What a Polish GDPR Complaint Says OpenAI Must Explain

Privacy researcher Lukasz Olejnik filed a complaint with Poland’s data protection authority, alleging that OpenAI failed to meet GDPR requirements for transparency, data access, accuracy and privacy by design. The authority confirmed receipt and said it was analyzing the complaint to decide what to do next.

WTF Index IDIOCRACY
◄ Terminator 1 Idiocracy 2 ►

The story raises concerns about inaccurate AI-generated information and limits on correcting it, but mainly reports a regulatory complaint still under review.

What a Polish GDPR Complaint Says OpenAI Must Explain

A complaint filed with Poland’s data protection authority puts a practical question about ChatGPT in focus: can people access and correct personal information the service may process, including information used to train its models? Privacy researcher Lukasz Olejnik says his experience trying to correct errors in a ChatGPT-generated biography led him to ask the authority to investigate.

A request for access raised questions about training data

Olejnik used ChatGPT to produce a biography of himself and found that the response contained errors. Toward the end of March, he contacted OpenAI to report the inaccuracies and ask for them to be corrected. He also requested information about how the company had processed his personal data.

According to the complaint, OpenAI provided some information in response to his Subject Access Request, but did not provide everything Olejnik believes the GDPR requires. In particular, the complaint says the response did not adequately describe personal data processing connected with training AI models.

The complaint argues that people should be told when their personal data is being processed and be able to get information about that processing. It says that describing training data in general terms, without explaining the relevant processing operations, leaves important questions unanswered for someone seeking access to their data.

Those claims concern the GDPR principles of lawful, fair and transparent processing, as well as access rights. The complaint cites Articles 5(1)(a), 12 and 15, among other provisions. They are allegations for regulators to assess; filing the complaint does not establish that OpenAI violated the rules.

Correction is a separate challenge

Olejnik’s complaint also focuses on the errors in his biography. He says OpenAI initially responded to his request by blocking ChatGPT requests that referred to him, though he had asked for the inaccuracies to be corrected. The complaint says OpenAI later told him it could not make the correction.

The GDPR includes a right to rectification of personal data. The complaint argues that a system unable to correct inaccurate information about a person may make that right difficult to exercise. It suggests the problem could extend beyond Olejnik’s case, while presenting that as a concern about how the system works rather than a finding by a regulator.

As a possible response, the complaint proposes a mechanism to check and correct content, including information users flag as wrong. It also says that if OpenAI considers correction mechanisms infeasible, the issue could be discussed with supervisory authorities through prior consultation. The complaint links this question to the wider challenge of handling inaccuracies in content generated by an AI chatbot.

Privacy by design and oversight

The complaint says the way ChatGPT was designed and operated conflicts with the GDPR’s principle of data protection by design and default. Among its concerns are the alleged gaps in information about model training and the reported inability to correct data. It argues that testing involving personal data should have been addressed during design, rather than after the tool was made available to users.

It also raises the question of whether OpenAI should have consulted regulators before launching the service in Europe. The article says TechCrunch asked OpenAI whether it had produced a data protection impact assessment before launch and why it had not sought prior consultation. At the time of publication, OpenAI had not responded to those questions.

Poland’s authority, the UODO, confirmed it had received the complaint and was analyzing it to decide on further action. It said this was the first complaint about ChatGPT it had received and that it had not previously corresponded with OpenAI about the service’s GDPR compliance.

A complaint amid wider European scrutiny

The Polish filing came after other GDPR concerns about ChatGPT had drawn attention. Italy’s privacy watchdog had ordered OpenAI to stop processing data locally and address preliminary concerns, including lawful basis, information disclosures, user controls and child safety. ChatGPT later resumed service in Italy after changes to its presentation, while the Italian investigation continued.

In April, data protection authorities across the bloc formed a task force through the European Data Protection Board to consider how to approach generative AI. The article notes that a unified approach was not certain. The GDPR remains in force, and people who believe their data rights have been infringed can raise concerns with their local data protection authority.

The complaint therefore puts specific requests—access to information and correction of inaccuracies—alongside broader questions about transparency and design. What happens next depends on the UODO’s analysis and any further regulatory action. The filing itself is an opportunity for scrutiny, not a decision on the allegations.