ChatGPT and privacy: what are the challenges for businesses?
Since its launch, ChatGPT has been the subject of much discussion. This artificial intelligence (AI) system is at the centre of a great deal of controversy. In an open letter dated 29 March 2023, AI experts called for a minimum six-month moratorium on the development of AI systems such as ChatGPT, calling in particular for the establishment of new regulatory bodies in this field.
This tool is revolutionising the way we process information, as it has the ability to respond quickly and effectively to a wide variety of queries, ranging from the simplest to the most complex. This is made possible by a ‘Generative Pre-trained Transformer’ (GPT) language model, which gives the tool the ability to hold human-like conversations. Its use in business can therefore greatly improve staff productivity and contribute to growth objectives.
However, this tool also raises numerous legal issues, particularly in terms of privacy and intellectual property. Furthermore, the unreliability of its results and the tool’s lack of critical thinking may also render it unnecessary in certain situations.
Recently, some countries have questioned its use, notably on the basis of the provisions of the General Data Protection Regulation (GDPR). On 31 March 2023, Il Garante per la protezione dei dati personali, the Italian Data Protection Authority, banned Italian citizens from accessing ChatGPT due to privacy concerns. The reasons cited relate to the unlawful collection of personal data and the lack of a system to verify the age of minors. The Authority has given OpenAI, the company behind the tool, 20 days to outline the measures it has put in place to address the Authority’s concerns. Failing to do so, the company will face a fine of up to €20 million or 4 per cent of its global annual turnover (in accordance with Article 83 of the GDPR). In the meantime, it is understood that, given the stakes, OpenAI has opted to suspend access to its tool in Italy. In France, several complaints regarding ChatGPT have also been lodged with the CNIL.
Among businesses, the issue of ChatGPT’s use is also a subject of debate. Companies such as Amazon, Bank of America and Goldman Sachs have recently banned their employees from using it in order to protect any confidential information they might inadvertently share with the tool.
ChatGPT and the GDPR
Furthermore, as ChatGPT is US-based software, its use therefore involves the transfer of data to the United States. However, it is well known that such transfers are likely to fall under the provisions of the GDPR (Article 44 et seq.).
By its very design, the software required the processing of personal data for its ‘training’. Indeed, it has emerged that OpenAI used around 300 billion data points gathered from the internet, notably from Wikipedia. These sites contain a great deal of personal information, some of which is sensitive. However, the consent of the data subjects to be included in this processing was neither sought, nor, a fortiori, obtained. Nor does OpenAI’s legitimate interest appear to justify the processing of this personal data. Certain rights provided for under the GDPR are also not being respected, as individuals are unable to request access to or the erasure of their personal data used in breach of the GDPR.
Furthermore, the use of the tool, which is hosted in the United States, also involves the processing of personal data, such as:
- the user’s email address;
- the telephone number;
- IP address;
- the type of web browser;
- data on interactions with the website;
- information on users’ web browsing activity over time.
It should also be noted that OpenAI reserves the right to share personal information with third parties, without specifying which ones.
Whilst the use of this data within the context of a contract may be justified under the GDPR, the issue of its transfer to the United States arises. Such a transfer does indeed require specific consent, which is not sought from the user at all.
Risks for businesses
In the context of professional use within a business, issues relating to trade secrets may also arise. This is due to the significant number of benefits that can be derived from the use of ChatGPT by any business seeking to improve its productivity and efficiency.
Given the wide range of uses, there is a high risk of data being disclosed. This risk also extends to the employee, who is bound by a confidentiality agreement with their employer. If an employee shares confidential data (whether intentionally or not), they are breaching their obligation, with all the consequences that entails.
Automated decisions and their legal framework
ChatGPT could also, in certain cases, be used by companies to make decisions concerning individuals. This is referred to as an ‘automated decision’. It refers to any decision taken regarding a person, using algorithms applied to their personal data, without any human intervention in the process.
One notable example is its potential use by financial institutions to assess an individual’s creditworthiness when applying for a loan. In this case, the algorithm analyses the individual’s financial situation against certain defined criteria, without any human intervention. Consequently, the algorithm will make a decision on its own by processing personal data. The institution would then follow the tool’s recommendation in making its decision.
In light of these issues, the European Union has sought to regulate the use of such decisions under Article 22 of the GDPR. This article stipulates that every individual has the right not to be subject to a decision based solely on automated processing which produces legal effects concerning them or similarly significantly affects them.
The aim is clear: to prevent humans from being subject to decisions made entirely by machines. Exceptions are, however, provided for, notably where the explicit consent of the data subjects has been obtained or within the framework of specific legal provisions.
The company’s liability in the event of harm
Finally, there is the question of the liability of a company that has taken a decision based on advice from ChatGPT, a decision which has caused harm to others. In the absence of specific regulations applicable to AI, general civil liability law applies, and the user is liable for any harmful consequences arising from the use of AI-generated content. In September 2022, the European Commission published a proposal for a directive on adapting the rules on non-contractual civil liability to the field of AI. Pending more specific rules on this matter, case law will play a key role in providing greater legal certainty regarding all these new challenges.
It is therefore clear that ChatGPT should be used with caution and with an awareness of the risks involved. The concept of ‘due care’ takes on its full meaning here, and even more so in a professional context, given the sensitive nature of the information being processed. One should therefore avoid using the tool for tasks that may involve processing personal data, confidential data, or for decisions affecting an individual.
In conclusion, there is no doubt that countries and companies will gradually have to adapt to this revolution brought about by AI. AI itself will not be immune to this adaptation either, given the need to consider compliance with current legal regulations.