Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Ireland’s Data Protection Commission (DPC) is investigating whether X Internet Unlimited Company lawfully processed personal data in publicly accessible posts by EU and European Economic Area (EEA) users to develop and train Grok. The inquiry, opened in April 2025, has not produced a verified final finding or penalty. It is separate from later investigations into Grok-generated sexualized images and X’s handling of platform risks.
What the GDPR inquiry is about
The DPC’s April 11, 2025 inquiry concerns personal data contained in publicly accessible posts by people in the EU and EEA, and X’s processing of that information to develop and train generative-AI models, particularly Grok. The regulator is examining whether the processing complied with the GDPR, including requirements concerning lawfulness and transparency, and has also identified purpose limitation as an issue.
The company named in the inquiry is X Internet Unlimited Company (XIUC), which the DPC identifies as X’s relevant EU/EEA data controller. XIUC told the regulator that it changed its name from Twitter International Unlimited Company effective April 1, 2025. Grok is developed by xAI and made available through X; the inquiry does not, by itself, mean that Elon Musk is personally a subject of the GDPR case.
The DPC is the lead supervisory authority for XIUC across the EU/EEA. That role explains why an Irish regulator is handling this cross-border GDPR matter; it is not a European Commission GDPR case.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
Irish DPC announcement of the April 2025 inquiry
How the case developed
| Date | What happened |
|---|---|
| May 7–August 1, 2024 | The DPC later identified this as the period in which the relevant EU/EEA public-post data was processed for Grok training. |
| August 8, 2024 | The DPC sought urgent relief in Ireland’s High Court. X agreed to suspend the specified processing of personal data from public EU/EEA posts for Grok training. |
| September 4, 2024 | The High Court proceedings concluded after X agreed to continue complying with the undertaking on a permanent basis. The DPC also requested an opinion from the European Data Protection Board on issues raised by AI-model development and training. |
| April 11, 2025 | The DPC announced its formal own-volition inquiry into X’s processing of public EU/EEA user posts for developing and training Grok. |
| End of 2025 | The DPC’s 2025 annual report said the information-gathering phase was still ongoing; X had responded to several rounds of queries. |
| January 26, 2026 | The European Commission opened a separate investigation under the Digital Services Act (DSA) into X’s handling of risks associated with Grok and its recommender systems. |
| February 17, 2026 | The DPC opened a separate GDPR inquiry into the generation and publication through Grok and X of potentially harmful, non-consensual sexualized images involving EU/EEA data subjects, including children. |
DPC statement on X’s 2024 suspension undertaking · DPC statement on the conclusion of the High Court proceedings · DPC 2025 annual report
Why public posts can still raise GDPR questions
A post being publicly viewable does not automatically remove the personal-data protections that apply to information about an identifiable person. Nor does public availability alone settle whether a company may reuse that information for a different purpose, such as developing an AI model.
The regulator’s questions include whether X had a valid legal basis for processing, gave users adequate information, and respected purpose limitation: the requirement to consider whether later processing is compatible with the purposes for which information was collected. If X relies on legitimate interests, the legal analysis would also consider necessity, proportionality, and users’ rights and reasonable expectations. The DPC inquiry is examining compliance; its public announcement does not establish which legal basis X relies on or whether a violation occurred.
Technical details can matter too. Data used for pre-training may raise different questions from data used for fine-tuning, evaluation, safety testing, or retrieval. Claims that information was filtered, aggregated, pseudonymized, or anonymized require their own legal and technical assessment. Deleting a post from X does not necessarily establish that the information was removed from a dataset or model, and a model’s ability to reproduce personal information is a distinct issue from the legality of its original collection.
DPC description of the processing under examination
Three regulatory actions, three different questions
The April 2025 GDPR inquiry: training data
This is the case about X’s processing of personal data in publicly accessible EU/EEA posts to develop and train Grok. Its focus is data protection and whether the processing met GDPR obligations.
The February 2026 GDPR inquiry: generated images
The later DPC inquiry concerns Grok’s apparent creation and publication of potentially harmful, non-consensual intimate or sexualized images involving people in the EU/EEA, including children. The DPC said it was examining obligations under GDPR Articles 5, 6, 25, and 35, covering principles such as lawfulness and purpose limitation, lawful bases, data protection by design and by default, and impact assessments. This is not the same inquiry as the one into training on public posts.
The January 2026 DSA investigation: platform risks
The European Commission’s separate DSA investigation concerns X’s assessment and mitigation of systemic risks associated with Grok’s deployment and X’s recommender systems. The Commission cited risks involving illegal content, manipulated sexually explicit images, and possible child sexual-abuse material. The DSA action is not a GDPR investigation, even though the same product may raise issues under more than one legal framework.
Best Value
- No more exposed information in unprotected notary journals. This product shields clients' confidential information from prying eyes. It allows the Notary Public to keep the journal open during the transaction, as NO prior client information is viewable.
- Shields clients' AND Notary Publics' confidential information
- GLBA and HIPAA require non-disclosure policies and procedures. Notary Privacy Guard is a compliance tool for the professional Notary Public.
- Decreases Notary Public's liability from exposing client information
- Journal column headers are printed on the Notary Privacy Guard, no having to peek underneath to complete the journal entry. Becomes part of the journal and also acts as a place marker.
DPC announcement of the separate 2026 GDPR inquiry · European Commission announcement of the DSA investigation
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What X could face—and what has not been established
Depending on its findings, the DPC could close the inquiry without an infringement finding or take corrective action. Possible measures include requiring changes to notices or safeguards, restricting particular processing, ordering remedial steps, or imposing a GDPR administrative fine. The inquiry’s progress through EU/EEA supervisory cooperation may also be relevant to any eventual decision. No fine, deadline, or outcome should be assumed before a decision is announced.
The official materials cited here do not establish that X has already been found to have violated the GDPR in the AI-training case, or that the company has been penalized in that inquiry. The 2024 High Court proceedings ended, but that did not settle the broader inquiry announced in 2025.
Quick Recap
DPC 2025 annual report and reported inquiry status
What users should take from the inquiry
- Making a post public does not necessarily waive GDPR protections, but the inquiry does not establish that every public post was used or unlawfully processed.
- The 2024 undertaking concerned specified processing of EU/EEA public-post data for Grok training; it was not a general ban on all AI training.
- Removing a post now does not, on the information available, prove that it has been removed from any prior training process.
- For a confirmed outcome, look for a final DPC decision rather than treating an open inquiry or the separate DSA case as a finding in the training-data case.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




