EU Regulation 2016/679 - Decision Register

SUPERVISORY AUTHORITY PROFILE / ITALIAN GARANTE

Italian Garante GDPR Fines, Enforcement Record & AI Cases

Europe's most AI-and-biometric forward DPA. The Garante's ChatGPT temporary block, Replika ban, and Clearview €20M fine made it the regulator most willing to confront generative AI and facial recognition head-on.

Cumulative fines

~€200M+

Largest fine

€20M (Clearview)

AI/biometric cases

10+ since 2022

ChatGPT block

Mar-Apr 2023

Active since

1997

EDUCATIONAL ONLY

This page is a reference summary of a published regulator decision. It is not legal advice. Consult a qualified data protection lawyer for advice on your specific situation. The UK GDPR is a separate regime from the EU GDPR following Brexit. Always read the source decision in full before relying on any figure or quote.

PROFILE

Mandate and constitution

The Garante per la Protezione dei Dati Personali was established by the Codice della Privacy (Legislative Decree 196/2003) and operates under that statute as amended by Legislative Decree 101/2018 to give effect to the GDPR. The Garante is an independent administrative authority headquartered in Rome, with statutory independence from the executive branch and reporting obligations to the Italian Parliament.

Governance is collegial: a four-member College, of which one acts as President, adopts decisions and sanctions. Members are appointed by Parliament for a seven-year non-renewable term, with the chamber of deputies and the senate each appointing two members. The collegial structure means major decisions reflect consensus among the four College members rather than a single Commissioner's discretion, which has been credited with the Garante's willingness to take aggressive provisional measures on novel issues like generative AI.

Fining philosophy

The Garante's defining characteristic is its willingness to act first on emerging technology areas. It was the first EU DPA to take formal action against a generative-AI provider (ChatGPT, March 2023), the first to ban a generative-AI chatbot for absence of age verification (Replika, February 2023), and the first of the parallel EU Clearview decisions (February 2022). The Garante's provisional measures under Article 58(2)(f) GDPR (temporary processing suspensions) are used more readily than by most other DPAs, on the rationale that urgent measures are appropriate where ongoing processing presents fundamental- rights risks that cannot wait for a full investigation.

Fine sizes are typically in the low-millions range, with the €20M Clearview fine and the €15M OpenAI fine as the high-end outliers (the OpenAI fine was later annulled on appeal, leaving Clearview as the standing high-water mark). The Garante's jurisprudence emphasises specific corrective orders (cease processing, delete data, implement specific controls) alongside fines, on the view that the corrective action is the operationally important outcome.

The ChatGPT case in detail

On 30 March 2023, the Garante adopted Provvedimento 9870832, an urgent provisional measure under Article 58(2)(f) GDPR ordering OpenAI L.L.C. to suspend processing of personal data of users in Italy on the ChatGPT service. The measure cited four substantive concerns. First, the absence of an age-verification mechanism notwithstanding ChatGPT's terms requiring users to be 13 or older. Second, the absence of a documented lawful basis under Article 6 for processing personal data in the training corpus, particularly where the corpus included personal data of European individuals scraped from publicly accessible sources. Third, the absence of adequate transparency to data subjects under Articles 13 and 14, particularly for individuals whose data appeared in training without their knowledge. Fourth, the absence of any mechanism for data subjects to exercise their Article 15-22 rights in relation to model outputs referencing them.

OpenAI restored service on 28 April 2023 after implementing requested remediations: an age-verification step in the signup flow, an expanded privacy notice describing the use of personal data in training, a contact form for data-subject requests, and a public-facing description of the lawful basis claimed for training processing (legitimate interests under Article 6(1)(f), with documented balancing). The formal investigation continued throughout 2023 and 2024, and on 20 December 2024 the Garante adopted Provvedimento 9978020 imposing a €15 million fine on OpenAI for the original substantive infringements plus a separate procedural sanction for failure to notify a data breach (involving exposure of payment information for a small percentage of ChatGPT Plus subscribers in March 2023). The decision also ordered OpenAI to run a six-month information campaign across Italian media explaining how it uses personal data to train its models.

On 18 March 2026 the Court of Rome (Tribunale Ordinario di Roma, case R.G. 4785/2025) annulled the €15 million fine and the media-campaign order. The court decided the case on jurisdiction rather than substance: because OpenAI had established OpenAI Ireland Limited in February 2024, the one-stop-shop mechanism made the Irish Data Protection Commission the lead supervisory authority, so the Garante lacked competence to issue a stand-alone national sanction. The judgment did not rule on whether OpenAI had in fact breached the GDPR, and the Garante removed the original decision from its website following the ruling. The outcome leaves the substantive questions about generative-AI training and Article 5/6 open, and the €15M fine no longer stands as a collectible penalty. See the full OpenAI €15M case breakdown for the decision and annulment in detail.

Other notable decisions

Replika (Provvedimento 9852214, February 2023): the Garante ordered Luka Inc to cease processing personal data of Italian users on the Replika chatbot service, citing the absence of age-verification, the absence of lawful basis for child processing, the inadequacy of the privacy notice, and the affective-companion design that posed risks to minors. The decision was the first EU DPA action against a consumer-facing generative-AI chatbot.

Clearview AI (Provvedimento 9751362, February 2022): the Garante imposed a €20 million fine on Clearview AI Inc, ordered deletion of data relating to Italian residents, prohibited further processing of biometric data of Italian residents, and required the designation of an EU representative under Article 27. The decision applied Article 3 extraterritoriality to a US-only company on the basis that scraping and indexing facial images of Italian residents constitutes monitoring of behaviour within the EU.

Other significant Garante decisions include Enel Energia (€26.5M, 2022) for telemarketing-related infringements; Tim S.p.A. (€27.8M, 2020) for telemarketing and consent failures; Foodinho (€2.6M, 2021) for algorithmic management of delivery riders without adequate transparency or worker-rights protections; and a sequence of decisions on health-data processing in the Italian regional health systems addressing security and lawful-basis questions.

AI Act intersection

With the entry into force of the EU AI Act (Regulation (EU) 2024/1689) in 2024 and phased application through 2027, the Garante's AI-specialism positions it as a likely national competent authority for AI Act enforcement in Italy. The Garante has issued public guidance on the AI Act × GDPR intersection, addressing how Article 25 by-design obligations interact with the high-risk-AI requirements of the AI Act, and how the prohibition on certain AI practices (Article 5 AI Act) overlaps with existing Article 9 GDPR prohibitions on biometric processing.

FREQUENTLY ASKED

About the Italian Garante

Why did the Garante block ChatGPT?
On 30 March 2023, the Garante issued an urgent provisional measure ordering OpenAI to suspend processing of personal data of Italian users on ChatGPT, citing the absence of an age-verification system for under-13 users, the absence of a lawful basis for training-data processing, the lack of transparency to data subjects about the use of their personal data in training, and the lack of any mechanism for data subjects to exercise their rights. Service was restored on 28 April 2023 after OpenAI implemented requested remediations, but a formal investigation continued and culminated in a €15 million fine adopted on 2 November 2024 and announced in December 2024. The Court of Rome annulled that fine on 18 March 2026 on jurisdictional grounds (see below), so it no longer stands.
What is the difference between the ChatGPT block and the OpenAI fine?
The March 2023 block was an urgent provisional measure under Article 58(2)(f) GDPR pending investigation. The €15 million fine (adopted 2 November 2024, announced December 2024) was the formal sanction following the conclusion of the investigation, covering the absence of a legal basis for training-data processing, transparency failures, the lack of age verification for minors, and the failure to notify a March 2023 data breach. The Court of Rome subsequently annulled that fine on 18 March 2026, holding that OpenAI's February 2024 Irish establishment had made the Irish DPC the lead authority under the one-stop-shop, without ruling on the substance of the alleged infringements.
What other AI cases has the Garante led?
Replika (the chatbot companion service) was ordered to suspend processing of Italian user data in February 2023, on similar grounds to ChatGPT (no age verification, no lawful basis for child users, inadequate transparency). Clearview AI was fined €20 million in February 2022, the earliest of the parallel EU Clearview decisions. Several enforcement actions against generative-AI providers have followed in 2024-2026.
Who heads the Garante?
The Garante is led by a four-member College, of which one acts as President. The College is appointed by the Italian Parliament for a seven-year non-renewable term. As of 2026, the College structure means decisions issue from the collegiate body rather than from a single Commissioner, which produces more collegial reasoning than the single-Commissioner models in other Member States.
Does the Garante focus only on AI?
No. The Garante has a substantial workload across all GDPR domains, including healthcare-data processing (where Italy has particularly active national rules layered over GDPR), employment data, telecom, public sector and education. AI and biometrics are a notable specialism, but not the only one.
Is the Garante influential in EDPB work?
Yes. The Garante is one of the most actively-participating concerned authorities in cross-border inquiries, regularly raising reasoned objections to lead-authority drafts. The Garante's reasoned objection contributed materially to the EDPB Article 65 binding decisions in WhatsApp, Instagram, TikTok and Meta Chapter V, each of which raised the Irish DPC's draft fine substantially.

CROSS-REFERENCES

Cases led by the Garante

GARANTE CASE

Clearview €20M (2022)

The leading extraterritorial GDPR application decision against a US-only facial-recognition firm.

Open reference →

GARANTE CASE

OpenAI €15M (2024, annulled)

The ChatGPT fine, annulled by the Court of Rome in March 2026 on one-stop-shop jurisdiction grounds.

Open reference →

ARTICLES 44-49

International Transfer Enforcement

Schrems II framework that informs Garante's transfer analysis.

Open reference →

PEER DPA

French CNIL

The other ad-tech and AI-active DPA. Parallel Clearview decisions.

Open reference →

PEER DPA

Irish DPC

The Garante is a frequent concerned-authority objector in DPC inquiries.

Open reference →

ARTICLE 5

Article 5 Enforcement

Data-minimisation principles central to the ChatGPT and Replika analyses.

Open reference →

REGISTER

Full Decision Register

All major indexed fines including Garante decisions.

Open reference →

SOURCES & CITATIONS

Primary sources

Figures as of July 2026. Verified against published DPA decisions.

REGISTER UPDATED 2026-04-28