Italian DPA ChatGPT Suspension and GDPR Enforcement Analysis
Italy's ChatGPT case shows where GDPR and AI training remain legally unsettled.

The Italian data protection authority's case against OpenAI runs from an emergency suspension in March 2023, through a substantial fine in December 2024, to a court annulment in 2026 that vacated the penalty without ever touching the underlying question of whether training a large language model on personal data without consent is lawful. Each stage resolved a narrower question than the one before it, and the arc as a whole shows exactly where GDPR and generative AI training remain unsettled, no matter which regulator holds the file.
What the Garante Did in March 2023
The Garante per la Protezione dei Dati Personali did not fine OpenAI on March 30, 2023, and it did not find the company guilty of anything in a formal legal sense. It issued a provisional restriction under Article 58(2)(f) of the GDPR, a power that most data protection authorities use sparingly because it allows them to order an immediate halt to processing before a full investigation has concluded. The Garante used that power to force OpenAI to disclose structural gaps in how ChatGPT handled personal data, and the order, Provvedimento 9870832, named four of them explicitly.
OpenAI had no documented lawful basis under Article 6 of the GDPR for processing personal data inside ChatGPT's training corpus, a corpus that included data scraped from public sources without the knowledge of the European individuals it described. The company also failed to provide adequate transparency to data subjects under Articles 13 and 14, leaving people whose information appeared in the training data with no clear notice that it had been used. There was no functioning mechanism for those individuals to exercise their data-subject rights where a model's outputs referenced them, and there was no effective age-verification system despite ChatGPT's own terms requiring users to be at least 13 years old.
A fifth factor hardened the Garante's resolve to act. The Garante was the first EU data protection authority to take formal action against a generative-AI provider, and it did so against a backdrop of its own prior willingness to move early: it had already taken the first EU action against a consumer-facing AI chatbot, Replika, in February 2023, and had issued one of the first Clearview AI decisions in February 2022.
OpenAI's rapid compliance after the ban
OpenAI restored ChatGPT service in Italy on April 28, 2023, roughly a month after the suspension began, and the speed of that turnaround demonstrated something important about regulatory pressure: a ban backed by no fine at all can still force rapid, concrete change in how a product operates. OpenAI added an age-verification step to its signup flow, expanded its privacy notice to describe how personal data gets used in training, and built a contact form through which data subjects could submit requests. It also published a claimed lawful basis for its processing: legitimate interests under Article 6(1)(f), supported by a documented balancing test.
Those changes answered the Garante's procedural demands, but they left the central legal question untouched. The Garante later found that both of the documents meant to establish that basis arrived long after the fact: the Data Protection Impact Assessment was produced May 19, 2023, and the Legitimate Interests Assessment was produced November 20, 2023, and only because the Garante had expressly demanded it.
That sequencing mattered because the GDPR's accountability principle requires a controller to identify its lawful basis before processing begins, not to construct one after a regulator has already intervened. The 2023 fix solved "how are you handling this now." It left "did you ever have the right to do this" completely open, and that open question is what kept the formal investigation alive well after the ban had lifted.
What the Garante's December 2024 Fine Found
The Garante adopted Decision No. 755 on November 2, 2024, and announced it publicly on December 20, 2024. The decision found that OpenAI had processed personal data for training without an adequate legal basis, with the violation dated from at least November 30, 2022, the day ChatGPT launched. It found a failure to fulfil transparency obligations to users, a failure to implement adequate age verification, and, layered on top of the substantive findings, a separate procedural failure to notify the March 2023 data breach as Article 33 requires.
The fine was not the only instrument the Garante reached for. For the first time, it exercised its power under Article 166(7) of the Italian Data Protection Code to order a corrective measure with a public dimension: a six-month awareness campaign, run across radio, television, print, and online media, explaining to the Italian public how OpenAI uses personal data to train its models. When the Court of Rome later annulled the decision, it annulled the campaign order along with it, which is part of why the annulment matters as much as the original fine did.
The Court of Rome's jurisdictional annulment
The Court of Rome's ruling, issued March 18, 2026, is the hinge of the entire arc, and the first thing to understand about it is what it did not do. The court did not find that OpenAI's data practices were lawful. It did not reexamine the Garante's conclusions about missing legal basis, inadequate transparency, absent age verification, or the unreported breach. It annulled the fine on jurisdictional grounds alone, on the theory that once OpenAI had established a formal presence in Ireland, in February 2024, competence over the company's conduct under the GDPR's one-stop-shop mechanism shifted to the lead supervisory authority in that country, leaving the Garante without standing to issue a national fine.
That distinction deserves to be held onto through everything that follows. A jurisdictional annulment is not an acquittal. The full reasoning behind the Court of Rome's decision has not been published in complete form. Stronger characterizations of the ruling circulating elsewhere should be read with some caution. What is clear is narrower than what some accounts suggest: a court decided who could enforce, not what should have been enforced.
The enforcement vacuum the annulment created
The annulment does not hand the case cleanly to another national data protection authority. The realistic outcome is a negative conflict: the Garante has been shut out of a case it built over nearly three years, and it is far from certain that the lead supervisory authority in Ireland has jurisdiction over conduct that predates OpenAI Ireland's establishment in February 2024. If neither authority can act on the pre-establishment conduct, the violations the Garante documented, reaching back to November 2022, are left in a jurisdictional no-man's-land.
Scholarly analysis of the ruling has pointed to something more troubling than a one-off gap: a replicable sequence. Conduct that occurred and ended before an EU establishment existed does not fit neatly into that framework or any other.
There is a reasonable objection to calling this a gap. The one-stop-shop mechanism was built specifically to stop fragmented national enforcement across 27 member states, and the Court of Rome did nothing more than apply the GDPR as written. That objection has real force, but it runs into a timing problem the mechanism's own design does not anticipate. The one-stop-shop was built for providers that establish in the EU before or at the start of their operations, not for a company that operates for years under direct national scrutiny and only establishes an EU presence after enforcement is already underway. That sequencing is what makes this a structural gap rather than an isolated inconvenience, and it is the strongest reason to treat the Rome ruling as something more than the system working as intended.
Ireland's track record as a lead supervisory authority gives the concern added weight. In January 2025, the EU General Court ruled that the Irish DPC had acted unlawfully by refusing to investigate a complaint about Meta's data practices, a complaint filed on the very first day the GDPR came into force. Against that backdrop, treating Ireland as the obvious next venue for the ChatGPT questions assumes a capacity and willingness that the DPC's own history does not clearly support.
What enforcement without a collectible fine achieves and where it stops
It would be a mistake to read the Rome annulment as proof that regulatory pressure without a surviving fine accomplishes nothing. The record says otherwise, though its reach has real limits. Regulatory compulsion that never produces a collectible penalty has demonstrably changed how AI companies operate inside Europe, and its leverage tracks a specific condition: whether the company in question actually values access to the EU market.
The ChatGPT case is itself the clearest evidence that non-fine enforcement works. A similar pattern played out with Meta. Following sustained engagement with the Irish DPC in June 2024, Meta paused its plans to train large language models on public content pulled from Facebook and Instagram across the EU and EEA. When training resumed in May 2025, it resumed under materially different conditions: enhanced transparency notices, improved objection mechanisms, and added technical safeguards that bore little resemblance to the original proposal.
DeepSeek shows what happens when that leverage disappears. On January 30, 2025, the Garante announced an immediate ban on accessing DeepSeek within Italy after the company's response to a data-practices inquiry was judged "totally insufficient," and after DeepSeek had asserted that EU law simply did not apply to it. The company was removed from Italian Apple and Google app stores. The violations behind that ban were substantial: a privacy policy available only in English, no specified legal basis under Article 6, data stored in China in violation of Article 44's transfer restrictions, and no EU representative appointed as Article 27 requires. DeepSeek did not appoint an EU representative until May 28, 2025, four months after the Italian ban took effect, and only after the Greek Hellenic Data Protection Authority issued an interim ruling ordering the company to designate one.
DeepSeek has no EU establishment. The jurisdictional escape route that worked for OpenAI is not available to it. Every member-state DPA retains jurisdiction over its conduct. But that legal advantage for regulators runs into a practical wall: the Italian ban remains in force, and DeepSeek continues operating globally regardless. Exclusion from the Italian market constrains only a company that prioritizes EU access in the first place, and DeepSeek's conduct suggests it has been willing to absorb that exclusion instead. Enforcement without fines reshapes the behavior of companies that want to stay in the European market and excludes the ones that do not, but in neither case does it resolve the underlying legal question of whether training data processing was lawful to begin with.
The unresolved legal questions that survive every enforcement outcome
The Court of Rome's annulment left every substantive GDPR question about generative AI training exactly where the Garante found it: unanswered. Lawful basis, transparency obligations, and data-subject rights at the moment of training all remain open questions at the level of binding enforcement. Every organization that deploys or uses these tools on European personal data has to work out its own answers.
Several of those questions sit squarely unresolved. It remains unclear whether legitimate interests under Article 6(1)(f) can ever justify large-scale training on scraped personal data, given that the basis requires balancing against data subjects' reasonable expectations and given that the EU's top court has already rejected legitimate interests as a basis for Meta's behavioral advertising in a closely watched prior ruling. Nobody has solved the technical problem of how a data subject's objection right can be honored once their data is already embedded in a model's trained weights. And whether the GDPR applies at the training stage, the inference stage, or both remains formally untested by any final court judgment, even though the view that it applies to training is widely shared among European data protection authorities.
The EU's data protection coordinating body has added one more layer that deserves attention from anyone building on top of these models. Subsequent EDPB guidance made clear that organizations using ChatGPT for their own purposes carry a separate obligation: they must document their own lawful basis for every category of prompt they send through the system, independent of whatever basis OpenAI claims for its training data. These are two distinct compliance obligations, and meeting one says nothing about the other. Any organization deploying generative AI on European personal data cannot wait for enforcement to settle the underlying law. It needs a documented lawful basis for its own inference-time processing now, and it should not assume that a provider's claimed training-data basis extends to cover its own use of the tool.
One structural answer to the transparency and data-subject-rights gaps the Garante identified in 2023 does not depend on winning an argument about legitimate interests or waiting for a court to rule on Article 6. It is architectural: systems built so that user data never feeds back into training at all remove the category of risk the Garante spent three years investigating, rather than defending against it complaint by complaint. That is a design decision, not a compliance notice, and it is the kind of answer that does not depend on which regulator holds jurisdiction in a given year.
The Garante's enforcement arc against OpenAI is complete. The fine is gone, annulled on a jurisdictional technicality that said nothing about whether the underlying conduct was lawful. What is left behind is a set of questions about training data, consent, and data-subject rights that are more pressing now than when the Garante first raised them in March 2023, precisely because they no longer have a single pending enforcement decision to anchor them.


