DocumentedData Privacy & Regulatory Violation2023-02-02 (ban); 2025-05-19 (fine)Italy

Italy Replika Chatbot Ban and 5M Euro Fine

Italy's Garante issued an urgent order halting Replika from processing Italian user data February 2023. Found: no effective age verification (only name, email, gender); no valid legal basis for processing; sexually suggestive content served to minors; English-only privacy policies citing US COPPA instead of GDPR; significant risks to emotionally vulnerable adults, some of whom reported mental-health crises when erotic roleplay was later restricted.

Fine: €5.0MAI system:Replika AI companion chatbot

Impact

First major EU regulatory action against an emotional AI companion. Later Character.AI teen suicides validated the regulator's concerns.

Outcome

Despite June 2023 interim remediation order, Luka did not sufficiently comply. May 19, 2025: 5 million euro fine imposed, plus ongoing investigation into whether the underlying LLM training methods themselves violate GDPR - one of the first regulatory probes of LLM training legality in Europe.

Sources

  1. Source 1European Data Protection Boardwww.edpb.europa.eu/news/national-news/2025/ai-italian-supervisory-authority-fines-company-behind-chatbot-replika_en
  2. Source 2TechCrunchtechcrunch.com/2023/02/03/replika-italy-data-processing-ban/
  3. Source 3IAPPiapp.org/news/a/italy-s-dpa-reaffirms-ban-on-replika-over-ai-and-children-s-privacy-concerns

Related incidents

Same category, country, or harm tier.