← the record
AIAAIC-1196

Poland investigates ChatGPT for alleged privacy abuse

Poland's data protection authority the Urząd Ochrony Danych Osobowych (UODO) announced it was opening an investigation into OpenAI's ChatGPT for violating the privacy of Polish users. The announcement of the investigation comes after a complaint had accused OpenAI and ChatGPT of multiple breaches of the EU’s General Data Protection Regulation (GDPR), including processing 'data in an unlawful and unreliable manner' and in a non-transparent manner. According to TechCrunch , the complaint was filed by local privacy and security researcher Lukasz Olejnik accusing OpenAI of a string of breaches concerning lawful basis, transparency, fairness, data access rights, and privacy by design. According to Olejnik, OpenAI had said it was unable to correct incorrect personal data about him, and had failed to respond properly to his subject access request, giving 'evasive, misleading and internally contradictory' answers when he had sought to exercise his legal rights to data access. System 🤖 ChatGPT Operator: OpenAI Developer: OpenAI Country: Poland Sector: Multiple Purpose: Generate text Technology: Chatbot; Generative AI; Machine learning Issue: Privacy; Transparency Regulation ⚖️ EU General Data Protection Regulation Investigations, assessments, audits 🧐 UODO (2023). Technologia musi być zgodna z RODO

Date it happened
2023-09-01
Organisation involved
OpenAI
Product, system or model
ChatGPT
Where this came from
Share this incident
XLinkedInFacebookWhatsAppEmail
Attribution

This incident was imported from AIAAIC and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.

This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.