We’re training an AI model on customer data. Has anyone been fined for that?
Yes. Italy fined OpenAI €15 million for training ChatGPT on personal data without a proper legal basis and without telling people enough. Clearview AI was fined €20 million or more in several countries for building a face-recognition database from photos taken from the web. The key question for you: your customers gave you their data for the service, and training a model is usually a new purpose. You must be able to justify it, tell them, and let them object.
Training is usually a new purpose
Article 5(1)(b) says data collected for one purpose must
“not further processed in a manner that is incompatible with those purposes”
Article 6(4) gives the test for whether a new purpose is compatible: how close the two purposes are, what customers would expect from their relationship with you, how sensitive the data is, the possible consequences for them, and safeguards such as encryption or pseudonymisation (replacing names with codes).
Legitimate interests, with a written test
Most companies rely on legitimate interests (Article 6(1)(f)). That can work for AI training, but only after a documented three-step test: a real interest, training that is necessary for it, and a balance against people’s rights that comes out in your favour. What people would reasonably expect weighs heavily. The European Data Protection Board explained how to apply the test to AI models in December 2024. EDPB Opinion 28/2024 ↗
Tell customers, and let them object
Customers must be told about the training (Article 13), and when you rely on legitimate interests they can object (Article 21). They can only object if they were told in time. That is part of why Italy fined Character.AI in 2026: users were not told their data could be used to pre-train models.
Sensitive data and the impact assessment
Health, biometric or similar data in the training set falls under Article 9, with much stricter rules. Training on large amounts of customer data with new technology also normally needs a written impact assessment first (Article 35).
Where the AI Act comes in
The AI Act adds its own rules on top of the GDPR. Providers of general-purpose AI models must publish a summary of their training content (since August 2025). High-risk AI systems will need data-quality controls (Article 10) from December 2027, or August 2028 for AI built into regulated products, after the 2026 amendment. The AI Act is coming to Fino.
What regulators decided
The closest decisions in Fino, biggest fine first. Each line opens the decision with its source.
- May 2024Clearview AI Inc.Scraped photos from the web to build a face-recognition database, with no legal basis.Dutch Supervisory Authority for Data Protection (AP) · Netherlands€30,500,000
- Feb 2022Clearview Al Inc.The same database, fined in Italy (and €20 million each in France and Greece).Italian Data Protection Authority (Garante) · Italy€20,000,000
- Dec 2024OpenAITrained ChatGPT on personal data without first identifying a legal basis, was not transparent, and had no age checks. Also ordered a six-month public information campaign.Garante per la protezione dei dati personali (Italy) · Italy€15,000,000
- May 2025Luka Inc.An AI “companion” app processed users’ data unlawfully, without clear information and without effective age checks.Garante per la protezione dei dati personali (Italy) · Italy€5,000,000
- Feb 2022Budapest Bank Zrt.AI analysed the emotions in recorded customer calls, without a valid legal basis and without telling customers they could object.Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) · Hungary€634,000
- Jul 2026Character Technologies Inc.Users were not told their data could be used to pre-train AI models, which limited their right to object. The impact assessment came late.Italian Data Protection Authority (Garante) · Italy€158,000
Decided the other way
See every decision in Fino and search for “AI”.
Check before you train
- Did customers know, when they gave you their data, that it might train models?
- Can they object easily, and before the training happens?
- Do you need personal data at all, or would anonymised or pseudonymised data do?
- Is there health, biometric or children’s data in the set?
- Is there a written impact assessment and a legitimate interests assessment?
Related explainers
Sources. GDPR text on Fino. EDPB Opinion 28/2024. AI Act: Regulation (EU) 2024/1689 as amended in 2026. Decisions from GDPRhub (noyb) and the CMS Enforcement Tracker, CC BY-NC-SA 4.0; descriptions rewritten in plain words by Fino.
Not legal advice. National rules can add to what is described here.