The Italian Garante vs OpenAI: €15 million to map the perimeter of consumer AI
5 min read
Just over a year ago, on 20 December 2024, the Garante (Italy’s data protection authority) closed its investigation into ChatGPT with a €15 million fine against OpenAI. This was no bolt from the blue: it was the administrative epilogue of a tug-of-war that began in March 2023, when the Italian authority had blocked the service — the first case of its kind worldwide — over the unlawful collection of personal data. OpenAI called the fine “disproportionate” and appealed it; in March 2025 the Rome Tribunal suspended the fine on a precautionary basis, and the ruling on the merits is still pending. Waiting for the verdict to draw conclusions is the wrong perspective: for businesses, the lesson is already written into the case file, and it concerns the legal perimeter within which every consumer AI service used at work operates.
The facts, in order
- 30 March 2023: the Garante orders a provisional limitation on the processing of Italian users’ data. The complaints: no adequate privacy notice, no legal basis for the massive collection of data used for training, no age verification, and a data breach on 20 March (conversations and payment data exposed). OpenAI suspends ChatGPT in Italy.
- Late April 2023: the service becomes available again after the introduction of the required measures — clearer privacy notices, age checks, tools to object to the use of one’s own data.
- 20 December 2024: the investigation closes and the €15 million fine arrives. Four findings: processing of data to train ChatGPT without an adequate legal basis, breach of transparency obligations, failure to notify the 2023 breach, and absence of age verification mechanisms. On top of that, an unprecedented measure: the obligation to run a six-month public information campaign across radio, TV, newspapers and the internet on how the service works and on data subjects’ rights.
- OpenAI’s response: the decision is “disproportionate” — nearly twenty times the revenue generated in Italy over the period — and will be appealed; the company maintains it cooperated with the authority after the 2023 block.
- What followed: since OpenAI established its European headquarters in Ireland during the investigation, the Garante forwarded the case file to the Irish authority, lead authority under the “one-stop-shop” mechanism. On 21 March 2025 the Rome Tribunal suspended the fine pending the ruling on the merits.
The court will decide who is right on proportionality. But the four findings describe precisely where the boundary lies that every business using these tools needs to know.
Lesson no. 1: “consumer” does not mean “outside the GDPR” — it means the risk is yours
When an employee pastes a customer’s personal details or a medical report into a consumer AI service, the company remains the data controller: compliance does not transfer to the vendor along with the prompt. And the Italian case shows that even the legal basis on which a vendor trains its models can be challenged by the authority. Banning everything does not work — shadow use simply continues, unchecked. What works is governance: mapping which tools are actually in use, distinguishing consumer versions from business versions, and defining what can and cannot go into a prompt. This is the work of compliance by design that separates adoption from exposure.
Lesson no. 2: the contract is the perimeter — and it must be read first
The Garante’s findings amount to a contractual checklist in reverse. Uncertain legal basis for training? The contract must specify whether your data feeds the vendor’s models and how this can be excluded. Failure to notify a breach? You need clauses obliging the vendor to notify you within a timeframe compatible with your own 72 hours to the authority. Inadequate privacy notice? It must be clear who is controller, who is processor under Article 28, where the data resides, and which sub-processors touch it. Consumer terms, by their very design, offer almost none of this: anyone bringing AI into operational processes must demand enterprise terms, with a signed and verifiable DPA.
Lesson no. 3: the vendor’s registered office and jurisdiction matter too
One procedural detail of the case is worth more than many conferences: during the investigation, OpenAI established its European headquarters in Ireland, and jurisdiction over subsequent violations passed to the Irish authority. Legitimate. But for buyers it means that oversight of your vendor can change country during the course of the relationship, with different timelines and different sensitivities. Knowing where your vendor is headquartered, where the data resides and which authority has oversight is not bureaucracy: it is part of the sovereignty assessment that should be carried out before signing, just as with any critical infrastructure.
What to do if consumer AI has already entered your organisation
- Map actual use: which AI tools people use, with what data, on which accounts.
- Migrate to business/enterprise plans where available: DPA, exclusion from training, logs and controls.
- Check four clauses: use of data for training, location and retention, breach notification, sub-processors.
- Write a short, enforceable usage policy: what can go into a prompt, what never can, who authorises exceptions.
- Assess the need for a DPIA whenever processing touches customer data, employee data, or special categories of data.
Want a map of your AI perimeter — tools, data, contracts — before an authority draws it for you? Half an hour with one of our experts for an initial assessment.
Sources
- Garante privacy — press release: ChatGPT, investigation closed. €15 million fine and information campaign (20 December 2024)
- Euronews — Italy’s privacy watchdog fines OpenAI €15 million after probe into ChatGPT data collection
- Federprivacy — The Rome Tribunal suspends the €15 million fine imposed by the Garante on OpenAI