This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.
Asset 3
  • About
  • People
  • Capabilities
  • Insights
  • Careers
  • Public Interest
  • Inclusion
  • Contact us
    Contact us
  • Locations
    Locations
  • Search
    Search
  • About
    • About
    • Message From the CEO
    • Firm History
    • Alumni
    • Alumni
    • In Memoriam
  • People
  • Capabilities
    • Practices
    • Industries
    • Global Reach: The Law Firm Network
    • Bankruptcy & Restructuring
    • Brand & Reputation Management
    • Intellectual Property
    • Litigation & Dispute Resolution
    • Special Situations, Distressed Debt and Debt Trading
    • Transactions
    • Tax
    • White Collar Defense, Investigations & Compliance
    • Energy & Environmental
    • Entertainment & Media
    • Investment Management 
    • Life Sciences
    • Technology
    • Real Estate
    • Bankruptcy & Restructuring
    • Bankruptcy Litigation
    • Mass Torts Bankruptcy
    • Intellectual Property
    • Intellectual Property Litigation
    • Patents
    • Trademark, Copyright & Advertising
    • Patent Trial and Appeals Board (PTAB)
    • Litigation & Dispute Resolution
    • Civil Fraud Litigation
    • Employment Practices and Litigation
    • Government Contracts Litigation
    • Intellectual Property Litigation
    • Insurance Recovery
    • Litigation Funding
    • M&A and Private Equity Litigation
    • Real Estate Litigation
    • Patent Trial and Appeals Board (PTAB)
    • UK Tax Controversy & Litigation
    • Special Situations, Distressed Debt and Debt Trading
    • Distressed Debt & Claims Trading
    • Litigation Funding
    • Finance
    • Real Estate Special Situations
    • Transactions
    • Capital Markets
    • Cross-Border Transactions
    • Emerging Growth Companies & Venture Capital
    • Employment
    • Finance
    • Franchising
    • Mergers & Acquisitions
    • Tax
    • White Collar Defense, Investigations & Compliance
    • Economic Sanctions & Export Controls
    • Energy & Environmental
    • Energy
    • Energy Transition
    • Environmental
    • Entertainment & Media
    • Brand & Reputation Management
    • Intellectual Property
    • Sports
    • Investment Management
    • Fund Formation
    • Private Equity Transactions
    • Distressed Debt
    • Emerging Growth Companies & Venture Capital
    • Family-Owned & Closely Held Businesses
    • Private Equity Litigation
    • Life Sciences
    • BR BioAdvisory Services
    • Technology
    • Artificial Intelligence
    • Cybersecurity & Data Privacy
    • Digital Commerce
    • Fintech
    • Real Estate
    • Hospitality & Leisure
    • Distressed Real Estate
    • Real Estate Special Situations
    • Real Estate Litigation
    • Wireless Network Infrastructure
  • Insights
    • Client News
    • Firm News
    • Briefings
    • Events
  • Careers
    • Experienced Lawyers
    • U.S. Law Students
    • London Trainee Program
    • Business Professionals
    • Professional Development
  • Public Interest
    • Brown Rudnick Charitable Foundation
    • Pro Bono & Community Service
  • Inclusion
    • Inclusion
    • Women in Business Series
  • Contact Us
  • Location
  • Search
  • About
    • About
    • Message From the CEO
    • Firm History
    • Alumni
    • Alumni
    • In Memoriam
  • People
  • Capabilities
    • Practices
    • Industries
    • Global Reach: The Law Firm Network
    • Bankruptcy & Restructuring
    • Brand & Reputation Management
    • Intellectual Property
    • Litigation & Dispute Resolution
    • Special Situations, Distressed Debt and Debt Trading
    • Transactions
    • Tax
    • White Collar Defense, Investigations & Compliance
    • Energy & Environmental
    • Entertainment & Media
    • Investment Management 
    • Life Sciences
    • Technology
    • Real Estate
    • Bankruptcy & Restructuring
    • Bankruptcy Litigation
    • Mass Torts Bankruptcy
    • Intellectual Property
    • Intellectual Property Litigation
    • Patents
    • Trademark, Copyright & Advertising
    • Patent Trial and Appeals Board (PTAB)
    • Litigation & Dispute Resolution
    • Civil Fraud Litigation
    • Employment Practices and Litigation
    • Government Contracts Litigation
    • Intellectual Property Litigation
    • Insurance Recovery
    • Litigation Funding
    • M&A and Private Equity Litigation
    • Real Estate Litigation
    • Patent Trial and Appeals Board (PTAB)
    • UK Tax Controversy & Litigation
    • Special Situations, Distressed Debt and Debt Trading
    • Distressed Debt & Claims Trading
    • Litigation Funding
    • Finance
    • Real Estate Special Situations
    • Transactions
    • Capital Markets
    • Cross-Border Transactions
    • Emerging Growth Companies & Venture Capital
    • Employment
    • Finance
    • Franchising
    • Mergers & Acquisitions
    • Tax
    • White Collar Defense, Investigations & Compliance
    • Economic Sanctions & Export Controls
    • Energy & Environmental
    • Energy
    • Energy Transition
    • Environmental
    • Entertainment & Media
    • Brand & Reputation Management
    • Intellectual Property
    • Sports
    • Investment Management
    • Fund Formation
    • Private Equity Transactions
    • Distressed Debt
    • Emerging Growth Companies & Venture Capital
    • Family-Owned & Closely Held Businesses
    • Private Equity Litigation
    • Life Sciences
    • BR BioAdvisory Services
    • Technology
    • Artificial Intelligence
    • Cybersecurity & Data Privacy
    • Digital Commerce
    • Fintech
    • Real Estate
    • Hospitality & Leisure
    • Distressed Real Estate
    • Real Estate Special Situations
    • Real Estate Litigation
    • Wireless Network Infrastructure
  • Insights
    • Client News
    • Firm News
    • Briefings
    • Events
  • Careers
    • Experienced Lawyers
    • U.S. Law Students
    • London Trainee Program
    • Business Professionals
    • Professional Development
  • Public Interest
    • Brown Rudnick Charitable Foundation
    • Pro Bono & Community Service
  • Inclusion
    • Inclusion
    • Women in Business Series

Search People

Search by last name

A
B
C
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z

see all people

Asset 3
  • LinkedIn
  • X (formerly known as Twitter)
  • Facebook
  • Instagram
  • Threads
  • YouTube
  • rss
  • Contact Us
  • Terms of Use
  • Privacy
  • Sitemap
  • LinkedIn
  • X (formerly known as Twitter)
  • Facebook
  • Instagram
  • Threads
  • YouTube
  • rss

© 2024 Brown Rudnick LLP. Attorney advertising.

All Rights Reserved.

All Posts Subscribe
print-logo
4/7/2023 3:43:56 PM | 3 minute read

AI Chatbots Pose Personal Data Concerns

4
11
29

Get in touch

Avatar
Matthew Richardson
Partner

Get in touch

Avatar
Matthew Richardson
Partner
featured image
4
11
29

ChatGPT and its successor, GPT4, are having a moment. Every college student is using them for research, every naturally occurring intelligence is talking about them. They have secured a massive funding stream from tech giant Microsoft, and millions upon millions of people have signed up for the service. The system is even finding a dedicated userbase who are substituting ChatGPT for therapy.

It is, however, only part of the story. Behind the headlines and the success lie some alarming, and unaddressed issues, which threaten to undermine public confidence in AI and bring substantial regulatory scrutiny on professional users.

Late last month, ChatGPT suffered a substantial data breach caused by a system bug allowing users to view one another’s private conversations with the chatbox. This has led Italy to ban ChatGPT from use in the country, and other European data regulators to take a very close look at the operation of the system. It cannot be denied that these are substantial setbacks for the nascent system.

In the European context, ChatGPT is a processor to which all elements of the GDPR and associated Member State legislation applies, likewise the U.K. GDPR. They are required by Article 32 to “implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.” Certainly, at the very least – given the recent breach, the Italian authorities are unhappy that this obligation has not been met. However, the obligations placed upon controllers and processors goes beyond that, there must also be a lawful basis for the processing of Personal Data. It is this latter point that has raised the most concern.

Many users of ChatGPT are deploying the system for content creation in all kinds of fields, including journalism, law and marketing to name but a few. These uses, as well as more casual uses, may result in the processing of Personal Data and Sensitive Personal Data.

The GDPR defines Personal Data as any information that relates to an identified or identifiable living individual. The innocuous request to ChatGPT “Create invitations to my CFO, John Smith’s, retirement party, in Paris” would necessitate the processing of Personal Data. If John Smith has not consented to this processing, a GDPR breach has occurred. This breach, of course, is trivial, and unlikely to cause any person trouble. It merely gives a flavor of how easy it is to accidentally process data unlawfully using an AI platform.

However, the real concern arises in the case of Sensitive Personal Data. This is data which reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, data concerning health or data concerning a natural person’s sex life or sexuality. Any attempt to use any AI system to deal with data such as this should be avoided at all costs, until the regulatory regime has caught up.

The issues should raise red flags for any business that is using an AI system for its content creation, including but especially medical professionals, lawyers, financial services businesses, or any industry that routinely processes Personal Data and Sensitive Personal Data. While these concerns may seem like that are EU and U.K. centric, there are U.S. analogues that may cause similar problems at a federal and state level. These include HIPAA, FERPA, CPRA, CCPA, and the Bank Secrecy Act to name a few. None of this even touches on the potential intellectual property concerns that exist within the system.

AI technology has advanced very quickly over the past six month, and it is undoubtedly true that the regulatory regime hasn’t yet found its footing. While these tools may seem like huge time savers, the potential regulatory downside is massive. GDPR fines are no joke, and the increased U.S. enforcement in relation to privacy from the FTC and other federal and state agencies should give anyone cause for worry. It will not be sufficient to lay the blame on the AI system for failures. The user themselves will bear as much responsibility as controllers of the data for requesting its processing by these untested systems.

As the technology matures, so too will the legislation and regulation relating to our new robot overlords. Until then, however, approach all such systems with caution, and hope that the ghost of Isaac Azimov will protect you.

Tags

cybersecurity & data privacy

Get in touch

Avatar
Matthew Richardson
Partner

Get in touch

Avatar
Matthew Richardson
Partner
DOJ Updates White-Collar Enforcement Priorities
5/15/2025 8:37:21 PM

DOJ Updates White-Collar Enforcement Priorities

By Daniel Sachs Steven Tyrrell Stephen Best Angela Papalaskaris +1 more...

Show less

DOJ Updates White-Collar Crime Enforcement Priorities  On May 12, 2025, the Criminal Division of the U.S. Department of Justice (DOJ)...

Latest Insights

Renewable Transport Fuel Obligation (RTFO) and Tax Disputes: Navigating a Complex Compliance Landscape
5/12/2025 12:30:58 PM

Renewable Transport Fuel Obligation (RTFO) and Tax Disputes: Navigating a Complex Compliance Landscape

By Matthew Sharp
2
2
Raising the Stakes: UK Government Consults on the Tax Treatment of Remote Gaming and Gambling
5/9/2025 2:45:43 PM

Raising the Stakes: UK Government Consults on the Tax Treatment of Remote Gaming and Gambling

By Matthew Sharp Menelaos Karampetsos
1
14
15
[2025] UKUT 00124 (TCC) George Mantides Limited v HMRC: Further Ammunition for HMRC in Its Battle Against Self-Employment in Healthcare?
5/1/2025 2:34:46 PM

[2025] UKUT 00124 (TCC) George Mantides Limited v HMRC: Further Ammunition for HMRC in Its Battle Against Self-Employment in Healthcare?

By Matthew Sharp
39
39