OpenAI Found to Have Violated Canadian Privacy Law
Key point
Canadian privacy regulators determined that OpenAI's collection of personal information violated the law.
Details
Canada's federal privacy commissioner and the BC, Alberta, and Quebec privacy regulators concluded that OpenAI's early training data collection for ChatGPT violated PIPEDA and provincial privacy laws.
The investigation targeted the data collection and training methods used for the early GPT-3.5 and GPT-4 models. This included public web scraping, licensed third-party sources, and ChatGPT user interactions, and the regulators found that OpenAI had collected vast amounts of personal information, which could include health information, political affiliations, and information related to children.
The key findings were as follows.
- OpenAI failed to obtain valid consent.
- There was insufficient transparency regarding data collection and its use in training.
- There were no effective means to access, correct, or delete personal information.
- ChatGPT was launched without adequately addressing known privacy risks.
OpenAI committed to certain corrective measures during the investigation. At the federal level, the case was closed on a conditional basis, but Quebec left the consent issue unresolved, and BC and Alberta classified the matter as unresolved under provincial law.
The company's commitments included adding data-use disclosures to the logged-out web version within 3 months, improving data export and objection pathways within 6 months, strengthening protections for datasets kept for historical reference, and testing protections for the minor family members of public figures. The regulators emphasized that this case demonstrates the need to update Canadian privacy law for the AI era.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.