4 ms·
A CCPA Request to OpenAI Took 101 Days and Raises More Questions Than Answers
- lelandfe 3y agoThe title makes it sound like they took forever, but their response times actually seem decent against my experiences with other companies. Also, did it take 101 days? It seems the request was answered on April 7th. There are other problems here, of course.
- diggan 3y ago> but their response times actually seem decent against my experiences with other companies It seems like on average it took them around 20 days to reply to each email. Is that really your experience with other companies? I usually end up getting replies within a week at least.
- upon_drumhead 3y agoThe vast majority of cases when I asked something unusual is meet with complete silence.
- echoangle 3y agoIs it actually possible to force a business to find all instances of my data in their databases? That sounds really weird. Account data and so on, I would understand, but could I ask archive.org, for example, to give me a list of all Websites they archived where my name appears? Even if the data was already public and does not contain any private data of me?
- everforward 3y agoMy understanding of GDPR via compliance is that yes, you can. I didn't get any specific to CCPA, so not sure if CCPA allows the same thing but I think it does. My experience on the implementation side is that data sources are flagged as containing PII or not for access control, and each data source flagged as containing PII has some (typically automated) procedure for flushing information out. E.g. legal gets a request to delete information for John Doe, they send that to compliance who finds the user ID for John Doe, and an automated system blasts out a "scrub user ID 12345" message to all the PII systems. > Even if the data was already public and does not contain any private data of me? You can only make the data private by taking down public sources. And under GDPR, the operative term is "personal identifiable information" not "private". GDPR doesn't care whether the data is "private" or not, only whether it can identify a person. If the information can identify you, you have the right to force them to delete it (barring some exclusions for e.g. KYC). You can also ask for copies of the data they have so you can evaluate whether you're okay with the data that they're gathering and what they're using it for. > Account data and so on, I would understand, but could I ask archive.org, for example, to give me a list of all Websites they archived where my name appears? To my understanding, sure. They might point you to the search bar and tell you to do it yourself (I'm not sure what their obligations are if you already have access to the raw data).
- echoangle 3y agoHow would I prove that the Data is about me and not about someone with the same name as me? Could I delete the Websites of all people with my name from archive.org?
- everforward 3y agoI'm honestly not well-versed in that, I only get the compliance briefings. I would be curious how they handle people with the same name, though.
- zeroz 3y agoSuper exciting question to see how courts assess the situation when AI does not reveal personal data from the training data but makes clever guesses. Does this still count as a GDPR violation? Edit: To add another thought - if thats the case, what is the basic data to delete in this case? If there is nothing specific to delete, does this require another layer of output filter?
- RecycledEle 3y agoOuch. Their answers are not good.