Italy - Temporary Order Against ChatGPT
Provision April 11, 2023 - Precautionary Measures and Temporary Order Against ChatGPT (Data Protection Authority)
Provvedimento 11 April 2023 - Misure cautelari e ordine temporaneo contro ChatGPT (Garante per la protezione dei dati personali)
Italy
RAI-IT-NA-P1A2MXX-2023On 11 April 2023 the Italian Data Protection Authority (Garante) issued Provvedimento n.114, conditionally suspending an earlier emergency limitation on ChatGPT (OpenAI) in light of commitments from the company. The measure required OpenAI to adopt transparency, age‑verification, legal‑basis and user‑rights safeguards within specified deadlines (notably 30 April 2023 for core items) or face reactivation of the limitation and further enforcement steps under GDPR.
Summary
Read full text ↗Plain English
Overview
The Provvedimento of 11 April 2023 (Registro dei provvedimenti n. 114) issued by the Italian Data Protection Authority (Garante per la protezione dei dati personali) followed an emergency limitation adopted on 30 March 2023 against OpenAI's ChatGPT service. The April 11 decision conditionally suspended the earlier limitation in view of commitments presented by OpenAI while continuing the formal inquiry and reserving the right to further enforcement action. The Garante framed its decision around transparency obligations, the legal basis for processing personal data used to train large generative models, the rights of data subjects (including non‑users whose data may be in training corpora) and measures to prevent access by under‑age children. The full official narrative and the text of the Garante communications are available from the authority’s website: Garante – Provvedimento 11 April 2023 (print view) and related communiqués such as Intelligenza artificiale: il Garante blocca ChatGPT.
Definitions
For the purposes of the provvedimento: "Controller/Titular del trattamento" refers to OpenAI L.L.C. as identified by the Garante; "processing for training" denotes collection and retention of personal data (including content of user interactions and third‑party data) to tune and develop underlying machine‑learning models; "interested parties" includes both users of ChatGPT and non‑users whose data were identified as having been included in training datasets; "age gate" and "age verification" refer to procedural and technological measures to exclude or obtain verifiable parental consent for under‑13s (or other age thresholds required by law); and "prescriptions" are the specific injunctive requirements set out by the Garante in Provvedimento n.114.
Governance and Institutional Framework
The Garante exercised powers under Article 58 of the EU General Data Protection Regulation (Regulation (EU) 2016/679) and applicable provisions of the Italian Data Protection Code (d.lgs. 196/2003). The authority's approach combined urgent injunctive powers (initial emergency limitation of 30 March 2023, subsequently ratified) with a conditional supervisory remedy (the 11 April 2023 provvedimento) that hinged on demonstrable remediation by the controller. The Garante coordinated with other EU data protection authorities and the European Data Protection Board (EDPB) which established a task force addressing generative AI concerns; see the Garante's announcement on EU cooperation at Garante – task force / EDPB. The institutional framework thus blended national enforcement discretion with EU‑level cooperation mechanisms and highlighted the cross‑border enforcement dynamics typical of digital platforms operating in the EU.
Key Focus Areas
Provvedimento n.114 emphasized several focus areas: (1) Transparency and information duties — the Garante required a clear, accessible notice explaining the categories of data used for model training, processing logic and the rights of data subjects; (2) Legal basis and accountability — the controller had to remove references to 'contract' as a legal basis for training and instead specify consent or legitimate interest with associated accountability measures, and provide mechanisms that permit the exercise of the right to object; (3) Rights of non‑users — the decision explicitly recognized remedies for individuals whose data may have been included in training without their active interaction with the service; (4) Age verification and protection of minors — an immediate age gate at restart and a plan for robust verification were required; (5) Remedies and redress — tools for rectification, deletion and opposition must be provided and made easily accessible; (6) Public awareness — a non‑promotional public information campaign was mandated to notify potentially affected individuals. The Garante set concrete deadlines and required the company to report the measures taken within specified timelines. For official Garante communications and the text of subsequent updates, see Garante – OpenAI collaborates, April updates.
Implementation Framework
Implementation under the provvedimento was pragmatic and time‑bound. The Garante ordered that items 1–7 (core transparency, rights mechanisms, immediate age gate, removal of contractual basis wording and other immediate safeguards) be fully implemented by 30 April 2023. Secondary items — submitting an age‑verification plan by 31 May 2023 and implementing verification mechanisms by 30 September 2023 — allowed staged technical deployment while obliging the company to present concrete roadmaps. The Garante required the company to provide confirmations and documentary evidence of the steps taken. The authority retained the right to verify the effectiveness of technical measures and to adopt urgent additional steps if implementation was inadequate. The Garante’s public notices set out these timelines in detail; see the Garante press releases at Garante – OpenAI reopens with commitments.
Monitoring and Evaluation
The Garante made continued oversight explicit: the authority would assess the adequacy and sufficiency of measures, retain the ability to verify technical implementations, and continue the formal investigatory procedure (istruttoria). Reporting obligations required the controller to communicate progress and to supply the authority with the documentation of measures taken by the specified deadlines. The Garante also signalled cooperation with peer authorities through the EDPB task force, enabling cross‑checking of evidence and coordinated action where processing affected residents across EU Member States.
Penalties, Liability, and Appeals
The provvedimento invoked the Garante's enforcement remit under GDPR Article 58 and linked potential sanctions to breaches of Article 83 (administrative fines). The Garante explicitly warned that failure to respond to Article 58 requests may trigger penalties as per Article 83(5)(e) GDPR. Separately, the authority preserved the right to impose other measures (temporary or definitive) at the conclusion of the formal inquiry. The provvedimento explained judicial remedies: parties may challenge the administrative measure before national ordinary courts (appeal terms specified in the measure). For the Garante's statements on sanctions and procedural rights, consult Garante – provvedimento (print).
Relationship to Other Instruments
Provvedimento n.114 sits within the GDPR enforcement architecture and interacts with Italian data protection legislation (d.lgs. 196/2003 as amended). It also formed part of a broader set of national supervisory actions in spring 2023 targeting generative AI and data practices (including separate inquiries into other chatbot providers). Additionally, the Garante's actions informed and were informed by EU‑level coordination via the EDPB and by evolving discussions on the EU AI Act, though the provvedimento was based on GDPR enforcement powers rather than AI Act rules (which were under negotiation at that time). The measure functioned as a supervisory bridging instrument between immediate protective action and longer‑term regulatory frameworks for AI.
International Alignment
The Garante explicitly engaged with other EU supervisory authorities through the EDPB task force to ensure coordinated oversight of cross‑border AI services and to share technical and legal assessments. The action signalled regulator expectations internationally: transparency over model training, lawful legal bases for large‑scale data processing, demonstrable age‑verification mechanisms, and meaningful access and redress routes for data subjects. The Garante’s communiqué highlights cooperation with OpenAI representatives and with EU counterparts; see the Garante press note on cooperation and commitments at Garante – OpenAI collaborates.
Implementation Timeline
| Date | Milestone / Requirement | Reference |
|---|---|---|
| 2023-03-30 | Emergency limitation adopted (Provvedimento n.112) that restricted processing by ChatGPT in Italy. | Garante – 30 Mar 2023 block |
| 2023-04-05 | Teleconference meeting between OpenAI and the Garante; OpenAI expressed willingness to cooperate. | Garante – meeting announcement |
| 2023-04-11 | Provvedimento n.114 issued: conditional suspension of prior limitation subject to compliance with prescriptions 1–9. | Garante – Provvedimento 11 Apr 2023 |
| 2023-04-30 | Deadline to fully implement core prescriptions 1–7 and to report actions taken. | Garante – deadlines |
| 2023-05-15 | Deadline to launch agreed non‑promotional public information campaign. | Garante – prescriptions |
| 2023-05-31 | Deadline to submit an age‑verification plan to the Garante. | Garante – prescriptions |
| 2023-09-30 | Implementation deadline for a robust age‑verification system per plan. | Garante – prescriptions |
| 2023-04-28 | Garante published follow‑up communications noting progress and platform reopening subject to measures. | Garante – 28 Apr 2023 communiqué |
Compliance Checklist
| Requirement | Compliant (Yes/No/Partial) | Notes / Evidence |
|---|---|---|
| Publish a detailed, accessible privacy notice covering data used for training and processing logic | Yes / Partial | Notice must include information for users and non‑users; the Garante required publication on the company site. See Provvedimento n.114. |
| Provide an online instrument for non‑users to exercise the right of opposition | Yes / Partial | Garante required an accessible opt‑out/objection mechanism if legitimate interest is invoked. |
| Remove references to 'contract' as legal basis for training; state consent or legitimate interest and accountability measures | Yes / Partial | Garante insisted on explicit legal basis and accountability description. |
| Implement an age gate at first access after reactivation | Yes | Immediate measure required by the Garante pending stronger verification controls. |
| Submit age verification action plan by 31 May 2023 | Yes / Partial | Plan required; full implementation due by 30 Sep 2023. |
| Run a non‑promotional national information campaign by 15 May 2023 | Yes / Partial | Campaign contents to be agreed with the Garante. |
| Provide tools for rectification and deletion (users & non‑users) | Yes / Partial | Accessible mechanisms required, with particular focus on algorithmic training data. |
Sources and References
The Italian Data Protection Authority's order requires OpenAI to implement significant privacy safeguards for its ChatGPT service, affecting both users and non-users whose data may have been used for training.
This order specifically targets OpenAI L.L.C. as the data controller for its ChatGPT service in Italy. It impacts not only individuals directly using ChatGPT but also anyone whose personal data might have been included in the vast datasets used to train the underlying artificial intelligence models.
OpenAI was given strict deadlines to address several key areas. By April 30, 2023, it had to provide clear, accessible privacy notices explaining what data is used for training and how it's processed. It also needed to remove any claims that 'contract' is a valid legal basis for this training, instead relying on consent or legitimate interest. An immediate age gate was required to prevent children under 13 from accessing the service without parental consent. Furthermore, OpenAI must offer easily accessible tools for both users and non-users to exercise their rights, such as objecting to data processing or requesting data rectification and deletion.
While an initial emergency block on ChatGPT in Italy was issued on March 30, 2023, this April 11 order conditionally suspended it, allowing the service to resume if OpenAI met these commitments. Beyond the April 30 deadline for core items, OpenAI also had to launch a public information campaign by May 15, submit a plan for robust age verification by May 31, and fully implement that system by September 30, 2023.
Failure to comply could lead to the reactivation of the initial service limitation and significant administrative fines under the European Union's General Data Protection Regulation (GDPR), potentially reaching millions of euros. A key takeaway for product teams is the explicit requirement to provide mechanisms for *non-users* to object to their data being processed or to request its deletion. This means companies must consider how to identify and manage data subject rights for individuals who have never directly interacted with their service but whose data might be part of their training corpus.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 9 marked completePlain-English obligations under Italy - Temporary Order Against ChatGPT. Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Apr 30, 2023
Applies to: OpenAI as the data controller of ChatGPT.
“required a clear, accessible notice explaining the categories of data used for model training, processing logic and the rights of data subjects”
- #2Critical⏰ Apr 30, 2023
Applies to: OpenAI as the data controller of ChatGPT.
“controller had to remove references to 'contract' as a legal basis for training and instead specify consent or legitimate interest”
- #3Critical⏰ Apr 30, 2023
Applies to: OpenAI as the data controller of ChatGPT.
“provide mechanisms that permit the exercise of the right to object”
- #4Critical⏰ Apr 30, 2023
Applies to: OpenAI as the data controller of ChatGPT.
“an immediate age gate at restart”
- #5Critical⏰ Apr 30, 2023
Applies to: OpenAI as the data controller of ChatGPT.
“tools for rectification, deletion and opposition must be provided and made easily accessible”
- #6Critical⏰ May 15, 2023
Applies to: OpenAI as the data controller of ChatGPT.
“a non‑promotional public information campaign was mandated to notify potentially affected individuals.”
- #7Critical⏰ May 31, 2023
Applies to: OpenAI as the data controller of ChatGPT.
“submitting an age‑verification plan by 31 May 2023”
- #8Critical⏰ Sep 30, 2023
Applies to: OpenAI as the data controller of ChatGPT.
“implementing verification mechanisms by 30 September 2023”
- #9Critical
Applies to: OpenAI as the data controller of ChatGPT.
“required the company to report the measures taken within specified timelines.”
Related Regulations
Provvedimento n.329 (20 May 2024) - Nota informativa su web scraping per finalità di addestramento di intelligenza artificiale generativa (Garante per la protezione dei dati personali)
Italy89% similar
Disegno di legge n.1146 - Disposizioni e deleghe al Governo in materia di intelligenza artificiale (Parliamentary bill on AI)
Italy88% similar
Data Protection Commission Guidance on AI and Large Language Models
Ireland87% similar
Explanatory Note on Chatbots (ChatGPT Example) (Sohbet Robotları (ChatGPT Örneği) Hakkında Bilgi Notu)
Turkey87% similar
Buenos Aires Province Generative AI Guidelines
Argentina86% similar
© Regulations.AI — created on 13-Jun-2026