Italy’s decision to block ChatGPT over privacy concerns has put the chatbot’s status in other European countries under scrutiny. Data protection authorities are exchanging views, but their responses so far range from considering possible steps to rejecting a ban.
Authorities weigh their next steps
According to a Reuters report, the data protection authorities of France and Ireland contacted the Italian authority after its action against ChatGPT. The authorities are discussing possible further steps. Ireland’s authority also said it would exchange views with all EU data protection authorities.
Spain had not received a complaint, though its authority did not rule out an investigation. Sweden, by contrast, had no plans to block ChatGPT. These different positions show that Italy’s decision had not produced a single EU-wide response.
Germany’s Ministry for Digital Affairs rejected a ban. A ministry spokesperson told the German newspaper Handelsblatt that ways should be found to “safeguard values such as democracy and transparency.” The spokesperson added that Europe must become a “global pioneer for trustworthy AI.”
Ulrich Kelber, Germany’s Federal Commissioner for Data Protection, said a ChatGPT block would in principle be enforceable. But it would have to go through regional data protection authorities, making a ban more complicated. Kelber’s office was in contact with the Italian authority.
What Italy objected to
The Italian authority cited a lack of legal basis for the “mass collection and storage of personal data” used for further AI training. It also said children under 13 were not adequately protected.
Those objections raise questions about both the data used to build a system and the information people provide when they use it. Generative AI training data may include text or images that fall under data protection rules. The concern is that such material could become visible again in a model’s output.
There is another point of contact: information entered during conversations may be processed by the system, including to further optimize the AI. ChatGPT does not explicitly ask for personal data in the way social media services do. Still, people may use it to edit or create private and business documents that contain information relevant to privacy.
OpenAI’s privacy policy says personal data may also be used to improve its services. That makes the handling of information entered in a chatbot part of the broader privacy debate, alongside questions about training material.
Privacy and copyright questions overlap
Privacy is only one unsettled issue. Questions remain about the copyright status of training data and the use of copyrighted content in chatbots such as Bing Chat. Together, these concerns put pressure on existing privacy and copyright rules as generative AI systems are developed and used.
The practical challenge is to determine how existing protections apply: what legal basis supports the collection and use of data, how children are protected, and how copyrighted material may be used. The source article does not describe a settled answer to those questions. Instead, it captures a moment when authorities are considering their options and exchanging views.
For now, the national responses differ. Italy acted against ChatGPT, France and Ireland sought contact with the Italian authority, Spain left open the possibility of an investigation, Sweden had no plans to block the service, and Germany rejected a ban while calling for trustworthy AI. Whether other countries take action remains unresolved.