GDPR contextITannulled
Italian authority fines OpenAI 15 million euros
- Body:
- Garante per la protezione dei dati personali (supervisory authority)
- Reference:
- Garante, docweb 10085432
- Decided:
- 20 December 2024
- Recorded by us:
- 13 August 2026
The Garante closed its ChatGPT investigation with a 15 million euro fine for training on personal data without an appropriate legal basis and inadequate information. The Court of Rome annulled the fine on 18 March 2026: after OpenAI established itself in Ireland, jurisdiction ran through the one-stop-shop mechanism, and the court never reached the substantive allegations. Since 2 August 2025, GPAI models carry their own documentation and transparency duties under the AI Act, enforced by the AI Office rather than national privacy authorities.
What this ruling does to which provision
illustrates: Article 53: GPAI model providers
A fine over training a model on personal data, under the GDPR, later annulled on the question of jurisdiction. The documentation and transparency duties for GPAI models sit in Article 53 of the AI Act and are enforced by the AI Office; this decision says nothing about how they are to be read.
Garante, besluit van 2 november 2024, bekendgemaakt op 20 december 2024, docweb 10085432
Open the primary source (Garante, besluit 2 november 2024, bekendgemaakt 20 december 2024)
praxikon:eu:gdpr:ruling:it-garante-openai-2024
GDPR contextNLfinal
Dutch DPA fines Clearview AI 30.5 million euros
- Body:
- Autoriteit Persoonsgegevens (AP) (supervisory authority)
- Reference:
- Autoriteit Persoonsgegevens, boetebesluit Clearview AI
- Decided:
- 3 September 2024
- Recorded by us:
- 13 August 2026
The Dutch DPA fined Clearview AI 30.5 million euros for building an illegal database of billions of facial images, including of Dutch citizens. The DPA also explicitly warned that use of Clearview by Dutch organisations is prohibited. This scraping practice now also falls under the Article 5 prohibition of the AI Act.
What this ruling does to which provision
illustrates: Article 5: prohibited practices
The Dutch authority fined the same database and additionally warned that use by Dutch organisations is prohibited. That warning rests on the GDPR; the Article 5 prohibition on untargeted scraping of facial images in the AI Act stands separately from it.
Autoriteit Persoonsgegevens, boetebesluit bekendgemaakt op 3 september 2024
Open the primary source (Autoriteit Persoonsgegevens, boetebesluit, bekendgemaakt 3 september 2024)
praxikon:eu:gdpr:ruling:nl-ap-clearview-2024
GDPR contextFRfinal
CNIL fines Amazon France Logistique 32 million euros for employee monitoring
- Body:
- Commission Nationale de l’Informatique et des Libertés (CNIL) (supervisory authority)
- Reference:
- CNIL SAN-2023-021
- Decided:
- 27 December 2023
- Recorded by us:
- 13 August 2026
The CNIL fined Amazon France Logistique 32 million euros for an excessively intrusive system that tracked warehouse workers’ activity via scanners down to the second. Under the AI Act, algorithmic monitoring of workers is a high-risk use (Annex III, employment), with obligations applying from 2 December 2027.
What this ruling does to which provision
illustrates: Annex III: high-risk AI
Algorithmic monitoring of warehouse workers, decided under the GDPR. Under the AI Act this kind of use falls in the employment category of Annex III, with obligations applying from 2 December 2027; this decision concerns none of those obligations.
CNIL, besluit SAN-2023-021 van 27 december 2023
Open the primary source (CNIL, besluit SAN-2023-021)
praxikon:eu:gdpr:ruling:fr-cnil-amazon-2023
GDPR contextITwithdrawn
Italian authority imposes temporary limitation on ChatGPT
- Body:
- Garante per la protezione dei dati personali (supervisory authority)
- Reference:
- Garante, docweb 9870832
- Decided:
- 30 March 2023
- Recorded by us:
- 13 August 2026
The Garante imposed a temporary processing limitation on OpenAI for ChatGPT over the lack of a legal basis and of age verification. The limitation was lifted at the end of April 2023 after OpenAI took measures. The case showed early on that European authorities can directly affect generative AI; the transparency and information duties for such systems now sit in Article 50 of the AI Act.
What this ruling does to which provision
illustrates: Article 50: transparency
A temporary processing limitation on a generative system, imposed and later lifted under the GDPR. The transparency and information duties for such systems sit in Article 50 of the AI Act; this measure does not rest on it.
Garante, maatregel van 30 maart 2023, docweb 9870832
Open the primary source (Garante, maatregel 30 maart 2023)
praxikon:eu:gdpr:ruling:it-garante-chatgpt-2023
GDPR contextELfinal
Greek authority fines Clearview AI 20 million euros
- Body:
- Hellenic Data Protection Authority (supervisory authority)
- Reference:
- HDPA 35/2022
- Decided:
- 13 July 2022
- Recorded by us:
- 13 August 2026
The Greek authority fined Clearview AI 20 million euros for processing biometric data of Greek citizens without a lawful basis. The same practice, building a facial recognition database through scraping, now falls under the Article 5 prohibition of the AI Act.
What this ruling does to which provision
illustrates: Article 5: prohibited practices
A second authority, the same practice, the same outcome under the GDPR. That two authorities reached a fine independently says something about the practice and nothing about how Article 5 of the AI Act is to be read.
HDPA, besluit 35/2022 van 13 juli 2022
Open the primary source (HDPA, besluit 35/2022, 13 juli 2022)
praxikon:eu:gdpr:ruling:el-hdpa-clearview-2022
GDPR contextITfinal
Italian authority fines Clearview AI 20 million euros
- Body:
- Garante per la protezione dei dati personali (supervisory authority)
- Reference:
- Garante, docweb 9751362
- Decided:
- 9 March 2022
- Recorded by us:
- 13 August 2026
The Garante fined Clearview AI 20 million euros for collecting facial images from the internet without a legal basis to build a biometric search database. Untargeted scraping of facial images to build facial recognition databases has been explicitly prohibited under Article 5 of the AI Act since 2 February 2025.
What this ruling does to which provision
illustrates: Article 5: prohibited practices
Untargeted collection of facial images for a biometric search database, decided under the GDPR. The same practice has been prohibited in as many words by Article 5 of the AI Act since 2 February 2025; this decision is not about that provision.
Garante, besluit van 10 februari 2022, docweb 9751362
Open the primary source (Garante, besluit 10 februari 2022)
praxikon:eu:gdpr:ruling:it-garante-clearview-2022
GDPR contextHUfinal
Hungarian authority fines bank for AI voice analysis of customer calls
- Body:
- Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) (supervisory authority)
- Reference:
- NAIH-85-3/2022
- Decided:
- 8 February 2022
- Recorded by us:
- 13 August 2026
The NAIH imposed a fine of 250 million forints (around 700,000 euros) on a bank that automatically analysed customer service calls for emotion with AI, without a valid legal basis and without informing customers. Emotion recognition in the workplace and in education now falls under the Article 5 prohibition of the AI Act; in customer contact the Article 50 transparency duties apply.
What this ruling does to which provision
illustrates: Article 5: prohibited practices
Emotion recognition from speech, decided under the GDPR. The AI Act prohibits emotion recognition in the workplace and in education in Article 5; this decision concerned customer contact and rests on a different instrument, so it does not interpret Article 5.
NAIH-85-3/2022, boetebesluit over geautomatiseerde emotieanalyse van klantgesprekken
illustrates: Article 50: transparency
The customers did not know an AI analysis ran on their call. Under the AI Act the information duty for such systems sits in Article 50; this decision rests on the GDPR and says nothing about how Article 50 is to be read.
NAIH-85-3/2022, onderdeel over het niet informeren van de betrokken klanten
Open the primary source (NAIH besluit NAIH-85-3/2022)
praxikon:eu:gdpr:ruling:hu-naih-budapest-bank-2022