OpenAI – Violation Found (Italy, 2023)

Violation Found
Garante per la protezione dei dati personali30 March 2023Italy
final
ePrivacy
Violation Found

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

OpenAI's ChatGPT was found to have several issues regarding user privacy, including not providing clear information about data processing and failing to verify user ages. This matters because it shows that companies must be transparent about how they use personal data and ensure they comply with age restrictions.

What happened

The Italian Data Protection Authority found that OpenAI did not provide adequate information to users about how their personal data was processed.

Who was affected

Users of ChatGPT, particularly those whose personal data was collected without proper notice, were affected.

What the authority found

The authority ruled that OpenAI violated GDPR by not having a valid legal basis for processing personal data and failing to provide necessary privacy information.

Why this matters

This ruling emphasizes the need for companies to be transparent about data use and to implement age verification measures. Website operators should ensure they have clear privacy policies and comply with data protection laws.

GDPR Articles Cited

AI-verified

Art. 6(GDPR)
Art. 8(GDPR)
Art. 13(GDPR)
Art. 25(GDPR)
Art. 5(1)(d) GDPR
Art. 58(2)(f) GDPR
View original scraped data
Art. 5(GDPR)
Art. 6(GDPR)
Art. 8(GDPR)
Art. 13(GDPR)

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Art. 170 Codice Privacy
Source verified 12 April 2026
articles corrected
national law identified
Full Legal Summary
Detailed

The Italian DPA after receiving complaint from Inder Kahlon on 24th February 2023 (Numero protocollo: 0033835) opened an investigation concerning ChatGPT, an AI service offered by the American company OpenAI. The investigation focused on three main areas. First, the controller did not provide the data subjects whose personal data had been collected through the Internet with appropriate information about the processing. Second, the DPA found that ChatGPT final outcome – its “answers” – despite based also on personal data and thus often containing personal data, did not always represent reality in an accurate way. Finally, the investigation showed that OpenAI did not adopt any measure to check that users were above the minimum age requirement of 13 years. The Italian DPA held that the controller did not comply with its obligation to provide data subjects with a privacy policy pursuant to Article 13 GDPR. Moreover, the collection of personal data and their use in the training of ChatGPT algorithms were undertaken in lack of a proper legal basis,in violation of Article 5 and 6 GDPR. Concerning specifically data of people other than the users, namely those data subjects whose data were collected on the internet, the DPA found that the algorithms behind the functioning of ChatGPT did not guarantee the principle of accuracy as enshrined in Article 5(1)(d). Finally, the DPA also considered that the lack of any mechanism to check the age of the users entailed a violation of Article 8 GDPR. In light of the above and in the context of an urgency procedure, the DPA imposed on OpenAI a temporary limitation of processing pursuant to Article 58(2)(f) GDPR. Such limitation concerns all processing operations involving data subjects on the Italian territory.

Outcome

Violation Found

The DPA found a violation but did not impose a fine.

Details

Decision Date

30 March 2023

Authority

Garante per la protezione dei dati personali

GDPRhub ID

gdprhub-5777

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. OpenAI - Italy (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: