Back to all lessons
Awareness Lessons
3 months ago

Italian Garante Fines Company for GDPR Failures: LLM Training Transparency, Age Verification, and Missing DPIAs

A company offering services to EU residents was found in violation of GDPR despite lacking an EU establishment, confirming that geographic location of the controller does not exempt organizations from EU data protection obligations. Key failures included insufficient transparency around the use of personal data for LLM training, inadequate age verification to protect minors, and the failure to conduct timely Data Protection Impact Assessments (DPIAs) for high-risk processing activities. These violations highlight that AI-driven data processing introduces novel regulatory obligations that many organizations are unprepared to meet. The case is a critical reminder that GDPR's extraterritorial reach means any business targeting EU users must fully embed compliance into its data operations from day one.

Tactical Insight

Immediate actions

  • Audit all data processing activities involving personal data to identify any that require a DPIA and initiate those assessments without delay.
  • Review and update all privacy notices to clearly disclose if personal data is used for AI or LLM training, ensuring language is plain and unambiguous.
  • Implement robust age verification mechanisms for any service that may be accessed by minors, aligned with GDPR Article 8 requirements.

Long-term improvements

  • Establish a formal DPIA program with defined triggers, templates, and ownership so that high-risk processing is assessed before it begins, not retrospectively.
  • Appoint an EU Representative under GDPR Article 27 if your organization processes EU residents' data without an EU establishment.
  • Embed privacy-by-design principles into the AI/ML model development lifecycle, including data minimization and purpose limitation controls for training datasets.

Governance & compliance measures

  • Maintain a comprehensive and up-to-date Record of Processing Activities (RoPA) under GDPR Article 30 to ensure visibility of all data flows, including those used for AI training.
  • Conduct annual regulatory compliance reviews specifically targeting AI and emerging technology use cases to stay ahead of evolving DPA guidance.
  • Train product, engineering, and legal teams on GDPR obligations specific to AI systems, including the requirements triggered by automated decision-making and profiling.