Italy bans ChatGPT for 'unlawful collection of personal data'
- Reference: 1680280145
- News link: https://www.theregister.co.uk/2023/03/31/italy_bans_chatgpt_for_unlawful/
- Source link:
The [1]announcement of the probe came alongside a [2]decree in which the Guarantor for the Protection of Personal Data (GPDP) said it was imposing an immediate "temporary limitation of the processing of personal data" of Italian citizens due to violations of both the EU's [3]General Data Protection Regulation and Italy's own [4]data protection code .
"The Privacy Guarantor notes the lack of information to users and all interested parties whose data is collected by OpenAI," the GPDP said in a statement. It added that ChatGPT's processing of user data can provide an inaccurate picture, "as the information provided by ChatGPT does not always correspond to the real data."
[5]
The Guarantor also expressed concern that Open AI hadn't vetted the age of its users, which the Microsoft-backed firm [6]says is designed for those 13 or older. There's no age verification process for ChatGPT users, which the GPDP said "exposes minors to absolutely unsuitable answers compared to the degree of development and self-awareness," presumably in the pre-teens using it, and not the AI itself.
[7]
[8]
In its statement, the GPDP also referenced the [9]data exposure bug that last week caused ChatGPT to display partial payment details and chat histories for other users on people's accounts. While the breach wasn't mentioned in the limitation decree, the GPDP's mention of it in its statement implies its investigation is centered around the incident.
The Guarantor said the temporary limit extends to all personal data of interested parties being collected within Italy's borders, in essence blocking use of the service until Open AI is able to show that it has resolved the issues identified by the GPDP.
[10]
Open AI has 20 days to respond, the Guarantor said, or else it faces fines of up to €20 million ($21.7 million) and up to 4 percent of its annual global turnover.
Is that AI mistreating you?
This isn't the first time the Guarantor has taken action against an AI that it thought was behaving badly. In February the GPDP announced a [11]similar prohibition against Replika, an AI chatbot app that allows users to customize a virtual companion for anything from friendly chats to a virtual relationship.
The GPDP said last month it was concerned that Replika may increase risks for individuals "still in a developmental stage" (ie, minors), "or in a state of emotional fragility." As we've noted in [12]previous coverage of Replika , CEO Eugenia Kuyda has said that otherwise stable individuals have been fooled by the app into thinking their Replikas are sentient and have built relationships with their personal chatbot.
Italian authorities also made claims that Replika lacked an age verification mechanism. As such, they alleged in February, Replika is breaching the GDPR and unlawfully processing personal data.
ChatGPT, Replika and tools like it are so new that it's easy to forget widespread use has only been happening "for a matter of weeks," said Edward Machin, a London-based privacy lawyer at international law firm Ropes & Gray.
[13]Leaked IT contractor files detail Kremlin's stockpile of cyber-weapons
[14]FTC urged to freeze OpenAI's 'biased, deceptive' GPT-4
[15]So you want to integrate OpenAI's bot. Here's how that worked for software security scanner Socket
[16]Microsoft wants to stick adverts in Bing chat responses
Machin told us in a statement that most users probably haven't stopped to consider the privacy implications of their data being used to train Open AI's software. "The allegation here is that users aren't being given the information to allow them to make an informed decision, and more problematically, that in any event there may not be a lawful basis to process their data."
The move to ban Open AI's processing of Italians' data is one of the most powerful weapons in the GPDP's armory, Machin said. "I suspect that regulators across Europe will be quietly thanking the Garante for being the first to take this step and it wouldn't be surprising to see others now follow suit and issue similar processing bans," Machin predicted.
[17]
Open AI hadn't responded to our questions by the time of publication. ®
Get our [18]Tech Resources
[1] https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9870847
[2] https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/9870832
[3] https://gdpr-info.eu/
[4] http://www.privacy.it/archivio/privacycode-en.html
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZCdYBqsTwufGViMkAHGAcQAAAI0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[6] https://openai.com/policies/terms-of-use
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZCdYBqsTwufGViMkAHGAcQAAAI0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZCdYBqsTwufGViMkAHGAcQAAAI0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2023/03/23/openai_ceo_leak/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZCdYBqsTwufGViMkAHGAcQAAAI0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://www.reuters.com/technology/italy-bans-us-based-ai-chatbot-replika-using-personal-data-2023-02-03/
[12] https://www.theregister.com/2022/07/04/ai_in_brief/
[13] https://www.theregister.com/2023/03/31/vulkan_files_russia/
[14] https://www.theregister.com/2023/03/30/ftc_openai_gpt4/
[15] https://www.theregister.com/2023/03/30/socket_chatgpt_malware/
[16] https://www.theregister.com/2023/03/30/microsoft_wants_to_stick_ads/
[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZCdYBqsTwufGViMkAHGAcQAAAI0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[18] https://whitepapers.theregister.com/
Italy is trying to ban search technology, plus text rewriting. This is absurd!
FTFY
Italy is trying to ban search technology, plus text rewriting and the unlawful collection of personal data.
Re: FTFY
"Italy is trying to ban search technology, plus text rewriting and the unlawful collection of personal data."
Is it? Or is that just a handy hook from which to hang OpenAI?
What personal data is it processing, exactly? Likely nothing other than that which the user provides in the process of talking to the bot. Surely, by doing so, you must provide implicit consent for the data to be processed! If not, how do you expect the bot to answer your query. In most cases, the user isn't providing any personal data - here's an article, please rewrite it, give five reasons the Italian government are flueless cluckwits and give five more showing they are the best government ever etc. No personal data there.
If people are so stupid as to need help with the idea that telling the thing about your personal data involves it processing your personal data, then they might as well give up and admit that chatGPT is already smarter than them.
Re: FTFY
Under GDPR, consent MUST be explicit. Implicit consent doesn't cut it.
"there may not be a lawful basis"
This sentence raises my hackles. It is full of FUD, and seems to imply that unless you have a law authorizing something, it must be forbidden by default. If there is a law being broken, then point out which one, clearly; otherwise go fuck yourself.
Re: "there may not be a lawful basis"
Spoken like a true #Retardistani
Re: "there may not be a lawful basis"
Italy - and much of Europe - have a different legal constitution to the UK (and US).
That said, the UK seems to be drifting towards a situation where TPTB use the lack of a law to indicate something should somehow not be allowed.
Re: "there may not be a lawful basis"
The mistaken idea that common law permits everything which is not specifically illegal and napoleonic code bans everything which is not specifically legal is one that just won't die.
As usual the raving right completely misunderstand the obvious
Under GDPR there is the idea of lawful basis when collecting personal data. A bank will collect personal data when opening an account to ensure that you are who you say you are so they can prevent money laundering or a company that enables you to register a company is required by companies house to id the registrant.
No matter how much a search engine or bot may want to gather as much info about you that they can in order to sell adverts, at the greatest profit, to third parties, they have no legal basis to do so in the EU.
Just accept that and let the angst you have about your freedom rise from your shoulders.
Because some are unaware of how companies inaccurately profile them doesn't mean regulators should turn a blind eye, just as we shouldn't just take your howls of freedoms being withdrawn and do the opposite and let companies do what they will.
Let the down voting begin.
Err, wot?
"ChatGPT, Replika and tools like it are so new that it's easy to forget widespread use has only been happening "for a matter of weeks," said Edward Machin, a London-based privacy lawyer at international law firm Ropes & Gray."
So what? GDPR has been around for a while now and companies have no excuse not to be aware of it. Just because the company or technology is new does NOT give them carte blanche to ride roughshod over the law until someone stops them. Collecting personal data without consent is already illegal. ChatGPT being new doesn't change that.
Welly welly well
-> Machin told us in a statement that most users probably haven't stopped to consider the privacy implications of their data being used to train Open AI's software.
That's probably because those users don't have the brains to think about things like that. What next? Nobody will guess I'm using "password" as my password?