flackz
Senior Member
- Nov 28, 2023
- 836
- 342
According to the GDPR (Regulation (EU) 2016/679), the ID checks that Google, OpenAI, and many others have implemented are not legally justified. Article 5 requires data minimization, yet Google demands a full ID, such as a driver's license or passport, just to run ads, and OpenAI requires a passport and biometric selfie just to use GPT-Image-1. Article 6(1)(c), which applies to banks and financial services under anti-money laundering (AML) laws, does not apply to advertising or AI image generation. Therefore, these companies cannot rely on it. Furthermore, Article 9 prohibits processing biometric data without explicit and freely given consent. OpenAI forces users to provide their biometrics via "Persona," but consent cannot be given when access is completely blocked unless the data is provided. In short, these companies are enforcing ID requirements where no law obligates them to do so, rendering their practice incompatible with the GDPR.
So far, no one has sued these companies for clearly breaking the law, but it is only a matter of time.
So far, no one has sued these companies for clearly breaking the law, but it is only a matter of time.