Data Protection and Privacy 2025

ITALY Law and Practice Contributed by: Paolo Balboni, Luca Bolognini, Nicolò Maria Salvi and Davide Baldini, ICT Legal Consulting

1.4 Data Protection Fines in Practice One of the Most Significant Administrative Proceedings of 2024 Involved OpenAI In December 2024, the Italian Supervisory Authority concluded an investigation into Ope - nAI, identifying several GDPR violations relat - ed to the ChatGPT service. These violations included the processing of personal data with - out a proper legal basis, a lack of transparency towards users, and the absence of effective mechanisms for age verification, which exposed minors to inappropriate content. As a result, the Italian Supervisory Authority imposed a fine of EUR15 million on OpenAI and mandated a six-month public information cam - paign across various media to raise awareness about how ChatGPT operates and the rights of data subjects. Furthermore, given that the com - pany established its European headquarters in Ireland during the investigation, the Authority, in compliance with the “one-stop shop” rule, referred the case to the Irish Data Protection Commission (DPC), which became the lead supervisory authority under the GDPR, to con - tinue the investigation regarding any ongoing violations that persisted prior to the establish - ment of the European headquarters. Additional Proceedings by the Italian Supervisory Authority Another series of proceedings conducted by the Italian Supervisory Authority focused on tele - marketing and teleselling activities, culminating in the imposition of substantial fines on com - panies in the telecommunications and energy supply sectors. Within this context, a notable sanction was imposed on Enel Energia but was subsequently annulled by the court. Following legal proceedings, the Rome Tribunal highlight - ed procedural shortcomings in the Italian Super -

of the matter under examination. The addressee of the notice may also request a hearing before the GPDP. Failure to submit written counterarguments or a request for a hearing shall not prejudice the continuation of the proceedings. Decision Where necessary, the board of the GPDP, by its own resolution, shall adopt the corrective and sanctioning measures referred to in Article 58(2) of the GDPR (in the case of an administrative pecuniary sanction, the quantum is calculated on the basis of the criteria indicated by Article 83 of the GDPR). The decision is notified to the par - ties by the department, service or other organi - sational unit that has supervised the preliminary investigation. Appeal Against Measures of the GPDP Under penalty of inadmissibility, an appeal against the measures adopted by the GPDP must be lodged within 30 days from the date of communication of the decision or within 60 days if the appellant resides abroad, with the ordinary court of the place where the data con - troller resides, or with the court of the place of residence of the data subject. At the time of the appeal, it is also possible to request the court to suspend the enforceability of the contested decision. The so-called “work ritual” applies to the judi - cial procedure, and the sentence that defines the judgment is not appealable before the judge and may prescribe the necessary measures and compensation for damages.

225 CHAMBERS.COM

Powered by