The Italian authority sanctions Character Technologies for GDPR breaches related to its generative artificial intelligence service
Facts and context
The Italian data protection authority (GPDP) today published a sanction decision against Character Technologies, Inc. (including the imposition of a €158,000 fine) for breaches related to transparency, processing of minors' data, and training of its artificial intelligence model.
The case originated from an ex officio investigation launched by the authority in November 2024 concerning the compliance of the generative artificial intelligence service Character.AI, offered in Italy via an application and a web platform allowing users, including minors, to create virtual characters and interact with them.
Grounds for the decision
- Transparency obligation (articles 12, 13 and 14 of the GDPR): The authority found the successive privacy policies (October 2023 and August 2025) non-compliant. The first version was only available in English while the service was offered in Italian, and omitted to mention the representative in the Union. Both versions lacked clarity on retention periods, legal bases (sometimes indicating multiple bases for the same purpose, contrary to the clarity principle), data transfers outside the EU, and the right to object. The authority relied on the WP29 guidelines on transparency (WP 260), recalling that information must be concrete, precise, and easily understandable.
- Information obligation for data not collected from the data subject (article 14 of the GDPR): The authority found that the company did not provide adequate information to Italian data subjects whose publicly available data on the internet were used for pre-training its large language models (LLM). The company's defense invoking disproportionate effort (article 14, paragraph 5, point b) was rejected as it did not demonstrate a documented balancing of interests as required by the European Data Protection Board (EDPB) guidelines. Publishing information on third-party forums (Reddit, Discord) was not considered an adequate means to fulfill this obligation.
- Data protection by design and by default (article 24 and 25 of the GDPR): The company was reproached for not implementing adequate technical and organizational measures to verify the age of minor users. Initially, no mechanism was in place. Subsequently, the implemented age gate proved ineffective, with an authority check showing that a user declaring to be under 16 could register. Moreover, minors' profiles were public by default, violating the data protection by default principle, particularly important for vulnerable persons as highlighted by the binding decision of the EDPB No. 2/2023 (TikTok).
- Obligation to carry out a data protection impact assessment (article 5, paragraph 2 and 35 of the GDPR): The company formalized its first data protection impact assessment (DPIA) only in November 2024, well after the service launch. The authority deemed this late, recalling that the DPIA is mandatory before processing begins when it presents a high risk, which is the case for a service using innovative technology like artificial intelligence, processing data at large scale and targeting minors. Conducting undocumented internal assessments does not satisfy the accountability principle.
- Obligation to designate a representative in the Union (article 27 of the GDPR): The company designated its representative in May 2025, more than a year after starting to offer its service in Italian. The authority dismissed the occasional processing exception, considering that targeting an Italian audience by language made the processing systematic and the designation obligation applicable from the start of this offer. However, the breach related to a defective contact link to the representative was judged a mere material error without consequence, as other contact means remained available.
Authority's decision
Consequently, the authority imposed a fine of €158,000 on Character Technologies, Inc.
Furthermore, the authority ordered the company to bring its processing into compliance within 120 days, notably by:
- amending its privacy policy to correct persistent shortcomings;
- assessing the lawfulness of retaining data used for pre-training or, failing that, deleting them;
- ensuring the proper functioning of age verification measures for Italian users and configuring minors' profiles to private by default.
Lessons learned
This decision confirms / specifies / recalls that:- Training artificial intelligence models from publicly accessible internet data constitutes personal data processing requiring compliance with the information obligations of article 14 of the GDPR.
- Invoking the disproportionate effort exception to not inform data subjects must be supported by a documented analysis balancing the required effort and the impact on individuals' rights.
- For services likely to be used by minors, a simple declarative age gate is insufficient if not technically robust and effective; data protection by default measures, such as profile privatization, are imperative.
- A data protection impact assessment must be carried out before launching any service based on innovative technology presenting a high risk, and cannot be replaced by informal internal assessments.
- Offering a service in the language of a European Union Member State constitutes targeting that renders the occasional processing exception inapplicable and imposes the designation of a representative in the Union.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire