[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fMIqiN7uSCssn2Az4P0-Wx0t35lLpA1f4ZrRcX1qhTbc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":26,"created_at":27,"published_at":28,"article":29,"tags":33,"podcasts":52},"4d8f1d01-4ff7-4199-99e6-8e946cbb71f2","italian-garante-fines-company-for-gdpr-failures-llm-training-transparency-age-verification-and-missi","4cf27907-fc76-45d6-aaa1-22a85069febb","Italian Garante Fines Company for GDPR Failures: LLM Training Transparency, Age Verification, and Missing DPIAs","A company offering services to EU residents was found in violation of GDPR despite lacking an EU establishment, confirming that geographic location of the controller does not exempt organizations from EU data protection obligations. Key failures included insufficient transparency around the use of personal data for LLM training, inadequate age verification to protect minors, and the failure to conduct timely Data Protection Impact Assessments (DPIAs) for high-risk processing activities. These violations highlight that AI-driven data processing introduces novel regulatory obligations that many organizations are unprepared to meet. The case is a critical reminder that GDPR's extraterritorial reach means any business targeting EU users must fully embed compliance into its data operations from day one.","**Immediate actions:**\n- Audit all data processing activities involving personal data to identify any that require a DPIA and initiate those assessments without delay.\n- Review and update all privacy notices to clearly disclose if personal data is used for AI or LLM training, ensuring language is plain and unambiguous.\n- Implement robust age verification mechanisms for any service that may be accessed by minors, aligned with GDPR Article 8 requirements.\n\n**Long-term improvements:**\n- Establish a formal DPIA program with defined triggers, templates, and ownership so that high-risk processing is assessed before it begins, not retrospectively.\n- Appoint an EU Representative under GDPR Article 27 if your organization processes EU residents' data without an EU establishment.\n- Embed privacy-by-design principles into the AI\u002FML model development lifecycle, including data minimization and purpose limitation controls for training datasets.\n\n**Governance & compliance measures:**\n- Maintain a comprehensive and up-to-date Record of Processing Activities (RoPA) under GDPR Article 30 to ensure visibility of all data flows, including those used for AI training.\n- Conduct annual regulatory compliance reviews specifically targeting AI and emerging technology use cases to stay ahead of evolving DPA guidance.\n- Train product, engineering, and legal teams on GDPR obligations specific to AI systems, including the requirements triggered by automated decision-making and profiling.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25],"GDPR Article 5 – Principles relating to processing of personal data","GDPR Article 7 – Conditions for consent","GDPR Article 8 – Conditions applicable to child's consent","GDPR Article 13 & 14 – Transparency and information obligations","GDPR Article 25 – Data protection by design and by default","GDPR Article 27 – Representatives of controllers not established in the EU","GDPR Article 30 – Records of processing activities","GDPR Article 35 – Data Protection Impact Assessment (DPIA)","NIST Privacy Framework PR.PO-P1 – Policies and procedures for data processing","NIST SP 800-53 PT-2 – Authority to Process Personally Identifiable Information","NIST AI RMF GOVERN 1.1 – AI risk policies and accountability","CIS Control 3 – Data Protection","ISO\u002FIEC 29134 – Guidelines for Privacy Impact Assessment","ITIL Service Design – Information security and privacy management","published","2026-07-14T10:22:01.436867+00:00","2026-07-14T10:22:01.316+00:00",{"id":7,"url":30,"slug":31,"title":32},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_487\u002F2026&diff=52204&oldid=52203","garante-per-la-protezione-dei-dati-personali-italy-487-2026-03f2d3","Garante per la protezione dei dati personali (Italy) - 487\u002F2026",[34,40,46],{"id":35,"name":36,"slug":37,"description":38,"color":39},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":41,"name":42,"slug":43,"description":44,"color":45},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":47,"name":48,"slug":49,"description":50,"color":51},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]