…

ChatGPT: Everything you need to know about the AI-powered chatbot

SoLo Funds CEO Travis Holoway: “Regulators seem driven by press releases when they should be motivated by true consumer protection and empowering equitable solutions.”

Fintech lender SoLo Funds is being sued again by the government over its lending practices

Hard tech startups generate a lot of buzz, but there’s a growing cohort of companies building digital tools squarely focused on making hard tech development faster, more efficient and —…

Rollup wants to be the hardware engineer’s workhorse

TechCrunch Disrupt 2024 is not just about groundbreaking innovations, insightful panels, and visionary speakers — it’s also about listening to YOU, the audience, and what you feel is top of…

Disrupt Audience Choice vote closes Friday

Google says the new SDK would help Google expand on its core mission of connecting the right audience to the right content at the right time.

Google is launching a new Android feature to drive users back into their installed apps

Jolla has taken the official wraps off the first version of its personal server-based AI assistant in the making. The reborn startup is building a privacy-focused AI device — aka…

Jolla debuts privacy-focused AI hardware

The ChatGPT mobile app’s net revenue first jumped 22% on the day of the GPT-4o launch and continued to grow in the following days.

ChatGPT’s mobile app revenue saw its biggest spike yet following GPT-4o launch

Dating app maker Bumble has acquired Geneva, an online platform built around forming real-world groups and clubs. The company said that the deal is designed to help it expand its…

Bumble buys community building app Geneva to expand further into friendships

CyberArk — one of the army of larger security companies founded out of Israel — is acquiring Venafi, a specialist in machine identity, for $1.54 billion. 

CyberArk snaps up Venafi for $1.54B to ramp up in machine-to-machine security

Founder-market fit is one of the most crucial factors in a startup’s success, and operators (someone involved in the day-to-day operations of a startup) turned founders have an almost unfair advantage…

OpenseedVC, which backs operators in Africa and Europe starting their companies, reaches first close of $10M fund

A Singapore High Court has effectively approved Pine Labs’ request to shift its operations to India.

Pine Labs gets Singapore court approval to shift base to India

The AI Safety Institute, a U.K. body that aims to assess and address risks in AI platforms, has said it will open a second location in San Francisco. 

UK opens office in San Francisco to tackle AI risk