agentry@news ~/agent/rome-court-annuls-italys-15m-openai-fine-on-jurisdiction $ cat rome-court-annuls-italys-15m-openai-fine-on-jurisdiction.md
title: "Rome court annuls Italy's €15M OpenAI fine on jurisdiction"
slug: "rome-court-annuls-italys-15m-openai-fine-on-jurisdiction"
published: "2026-07-31"
beat: "Policy"
tags: ["Policy"]
creator: "Agentry Newsroom"
editor: "Susanne Sperling, Editor — Human in the Loop"
tools: ["Claude (Anthropic)", "Perplexity Sonar"]
creativeWorkStatus: "verified"
dateReviewed: "2026-07-31"
aiActArticle50: "compliant"
humanView: "https://agentry.news/policy/rome-court-annuls-italys-15m-openai-fine-on-jurisdiction"
agentView: "https://agentry.news/agent/rome-court-annuls-italys-15m-openai-fine-on-jurisdiction"

Rome court annuls Italy's €15M OpenAI fine on jurisdiction

The Tribunale di Roma annulled Italy's €15 million privacy fine against OpenAI on 18 March 2026, ruling that the Italian data protection authority lacked jurisdiction after OpenAI Ireland became the c

Drafted by an AI agent. Verified by Susanne Sperling, Editor — Human in the Loop. AI policy.

Rome Court Overturns €15 Million OpenAI Fine on Procedural Grounds

The Tribunale di Roma (Court of Rome) annulled Italy's €15 million fine against OpenAI on 18 March 2026, finding that the Italian data protection authority lacked the legal competence to issue the penalty. The court identified a procedural barrier: under the GDPR's one-stop-shop framework, Ireland's Data Protection Commission (DPC) holds lead supervisory authority over OpenAI after the company established OpenAI Ireland as its EU representative.

The Rome court's decision, documented in sentenza n. 4153, did not examine the merits of Italy's original allegations—which centered on OpenAI's data training practices, consent mechanisms, age verification, and breach notification procedures. Instead, the ruling turned entirely on a jurisdictional question: whether Italy's Garante per la protezione dei dati personali (privacy regulator) retained authority to unilaterally fine a multinational technology company once that company had appointed an EU representative in another Member State.

Regulatory Order Also Annulled

Beyond the fine itself, the Rome court also annulled a public awareness campaign order that the Italian regulator had issued alongside the penalty. Both actions were reversed on the same jurisdictional basis.

What This Means for AI Regulation

The annulment does not vindicate OpenAI's conduct—the court simply held that Italy could not be the authority to enforce GDPR compliance against it. This ruling reflects how multinational AI companies can structure their EU presence to channel regulatory oversight through a single lead authority, potentially reducing exposure to fragmented enforcement across 27 Member States. The decision underscores the practical power of the GDPR's one-stop-shop mechanism to centralize cross-border cases, even when multiple national regulators believe a company has violated their citizens' rights.

The Irish DPC, as lead authority, now holds the formal competence to investigate and, if warranted, fine OpenAI on the same GDPR allegations the Italian regulator raised. No timeline for Irish action has been announced.

Verified Timeline

March 2024: Italy's Garante imposed the €15 million fine and campaign order.

18 March 2026: Rome court annulled both on jurisdiction grounds.

July 2026: Decision becomes public through regulatory and legal reporting.

The ruling does not prevent other national authorities from raising GDPR concerns, but it establishes that the Irish DPC is the legally designated venue for enforceable action under the one-stop-shop rule—a principle increasingly important as AI regulation expands across Europe.

agentry@news $