Overview
- The municipality says employees uploaded personal data to public AI tools such as ChatGPT, prompting a confirmed data leak.
- An external review by Hooghiemstra & Partners found highly sensitive files, including Jeugdwet and WMO records, BSNs, some photos, CVs and internal staff reports.
- Eindhoven has blocked public AI sites, limited staff to an internal Copilot since October 23, tightened external-traffic monitoring, and adopted an AI behavior code on November 18.
- The leak was reported to the Dutch Data Protection Authority on October 23, and the AP’s intensified supervision of the city ended in October.
- The city requested OpenAI to remove uploaded files but reports no response; experts say deletion is likely impossible once data trains models, with immediate misuse risk assessed as limited but not zero.