Balancing Between Innovation and Data Protection Using the Example of ChatGPT

Main Article Content

Tamara N. Tasić

Abstract

Personal data protection in the age of artificial intelligence is a very intriguing and new topic in domestic and EU law. The use of innovative chatbots such as ChatGPT is becoming increasingly common, which increases the risk of misuse and potential violations of personal data. In this paper, the author defines the concept of chatbots and conducts a review of the General Data Protection Regulation (GDPR). The second part analyzes how ChatGPT collects, stores, and processes personal data. The paper also focuses on the risks associated with innovations and possible violations that may occur when using ChatGPT. The author also points out balancing techniques that could prevent the risk of personal data breaches, with an analysis of the GDPR, and provides concrete suggestions for compliance.

Downloads

Download data is not yet available.

Article Details

Section
Articles
Author Biography

Tamara N. Tasić, Faculty of Law, Union University, Belgrade, Serbia

Master of Laws, Lawyer, PhD Candidate

References

Alkaissi, H. & McFarlane, I. 2023. Artificial Hallucinations in ChatGPT: Implications in Scientific Writing. Cureus, 15(2), pp. 1-4. https://doi.org/10.7759/cureus.35179

Andonović, S. 2024. Institut pristanka kod zaštite ličnih podataka. U: Stanić, M. & Rajić Ćalić, J. (ur.), Neobjavljeni radovi dr Stefana Andonovića: zbornik radova sa naučnog skupa. Beograd: Institut za uporedno pravo, pp. 103-112.

Andonović, S. 2020. Normativni aspekti veštačke inteligencije u radu organa uprave u Republici Srbiji. U: Soković, S. (ur.), Usklađivanje pravnog sistema Srbije sa standardima Evropske unije: zbornik radova. Kragujevac: Pravni fakultet Univerziteta u Kragujevcu, pp. 141-154.

Andonović, S. 2019. Zaštita podataka u elektronskoj javnoj upravi u Republici Srbiji – pravni aspekti. Doktorska disertacija. Beograd: Pravni fakultet Univerziteta u Beogradu.

Avramović, D. & Jovanov, I. 2023. Sudiјska (ne)pristrasnost i veštačka inteligencija. Strani pravni život, 67(2), pp. 161-177. https://doi.org/10.56461/SPZ_23201KJ

Cecconi, F. 2023. AI in the Financial Markets: New Algorithms and Solutions. Switzerland: Springer. https://doi.org/10.1007/978-3-031-26518-1

Choudhury, A. & Shamszare, H. 2023. Investigating the Impact оf User Trust оn Adoption аnd Use оf ChatGPT: А Survey Analysis, Journal of Medical Internet Research, 25, pp. 1-11. https://doi.org/10.2196/47184

Diligenski, A. & Žižić, M. 2020. Pravo na naknadu štete kod povreda zaštite podataka o ličnosti. U: Andonović, S., Prlja, D. & Diligenski, A. (ur.), Zaštita podataka o ličnosti u Srbiji: zbornik radova. Beograd: Institut za uporedno pravo, pp. 139-151.

Đukić, D. 2017. Zaštita podataka o ličnosti sa osvrtom na novo zakonodavstvo Evropske unije u ovoj oblasti. Pravni zapisi, 7(1), pp. 49-60.

Gasmi, G. & Prlja, D. 2021. Ugrožavanje ljudskih prava i veštačka inteligencija. U: Perović Vujačić, J. S. (ur.), Primena prava i pravna sigurnost: zbornik radova. Zbornik radova Kopaoničke škole prirodnog prava Slobodan Perović, 3, pp. 323-335.

Gajin, S., Resanović, A. & Vodinelić, V. 2006. Model zakona o zaštiti podataka o ličnosti. Hereticus – Časopis za preispitivanje prošlosti, 4(3/4), pp. 138-156

Goldsteen, A., Ezov, G., Shmelkin, R., Moffie, M. & Farkash, A. 2022. Data Minimization for GDPR Compliance in Machine Learning Models. AI Ethics, 2, pp. 477-491. https://doi.org/10.1007/s43681-021-00095-8

Hasal, M., Nowaková, J., Saghair, K. A., Abdulla, H., Snášel, V. & Ogiela, L. 2021. Chatbots: Security, Privacy, Data Protection, and Social Aspects. Wiley, pp. 1-13. https://doi.org/10.1002/cpe.6426

Kovačević, T. 2023. Izazovi digitalizacije rada i zaštite ličnih podataka. Strani pravni život, 67(2), pp. 299-320. https://doi.org/10.56461/SPZ_23207KJ

Mathis, K. & Tor, A. 2022. Law and Economics of the Digital Transformation. Switzerland: Springer. https://doi.org/10.1007/978-3-031-25059-0

Milić, D. 2020. Legitimni interes kao osnov za obradu podataka o ličnosti. U: Andonović, S., Prlja, D. & Diligenski, A. (ur.), Zaštita podataka o ličnosti u Srbiji: zbornik radova. Beograd: Institut za uporedno pravo, pp. 47-60.

Naghiyev, K. 2024. ChatGPT from a Data Protection Perspective. Baku State University Law Review. 10(1) pp. 1-34. https://doi.org/10.2139/ssrn.4818860

Savar, M. P. 2023. ChatGPT: A Study of AI Language Processing and its Implications. International Journal of Research Publication and Reviews, 4(2), pp. 435-440. https://doi.org/10.55248/gengpi.2023.4218

Sebastian, G. 2023. Privacy and Data Protection in ChatGPT and Other AI Chatbots: Strategies for Securing User Information. International Journal of Security and Privacy in Pervasive Computing, 15(1), pp. 1-14. https://doi.org/10.4018/IJSPPC.325475

Sen, Z., Uygun, O. & Erden, C. 2023. Advances in Intelligent Manufacturing and Service System Informatics. Singapore: Springer. https://doi.org/10.1007/978-981-99-6062-0

Tošić, I. & Novaković, O. 2020. Uticaj nove regulacije u oblasti zaštite podataka o ličnosti na rad osiguravajućih društava. U: Andonović, S., Prlja, D. & Diligenski, A. (ur.), Zaštita podataka o ličnosti u Srbiji: zbornik radova. Beograd: Institut za uporedno pravo, pp. 93-103.

Vilić, V. & Radenković, I. 2015. Pravo na privatnost u svetlu zakona o zaštiti podataka o ličnosti. Pravni život, 64(10), pp. 331-341.

Villaronga, E., Kieseberg, P. & Li, T. 2018. Humans Forget, Machines Remember: Artificial Intelligence and the Right to be Forgotten. Computer Law & Security Review, 34(2), pp. 304-313. https://doi.org/10.1016/j.clsr.2017.08.007

Zarifis, A., Ktoridou, D., Efthymiou, L. & Cheng, X. 2024. Business Digital Transformation. Switzerland: Palgrave Macmillan. https://doi.org/10.1007/978-3-031-33665-2

Xiongbiao, Y., Yan, Y., Li, J. & Jiang, B. 2024. Privacy and Personal Data Risk Governance for Generative Artificial Intelligence: A Chinese Perspective. Telecommunications Policy, 48, pp. 1-14. https://doi.org/10.1016/j.telpol.2024.102851

Pravni izvori

Artificial Intelligence Act (AI Act) 2024. Official Journal of the European Union, L 1689. Dostupno na: https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng (20. 5. 2025).

California Consumer Privacy Act 2018. Dostupno na: https://govt.westlaw.com/calregs/Document/IB2273E40D44D11ED85F08DB10BE8 E2E0 (20. 4. 2025).

General Data Protection Regulation (GDPR) 2016. Official Journal of the European Union, L 119, 2016/679. Dostupno na: https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (20. 5. 2025).

Krivični zakonik RS. Službeni glasnik RS, br. 85/2005, 88/2005 – ispr., 107/2005 – ispr., 72/2009, 111/2009, 121/2012, 104/2013, 108/2014, 94/2016, 35/2019, 94/2024.

Zakon o zaštiti podataka o ličnosti. Službeni glasnik RS, br. 87/2018.

Zakon o obligacionim odnosima. Službeni list SFRJ, br. 29/1978, 39/1985, 45/1989 – odluka USJ i 57/1989, Službeni list SRJ, br. 31/1993; Službeni list SCG, br. 1/2003 – Ustavna povelja; Službeni glasnik RS, br. 18/2020.

Internet izvori

A Primer on the EU AI Act. 2024. Dostupno na: https://openai.com/global-affairs/a-primer-on-the-eu-ai-act/, 17. 1. 2025.

Data Controls FAQ. 2024. Dostupno na: https://help.openai.com/en/articles/7730893-data-controls-faq, 17. 1. 2025.

How to Delete Your Account. Dostupno na: https://help.openai.com/en/articles/6378407-how-to-delete-your-account, 17. 1. 2025.

Imran Rahman-Jones. ChatGPT: Italy Says OpenAI's Chatbot Breaches Data Protection Rules. 2024. Dostupno na: https://www.bbc.com/news/technology-68128396, 11. 1. 2025.

March 20 ChatGPT Outage: Here’s What Happened. 2023. Dostupno na: https://openai.com/index/march-20-chatgpt-outage/, 16. 1. 2025.

Privacy Policy. 2024. Dostupno na: https://openai.com/policies/row-privacy-policy/ (17. 1. 2025). Security & Privacy. Dostupno na: https://openai.com/security-and-privacy/, 17. 1. 2025.

Vlada Republike Srbije. 2020. Etičke smernice za razvoj, primenu i upotrebu pouzdane i odgovorne veštačke inteligencije. Dostupno na: https://www.ai.gov.rs/tekst/sr/586/eticke-smernice.php, 5. 1. 2025.

Vlada Republike Srbije. 2019. Strategija razvoja veštačke inteligencije u Republici Srbiji za period 2020–2025. Dostupno na: https://www.srbija.gov.rs/extfile/sr/437304/strategija_razvoja_vestacke_inteligencije261219_2_cyr.pdf, 17. 1. 2025.

Vlada Republike Srbije. 2019. Strategija razvoja veštačke inteligencije u Republici Srbiji za period 2020–2025. Dostupno na: https://www.srbija.gov.rs/tekst/437277, 2. 2. 2025.

Wim Nauwelaerts. Dutch Data Protection Authority Warns That Using AI Chatbots Can Lead to Personal Data Breaches. Dostupno na: https://www.alstonprivacy.com/dutch-data-protection-authority-warns-that-using-ai-chatbots-can-lead-to-personal-data-breaches/, 11. 1. 2025.