When the world’s regulators were still working out how to react to generative AI, one of them simply switched ChatGPT off. That was Italy’s Garante — and it is why the first big AI penalties in Europe are Italian and run through GDPR, not the AI Act. This is a profile of what the Garante is, how it is structured, what it did on AI, and who runs it after the January 2026 change in its Collegio. Every fact is sourced.
Quick facts
- Full name: Garante per la protezione dei dati personali (the Italian data protection authority) (EDPB members)
- Role: Italy’s GDPR supervisory authority — the independent national body that enforces data-protection law in Italy and sits on the EDPB (EDPB members)
- Governing instrument: the Codice in materia di protezione dei dati personali (the Italian Data Protection Code, Legislative Decree no. 196/2003), the national law that, alongside the GDPR, frames the Garante’s powers (Garante)
- Structure: a collegiate body of four members elected by Parliament for a seven-year, non-renewable term (Garante)
- Current Collegio: elected by Parliament on 14 July 2020, took office on 29 July 2020 (Garante — Collegio)
- President: Pasquale Stanzione (EDPB members; Garante — Collegio)
- Headquarters: Piazza Venezia 11, 00187 Roma (Garante)
- Website: garanteprivacy.it
What the Garante is — and what it is not
The Garante is Italy’s data protection authority (DPA — the independent national regulator that supervises and enforces data-protection law) and, since the GDPR became applicable, Italy’s GDPR supervisory authority (EDPB members). It is one of the 27 national authorities that make up the EDPB, and it enforces data-protection law in Italy under the Codice in materia di protezione dei dati personali read together with the GDPR (Garante).
What it is not: it is not Italy’s AI Act authority. The Garante polices how personal data is processed — including inside AI systems. But the AI Act regulates the AI system itself as a product (risk class, conformity assessment, market surveillance — much as the EU regulates machinery or medical devices), and in Italy that job is designated to a separate competent authority, not the Garante. So the Garante’s AI work is GDPR enforcement that happens to touch AI, which is exactly why it is on the GDPR pillar, not framed as AI Act enforcement.
What the Garante actually does
Like every GDPR supervisory authority, the Garante’s job is to apply one EU regulation consistently — handle complaints, investigate, authorise or prohibit processing, and impose corrective measures and fines. Three things make it stand out in the EU landscape:
- It moves first and fast. It is among the most assertive DPAs in Europe — willing to order an immediate processing stop, not only to fine after the fact.
- It reaches non-EU operators. Its highest-profile actions have been against US companies offering services to Italian users.
- Its decisions are testable in court. Garante sanctions are challenged before the Tribunale di Roma (the Rome civil court that hears appeals against Garante fines) — and, as the OpenAI case below shows, they can be overturned there.
The Garante and AI — why the first big AI fines are Italian
The Garante is the reason “the EU fined an AI company” headlines exist at all. In March 2023 it became, in effect, the first authority in the world to temporarily block ChatGPT over data-protection concerns. It then turned that into formal enforcement:
- OpenAI / ChatGPT — €15 million (December 2024) — later annulled. The fine was issued, then annulled in full by the Tribunale di Roma with judgment no. 4153/2026, filed on 18 March 2026.
- Luka / Replika — €5 million (April 2025). A fine on the US operator of the Replika “AI companion” app, with a separate investigation into model-training data reserved.
Both cases reduce to the same GDPR failure — personal data used to build or run an AI service without a valid legal basis (the lawful ground GDPR’s Article 6 requires before any personal data is processed) — not to any AI-Act breach. The full breakdown, the exact articles, the corrective measures and the live court status are in the dedicated registry: Garante AI fines. The key lesson it documents: a headline fine is not a final, collected fine.
The Collegio — how the Garante is run
The Garante is not run by a single director but by a Collegio (a collegiate board) of four members, elected by the Italian Parliament for a seven-year, non-renewable mandate (Garante). The current Collegio was elected on 14 July 2020 and took office on 29 July 2020 (Garante — Collegio).
- President: Pasquale Stanzione (EDPB members; Garante — Collegio).
- Vice President: Ginevra Cerrina Feroni (Garante — Collegio).
- Component: Agostino Ghiglia (Garante — Collegio).
- Fourth seat: the Garante’s Collegio page records the mandate of component Guido Scorza as running from 29 July 2020 to 19 January 2026 (Garante — Collegio). That mandate has now ended; as of June 2026 the seat is vacant and Parliament has not yet elected a successor, so the Collegio is operating with three members. The official Collegio page can lag — verify the current fourth member there before citing it.
Because it is collegiate, the Garante’s decisions are the board’s, not one official’s — a structural contrast with single-head regulators.
What this means for you
- If you train or run AI on personal data, and Italian users can reach it: the Garante is the single most likely EU authority to act first, and to act by stopping the processing, not only fining it. Establish your Article 6 legal basis before launch, not after.
- If your service can be used by minors: both Italian AI cases turned partly on the absence of real age verification. A terms-of-service exclusion is not a control.
- If you receive a Garante sanction: it is not the last word — appeals go to the Tribunale di Roma, and the OpenAI annulment shows first-instance decisions can fall. Equally, a suspension or block bites immediately, long before any appeal.
- If you are a journalist or researcher: “Italy’s privacy regulator” = the Garante per la protezione dei dati personali, a four-member Collegio elected by Parliament, President Pasquale Stanzione, seat Piazza Venezia 11, Rome — and note the 19 January 2026 mandate end on the Scorza seat when citing the board’s composition.
TL;DR
The Garante per la protezione dei dati personali is Italy’s GDPR supervisory authority and one of the most assertive DPAs in the EU — the regulator that temporarily blocked ChatGPT in March 2023 and then issued Europe’s first headline AI fines (OpenAI €15M, annulled by the Tribunale di Roma with judgment 4153/2026 filed 18 March 2026; Luka/Replika €5M). It is a collegiate body of four members elected by Parliament for a seven-year non-renewable term, governed by the Codice in materia di protezione dei dati personali (Legislative Decree 196/2003), based at Piazza Venezia 11, Rome. President: Pasquale Stanzione; Vice President Ginevra Cerrina Feroni; component Agostino Ghiglia; the official Collegio page records Guido Scorza’s mandate as ending 19 January 2026. Its AI enforcement is GDPR enforcement — see the Garante AI fines registry.
Sources
- EDPB — Members — Italy’s supervisory authority name and President
- Garante — Il Garante — name, governing Code (D.Lgs. 196/2003), collegiate four-member structure, seven-year non-renewable mandate, seat (Piazza Venezia 11, 00187 Roma)
- Garante — Il Collegio — current Collegio, elected 14 July 2020 / in office 29 July 2020; President Stanzione, Vice President Cerrina Feroni, component Ghiglia; Scorza mandate 29 July 2020 – 19 January 2026
- Garante AI fines registry (klarproof) — the OpenAI and Replika decisions, articles, amounts and court status, fully sourced
- GDPR — Regulation (EU) 2016/679 (EUR-Lex) — Article 6 legal basis
- GDPR pillar · EDPB profile · garanteprivacy.it