Artificial Intelligence

Italy’s Privacy Watchdog Fines OpenAI for ChatGPT’s Violations in Collecting Users Personal Data

Italy’s data protection watchdog fined OpenAI 15 million euros ($15.6 million) after wrapping up a probe into collection of personal data.

ChatGPT vulnerability

Italy’s data protection watchdog said Friday it has fined OpenAI 15 million euros ($15.6 million) after wrapping up a probe into the collection of personal data by the U.S. artificial intelligence company’s popular chatbot ChatGPT.

The country’s privacy watchdog, known as Garante, said its investigation showed that OpenAI processed users’ personal data to train ChatGPT “without having an adequate legal basis and violated the principle of transparency and the related information obligations towards users”.

OpenAI dubbed the decision “disproportionate” and said it will appeal.

“When the Garante ordered us to stop offering ChatGPT in Italy in 2023, we worked with them to reinstate it a month later,” an OpenAI spokesperson said Friday in an emailed statement. “They’ve since recognized our industry-leading approach to protecting privacy in AI, yet this fine is nearly 20 times the revenue we made in Italy during the relevant period.”

OpenAI added, however, it remained “committed to working with privacy authorities worldwide to offer beneficial AI that respects privacy rights.”

The investigation, launched last year, also found that OpenAI didn’t provide an “adequate age verification system” to prevent users under 13 years of age from being exposed to inappropriate AI-generated content, the watchdog said.

Advertisement. Scroll to continue reading.

The Italian authority also ordered OpenAI to launch a six-month campaign on different Italian media to raise public awareness about ChatGPT, specifically in regard to data collection.

The booming popularity of generative artificial intelligence systems like ChatGPT has drawn scrutiny from regulators on both sides of the Atlantic.

Regulators in the U.S. and Europe have been examining OpenAI and other companies that have played a key part in the AI boom, while governments around the world have been drawing up rules to protect against risks posed by AI systems, led by the European Union’s AI Act, a comprehensive rulebook for artificial intelligence.

Related: Dane Stuckey Joins OpenAI as CISO

Related: OpenAI Says Iranian Hackers Used ChatGPT to Plan ICS Attacks

Related: OpenAI Chief Technology Officer Mira Murati and 2 Other Execs Are Leaving the ChatGPT Maker

Related Content

Artificial Intelligence

Corma emerged from stealth with seed funding from Sequoia Capital, Khosla Ventures, and Coatue.

Artificial Intelligence

OpenAI has also announced the expansion of its Daybreak platform to give more organizations access to its AI.

Artificial Intelligence

The current GPT-5.6-Sol has been assigned a ‘high’ cybersecurity threshold, but Astra could reach the maximum ‘critical’ threshold. 

Artificial Intelligence

An AI agent executes instructions that an attacker has planted in the log or alert that records a blocked request word for word.

Artificial Intelligence

The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data.

Artificial Intelligence

Zenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched.

Artificial Intelligence

An attacker could self-register, sign in for board-level API access, and import a new company for code execution.

Artificial Intelligence

The incident involved a testing environment set up by Irregular, similar to what Anthropic reported last week.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version