Character Technologies, Inc – €158,000 Fine (Italy, 2026)

€158,000Garante per la protezione dei dati personali3 July 2026Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Character Technologies, Inc. was fined for not properly informing users about data processing on its AI chat platform. This case matters because it underscores the need for clear communication about how personal data is handled, especially for online services. Companies should prioritize transparency in their privacy policies.

What happened

Character Technologies, Inc. failed to provide adequate information to users regarding data processing practices on its platform.

Who was affected

Users of the Character.AI platform were affected by the lack of information about data processing.

What the authority found

The authority ruled that Character Technologies, Inc. violated several GDPR articles related to user information and consent.

Why this matters

This ruling stresses the importance of clear privacy communication. Online service providers should ensure their privacy policies are understandable and comprehensive.

GDPR Articles Cited

AI-verified

Art. 3(2) GDPR
Art. 35(GDPR)
Art. 5(2) GDPR
Art. 12(1) GDPR
Art. 13(1) GDPR
Art. 14(1) GDPR
Art. 14(2) GDPR
Art. 14(5)(b) GDPR
Art. 21(1) GDPR
Art. 21(4) GDPR
Art. 24(1) GDPR
Art. 25(2) GDPR
Art. 27(1) GDPR
Art. 27(2) GDPR
View original scraped data
Art. 3(2) GDPR
Art. 5(2) GDPR
Art. 12(1) GDPR
Art. 13(1) GDPR
Art. 14(1) GDPR
Art. 14(2) GDPR
Art. 14(5)(b) GDPR
Art. 21(1) GDPR
Art. 21(4) GDPR
Art. 24(1) GDPR
Art. 25(2) GDPR
Art. 27(1) GDPR
Art. 27(2) GDPR
Art. 35(GDPR)

Original data from scraper before AI verification against source document.

Source verified 15 July 2026
articles corrected
scope corrected
Full Legal Summary
Detailed

Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to create and interact through chat with virtual characters that already exist or are created at the moment. The controller made this available to data subjects in Italian, and had a specific version for children. The DPA initiated an ex-officio investigation in 2024. The DPA requested information related to the LLM models used by the controller, the provision of the service, and data transfers. The controller provided a DPIA, and stated that it introduced an age verification system that required data subjects to register their date of birth. In 2025, the controller announced it would prevent underage data subjects from accessing open chat rooms, and would begin processing personal data of data subjects in the EEA to post-train its generative AI systems. The DPA first clarified that the GDPR is applicable even if the controller was established outside of the EU, in accordance with Article 3(2) GDPR. The DPA took into account the fact that the service was available in Italy and in Italian, as well as the privacy policy also applying to EEA residents. Given that the controller did not have an establishment in the EU, the one-stop-shop mechanism did not apply and the DPA was competent. The DPA found a violation of Articles 12(1), 13(1) and (2), and 14(1) and (2) GDPR. The DPA considered that the controller had failed to meet its information obligations. In terms of the controller’s privacy policy, the DPA considered that the controller had not provided data subjects’ with clear information regarding its processing activities, data transfers, or data subjects’ right to object and opt out. In addition, the controller failed to designate a representative in the EU, and included misleading and inaccurate statements on the processing of personal data for purposes of post-training LLMs for the servic

Related Enforcement Actions (0)

No other enforcement actions found for Character Technologies, Inc in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

3 July 2026

Authority

Garante per la protezione dei dati personali

Fine Amount

€158,000

GDPRhub ID

gdprhub-10126

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Character Technologies, Inc - Italy (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: