EU Regulation 2016/679 - Decision Register

DECISION OF THE GARANTE / PROVV. 755 / 2 NOVEMBER 2024

OpenAI €15 Million Garante Fine (2024), Annulled by the Court of Rome

Italy's data protection authority fined OpenAI €15 million over ChatGPT for training on personal data without a legal basis, transparency and age-verification failures, and an unnotified 2023 breach. On 18 March 2026 the Court of Rome annulled the fine on one-stop-shop jurisdiction grounds.

Fine amount

€15,000,000

Issuing DPA

Italian Garante

Decision date

2 November 2024

Status

Annulled (Rome, Mar 2026)

Grounds

Legal basis, transparency, breach

EDUCATIONAL ONLY

This page is a reference summary of a published regulator decision. It is not legal advice. Consult a qualified data protection lawyer for advice on your specific situation. The UK GDPR is a separate regime from the EU GDPR following Brexit. Always read the source decision in full before relying on any figure or quote.

DECISION SUMMARY

What happened

On 2 November 2024 the Italian Garante per la Protezione dei Dati Personali adopted decision no. 755, imposing a €15 million administrative fine on OpenAI over its ChatGPT service; the authority announced the sanction publicly in December 2024. Alongside the fine, the Garante ordered OpenAI to run a six-month information campaign across Italian radio, television, newspapers and the internet, explaining how the company collects and uses personal data to train its models. OpenAI described the decision as disproportionate and lodged an appeal.

The fine concluded an investigation that had begun with the Garante's emergency action of 30 March 2023, when the authority ordered OpenAI to suspend processing of Italian users' personal data on ChatGPT. Service was restored on 28 April 2023 after OpenAI added an age-declaration step, expanded its privacy notice and provided a mechanism for data-subject requests, but the formal inquiry continued through 2023 and 2024 and produced the €15 million sanction.

What the Garante found

The decision rested on four grounds. First, a lawful-basis failure: OpenAI had processed personal data to train ChatGPT without an adequate Article 6 basis, the same core objection the Garante had raised in 2023. Second, a transparency failure: users and the individuals whose data appeared in the training corpus were not given the information the GDPR requires under Articles 5(1)(a), 12, 13 and 14. Third, an age-verification failure: ChatGPT lacked an effective mechanism to keep children under 13 off the service, exposing minors to content unsuitable for their age. Fourth, a breach-notification failure under Article 33: OpenAI had not notified the Garante of a March 2023 incident in which a bug briefly exposed payment-related information for a small percentage of ChatGPT Plus subscribers.

The €15 million figure sat well below the GDPR's upper-tier ceiling (the greater of €20 million or 4% of worldwide annual turnover). The Garante's reasoning emphasised the corrective element, particularly the unusual public-awareness campaign, over the headline monetary penalty.

The Court of Rome annulment (March 2026)

On 18 March 2026 the Court of Rome (Tribunale Ordinario di Roma, Sezione Diritti della Persona e Immigrazione, case R.G. 4785/2025) annulled both the €15 million fine and the media-campaign order. The court decided the case on jurisdiction rather than substance. Because OpenAI had established OpenAI Ireland Limited in February 2024, the GDPR's one-stop-shop mechanism made the Irish Data Protection Commission the lead supervisory authority for OpenAI's cross-border processing. On that reading, the Garante could no longer impose a stand-alone national sanction of this kind, and the decision fell away.

Crucially, the judgment did not rule on whether OpenAI had in fact breached the GDPR. The substantive questions about training on scraped personal data, transparency and age verification were left open. Following the ruling, the Garante removed the original decision from its website. The Garante retains the option of pursuing the matter through other channels, and the underlying questions could be revisited by the Irish DPC as lead authority; but the €15 million penalty itself is no longer a collectible fine.

Why this case matters

The OpenAI decision was, for a time, the most significant GDPR enforcement action against a generative-AI provider anywhere in Europe. Its annulment is just as significant, because the ground was structural rather than factual. The Court of Rome's reasoning shows how a provider that opens an EU establishment mid-investigation can shift the lead-authority question under the one-stop-shop, complicating enforcement by the national DPA that started the case. For the wider debate about AI and data protection, the episode leaves the hard substantive questions unresolved while illustrating that jurisdiction, not just the merits, decides who may fine whom.

For readers tracking the numbers, this is why the register treats the €15 million figure as a fine that was imposed and then set aside, rather than as a standing penalty. The Garante's largest fine that still stands is the €20 million Clearview AI decision of 2022.

FREQUENTLY ASKED

About the OpenAI €15 million Italian fine

How much was OpenAI fined and when?
The Italian Garante adopted decision no. 755 on 2 November 2024 and announced it publicly in December 2024, imposing a €15 million administrative fine on OpenAI over the ChatGPT service. The Garante also ordered OpenAI to run a six-month information campaign across Italian radio, television, newspapers and the internet explaining how it uses personal data to train its models. The fine no longer stands: the Court of Rome annulled it on 18 March 2026.
What did the Garante say OpenAI did wrong?
The decision identified four grounds. First, OpenAI processed personal data to train ChatGPT without an adequate legal basis. Second, it breached the transparency and information obligations owed to users and to the individuals whose data appeared in the training corpus. Third, it lacked an effective age-verification mechanism, risking the exposure of children under 13 to content unsuitable for their age. Fourth, it failed to notify the Garante of a data breach in March 2023 that exposed payment information for a small percentage of ChatGPT Plus subscribers. These grounds correspond to the GDPR's lawful-basis (Article 6), transparency (Articles 5(1)(a), 12, 13, 14) and breach-notification (Article 33) provisions.
Why was the €15 million fine annulled?
On 18 March 2026 the Court of Rome (Tribunale Ordinario di Roma, Sezione Diritti della Persona e Immigrazione, case R.G. 4785/2025) annulled both the €15 million fine and the media-campaign order. It decided the case on jurisdiction rather than substance: because OpenAI had established OpenAI Ireland Limited in February 2024, the GDPR's one-stop-shop mechanism made the Irish Data Protection Commission the lead supervisory authority. On that reading the Garante lacked competence to impose a stand-alone national sanction. The judgment did not rule on whether OpenAI had in fact breached the GDPR.
Does the annulment mean OpenAI did nothing wrong?
No. The Court of Rome annulled the fine on a procedural, jurisdictional ground and expressly did not reach the substantive questions about ChatGPT's training data, transparency or age verification. Those questions remain open and could be revisited by the Irish DPC as lead authority under the one-stop-shop, or in other Member States. The annulment removes this particular penalty; it does not resolve whether generative-AI training on scraped personal data satisfies Articles 5 and 6.
What was the March 2023 ChatGPT breach?
In March 2023 a bug in an open-source library briefly exposed some ChatGPT Plus subscribers' payment-related information and other users' conversation titles. OpenAI disclosed the incident publicly but did not notify the Italian Garante, and that omission formed part of the later fine as a breach-notification failure. The same period saw the Garante's 30 March 2023 emergency order temporarily suspending ChatGPT in Italy; service was restored on 28 April 2023 after OpenAI implemented remediations.
Is this the same as the 2023 ChatGPT ban?
No, but they are connected. The 30 March 2023 measure was an urgent provisional suspension under Article 58(2)(f) GDPR, lifted on 28 April 2023 once OpenAI made changes to its signup flow, privacy notice and data-subject request handling. The €15 million fine was the separate, formal sanction concluding the investigation that the provisional measure opened. The fine, not the 2023 suspension, is what the Court of Rome annulled in 2026.

CROSS-REFERENCES

Related entries on this register

SUPERVISORY AUTHORITY

Italian Garante Profile

Europe's most-active DPA on AI/biometric cases. ChatGPT, Replika, Clearview and more.

Open reference →

RELATED CASE

Clearview AI €20M (Garante 2022)

The Garante's largest standing fine and its other landmark AI decision.

Open reference →

ARTICLE 5

Article 5 GDPR Fines

Transparency and minimisation principles central to the ChatGPT analysis.

Open reference →

SUPERVISORY AUTHORITY

Irish DPC Profile

The lead authority for OpenAI's EU processing after its Irish establishment.

Open reference →

APPEALS

How GDPR Fines Are Challenged

Article 78 appeals and the annulments and reductions they produce.

Open reference →

REGISTER

Full Decision Register

Every major indexed GDPR fine.

Open reference →

SOURCES & CITATIONS

Primary sources

Figures as of July 2026. Verified against published DPA decisions.

REGISTER UPDATED 2026-04-28