[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f-xTlmHAPG2gGwumoHfm4qPWeUlTGPDlh1pi7VkJ5QDc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"3293f09f-e1ee-4270-8b11-7042146d2671","characterai-fined-158k-for-gdpr-failures-on-user-transparency-and-age-verification","8ce3e7f1-4e0c-4349-a7a5-4c9f8938f94f","Character.AI Fined €158K for GDPR Failures on User Transparency and Age Verification","Character Technologies, Inc. was penalized by Italy's Garante for failing to adequately inform users about how their personal data is processed within its generative AI platform, and for lacking effective mechanisms to prevent minors from accessing the service. These failures represent fundamental GDPR obligations under Articles 13\u002F14 (transparency) and the principle of data protection by design and by default. The case highlights the heightened scrutiny AI-driven consumer services face when handling potentially vulnerable user groups such as children. Regulators across Europe are increasingly treating age verification and clear privacy disclosures not as optional best practices, but as mandatory compliance requirements — especially for AI platforms that process sensitive behavioral and conversational data.","**Immediate actions:**\n- Audit all user-facing privacy notices and data processing disclosures to ensure they meet GDPR Articles 13 and 14 transparency requirements.\n- Implement a technically robust age verification mechanism (e.g., age gates, parental consent flows) before allowing minors to create accounts or interact with AI services.\n\n**Compliance & governance improvements:**\n- Conduct a Data Protection Impact Assessment (DPIA) specifically for generative AI services that process large volumes of personal conversational data.\n- Appoint or empower a qualified Data Protection Officer (DPO) to regularly review AI product features for GDPR compliance before launch.\n- Establish a cross-functional review process requiring legal, privacy, and product teams to sign off on any new data processing activities involving user-generated content.\n\n**Ongoing monitoring & training:**\n- Train product and engineering teams on GDPR obligations specific to AI systems, including data minimization, purpose limitation, and special protections for children's data.\n- Schedule periodic third-party privacy audits to assess compliance with regional data protection laws across all markets where the service operates.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 5 – Principles of data processing","GDPR Article 13 – Information to be provided where personal data are collected from the data subject","GDPR Article 14 – Information to be provided where personal data have not been obtained from the data subject","GDPR Article 25 – Data protection by design and by default","GDPR Article 35 – Data Protection Impact Assessment (DPIA)","GDPR Article 8 – Conditions applicable to child's consent","NIST Privacy Framework PR.PO-P1 – Policies and procedures for privacy","NIST SP 800-53 PT-2 – Authority to Process Personally Identifiable Information","CIS Control 3 – Data Protection","ISO\u002FIEC 27701 – Privacy Information Management","COPPA (Children's Online Privacy Protection Act) – U.S. analogous child data protection standard","published","2026-07-15T08:20:23.544754+00:00","2026-07-15T08:20:23.236+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_487\u002F2026&diff=52218&oldid=52204","garante-per-la-protezione-dei-dati-personali-italy-487-2026-7da216","Garante per la protezione dei dati personali (Italy) - 487\u002F2026",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]