Timeline

Italy orders ChatGPT offline

The Garante cited a recent data breach and a lack of legal basis for training on personal data; OpenAI restored service within a month after adding disclosures and an age gate.

  • Government & policy
  • Courts & copyright
  • Notable

Italy’s data protection authority, the Garante, issued an emergency order requiring OpenAI to stop processing the personal data of people in Italy, making Italy the first Western country to block ChatGPT. The order took effect immediately and the service became unavailable to Italian users within days.

The Garante’s stated grounds combined an acute trigger and standing concerns. It had received notice on 20 March of a bug that exposed some users’ conversation histories and, for a period, payment details of ChatGPT Plus subscribers to other users — a breach OpenAI had not separately reported to the authority, itself a distinct compliance failure under GDPR. Beyond the breach, the Garante found no adequate legal basis for OpenAI’s use of personal data scraped from the web to train ChatGPT, said the company had not given users and non-users the transparency notices GDPR requires, and noted ChatGPT had no mechanism to verify that users were over 13, despite producing content unsuited to children.

OpenAI called the suspension “concerning” and said it believed it complied with privacy law, but did not immediately challenge the order in court. Over the following weeks it published a privacy policy explaining its use of personal data, added a form letting European users object to their data being used for training, and introduced an age-verification step at sign-up. The Garante judged these sufficient and lifted the block roughly four weeks after imposing it.

The episode was the opening move in a long-running dispute rather than its resolution: the same investigation eventually produced a €15 million fine against OpenAI in December 2024, which a Rome court later annulled on jurisdictional grounds. It also set a pattern other European regulators followed — treating a chatbot’s training data and its handling of minors’ access as ordinary data-protection questions rather than a novel category exempt from existing law.