Data Protection and Privacy 2025

ITALY Trends and Developments Contributed by: Paolo Balboni, Luca Bolognini, Davide Baldini and Nicolò Maria Salvi, ICT Legal Consulting

The GPDP inquiry into Clearview AI revealed that the company processed personal data, including biometric and geolocation information, unlawfully without a proper legal basis. In par - ticular, the legitimate interest leveraged by the US-based company as the relevant legal basis for the processing was not suitable for the pro - cessing of biometric data, which qualifies as a special category of personal data under Article 9 GDPR so that its processing is generally pro - hibited, save where specific exceptions provided by paragraph 2 of Article 9 GDPR apply. Moreo - ver, Clearview AI violated several fundamental principles of the GDPR, such as lacking trans - parency in adequately informing users, exceed - ing the intended purposes for processing users’ data made available online, and neglecting to establish a data storage period. Consequently, Clearview AI is infringing on the freedoms of data subjects, including their right to privacy, person - al data protection and non-discrimination. Through web scraping, Clearview AI has amassed a database containing billions of facial images sourced globally from public web outlets like media platforms, social media, and online videos. By processing such personal data by means of advanced algorithms, Clearview AI has been able to provide a refined search service allowing the creation of profiles based on bio - metric data extracted from these images. These profiles can then be augmented with additional information, such as image tags, geolocation, and so on. As a result of these violations, the GPDP imposed a EUR20 million fine on Clearview AI and mandated the deletion of data pertaining to individuals residing in Italy. The authority also prohibited any further collection and processing of data through Clearview AI’s facial recognition system. Additionally, Clearview AI was instruct -

ed by the Italian SA to appoint a representative in the EU pursuant to Article 27 GDPR, facilitating the exercise of data subject rights, alongside (or

in lieu of) the US-based controller. Enforcement action against OpenAI

In late March 2023, only a few months after its launch, the Garante identified several violations of the GDPR and Italian Data Protection Law regarding the famous and widespread generative AI system “ChatGPT”. According to the GPDP, OpenAI failed to demonstrate the presence of a valid legal basis for collecting and processing personal data for the purposes of training Chat - GPT, and the information provided to users and individuals whose data was used for training the generative AI system was incomplete. Moreover, individuals whose data was used for training the AI system had no easy way to exercise their data protection rights, including the rights of access, rectification and objection. Interestingly, the GPDP also noted that ChatGPT’s responses to users’ prompts often deviated from reality (so- called hallucinations), thereby violating the accu - racy principle established by the GDPR when such responses concerned another individual. The ChatGPT case underscores, once again, the GPDP’s scrutiny of data processing concerning children: in this respect, the authority questioned whether the platform’s outputs might result in inappropriate responses for children, even if the service is purportedly aimed at users above the age of thirteen, as stated in OpenAI’s terms of service. As a result, the GPDP required OpenAI to implement a suitable age verification system. On 28 April 2023, the Garante lifted the ban, finding that the measures adopted by OpenAI adequately addressed the data protection issues raised by the authority and which underpinned the ban. Such measures included updating ChatGPT’s privacy policy, implementing ade -

241 CHAMBERS.COM

Powered by