<?xml version="1.0" encoding="utf-8"?>
<TEI xmlns="http://www.tei-c.org/ns/1.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:hal="http://hal.archives-ouvertes.fr/" xmlns:gml="http://www.opengis.net/gml/3.3/" xmlns:gmlce="http://www.opengis.net/gml/3.3/ce" version="1.1" xsi:schemaLocation="http://www.tei-c.org/ns/1.0 http://api.archives-ouvertes.fr/documents/aofr-sword.xsd">
  <teiHeader>
    <fileDesc>
      <titleStmt>
        <title>HAL TEI export of hal-04844898</title>
      </titleStmt>
      <publicationStmt>
        <distributor>CCSD</distributor>
        <availability status="restricted">
          <licence target="https://creativecommons.org/publicdomain/zero/1.0/">CC0 1.0 - Universal</licence>
        </availability>
        <date when="2026-05-17T01:15:14+02:00"/>
      </publicationStmt>
      <sourceDesc>
        <p part="N">HAL API Platform</p>
      </sourceDesc>
    </fileDesc>
  </teiHeader>
  <text>
    <body>
      <listBibl>
        <biblFull>
          <titleStmt>
            <title xml:lang="en">AI Hallucinations and Data Subject Rights under the GDPR: Regulatory Perspectives and Industry Responses</title>
            <author role="aut">
              <persName>
                <forename type="first">Theodore</forename>
                <surname>Christakis</surname>
              </persName>
              <idno type="idhal" notation="numeric">786435</idno>
              <idno type="halauthorid" notation="string">1326778-786435</idno>
              <idno type="IDREF">https://www.idref.fr/034511636</idno>
              <affiliation ref="#struct-1043134"/>
            </author>
            <editor role="depositor">
              <persName>
                <forename>Shadée</forename>
                <surname>Pinto</surname>
              </persName>
              <email type="md5">72b735ccba78059c6e7af3ba9239366b</email>
              <email type="domain">univ-grenoble-alpes.fr</email>
            </editor>
            <funder ref="#projanr-50501"/>
            <funder ref="#projanr-69637"/>
          </titleStmt>
          <editionStmt>
            <edition n="v1" type="current">
              <date type="whenSubmitted">2024-12-18 10:07:01</date>
              <date type="whenModified">2025-09-27 20:03:27</date>
              <date type="whenReleased">2025-01-07 16:07:24</date>
              <date type="whenProduced">2024-12-11</date>
              <date type="whenEndEmbargoed">2024-12-18</date>
              <ref type="file" target="https://hal.univ-grenoble-alpes.fr/hal-04844898v1/document">
                <date notBefore="2024-12-18"/>
              </ref>
              <ref type="file" subtype="author" n="1" target="https://hal.univ-grenoble-alpes.fr/hal-04844898v1/file/ssrn-5042191.pdf" id="file-4844898-4217225">
                <date notBefore="2024-12-18"/>
              </ref>
            </edition>
            <respStmt>
              <resp>contributor</resp>
              <name key="1609961">
                <persName>
                  <forename>Shadée</forename>
                  <surname>Pinto</surname>
                </persName>
                <email type="md5">72b735ccba78059c6e7af3ba9239366b</email>
                <email type="domain">univ-grenoble-alpes.fr</email>
              </name>
            </respStmt>
          </editionStmt>
          <publicationStmt>
            <distributor>CCSD</distributor>
            <idno type="halId">hal-04844898</idno>
            <idno type="halUri">https://hal.univ-grenoble-alpes.fr/hal-04844898</idno>
            <idno type="halBibtex">christakis:hal-04844898</idno>
            <idno type="halRefHtml">2024</idno>
            <idno type="halRef">2024</idno>
            <availability status="restricted">
              <licence target="https://creativecommons.org/licenses/by/4.0/">CC BY 4.0 - Attribution<ref corresp="#file-4844898-4217225"/></licence>
            </availability>
          </publicationStmt>
          <seriesStmt>
            <idno type="stamp" n="SHS">Sciences de l'Homme et de la Société</idno>
            <idno type="stamp" n="UGA">HAL Grenoble Alpes</idno>
            <idno type="stamp" n="AO-DROIT">Archives ouvertes des Sciences juridiques</idno>
            <idno type="stamp" n="IEPG">Institut d'Études Politiques [IEP] - Grenoble</idno>
            <idno type="stamp" n="CESICE">Centre d'Etudes sur la Sécurité Internationale et les Coopérations Européennes</idno>
            <idno type="stamp" n="MIAI">Multidisciplinary Institute in Artificial intelligence - Grenoble Alpes</idno>
            <idno type="stamp" n="PNRIA">Programme National de Recherche en IA</idno>
            <idno type="stamp" n="UGA-EPE">Université Grenoble Alpes [2020-*]</idno>
            <idno type="stamp" n="ANR">ANR</idno>
            <idno type="stamp" n="CYBERSCURITE">PEPR Cybersécurité</idno>
            <idno type="stamp" n="IPOP">IPOP</idno>
            <idno type="stamp" n="ANR-IA-19" corresp="ANR-IA">ANR-IA-19</idno>
            <idno type="stamp" n="ANR-IA">ANR-IA</idno>
            <idno type="stamp" n="TEST-UGA">TEST-UGA</idno>
          </seriesStmt>
          <notesStmt>
            <note type="description">AI-Regulation.com, the website of the Chair on the Legal and Regulatory Implications of Artificial Intelligence at MIAI Grenoble Alpes</note>
            <note type="popular" n="0">No</note>
            <note type="other" n="1">Blog article</note>
          </notesStmt>
          <sourceDesc>
            <biblStruct>
              <analytic>
                <title xml:lang="en">AI Hallucinations and Data Subject Rights under the GDPR: Regulatory Perspectives and Industry Responses</title>
                <author role="aut">
                  <persName>
                    <forename type="first">Theodore</forename>
                    <surname>Christakis</surname>
                  </persName>
                  <idno type="idhal" notation="numeric">786435</idno>
                  <idno type="halauthorid" notation="string">1326778-786435</idno>
                  <idno type="IDREF">https://www.idref.fr/034511636</idno>
                  <affiliation ref="#struct-1043134"/>
                </author>
              </analytic>
              <monogr>
                <imprint>
                  <date type="datePub">2024-12-11</date>
                </imprint>
              </monogr>
            </biblStruct>
          </sourceDesc>
          <profileDesc>
            <langUsage>
              <language ident="en">English</language>
            </langUsage>
            <textClass>
              <keywords scheme="author">
                <term xml:lang="en">Artificial Intelligence</term>
                <term xml:lang="en">Data Protection</term>
                <term xml:lang="en">AI Regulation</term>
                <term xml:lang="en">Responsible AI</term>
                <term xml:lang="en">Transparency</term>
                <term xml:lang="en">Accuracy</term>
                <term xml:lang="en">Privacy</term>
                <term xml:lang="en">ChatGPT</term>
                <term xml:lang="en">Generative AI</term>
                <term xml:lang="en">Large Language Models</term>
                <term xml:lang="en">AI hallucinations</term>
                <term xml:lang="en">GDPR</term>
              </keywords>
              <classCode scheme="halDomain" n="shs.droit">Humanities and Social Sciences/Law</classCode>
              <classCode scheme="halDomain" n="info.info-ai">Computer Science [cs]/Artificial Intelligence [cs.AI]</classCode>
              <classCode scheme="halTypology" n="BLOG">Scientific blog post</classCode>
              <classCode scheme="halOldTypology" n="OTHER">Other publications</classCode>
              <classCode scheme="halTreeTypology" n="BLOG">Scientific blog post</classCode>
            </textClass>
            <abstract xml:lang="en">
              <p>The rise of general-purpose artificial intelligence (GPAI) systems is transforming industries by generating human-like text, images, and other content. However, these advancements bring a significant challenge: AI hallucinations—instances where AI produces plausible but false or nonsensical information. Such hallucinations undermine the reliability of AI outputs and pose risks when disseminated as factual data, especially in critical fields like law, healthcare, and journalism.This article explores the complex interplay between AI hallucinations and data subject rights under the General Data Protection Regulation (GDPR). It examines high-profile cases where individuals were inaccurately portrayed by AI systems, leading to data protection complaints. In April 2024, the consumer organization Noyb notoriously filed a complaint with the Austrian Data Protection Authority (DPA), alleging that ChatGPT violated GDPR's accuracy principle by providing an incorrect date of birth for a public figure and failing to rectify the error when notified. Drawing on regulatory perspectives, the article focuses into the nuanced approaches proposed by DPAs such as the Hamburg DPA and the UK's Information Commissioner's Office. In July 2024, the Hamburg DPA published a Discussion Paper that ignited extensive debate. This paper's significance lies in the Hamburg DPA's focus on the critical distinction between GPAI systems and Large Language Models (LLMs), which constitute only one component of GPAI systems. According to the Hamburg DPA, LLMs themselves do not contain personal data and, as such, fall outside the scope of the GDPR—a stance that has drawn criticism examined in detail in the paper – as well as the Hamburg DPAs response.However, the true significance of the Discussion Paper, lies in its call to shift regulatory attention toward other components of GPAI systems—particularly their outputs, where the GDPR clearly applies—rather than the internal mechanics of LLMs. The Hamburg DPA’s paper underscores an important point: LLMs do not store personal data in discrete records or operate as traditional structured databases. Consequently, applying the GDPR's accuracy requirement in its conventional form may be neither feasible nor appropriate.Similarly, the ICO proposed a risk-based approach to the issue of AI hallucinations, tailoring accuracy requirements to the purpose and context of AI use and emphasizing information and transparency. The combination of these guidances could be very helpful to mitigate the risks of violating the principle of accuracy and data subject rights under the GDPR when GPAI systems generate incorrect personal information, without hindering the development of these technologies in Europe.This article also explores the multifaceted efforts by GPAI system creators to address these issues, explaining in detail the technical and legal measures implemented to reduce hallucinations and mitigate associated risks. While these measures represent significant progress, they are yet far from perfect, and ongoing refinement is necessary as the technology evolves.By weaving together regulatory insights and industry practices, the article argues for a balanced approach and for  ongoing collaboration among stakeholders to refine strategies that effectively manage AI hallucinations within the GDPR framework.</p>
            </abstract>
          </profileDesc>
        </biblFull>
      </listBibl>
    </body>
    <back>
      <listOrg type="structures">
        <org type="laboratory" xml:id="struct-1043134" status="VALID">
          <idno type="IdRef">140559469</idno>
          <idno type="ISNI">0000 0004 0623 0878</idno>
          <idno type="RNSR">199513955V</idno>
          <idno type="ROR">https://ror.org/033d95m27</idno>
          <idno type="Wikidata">Q51778818</idno>
          <orgName>Centre d'études sur la sécurité internationale et les coopérations européennes</orgName>
          <orgName type="acronym">CESICE</orgName>
          <date type="start">2020-01-01</date>
          <desc>
            <address>
              <addrLine>Université Grenoble Alpes, Faculté de Droit, 1133 rue des résidences, 38400 St Martin d'Hères</addrLine>
              <country key="FR"/>
            </address>
            <ref type="url">https://cesice.univ-grenoble-alpes.fr/</ref>
          </desc>
          <listRelation>
            <relation name="EA2420" active="#struct-1042703" type="direct"/>
            <relation active="#struct-1043359" type="direct"/>
            <relation active="#struct-1042703" type="direct"/>
          </listRelation>
        </org>
        <org type="regroupinstitution" xml:id="struct-1042703" status="VALID">
          <idno type="IdRef">240648315</idno>
          <idno type="ROR">https://ror.org/02rx3b187</idno>
          <orgName>Université Grenoble Alpes</orgName>
          <orgName type="acronym">UGA</orgName>
          <date type="start">2020-01-01</date>
          <desc>
            <address>
              <addrLine>Adresse CS 40700 - 38058 Grenoble cedex</addrLine>
              <country key="FR"/>
            </address>
            <ref type="url">http://www.univ-grenoble-alpes.fr</ref>
          </desc>
        </org>
        <org type="institution" xml:id="struct-1043359" status="VALID">
          <idno type="IdRef">026386305</idno>
          <idno type="ROR">https://ror.org/03c7zyj82</idno>
          <orgName>Sciences Po Grenoble-UGA - Institut d'études politiques de Grenoble</orgName>
          <orgName type="acronym">IEPG</orgName>
          <date type="start">2020-01-01</date>
          <desc>
            <address>
              <addrLine>1030, rue des universités - Domaine Universitaire - 38400 Saint-Martin-d'Hères</addrLine>
              <country key="FR"/>
            </address>
            <ref type="url">http://www.sciencespo-grenoble.fr/</ref>
          </desc>
          <listRelation>
            <relation active="#struct-1042703" type="direct"/>
          </listRelation>
        </org>
      </listOrg>
      <listOrg type="projects">
        <org type="anrProject" xml:id="projanr-50501" status="VALID">
          <idno type="anr">ANR-19-P3IA-0003</idno>
          <orgName>MIAI</orgName>
          <desc>MIAI @ Grenoble Alpes</desc>
          <date type="start">2019</date>
        </org>
        <org type="anrProject" xml:id="projanr-69637" status="VALID">
          <idno type="anr">ANR-22-PECY-0002</idno>
          <orgName>iPoP</orgName>
          <desc>interdisciplinary Project on Privacy</desc>
          <date type="start">2022</date>
        </org>
      </listOrg>
    </back>
  </text>
</TEI>