openai.com — 68/100 (Μέτριος κίνδυνος απορρήτου)

Τελευταία ανάλυση

Νέα ανάλυση σε άλλη πολιτική

OpenAI · openai.com

Λεπτομέρειες αναφοράς

Μέτριος κίνδυνος απορρήτου

Η πολιτική απορρήτου της ΕΕ της OpenAI προσφέρει ισχυρούς ελέγχους χρηστών και διαφάνεια, αλλά είναι ανεπαρκής όσον αφορά την ελαχιστοποίηση δεδομένων, τη σαφήνεια στη διαμοιρασία με τρίτους και τις εγγυήσεις για τις διεθνείς μεταφορές δεδομένων των χρηστών της ΕΕ.

OpenAI’s EU privacy policy provides detailed disclosures about data collection, processing purposes, and user rights, including explicit opt-outs for model training. However, it collects broad categories of data (e.g., user content, logs, device info), shares data extensively with vendors and affiliates, and transfers data to the US and other non-EEA countries using SCCs. While it offers granular controls (e.g., temporary chats, model training opt-outs), gaps remain in data minimization, third-party subprocessor transparency, and the practical enforceability of transfer mechanisms under EU law. The policy is compliant on paper but raises concerns about proportionality and oversight.

Δεν μπορέσαμε να μεταφράσουμε αυτή την αναφορά αυτή τη στιγμή, γι' αυτό οι λεπτομέρειες παρακάτω είναι στα αγγλικά.

Τελευταία ανάλυση
ΠηγήURL

Αξιολόγηση ανά κατηγορία

Ανάλυση της πολιτικής σε βασικούς τομείς συμμόρφωσης. Καλό = ισχυρό, μέτριο = μικτό, κακό = ανησυχητικό.

Data MinimizationΜέτριο

Collects extensive data (e.g., prompts, files, IP addresses, device IDs) beyond what’s strictly necessary for core functionality, though some controls (e.g., temporary chats) limit retention.

TransparencyΚαλό

Detailed disclosures on data types, purposes, and legal bases, with clear links to help center articles and opt-out mechanisms.

Third-party SharingΚακό

Shares data broadly with vendors, affiliates, and business partners (e.g., cloud providers, payment processors) without a comprehensive, named subprocessor list or granular consent for each category.

International TransfersΜέτριο

Uses SCCs for non-EEA transfers but lacks detail on supplementary measures to address US surveillance risks, and does not restrict transfers to ‘adequate’ jurisdictions only.

AI/Model TrainingΚαλό

Explicit opt-out for model training is available, and users can disable memory/history features to limit data used for improvements.

User RightsΚαλό

Clearly lists GDPR rights (access, deletion, portability, objection) and provides multiple channels (account settings, privacy portal, email) to exercise them.

Βασικά ευρήματα

Σημαντικές ρήτρες, ζητήματα ή θετικές πρακτικές (κρίσιμα πρώτα)

Κρίσιμο

Inadequate safeguards for international transfers to the US

Section 10 confirms transfers to the US and other non-EEA countries using SCCs, but does not describe supplementary technical/organizational measures (e.g., end-to-end encryption, zero-knowledge architectures) to address US government surveillance risks. Post-Schrems II, SCCs alone are often deemed insufficient by EU courts and regulators (e.g., CNIL, EDPB).

Προειδοποίηση

Overly broad data collection undermines minimization

Section 1 lists extensive categories of data collected, including user content (prompts, files, images, voice/video), log data (IP, browser settings), usage data (interactions, feedback), device info, and location data. While some data is necessary for service delivery, the policy does not justify the proportionality of collecting all these categories for every user or feature. For example, location data is inferred from IP addresses ‘for security’ but also used for ‘product experience’ without clear necessity.

Προειδοποίηση

Lack of named subprocessor list for third-party sharing

Section 3 states data is shared with ‘vendors and service providers’ (e.g., hosting, cloud, analytics, payment processors) but does not provide a named list or link to a subprocessor registry. This omits critical transparency required under GDPR Art. 28(3) for users to assess risks of sharing with specific third parties (e.g., AWS, Stripe).

Προειδοποίηση

Ambiguous legal basis for model training with user content

Section 2 states user content may be used to ‘improve models’ but relies on ‘legitimate interests’ as a legal basis, which may conflict with GDPR’s requirement for explicit consent for high-risk processing (e.g., training generative AI). While an opt-out exists, the default inclusion of user content in training without clear consent is a compliance risk.

Info

Retention periods lack specificity for certain data types

Section 4 describes retention based on ‘legitimate business purposes’ (e.g., fraud prevention, legal obligations) but does not specify maximum durations for categories like log data or usage analytics. For example, it states data may be retained ‘as long as necessary’ for security but does not define what ‘necessary’ entails for non-critical data.

Περίληψη για τον χρήστη

You have significant control over your data (e.g., opting out of model training, deleting chats), but OpenAI collects a wide range of personal data, shares it with many third parties, and transfers it outside the EU. If privacy is a priority, disable model training, avoid uploading sensitive files, and review third-party integrations carefully.

Στάση συμμόρφωσης

The policy aligns with GDPR requirements on transparency, legal bases, and user rights, but its reliance on SCCs for non-EEA transfers and broad data sharing with vendors/affiliates may not satisfy stricter interpretations of EU data protection (e.g., Schrems II). The Irish DPC’s oversight adds credibility, but enforcement risks persist for high-risk transfers.

Μεταφορές ΕΕ

Data is transferred to the US and other non-EEA countries using Standard Contractual Clauses (SCCs) and, where applicable, adequacy decisions. However, the policy does not address supplementary measures (e.g., encryption, pseudonymization) to mitigate US surveillance risks under FISA 702, leaving transfers vulnerable to legal challenges under EU law. No explicit mention of Binding Corporate Rules (BCRs) or other safeguards beyond SCCs.

Εντοπισμένα σήματα

Συγκεκριμένα δεδομένα και πρακτικές που εντοπίστηκαν στο κείμενο

Δεδομένα που συλλέγονται
Account information (name, contact details, credentials, birthdate, payment info, transaction history)User content (prompts, uploaded files, images, voice/video, connected service data)Communication information (name, contact details, message content)Contact data (device address book, contact verification status)Other user-provided information (event participation, surveys, identity/age verification)Log data (IP address, browser type/settings, request timestamps, interaction data)Usage data (content types viewed/interacted with, features used, feedback, timezone, country, access dates/times, user agent, device type)Device information (device name, OS, device identifiers, browser)Location data (inferred from IP, precise GPS if enabled)Cookies and similar technologies
Σκοποί επεξεργασίας
Deliver, analyze, and maintain services (e.g., respond to ChatGPT queries)Improve and develop services and conduct research (e.g., develop new features, train models)Personalize and customize user experience (e.g., memory, custom instructions, topic suggestions)Display and measure ads for Free/Go users (e.g., ad personalization, performance measurement)Communicate with users (e.g., service updates, marketing, support responses, surveys)Identify contacts using services when users connect address booksPrevent fraud, illegal activity, or abuse (e.g., monitor suspicious logins, detect policy violations)Comply with legal obligations and protect rights/safety (e.g., retain billing data, respond to law enforcement requests)
Κοινοποίηση σε τρίτους
Shared with vendors/service providers (hosting, cloud, analytics, payment processors, security, email, IT)Shared with affiliates (entities under common control with OpenAI)Shared with business account administrators (e.g., access to user content for Enterprise accounts)Shared with parents/guardians of linked teen accountsShared with other users/third parties via user interactions (e.g., shared ChatGPT links, search/shopping partners)Shared with public authorities/third parties if legally required or to protect rights/safetyShared in aggregated/de-identified form with third parties
Διεθνείς μεταφορές
Data processed on servers outside EEA, Switzerland, and UK (e.g., US)Transfers rely on EU adequacy decisions where applicableTransfers to non-adequate countries use Standard Contractual Clauses (SCCs)UK transfers use SCCs + UK International Data Transfer AddendumNo mention of supplementary measures (e.g., encryption) for US transfers
AI / Εκπαίδευση μοντέλων
User content may be used to train models by defaultExplicit opt-out available for model training via data controlsFeedback on model responses may be used for trainingPublicly available internet content used for trainingFree/Go user ad interaction data used to improve ad quality

Αποσπάσματα αποδείξεων

Απευθείας αποσπάσματα από την πολιτική που υποστηρίζουν αυτά τα ευρήματα

Vi indsamler personoplysninger om dig (“Personoplysninger”) som følger: Kontooplysninger, Brugerindhold, Kommunikationsoplysninger, Kontaktdata, Andre oplysninger, du giver, Logdata, Brugsdata, Enhedsoplysninger, Lokationsoplysninger, Cookies og lignende teknologier.

Vi deler dine personoplysninger med leverandører og tjenesteudbydere, herunder udbydere af hostingtjenester, cloudtjenester, indholdsleveringstjenester, support- og sikkerhedstjenester, e-mail-kommunikationssoftware, webanalysetjenester, betalings- og transaktionsbehandlere.

OpenAI behandler dine personoplysninger på servere, der er placeret uden for EØS, Schweiz og Storbritannien... Når vi overfører personoplysninger uden for EØS, Schweiz eller Storbritannien, benytter vi gyldige overførselsmekanismer for at overholde gældende databeskyttelseslovgivning, såsom Europa-Kommissionens afgørelser om tilstrækkeligheden af databeskyttelse og standardkontraktbestemmelserne (SCC).

Vi bruger det indhold, du giver os, til at forbedre vores tjenester, for eksempel til at træne de modeller, der driver ChatGPT. Læs vores vejledning om, hvordan du kan fravælge, at vi bruger dit indhold til at træne vores modeller.

Vi opbevarer kun dine personoplysninger, så længe vi har brug for dem til at levere vores tjenester til dig, eller til andre legitime forretningsformål såsom løsning af tvister, af sikkerheds- og sikkerhedsmæssige årsager eller for at overholde vores retlige forpligtelser.

Λείπει ή ασαφές

  • No named list of subprocessors (vendors/service providers) with roles and locations
  • No detail on supplementary technical measures for international transfers (e.g., encryption, pseudonymization)
  • No explicit restriction on data retention periods for non-critical data (e.g., logs, analytics)
  • No clarity on whether ‘legitimate interests’ for model training meets GDPR’s high bar for consent in AI contexts
  • No disclosure of data subject to US government requests (e.g., FISA 702) or how such requests are handled
  • No information on Binding Corporate Rules (BCRs) or other transfer mechanisms beyond SCCs

Ερωτήσεις προς υποβολή

  • Can OpenAI provide a full, up-to-date list of all subprocessors (including sub-subprocessors) involved in processing EU user data, with their locations and roles?
  • What supplementary technical measures (e.g., end-to-end encryption, zero-knowledge proofs) does OpenAI implement to protect EU data transferred to the US from government surveillance?
  • Does OpenAI obtain explicit consent (not just an opt-out) for using user content to train models, given the high-risk nature of generative AI under GDPR?
  • How long does OpenAI retain log data, usage analytics, and device identifiers for users who are not under active investigation or legal hold?
  • What specific legal bases apply to the collection of location data, contact data, and device identifiers, and how are these justified as necessary?
  • How does OpenAI ensure that vendors/service providers (e.g., cloud providers) do not access or use EU user data for their own purposes (e.g., model training)?
  • Has OpenAI conducted a Data Protection Impact Assessment (DPIA) for its model training practices, and can it be shared with regulators or users upon request?
Αυτή η ανάλυση δημιουργείται από AI και δεν αποτελεί νομική συμβουλή. Συμβουλευτείτε πάντα εξειδικευμένο νομικό για αποφάσεις συμμόρφωσης GDPR.

Κοινοποίηση αυτής της ανάλυσης

Οποιοσδήποτε με αυτόν τον σύνδεσμο μπορεί να δει το αποτέλεσμα παραπάνω.

Δημιουργήθηκε από το DentroChat

100% ευρωπαϊκό AI chat για όλους

Συνομιλήστε με AI, εργαστείτε με αρχεία, δημιουργήστε εικόνες και αναζητήστε στο διαδίκτυο. Τα δεδομένα παραμένουν στην Ευρώπη.

Υποδομή φιλοξενούμενη στην ΕΕΚείμενο, αρχεία, εικόνες και αναζήτηση webΛειτουργίες Γρήγορη, Σκέψη και ΔημιουργικήΠροτεραιότητα στην ιδιωτικότηταΚανένα δεδομένο δεν φεύγει από την Ευρώπη
Δοκιμή δωρεάν →
Προβολή όλων