Italy Hits OpenAI with €15M Fine, Mandates AI Education Campaign

OpenAI’s ChatGPT is facing a steep €15 million fine
from Italy’s data protection authority. The penalty involves alleged data
breach and misuse of personal information.

According to a statement by the regulator, the
investigation began in March 2023 after a data breach involving ChatGPT raised
concerns. The Italian Data Protection Authority (IDPA), also known as the
Garante, uncovered several violations, including OpenAI’s failure to notify the
breach and its use of personal data to train its AI model without an adequate
legal basis.

Age Verification Mechanism

These actions, the IDPA said, violated principles of
transparency under the General Data Protection Regulation (GDPR). Further
concerns arose about the lack of effective age verification mechanisms, leaving
minors under 13 exposed to potentially inappropriate responses from the
chatbot.

“OpenAI has not provided mechanisms for age
verification, with the consequent risk of exposing minors under 13 to responses
that are unsuitable for their level of development and self-awareness, the
regulator wrote.

The IDPA has now ordered OpenAI to execute a six-month
public information campaign across radio, television, newspapers, and online
platforms. The campaign aims to educate the public on how generative AI works,
the data it collects, and how users can exercise their GDPR rights, such as
data rectification or opposition.

The fine reflects OpenAI’s partial cooperation during
the investigation, which the IDPA acknowledged in its final ruling.
Additionally, OpenAI’s establishment of a European headquarters in Ireland
during the investigation triggered the GDPR’s one-stop shop rule. This means
further inquiries into ongoing compliance will be overseen by Ireland’s Data
Protection Authority.

“ChatGPT users and non-users should be made aware of
how to oppose the training of generative artificial intelligence with their
personal data and, therefore, be effectively placed in the position to exercise
their rights under the GDPR, the regulator noted.

Expect ongoing updates as this story evolves.

OpenAI’s ChatGPT is facing a steep €15 million fine
from Italy’s data protection authority. The penalty involves alleged data
breach and misuse of personal information.

According to a statement by the regulator, the
investigation began in March 2023 after a data breach involving ChatGPT raised
concerns. The Italian Data Protection Authority (IDPA), also known as the
Garante, uncovered several violations, including OpenAI’s failure to notify the
breach and its use of personal data to train its AI model without an adequate
legal basis.

Age Verification Mechanism

These actions, the IDPA said, violated principles of
transparency under the General Data Protection Regulation (GDPR). Further
concerns arose about the lack of effective age verification mechanisms, leaving
minors under 13 exposed to potentially inappropriate responses from the
chatbot.

“OpenAI has not provided mechanisms for age
verification, with the consequent risk of exposing minors under 13 to responses
that are unsuitable for their level of development and self-awareness, the
regulator wrote.

The IDPA has now ordered OpenAI to execute a six-month
public information campaign across radio, television, newspapers, and online
platforms. The campaign aims to educate the public on how generative AI works,
the data it collects, and how users can exercise their GDPR rights, such as
data rectification or opposition.

The fine reflects OpenAI’s partial cooperation during
the investigation, which the IDPA acknowledged in its final ruling.
Additionally, OpenAI’s establishment of a European headquarters in Ireland
during the investigation triggered the GDPR’s one-stop shop rule. This means
further inquiries into ongoing compliance will be overseen by Ireland’s Data
Protection Authority.

“ChatGPT users and non-users should be made aware of
how to oppose the training of generative artificial intelligence with their
personal data and, therefore, be effectively placed in the position to exercise
their rights under the GDPR, the regulator noted.

Expect ongoing updates as this story evolves.

This post is originally published on FINANCEMAGNATES.

  • Related Posts

    Week in Review: iFOREX Delays IPO, Eightcap Gains Dubai License, and More

    Plus500 has a new shareholder Starting off our weekly news recap, America’s asset management firm Capital Group, with $2.2 trillion worth of assets under management, is now one of Plus500’s…

    2025 Mini-Football Tournament Kicks Off in Ypsonas, Limassol

    When spreadsheets give way to sliding tackles, you know it’s time for FXCubic’s annual football tradition. Financial firms from around the world are gathered in Limassol for a football tournament…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Gold Price Hits $3,340: Why Is Gold Going Up and What’s Next?

    • June 14, 2025
    Gold Price Hits $3,340: Why Is Gold Going Up and What’s Next?

    Why Does Gold Prices Fall Even When The Dollar Weakens?

    • June 14, 2025
    Why Does Gold Prices Fall Even When The Dollar Weakens?

    What Is Chart Context in Trading and Why Do Beginners Ignore It?

    • June 14, 2025
    What Is Chart Context in Trading and Why Do Beginners Ignore It?

    Week in Review: iFOREX Delays IPO, Eightcap Gains Dubai License, and More

    • June 14, 2025
    Week in Review: iFOREX Delays IPO, Eightcap Gains Dubai License, and More

    How to Trade XAG/USD vs. XAU/USD and What’s the Difference?

    • June 13, 2025
    How to Trade XAG/USD vs. XAU/USD and What’s the Difference?

    Why Micro Accounts in Forex Fail and How to Fix Them?

    • June 13, 2025
    Why Micro Accounts in Forex Fail and How to Fix Them?