The Hamburg DPA aligns on tracking tokens and behavioral identification

Glad to see the Hamburg DPA going in a similar direction as what I was suggesting in the post below: tokens should not be viewed as personal data.

Even at the level of the output, “the mere presence of plausible personal information in LLM output is not conclusive
evidence that personal data has been memorized, as LLMs are capable of generating texts that coincidentally matches training data”.
The Hamburg DPA further adds that conducting targeted attacks on LLM to induce reproduction of training data or personal data “could be considered a practically disproportionate effort and potentially a legally prohibited means of determining whether personal data is stored in the LLM”.

More discussion definitely needed, but it shows all is not black or white.

Discussion paper by the Hamburg DPA (English version): https://lnkd.in/epf8qvtg

GDPR data protection GenerativeAI

🫖

Did this analysis get you thinking? Reach out!

DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!

Get in touch ↗   Let's connect on LinkedIn ↗