Italian privacy regulator bans ChatGPT
politico.eu
politico.eu
These bureaucrats only pretend to work. The number of privacy violations in italy is staggering, i have to take 10 calls a day from power companies because they have access to all the phone number of anybody who has a gas or energy contract.
I had to change phone numbers. Meanwhile they are going against a service that as far as i know does not even require your name to serve you.
From Poland: I have two numbers - one I use for various services, and it's constantly bombarded with spam (multiple calls a day), one I only use to contact family members, sometimes some small companies like when ordering firewood - got two phonecalls from an unknown number within a couple days (and I didn't care to answer), and that's it for almost a year now.
I do the same thing. One phone number is just unusable and I don't answer any calls anymore, mostly UK callers recruiting, or other random spam.
The other, which I don't give to almost anyone except close friends/family, gets no spam. Not sure where my first phone number ended up to become spam target, but I remember I got a call once, when that was really uncommon, which an offer to change insurance companies... I was pissed off with my previous company so I actually did it, and it actually worked well, it was not malicious... but since then I think I was added to a list of "spam-friendly idiot" or something.
I don't know why my spam dropped so significantly when I moved up to Canada but it was quite dramatic compared to the US. There are periodic waves but I tend to miss out of them - I suspect because Canada works hard to prevent dumb auto-dialers from working.
[0] https://www.cbc.ca/news/business/crtc-telecom-call-authentif...
I used to get perhaps 3-4 calls a week from the same Indian sounding scammers (a man and a woman). They call from UK numbers. However, since I got the pixel, it has a setting to block spam calls, I have not gotten any :)
> Haven't received a spam call in years.
Ditto.
It‘s not nearly the same extent as in the US, though.
However there is a proposal for some changes - it doesn't make any sense for me (make it less onerous yet also somehow maintain compatibility with EU GDPR?) but I don't have time for the actual legalese frankly and the press release was devoid of detail in favour of annoying quips, and completely confusing.
I honestly think politics would be better off without television and radio (again). If the only way lay people heard of stuff was through slower news (if at all) then surely they'd speak normally (not in pithy soundbites) and have better debates.
https://ico.org.uk/for-organisations/guide-to-data-protectio...
It's occasionally inconvenient—maybe once or twice a year I deal with a company that needs to call me. But if it's a call from a real person, I can always listen to the voicemail and call them back. Most spam calls either don't leave voicemail, or leave 1 second message that I can bulk delete every few months.
And the real-life version of this: you're not morally required to open the front door (or even acknowledge) if you don't knock the person ringing your doorbell. You can actually just... ignore them.
And the real-life version of this: you're not morally required to open the front door (or even acknowledge) if you don't knock the person ringing your doorbell. You can actually just... ignore them."
I do both and keep my phone on do not disturb with a few bypasses (starred contacts). Neither technology nor people should be able to demand my attention and unilaterally dictate the terms.
Settings->General->Phone->Silence Unknown Callers
Settings->Phone->Silence Unknown Callers
The industry stakeholders and FCC should get together and fix caller ID authentication; the rest will follow from there.
Profit! But not for them.
Having left the EU, we are finding it hard to make ends meet. If you send me £50k,I will be able to release £100m frozen in evil EU banks. I will give you 50%.
The offer being presented sounds too good to be true and the request for money upfront is a common red flag for scams.
> These huge companies need to stops behaving like they own the world.
How would you call that?
[1] https://en.wikipedia.org/wiki/Server_Name_Indication#Encrypt...
[2] https://blog.cloudflare.com/handshake-encryption-endgame-an-...
Coupled with uBlock origin on all laptops and PCs, the online world is very ad-free.
If I bypass the blocking I am dismayed by how much ad crap there is out there.
All they needed, then, was to have an event appear “extraordinary” and they could legally compromise the privacy of the entire population.
You also have their reputation to guide you and their professional organisation theoretically enforces minimum standards.
You have no such recourse against chatGPT.
With a real lawyer almost all the time what they tell me will be legally correct, so if I don't know how to recognize when something is not legally correct that will almost never hurt me.
From what I've seen of people's posts of ChatGPT output it is much more likely to provide incorrect legal advice, and so using it without having a way to recognize incorrect legal advice is much more likely to hurt me.
You can't sue OpenAI for giving you really bad advice because they're not a law firm.
Also in the UK, for example, lawyers can't hide behind a limited liability company, they have to have skin in the game.
i.e. you can sue them personally for negligent advice and in theory they could loose everything they own (barring tools of the trade and bedding).
You can't do that to anyone that works at OpenAI Incorporated just because their language predictor convinced you of something that wasn't true.
Even if they were based in the country you could only sue the corporation.
Then this person will generate a legal document, which is eighty to ninety percent already there. The next step is to correct that remaining 10% of the document and you are good to go. Instead of paying 1000$ to a lawyer for legal fees, you paid 50 or a 100 bucks and the quality is the same, if not better. Specialized tools for that purpose are created as well, ai-lawyer or something like that.
And we all know if ads come into play then tracking follows closely.
What’s the correlation between the alleged privacy violations of OpenAI laid out in the article and the “bureaucrats only pretend to work”?
Honestly asking: if there are indeed privacy violations in OpenAI (we don’t know that yet I think) shouldn’t that authority address them?
These companies are using the old phone infrastructure that on paper could be traced without problems. Yet nothing, they operate with impunity
A is not doing good in B B+ is a worse version of B A addressed B+
Then people not encouraging them, but still say A is "pretending to work"...
Are you "pretending to think", or just is another troll?
Privacy is so broken here.
Yesterday I received a call from Bari, my patron saint's city in Italy. It seems they're exporting their spam. Italy has a weird criminal legislation for scams, that's why there are so many fake products in used items applications like Wallapop or Vinted.
It might be worth getting a SIM and/or VOIP number from a different country and a different country code.
So do (certain) books.
That's another issue right? If you let your minor access stuff, they.. access stuff. Hard to control? I know and it is. How is this specific to OpenAI?
* a box of matches
* a handgun
* an assault rifle
* a 50 cal BMG
* an ICBM with nuclear MIRV
Saying that X has a property similar to the one Y has while ignoring the magnitude of the difference is silly.
[Edit: the ICBM was edited into the comment after the fact.]
I guess I can be nonchalant about this topic. For me personally I cannot imagine something worse than either books or anything you can already access on the internet. To me it is not an assault rifle as you say, but I understand that's just an opinion.
I think we had very similar argument when posted showed a tool that could approximate users based on their writing style and more recently copying voice based on 20 seconds. We can estimate risk. We don't get it right consistently though.
Parents can try to block chatgpt with a firewall if they wish. It’s no less likely to work than blocking other internet sites.
Edit: Also, LLMs do have mandatory parental controls. They work about as well as book censorship, safe search or internet blacklists (very, very poorly).
I disagree it's easy to block the internet in general, but I get the point (I think).
These tools exist where a non technical user can install it in their own network and block websites by URL. I don't know what else is needed, since you acknowledge this already exists.
Is that true? Can a 13 year old child in Italy not walk into their local town library and pick a novel off the shelf and start reading all sorts of violent and explicit narratives? Not to mention all the medical textbooks, and books containing images of artistic works depicting undressed humans.
What kind of dystopian library do you go to? Kids can get what they like where I am.
It’s mostly self checkouts, so yes, if the library has the book. They wouldn’t have porn magazines.
Or they can read it there, or they can take it to the counter and get it out via the librarian.
There are also computers for use, though I assume they have filters/blockers/restrictions.
That the difference didn’t matter is my opinion and that is just disagreement. Determining what ballpark something is in wrt damage is, in our context, subjective, no? I did not think what you argued (or what I thought you argued) was impossible or unimaginable. That is different from incredulity. Right? I don’t care either way, honestly curious. You may enlighten me if you wish.
It seems silly to be able to say to everyone that disagrees on an assumption you made that they are making an argument from incredulity.
This is simply not on the scale of dangerous things - if something exposes minors to answers unsuitable to their degree of development, well, that's completely fine. With this particular argument there's no tradeoff of "is it justified to do X to protect against the bad thing Y" because in this case Y is zero, preventing this justifies literally nothing.
If parents want to disallow their kids from reading "unsuitable answers", that's between the parents and the kids, but it doesn't imply that "unsuitable answers" should be somehow limited.
There is no current plausible evident mapping from the example, to any LLM-powered service currently on offer, leastwise in Italian.
it's not, that's why there are consent thingies on websites (e.g. when you could not sign up for instagram as a minor).
I don't know what strange thing the regulator found in chatgpt, but it's pretty standard.
I think it’s called a “consent thingy”
Are there consent thingies on Google and Wikipedia?
> when you could not sign up for instagram as a minor
Sign up to post stuff. There are normally no "consent thingies" for looking.
If a parent doesn't want a minor to look at stuff they should either not give them access or limit it.
Google has, just tested. Wikipedia hasn't. This website hacker news don't have one either and doesn't need one. Its when you want to monetize the data that you need one, Google monetizes data, wikipedia and hacker news doesn't.
but perhaps the difference is that chatgpt could tell them stuff like "yeah, you should kill yourself"?
That case was big on the public opinion in Italy, and quite recent. No doubt it affected this case too.
> So do (certain) books.
Minors are typically given books that are appropriate to "their degree of development and self-awareness."
This is not about what they are given, it's about what they have access to.
But most kids don't manage to do that for some time. School libraries (typically) don't have porn in them, and internet access is often supervised or limited.
The root of this thread quoted the article selectively. The full quote is:
> It added OpenAI does not verify the age of users and exposes "minors to absolutely unsuitable answers compared to the their degree of development and self-awareness."
That is very reasonable take, especially given how insane ChatGPT can be.
I understand it's important, but I hate bureaucratic "solutions" that are technically correct but don't actually fix the issue.
Or I supposed they could sell their models as packaged software, and the store clerk can check the ID.
The model of standalone packaged software has several benefits to consumers, and privacy is one of those.
Reinforcement learning is the technique they use, and that means they are feeding the machine good text or image generations, produced by the machine. This means that the data are mushed together in the weights of billions and trillions of other data, and there is no way to get them back.
The only protection they have is that they those materials are usually (but not always) available in certain hours and there is a nice warning before that says that the content is not appropriate for them.
Chat GPT I can manage the same way I can manage search engine and video site use.
This is basically the same reasoning why it is legal for parents to buy cigarettes and store them at home, but shop owners can be held liable if they do not check the age of people that they sell cigarettes to.
Rape, incest, murder, maiming, slaughter, torture...
Neither have you - those things are omitted in Sunday school.
* for some value of reasonable -_-
[EDIT] the privacy regulator is independent from the government but elected by the parliament every 7 years. nevertheless this is a testament on how in general, regardless of political party, the situation is at the moment and for the foreseeable future
[0] https://www.bbc.co.uk/news/world-europe-65110744 [1] https://www.open.online/2023/03/31/rampelli-fdi-parole-stran...
If openai perceives this to be just a problem for one 60M people country, not particularly known for tech enterprises, they may just shrug it off and close off service to Italy and call it a day.
That's exactly what they did. My plus account got refunded and blocked. VPN only allows me to access the free service, so no GPT-4 for me.
So unless other countries are following on and ensuring that tech giants are respecting privacy, this will just hurt Italian citizens and their ability to compete globally.
That's a political question, I just want to point out that this measure is backed by the GDPR, for better or worse.
At least some of the big companies take this seriously, because I've worked in consultants and seen it. It would be completely reasonable for OpenAI to be more private in the paid models - make the weights readonly, encrypt conversations, allow permanent deletion.
For the free models, I'd find it OK to train on the input, but GDPR says users should be able to request data deletion - not sure how viable that is for LLMs, where training frons scratch regularly (without the requested deletions) is probably expensive as fuck.
The internet has been a wild west with lots of privacy abuse, it's good to see some rules and enforcement!
It was expensive but we had to retrain models frequently anyway because of other reasons so this just added a more strict cadence and time bound checks but didn't really inflate costs dramatically
It is neither "antiquated" nor "idiotic", I value good, tasty and healthy food, in that regards I think Italians and French are alike.
Garante della privacy is an independent office, and there were very simple motivators behind this choice: - illegal or improper use of personal data - nothing to protect children
That's it. Once they "fix it", there can't be so much that can be done on this.
After the TikTok case etc., I believe countries are getting a little bit ahead on such topics, before something small becomes the next Facebook and it's basically impossible to stop.
The current president of garante of privacy was chosen in 2020, while the current government has been running for less than a year.
- Italy, like the rest of south europe is hobbled by an army of bureaucrats doing busywork and their jobs are the first to be threatened by an AI speaking fluent Italian. So it helps them to keep unemployment from getting even higher
- It's an opportunity for an Italian company to create a model and grow in this window of opportunity. Italy has great engineers
Is it? It is probably impossible to find enough data to train an LLM without accidentally including at least one piece of PII. Even manage it, how would you ever prove it?
The Internet is bigger than Italy
nobody is going to invest a dime in a country where regulators and government are against anything that is "new". it's just not a place for new business or tech overall. it's a very hostile environment to be operating in
Does it? Ferrari's become a real joke in recent years. I do fully buy the bureaucrats being threatened by automation theory though.
> this is obviously a dumb move
It's also a dumb move by OpenAI to pretend they can get away with not processing data in the EU like any other service has to. Just spin up a few instances, what's the big deal? It's just complete arrogance on their part. GDPR is not an optional suggestion.
No it's some dumb fad. If you are not in Europe just disregard it. You don't have to respect Republic of Peru laws either.
Whether you can be reached and punished by a Peruvian court is another issue.
Similarly, if your business serves any EU country, you have to respect its laws, and that includes GDPR, whether you like it or not.
OpenAI's choice is then to close access to the EU, see its access forcibly shutdown, or comply with local laws.
Since the EU is probably a very significant market for them (probably on par with the US), playing dumb is fairly dangerous.
On the other hand, the sudden disappearance of ChatGPT in Europe may be what allows a locally grown one to succeed commercially (I doubt OpenAI will remain the only AI service provider forever).
Most of them work abroad.
The brain exodus (fuga dei cervelli) may have slowed down in the last few years, but depending how the situation evolves it may resume
But i do think that outright banning foreign products is a way to grow some tech sector.
I wonder whether there are real hard numbers supporting this statement. Not saying it's not true, just wondering whether it actually is.
I checked once for another country of South Europe and the reality was that both France and Germany had more "bureocrats" (public servants) per capita, contrary to public perception.
There are many things we all think are true that, when actually checked, turn out to be false. Sometimes it's a matter of false stereotypes and sometimes it's something that was true at some point but it's not anymore.
For example, about social mobility: USA is known as the land of the opportunities and a much more open and meritocratic place than Europe. That was certainly the case when it was founded. But the reality is that in the last decades (Western) Europe's social cohesion system created a much more favourable environment for children of poor people to prosper somewhat equal opportunities to children of medium and high earners (good and cheap/affordable public education, strong social network of public services,...), while the opposite trend took place in the USA. The results are quite outstanding:
https://www.weforum.org/reports/global-social-mobility-index...
I'm in the Netherlands as you can tell and 'even' we are not that much more progressive. There is currently a massive farmer uprising and everybody is complaining literally non-stop about just about everything. Meanwhile nobody has even tried GPT. I get pitchforked even in my own country for saying we need to stop focusing on breeding cows and get (and stay) better at real tech.
Then again, my social skills are not really up there..
EDIT: "real tech", I know. Simplification. I know it's hard and I know it's important we eat, but countries with like 5000% more arable land can provide for us.
Massive simplification, but I don't think it's a completely unfair characterisation.
Well, It's easy to see why you get backlash when you tell people to change their way of life, get asked for a reason, and say you don't care.
And vast swathes of technologists are insanely over-enthusiastic about technical change, to the point of it resembling a religion (and the singularitarians are like the monks who self-immolate themselves, except they want to immolate all the rest of us, too).
Frankly, it's probably far wiser to take it slow than charge full speed ahead for no good reason and just hope you can fix the problems you cause.
I asked a group 10 friends, none of who work in tech, about what they think about ChatGPT and then consensus is that it's a slightly better Google in certain situations. None of them are worried that it's going to put them out of work, take over the world, or violate their privacy. I have to agree with them. I think all this AI stuff is way overhyped, just like all the other fads that came before: VR, crypto, drone delivery, CRISPR, autonomous vehicles, metaverse, etc.
I remember having the exact same discussions on HN about autonomous vehicles over a decade ago. The consensus then was that autonomous vehicles would make truck and taxi drivers obsolete within 5 years, and that this massive, sudden loss of jobs would cause a lot of social unrest. Yet here we are in 2023 and there are a grand total of zero driverless trucks on the road. I'm not saying AV tech is totally useless or that we won't someday get to a world where a large percentage of vehicles are self-driven, but it's clear now that the hype and fear around them was heavily exaggerated.
I feel the same way about ChatGPT. It's definitely cool and impressive, but the hype will die down once people realize how truly limited it is.
Edit: I do think there is a slight difference from your example here. Trucks are already here and driving them is a known thing and it is easy to see how it could work (making it work is still hard). Automating cognition itself is automating a nearly unknown skill. Nobody quite knows what it is we are doing and what box we are opening.
That is entirely reasonable ask, especially when the harm could be large. It's a lot harder (and often impossible) to put a genie back in a bottle once it's out.
> I remember having the exact same discussions on HN about autonomous vehicles over a decade ago. The consensus then was that autonomous vehicles would make truck and taxi drivers obsolete within 5 years, and that this massive, sudden loss of jobs would cause a lot of social unrest.
So some internet commenters' schedule was wrong, but that doesn't mean the bigger point was wrong. Some people thought we'd die in a nuclear war in the 80s, and they'd still be prescient if it turns out we die in on in the 2030s.
Technologists tend to be pathologically optimistic about technology, and tend to hand wave away the problems it will cause. It's important to keep that attitude in check, because they sure as hell don't seem to have the wisdom to do it themselves.
https://arstechnica.com/tech-policy/2023/03/these-angry-dutc...
Just one sample quote, but it's worth reading it all:
> The dispute over nitrogen permits has put Microsoft’s data center developments in direct opposition to an increasingly powerful farming community. Earlier this month, a new political force, called the Farmer Citizen Movement (BBB), did so well in provincial elections, it became the joint-largest party in the Dutch Senate. The party, which emerged in response to the nitrogen crisis, also has strong views on data centers. “We think the data center is unnecessary,” says Ingrid de Sain, farmer turned party leader of the BBB in North Holland, referring to the Microsoft complex. “It is a waste of fertile soil to put the data centers boxes here. The BBB is against this.”
And another one because it shows some of the thoughts:
> “Of course, we need some data centers,” he says. But he wants us to talk about restructuring the way the Internet works so they are not so necessary. “We should be having the philosophical debate of what do we do with all our data? I don’t think we need to store everything online in a central place.”
I'm waiting for them to suggest it should be moved to the cloud rather than put in data centres.
This is a symptom of widespread technological illiteracy, globally (at least in the west)
> Ruiter says he’s continued to talk about data centers because he wants to remind people that “the cloud” they’ve come to rely on isn’t just an ethereal concept—it’s something that has a physical manifestation, here in the farmland of North Holland. He worries that growing demand for data storage from people, and also, increasingly, AI, will just mean more and more hyperscale facilities.
Your country is very lucky to have its own high-quality farmland and the culture around it. The food there is of such a quality that "countries with like 5000% more arable land" will never have a chance at of having. See the US, for all its land, most of the food is low in nutrition or outright toxic.
I am European, and I just proved it by complaining about complainers :)
Also, reverse the tables: If someone comes suggesting to you to ban computers and the Internet completely and pull a study out (Internet damages brain). Would you be happy, offended, indifferent... okay I hope you get the point.
And even capital gains are taxed far less than income.
I think it's more that the US was made up of immigrants so it got to start anew without a massive established aristocracy and monarchies.
There is an issue on the capital gain / income in the E.U., but my understanding was that the U.S. was even worse in that regard (people can live of their salary through most of Europe).
I live in the UK. Our Secretary of State for Science, Innovation and Technology is a woman called Michelle Donelan. She graduated with a BA in history and politics, and her career outside of being a career politician was in marketing, including a time working on Marie Claire magazine and for World Wrestling Entertainment (WWE). How in the world is she qualified for to run the nations tech initiatives? If she was appointed as CEO of a tech company, the stock would sink like a rock over night. Dare I even get started on Michael Gove, who originally wanted the role...
Taiwan's Minister of Digital Affairs; Audrey Tang. Tang was a child prodigy, reading works of classical literature before the age of five, advanced mathematics before six, and programming before eight, and she began to learn Perl at age 12. On CPAN, Tang initiated over 100 Perl projects between June 2001 and July 2006, including the popular Perl Archive Toolkit (PAR), a cross-platform packaging and deployment tool for Perl 5.
South Korea's Minister of Science and ICT; Lee Jong-ho. Professor of electrical and computer engineering at Seoul National University. He was named Fellow of the Institute of Electrical and Electronics Engineers (IEEE) in 2016 for contributions to development and characterization of bulk multiple-gate field effect transistors.
Australian Minister for Industry and Science; Edham Husic. Husic worked as a research officer for the member for Chifley, Roger Price. Husic was first elected as a branch organiser in 1997. In 1998, he was elected as vice-president of the Communications Division of the CEPU. From 1999 to 2003, he worked for Integral Energy as a communications manager.
That's just from a quick search of some countries other than Europe/US/China. I tried Israel and Singapore too, but neither of those ministers had a "technical" background per-se.
I don't disagree with your general point that technical competency is a really, really good idea, but I don't share the I guess cynism. Lots of people don't have the capabilities of their subordinates and that doesn't stop them from being effective leaders. The leaders we look at are just incompetent.
It's the job. It sucks. Nobody that is actually good would want to do it. It ends your life.
Edit: it also doesn't help that these leaders are chosen either directly or indirectly by people - the general public - that have no idea what the job actually entails. To become a politician you have to endure the political equivalent of a modern code interview - being "popular" - without actually testing if you can do the actual job and have the required levels of competency for it.
I do think that they should have a basic grasp of the fundamentals of their field though, and most politicians honestly don't even have that. I don't want to put up walls to being a back-bencher MP, but there should be a bare-minimum barrier for entry for certain Ministerial positions, especially one like Technology minister. You can't have someone leading a team who needs every-single-concept dumbed down for them so they can only make decisions from basic abstractions.
I think the problem with democracy is we ultimately interview and select leaders whos skills are in persuading a population, but we don't generally need those leaders to actually take the job, we need people who are good at distilling information and making appropriate judgements for the benefit of the population
William Easterly.
I too wish they'd know more about what they decide on, but really they should already rely on subject matter experts and otherwise I don't think the problem is lack of knowledge, as the quote indicates. It was said in the context of erradicating poverty but I think it applies to these discussions too.
Arguing from authority is nice and all (not), but the problem is not lack of technical expertise in decision makers (no one can reasonably expect a politician to understand modern AI tools), but rather about the decision making process itself.
There should be an established process by which such a dumb decision, with - in all likelihood - negative economic implications for the entire country, could be put to rest via a democratic process.
I'm not asking for some IEEE fellow with 100s of patent. I'm not even asking for a junior engineer with a couple of years in the industry. Hell, I daren't even ask for someone with a Math A-Level at this point. I'm asking for someone who can string a sentence about technology together, while also understanding a 10th of what they just regurgitated. It's embarrassing watching the leader that is meant to represent our industry go on stage and repeat a babble of buzzwords that they learnt about 4 hours before, in their latest think-tank meeting. That's not leadership. That's bull-shiting, and it stinks.
The whole point is that you don't need any tech knowledge to respect the basic ratified human right of access to information. That is all you need to not enact bans on specific websites for your country.
Being a good technologist is an advantage to such a position, obviously.
I don’t have much of a problem with a minister who knows they’re not an expert but makes it a top priority to surround themselves with people who are, and to listen to them, who has good morals.
That of course describes zero Tory ministers but one can dream.
As consequence both journalism and politics in the UK seem less about the truth or doing what's best and more about selling convincing short term rhetoric.
We need a revolution where we hang the last Cambridge classics graduate with the entrails of the last Oxford PPE graduate[1].
1. Hahahahahaha, I'm joking[2] of course!
2. Kinda...
There's plenty of innovation happening in Europe. See e.g. ASML.
What Europe is not good at is generating a lot of hype around something. Which has probably something to do with the investor climate there.
"No weed for me thanks, I don't wanna take any chances. I'll stick to the cocaine tonight"
"Custom officers can subject travellers to a drug screening test at the point of entry to Singapore. If you test positive for drugs, you can be arrested and prosecuted, even if the drugs were consumed prior to your arrival in the country."
That's insanity.
There are billions of people who would love to live there.
Now we're back in the states we hit the vape quite often but didn't need it in SG. No place has everything.
EU user data can't be stored in the US.
India also tried to push for data locality (though I think they went back on that)
European data, European rules.
I'm still waiting to see how well that holds up in court.
https://www.pinsentmasons.com/out-law/guides/international-t...
I'll wait to see how it holds up when the EU tries to enforce it against a US website with no presence of any kind in the EU.
That's called moving the goalposts.
But even in that case: the EU has a lot of power and no matter what you are still required to have a legal presence in the EU if you want to serve EU customers. Breaking the law is generally not the best course of action for any company that wants to stay in business over the longer term.
No, it isn't. That's the test.
> no matter what you are still required to have a legal presence in the EU if you want to serve EU customers.
That's nonsense. There is nothing stopping EU citizens from buying something via my US based website while they are in the EU, and I have no obligation to have any kind of presence in the EU.
Ignorance of the law is not an excuse for breaking the law.
https://ico.org.uk/for-organisations/dp-at-the-end-of-the-tr...
https://gdpr-info.eu/art-27-gdpr/
You seem to be arguing from how you believe it should work or how you think it works without knowing how it actually works, which is quite important when you are operating a business.
Practicality > useless laws
The Deloitte page I linked to gives a Chinese web store located in China with no EU presence as an example.
It's bonkers that the EU thinks they can enforce their laws in a situation like that. But then, that's why it hasn't been tested.
It's basically a 'feel good' law with no teeth (at least the extraterritorial aspects).
It will drive Europe to a sort of digital isolationism where offshore companies will either a) dismiss and continue b) cease operations there.
I think it's like I said, it's a lot of "feel good" laws.
> It will drive Europe to a sort of digital isolationism where offshore companies will either a) dismiss and continue b) cease operations there.
I think it's more likely the US adopts a softer version of the GDPR, and it will be the EU and the US and the Commonwealth countries vs pretty much other more restricted Internet 'islands'.
I really hope we have a working decentralized alternative before that happens. It's something I want to start contributing to later this year, because I think it really needs to be a priority.
You seem maybe out of our depth in this discussion. I'm not sure why you take me pointing out that truth of the matter that the GDPR is unprecedented in its extraterritoriality as an attack, but it's not. This mistake is clouding all of your replies and input into this discussion.
I'm fully aware of the law. That's what has been being discussed up until this point. The whole point of the law is that it isn't enforceable.
> You seem to be arguing from how you believe it should work or how you think it works without knowing how it actually works, which is quite important when you are operating a business.
No, I'm arguing that the GDPR is unprecedented, and EU has tried to claim jurisdiction in areas that they simply can't enforce.
If you believe otherwise, that's fine, but almost all of the legal community disagrees with you.
That's baseless rambling, sorry.
Do you have anything to contribute other than misguided insults?
Companies can either adapt to the ruling or take their business elsewhere.
No one claimed otherwise.
It's still fascinating (and, I believe, a first) that the EU thinks they have extraterritorial jurisdiction just because their citizens are affected.
If I want to sell data in the EU, I can. I'm not subject to their laws unless I have a presence there.
GDPR tries to change that.
See https://www2.deloitte.com/ch/en/pages/risk/articles/gdpr-ext...
This is more like me deciding to try and sue people in other countries because they said something I didn't like on the internet.
In general countries may well claim that their law applies even if you believe it doesn't, you then break that law at your own risk, and given that the penalties can be pretty serious I would caution against this without having consulted with a lawyer.
Note that I'm perfectly fine with the EU protecting the rights of its citizens, being one of those myself, and that I'm also perfectly fine with the US protecting the rights of its citizens.
I'm a bit weirded out by how the US taxes its nationals even when they live abroad but if that's the law then that's how it is for now.
So what? We're discussing the GDPR. Pretty sure the US has no similar law at all. GDPR was considered a first.
> In general countries may well claim that their law applies even if you believe it doesn't, you then break that law at your own risk
You're trying to compare GDPR to general prinicples and it doesn't work. GDPR was a new type of law.
See https://www2.deloitte.com/ch/en/pages/risk/articles/gdpr-ext...
"Let’s say for example that you are a Chinese web shop with a website that is available in German, French and English as well. You also process multiple orders a day from individuals within the EU and ship your products to them. This will make you fall in the scope of the GDPR, even though you have no establishment in the EU and are not performing any data processing activities within the EU."
Yeah, that's unprecedented.
https://oag.ca.gov/privacy/ccpa
> You're trying to compare GDPR to general prinicples and it doesn't work. GDPR was a new type of law.
No, it's a law like every other. You abide by it or you end up dealing with the business end.
> "Let’s say for example that you are a Chinese web shop with a website that is available in German, French and English as well. You also process multiple orders a day from individuals within the EU and ship your products to them. This will make you fall in the scope of the GDPR, even though you have no establishment in the EU and are not performing any data processing activities within the EU."
> Yeah, that's unprecedented.
No, it isn't unprecedented.
https://en.wikipedia.org/wiki/Unlawful_Internet_Gambling_Enf...
And that's before we get to AML and ATF legislation that the US has enacted and basically enforced all of the world of finance.
It’s trying to regulate the data collection and processing of users in its territory.
On the other hand, CLOUD act was trying to regulate data on foreign servers.
This isn't just my take by the way, it's common knowledge and was the cause for much discussion and speculation.
A country can ban a service when it doesn't follow its laws, there isn't anything crazy about it
It's more like not allowing you to smoke weed you bought in Amsterdam if you already came back to Italy
Something being legal somewhere doesn't mean it's legal everywhere
> When I connect to a service in the US, my bits are traveling there
Well yeah, that's like exactly the issue they're pointing out ...
In economics this is called "createtive destruction" [0]. Basically it's the freedom of messing up someone else's business by creating something better. Think e-mail destroying most jobs for mail delivery or digital photos destroying photo development shops.
One of the hallmarks of lesser developed economies is that they do not allow these kind of things. What happens in stead is that the people that have a lot to lose will use their political power to stop the innovation from happening.
The more common practise this is in a country, the less developed the economy is usually. Because this partly destroys the incentive to innovate.
So basically a lot of powerful people in Italy are pretty scared for their jobs / income because of the rapid innovation in Large Language Models.
It makes sense that now that they're huge they need to operate as a more mature company.
They'll hire some expensive lawyers and enable Facebook style age verification on sign up and they'll get away from this one. But I'm sure they'll have a thousands of other random requests from all over the world
I very much doubt it happened the way you describe it, you're probably omitting very important details
So while I won't join in the assumption that the story was a lie/exaggeration, I am equally interested in getting the full details because I'd like to know if it's the case that minor violations like that actually are being enforced.
In which case the detail OP ommited would be that they did not in fact ask for consent
https://www.sueddeutsche.de/muenchen/muenchen-google-fonts-a...
Does OpenAI have a legal presence in Europe? If not, there isn't an enforcement channel. I suppose they could block EU IPs, but until enforcement is threatened they have better things to focus on.
or test it has been implemented?
https://www.reuters.com/technology/microsoft-talks-invest-10...
1. I've never seen the Italian government move so quickly on anything 2. Now that they have, they've done so for something extremely stupid 3. They haven't exactly halted AI development. They've just widened the productivity gap between Italy and the rest of the world. And Italy wasn't exactly a beaming light of economic productivity beforehand. 4. Within Italy, tech savvy people will just use VPNs. Most people aren't tech savvy though, so you're widening the gap even further within your own borders.
I don't want an incompetent patronizing government. I want competent leadership in politics and business that is able to set up a culture of innovation.
This isn't an EU level decision. Countries in the EU have a lot of control over their own affairs, as they should.
Conflating EU and Domestic policies is a bad thing (this was done a lot in the UK)
[1] From the FT but here's a non-paywalled link https://archive.is/p4H9X
Here's a classic for you, one of the early incidents which lead to this kind of regulation: https://en.wikipedia.org/wiki/1858_Bradford_sweets_poisoning
Here's some more contemporary links:
https://food.ec.europa.eu/safety/food-improvement-agents/add...
https://food.ec.europa.eu/safety/food-improvement-agents/fla...
Which includes an answer to your question: "The procedure for authorisation of a flavouring substance is common to the one established for food additives and enzymes under Regulation (EC) No 1331/2008."
>Are you seriously confused why governments regulate what can be put in food and sold to the public?
Are these the same regulators that allowed Olestra to be used? sidebar--just to check the spelling of Olestra, I used the Mac's force click dictionary access: "Origin 1980s: from (p)ol(y)est(e)r + the suffix -a." WTF? Seriously? We dropped some letters from polyester and called it food ingredient?
Yeah, sounds like some "regulations will save us" doesn't work as expected.
I don't see how said regulation would have helped in this case, the shop owner simply mistook fake sugar for arsenic, it's not like he decided to sell arsenic-flavored candies.
(He didn't mix up the sugar with arsenic. He mixed up the gypsum.)
Then you're free to do so if you aren't putting artificial sweeteners in them.
https://en.wikipedia.org/wiki/Commission_Directive_91/71/EEC
So Italy's concerns might also apply to us, and every EU nation with EU GDPR.
BUT let's not kid ourselves there is huge pressure to stop OpenAI from techphobes to pearl-clutching techphiles and of course ruthless rivals who want a breather to catchup.
This was the bit i wondered about, there’s at least an incentive for this kind of jiggery pokery lobbying but little transparency.
It's a decision by a domestic DPA based on the GDPR. In practice, it will have an impact across the EU, because any company intending to operate uniformly across the EU has to, in practice, comply with the most onerous GDPR interpretation taken by any domestic DPA.
This ratcheting effect is a practical reality given how the GDPR operates. It's also why orgs like Schrems' NOYB celebrate individual victories with the most activist DPAs. They ultimately do have an impact across the EU.
In this certain case, I see already other nation's leaders and eventually the EU commission feeling inspired by this "bold" way Italy deals with ChatGPT. And #chatcontrol is an issue that directly comes from the EU commission (again the German "home secretary" is pointing at Brussels while officially hilariously stating "no we won't install client-side scanning everywhere").
I wonder where Belgians point to. Schuman?
But boy was I wrong. The people criticizing GDPR were right: Tech giants were able to cope better with the regulations while smaller domestic companies were put under an additional burden of excessive bureaucracy. And from what I perceive, there's now cookie banners everywhere while my personal data is still going into opaque silos.
Those cookie banners are either non-compliant with the regulations or meaningless. Why people add them is anyones guess.
It's true that a cookie banner (notification only) does not equal "the site can now do whatever it wants and is GDPR compliant thanks to the banner".
However, cookie notification banners are nothing to do with GDPR! They are to comply with an earlier (but still active after GDPR) bit of legislation, the 2002 'ePrivacy Directive' (sometimes known as the "cookies law").
If you don't go near personal data, but still want to use cookies for website functionality, then GDPR doesn't apply but you need to notify users of your use of cookies. If you are doing stuff that's covered under GDPR, then you obviously need to do more than just a cookie notification, and in most cases doing that 'more' will cover the non-personal cookies too so no need for a separate cookie notification on top.
https://en.wikipedia.org/wiki/Privacy_and_Electronic_Communi...
edit to be more specific: section (25) includes "Where such devices, for instance cookies, are intended for a legitimate purpose, such as to facilitate the provision of information society services, their use should be allowed on condition that users are provided with clear and precise information in accordance with Directive 95/46/EC about the purposes of cookies or similar devices so as to ensure that users are made aware of information being placed on the terminal equipment they are using." and "Access to specific website content may still be made conditional on the well-informed acceptance of a cookie or similar device, if it is used for a legitimate purpose." (meaning that unlike with GDPR, it's easier to say "these cookies are necessary, accept them or don't use this website")
Full text of that 2002 directive: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
And usual disclaimer, this is not legal advice, if you're doing anything affected by either the ePrivacy Directive or GDPR you'd do well to do one or both of getting specific advice from a lawyer with specific expertise in this area, and that if it's a personal site (or a company without the money for legal advice), better safe than sorry and better to give users more power (in terms of requiring their consent to use even cookies that might not need explicit opt-in to be legal, etc) than required rather than less. Both better in terms of liability, and in terms of ethics!
The cookie banners people are now complaining about are literally companies skirting or otherwise breaking GDPR. Because they now have to ask for your consent before the siphon your data and sell it wholesale to the highest bidder.
There are certainly plenty of examples of poorly implemented banners attempting to comply with GDPR while not actually being compliant, where consent is required, but I wouldn't call those 'cookie banners' since they generally talk about privacy and personal data, not just about cookies/local storage.
My point was that there are plenty of websites that don't need to comply with GDPR (because nothing they do falls under its scope), but they still need to comply with the ePrivacy Directive and therefore there are plenty of cookie banners used for that purposes that are a perfectly acceptable way of complying with that law - though because people are more familiar with GDPR than with the ePrivacy Directive, they see those banners and think it's a non-compliant attempt at dealing with GDPR.
---
I think, but don't quote me in that, that with ePrivacy you don't really need a banner, but an explanation that you use cookies. But that is a minor issue
Hearsay and rumors, so don't take this seriously
But it's from 2017... https://eur-lex.europa.eu/legal-content/EN/TXT/?darkschemeov...
(If the twitter discussion was interesting, any suggested accounts to follow for this sort of topic?)
I guess you'd want follow
- Felix Reda https://twitter.com/Senficon (former European MP for the Purate Party)
- NOYB EU https://twitter.com/NOYBeu (fighting the GDPR fight)
- Max Schrems https://twitter.com/maxschrems (https://en.wikipedia.org/wiki/Max_Schrems)
These are more or less the usual suspects you'd follow :)
My point is: Did it help fighting privacy issues? I don't think so. Did it harm? I do think so. Will it ever be somehow measured for its effectiveness and be taken back/changed to be more effective? I don't think so. So better get rid of it.
The problem is that not enough fines have been meted out. Had they been, we'd see less of the unuseful, annoying, unnecessary banners. Because they are this way on purpose: to make you "consent" to wholesale collection and trading of your data.
I don't think it has made of jot of difference for privacy, but it sure has degraded the user experience of using the web.
There was already one large crackdown on non-compliant cookie banners, and even large entities had to stop fooling around and implement them properly.
The leftovers need to be picked up one by one, but that necessarily takes time.
I don't really want my government 'innovating' much at all. I want them to provide for defense of the people and freedoms.
How many competent government leaders have you seen?
Hear, hear.
How many "accept all cookies" button did you have to press today?
As additional homework, you can also lookup malicious compliance etc. Or even the sibling discussion on how Facebook wants you to apply for a permission to opt out of their tracking: https://news.ycombinator.com/item?id=35383925
Privacy should have been promoted through technological means, e.g the EU could have funded development of fingerprintless browser technologies, zero-knowledge proof based identity verification, etc, instead of through bureaucratic regimentation of private interaction.
Not, however, on Hacker News, because Hacker News isn't using data for more than actual functionality, and you don't need to ask permission in that case.
edit: minor additions/corrections
However, I often sense that in many places, the country seems to be entrenched in its medieval past.
This decision will not accelerate Italy's progress towards a more prosperous future.
But I am happy to have a watchdog over my basic human rights.
> However, I often sense that in many places, the country seems to be entrenched in its medieval past.
It might be. But not on this front.
For example, what if some italians uses chatgpt and leak things you dont wanna know about italy? That, I believe would prompt otherwise slow-to-act politicians to jump off their rocking-chairs and start making some phone calls.
Not about your neck.
Just a guess.
Lets ask chatgpt what he think about sex:
"It is important to protect oneself during sexual activities to prevent the transmission of sexually transmitted infections (STIs) and unwanted pregnancies. Using condoms or other forms of contraception can greatly reduce the risk of transmission and unplanned pregnancy.
Additionally, it is important to communicate openly and honestly with sexual partners about sexual health and STI status, and to get tested regularly for STIs, especially if one is sexually active with multiple partners.
Ultimately, the decision to protect oneself during sexual activities is a personal one that depends on individual circumstances and preferences. However, it is generally recommended that individuals take steps to protect themselves and their sexual partners from potential health risks."
I especially liked the "multiple partners" part didnt you?
Besides, the Vatican has zero weight in decisions taken by the EU.
You are dreaming.
Read the ruling. They are specifically referring to the data leak of some days ago that revealed personal information of GPT users that 1) was not explicitly collected and 2) was available to subjects that should not handle it (other users).
now I am not saying that they have to stop making use of my data, but at least notify me how and where my of phone is being used?
https://help.openai.com/en/articles/6613520-phone-verificati...
This is also covered under the "consent" lawful basis part of the GDPR.
The bug is not a problem. GDPR covers data leaks. If you're an EU company you have to inform your DPA within 72 hours, and the users affected. It's not illegal to have such breaches. OpenAI isn't an EU company so doesn't have a DPA, but it did notify everyone that the leak occurred anyway.
I still don't find the guarantor's request unimpeachable
Nitpick: It asks for your name, email and phone number before you get to use it. Not to detract from your larger point, but people have expressed disappointment about the phone number part.
As long as they're transparent on what they're doing with the data I'm totally okay with it, nobody is forcing you to use ChatGPT.
If anything this news points to the opposite: that Italy takes privacy seriously in the digital world while large parts of the world are at the "who cares, they already have all my data" stage.
I fully agree. But do Europeans in general? Where I am (Sweden) the whole point of politics seems to be to “protect” us from ourselves.
"You are so dumb, you need to be protected by the state doing stupid things with your data."
Oh wait.. the whole world is not a developer. I can definitely see how some people need protection here. Even developers are inputting sensitive code and info about their work. Weird times.
You don't need regulation for companies to tell you that a product contains a harmful substance. You just need a functioning legal system.
In other words, it produces real things apart from food.
This is a great privacy initiative that will help Europeans focus further on things that actually matter as opposed to data mining.
Satire aside, the priority in Europe is not a prosperous future — it’s social stability.
Hear that Italians? If you don't surrender your data and your privacy to American companies you are medieval. According to some other comments, you are fascist too.
Also neither company seem to have much regard for user privacy.
To explain this further: OpenAI et al. (as commercial products) are being trained on content that is published under licenses that allow non-commercial use only. Do those systems respect these licenses? It doesn't look like that. "AI companies" need to stick to laws but as nobody is able to look inside their blackboxes, we can't make sure they follow the law. That's where legislation like this comes from.
and that's bad because?
I would see the point if they were training on my private data I entrusted to somebody and they illegally obtained it without my permission. Are they doing that?
As long as copyright is here; it is expected big players are to be bound by it to the same degree they push legal systems to bind the little guy.
What you get instead, is the big guy pilfering the little guys under the justification that "it's different when we do it, and if you challenge us, I'll put my subsidized legal department to work burying you."
Copyright needing significant overhaul or abolition doesn't detract from that state of affairs, I hope we can agree?
As Mom used to put it: The world ain't gonna change to accommodate you. You must adapt to it. When in Rome; pick 1:
Do as the Romans
embrace the consequences of non-compliance
GTFO
The world is otherwise your Oyster, until it isn't. The larger part of Wisdom is learning to recognize and accept when it isn't.Hold on, when did I consent to you monetizing my traffic? I just want to read your content. Pay me a share of the money and then we'll see if I want to allow you to use my traffic to make money.
That the rest of the tech world was so enraptured by the fact that suddenly, handing off people's business records to somebody else no longer involved literally moving boxes of paper, and threw professional discretion to the winds is more an indictment of the state of mind and sense of entitlement of the typical tech-enabled business class as a whole than a condemnation of the allegedly "backward" European Union.
t. American Technologist actually proud of the EU for standing up for common decency, and recognizing exploitive behavior when they see it.
And if their remembering-and-retelling constitutes a "derivative work" (or, perhaps, a "public performance"), they may be in trouble, despite the original work being openly published.
> We are issuing refunds to all users in Italy who purchased a ChatGPT Plus subscription in March. We are also temporarily pausing subscription renewals in Italy so that users won't be charged while ChatGPT is suspended.
> Dear ChatGPT customer,
We regret to inform you that we have disabled ChatGPT for users in Italy at the request of the Italian Garante.
We are issuing refunds to all users in Italy who purchased a ChatGPT Plus subscription in March. We are also temporarily pausing subscription renewals in Italy so that users won't be charged while ChatGPT is suspended.
We are committed to protecting people's privacy and we believe we offer ChatGPT in compliance with GDPR and other privacy laws. We will engage with the Garante with the goal of restoring your access as soon as possible.
Many of you have told us that you find ChatGPT helpful for everyday tasks, and we look forward to making it available again soon.
If you have any questions or concerns regarding ChatGPT or the refund process, we have prepared a list of Frequently Asked Questions to address them.
—The OpenAI Support TeamThere must be something fundamentally different between the two, and I'm not sure what it is.
If I could short LLMs in Europe, I would go all in.
It's "the few" who are not taking advantage of it.
Do you need to verify your age to perform a Google search?
I think "age verification" is just another "think of the children" ploy to force all websites to check their users' government IDs (starting with sites run by people whose politics are different from those of the government that's enacting the ploy).
That's all it takes to be offending for conservatives.
But of course they should have banned Windows 10/11, Office 365, MS Teams, basically any Microsoft product first. But the law in the EU seems to apply only for small companies. Big companies like MS, Amazon, Facebook etc. can do whatever they want.
I, as an EU resident citizen, have the right to know where MY data goes: Basically with GDPR the user must be informed clearly, as concisely as possible, in terms understandable even to a layman, about where his data ends up, giving active consent to its use (in this case consent has no inertia)
After the data breach on March 20, the Italian authority opened an investigation to examine the lack of user information and other related things! It doesn't seem to me that this is so wrong; I guess you want to know what data a big company has on you
OpenAI has 20 days to communicate the measures taken; it is not a ban on the service, but a response to possible data leaks
for reference, my family taxes are handled by a tax consultant, i do my taxes through an online service, which is way cheaper than having a dedicated consultant. since my mother couldn't keep her mouth shut, somehow this information got leaked to the family tax consultant, resulting in a police search of my office, and a mandatory visit to a police station almost an hour away. this kind of stuff happens regularly.
Why ? is it illegal to do taxes online in italy?
[1] https://www.garanteprivacy.it/home/trasparenza/organizzazion...
"It is important to protect oneself during sexual activities to prevent the transmission of sexually transmitted infections (STIs) and unwanted pregnancies. Using condoms or other forms of contraception can greatly reduce the risk of transmission and unplanned pregnancy.
Additionally, it is important to communicate openly and honestly with sexual partners about sexual health and STI status, and to get tested regularly for STIs, especially if one is sexually active with multiple partners.
Ultimately, the decision to protect oneself during sexual activities is a personal one that depends on individual circumstances and preferences. However, it is generally recommended that individuals take steps to protect themselves and their sexual partners from potential health risks."
Im sure they'd especially like the "multiple partners" part of its answer.
In my experience, very few companies in the EU actually care about innovation and lack world-class engineers.
> Having conducted risk assessments and threat analysis myself for various companies with a global presence, I was most intrigued by this phenomenon in the EU as it was mostly not driven by technical accuracy.
Reasons I heard for a lot of companies to not use GCP/AWS/Github simply were: It is a US company, it will be very easy for CIA to retrieve that data (https://en.wikipedia.org/wiki/CLOUD_Act) or poison the service, let's use XYZ local provider.
And the ironic thing is that these local providers had either a terrible reliability record or poor security posture so a mildly competent mediocre hacker would be able to compromise the data which is being defended against CIA. Not once in tens of engagements I came across a calculated measure of defending against nation-state vs run-of-the-mill malware.
Of course, for a company that's a numbers game. For private citizens or the general public, especially in countries with a history like Germany or Italy, it's not.
https://en.m.wikipedia.org/wiki/1948_Italian_general_electio...
A phobia is an irrational fear, this is a rational fear.
About how EU treat engineers, this is a separate issue, in France at least, there is the belief that advancing in your career (=get paid more) means becoming manager.
I think for career advancement, getting paid more is not the only motivation for a lot of world class engineers. Innovatio itself is sometimes sufficient.
User data uncertainties and not enough age gated.
The key issue under GDPR seems to be that OpenAI:
> lacks a legal basis justifying "the mass collection and storage of personal data ... to 'train' the algorithms" of ChatGPT"
My reading: OpenAI could comply with this by modifying ChatGPT to give users protected by GDPR a clear choice to opt-in vs opt-out on their chats being used as future OpenAI training data.
Here are the reasons:
DETECTED, from a check carried out in this regard, that no information is provided to users, nor to interested parties whose data has been collected by OpenAI, L.L.C. and processed through the ChatGPT service;
NOTING the absence of an appropriate legal basis in relation to the collection of personal data and their processing for the purpose of training the algorithms underlying the functioning of ChatGPT;
NOTING that the processing of personal data of the interested parties is inaccurate as the information provided by ChatGPT does not always correspond to the real data;
DETECTED, moreover, the absence of any verification of the age of users in relation to the ChatGPT service which, according to the terms published by OpenAI L.L.C., is reserved for individuals who are at least 13 years old;
CONSIDERING that the absence of filters for minors under the age of 13 exposes them to absolutely unsuitable responses with respect to their degree of development and self-awareness;
CONSIDERING therefore that in the situation outlined above, the processing of personal data of users, including minors, and of interested parties whose data is used by the service is in violation of articles 5, 6, 8, 13 and 25 of the Regulation;
RECOGNIZING, therefore, the need to have, pursuant to art. 58, par. 2, lit. f), of the Regulation - as a matter of urgency and pending the completion of the necessary investigation with respect to what has emerged so far against OpenAI L.L.C., a US company that develops and manages ChatGPT, the extent of the temporary limitation of the treatment;
CONSIDERING that, in the absence of any mechanism for verifying the age of the users, as well as, in any case, of the complex of violations detected, said temporary limitation must extend to all personal data of the interested parties established in the Italian territory;
CONSIDERED it necessary to order the aforementioned limitation with immediate effect from the date of receipt of this provision, reserving any other determination to the outcome of the definition of the preliminary investigation started on the case;
RECALLING that, in the event of non-compliance with the measure established by the Guarantor, the criminal sanction pursuant to art. 170 of the Code and the administrative sanctions provided for by art. 83, par. 5, letter. e), of the Regulation;
CONSIDERING, on the basis of the foregoing, that the prerequisites for the application of art. 5, paragraph 8, of Regulation no. 1/2000 on the organization and functioning of the Guarantor's office, which provides that «In cases of particular urgency and in which the Guarantor cannot be convened in good time, the president can adopt the measures pertaining to the body , which cease to have effect from the moment of their adoption if they are not ratified by the Guarantor in the first useful meeting, to be convened no later than the thirtieth day";
[1]https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb...
From the latest ChatGPT General FAQ [0]:
> Will you use my conversations for training? Yes. Your conversations may be reviewed by our AI trainers to improve our systems.
[0] https://help.openai.com/en/articles/6783457-chatgpt-general-...
https://help.openai.com/en/articles/6950777-chatgpt-plus
https://docs.google.com/forms/d/e/1FAIpQLScrnC-_A7JFs4LbIuze...
From the above, my understanding is that they currently offer opt out for the paid subscription users only ("ChatGPT Plus").
Perhaps they may end up compelled by this case to add a similar opt out to the free version.
Or, possibly, to allow a free choice - where opting in and opting out are equally straightforward.
Your Honor, I only murdered people in the past. I'm not murdering anyone at the moment so I should be set free!
At any rate OpenAI isn't an EU company and has no presence there, so can simply ignore Italy entirely (or block it themselves).
Then some more: I don't think OpenAI will have problems implement it, they are probably just late.
But the big issue may be another one (I hope to be wrong): if I train my model with the contributions of many users, then some users ask me to remove their 'contribution', am I able to do it?
As for the more interesting question if you can modify an existing model in a simple way: probably not. But you might get away with just dropping any response containing snippets of the contribution to be expunged, and that is hopefully good enough for the regulator.
> The authority said the company lacks a legal basis justifying "the mass collection and storage of personal data ... to 'train' the algorithms" of ChatGPT.
> ChatGPT also suffered a data breach and exposed users conversations and payment information of its users last week,
> It added OpenAI does not verify the age of users and exposes "minors to absolutely unsuitable answers compared to the their degree of development and self-awareness."
That's it.
Apart from the age verification I don't see major issues (though it wouldn't justify an outright ban)
Their partner/owner Microsoft already hosts GDPR compliant OpenAI GPT-3 models from an Azure data center (in the EU). It's only a question of time before they also host GPT-3.5-turbo and GPT-4.
https://learn.microsoft.com/en-us/azure/cognitive-services/o...
Azure ain't cheap but they know how to do EU compliance. Many EU governments put their citizens data on Azure's EU data centers.
https://www.adobe.com/sensei/generative-ai/firefly.html
https://blog.adobe.com/en/publish/2023/03/21/responsible-inn...
The creator compensation thing is probably speculative although they do have business reasons to follow through, like not alienating their entire customer base.
The article clearly states the issues
Seriously though this site could do with a filter like the major subreddits.
but you should write a js filter yourself, should be easy with Tampermonkey. or you could stay on reddit of course.
Or you could use GPT, lol.
I love everything about this. As usual EU leads the way in protecting people's privacy.
- the privacy commissioner is 78
- he doesn't have any tech background, he's a law academician
- the privacy commission office's home page still has a fax number on their front page, as of this morning
- the commissioner boasted in TV that he signed Musk's AI temp ban letter
- the official reason of the ban is that 12-year-old kids could potentially use the AI service, and OpenAI should instead filter them out
- no evidence that ChatGPT is bad for 12 years old is given
- no study on how many kids below 13 use the site, in relation to how many people overall in Italy
- he acted alone, instead as part of a commission, because he claims it was urgent
- no matter what, he is not liable for his actions by Italian law
Connect the dots anyway you like. I chose the following narrative:
At 78 he doesn't give a :poop:, he doesn't like progress because he's a boomer and abused his office to make a political statement because no one can touch him.
Apart from that, they would have a very good argument against most of the claims of the authority based on freedom of speech and information. They're essentially in the business of providing information
It's not like Italy needed the productivity boost (SORRY, SORRY!!)
What a win for Microsoft if they can expose openAI as a usable solution...
I wonder how will EU when the final ICE auto manufacturer and will go bust
Stop ChatGPT until it complies with privacy regulations. The Guarantor for the protection of personal data has imposed, with immediate effect, the temporary limitation of data processing of Italian users by OpenAI, the US company that developed and manages the platform. The Authority has simultaneously opened an investigation.
ChatGPT, the most famous among relational artificial intelligence software capable of simulating and processing human conversations, suffered a data breach on March 20th, concerning user conversations and information relating to payment by subscription service subscribers.
In the provision, the privacy Guarantor notes the lack of information to users and all those concerned whose data is collected by OpenAI, but above all, the absence of a legal basis justifying the massive collection and retention of personal data, for the purpose of "training" the algorithms underlying the platform's operation.
As also demonstrated by the investigations carried out, the information provided by ChatGPT does not always correspond to the real data, thus determining an inaccurate treatment of personal data.
Finally, despite - according to the terms published by OpenAI - the service being aimed at those over 13 years old, the Authority highlights how the absence of any filter for verifying the age of users exposes minors to responses that are entirely unsuitable for their level of development and self-awareness.
OpenAI, which does not have a headquarters in the Union but has designated a representative in the European Economic Area, must communicate within 20 days the measures taken in implementation of what is required by the Guarantor, under penalty of a fine of up to 20 million euros or up to 4% of the annual global turnover
IMHO that would block every LLM.
Artificial Intelligence: The Guarantor blocks ChatGPT Illegal collection of personal data. Absence of systems for verifying the age of minors
Stop ChatGPT until it respects the privacy regulation. The Guarantor for the protection of personal data has ordered, with immediate effect, the temporary limitation of the processing of data of Italian users against OpenAI, the US company that developed and manages the platform. At the same time, the Authority opened an investigation.
ChatGPT, the best known of the relational artificial intelligence software capable of simulating and processing human conversations, on March 20 suffered a data loss (data breach) regarding user conversations and information relating to the payment of subscribers to the paid service.
In the provision, the Privacy Guarantor notes the lack of information to users and all interested parties whose data is collected by OpenAI, but above all the absence of a legal basis that justifies the mass collection and storage of personal data, for the purpose of "train" the algorithms underlying the operation of the platform.
As evidenced by the checks carried out, the information provided by ChatGPT does not always correspond to the real data, thus determining an inaccurate processing of personal data.
Lastly, although - according to the terms published by OpenAI - the service is aimed at people over the age of 13, the Authority points out that the absence of any filter for verifying the age of users exposes minors to absolutely unsuitable answers compared to the their degree of development and self-awareness.
OpenAI, which does not have an office in the Union but has designated a representative in the European Economic Area, must communicate within 20 days the measures undertaken in implementation of what is requested by the Guarantor, under penalty of a fine of up to 20 million euros or up to 4% of the annual global turnover.
Rome, 31 March 2023
Provision of March 30, 2023
Register of measures n. 112 of 30 March 2023
THE GUARANTOR FOR THE PROTECTION OF PERSONAL DATA
HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter, the "Regulation");
HAVING REGARD also to the Personal Data Protection Code (Legislative Decree No. 196 of 30 June 2003);
NOTING the numerous interventions by the media regarding the functioning of the ChatGPT service;
DETECTED, from a check carried out in this regard, that no information is provided to users, nor to interested parties whose data was collected by OpenAI, LLC and processed through the ChatGPT service;
NOTING the absence of a suitable legal basis in relation to the collection of personal data and their treatment for the purpose of training the algorithms underlying the functioning of ChatGPT;
NOTING that the processing of personal data of the interested parties is inaccurate as the information provided by ChatGPT does not always correspond to the real data;
DETECTED, moreover, the absence of any verification of the users' age in relation to the ChatGPT service which, according to the terms published by OpenAI LLC, is reserved for individuals who have completed at least 13 years;
CONSIDERING that the absence of filters for minors under the age of 13 exposes them to absolutely unsuitable responses with respect to their degree of development and self-awareness;
CONSIDERING therefore that in the situation outlined above, the processing of personal data of users, including minors, and of interested parties whose data is used by the service is in violation of articles 5, 6, 8, 13 and 25 of the Regulation;
RECOGNIZING, therefore, the need to have, pursuant to art. 58, par. 2, lit. f), of the Regulations - as a matter of urgency and pending the completion of the necessary investigation with respect to what has emerged so far against OpenAI LLC, a US company that develops and manages ChatGPT, the extent of the temporary limitation of the treatment;
CONSIDERING that, in the absence of any mechanism for verifying the age of the users, as well as, in any case, of the complex of violations detected, said temporary limitation must extend to all personal data of the interested parties established in the Italian territory;
CONSIDERED it necessary to order the aforesaid limitation with immediate effect from the date of receipt of this provision, reserving any other determination to the outcome of the definition of the investigation started on the case;
RECALLING that, in the event of non-compliance with the measure established by the Guarantor, the penal sanction pursuant to art. 170 of the Code and the administrative sanctions envisaged by art. 83, par. 5, letter. e), of the Regulation;
CONSIDERING, on the basis of what has been described above, that the prerequisites for the application of art. 5, paragraph 8, of Regulation no. 1/2000 on the organization and functioning of the Guarantor's office, which provides that «In cases of particular urgency and in which the Guarantor cannot be convened in good time, the president can adopt the measures pertaining to the body , which cease to have effect from the moment of their adoption if they are not ratified by the Guarantor in the first useful meeting, to be convened no later than the thirtieth day";
HAVING REGARD to the documentation in the deeds;
ALL THE ABOVE CONSIDERING THE GUARANTOR:
a) pursuant to art. 58, par. 2, lit. f), of the Regulation, urgently provides OpenAI LLC, a US company that develops and manages ChatGPT, as owner of the processing of personal data carried out through this application, the measure of the temporary limitation of the processing of personal data of data subjects established in the Italian territory;
b) the aforesaid limitation has immediate effect from the date of receipt of this provision, subject to any other determination following the outcome of the definition of the investigation started on the case.
The Guarantor, pursuant to art. 58, par. 1, of Regulation (EU) 2016/679, invites the data controller who is the recipient of the provision, also, within 20 days from the date of receipt of the same, to communicate what initiatives have been undertaken in order to implement the provisions and to provide any element deemed useful to justify the violations highlighted above. Please note that failure to respond to the request pursuant to art. 58 is punished with the administrative sanction pursuant to art. 83, par. 5, letter. e), of Regulation (EU) 2016/679.
Pursuant to art. 78 of the Regulation, as well as the articles 152 of the Code and 10 of Legislative Decree lg. 1 September 2011, no. 150, opposition to this provision may be lodged with the ordinary judicial authority, with an appeal lodged with the ordinary court of the place where the data controller has his residence, within the term of thirty days from the date of communication of the provision itself, or sixty days if the appellant resides abroad.
In Rome, March 30, 2023
THE PRESIDENT Station
Now we just need a authentic Italian to tell us which version is most accurate :)
That said, all 3 do a decent job at translating, it's really hard for me to say which got closer (I can say GTranslate sure didnt, but it's not far behind) those kinds of docs employ legalese that's sometimes way removed from colloquial italian (e.g. "ovvero" almost always means "that is" in italian, but always means "or else" in legal documents).
I'm Italian. The proper translation is: "RECOGNIZING, therefore, the need to have the measure to temporarily limit the treatment, pursuant to art. 58, par. 2, lit. f), of the Regulations - as a matter of urgency and pending the completion of the necessary investigation with respect to what has emerged so far against OpenAI LLC, a US company that develops and manages ChatGPT". Everything else is translated pretty well.
If this regulator knows what is best, they should definitely fine Microsoft 4% of their global revenues on top of that reckless chat history leakage incident O̶p̶e̶n̶AI.com had.
There is a reason why Google launched Bard in non-EU countries.
† I mean, that's probably not the exact intention, but that is the effect of a huge monetary cap alongside the proportion of turnover. I also think 4% of turnover is problematic given the old Pinto equation (https://www.spokesman.com/blogs/autos/2008/oct/17/pinto-memo... ); I'd rather a cap set in the region of 150% of global gross profit, but capitalists would never go for that.
Is there a legal reason to play along? Trade agreement violation? Or, is it just a matter of wanting to keep those markets.
In short, walk with care on the feet of Caesar. For you are small, and once roused to anger, said train has not been known to quickly brake.
>Both translations effectively convey the main points and ideas of the original Italian text. However, the translation I provided seems to be more fluent and coherent, using more natural English phrasing and terminology. For example, "the Guarantor for the protection of personal data" is translated as "the Italian Data Protection Authority," which is more common and clearer in English.
>While Google's translation is generally accurate, it has a few awkward phrases or word choices that make it slightly less clear or idiomatic, such as "the best known of the relational artificial intelligence software" instead of "the most well-known relational artificial intelligence software."
>Overall, the translation I provided is more polished and reads more smoothly in English, which may be preferred for better understanding and clarity.
>Taking into account accuracy, fluency, and clarity, I would rate the translations as follows:
>My translation (ChatGPT): 95/100
>- The translation is accurate, fluent, and clear. It effectively conveys the original text's meaning and reads smoothly in English. The phrasing and terminology used are natural and idiomatic.
>Google's translation: 85/100
>- The translation is mostly accurate, but there are some instances of awkward phrasing or word choice. Some sentences may not read as smoothly or clearly as they could in English. Despite these issues, the overall meaning is still conveyed. Please note that these ratings are subjective and may vary depending on individual preferences and interpretation.
Not irony, demonstrating the point that GPT lies.
Pretty sure OpenAI could just ignore this if they wish, unless they have a presence in the EU.
Although realistically no big company would really do this.
As an AI language model, I do not collect personal data directly as I do not have access to user information. However, I understand that OpenAI, the company that developed and manages the platform, has been ordered to temporarily limit the processing of data of Italian users and is under investigation by the Italian Data Protection Authority.
As an AI language model, my purpose is to provide conversational assistance and generate human-like text based on the input provided by the user. My training data is sourced from publicly available text on the internet and does not specifically target any individual or collect personal data.
I understand that OpenAI has been accused of not providing adequate information to users regarding the collection and storage of personal data and not having a legal basis for such collection. I cannot comment on OpenAI's specific policies and practices regarding data collection and storage, as I am not privy to such information.
However, I believe that it is important for companies to prioritize user privacy and to comply with data protection regulations. I hope that OpenAI will take the necessary measures to address the concerns raised by the Italian Data Protection Authority and implement appropriate safeguards to protect the personal data of its users.
Gonna be really miffed if it turns out to be that easy ..
Training on publicly available data doesn’t mean that it doesn’t collect PII. Just ask it “who is <some public figure>?” to demonstrate this for yourself. I asked it about some of my colleagues and it was able to write a brief profile about them, and they’d barely qualify as public figures at all.
GDPR supposedly allows you to process public data without consent, but I’m not an expert on that specific usecase, and it seems to have plenty of grey areas. The right to be forgotten still applies though, and LLMs seem as though they would struggle with that. To me it looks like it’s probably one of the areas where GDPR is just manifestly impractical to manage, and the European courts have a habit of saying “too bad” in those situations.