Italy’s Data Protection Watchdog Issues €15m Fine To Openai Over Chatg
Category

### #DataPrivacy #AIRegulations #OpenAICompliance

Summary: The Italian Data Protection Authority has imposed a €15 million fine on OpenAI for data protection violations related to ChatGPT, alongside a public awareness campaign about its data collection practices. The investigation revealed failures in legal compliance and age verification mechanisms.

Threat Actor: OpenAI | OpenAI
Victim: Users of ChatGPT | ChatGPT users

Key Point :

  • OpenAI fined €15 million for failing to notify authorities of a data breach.
  • The company must conduct a six-month public awareness campaign on data collection practices.
  • Investigation found violations of transparency and legal basis for data processing.
  • Concerns raised over inadequate age verification, risking exposure of children to inappropriate content.
  • Procedural documents forwarded to the Irish Data Protection Authority for further investigation.

The Italian Data Protection Authority (Garante per la protezione dei dati personali) has taken sanctions against OpenAI over data protection failures related to the ChatGPT chatbot.

OpenAI must pay a €15m ($15.6m) fine and carry out a six-month public awareness campaign across Italian media. This campaign is aimed to educate the public on how ChatGPT operates, with a specific focus on the data collection practices involving both users and non-users for algorithm training.

The fine comes following the company’s failure to notify the Italian authority of a data breach it underwent in March 2023. This prompted the regulator to investigate how the ChatGPT developer processed personal data.

This investigation concluded that OpenAI had processed users’ data to train ChatGPT without first identifying an appropriate legal basis and violated the principle of transparency and related information obligations toward users.

The company is also accused of lacking mechanisms for age verification, which could lead to the risk of exposing children under 13 to inappropriate responses concerning their degree of development and self-awareness.

The sum of the fine was calculated by “taking into account the company’s cooperative attitude,” said the watchdog.

The Italian Data Protection Authority added that it forwarded the procedural documents to the Irish Data Protection Authority (DPC). The DPC is the lead supervisory authority under the EU’s General Data Protection Regulation (GDPR) and will continue investigating any ongoing infringements that have not been exhausted before the opening of OpenAI’s European headquarters.

This announcement comes a day after the European Data Protection Board (EDPB) published its opinion on the use of personal data for the development and deployment of AI models.

Read now: Italy’s Privacy Watchdog Blocks ChatGPT Amid Privacy Concerns

Source: https://www.infosecurity-magazine.com/news/italy-15m-fine-to-openai-chatgpt