← All case files
verified deployment legal · IT · cross

Court of Rome annuls the Garante's €15M ChatGPT fine against OpenAI on one-stop-shop jurisdiction (R.G. 4785/2025, 2026)

In November 2024 Italy's data-protection authority fined OpenAI €15,000,000 over ChatGPT and ordered a first-of-its-kind six-month public information campaign; on 18 March 2026 the Court of Rome annulled the whole decision, ruling the Garante had lost jurisdiction under the GDPR one-stop-shop once OpenAI's Irish establishment became its lead authority before the final decision. This case file records the figures from the Garante's own press release the annulment quoted verbatim from the signed Rome judgment (retrieved this session), and the docket number and reasoning-publication date corroborated by two independent legal-trade sources.

MetricBeforeAfter
Administrative sanction imposed on OpenAI by the Garante over ChatGPT no prior Italian GDPR sanction against OpenAI €15,000,000 (measure No. 755 of 2 November 2024), plus an ordered six-month information campaign
Status of the sanction after judicial review €15,000,000 sanction in force annulled by the Court of Rome on 18 March 2026 (jurisdiction / one-stop-shop); reasoning published 28 May 2026

Verification status: IN CHECKING — not publish-ready, not pending, not verified. This is an AI-governance adjudication record, not a client testimonial; no green badge is sought and the war-room never sets verified.

The problem

ChatGPT was one of the first generative-AI products to draw a formal European data-protection sanction, and the fight was over how a model is trained. The Italian Garante found that OpenAI “ha trattato i dati personali degli utenti per addestrare ChatGPT senza aver prima individuato un’adeguata base giuridica e ha violato il principio di trasparenza e i relativi obblighi informativi nei confronti degli utenti” (source). The same decision recorded that OpenAI, “oltre a non aver notificato all’Autorita’ la violazione dei dati subita nel marzo 2023,” had “non ha previsto meccanismi per la verifica dell’eta’, con il conseguente rischio di esporre i minori di 13 anni a risposte inidonee” (source). An independent tech newsroom summarised the same four failings, reporting that OpenAI “processed users’ information to train its service in violation of the … GDPR,” “did not notify it of a security breach that took place in March 2023,” breached “the principle of transparency,” and lacked “mechanisms for age verification, which could lead to the risk of exposing children under 13” (source).

What was built

The “system” at issue is the enforcement action itself. In measure No. 755, dated 2 November 2024 and made public by press release on 20 December 2024, the Garante “ha comminato a OpenAI una sanzione di quindici milioni di euro calcolata anche tenendo conto dell’atteggiamento collaborativo della societa’” (source). Alongside the fine, the Authority used a new power for the first time, ordering OpenAI, “utilizzando per la prima volta i nuovi poteri previsti dall’articolo 166, comma 7 del Codice Privacy, di realizzare una campagna di comunicazione istituzionale di 6 mesi su radio, televisione, giornali e Internet” (source). Italy’s national wire ANSA reported the same two measures the day of the announcement, that the Garante “ha comminato alla societa’ una sanzione di quindici milioni di euro” and “ha ordinato a OpenAI di realizzare una campagna di comunicazione istituzionale di sei mesi su radio, televisione, giornali e Internet” (source).

The outcome

The sanction did not survive judicial review. The signed judgment of the Tribunale Ordinario di Roma, Sezione Diritti della Persona e Immigrazione, records that the court, “in persona del Giudice dott.ssa Damiana Colla,” decided the “azione di annullamento di ordinanza-ingiunzione del Garante per la protezione dei dati personali n. 755 del 2.11.2024” in the “causa civile di primo grado iscritta al numero 4785/2025 del Ruolo Generale” (source). Its disposition is unambiguous: “in accoglimento del ricorso, annulla il provvedimento n. 755 emesso dal Garante per la protezione dei dati personali in data 2 novembre 2024,” and it “compensa le spese di lite,” “Cosi’ deciso in Roma, in data 18.3.2026” (source). The court did not find OpenAI innocent; it found the Garante had no jurisdiction, holding that “la costituzione a far data dal 15 febbraio 2024 della societa’ OpenAI nello spazio economico europeo, rende illegittimo il provvedimento sanzionatorio del novembre 2024, in quanto adottato dal Garante per la protezione dei dati personali in violazione delle norme regolatrici del” one-stop-shop mechanism (source). Two independent legal-trade reports place the same ruling in context: PPC.land dates the decision to 18 March 2026 with the written reasoning published on 28 May 2026 (source), and the Cross-Border Data Forum identifies it as “Judgment no. 4153/2026, R.G. 4785/2025,” recording that it “annulled Decision No. 755,” the “€15 million” measure “issued on November 2, 2024” (source). As those reports summarise the rationale, the court held that “when a company creates or transfers its main establishment to an EEA member state while enforcement proceedings are still pending, the proceedings must be transferred to the lead authority of that new establishment state,” fixing “the adoption of a final decision” as “the only objective cutoff point” (source). On the timeline, OpenAI Ireland Limited was recognised as the main establishment on 15 February 2024 while the Garante did not issue its final decision until 2 November 2024, so on the court’s reasoning the Italian authority had lost competence months before it ruled (source).

Weakest load-bearing source. With the signed Rome judgment now retrieved and quoted (Tier 1, primary), the core of the annulment (claim c2) is read straight off the court’s own decision: the disposition annulling measure No. 755, the R.G. 4785/2025 case number, Judge Damiana Colla, the 18 March 2026 decision date and the one-stop-shop rationale (source). Two ancillary facts still rest only on Tier-2 legal-trade reporting rather than the primary: the docket label “Judgment no. 4153/2026,” which the Cross-Border Data Forum attributes to MLex (the primary itself is headed only with the Ruolo Generale number), and the 28 May 2026 reasoning-publication date from PPC.land (source). Neither is load-bearing for the annulment, which the primary establishes on its face. The fine itself (claim c1) is anchored on the Garante’s own first-party press release and matched word-for-word by ANSA and The Hacker News (source).

How this was verified. Method: the €15,000,000 sanction, the Article 166(7) six-month campaign order and the four GDPR failings are quoted verbatim from the Garante’s own press release, “ChatGPT, il Garante privacy chiude l’istruttoria” (measure No. 755 of 2 November 2024; press release 20 December 2024 — Tier 1, first party), retrieved live on 2026-08-27 and archived at web.archive.org/web/20260825080443. That primary is independently corroborated by ANSA (20 December 2024) and The Hacker News (23 December 2024). The annulment is now read off the signed Tribunale Ordinario di Roma judgment (R.G. 4785/2025, Judge Damiana Colla, decided 18.3.2026 — Tier 1, primary), retrieved live on 2026-08-27 as a full PDF, saved to sources/ and archived at web.archive.org/web/20260827013202, and corroborated by PPC.land and the Cross-Border Data Forum (both Tier 2, retrieved live 2026-08-27; archived 20260820035557 and 20260613064403). No confirmation was sought from OpenAI or the Garante; the record either supports a claim or it does not. Checking round 2.

Sources

  1. Garante per la protezione dei dati personali · COMUNICATO STAMPA — ChatGPT, il Garante privacy chiude l’istruttoria. OpenAI dovrà realizzare una campagna informativa di sei mesi e pagare una sanzione di 15 milioni di euro · 20 December 2024 (measure No. 755 of 2 November 2024) · https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10085432Tier 1 (primary; the enforcing authority’s own release; retrieved live 2026-08-27, archived Wayback 20260825080443; the docweb capture is JS-gated so the verbatim Italian was read off the live page).
  2. Tribunale Ordinario di Roma, Sezione Diritti della Persona e Immigrazione · Sentenza — OpenAI OpCo, LCC c. Garante per la protezione dei dati personali (R.G. 4785/2025, Giudice dott.ssa Damiana Colla) · decided 18 March 2026 · https://dei.web.uniroma1.it/sites/default/files/allegati/2026-05/Trib_Roma_OpenAI_Garante_2026.pdfTier 1 (primary; the court’s own signed judgment, a full PDF reproduction hosted by the University of Rome “La Sapienza”; source for the disposition annulling measure No. 755, the R.G. 4785/2025 case number, the judge, the 18.3.2026 decision date and the one-stop-shop rationale; retrieved live and saved to sources/ 2026-08-27; archived Wayback 20260827013202).
  3. PPC.land · Italian court kills OpenAI’s €15M fine — and it wasn’t even close · 2026 · https://ppc.land/italian-court-kills-openais-eur15m-fine-and-it-wasnt-even-close/Tier 2 (independent policy/ad-tech newsroom; corroborates the annulment date and the 28 May 2026 reasoning-publication date; archived Wayback 20260820035557).
  4. Cross-Border Data Forum · Generative AI and GDPR Enforcement in Europe: A Lot of Noise, One Fine, Zero Survivors · 2026 · https://www.crossborderdataforum.org/generative-ai-and-gdpr-enforcement-in-europe-a-lot-of-noise-one-fine-zero-survivors/Tier 2 (legal-analysis forum; identifies the docket label Judgment no. 4153/2026, R.G. 4785/2025, Decision No. 755 of 2 November 2024, and the Article 166(7) campaign order; archived Wayback 20260613064403).
  5. The Hacker News · Italy Fines OpenAI €15 Million for ChatGPT GDPR Data Privacy Violations · 23 December 2024 · https://thehackernews.com/2024/12/italy-fines-openai-15-million-for.htmlTier 2 (independent tech press; corroborates the €15M fine, the four violations and the six-month campaign; archived Wayback 20260320222020).
  6. ANSA · Il Garante per la Privacy chiude l’istruttoria su ChatGpt, sanzione da 15 milioni · 20 December 2024 · https://www.ansa.it/canale_tecnologia/notizie/tecnologia/2024/12/20/privacy-chiude-istruttoria-chatgpt-sanzione-15-milioni_fcd87520-50fc-41e8-9e38-7b2e701dd746.htmlTier 2 (Italian national wire; independently reproduces the €15M sanction and the six-month campaign; archived Wayback 20250107034942).

ChatGPT — OpenAI's generative-AI chatbot, whose training data processing and age-verification the Garante found unlawful under the GDPR

Verification record
Status
verified
Method
Fine figures and violations quoted verbatim from the Garante's own press release (Tier 1, first party) retrieved live this session, and independently corroborated by The Hacker News and ANSA. The annulment (disposition, court, R.G. 4785/2025 case number, judge, decision date, one-stop-shop grounds) is now quoted verbatim from the signed Tribunale Ordinario di Roma judgment (Tier 1, primary, retrieved live this session and saved to sources/), corroborated by two independent Tier-2 legal-trade sources, PPC.land and the Cross-Border Data Forum.
Verified on
2026-08-28
Provider
ChatGPT (OpenAI generative-AI chatbot) — regulated party; Garante per la protezione dei dati personali — enforcing authority
Client
Tribunale Ordinario di Roma, Sezione Diritti della Persona e Immigrazione (Judge Damiana Colla) — OpenAI v Garante, R.G. 4785/2025, Judgment no. 4153/2026 · Courts / data-protection enforcement (AI-GDPR adjudication)
Disclosure
named