Italy's Garante and ChatGPT: the Full Dated Timeline
10 min read · updated August 11, 2026
The ChatGPT suspension is remembered as a month-long outage in spring 2023. The proceeding it opened ran for three more years, produced a €15 million fine, and ended at first instance in March 2026 with that fine annulled on a jurisdictional point that had nothing to do with whether the processing was lawful.
The dated sequence
- 20 March 2023. A bug in an open-source library used by ChatGPT exposed some users’ conversation titles and, for a subset of ChatGPT Plus subscribers, partial payment details. OpenAI disclosed the incident publicly. It is the trigger the Garante names.
- 30 March 2023. The Garante adopts an urgent provvedimento imposing a provisional limitation on the processing of the personal data of data subjects in Italy by OpenAI L.L.C., effective on receipt, citing Articles 5, 6, 8, 13 and 25 of the GDPR and the Article 58(2)(f) power. The 30 March 2023 order is in the Garante’s archive. OpenAI made the service unavailable in Italy in response.
- 11 April 2023. The Garante adopts a second provvedimento suspending its own limitation, conditional on OpenAI implementing a list of measures on a staged set of deadlines. That order sets out the conditions.
- 28 April 2023. ChatGPT becomes available again in Italy, OpenAI having reported the first tranche of measures. The inquiry itself continued.
- 15 February 2024. The Irish Data Protection Commission recognises OpenAI Ireland Ltd as OpenAI’s main establishment in the EEA. This date carries no visible weight at the time and decides the case two years later.
- 20 December 2024. The Garante closes the inquiry with provvedimento n. 755/2024: a €15 million fine and an order to run a six-month public information campaign. OpenAI announces it will appeal.
- 18 March 2026. The Tribunale di Roma, in sentenza n. 4153/2026, annuls the penalty on the ground that the Italian authority lacked competence to impose it once OpenAI Ireland was the EEA main establishment.
The conditions OpenAI had to meet
The 11 April 2023 order is the substantive one, because it is where the regulator stated what compliance would look like. Its requirements, with the deadlines it attached:
- By 30 April 2023 — publish an information notice describing the processing, including the arrangements and the logic involved in training the model, and the rights available to users and to non-users whose data was processed; make it reachable before sign-up, from the registration flow; give Italian users and non-users a tool to object to processing for training; provide a way to request correction of inaccurate personal data generated about them, or erasure where correction is not technically feasible; and replace contract with either consent or legitimate interest as the basis for training-related processing.
- By 15 May 2023 — run an information campaign on radio, television, newspapers and the internet, so that people who are not users would learn that their data may have been used and how to object.
- Immediately, then by 30 September 2023 — put an age gate on access, and submit by 31 May 2023 a plan for a stronger age verification mechanism to be in place by the end of September.
Two of those are load-bearing well beyond this case. The instruction to abandon contract as the basis for training-related processing is the Garante taking a position on a question the whole industry was arguing about, and it pushed OpenAI onto legitimate interests, which carries its own balancing obligation — the lawful basis for scraped training data is the same argument in general form. The correction-or-erasure requirement is the earliest regulatory recognition that a model asserting false statements about a person is a data accuracy problem under Article 5(1)(d), which is now a live question about rectification and hallucinated facts.
The December 2024 penalty
Provvedimento n. 755/2024, adopted 20 December 2024, imposed a fine of €15 million. The Garante’s account of the findings covers processing personal data to train ChatGPT without an adequate basis and without telling people, transparency failings in the information given to users, the absence of an age verification system, and the handling of the March 2023 breach.
The corrective order attached to it was unusual and worth noting on its own: a six-month information campaign across radio, television, print and online, designed to explain to the Italian public how ChatGPT collects and uses data and how users and non-users can exercise their rights to object, to erasure and to rectification. Regulators rarely order publicity as a remedy, and it is a sign the authority regarded the transparency deficit as the durable harm rather than the breach.
OpenAI called the fine disproportionate and appealed. In Italy an appeal against an administrative fine of this kind goes to the ordinary courts — which is how the matter reached the Tribunale di Roma.
The 2026 annulment, and its narrow ground
The Tribunale di Roma upheld the appeal in sentenza n. 4153/2026, deposited 18 March 2026, and annulled the €15 million penalty. The reported ground is the GDPR’s one-stop-shop mechanism. Once the Irish Data Protection Commission recognised OpenAI Ireland Ltd as the company’s sole establishment in the EEA on 15 February 2024, the argument runs, the Irish authority became the lead supervisory authority for OpenAI’s cross-border processing under Article 56, and the Italian authority could no longer impose a penalty for that processing on its own account.
If that is the reasoning — and the full text was not public when this page was written — then the decision is about who may penalise, not about what was done. It leaves the 2023 measures in a different position from the 2024 fine, because those predate February 2024 and were urgency measures of the kind Article 66 of the GDPR expressly preserves for a national authority even where a lead authority exists.
Whether the Garante appeals further, and how a higher court treats the competence question, is open. The wider consequence, if it stands, is about sequencing: establishing an EU main establishment does not cure past conduct, but it does change which regulator is entitled to act on it, and companies that established in Ireland partway through an investigation have been arguing exactly this.
What none of this decided
The list is longer than the list of things that were decided, and it is the honest part of the page.
It did not decide that training on scraped personal data is lawful, or unlawful. The Garante asserted a position in a corrective order and later in a penalty; the penalty fell on competence grounds. No court has ruled on the substantive lawfulness in this case.
It did not establish that the age gate OpenAI implemented is adequate. The 2023 order set a deadline for a plan and a mechanism; nothing in the sequence adjudicates the sufficiency of what was built.
It did not resolve the position for other companies.The competence ruling depends on a specific fact — a formally recognised main establishment in another Member State from a specific date. A provider with no EU establishment is in the position Luka Inc. was in for the Replika measure, where any concerned authority can act directly.
And it did not end the regulatory question. If the Irish DPC is the lead authority for OpenAI’s EEA processing, the consequence is that the file moves, not that it closes. Where that file sits, and what the EDPB’s position on model training implies for it, is the thing to follow rather than the Italian fine.