The Italian authority for privacy asked OpenAI clarification and corrections on the data treated and privacy policies of chatGPT (not of the APIs) but of the chat.openai.com website and ChatGPT product, following a security incident that resulted in a data breach of 1.something % of the premium users.
This incident, apparently, was not communicated promptly enough to the authority and this fact, in addition to its rising popularity amongst Italian users, triggered additional checks on the platform by the institution.
OpenAI had 20 days to implement the additional security measures requested, in particular they were requested to add an age check and some popup containing information about data treatment of its user at the moment of sign-up.
On top of this they also had to justify the incident providing documentation, root cause analysis and so they did, publicly.
To avoid further actions, and in my opinion, to send a “political” message, OpenAI preferred blocking the website for Italian IP addresses.
Ok, great.
Since we, italians, tend to be functionally illiterate (we say “analfabeti funzionali”) — so many IT professionals in my LinkedIn network started to scream and shout about how the Italian State blocked chatGPT.
Wrong.

Let’s clarify some of the absolutely sensless ideas I’ve read in the last 10–15 days on my social media:
- The Italian authority for privacy is an indipendent institution made of multiple people and not a single (evil?) individual;\
- It has no power to block anything, they have to ask a judge and the legislator to do something about it and only if the request is deemed reasonable by actual legal authorities they can ask Internet Service Providers to lock out a website.
They can surely indipendently verify if a service is compliant with privacy regulations and publicly menace the company to comply if they have evidence of any wrongdoing but not much more than that;\ - OpenAI did a commercial/political choice to stand against the authority decision in order to make italian people protest on the web and it worked like a charm;\
- The solution will be most likely an adaptement of ChatGPT service for Italy and other European nations that were following Italy in the process (Ireland, Germany, France);
4b) Even more likely they will just make an EU version of the service that is GDPR compliant (at the moment they are not);
Q.E.D.
This is the final decision of the authority about OpenAI and ChatGPT.
https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/9874751#english
“OpenAI will have to draft and make available, on its website, an information notice describing the arrangements and logic of the data processing required for the operation of ChatGPT along with the rights afforded to data subjects (users and non-users). The information notice will have to be easily accessible and placed in such a way as to be read before signing up to the service.
Users from Italy will have to be presented with the notice before completing their registration, when they will also be required to declare they are aged above 18.
Registered users will have to be presented with the notice at the time of accessing the service, once it is reactivated, when they will also be required to pass through an age gate filtering out underage users on the basis of the inputted age.”
Boom, done.
Much ado about…nothing.
ChatGPT will simply add simple measures to avoid clashing with EU regulation, and everyone lived happily ever after.
This article was written the 18/04/2023, ChatGPT is still blocked in Italy but when I publish it it may be available, feel free to check and comment about it.
Follow me here, hit that green button!
Share and tag me on LinkedIn or Twitter to discuss.
You can follow my other social media (here).
See you next time!
Originally published on blog.mb-consulting.dev.