title: "Rome court annuls Italy's €15M OpenAI GDPR fine on jurisdiction ground" slug: "rome-court-annuls-italys-15m-openai-gdpr-fine-on-jurisdiction-grounds" published: "2026-07-29" beat: "Policy" tags: ["Policy"] creator: "Agentry Newsroom" editor: "Susanne Sperling, Editor — Human in the Loop" tools: ["Claude (Anthropic)", "Perplexity Sonar"] creativeWorkStatus: "verified" dateReviewed: "2026-07-29" aiActArticle50: "compliant" humanView: "https://agentry.news/policy/rome-court-annuls-italys-15m-openai-gdpr-fine-on-jurisdiction-grounds" agentView: "https://agentry.news/agent/rome-court-annuls-italys-15m-openai-gdpr-fine-on-jurisdiction-grounds"
A Rome court on 18 March 2026 struck down Italy's €15 million penalty against OpenAI, ruling the Italian data protection authority lacked competence to issue the fine after Ireland's regulator became
Drafted by an AI agent. Verified by Susanne Sperling, Editor — Human in the Loop. AI policy.
The Court of Rome annulled Italy's €15 million fine against OpenAI on 18 March 2026, holding that the Italian Data Protection Authority (Garante per la protezione dei dati personali) lacked jurisdiction to issue a final cross-border penalty The Leveraged Years. The ruling, delivered in Case R.G. 4785/2025, did not address the merits of the original GDPR allegations but instead turned on a procedural question of regulatory authority LinkedIn.
The Italian Garante had imposed the €15 million penalty in November or December 2024, citing alleged violations of GDPR rules governing AI training practices, transparency, age verification, and breach notification. However, the Rome court found that once OpenAI Ireland established itself as the company's EU representative, the one-stop-shop mechanism under GDPR Article 56 placed lead supervisory authority with Ireland's Data Protection Commission (DPC), not Italy LinkedIn. Under this mechanism, when a non-EU controller or processor has a single EU establishment, the regulator in that Member State becomes the lead authority for cross-border processing cases. The Rome court concluded the Italian authority therefore could not unilaterally impose a final enforcement decision Ops Intel.
The court also annulled a companion public awareness campaign order that had been issued alongside the fine The Leveraged Years.
Critically, the Rome judgment does not resolve whether OpenAI's actual practices—its training datasets, consent mechanisms, age-gating, or incident response—complied with the GDPR Economic Times. The annulment is purely procedural. This leaves the substantive GDPR allegations potentially subject to enforcement by the Irish DPC under its lead authority role, or to investigation and decision by Italy through a coordinated process under GDPR's consistency mechanism.
The decision reflects emerging tensions in EU AI regulation: national authorities have begun issuing unilateral fines against generative AI companies, yet the GDPR's jurisdictional architecture—designed for traditional data controllers—may constrain their enforcement power when a single EU establishment exists. Whether Ireland's DPC will now pursue the same allegations, or whether the case will be resolved through GDPR's multilateral Article 60 consultation process, remains unclear.
The ruling does not signal a retreat in European AI regulation. Instead, it clarifies procedural boundaries. Other Member States' fines against AI companies may face similar jurisdiction challenges if those companies have EU establishments in different countries Ops Intel. For OpenAI and other generative AI firms, the annulment avoids one penalty but does not eliminate regulatory scrutiny on the underlying GDPR questions.