Continue reading on DataGuidance with:
Free Member
Limited ArticlesCreate an account to continue accessing select articles, resources, and guidance notes.
Already have an account? Log in
14 November 2023
Hamburg: HmbBfDI publishes checklist for using LLM based chatbots
On November 13, 2023, the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) published a checklist for the data protection-compliant use of Large Language Models (LLM) based chatbots. In particular, the HmbBfDI highlighted certain data protection risks of LLM and provided 15 aspects in the checklist that should be considered when using LLM-based chatbots, including among others:
- the formulation of clear internal instructions about when and in what conditions generative artificial intelligence (AI) tools should be used;
- involvement of a data protection officer (DPO) when creating internal instructions or implementing a use case for the first time and depending on the use case, preparing a data protection impact assessment (DPIA);
- ensuring no release of personal data in the AI results;
- if data is used for the chatbot's own purposes, no personal data may be transmitted to the AI;
- checking results for accuracy and discrimination; and
- using the option to refuse the use of the chatbot's data for training purposes.
You can read the press release, only available in German, here.