chatgpt_inteligenciaartificial

Privacy risks: ChatGPT

ChatGPT is the most important Artificial Intelligence development in recent years. Last month we discussed its impact on data protection. Today we will delve deeper into the risks it poses to privacy. Let’s go!

Working under the assumption that chatbots rely on our personal data and the more data they collect, the more accurate they are at both detecting patterns and anticipating and generating responses, the risk to privacy increases substantially.

Besides if bearing in mind that the information used to train artificial intelligence products like ChatGPT is taken from the Internet. And personal data that is often acquired without user consent, this is a case that breaches privacy regulations.

 

Measures that ChatGPT must adopt to comply with privacy regulations

  1. Inform on data processing. What data is used and its purpose.
  2. Inform on how data subjects can oppose the use of their data for training algorithms and implement mechanisms to do so.
  3. Conduct information campaigns in the media.
  4. Set up mechanisms to prevent users under the age of 13 from accessing the service.

Provisions of the privacy regulation that are not met

Firstly, the duty of information is breached since complete and transparent information is generally not provided to users and interested parties regarding the processing their data undergoes in these systems.

Additionally, they do not comply with the principles that regulate personal data processing, including the principle of accuracy. Given that a large amount of data introduced into the systems is inaccurate, the result is large-scale misinformation. In this vein, one of the most serious concerns regarding the use of systems like ChatGPT is the tendency to embellish the information and increase the bias in the answers given to the user.

Another of the notable violations is the lack of legitimate basis for the mass processing of personal data in order to train the algorithms that govern chatbot operation.

It is also important to highlight that the principle of confidentiality is contravened and that there is a lack of security measures. This greatly increases the risk of breaches and cyberattacks.

Therefore, we can conclude that although AI holds to potential to transform sectors, solve problems, simplify answers or be a great source of information, it also poses great ethical and social risks.

It is important to note that chatbot systems can reproduce, reinforce and amplify patterns of discrimination and/or inequality. As a result, the irresponsible data handling by these systems leads to unreliable results, which can harm the well-being of citizens and security in legal proceedings.

Will a robust regulatory framework be created worldwide that regulates artificial intelligence systems like ChatGPT? Here at Bacaria we will closely monitor the situation and keep you up to date.

 

CHAT_GPT_OPENAI

ChatGPT and its impact on data protection

ChatGPT is an OPEN AI product that is considered to be the most important Artificial Intelligence development in recent years. It is a trained language model (Generative Pre-trained Transformer) that provides coherent and natural responses to questions and text commands. It is mainly characterised by its ability to offer coherent answers to complex questions and its rapid learning and improvement in performance.

Its primary tasks include the following: translating languages, writing songs, writing blog posts, creating cooking recipes, answering research questions, generating code, and it has even passed university exams.

How does it work?

When given text input, it uses its GPT model to analyse the meaning and context of the input and generate a coherent response. Moreover, ChatGPT uses its prior knowledge and ability to continuously learn to improve its performance and provide more accurate and relevant answers to user questions.

How do I use it?

First, you must visit the Open AI website https://openai.com/ and register. Once the registration process is complete, you can get started with your free trial. But please keep in mind that you will need a paid subscription to access all of the product’s features.

At Bacaria, we recommend that you review its policies at https://openai.com/policies/usage-policies before using it.

 

How does ChatGPT affect Data Protection?

Is important to note that ChatGPT itself does not collect personal data. However, if the user enters it in the chat, the product processes it and generates responses based on the user’s information. It can also access the IP address, as well as the browser type and settings, mainly for security purposes.

Also it is advisable not to enter personal, confidential or sensitive data, since the team responsible for developing and maintaining ChatGPT may review conversations to improve the systems and for quality purposes.

Furthermore, OPEN AI ensures that computer security measures are used, such as data encryption, limited access to servers and the regular deletion of user data to avoid any risk of exposure and vulnerabilities.

What should I bear in mind in terms of data protection if I want to implement a ChatGPT chatbot at my company?

Said company, as the data controller of the data processed through the ChatGPT chatbot, must take into account the following implications:

  1. Identify the processing of personal data that will be carried out with ChatGPT in its Record of processing activities.
  2. Use one of the lawful bases set forth in Article 6 of the GDPR.
  3. Fulfil the duty to clearly and simply inform the interested party/user of the chatbot about the processing of their data.
  4. In the event that the ChatGPT chatbot is provided by a service provider, a data processing agreement must be signed. Alternatively, if it is implemented directly by the company, a processing agreement must be signed with OPEN AI, and to do so, you must contact them via the email provided on their website, stating that you need to sign said data processing agreement.
  5. Perform a Data Protection Impact Assessment to analyse the features of the ChatGPT chatbot, how personal data is collected and used, the impact on rights and freedoms, and which measures will be taken to protect personal data and mitigate privacy risks.

In summary, it is evident that the use of this type of technology can entail a risk to privacy, which is why the provisions of the Data Protection Regulation and other complementary regulations must be taken into account. At Bacaria, we have a team specialised in Artificial Intelligence and privacy and we will be happy to assist you.