Italian Watchdog Halts ChatGPT Over GDPR Compliance Concerns
Italy's data protection authority orders OpenAI to stop processing local users' data, citing a lack of legal basis and transparency. This emergency move signals a broader regulatory crackdown on generative AI across Europe.
Italy's data protection authority, known as the Garante, issues an emergency order requiring OpenAI to immediately halt ChatGPT's data processing activities for Italian users. This temporary ban follows a recent data breach that exposes the chat histories and payment details of some subscribers. Legal experts note that this decisive action serves as a wake-up call that accelerates regulatory scrutiny of artificial intelligence across Europe.
The Garante identifies three primary reasons for finding ChatGPT non-compliant with the General Data Protection Regulation. First, OpenAI collects massive amounts of personal data to train its algorithm without properly informing users or establishing a valid legal basis. Second, the platform fails to provide clear information about how it processes and utilizes this personal data. Third, the AI system generates responses that present significant challenges regarding the accuracy and rectification of personal information.
This intervention demonstrates that existing privacy laws provide robust tools for regulators to actively shape the future of AI technology. By tackling the unique privacy challenges posed by generative AI, the Italian authority potentially leads the way in establishing how European regulators apply the GDPR to these advanced systems. The outcome of this investigation provides crucial guidance for the broader intersection of artificial intelligence and data privacy rights.