Timeline

Italy's data protection authority fines OpenAI €15 million over ChatGPT privacy violations

Garante also ordered a six-month public information campaign about ChatGPT's data use; a Rome court annulled the fine in March 2026 on jurisdictional grounds.

  • Courts & copyright
  • Notable

Italy’s data protection authority, the Garante, closed a nearly two-year investigation into ChatGPT by fining OpenAI €15 million and ordering it to run a six-month public information campaign about how the product collected and used personal data. The decision followed the Garante’s brief emergency ban on ChatGPT in Italy in March 2023, the opening action in the investigation that concluded with this fine.

The Garante found that OpenAI had processed personal data to train ChatGPT without an adequate legal basis under the GDPR, had failed to meet its transparency obligations to users and non-users whose data was involved, and had not built in age-verification measures adequate to prevent children under 13 from being exposed to content unsuited to them. It also found that OpenAI had failed to notify the authority of a security breach affecting user data in March 2023, a separate reporting obligation under EU law. The Garante said it set the €15 million figure taking into account OpenAI’s cooperation during the investigation. Beyond the fine, it ordered a six-month campaign across radio, television, print and online media explaining to the Italian public how ChatGPT collected and used data for training and how individuals could exercise rights to object to, correct or delete their data.

OpenAI called the decision disproportionate, noting the fine was many times its revenue in Italy over the period in question, and said it would appeal. It was among the first substantial GDPR penalties imposed on a major generative-AI product in Europe, and became a reference point for other data protection authorities weighing how existing privacy law applied to models trained on data scraped from the public web.

The fine did not stand: a Rome court suspended it in March 2025 pending appeal and, in March 2026, annulled both the fine and the campaign order outright, ruling that the Garante had lost jurisdiction once OpenAI’s Irish subsidiary was recognised as its main EU establishment — the case then falling instead to Ireland’s data protection authority under the GDPR’s one-stop-shop mechanism.