Italy bans ChatGPT; tool falls short in many areas

by Erik Bouwer

Italy bans ChatGPT; tool falls short in many areas

by Erik Bouwer

by Erik Bouwer

Italy has an AI chatbot immediately ChatGPT temporarily banned. The Italian privacy regulator GDPR states that OpenAI's service violates European privacy legislation (GDPR) on a number of essential points. OpenAI is given 20 days by the regulator to let it know what measures have been taken to still be compliant. Also for OpenAI, the Italian regulator can impose a fine of up to 20 million euros or a maximum of 4% of OpenAI's worldwide annual turnover.

Angel friesArnoud Engelfriet of ICTRecht comes with a sharp reflection on the measures taken by the Italians blog. “The processing ban is limited to personal data of data subjects residing in Italy, but the reasons are fundamental and I do not see why this should be different in the Netherlands or elsewhere.”

Engelfriet points to the operation of ChatGPT, which uses statistics to determine which words and phrases should follow each other when generating output based on a prompt. ChatGPT can also use personal data “that are not accurate” (“noting that the processing of personal data of the parties involved is inaccurate, as the information provided by ChatGPT does not always correspond to the actual data”, according to the regulator).

Basic rights and obligations not defined

In addition, Engelfriet points out that nobody knows what information about him or her is included in the language model. “There is a privacy statement, but it doesn't really address data processing when vacuuming the entire internet. And that is a pity, because now we also do not know what basis OpenAI wanted to use for this processing. That is again a problem, because without a basis reported in advance you are by definition wrong.” Or as he suggests later on: “'We make a language model that produces output about you/based on you that people do anything with' is not a GDPR-compliant statement either way you look at it.”

Ziptone also noted that this is not clear where the input users give ends. The question is when the (overburdened and understaffed) Dutch Personal Data Authority comes into action.

Finally, Engelfriet comes with the (im) possibility to withdraw your consent; the right to be forgotten in the dataset; insight into who requests your data; or access of the Service by minors without any supervision or safeguards.

Follow by Email
Whatsapp
LinkedIn
Share

Also interesting

Featured, Technology
Top