These are the two press releases in which Italy's Garante per la protezione dei dati personali announced and then closed the first suspension of a frontier AI product by a regulator in a major market. The first, doc-web 9870847, is dated 31 March 2023 and announces an order (provvedimento) dated 30 March 2023, doc-web 9870832. The second, doc-web 9881490, is dated 28 April 2023 and records OpenAI's compliance with a further order of 11 April 2023, doc-web 9874702. Each page carries the Italian text followed by the authority's own English version; quotations below are from the authority's English text. See Garante provisional limitation order on ChatGPT (Italy, 2023) for the order as a regulatory instrument.
The March 2023 order
The Garante states that it "imposed an immediate temporary limitation on the processing of Italian users' data by OpenAI, the US-based company developing and managing the platform," and that "an inquiry into the facts of the case was initiated as well." The Italian text gives the measure's name as limitazione provvisoria del trattamento — a provisional limitation on processing rather than a fine or a ban on the product as such.
The precipitating event is recorded as a breach: "A data breach affecting ChatGPT users' conversations and information on payments by subscribers to the service had been reported on 20 March."
Four grounds are stated in the order as the authority summarizes it:
- No information notice. "No information is provided to users and data subjects whose data are collected by Open AI."
- No legal basis for training-data processing. "More importantly, there appears to be no legal basis underpinning the massive collection and processing of personal data in order to 'train' the algorithms on which the platform relies." This is the ground with the longest downstream reach; see AI Copyright and AI and Privacy.
- Inaccurate personal data. "As confirmed by the tests carried out so far, the information made available by ChatGPT does not always match factual circumstances, so that inaccurate personal data are processed" — the data-protection accuracy principle applied to model output. See Sycophancy and Hallucination.
- No age verification. "The lack of whatever age verification mechanism exposes children to receiving responses that are absolutely inappropriate to their age and awareness, even though the service is allegedly addressed to users aged above 13 according to OpenAI's terms of service."
On jurisdiction and consequence, the release states that "OpenAI is not established in the EU, however it has designated a representative in the European Economic Area," and that "it will have to notify the Italian SA within 20 days of the measures implemented to comply with the order, otherwise a fine of up to EUR 20 million or 4% of the total worldwide annual turnover may be imposed." The penalty is the GDPR maximum expressed as a ceiling on a possible future fine for non-compliance, not a fine imposed by this order.
The April 2023 reinstatement
The 28 April release records that OpenAI "sent a letter to the Italian SA describing the measures it implemented in order to comply with the order issued by the SA on 11 April," and that "based on these improvements, OpenAI reinstated access to ChatGPT for Italian users." The reinstatement is therefore recorded as OpenAI's act following the authority's assessment, not as a revocation order.
The measures the authority lists are:
- An information notice published on OpenAI's site "addressed to users and non-users, in Europe and elsewhere, describing which personal data are processed under which arrangements for training algorithms, and recalling that everyone has the right to opt-out from such processing."
- An expanded privacy policy, made accessible from the sign-up page before registration.
- A right for "all individuals in Europe, including non-users" to opt out of processing of their data for algorithm training, "also by way of an online, easily accessible ad-hoc form."
- A welcome-back page on reinstatement in Italy linking to the new privacy policy and the training-data information notice.
- Mechanisms "to enable data subjects to obtain erasure of information that is considered inaccurate, whilst stating that it is technically impossible, as of now, to rectify inaccuracies" — erasure substituted for rectification on a stated technical-impossibility basis.
- A clarification that OpenAI will continue to process certain personal data on a contractual basis for service functioning, but will process personal data for algorithm training on a legitimate-interest basis unless the data subject objects.
- An objection form already implemented for European users, allowing conversations and history to be excluded from training.
- A declaration button in the welcome screen for existing Italian users requiring them to state that they are adults or over thirteen with parental consent, and a date-of-birth field at registration blocking under-thirteens and requiring confirmation of parental consent for minors above that age.
The Italian text records the authority expressing satisfaction with the measures while stating expectations for further compliance with the same 11 April order, "with particular reference to the implementation of an age verification system and to the planning and realisation of a communication campaign" informing Italians of what had happened and of the right to object to use of their personal data for algorithm training. It states the inquiry opened against OpenAI would continue, alongside the work of the dedicated task force established within the board of EU data protection authorities — the referral that made this a European rather than solely Italian matter.
Provenance
Both press releases were retrieved August 1, 2026 by direct HTTPS fetch from garanteprivacy.it (HTTP 200) and converted to text with a local extractor; Firecrawl was out of credits during this cycle. The underlying orders of 30 March 2023 (doc-web 9870832) and 11 April 2023 (doc-web 9874702) are separate documents and were not retrieved; this page therefore describes the orders only as the authority's own press releases summarize them, and the four grounds above are the authority's summary rather than the order's operative text. The related-documents list on the March page also records communiqués of 4, 6, 8, 12 and 13 April 2023 and 20 December 2024, none retrieved.
Relationships
- related: Garante per la protezione dei dati personali (Italy) — the issuing authority.
- related: Garante provisional limitation order on ChatGPT (Italy, 2023) — the order tracked as a regulatory instrument.
- related: OpenAI — the subject of the order.
- depends-on: AI and Privacy — the legal framework the order applies.
- related: Sycophancy and Hallucination — the output-accuracy problem here treated as a data-protection violation.
- related: EU AI Act (Regulation 2024/1689) — the later EU instrument addressing the same systems on a different legal basis.