인피니언 8월20일부터
This page was machine-translated and may differ from the original. View original

Personal Information Protection Commission Imposes Fine on OpenAI and Issues Improvement Recommendations

Google 우선 소스Published2023.07.28 15:04


Planned Fact-Finding Inspections of Major Domestic and International AI Services Including ChatGPT

With the imposition of an administrative fine on OpenAI, which experienced a personal information breach, personal information protection for emerging generative AI and other cutting-edge technology services is being strengthened.

The Personal Information Protection Commission (Chairman Ko Hak-soo) held a plenary session on the 26th and decided to impose an administrative fine of 3.6 million won on OpenAI OpCo LLC (hereinafter "OpenAI"), which recently experienced a personal information breach, for violation of notification obligations, and adopted improvement recommendations including "establishment of recurrence prevention measures, compliance with domestic protection laws, and active cooperation with proactive fact-finding inspections by the Personal Information Protection Commission."

The Personal Information Protection Commission initiated investigations ex officio based on OpenAI's self-notification in March that a personal information breach had occurred on its ChatGPT service and related domestic and international media reports. In the process, the Commission also conducted verification work on overall compliance with domestic protection law obligations and personal information infringement factors across all service usage.

Between 17:00 on March 20, 2023 and 02:00 on March 21, some personal data of global users who accessed ChatGPT Plus—including names, email addresses, billing addresses, and the last four digits and expiration dates of credit cards—were exposed to other users. It was confirmed that 687 Korean users (based on Korean IP addresses) were included.

The cause of the breach was identified as an unknown error (bug) that occurred in an open-source based caching (temporary storage) solution implemented to increase service speed.

Following precise analysis through technical expert review meetings and other means, it was determined that OpenAI could not be said to have neglected generally expected protective measures, so no action was taken for violation of safety obligation requirements. However, an administrative fine was imposed for violation of notification obligations by failing to report within 24 hours of discovering the breach. The Commission adopted an improvement recommendation for OpenAI to conduct self-inspections of its personal information processing system and establish recurrence prevention measures.

Upon review of the personal information handling policy and actual subscription procedures, it was found that the policy is provided only in English, no separate consent procedure exists (presumed to be replaced by subscription), and issues regarding protection law compliance deficiencies were identified, including unclear custodian relationships, specific data destruction procedures and methods, and the absence of a clear domestic representative.

Additionally, there was an issue of restricting subscriptions for those under 13 years old, which is somewhat inconsistent with the domestic protection law's statutory guardian consent application age standard of under 14 years old.

However, during the investigation, OpenAI explained that it is a new business operator that recently began global services, and has been formally submitting opinions on compliance with domestic protection laws in accordance with amendments to the protection law through cooperation with the Personal Information Protection Commission. Accordingly, at this point in time, the Commission decided to recommend improvement and continuously monitor and verify implementation.

To examine privacy infringement factors as a cutting-edge technology, the Commission requested materials regarding data collection and usage (including personal information), sources of Korean language training data, efforts to prevent ethical issues, and methods to refuse data collection. However, OpenAI's explanations remained at a general and broad level, making clear analysis difficult.

Nevertheless, the Personal Information Protection Commission determined that early strengthening of personal information protection through fact-finding inspections and cooperative improvement is desirable in a situation where applicable legal provisions for newly emerging services (super-large scale and generative AI) remain unclear. The Commission decided to conduct proactive fact-finding inspections targeting major domestic and international AI services including ChatGPT to minimize personal information infringement factors, and also adopted an improvement recommendation requesting active cooperation from OpenAI.

This measure clearly establishes that domestic protection laws apply to global new services when Korean users are present. Going forward, the Personal Information Protection Commission plans to enhance personal information protection for Korean data subjects by issuing guidance documents for overseas business operators, substantially improving the domestic representative system, raising awareness of domestic regulations among major global personal information processors, and securing enforcement capabilities.

In particular, for cutting-edge technologies and services such as AI, the Commission plans to support safe service usage through proactive fact-finding inspections and other measures, with plans to continuously develop these efforts in detail going forward.
To request a correction, reply or follow-up report on this article, see how to file a request. Previously published statements are collected in corrections & replies.
배종인 기자
배종인 Reporter