---
title: OpenAI’s GDPR Travails Demonstrate Need for Data Security-by-Design
description: Firms offering AI services and corporate customers using and contributing data to these AI models, must develop a clear data-centric security strategy.
image: https://insights.comforte.com/hubfs/comforte%20AG_blog%20post_AI.png
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![comforte AG: OpenAI’s GDPR Travails Demonstrate Need for Data Security-by-Design](https://insights.comforte.com/hubfs/comforte%20AG_blog%20post_AI.png)](https://insights.comforte.com/openais-gdpr-travails-demonstrate-need-for-data-security-by-design)

[Mirza Salihagic](https://insights.comforte.com/author/mirza-salihagic) l Apr 6, 2023 l [GDPR](https://insights.comforte.com/tag/gdpr), [Data Protection](https://insights.comforte.com/tag/data-protection), [Compliance](https://insights.comforte.com/tag/compliance), [Big Data Analytics](https://insights.comforte.com/tag/big-data-analytics), [AI](https://insights.comforte.com/tag/ai)

# OpenAI’s GDPR Travails Demonstrate Need for Data Security-by-Design

After several weeks of incredible growth, OpenAI has come in for a bumpy ride of late. First it revealed details of a data breach exposing a significant number of ChatGPT subscribers. Then the Italian data protection regulator (GPDP) became the first in Europe to ban the product for users in the country, for contravening the GDPR.

Although the fallout from last month’s breach was limited, the regulatory action that followed makes one thing very clear. Firms offering AI services, and corporate customers using and contributing data to these AI models, must first develop a clear data-centric security strategy to mitigate any breach/leakage risks.

## What happened at OpenAI?

The ChatGPT maker was forced to take its flagship AI service offline in late March after it discovered a bug in a third-party open source library (Redis) that it uses. [The firm said](https://openai.com/blog/march-20-chatgpt-outage) that the issue may have enabled users to view:

- The title and first message of a newly created conversation belonging to other users
- Other active users’ first and last name, email address, payment address, the last four digits their credit card number, and credit card expiration date

OpenAI was at pains to point out that users would have needed to jump through several hoops to view the sensitive personal, chat and financial information of other ChatGPT users during this incident. It added that the payment-related information of only 1.2% of ChatGPT Plus subscribers was exposed during the nine-hour window. However, such personal information can be a treasure trove for fraudsters, who leverage it in follow-on phishing attacks designed to elicit more data.

That’s why organizations have obligations under the GDPR to ensure any such information is protected at all times from theft and alteration. That’s part of the reason for [the temporary ban](https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/9870847#english) on ChatGPT in Italy.

## The path to secure AI

In short, this particular breach at OpenAI thankfully wasn’t too serious. But the next one might be. That’s especially true of AI providers that use open source code, as most developers do these days to accelerate time to market. Threat actors are proactively inserting malicious packages in these upstream repositories so they can exploit them once downloaded by customers. Last year, [experts claimed](https://www.infosecurity-magazine.com/news/software-supply-chain-attacks-soar/) to have uncovered 88,000 malicious open source packages, a 742% increase on 2019 figures.

Breaches can come from many other sources besides third-party code repositories. And as the OpenAI case has shown, the potential response from regulators can be severe. That should focus minds more keenly on protecting sensitive customer account data with best practice mechanisms like strong encryption and tokenization. This means that if the data is stolen or accidentally leaked there should be minimal regulatory repercussions, because it would be impossible to read or use.

There’s a secondary consideration here for corporate customers of AI tools like ChatGPT. They might want to submit their own data to help train the model into providing more accurate and relevant outputs. Others may type sensitive information in and unwittingly have it stored and shared by the AI vendor. Any decision to do so should therefore be carefully weighed against the potential risk of breach or exposure by the third-party AI service provider.

Lawyers at compliance expert Cordery [had the following advice](https://www.corderycompliance.com/it-dpa-chatgpt-0423-01/):

*“If you’re inputting your data into the tool, do you know what that data will be used for? Will your data be added to the data training pot? If so, are you happy with that especially given the questionable ownership of some AI solutions? How can you guarantee the security of the data, which is also a GDPR requirement?”*

This is where comforte can help, with data-centric security that:

- Discovers and automatically classifies all sensitive data
- Searches locations like cloud data stores which are often hidden
- Offers multiple protection methods including tokenization, which preserve data utility for AI analytics and other use cases
- Integrates seamlessly with data flows and applications for rapid time-to-value

---

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/openais-gdpr-travails-demonstrate-need-for-data-security-by-design&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/openais-gdpr-travails-demonstrate-need-for-data-security-by-design&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/openais-gdpr-travails-demonstrate-need-for-data-security-by-design&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/openais-gdpr-travails-demonstrate-need-for-data-security-by-design&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/openais-gdpr-travails-demonstrate-need-for-data-security-by-design&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Want to learn more about data protection methods?

Click the button below to download our free eBook (without filling out any forms!) and get more in depth information about the advantages and disadvantages of leading data protection methods like tokenization, encryption, hashing, masking, and more. 

[![Download eBook](https://no-cache.hubspot.com/cta/default/4026697/0a8d23e5-0dae-480e-b4f4-060d5732901f.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/0a8d23e5-0dae-480e-b4f4-060d5732901f)

### Related posts

![How to Stay Agile and Compliant with Format-preserving Protection for Analytics](https://insights.comforte.com/hubfs/Analytics%20on%20Red%20Button%20Enter%20on%20Black%20Computer%20Keyboard..jpeg)

 Aug 4, 2022 l [GDPR](https://insights.comforte.com/tag/gdpr) , [PCI DSS](https://insights.comforte.com/tag/pci-dss) , [Compliance](https://insights.comforte.com/tag/compliance) , [Big Data Analytics](https://insights.comforte.com/tag/big-data-analytics) , [CCPA](https://insights.comforte.com/tag/ccpa)

### [How to Stay Agile and Compliant with Format-preserving Protection for Analytics](https://insights.comforte.com/how-to-stay-agile-and-compliant-with-format-preserving-protection-for-analytics?hsLang=en)

Cloud-based analytics offer a truly transformative opportunity for global organizations. By extracting insights from data, they are already helping companies better serve their customers, improve operational efficiencies and make better business...

[Read more](https://insights.comforte.com/how-to-stay-agile-and-compliant-with-format-preserving-protection-for-analytics?hsLang=en)

![17 Countries with GDPR-like Data Privacy Laws](https://insights.comforte.com/hubfs/Int_Datenschutz_Strategie_1.png)

 Jan 13, 2022 l [GDPR](https://insights.comforte.com/tag/gdpr) , [Data Protection](https://insights.comforte.com/tag/data-protection) , [Compliance](https://insights.comforte.com/tag/compliance) , [CCPA](https://insights.comforte.com/tag/ccpa)

### [17 Countries with GDPR-like Data Privacy Laws](https://insights.comforte.com/countries-with-gdpr-like-data-privacy-laws?hsLang=en)

GDPR wasn't the beginning and it certainly won't be the end. Strict data privacy legislation with extraterritorial applicability is appearing in more and more economies across the globe, meaning the list of “GDPR-free” havens is growing shorter by...

[Read more](https://insights.comforte.com/countries-with-gdpr-like-data-privacy-laws?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>