ChatGPT became unavailable to users in Italy after the country’s data protection authority ordered OpenAI to stop processing Italians’ data for the service. OpenAI said it had disabled access at the authority’s request, while maintaining that it believed the service complied with privacy laws.
Access stopped as an investigation began
The authority, known as the Garante, announced an investigation into suspected breaches of the European Union’s General Data Protection Regulation (GDPR). It said it was concerned that OpenAI had unlawfully processed Italians’ data.
OpenAI’s notice to people trying to reach ChatGPT from an Italian IP address said the company regretted the suspension. It also said it would engage with the Garante with the goal of restoring access as soon as possible.
The company said it would refund users in Italy who had purchased ChatGPT Plus the previous month. It also paused subscription renewals there so users would not be charged while the service was suspended.
The regulator’s concerns reach beyond access
The Garante’s investigation raised questions about how data was gathered and used to train ChatGPT. The article reports that OpenAI did not appear to have informed people whose online information was used, including data collected from internet forums. It also said the company had not been entirely open about the data it processed, particularly for GPT-4.
Information being publicly available online does not, by itself, settle the questions raised in the article. GDPR transparency principles may still require people to be informed about how their data is processed. That puts data collection and disclosure at the center of the dispute.
The Garante also pointed to the absence of a system to prevent minors from accessing the technology. It cited the lack of age verification as a child safety concern, including the possibility of inappropriate access.
Accuracy was another issue. Generative AI chatbots can sometimes produce false information about named individuals, a behavior AI makers call “hallucinating.” The article notes that GDPR gives individuals rights over their information, including a right to rectification of erroneous information. It was unclear whether OpenAI had a way for people to ask the chatbot to stop making false claims about them.
What the suspension meant for users
At the time, OpenAI appeared to be using a geoblock: access was restricted based on a user’s Italian IP address. The article described a VPN connecting through a non-Italian IP address as a potential workaround. But accounts originally registered in Italy might remain inaccessible, and users seeking to get around the block might need a new account created through a non-Italian IP address.
That distinction mattered because a regional access block did not answer the broader questions in the investigation. Users faced an immediate service interruption, while the regulator’s concerns involved how personal data was handled, how the system worked for people mentioned in its answers, and what protections existed for minors.
Wider implications under European privacy rules
The article describes GDPR as requiring data protection by design and default. In plain terms, privacy protections are expected to be built into systems that process personal data from the start. The Garante’s concerns therefore touched on the service’s design and operating practices, not just the wording of a privacy notice.
For confirmed GDPR breaches, penalties can reach 4% of a data processor’s annual global turnover or €20 million, whichever is greater. The article also notes that OpenAI had no main establishment in the EU. As a result, data protection authorities in other EU member countries could choose to investigate ChatGPT and issue fines for breaches found within their own jurisdictions.
OpenAI said it believed ChatGPT complied with GDPR and other privacy laws, and that it would work with the Garante to restore access. The investigation left the outcome unsettled. The case put a practical question before AI providers: how to make data use, accuracy controls and safeguards for minors fit within established privacy obligations.