{"id":5214,"date":"2023-09-04T15:29:47","date_gmt":"2023-09-04T15:29:47","guid":{"rendered":"https:\/\/toukiela.com\/scandale-le-createur-de-chatgpt-openai-accuse-dune-serie-de-violations-de-protection-des-donnees-dans-une-plainte-gdpr-deposee-par-un-expert-en-confidentialite\/"},"modified":"2023-09-04T15:30:09","modified_gmt":"2023-09-04T15:30:09","slug":"scandale-le-createur-de-chatgpt-openai-accuse-dune-serie-de-violations-de-protection-des-donnees-dans-une-plainte-gdpr-deposee-par-un-expert-en-confidentialite","status":"publish","type":"post","link":"https:\/\/toukiela.com\/en\/scandal-the-creator-of-chatgpt-openai-accused-of-a-series-of-data-protection-violations-in-a-complaint-gdpr-deposited-by-an-expert-in-confidentiality\/","title":{"rendered":"Scandal! ChatGPT creator OpenAI accused of a series of data protection violations in a GDPR complaint filed by a privacy expert!"},"content":{"rendered":"<p><em><\/em><\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_82_2 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Contents<\/p>\n<label for=\"ez-toc-cssicon-toggle-item-69f1d977a0cc2\" class=\"ez-toc-cssicon-toggle-label\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewbox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewbox=\"0 0 24 24\" version=\"1.2\" baseprofile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/label><input type=\"checkbox\"  id=\"ez-toc-cssicon-toggle-item-69f1d977a0cc2\"  aria-label=\"Toggle\" \/><nav><ul class='ez-toc-list ez-toc-list-level-1' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/toukiela.com\/en\/scandal-the-creator-of-chatgpt-openai-accused-of-a-series-of-data-protection-violations-in-a-complaint-gdpr-deposited-by-an-expert-in-confidentiality\/#Plainte_detaillee_deposee_contre_OpenAI_pour_violation_du_GDPR\" >Detailed complaint filed against OpenAI for GDPR violation<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/toukiela.com\/en\/scandal-the-creator-of-chatgpt-openai-accused-of-a-series-of-data-protection-violations-in-a-complaint-gdpr-deposited-by-an-expert-in-confidentiality\/#Preoccupations_concernant_la_conformite_au_RGPD\" >Concerns about RGPD compliance<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/toukiela.com\/en\/scandal-the-creator-of-chatgpt-openai-accused-of-a-series-of-data-protection-violations-in-a-complaint-gdpr-deposited-by-an-expert-in-confidentiality\/#Plainte_pour_traitement_illegal_des_donnees_a_des_fins_dentrainement_de_lIA\" >Complaint of illegal data processing for AI training purposes<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/toukiela.com\/en\/scandal-the-creator-of-chatgpt-openai-accused-of-a-series-of-data-protection-violations-in-a-complaint-gdpr-deposited-by-an-expert-in-confidentiality\/#Droit_de_rectification_des_donnees_personnelles_ignore\" >Right to rectify personal data ignored<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/toukiela.com\/en\/scandal-the-creator-of-chatgpt-openai-accused-of-a-series-of-data-protection-violations-in-a-complaint-gdpr-deposited-by-an-expert-in-confidentiality\/#Incompatibilite_de_la_protection_des_donnees_par_conception\" >Incompatible data protection by design<\/a><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"Plainte_detaillee_deposee_contre_OpenAI_pour_violation_du_GDPR\"><\/span>Detailed complaint filed against OpenAI for GDPR violation<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>A detailed complaint was filed with the Polish data protection authority yesterday, raising questions about ChatGPT-maker OpenAI's ability to comply with European privacy rules. The complaint alleges that the US-based AI giant is violating the EU's General Data Protection Regulation (GDPR) in several areas such as legal basis, transparency, fairness, data access rights and privacy. It is also suggested that OpenAI did not consult local regulators before launching ChatGPT in Europe, which would have avoided violating EU privacy rules.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Preoccupations_concernant_la_conformite_au_RGPD\"><\/span>Concerns about RGPD compliance<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>This isn't the first time concerns have been raised about ChatGPT's compliance with the RGPD. The Italian data protection authority, the Garante, ordered OpenAI to stop processing data locally and identified several issues in areas such as legal basis, information disclosures, user controls and child safety. Other EU data protection authorities are also investigating ChatGPT.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Plainte_pour_traitement_illegal_des_donnees_a_des_fins_dentrainement_de_lIA\"><\/span>Complaint of illegal data processing for AI training purposes<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The complaint filed with the Polish data protection authority is the work of Lukasz Olejnik, a security and privacy researcher, who is represented by a Warsaw-based law firm. Olejnik complained about errors in the biography generated by ChatGPT about him and asked OpenAI to correct these errors as well as to provide the information required by the GDPR. The complaint claims that OpenAI has failed to provide all the information required by law, particularly with regard to the processing of personal data for training AI models.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Droit_de_rectification_des_donnees_personnelles_ignore\"><\/span>Right to rectify personal data ignored<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The complaint also highlights OpenAI's refusal to correct the errors generated by ChatGPT in Mr. Olejnik's biography, even though he has the right to rectify his personal data under the GDPR. The complaint states that OpenAI does not have an adequate mechanism to correct the inaccurate data generated by ChatGPT.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Incompatibilite_de_la_protection_des_donnees_par_conception\"><\/span>Incompatible data protection by design<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The complaint also highlights ChatGPT's total violation of the RGPD's data protection by design and default principles. It claims that ChatGPT's design, which tested the tool using personal data in the production environment rather than in the design phase, contradicts the principles of data protection by design.<\/p>\n<p>We contacted OpenAI for answers to the allegations in the complaint and to find out whether it carried out a data protection impact assessment before launching ChatGPT. We also asked why OpenAI did not seek prior consultation with EU regulators to develop high-risk technology in a way that mitigates RGPD risks.<\/p>\n<p>We also contacted the Polish data protection authority, UODO, who confirmed that they had received the complaint and were analyzing it to decide what action to take. UODO also confirmed that this was the first complaint of its kind regarding ChatGPT and that it had not had any prior correspondence with OpenAI regarding ChatGPT's compliance with the GDPR.<\/p>\n<p>The process of examining the complaint by the Polish authority could take from six months to two years. If the breach of the GDPR is confirmed, the authority could order OpenAI to respect Mr. Olejnik's rights and initiate a prior consultation process with EU regulators. The complaint also asks the Polish authority to require OpenAI to submit a data protection impact assessment (DPIA) detailing the processing of personal data related to ChatGPT.<\/p>\n<p>Olejnik hopes to be able to exercise his rights under the RGPD and is confident that the RGPD process works.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1200\" height=\"602\" class=\"mpt-img wp-image-5219\" src=\"https:\/\/toukiela.com\/wp-content\/uploads\/2023\/09\/data-protection-1200x602.jpg\" alt=\"\" srcset=\"https:\/\/toukiela.com\/wp-content\/uploads\/2023\/09\/data-protection-scaled.jpg 1200w, https:\/\/toukiela.com\/wp-content\/uploads\/2023\/09\/data-protection-400x201.jpg 400w, https:\/\/toukiela.com\/wp-content\/uploads\/2023\/09\/data-protection-768x385.jpg 768w, https:\/\/toukiela.com\/wp-content\/uploads\/2023\/09\/data-protection-18x9.jpg 18w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><\/figure>","protected":false},"excerpt":{"rendered":"","protected":false},"author":1,"featured_media":5277,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","footnotes":""},"categories":[608],"tags":[],"class_list":["post-5214","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-actualite-intelligence-artificielle","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50"],"_links":{"self":[{"href":"https:\/\/toukiela.com\/en\/wp-json\/wp\/v2\/posts\/5214","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/toukiela.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/toukiela.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/toukiela.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/toukiela.com\/en\/wp-json\/wp\/v2\/comments?post=5214"}],"version-history":[{"count":0,"href":"https:\/\/toukiela.com\/en\/wp-json\/wp\/v2\/posts\/5214\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/toukiela.com\/en\/wp-json\/wp\/v2\/media\/5277"}],"wp:attachment":[{"href":"https:\/\/toukiela.com\/en\/wp-json\/wp\/v2\/media?parent=5214"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/toukiela.com\/en\/wp-json\/wp\/v2\/categories?post=5214"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/toukiela.com\/en\/wp-json\/wp\/v2\/tags?post=5214"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}