Privacy nonprofit noyb files a GDPR complaint against OpenAI in Austria on behalf of an unnamed public figure, who found ChatGPT gave his incorrect birth date
OpenAI is facing another privacy complaint in the European Union. This one, which has been filed by privacy rights nonprofit noyb …
Context & Ripple Effects
This complaint extends an EU privacy-regulation arc that included Italy’s temporary restriction and investigation of ChatGPT and a subsequent finding that OpenAI was suspected of GDPR violations. It shifts the focus from broad questions about training data and collection toward whether a generative system can handle inaccurate personal information in its outputs.
The case matters because an erroneous biographical answer presents a concrete test of GDPR rights in systems whose responses are generated dynamically, echoing earlier coverage of GDPR questions around data accuracy and erasure for AI models.
First-order effects
- OpenAI faces a new Austrian GDPR proceeding centered on ChatGPT’s incorrect personal-data output, putting its processes for correcting or contesting such outputs under scrutiny.
- The complainant gains a formal route to challenge the answer through noyb, rather than relying solely on product-level feedback or correction mechanisms.
Second-order effects
- Privacy advocates and regulators gain a fact pattern for testing whether GDPR accuracy and rectification expectations can be applied to generative-model outputs, alongside the broader Italian regulatory scrutiny of OpenAI.
- AI providers serving Europe may face pressure to make personal-data correction, provenance, and escalation processes more operationally usable, especially for identifiable people.
Third-order effects
- If authorities treat persistent erroneous outputs about people as a GDPR compliance issue, model developers may need to treat output governance as a continuing privacy obligation rather than a one-time data-ingestion question.
- The broader direction is toward enforceable accountability for AI systems’ handling of personal information, though the scope will depend on regulators’ eventual interpretation of how GDPR duties apply to generated answers.
The trend: Generative AI is moving from abstract privacy debates toward regulatory tests of how systems correct, explain, and govern personal-data outputs.