The Garante per la protezione dei dati personali is Italy's independent national data-protection authority, responsible for enforcing the GDPR within Italy. It was the first major Western DPA to take significant enforcement action against a frontier AI system.
AI enforcement
The 2023 ChatGPT limitation order
On March 30, 2023 the Garante issued an order imposing an immediate provisional limitation on the processing of Italian users' personal data by OpenAI, announced by press release the following day and accompanied by the opening of an inquiry. The instrument was a limitazione provvisoria del trattamento rather than a fine or a product ban, though its practical effect was that ChatGPT became unavailable in Italy. Four grounds were given: the absence of any information notice to users and other data subjects; the absence of a legal basis for "the massive collection and processing of personal data in order to 'train' the algorithms on which the platform relies"; the processing of inaccurate personal data, on the reasoning that ChatGPT's output "does not always match factual circumstances"; and the absence of age verification, despite terms of service nominally restricting the service to users over 13. The order followed a data breach affecting user conversations and subscriber payment information reported on March 20, 2023. Jurisdiction rested on OpenAI's designated representative in the European Economic Area, the company having no EU establishment; OpenAI was given 20 days to report compliance measures, failing which a fine of up to €20 million or 4% of worldwide annual turnover could be imposed (Garante ChatGPT temporary limitation order and reinstatement (Italy, March–April 2023)).
A further order of April 11, 2023 set compliance requirements, and on April 28, 2023 the authority recorded the measures OpenAI had implemented, on the basis of which OpenAI reinstated Italian access. Those measures — a public training-data information notice addressed to non-users as well as users, an opt-out form for processing of personal data for algorithm training available to all individuals in Europe, a legal-basis split placing service operation on contract and training on legitimate interest, erasure offered in place of rectification on a stated technical-impossibility basis, and age declaration at registration — became an early template for GDPR compliance by a generative-AI service. The authority stated it expected further compliance on age verification and a public communication campaign, that its inquiry would continue, and that a dedicated task force had been established within the board of EU data protection authorities (Garante ChatGPT temporary limitation order and reinstatement (Italy, March–April 2023)). Full detail at Garante provisional limitation order on ChatGPT (Italy, 2023).
The action established the precedent that DPAs treat AI training data as a GDPR enforcement matter, and that GDPR Articles 5–6 apply to AI training data. The Garante has continued to scrutinize AI-product deployments in Italy.
The position taken in the 2023 action has since been shared across EU DPAs and replicated by CNIL (Commission nationale de l'informatique et des libertés) (France), Office of the Privacy Commissioner of Canada (OPC) (Canada), and others. GDPR enforcement operates alongside the AI Act as an EU AI-and-privacy regulatory mechanism. The pattern of DPA action on training-data legality has a parallel in US tort litigation over the same question, including Bartz v. Anthropic (settled for $1.5B) and Hachette et al. v. Meta (and Mark Zuckerberg) (filed May 2026).
The Garante's 2023 posture escalated to a monetary penalty against OpenAI, but that fine did not survive appeal: an Italian appeals court annulled the Garante's €15 million OpenAI fine in March 2026, according to an enforcement analysis published July 20, 2026 by Ray Sun's Global AI Regulation Tracker (Source: techieray.substack.com). The same analysis noted that in July 2026 the Garante fined Character.AI over child privacy, situating Italy within a broader pattern in which privacy and data-protection authorities dominate AI enforcement — the tracker counted more than 1,825 AI enforcement actions across 133 jurisdictions, against roughly 240 copyright and fewer than 180 competition actions (Source: techieray.substack.com).
Relationships
- related: AI and Privacy, AI Content Licensing, AI Copyright Litigation — Analysis.
- related: CNIL (Commission nationale de l'informatique et des libertés), EU AI Office, Office of the Privacy Commissioner of Canada (OPC) (Canadian peer).
- related: Bartz v. Anthropic (parallel US tort track on training-data).
- related: Garante provisional limitation order on ChatGPT (Italy, 2023) — the 2023 order tracked as a regulatory instrument.
- depends-on: Garante ChatGPT temporary limitation order and reinstatement (Italy, March–April 2023) — the authority's own press releases announcing and closing the limitation.