← All cases

Italian Garante v. OpenAI — EUR 15 million ChatGPT fine (later annulled on appeal)

What happened

After briefly blocking ChatGPT in March 2023, Italy's data protection authority (Garante) investigated OpenAI. On 20 December 2024 it announced a EUR 15 million fine, finding that OpenAI had trained ChatGPT on personal data without an adequate legal basis, failed to give users transparent information, had no effective age verification to keep under-13s out, and had not notified the Garante of a March 2023 data breach. OpenAI was also ordered to run a six-month public information campaign in Italian media.

The rule

GDPR: lawfulness of processing (Art. 6), transparency and information duties (Arts. 12–14), breach notification (Art. 33) and protection of children. The Garante applied the GDPR to model training itself, not just to the chatbot interface.

Outcome

OpenAI appealed, calling the fine disproportionate. The Rome Tribunal suspended the fine in March 2025 and then, in judgment no. 4153/2026 filed 18 March 2026, annulled it, reported as finding that once OpenAI had an Irish establishment the GDPR 'one-stop-shop' made Ireland's DPC the lead authority, so the Garante lacked competence. The substantive findings were not endorsed; the corrective orders and campaign had already been carried out.

What this means for you

Regulators treat training data as personal data: you need a legal basis, a privacy notice covering training, age controls and breach reporting. Procedural wins on jurisdiction (as here) do not mean the practices were approved. Document your legal basis and DPIA before shipping generative features to EU users.

Laws involved

Sources

Last reviewed Sep 25, 2026.

Educational information, not legal advice. Laws change and details depend on your situation — check the linked sources and talk to a qualified lawyer before acting. Last content review: 2026-09-25.

Spotted an error? Ask the tutor or email hello@myaiguide.pro.