OpenAI Manually Reviews ChatGPT Conversations
OpenAI’s handling of ChatGPT conversations is receiving renewed attention after 404 Media reported details about an internal human-review program known as Project Lily. The report describes how selected conversations may be examined by human reviewers to help evaluate and improve the quality of ChatGPT’s responses.
According to the report, the reviewers—referred to as “prompt reviewers”—assess anonymized, real-world conversations. Their role is to determine whether an answer addresses the user’s question accurately, clearly, and appropriately. They may also check whether a response contains unwanted characteristics such as excessive “AI-speak,” a patronizing tone, unnecessary emojis, or excessive agreement with the user.
The reported guidance also addresses how ChatGPT should present itself. Reviewers are instructed to flag responses that suggest the system has personal experiences or human emotions. For example, ChatGPT may state that it “found some information,” but it should not claim to be a chef, describe personal preferences, or say that it knows what a user’s personal experience feels like.
From a European data protection perspective, the review of chat transcripts raises important questions under the General Data Protection Regulation (GDPR). Even when conversations are anonymized or used for service improvement, the processing of personal data must have a lawful basis, follow transparency requirements, and respect principles such as data minimization, purpose limitation, and security.
ChatGPT conversations can contain sensitive information, including health details, financial circumstances, employment issues, contact information, or details about other people. Removing direct identifiers may reduce the risk of identification, but anonymization is effective only if individuals can no longer be identified by reasonably likely means. If re-identification remains possible, the data may still qualify as personal data under the GDPR.
Users should therefore review the privacy settings and terms that apply to the ChatGPT service they use, particularly where conversations may be used to improve models. Organizations using ChatGPT for work should also establish clear rules for handling confidential or personal information, assess their legal basis for processing, and consider whether a data processing agreement or additional safeguards are required.
The reported project also highlights the need for clear information about human access to AI conversations. Users should be told, in understandable language, whether people may review their content, why such reviews occur, how long information is retained, and what rights are available. Those rights may include access, correction, deletion, restriction of processing, and objection, depending on the circumstances.