Desk Trials

ARCHIVE / Setup & friction

Italy's privacy regulator made OpenAI change ChatGPT to return

Three Garante documents show what the regulator found, what it demanded, and what it confirmed OpenAI changed before Italian access resumed.

Preserved retrospective record

Historical source and event dates are not site publication dates. Product plans, policies and availability may have changed since retrieval.

Visual for this record: Italy's privacy regulator made OpenAI change ChatGPT to return
Visual published by garanteprivacy.it, shown for identification of the record. Credit: garanteprivacy.itPreserved source visual · owner review pending

The setup

On 30 March 2023, Italy's data protection authority, the Garante, used its emergency GDPR power to order OpenAI to stop processing Italian residents' data through ChatGPT, effective immediately. The order is not a ruling on the merits; it is a provisional measure a data authority can issue under GDPR Article 58 when it judges ongoing processing poses a likely risk of serious harm, ahead of any final decision.

What the documents show

The order lists specific findings, not a general finding that OpenAI broke the law: no information notice for users or for people whose data had been collected to build the model; no adequate legal basis for using personal data to train the algorithms; no mechanism to verify a user's age despite terms restricting access to people 13 and older; and outputs that could misstate facts about real people. A follow-up order dated 11 April 2023 suspended the limitation only conditionally, tying the suspension to nine prescribed measures due by set deadlines — a published notice on the processing logic, a shift in the stated legal basis for training from contract to consent or legitimate interest, and two opt-out routes, one for accountholders and one for people whose data reached the system without their ever using it.

The friction

The orders disclose their own friction. An age gate at first access is a lesser thing than the full age-verification system the Garante also demanded, for which it set a separate, later timeline: a plan due 31 May 2023, implementation due 30 September 2023. The 11 April order treats consent and legitimate interest as alternative legal bases without settling which governs which processing, leaving that for further inquiry. Building a consent-based legal ground for training a general-purpose model on a regulator's deadline is a design change with real engineering and legal cost, not a settings toggle.

What changed in the work

The Garante's own 28 April 2023 press release records ChatGPT made accessible again to people in Italy, describing what it found on review: an expanded privacy notice available before signup, opt-out forms for accountholders and non-users, an 18-plus or 13-plus-with-parental-consent gate, and a welcome page for Italian users explaining the changes. That is the regulator's account of the fix, not OpenAI's own statement in its own words. The visible fix took under a month; the verification system the authority actually wanted was given until autumn.

  • Does your vendor publish a notice describing the logic behind its automated processing, not only that data is processed?
  • If a regulator ordered a temporary halt tomorrow, could you name the legal basis your vendor uses for training on your data?
  • Is there a working, separate opt-out path for people whose data reached the system without their ever having used it?

None of this proves ChatGPT safe or unsafe elsewhere; the finding was specific to what the Garante saw in March 2023 under Italian and EU law. The record establishes a concrete sequence — finding, conditional suspension, confirmed change — worth checking against a vendor's current notices rather than assuming a past fix traveled everywhere else.

Sources & verification

Preserved from the earlier archive. These sources have not all been freshly rechecked for this expansion.

  1. Provvedimento del 30 marzo 2023 [9870832] (Provisional limitation on ChatGPT processing)Source date: 2023-03-30 · Retrieved: 2026-09-16

    The Garante's own emergency order and the specific findings (no notice, no legal basis for training, no age verification, inaccurate outputs) that triggered it.

  2. Provvedimento dell'11 aprile 2023 [9874702] (Conditional suspension of the limitation)Source date: 2023-04-11 · Retrieved: 2026-09-16

    The nine prescribed measures and deadlines OpenAI had to meet, and that the suspension was conditioned on completing them.

  3. ChatGPT: OpenAI ha reso nuovamente accessibile il servizio in Italia [9881490]Source date: 2023-04-28 · Retrieved: 2026-09-16

    The regulator's own confirmation that ChatGPT was restored to Italian users and its account of the specific changes OpenAI made.

Continue the workflow

  1. Audit knowledge-base access with allowed and denied tests

    A minimum-rights test for a small team that checks both useful access and denied access across a shared knowledge base.

  2. Calculate the total cost of a workflow, not just the subscription

    Compare a manual process and an automated alternative without relying on volatile plan prices.

  3. Run a vendor exit drill before the exit is urgent

    Find out whether a team can leave a workflow vendor without losing data, behavior, access, or business continuity.

  4. GitLab's public handbook splits AI rules by team, not one policy

    Two public GitLab handbook pages, not the security team's gated one, show how Support and Engineering actually restrict AI use on company data.