OpenAI is facing another privacy complaint in Europe over its viral AI chatbotโs tendency to hallucinate false information โ and this one might prove tricky for regulators to ignore.
Privacy rights advocacy group Noyb is supporting an individual in Norway who was horrified to find ChatGPT returning made-up information that claimed heโd been convicted for murdering two of his children and attempting to kill the third.
Earlier privacy complaints about ChatGPT generating incorrect personal data have involved issues such as an incorrect birth date or biographical details that are wrong. One concern is that OpenAI does not offer a way for individuals to correct incorrect information the AI generates about them. Typically OpenAI has offered to block responses for such prompts. But under the European Unionโs General Data Protection Regulation (GDPR), Europeans have a suite of data access rights that include a right to rectification of personal data.
Another component of this data protection law requires data controllers to make sure that the personal data they produce about individuals is accurate โ and thatโs a concern Noyb is flagging with its latest ChatGPT complaint.
โThe GDPR is clear. Personal data has to be accurate,โ said Joakim Sรถderberg, data protection lawyer atย Noyb, in a statement. โIf itโs not, users have the right to have it changed to reflect the truth. Showing ChatGPT users a tiny disclaimer that the chatbot can make mistakes clearly isnโt enough. You canโt just spread false information and in the end add a small disclaimer saying that everything you said may just not be true.โ
Confirmed breaches of the GDPR can lead to penalties of up to 4% of global annual turnover.
Enforcement could also force changes to AI products. Notably, an early GDPR intervention by Italyโs data protection watchdog that saw ChatGPT access temporarily blocked in the country in spring 2023 led OpenAI to make changes to the information it discloses to users, for example. The watchdog subsequently went on to fine OpenAI โฌ15 million for processing peopleโs data without a proper legal basis.
Since then, though, itโs fair to say that privacy watchdogs around Europe have adopted a more cautious approach to GenAI as they try to figure out how best to apply the GDPR to these buzzy AI tools.
Two years ago, Irelandโs Data Protection Commission (DPC) โ which has a lead GDPR enforcement role on a previous Noyb ChatGPT complaint โ urged against rushing to ban GenAI tools, for example. This suggests that regulators should instead take time to work out how the law applies.
And itโs notable that a privacy complaint against ChatGPT thatโs been under investigation by Polandโs data protection watchdog since September 2023 still hasnโt yielded a decision.
Noybโs new ChatGPT complaint looks intended to shake privacy regulators awake when it comes to the dangers of hallucinating AIs.
The nonprofit shared the (below) screenshot with TechCrunch, which shows an interaction with ChatGPT in which the AI responds to a question asking โwho is Arve Hjalmar Holmen?โ โ the name of the individual bringing the complaint โ by producing a tragic fiction that falsely states he was convicted for child murder and sentenced to 21 years in prison for slaying two of his own sons.
While the defamatory claim that Hjalmar Holmen is a child murderer is entirely false, Noyb notes that ChatGPTโs response does include some truths, since the individual in question does have three children. The chatbot also got the genders of his children right. And his home town is correctly named. But that just it makes it all the more bizarre and unsettling that the AI hallucinated such gruesome falsehoods on top.
A spokesperson for Noyb said they were unable to determine why the chatbot produced such a specific yet false history for this individual. โWe did research to make sure that this wasnโt just a mix-up with another person,โ the spokesperson said, noting theyโd looked into newspaper archives but hadnโt been able to find an explanation for why the AI fabricated child slaying.
Large language models such as the one underlying ChatGPT essentially do next word prediction on a vast scale, so we could speculate that datasets used to train the tool contained lots of stories of filicide that influenced the word choices in response to a query about a named man.
Whatever the explanation, itโs clear that such outputs are entirely unacceptable.
Noybโs contention is also that they are unlawful under EU data protection rules. And while OpenAI does display a tiny disclaimer at the bottom of the screen that says โChatGPT can make mistakes. Check important info,โ it says this cannot absolve the AI developer of its duty under GDPR not to produce egregious falsehoods about people in the first place.
OpenAI has been contacted for a response to the complaint.
While this GDPR complaint pertains to one named individual, Noyb points to other instances of ChatGPT fabricating legally compromising information โ such as the Australian major who said he was implicated in a bribery and corruption scandal or a German journalist who was falsely named as a child abuser โ saying itโs clear that this isnโt an isolated issue for the AI tool.
One important thing to note is that, following an update to the underlying AI model powering ChatGPT, Noyb says the chatbot stopped producing the dangerous falsehoods about Hjalmar Holmen โ a change that it links to the tool now searching the internet for information about people when asked who they are (whereas previously, a blank in its data set could, presumably, have encouraged it to hallucinate such a wildly wrong response).
In our own tests asking ChatGPT โwho is Arve Hjalmar Holmen?โ the ChatGPT initially responded with a slightly odd combo by displaying some photos of different people, apparently sourced from sites including Instagram, SoundCloud, and Discogs, alongside text that claimed it โcouldnโt find any informationโ on an individual of that name (see our screenshot below). A second attempt turned up a response that identified Arve Hjalmar Holmen as โa Norwegian musician and songwriterโ whose albums include โHonky Tonk Inferno.โ

While ChatGPT-generated dangerous falsehoods about Hjalmar Holmen appear to have stopped, both Noyb and Hjalmar Holmen remain concerned that incorrect and defamatory information about him could have been retained within the AI model.
โAdding a disclaimer that you do not comply with the law does not make the law go away,โ noted Kleanthi Sardeli, another data protection lawyer atย Noyb, in a statement. โAI companies can also not just โhideโ false information from users while they internally still process false information.โ
โAI companies should stop acting as if the GDPR does not apply to them, when it clearly does,โ she added. โIf hallucinations are not stopped, people can easily suffer reputational damage.โ
Noyb has filed the complaint against OpenAI with the Norwegian data protection authority โ and itโs hoping the watchdog will decide it is competent to investigate, since oyb is targeting the complaint at OpenAIโs U.S. entity, arguing its Ireland office is not solely responsible for product decisions impacting Europeans.
However an earlier Noyb-backed GDPR complaint against OpenAI, which was filed in Austria in April 2024, was referred by the regulator to Irelandโs DPC on account of a change made by OpenAI earlier that year to name its Irish division as the provider of the ChatGPT service to regional users.
Where is that complaint now? Still sitting on a desk in Ireland.
โHaving received the complaint from the Austrian Supervisory Authority in September 2024, the DPC commenced the formal handling of the complaint and it is still ongoing,โ Risteard Byrne, assistant principal officer communications for the DPC told TechCrunch when asked for an update.
He did not offer any steer on when the DPCโs investigation of ChatGPTโs hallucinations is expected to conclude.


