Italian DPA bans Chat GPT Summary ChatGPT is the best known among relational Artificial • The information provided to the users might be Intelligence (AI) platforms that are capable of factually incorrect, possibly constituting processing emulating elaborate human conversations. The of inaccurate personal data. platform is developed by OpenAI, who trained the • The lack of a user age verification mechanism model on a large body of text gathered from various exposes children to receiving a service that is sources. In just a few months, the platform has inappropriate to their age and awareness. amassed more than 1 billion users. As the number of use-cases for platforms like ChatGPT are predicted to Additionally, the Italian DPA launched an investigation be almost unlimited, the regulatory response to the on the matter. massive success of the platform has gathered great attention throughout the EU. A few weeks later, the Italian DPA gave OpenAI a ‘to-do list’ for the DPA to lift the suspension order. OpenAI had The decision of the Italian DPA to: The Italian DPA imposed an immediate temporary • Become transparent and publish an information limitation on the processing of Italian users’ data by notice detailing its data processing. OpenAI for the following alleged violations: • Immediately adopt age gating to prevent minors • The service fails to provide users and data subjects from accessing the platform (and later implement with transparent information about the processing more robust age verification measures) of their personal data, • Clarifying the legal basis it claims for processing • There appears to be no legal basis underpinning people’s data for training its AI models. the massive collection and processing of personal • Provide ways for users and non-users to exercise data used in ‘training’ the algorithms on which the rights over their personal data. platform relies. The ban has since been lifted, but the investigation continues. Published: 30-03-23, Journal number: N/A Tags: Legal basis for processing and principles of processing 140
Complycloud EU GDPR Report Page 139 Page 141