OpenAI Fined €15M for ChatGPT Data Processing

Dec 2024 · €15M fine

By Karim El Labban · ZERO|TOLERANCE

OpenAI Fined EUR 15M for ChatGPT Data Processing

The Italian Data Protection Authority (Garante per la protezione dei dati personali) fined OpenAI EUR 15 million in December 2024 for multiple GDPR violations related to ChatGPT's processing of personal data for AI model training and its failure to implement adequate age verification mechanisms.

The enforcement action concluded an investigation that began in March 2023 when the Garante temporarily banned ChatGPT in Italy--the first regulatory action against a generative AI service in Europe.

01

KEY FACTS

  • .What: OpenAI processed EU personal data to train ChatGPT without valid legal basis.
  • .Who: EU residents whose data was scraped, plus minors bypassing weak age verification.
  • .Data Exposed: Scraped personal data, user conversations, account details, and minors' interactions.
  • .Outcome: Italian DPA fined OpenAI EUR 15M and ordered a public information campaign.
02

WHAT WAS EXPOSED

  • .Personal data of EU residents contained within internet content scraped to build ChatGPT's training dataset
  • .ChatGPT conversation data from EU users, including prompts containing personal information and health queries
  • .User account information collected during registration without adequate age verification
  • .Inaccurate personal information generated by ChatGPT's "hallucination" tendency about real individuals
  • .Minor users' interaction data processed without parental consent
03

REGULATORY ANALYSIS

The primary finding concerned absence of a valid legal basis under Article 6 for processing personal data in web-scraped training data.

Contractual necessity (Article 6(1)(b)) was rejected because training an AI model on user data is not necessary for providing ChatGPT. Legitimate interest (Article 6(1)(f)) failed the balancing test because data subjects had no reasonable expectation their data would train a commercial AI system.

Article 5(1)(a) transparency violations were found. Age verification relied solely on self-declared date of birth with no actual verification. The EUR 15 million fine considered OpenAI's cooperation and the measures subsequently implemented.

04

SOURCES

Garante Provision No. 10085022, Garante Provision No. 9870832 (temporary ban), EDPB ChatGPT Taskforce Report, GDPR Articles 5, 6, 8, 13, 14, 25, 35

RELATED ANALYSIS

USPTO GovDelivery Scam: How Fraudsters Weaponize Real .gov Emails to Steal From Trademark Filers
Apr 1, 2026 · 77K+ victims · 60+ domains · First-person investigation
Free Mobile Fined EUR 42M After 24.6 Million Customer Records Stolen
Jan 16, 2026 · EUR 42M fine
Illuminate Education: FTC Action Over 10.1 Million Student Records Breach
Dec 1, 2025 · $5.1M settlement
Capita Fined £14M After Black Basta Ransomware Exposes 6.6M Records
Oct 1, 2025 · £14M fine
SHEIN Fined €150M for Cookie Consent Violations
Jan 23, 2025 · €150M fine
MORE REGULATORY ENFORCEMENT →