DATA PROTECTION | The EDPB on ChatGPT’s data processing activities

On 23 May 2024, the European Data Protection Board (EDPB) adopted a report of the work undertaken by the ChatGPT Taskforce (the “Report”). This was set up to foster cooperation and exchange information between EU Data Protection Authorities (DPAs) on possible enforcement actions on the processing of personal data in the context of ChatGPT in the absence of a single establishment within the EU. The aim of the Report is to guide the DPAs in their ongoing investigations on the processing activities carried out by the LLM before 15 February 2024. It provides guidance on evaluating ChatGPT’s compliance with the GDPR principles of lawfulness, fairness, transparency and data accuracy, as well as on respecting data subjects’ rights. The Report extensively examines the web scraping activities performed by ChatGPT under legitimate interest basis. The EDPB suggests safeguards to DPAs which, if implemented, could change the balancing test in favour of the controller. Regarding sensitive data, the EDPB stresses that the mere fact that personal data is publicly accessible does not imply that “the data subject has manifestly made such data public”.

Newsletter n. 97 – June 2024