Particle.news

Eindhoven Confirms AI Data Leak With Scope Still Unclear

Because public AI services kept uploads for only 30 days, the city says it cannot identify all affected people.

Overview

  • The municipality says employees uploaded personal data to public AI tools such as ChatGPT, prompting a confirmed data leak.
  • An external review by Hooghiemstra & Partners found highly sensitive files, including Jeugdwet and WMO records, BSNs, some photos, CVs and internal staff reports.
  • Eindhoven has blocked public AI sites, limited staff to an internal Copilot since October 23, tightened external-traffic monitoring, and adopted an AI behavior code on November 18.
  • The leak was reported to the Dutch Data Protection Authority on October 23, and the AP’s intensified supervision of the city ended in October.
  • The city requested OpenAI to remove uploaded files but reports no response; experts say deletion is likely impossible once data trains models, with immediate misuse risk assessed as limited but not zero.