AI Policy Wiki
Dashboard

Garante provisional limitation order on ChatGPT (Italy, 2023)

high confidence · updated 2026-08-01

The Italian data protection authority's order of March 30, 2023 (doc-web 9870832) imposing an immediate provisional limitation on OpenAI's processing of Italian users' personal data under the GDPR, the further order of April 11, 2023, and the closure of the limitation on April 28, 2023 after OpenAI implemented transparency, opt-out and age-declaration measures.

The provisional limitation order issued by Italy's Garante per la protezione dei dati personali against OpenAI on March 30, 2023 was the first instance of a data protection authority suspending processing by a frontier AI product in a major market. It was announced in a press release of March 31, 2023 (doc-web 9870847), supplemented by a further order of April 11, 2023 (doc-web 9874702), and closed on April 28, 2023 after the authority reviewed OpenAI's compliance measures (Garante ChatGPT temporary limitation order and reinstatement (Italy, March–April 2023)).

The instrument is a limitazione provvisoria del trattamento — a provisional limitation on processing under the GDPR, directed at OpenAI's handling of Italian users' personal data. It is not a fine, and not a prohibition on the product as such, though its practical effect was that ChatGPT became unavailable in Italy until reinstatement.

Status and timeline

DateEvent
March 20, 2023Data breach affecting ChatGPT conversations and subscriber payment information reported
March 30, 2023Provisional limitation order issued (doc-web 9870832); inquiry opened
March 31, 2023Order announced by press release (doc-web 9870847)
April 11, 2023Further order setting compliance requirements (doc-web 9874702)
April 28, 2023Authority records OpenAI's compliance measures; OpenAI reinstates access for Italian users (doc-web 9881490)

Grounds

The authority's summary of the order gives four grounds (Garante ChatGPT temporary limitation order and reinstatement (Italy, March–April 2023)):

  1. Absence of an information notice to users and to other data subjects whose data OpenAI collects.
  2. Absence of a legal basis for "the massive collection and processing of personal data in order to 'train' the algorithms on which the platform relies" — the ground the authority itself flags as the more important of the first two, and the one with the widest application beyond this case.
  3. Processing of inaccurate personal data, on the reasoning that "the information made available by ChatGPT does not always match factual circumstances." This applies the GDPR accuracy principle to generated output rather than to stored records; see Sycophancy and Hallucination.
  4. Absence of age verification, exposing children to responses "absolutely inappropriate to their age and awareness" despite terms of service nominally restricting the service to users over 13.

Jurisdiction and enforcement

The order records that OpenAI "is not established in the EU, however it has designated a representative in the European Economic Area" — the basis on which the Italian authority asserted competence. OpenAI was required to notify the authority within 20 days of the measures implemented to comply, failing which "a fine of up to EUR 20 million or 4% of the total worldwide annual turnover may be imposed." That figure is the GDPR ceiling on a possible future non-compliance penalty; no fine was imposed by this order (Garante ChatGPT temporary limitation order and reinstatement (Italy, March–April 2023)).

Compliance measures accepted

The April 28, 2023 notice lists the measures OpenAI reported, which together set an early template for GDPR compliance by a generative-AI service:

  • A public information notice, addressed to users and non-users in Europe and elsewhere, describing what personal data are processed for algorithm training and stating a right to opt out.
  • An expanded privacy policy accessible from the sign-up page before registration.
  • A right for all individuals in Europe, including non-users, to object to processing of their data for training, exercisable through an online form.
  • A welcome-back screen on reinstatement in Italy linking to the new privacy policy and training-data notice.
  • A mechanism for erasure of information considered inaccurate, OpenAI "stating that it is technically impossible, as of now, to rectify inaccuracies" — erasure accepted in place of rectification on a technical-impossibility basis.
  • A stated legal-basis split: contract for data processed to operate the service, legitimate interest for data processed for algorithm training, subject to the right to object.
  • An objection form allowing European users to exclude their conversations and history from training.
  • An age-declaration button for existing Italian users and a date-of-birth field at registration, blocking under-13s and requiring confirmation of parental consent for minors above that age.

The authority stated it expected further compliance with the April 11 order, "with particular reference to the implementation of an age verification system and to the planning and realisation of a communication campaign" informing Italians of the events and of the right to object to training use of their data. The inquiry against OpenAI continued, alongside a dedicated task force established within the board of EU data protection authorities — the step that carried the Italian action into a European coordination process (Garante ChatGPT temporary limitation order and reinstatement (Italy, March–April 2023)).

Open questions

  • The operative text of the orders of March 30 and April 11, 2023 has not been retrieved; the provisions above are the authority's own summaries in its press releases.
  • Whether the age-verification system and communication campaign required by the April 11 order were subsequently implemented, and the outcome of the continuing inquiry, are not recorded here. The March 2023 page's related-documents list points to a further communiqué of December 20, 2024, which has not been ingested.

Relationships