Italian Data Protection Authority (Garante) · 3 July 2026
Character Technologies Inc.
Non-compliance with general data processing principles
- Regulator
- Italian Data Protection Authority (Garante)
- Decided
- 3 July 2026
- Country
- Italy
- Sector
- Media, Telecoms and Broadcasting
- Regulator’s reference
- Not recorded
- Fino case number
- 2026/IT/098
What happened
The Italian DPA has imposed a fine of EUR 158,000 on Character Technologies Inc. The controller develops and deploys Character.AI, an AI-based service that allows users to interact with virtual characters. By offering this service, the controller processes personal data. However, the controller did not adequately inform users about the processing of their data, particularly with regard to the processing of data subjects' personal data in non-EU countries. Furthermore, data subjects were not adequately informed that their data could be used to pre-train AI models, which restricts their right to object. The controller also failed to carry out a data protection impact assessment in a timely manner. The controller also designated an EU representative belatedly.
Summary from the CMS Enforcement Tracker, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(2)Read →
- Art. 12Transparent information, communication and modalities for the exercise of the rights of the data subject12(1)Read →
- Art. 24Responsibility of the controller24(1)Read →
- Art. 25Data protection by design and by default25(2)Read →
- Art. 27Representatives of controllers or processors not established in the Union27(1)Read →
- Art. 35Data protection impact assessment35(1)Read →
- Accountability
- DPIA
- Data principles
- Transparency
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/IT/098.