Cybersecurity Policy Report, Replika Chatbot Operator Hit With Privacy Fine in Italy, (May 19, 2025)
Italy’s data protection authority, Garante, has imposed a fine of 5 million euros ($5.62 million) on U.S.-based Luka, Inc., which manages the Replika chatbot, based on violations of the European Union’s General Data Protection Regulation (GDPR), Garante announced today.
It also launched an independent investigation to verify the correct processing of personal data carried out by the system of generative artificial intelligence at the base of the service.
The Replika chatbot enables users to create a “virtual friend” and uses a large language model (LLM) that is constantly fed and perfected through interaction with users, Garante noted in a news release.
Garante notified Luka of its infringement of articles 5(1)(a) and 6 of the GDPR for failing to identify the legal bases for the different processing operations carried out through the Replika service, which was made available to the public in Italy in 2023.
Further, the DPA found Luka infringed articles 5(1), 12, and 13 of the GDPR for providing a privacy policy that did not comply with the obligations and general principles on transparency established under the GDPR. Finally, the DPA found Luka infringed articles 5(1)(c), 6, 7, 8, 24, and 25(1) of the GDPR by failing to set up users’ age verification systems before the service became available to users in Italy.
The DPA ordered Luka to present an updated privacy policy to all users in Italy before allowing registration and access to the Replika service; implement an age gate mechanism in all service registration pages; implement a “cooling-off period” aimed at preventing minors from entering a different date of birth when they are denied access to services; enable users in Italy to exercise their privacy rights in a simple and effective way, including the right to object to the processing of personal data and to request access, rectification, and deletion of data; submit to the DPA, 15 days before the date scheduled for the reopening of the service to users in Italy, a plan for the development of a process to prevent access to the service by persons under the age of 18; and submit to the DPA, 15 days before the reopening of the service to users in Italy, a plan for the implementation of functions allowing users to report inappropriate content to prevent the Replika chatbot from repeating it.
News: InternationalLegislation LitigationEnforcement DataPrivacy GDPR