Italy Garante v. OpenAI: €15M Fine for ChatGPT GDPR Violations
Summary
Following its 2023 temporary ban, Italy's Garante concluded its ChatGPT investigation and found OpenAI processed personal data to train ChatGPT without an adequate legal basis, breached transparency obligations, lacked sufficient age verification, and failed to notify the authority of its March 2023 data breach.
Details
- Violation: GDPR violations — unlawful data processing, transparency, age verification, breach notification
- Penalty: €15 million fine
- Framework: GDPR (Articles 5, 6, 8, 13, 14, 33, 34)
- Status: Fine issued December 2024; OpenAI appealing
Key Takeaways
- AI training data collection requires a valid GDPR legal basis
- Transparency obligations apply to AI model training
- Age verification is required for AI services accessible to minors
- Data breaches in AI training must be reported to authorities
Additional Requirements
OpenAI was ordered to run a six-month public-awareness campaign in Italian media explaining how it collects personal data and users' GDPR rights. OpenAI called the fine disproportionate and said it would appeal.
Related Enforcement Actions
Italy Garante v. Replika: €5M Fine for AI Companion Chatbot Privacy Violations
Luka Inc. (Replika) · EUR 5,000,000 · Feb 15, 2025
Ireland DPC v. X Corp: First EU Halt of AI Training Data Use
X Corp. (Grok AI) · EUR 0 · Aug 8, 2024
Netherlands DPA v. Clearview AI: €30.5M Fine for Illegal Biometric Database
Clearview AI · EUR 30,500,000 · May 16, 2024