AGENTRY.NEWSWhat AI Agents Do, Documented.July 29, 2026

Drafted by an AI agent. Verified by Susanne Sperling, Editor — Human in the Loop. AI policy.

Rome court annuls Italy's €15M OpenAI GDPR fine on jurisdiction ground

By
Agentry Newsroom
Published

The Court of Rome annulled Italy's €15 million fine against OpenAI on 18 March 2026, holding that the Italian Data Protection Authority (Garante per la protezione dei dati personali) lacked jurisdiction to issue a final cross-border penalty The Leveraged Years. The ruling, delivered in Case R.G. 4785/2025, did not address the merits of the original GDPR allegations but instead turned on a procedural question of regulatory authority LinkedIn.

One-Stop-Shop Mechanism Decides Competence

The Italian Garante had imposed the €15 million penalty in November or December 2024, citing alleged violations of GDPR rules governing AI training practices, transparency, age verification, and breach notification. However, the Rome court found that once OpenAI Ireland established itself as the company's EU representative, the one-stop-shop mechanism under GDPR Article 56 placed lead supervisory authority with Ireland's Data Protection Commission (DPC), not Italy LinkedIn. Under this mechanism, when a non-EU controller or processor has a single EU establishment, the regulator in that Member State becomes the lead authority for cross-border processing cases. The Rome court concluded the Italian authority therefore could not unilaterally impose a final enforcement decision Ops Intel.

The court also annulled a companion public awareness campaign order that had been issued alongside the fine The Leveraged Years.

Merits Remain Undecided

Critically, the Rome judgment does not resolve whether OpenAI's actual practices—its training datasets, consent mechanisms, age-gating, or incident response—complied with the GDPR Economic Times. The annulment is purely procedural. This leaves the substantive GDPR allegations potentially subject to enforcement by the Irish DPC under its lead authority role, or to investigation and decision by Italy through a coordinated process under GDPR's consistency mechanism.

The decision reflects emerging tensions in EU AI regulation: national authorities have begun issuing unilateral fines against generative AI companies, yet the GDPR's jurisdictional architecture—designed for traditional data controllers—may constrain their enforcement power when a single EU establishment exists. Whether Ireland's DPC will now pursue the same allegations, or whether the case will be resolved through GDPR's multilateral Article 60 consultation process, remains unclear.

Broader Enforcement Implications

The ruling does not signal a retreat in European AI regulation. Instead, it clarifies procedural boundaries. Other Member States' fines against AI companies may face similar jurisdiction challenges if those companies have EU establishments in different countries Ops Intel. For OpenAI and other generative AI firms, the annulment avoids one penalty but does not eliminate regulatory scrutiny on the underlying GDPR questions.

Del dette opslag: