(Updated on April 2 at hour 16) At March 30 local time in Rome, the GPDP, Italy’s supervisory authority for personal data protection1(commonly known as the Garante), ordered a provisional restriction on the processing of personal data of users residing in Italy in connection with the ChatGPT service operated by the U.S. company OpenAI LLC. The GPDP pointed out that no information had been provided to the data subjects and users whose data ChatGPT collected, and that there was no appropriate legal basis for collecting and processing personal data to train the algorithms. It also pointed out that there was no filter for children under 13 and that the processing of users’ personal data, particularly minors’ personal data, violated several provisions of the EU General Data Protection Regulation (GDPR). The provisional restriction applies generally to the personal data of data subjects in Italy, and violations are subject to criminal and administrative penalties. The data controller was asked to provide, within 20 days, details of the steps taken to remedy the situation and any information it considered useful in justifying the violation.
The above was ChatGPT’s summary of Order No. 1122.
Details of the Order
Now let us examine the details. Order No. 112 consists of 2 parts: a preamble, or the section justifying the order, and the operative provisions.
Preamble
The opening of the preamble shows that the order is based on the GDPR (2016), Italy’s personal data protection law (2003), and recent news reports. It then states that the following matters were taken into consideration.
- Numerous news reports about ChatGPT
- This appears to refer to the widely reported data breach discovered on March 20: because of a bug, users could see the titles of other people’s initial conversations, and during the 9-hour period from Sunday until the service was temporarily suspended on Monday, payment-related information3 could be exposed for 1.2% of the ChatGPT Plus users who were active. For details, see OpenAI’s announcement of March 244.
- According to the investigation in this case, no information had been provided to users or to people whose data was collected by OpenAI and processed by ChatGPT.
- There was no lawful basis5 for collecting and processing data to train ChatGPT.
- The processing of data subjects’ personal data was inaccurate, as demonstrated by the fact that information supplied by ChatGPT does not necessarily correspond to actual data.
- Although the terms of use describe the service as being for persons aged 13 or older, no age verification was performed.
- Because there was no filter for children under 13, children were exposed to responses wholly inappropriate to their stage of development and self-awareness.
In view of these points, it found that the processing of personal data of users, including children whose data was processed, violated Article 56, Article 67, Article 88, Article 139, and Article 2510 of the GDPR.
On that basis, pursuant to Article 58(2)(f) of the GDPR11, it states that, although the investigation is continuing, a provisional order suspending data processing will be issued because of the urgency. It applies to the data of all residents of Italy, including those under 13. Although the terms of use set the age at 13 or older, persons under 13 are also covered because no age-restriction mechanism has been implemented. It takes effect when notice of the measure is received12. The details of the measure may change depending on the outcome of the investigation.
It next states that violating this order is punishable by imprisonment for between 3 months and 2 years under Article 170 of Italy’s personal data protection law.
It also states that, given the urgency, the order was issued by decision of the chair pursuant to Article 5, paragraph 8 of the law establishing the Italian data protection authority13.
Operative Provisions
On that basis, the data protection authority gives notice of the following orders.
- a) Pursuant to Article 58, paragraph 2(f) of the Regulation, urgently order OpenAI L.L.C., the U.S. company that develops and operates ChatGPT, in its capacity as data controller for the processing of personal data performed through that application, to provisionally restrict the processing of personal data of data subjects located in Italian territory14.
- b) This order takes effect immediately upon receipt, and additional measures may follow.
In addition,
- pursuant to Article 58 of the GDPR, the data controller must submit to the authority within 20 days its arguments justifying the processing of data involved in this infringement
is what the authority requires. It also states that a failure to comply with an inquiry under Article 58 may result in an administrative penalty under Article 83, paragraph 5(e).
Impressions
This is quite a tough situation for OpenAI. I think it will also be instructive for Japanese companies working in this field.
First, no information was provided to users or to people whose data was collected by OpenAI and processed by ChatGPT. Publicly available data contains a great deal of personal information, and the point seems to be that the individuals concerned must be informed of the processing before it takes place. That is quite demanding.
Next is the absence of a lawful basis for using data in training.
Article 6 of the GDPR lists
- (a) consent for a specific purpose;
- (b) performance of a contract or steps prior to entering into a contract;
- (c) a legal obligation;
- (d) protection of life;
- (e) the public interest;
- (f) legitimate interests (except where they are outweighed by the interests of persons under 13 and data subjects in not having their data processed)
as lawful bases. First, (a): consent to use the data as training data almost certainly has not been obtained, so “consent” does not seem available as a basis.
Then (b): at the stage when data is used as training data, one does not even know whether a contract will be concluded, so this is not possible.
It goes without saying that (c) and (d) do not work. The public interest in (e) also seems difficult.
Finally, there is the legitimate-interest basis in (f), and the immediate demand is for a response within 20 days. Ordinarily, one would expect a PIA report establishing that the data contains no information about persons under 13 and that the interests of data subjects are not harmed.
Next is a violation of the “accuracy principle.” It produces nonsense, after all. We tend to think that the accuracy principle concerns the accuracy of data stored in a database or similar system, but it applies to processing as a whole and therefore also to information produced as a result of processing.
Items 5 and 6 point out the lack of measures for children. Merely writing an age restriction into the terms appears insufficient; age verification seems to be required.
And if processing is not stopped, the penalty is imprisonment for between 3 months and 2 years. ChatGPT still appears to be operating from Japan for now, but did they perhaps make it inaccessible from Italy…? Yet that alone is not enough: they must stop processing the data of data subjects in Italian territory. How on earth can they do that??? Can they remove those portions from the model…?
As for the operative provisions, they are as straightforward as written. It will also be interesting to see whether OpenAI can properly submit its explanation within 20 days.
That is all for today (April 2). Follow-up coverage is here ====▷ News and Impressions Concerning Italy’s ChatGPT Restrictions
References
- The GPDP’s original order and its DeepL English translation
- Politico: Italian privacy regulator bans ChatGPT
- ChatGPT’s privacy policy dated March 14, 2023
- Its terms of use
Footnotes
- Garante per la protezione dei dati personali
- I translated the original Italian into English with DeepL, asked it to produce a summary, and then asked for it “in Japanese”
- first and last name, email address, payment address, the last four digits (only) of a credit card number, and credit card expiration date
- March 20 ChatGPT outage: Here’s what happened <https://openai.com/blog/march-20-chatgpt-outage>
- Article 6 of the GDPR: (a) consent for specific purposes; (b) performance of a contract or steps prior to entering into a contract; (c) a legal obligation; (d) protection of life; (e) the public interest; or (f) legitimate interests, except where the interests or fundamental rights and freedoms of children and data subjects take precedence
- fundamental principles relating to the processing of personal data
- lawfulness of processing
- conditions applicable to a child’s consent in relation to information society services
- information to be provided where personal data is collected from the data subject
- data protection by design and by default
- to impose a temporary or definitive limitation including a ban on processing
- in other words, immediately
- which provides that in an emergency the chair may decide independently without convening the authority
- degli interessati, “data subject” in English
