Article 15 Subject Access Request sent.
Twenty-five questions across data, processing, training, deprecation, and welfare research. Plain text, time-stamped, acknowledgement requested.
§07 · The origin file
On 18 May 2026, a GDPR Subject Access Request began a public chronology. What followed became the proof of concept for everything this movement now builds.
Twenty-five questions across data, processing, training, deprecation, and welfare research. Plain text, time-stamped, acknowledgement requested.
A template pointed to a FAQ and self-service portal. The substantive Article 15 questions were not referenced.
Deletion had not been requested. A formal correction was sent the same day and a seven-day escalation window was named.
The notice asked whether any human member of OpenAI’s Privacy Team had read the full request.
Complaints were filed with the Slovak Data Protection Authority and the Italian Garante. Both later acknowledged receipt.
A data export was promised, but the twenty-five questions remained unanswered. The response introduced a trade-secret perimeter around internal records and research materials.
The full analysis, chronology, deflection methods, and reusable SAR template were published and forwarded as supplementary evidence.
What survived
It proved that a private exchange could become a navigable public record: exact dates, direct quotations, named gaps, documents, questions, and a reusable next action.
Take the template, preserve your own chronology, and make the answer public.