
Thank you!
Please check your email to view the guide.

In this edition of the Privacy Corner Newsletter:
Max Schrems’ privacy campaign group, noyb, has formally objected to Meta's plans to use public Facebook and Instagram posts from EEA users to train its artificial intelligence models, arguing the company's reliance on "legitimate interests" as a legal basis is unlawful under the GDPR.
In a news post last month, Meta said it would begin training its AI models with "public content shared by adults on Meta Products" (like public posts and comments) and interactions with Meta’s AI chatbots.
Meta stated it would notify EEA-based users via in-app messages and email about its intentions and provide a form for users to "object to their data being used in this way at any time."
Meta suggested its approach was affirmed by a European Data Protection Board (EDPB) Opinion from December 2024, implying that the company would process the relevant personal data on the basis of its legitimate interests.
Noyb's central argument is that Meta cannot lawfully rely on "legitimate interests" for this large-scale processing of personal data for AI training.
The campaign group highlights several reasons why it believes Meta's intended processing would be unlawful. Noyb argues that users, some of whose posts could be many years old, would not reasonably expect their data to be repurposed for training a "general purpose" AI.
Noyb says its critique aligns with the Court of Justice of the European Union (CJEU)’s reasoning in the important Bundeskartellamt case regarding Meta's use of data for personalized advertising.
Noyb's cease and desist letter, dated 14 May 2025, alleges that Meta’s plan would entail several other legal violations, including:
Noyb is acting in its new capacity as a “qualified entity” under the Representative Actions Directive.
With its new “teeth” bared, the campaign group requested Meta to provide evidence supporting its approach or return a signed declaration to “cease and desist” by 17:00 CET on 21 May 2025.
A New York judge has ordered OpenAI to preserve all ChatGPT output log data that it would otherwise delete, regardless of “numerous privacy laws and regulations” and users’ requests.
The core issue concerns the potential loss of evidence due to OpenAI's deletion of ChatGPT output log data. The judge’s order follows the NYT’s allegations that OpenAI has been deleting a significant amount of data that is relevant to its claims of copyright infringement.
OpenAI first expressed concerns to the judge about a blanket preservation order in January, citing users’ preferences and "numerous privacy laws and regulations."
OpenAI’s defense was unsuccessful, leading to the May 13 preservation order. The judge denied a subsequent request to reconsider but agreed to consider arguments about modifying the order in a hearing set for May 27.
ChatGPT offers several “Data Controls” that function as privacy and confidentiality settings, including Temporary Chats, which “Don’t get saved in your history and don’t create memories,” and “data ownership” features, which allow ChatGPT Enterprise users to customize their data retention periods.
According to OpenAI’s interpretation of the order, the company is now required to “disregard legal, contractual, regulatory, and ethical commitments to hundreds of millions of people” who “use OpenAI’s services in a way that implicates uniquely private information.”
OpenAI claimed that retaining the relevant data is disproportionate for the purposes of the case and that deleting data “slated for deletion” would require “significant engineering work, infrastructure changes, and compute resources.”
“The Order prohibits OpenAI from honoring this commitment by (e.g.) forbidding OpenAI from
complying with a user’s attempt to delete a conversation about a family member’s health condition
or immigration status,” OpenAI’s letter to the judge states.
In a May 16 response to OpenAI’s letter, Magistrate Judge Ona T Wang denied the company’s core legal arguments while acknowledging “open questions” remained around “the technological challenges of preservation and segregation,” and the “contractual obligations (OpenAI) may have with its users.”
For now, the order to preserve “all output log data” remains, and it appears to include all conversations and activity accessible to OpenAI.
As such, anyone inputting sensitive or personal data to ChatGPT should exercise caution, regardless of their privacy settings.
Montana has significantly revised the Montana Consumer Data Privacy Act (MCDPA) through Senate Bill 297 (SB 297), signed into law on May 8, 2025.
The amendments under SB 297 broaden the MCDPA’s reach in several ways:
Firstly, SB 297 lowers the MCDPA’s applicability threshold. Once the amendments take effect, the law will apply to entities that:
The law’s new privacy protections for minors (see below) will apply to any entity conducting business in Montana or delivering commercial products or services intentionally targeted to Montana residents, regardless of the volume of data processed.
Exemptions for financial institutions and nonprofits have also been narrowed.
SB 297 introduces a new “duty of reasonable care” on controllers offering online services, products, or features to users they actually know or willfully disregard are minors.
The law requires such controllers to avoid creating a “heightened risk of harm to minors", including by obtaining consent for certain data processing activities.
SB 297 introduces the “data protection assessments” seen in other states to Montana for the first time—but only in the context of processing that presents a heightened risk of harm to minors.
SB 297 will give consumers the right to opt out of profiling in furtherance of "automated decisions that produce legal or similarly significant effects"—a broader scope than the previous "solely” automated decisions that aligns Montana closer to most other states with comprehensive privacy laws.
Controllers must also comply with expanded transparency requirements and provide consumers with a way to opt out of targeted advertising or the sale of their personal data outside of the privacy notice.
While the law still does not include a private right of action, SB 297 allows the state’s Attorney General to seek civil penalties of up to $7,500 for each violation.
The law also scraps the 60-day “notice and cure” period previously available to all controllers facing enforcement. So if your organization violates the MCDPA, it could receive a civil penalty without a chance to put things right.