It’s not surprising that ChatGPT has been accused of breaching the EU’s main privacy law – PIA blog noted that ChatGPT was a privacy disaster waiting to happen back in February. As the first complaint to be taken up by an EU data protection agency, this case will be watched closely by other EU Member States, and around the world. The Polish inquiry is likely to investigate many of the key GDPR issues that arise for AI programs and be used as a benchmark in future legal cases.

  • Magnor@lemmy.magnor.ovh
    link
    fedilink
    arrow-up
    10
    arrow-down
    1
    ·
    1 year ago

    Even if it is, this data is not processed in a way that would violate the law, unless the hosting party is doing something shady. It would be an incredible stretch to consider that a website only asking for a username to attach to a user somehow violates GDPR.

    • IzzyData
      link
      fedilink
      arrow-up
      12
      ·
      1 year ago

      Well for one thing a user is prevented from deleting their account when banned. I’m pretty sure this can be considered a violation of the law.

      • Magnor@lemmy.magnor.ovh
        link
        fedilink
        arrow-up
        6
        ·
        1 year ago

        Email works the same way. Once your data is received by the other party, you cannot delete it.

        Public mailing lists have a very similar behaviour to the fediverse’s. I am not aware of any credible GDPR cases against those, although it may happen down the line, we’ll see.

      • webghost0101@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        4
        ·
        1 year ago

        Thats a good point. An instance could comply if there remains a way to submit a remove my data form to the admins. But other instances may also have or retain data with Lemmy being a decentralized network, our data is all over the place, there is no easy way to really be forgotten on the fediverse and neither a way for law enforcement to fine every single instance.