A €158,000 GDPR fine: compliance is not optional

Character.AI learns that a US address doesn’t buy an EU exemption

On 3 July 2026, Italy’s data protection authority (Garante) fined Character Technologies

Inc. €158,000, following an ex officio investigation opened in November 2024, after

Garante observed the platform’s rapid growth among younger users in Italy.

The company operates Character.AI, a generative AI platform where users create and

interact with virtual characters through chat.

Why was the company fined?

Italy’s data protection authority identified a series of GDPR violations.

1. Inadequate privacy notices (Articles 12–14 GDPR)

Garante reviewed two versions of Character.AI’s privacy notice, dated October 2023 and

August 2025, and found both fell short of the transparency requirements set out in

Articles 12 to 14 of the GDPR.

Neither notice clearly explained the purposes for which user data was processed, the legal

basis relied on for that processing, how long the data would be retained, or the safeguards

applied when data was transferred outside the EU.

For a platform whose core function is ongoing, data-intensive conversation with an AI

system, that lack of clarity matters more than it might for a simpler service, users had

little way of understanding what happened to what they typed, or for how long.

2. Late DPIA and missing EU representative (Articles 35 and 27 GDPR)

Under the GDPR, any processing likely to result in high risk to individuals requires a

Data Protection Impact Assessment (DPIA) before the processing begins, not after, and

processing children’s data through an AI chat interface plausibly qualifies.

Character conducted its DPIA late, only after the platform had already been operating and

growing its user base across the EU. The company was similarly delayed in appointing anEU representative, a legal requirement for any non-EU company offering services to EU

users, meant to give regulators and individuals a real point of contact within the bloc.

3. Insufficient age verification

This was the most consequential finding in Garante’s decision. Character.AI’s existing

safeguards for verifying a user’s age were found to be inadequate, meaning the platform

could not reliably prevent minors from accessing content or interactions not suited to

their age. Combined with the platform’s immersive, conversational format, designed to

keep users engaged in long, personal exchanges with AI-generated characters, the

absence of solid age controls was treated by the authority as a serious gap.

The jurisdiction argument

Character’s defence rested on a familiar excuse: as a US-based company, EU rules

shouldn’t apply to it with the same rigour as they would to a European business. It is an

argument regulators have heard before, and Garante rejected it just as quickly, applying

the “targeting” criterion under Article 3 GDPR.

The rule is simple and leaves no room for interpretation: if a service is accessible to, and

used by, people in the EU, GDPR applies, regardless of where the company happens to be

headquartered. A US address has never been, and was never designed to be, an

exemption from European data protection law.

What does compliance look like in practice?

  • Robust age-verification systems, not a simple self-declared age at sign-up;
  • Cooling-off periods for underage users;
  • Private profiles set by default for accounts identified as belonging to minors;
  • Timely appointment of an EU representative, before entering the European market.

 

What should companies take away from this decision?

  • An EU audience, not an EU address, is what triggers GDPR obligations; where a company is headquartered is irrelevant if its service reaches EU users.
  • Age verification for AI products used by minors is now being assessed with the same rigour as data security or consent management, not treated as a secondary feature.
  • Transparency, timely risk assessments, and local representation are being judged as a single compliance system, not as separate, independent boxes to tick.


For a sector still moving faster than the rules meant to govern it, this fine is a reminder

that some obligations were never optional to begin with, they were simply, until now,

untested.


Sources

age verification failures”

Failures”


Join us

Sign up for our newsletter and take the first step in joining our community! Stay updated with the latest news, events, and educational resources from the hub.

By clicking “Send,” you consent to the processing of your email address for the purpose of sending you news and updates about Legal Accelerators events. We use MailerLite as our email marketing service provider. MailerLite is an EU-based company that operates under the General Data Protection Regulation (GDPR). For further details, please see MailerLite’s Privacy Policy.You have the right to withdraw your consent at any time and we will act immediately, unless there is a legal reason or legitimate interest in not doing so. For withdrawal of consent, please contact us at contact@legalaccelerators.com.