Burhan Doğuş Ayparlar

← All decisions

Italy · 18 March 2026

Italian DPA's EUR 15 million ChatGPT fine against OpenAI annulled for lack of competence

The Rome court annulled the Garante's fine, holding that competence passed to the Irish authority once OpenAI had a main establishment in Ireland.

Court / authority
Tribunale di Roma (Rome Civil Court)
Date
18 March 2026
Case / decision no.
OpenAI v Garante per la protezione dei dati personali (ChatGPT), R.G. 4785/2025
Status
Proceedings ongoing

Facts

The Italian Data Protection Authority (Garante per la protezione dei dati personali) had temporarily restricted ChatGPT in 2023 and opened an investigation. By decision no. 755 of 2 November 2024 it fined OpenAI EUR 15 million and ordered a six-month information campaign on radio, television, newspapers and the internet. It found that OpenAI had failed to notify a March 2023 data breach, lacked an appropriate legal basis for processing personal data to train its models, breached transparency obligations and had no age verification to protect children under 13. OpenAI challenged the decision before the Tribunale di Roma. By order of 21 March 2025 the court suspended enforcement of the fine on condition that OpenAI provide a first-demand guarantee for the full amount.

Question

The central question was whether the Garante still had competence to adopt its final decision in November 2024. OpenAI's Irish entity had been recognised as its main establishment in the Union on 15 February 2024. OpenAI argued that from that date the one-stop-shop mechanism in Articles 55, 56 and 60 of the General Data Protection Regulation (GDPR) applied to its cross-border processing, making the Irish Data Protection Commission (DPC) the lead supervisory authority. The Garante maintained that it remained competent for infringements that had already been completed.

Decision

The court upheld OpenAI's first ground of challenge and annulled decision no. 755, including the ancillary information campaign. In its view, what matters is not when the infringements occurred but whether the administrative proceedings were still pending when the main establishment was recognised. Where a controller sets up a main or single establishment in the Union during the proceedings, it benefits from the one-stop-shop mechanism and competence passes to the lead supervisory authority. The court rejected a distinction between completed and ongoing infringements. It did not examine the merits of the alleged breaches, and the costs were set off between the parties.

Why it matters

The judgment removed one of the largest national GDPR fines imposed on a generative AI provider without reaching the merits. It shows that a non-EU provider that sets up a main establishment in the Union while an investigation is pending can bring national authorities' competence to an end. Substantive questions such as the legal basis for model training and age verification remain undecided. Any continuing infringements fall within the remit of the Irish Data Protection Commission as lead supervisory authority.

Related stages

In its 20 December 2024 announcement the Garante said it had forwarded the file to the Irish Data Protection Commission as regards continuing infringements. The information campaign was suspended automatically once the decision was challenged. The Rome judgment is a first-instance ruling; as of September 2026 there is no report of an appeal by the Garante to the Court of Cassation (Corte di Cassazione).