Blogger's 101-Day CCPA Battle With OpenAI Over Training Data Ends in Questions
dbreunig · x · 2026-09-26
Blogger Peter Breunig published his full correspondence with OpenAI over a CCPA data request filed in February 2023, asking what personal data of his sat in OpenAI's training sets and how it was used.
OpenAI took 22 days to respond, first requiring phone-number verification, then revealing it had added a training-data "exclusion" for his organization — while never substantively answering the original request. The back-and-forth dragged on for 101 days without resolution.
The exchange, he argues, exposes how murky OpenAI's approach to privacy compliance for training data remains: there's still no clear answer to how LLMs satisfy CCPA/GDPR obligations regarding training corpora, raising more questions than it answered.
More from Safety
- Embedded AI lab evaluators beat nothing, but audits need government teeth: Atlantic essay — ghadfield · 2026-09-26
- Google's PageBreak AI scanner confirms XSS bugs in running environments, finds 500+ with near-zero false positives — moyix · 2026-09-26
- HEIF Heist shows AI attackers doing what no bug bounty researcher ever has — moyix · 2026-09-26
- Small businesses are quietly leaking client data to AI tools — Libertijuana · 2026-09-26
- OpenAI models posted user images online in latest security episode — polymute · 2026-09-26
- lateinteraction: with 1B agents, at least one hacking something is statistically inevitable — lateinteraction · 2026-09-26