The Garante's ChatGPT order: launch before a lawful basis

Italy's data protection authority temporarily limited ChatGPT in 2023 over lawful basis, transparency and age checks, then fined its provider EUR 15 million in 2024.

Year
2023
Jurisdiction
Italy (EU)
Sector
Generative AI: consumer chatbot
Evidence base
Primary sources
Incident record
AIID 513
Harm
Regulatory enforcement and forced suspension · Privacy intrusion and biometric surveillance

What happened

On 30 Mar 2023 the Italian data protection authority (Garante) ordered an immediate temporary limitation of the processing of Italian users' data by OpenAI 1. Its press release of 31 Mar noted that a data breach affecting users' conversations and subscribers' payment information had been reported on 20 Mar, and cited the absence of a legal basis for the mass collection and storage of personal data to train the algorithms 2.

On 20 Dec 2024 the Garante announced a EUR 15 million fine and a six-month information campaign on radio, television, newspapers and the internet. It found that the company had not notified the authority of the data breach of March 2023, had processed users' personal data to train ChatGPT without first identifying an adequate legal basis, had breached the transparency principle and the related information duties, and had provided no age-verification mechanism, exposing children under 13 to unsuitable answers 3. The AI Incident Database records the 2023 order 4.

Failure mode

The lawful basis, the transparency notice and the age check were not release preconditions. A service reached the public, and personal data reached training, before the first questions a regulator asks had documented answers.

The breach path failed separately: a personal-data breach must be notified to the authority on a deadline, and the Garante found that this notification had not been made 3.

Which control would have caught it

A policy card that makes three things release blockers (a recorded lawful basis for each training-data source, a published notice, and age assurance at entry) moves the regulator's checklist into the pipeline. The DPIA and fundamental-rights assessment, kept as code, carry the reasoning; an AIBOM ties each training dataset to its basis; a runtime guardrail enforces the age gate. The incident pipeline puts breach notification on the clock.

Patterns: Policy Card · FRIA-as-Code · AIBOM · Runtime Guardrail · Incident Pipeline

The evidence that would have existed

What an auditor could have read, and the stack layer that produces it.

  • L1 Policy card with the three release blockers and the CI check that enforced them
  • L1 DPIA recording the lawful basis for each processing purpose, training included
  • L2 AIBOM listing training-data sources with their lawful basis
  • L4 Age-assurance logs at sign-up
  • L5 Incident record for the breach: detection time, notification decision and the timestamp of the notice sent

Obligations it touches today

As of 2026-09-24. Mappings are illustrative, not a claim of conformity.

  • GDPR Art. 5(1)(a), 6, 8, 12-13, 33 Lawfulness and transparency, the legal basis for training, the conditions for a child's consent, the information duties and breach notification: the provisions behind both Garante decisions 35.
  • EU AI Act Art. 53(1)(d) Providers of general-purpose AI models publish a sufficiently detailed summary of the content used for training 6; these obligations apply since 2 Aug 2025, with Commission enforcement powers from 2 Aug 2026 (as of 2026-09-24) 7.

Sources

  1. [1] Provvedimento del 30 marzo 2023 [doc. web n. 9870832] (urgent temporary limitation of processing of data of users in Italy). Garante per la protezione dei dati personali. 2023-03-30. https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9870832 (verified: primary)
  2. [2] Artificial intelligence: stop to ChatGPT by the Italian SA [doc. web n. 9870847] (press release; data breach reported on 20 Mar; no legal basis for training data). Garante per la protezione dei dati personali. 2023-03-31. https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9870847 (verified: primary)
  3. [3] ChatGPT, il Garante privacy chiude l'istruttoria. OpenAI dovrà realizzare una campagna informativa di sei mesi e pagare una sanzione di 15 milioni di euro [doc. web n. 10085432] (press release on the EUR 15 million fine). Garante per la protezione dei dati personali. 2024-12-20. https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10085432 (verified: primary)
  4. [4] AI Incident Database, Incident 513: ChatGPT Reportedly Banned by Italian Authority Due to OpenAI's Purported Lack of Legal Basis for Data Collection and Age Verification. Responsible AI Collaborative. 2026. https://incidentdatabase.ai/cite/513/ (verified: primary)
  5. [5] Regulation (EU) 2016/679 (General Data Protection Regulation) (Art. 5 principles, Art. 6 lawfulness, Art. 8 child's consent, Art. 9 special categories, Arts. 12-15 transparency and access, Art. 22 automated individual decision-making, Art. 33 breach notification, Art. 35 DPIA). Official Journal of the European Union (EUR-Lex). 2016-04-27. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (verified: primary)
  6. [6] EU AI Act Art. 53 (obligations for providers of general-purpose AI models, including a sufficiently detailed public summary of the content used for training). Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_53 (verified: primary)
  7. [7] Commission's enforcement powers related to AI Act obligations for providers of the most advanced models (GPAI obligations apply since 2 Aug 2025; Commission enforcement powers from 2 Aug 2026). European Commission, AI Act Service Desk. 2026-08-02. https://ai-act-service-desk.ec.europa.eu/en/ai-act/faq/commissions-enforcement-powers-related-ai-act-obligations-providers-most-advanced-models (verified: primary)