Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Enforcement July 16, 2026 4 min

Character.AI fined EUR 158,000: minors, late DPIA and missing EU representative

Decision of 3 July 2026: the Italian DPA hits the 'virtual companions' chatbot. Three lessons for anyone launching an AI service in Europe

TL;DR for the DPO

Decision of 3/7/2026 (doc. 10269571), ex officio inquiry opened November 2024: EUR 158,000 to Character Technologies. Breaches: unclear and incomplete notice (Arts. 12, 13 and 14), late DPIA for processing that required one BEFORE launch, late EU-representative designation (Art. 27), shortcomings on age verification and minor protection. Corrective measures within 120 days: effective age verification, cooling-off against re-registration, minors' profiles private by default.

The three lessons that matter

  • The DPIA is a condition of lawfulness, not a formality: for a generative-AI service accessible to minors it had to be done BEFORE launch. Doing it afterwards, with the service live, is itself the breach.
  • Article 27 is the forgotten rule for non-EU companies: if you offer services to people in the EEA without an EU establishment, the representative must be designated at once - its absence is a standalone charge.
  • Minors: if the service can reach them (or you cannot rule it out), the authority expects age verification that actually works, anti-circumvention measures and protective defaults. Defaults matter as much as policies.

What to do now, in practice

If a client launches or adopts public-facing AI services: 1) DPIA before go-live, on file and dated; 2) check whether an EU representative is required (US vendors included: ask in due diligence); 3) if the service can reach minors, document age verification, protective defaults and anti-circumvention measures; 4) record these tools in the AI systems register - the framework meshes with the AI Act, whose prohibitions (Art. 5) and literacy duties already apply.

Why it matters for your clients

The authority's message targets the whole consumer-AI market: data protection is designed before, not patched after. It also works in reverse, for controllers ADOPTING chatbots and virtual assistants: vendor due diligence (DPIA, EU representative, handling of minors) is part of the DPO's job.

Official source:Italian Data Protection Authority - decision of 3 July 2026, doc. no. 10269571 (Character Technologies Inc.)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free