X and data privacy: a series of complaints shakes Musk’s platform | Benefits of Generative ai | Generative ai use Cases in Banking | Generative ai Tools List | Turtles AI

X and data privacy: a series of complaints shakes Musk’s platform
Editorial Team12 August 2024

 


Social media platform X, formerly known as Twitter, is at the center of a legal storm in the European Union over alleged violations of user privacy. The company, owned by Elon Musk, has been accused of using users’ personal data to train AI models without their consent, a practice that has raised concerns among privacy watchdogs in several European countries. This affair highlights the challenges large technology platforms face in complying with Europe’s strict data protection regulations, known as GDPR.

Key points:

1. Allegations of privacy violations: X has been sued in nine European countries for unauthorized use of user data for AI training.
2. Authorities’ response: Ireland’s DPC, the main regulator, has initiated legal action to stop the practice, but experts criticize the effectiveness of its measures.
3. Reactions of users and organizations: The noyb, a privacy rights organization, has filed numerous complaints against X, accusing it of failing to comply with GDPR regulations.
4. Industry precedent: Meta also recently suspended a similar plan to use European user data to train AI, after regulatory pressure.

In late July, a user discovered a setting on X that indicated how European users’ post data was being processed for training the chatbot Grok AI, an initiative of the same platform. This revelation provoked a reaction from the Irish Data Protection Commission (DPC), which expressed "surprise" about the practice, given that X is subject to DPC oversight for GDPR compliance. European legislation requires a valid legal basis for the use of personal data, and non-compliance can lead to penalties of up to 4 percent of the company’s global turnover.

The central charge brought against X concerns the failure to seek consent from users for the use of their personal data, a crucial aspect under the GDPR. The noyb, a nonprofit organization led by Max Schrems, has filed complaints with data protection authorities in Austria, Belgium, France, Greece, Ireland, Italy, the Netherlands, Poland, and Spain. According to Schrems, the DPC’s behavior in recent years has often been ineffective, and efforts are now being made to ensure that X fully complies with European law.

The DPC has already initiated legal action in the Irish High Court to stop X’s use of data for AI training. However, noyb criticizes the actions taken, pointing out that users have no way to remove data already used. Complaints filed in various European countries allege that X has no valid legal basis for processing the data of some 60 million EU citizens to train AI without obtaining their consent. X appears to rely on a legal justification known as "legitimate interest" to justify processing the data, but privacy experts argue that users’ explicit consent is necessary.

A similar example was observed in the case of Meta, which suspended a plan to train AI using European user data following similar complaints filed by noyb and intervention by regulators. This episode underscores the importance of obtaining users’ consent before using their personal data, especially in such sensitive contexts as AI systems training.

X added a new setting on the web version of the platform in late July, allowing users to opt out of data processing for AI. However, there was no way to block processing before then, and many users were not even aware that their data was being used for this purpose. This point is crucial because the GDPR was designed to protect European citizens from unexpected uses of their information, which could affect their rights and freedoms.

Noyb drew attention to a European Supreme Court ruling last summer, in which it was ruled that legitimate interest was not a valid legal basis for Meta’s use of people’s data for advertising targeting, stressing that explicit user consent is necessary. In addition, noyb pointed out that providers of generative AI systems, including OpenAI’s ChatGPT, have difficulty complying with other key requirements of the GDPR, such as the right to be forgotten and the right to obtain a copy of one’s personal data.

In conclusion, the affair highlights how large technology platforms must contend with strict European privacy regulations, which require transparency and respect for users’ rights. The X issue could have significant implications for the entire artificial intelligence industry, prompting companies to review their data management practices.

 The current situation calls for increased attention to the legal and ethical implications of the use of personal data, especially in a rapidly evolving technological environment such as AI.