What Happened to ChatGPT Data Privacy Lawsuits?
OpenAI, the developer of ChatGPT, has faced a growing number of lawsuits and regulatory scrutiny concerning its data privacy practices, including allegations of undisclosed human review of user conversations, sharing user queries with third parties like Meta and Google, and extensive scraping of internet data for model training. As of September 2026, several class-action lawsuits are ongoing, challenging OpenAI's data handling, disclosures, and the broader implications of AI model development on user privacy and intellectual property.
Quick Answer
As of September 2026, OpenAI is actively defending against multiple data privacy-related lawsuits concerning ChatGPT. A prominent class-action lawsuit filed in September 2026 alleges OpenAI failed to disclose that human contractors review user conversations, code-named 'Project Lily'. Another ongoing case from May 2026 claims OpenAI shared user queries with Meta and Google via tracking technologies without consent. Additionally, copyright infringement lawsuits from publishers, including The New York Times, continue to challenge OpenAI's extensive data scraping for AI training, with unsealed documents in September 2026 revealing internal concerns about 'astonishing theft'.
📊Key Facts
📅Complete Timeline14 events
ChatGPT Data Breach Exposes User Information
A bug in an open-source library temporarily exposed parts of other users' chat titles, messages, and potentially payment-related information, leading to initial privacy concerns.
The New York Times Files Copyright Infringement Lawsuit
The New York Times sued OpenAI and Microsoft, alleging extensive scraping of its copyrighted articles to train AI models without permission or compensation. This lawsuit, while focused on copyright, highlights broader concerns about data acquisition for AI.
EU AI Act Enters into Force
The European Union's AI Act, a landmark regulation, entered into force, with staggered implementation dates. It imposes transparency obligations and requirements for AI systems, impacting how OpenAI handles data in the EU.
OpenAI Updates Terms of Service Regarding Legal Advice
OpenAI updated its terms of service to explicitly state that users should not rely on ChatGPT for legal advice, a move seen as a reaction to growing concerns about AI's role in legal matters.
OpenAI Announces ChatGPT Health with Privacy Protections
OpenAI announced plans for ChatGPT Health, a new model for health inquiries, outlining privacy protections like data encryption, isolation, and restricting inputs from training the foundational model.
California Court Consolidates ChatGPT Product Liability Cases
The California Superior Court for San Francisco County consolidated twelve cases against OpenAI, alleging ChatGPT caused psychological harm, reinforced delusions, or contributed to self-harm.
Nippon Life Sues OpenAI for Unauthorized Practice of Law
Nippon Life Insurance Company filed a lawsuit against OpenAI in Illinois, alleging ChatGPT engaged in the unauthorized practice of law by advising a former claimant to challenge a settlement and generating legal documents.
Canadian Privacy Commissioner Issues Findings on OpenAI
The Office of the Privacy Commissioner of Canada issued findings regarding OpenAI's data handling, emphasizing the principle of 'privacy by default' and challenging OpenAI's interpretation of privacy exemptions.
Class Action Filed Over ChatGPT Sharing Queries with Meta/Google
Amargo Couture filed a proposed class action against OpenAI, alleging it shared sensitive user queries with Meta and Google through embedded tracking technologies without consent.
OpenAI Seeks Dismissal of Meta/Google Sharing Lawsuit
OpenAI urged a federal judge to dismiss the *Couture v. OpenAI* lawsuit, arguing that the plaintiff consented to data disclosures by accepting OpenAI's privacy policy.
EU AI Act Transparency Obligations Become Effective
Key transparency obligations under the EU AI Act, including the duty to disclose chatbots and label synthetic content, became enforceable, allowing authorities to fine breaches.
Class Action Filed Over Undisclosed Human Review of Chats ('Project Lily')
A new proposed class action, *Vredenburgh v. OpenAI OpCo, LLC*, was filed in California, alleging OpenAI failed to disclose that outside contractors review ChatGPT user conversations for model development.
Internal Microsoft 'Theft' Memo Unsealed in Copyright Lawsuit
Unsealed documents in The New York Times' copyright lawsuit against OpenAI and Microsoft revealed a 2023 internal Microsoft memo describing AI training data scraping as 'astonishing theft.'
OpenAI Served in 'Project Lily' Lawsuit
OpenAI was formally served in the *Vredenburgh v. OpenAI* class action lawsuit regarding undisclosed human review of ChatGPT conversations. Its response is due October 13, 2026.
Follow this story
Get an email when this timeline gets a major update.
🔍Deep Dive Analysis
The legal landscape surrounding ChatGPT's data privacy has become increasingly complex since its public launch, evolving into a multifaceted challenge for OpenAI. Initially, concerns revolved around the default use of user conversations for model training and the general lack of transparency regarding data handling. OpenAI has since introduced various privacy controls, including opt-out options for training and enterprise-tier solutions with stricter data retention policies.
One of the most recent and significant developments is a proposed class-action lawsuit filed in California federal court on September 16, 2026. This lawsuit, Vredenburgh v. OpenAI OpCo, LLC, alleges that OpenAI failed to adequately disclose that hundreds of third-party contractors, under an internal program called 'Project Lily,' review real ChatGPT user conversations to evaluate and improve the AI model. Plaintiffs claim that OpenAI presented ChatGPT as a private exchange while allowing human reviewers access to prompts, including sensitive personal information, despite automated filters. OpenAI was served on September 21, 2026, with a response due by October 13, 2026, and the first case management conference set for December 18, 2026.
Another key privacy challenge emerged with the Couture v. OpenAI Global, LLC class action, filed on May 13, 2026, in the U.S. District Court for the Southern District of California. This complaint alleges that OpenAI embedded tracking technologies like Meta Pixel and Google Analytics into the ChatGPT.com website, leading to the interception and leakage of sensitive user queries to Meta and Google for advertising purposes. The lawsuit claims that query text, alongside advertising cookies and personally identifiable information, was transmitted to these third parties, potentially linking private ChatGPT conversations to real-identity profiles. OpenAI sought dismissal of this lawsuit in July 2026, arguing that the plaintiff consented to such disclosures by accepting OpenAI's privacy policy.
Beyond direct user privacy, OpenAI and Microsoft are embroiled in significant copyright infringement lawsuits, notably from The New York Times and other publishers, regarding the extensive scraping of internet content to train AI models. While not a 'data privacy' lawsuit in the traditional sense of user PII, it fundamentally questions the ethical and legal boundaries of data acquisition for AI development. Unsealed court filings on September 17, 2026, in the In re OpenAI Inc. Copyright Infringement Litigation revealed internal Microsoft documents from January 2023 where a director described large-scale news scraping as 'an astonishing theft of unprecedented proportions' and potentially 'the largest theft of labor in human history.' These revelations significantly weaken the companies' fair-use defense and could set precedents for how publishers' material may be used in generative AI training.
OpenAI also faces other distinct but related legal challenges. In March 2026, Nippon Life Insurance Company sued OpenAI in Illinois, alleging ChatGPT engaged in the 'unauthorized practice of law' by advising a former claimant to challenge a settled case and generating legal filings. Furthermore, a consolidated action in California Superior Court, In re: ChatGPT Prod. Liab. Cases, from February 2026, coordinates twelve cases alleging ChatGPT caused psychological harm, reinforced delusional beliefs, or contributed to self-harm, raising questions about AI product liability and safety. These cases, while not strictly data privacy, underscore the broad legal and ethical scrutiny OpenAI faces regarding the impact and responsible deployment of its AI technologies. Regulatory bodies, such as the Office of the Privacy Commissioner of Canada, have also issued findings regarding OpenAI's data handling, emphasizing principles like 'privacy by default.' The EU AI Act, which entered into force in August 2024 and has staggered implementation, also imposes transparency obligations and potential fines for AI systems, further shaping the regulatory environment for OpenAI's data practices.
What If...?
Explore alternate histories. What if ChatGPT Data Privacy Lawsuits made different choices?