惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
J
Java Code Geeks
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Docker
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 聂微东
MyScale Blog
MyScale Blog
H
Help Net Security
Last Week in AI
Last Week in AI
T
The Blog of Author Tim Ferriss
M
MIT News - Artificial intelligence
大猫的无限游戏
大猫的无限游戏
酷 壳 – CoolShell
酷 壳 – CoolShell
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
P
Proofpoint News Feed
博客园 - 叶小钗
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
F
Fortinet All Blogs
Martin Fowler
Martin Fowler
Microsoft Security Blog
Microsoft Security Blog
T
Tailwind CSS Blog
aimingoo的专栏
aimingoo的专栏

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
OpenAI to lift ban on ChatGPT in Italy? Italian Garante T...
Jessica Ryder · 2023-04-14 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

The future of ChatGPT in Italy: OpenAI, the company behind the AI tool ChatGPT, has been ordered by the Italian Data Protection Authority (Garante) to comply with measures regarding transparency, data subjects’ rights, and the legal basis of processing users’ data by April 30th. 

UPDATE

ChatGPT is accessible again in Italy. After a meeting with the Garante Privacy, OpenAI has introduced new data protection measures, as required by the Italian authority.

In particular, OpenAI has published a notice, dedicated to all users and non-users, in which it explains which personal data are processed for algorithm training and in what manner. European users are also given the right to object to the processing of their personal data. Regarding the minimum age requirement, OpenAI has included the requirement to confirm the date of birth on the service sign-up page, and provided a block on registration for users under thirteen years of age.

You can access the official press release here.

ChatGPT in Italy
In short, the requirements imposed by the Garante on ChatGPT include:
  1. Having a correct and complete privacy policy for the OpenAI/ChatGPT site.
  2. Subjecting the use of the service to having read the privacy policy.
  3. Verifying the age of users.
  4. Adding tools for users to request opposition to the indexing or modification/cancellation of their personal data from the OpenAI services. 
  5. Adding tools for users to request opposition to the use of their personal data for training the algorithm.
  6. Undertaking an information campaign towards the public.
  7. Using the legitimate interest as a legal basis for training the algorithm using personal data, ⁣ in addition to consent.

🔎 The Details

OpenAI is required to draft and make available an information notice on its website that describes the data processing arrangements and logic required for ChatGPT’s operation, along with the rights of data subjects. Users from Italy must be presented with this notice before completing their registration, and registered users will have to be presented with the notice when accessing the service.

OpenAI is required to implement an age gating system and submit a plan for an age verification system by September 30, 2023, to filter out users aged below 13 and users aged 13 to 18 for whom no consent is available by the holders of parental authority. The company must also promote an information campaign in agreement with the Garante to inform individuals about the use of their personal data for training algorithms.

OpenAI must make available easily accessible tools for data subjects, including non-users, to obtain rectification of their personal data or to have that data erased if rectification is technically unfeasible.

The Garante has allowed OpenAI to use personal data to train the algorithm using legitimate interest as the legal basis, similar to the approach used by search engines when they index the web. This provision carries the ball forward for OpenAI, but the Garante reserves the right to evaluate the merit of using legitimate interest as the legal basis in the future.

The Garante will continue to investigate possible infringements of the legislation in force and may decide to take additional or different measures if necessary upon completion of the fact-finding exercise.

🗣️ OpenAI’s Response

In response, OpenAI has decided to start a constructive dialogue with the Garante, which has been very pragmatic in finding a solution that is feasible for OpenAI. 

This is a win-win situation for everyone: OpenAI obtains reasonable guidelines directly from the authority within which to operate in compliance with GDPR, the Garante is satisfied with substantial compliance with the rules, and citizens’ rights are protected. 

📬 Want the latest news on Data Protection and Privacy delivered to your inbox? Join the list @ dponewsletter.com