PogoWasRight.org

Menu
  • About
  • Privacy
Menu

AI: the Italian Supervisory Authority fines Luka, the U.S. company behind chatbot “Replika,” 5 Million €

Posted on May 25, 2025 by Dissent

Background information

  • Date of final decision: 10 April 2025
  • National case
  • Controller: Luka Inc.
    Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 6 (Lawfulness of processing),  Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject),  Article 13 (Information to be provided where personal data are collected from the data subject),  Article 24 (Responsibility of the controller),  Article 25 (Data protection by design and by default)
  • Decision: administrative fine,  Compliance order
  • Key words:  accountability, administrative fine, algorithms, principles relating to processing of personal data,  responsibility of the controller, transparency

Summary of the Decision

Origin of the case

The proceedings originated from an investigation initiated by the Italian Supervisory Authority (SA) of its own motion following the publication of press reports and preliminary fact-finding conducted on the Replika service, a chatbot with a written and voice interface developed and managed by the US company Luka Inc and based on a generative AI system. The chatbot features both a written and voice interface, allowing users to ‘generate’ a ‘virtual companion’ that can take on the role of a confidant, therapist, romantic partner, or mentor.

Key Findings

During its investigation, the Italian SA found that the alleged infringements notified in February 2023—when it had ordered the blocking of the application—had indeed occurred. According to the Italian SA, until 2 February 2023, the US company had failed to identify the legal basis for the data processing operations carried out through Replika. Moreover, Luka had provided a privacy policy that was inadequate in several respects. The Italian SA also found that, until 2 February 2023, the Company had not implemented any age verification mechanisms—either at registration or during use of the service—despite having declared that minors were excluded from potential users.

Technical assessments revealed that the age verification system currently implemented by the controller continues to be deficient in several respects.

For these reasons, in addition to imposing a fine, the Italian SA ordered the company to bring its processing operations into compliance with the provisions of the Regulation.

Decision

The Italian SA has imposed on Luka Inc. an administrative fine of 5 million € for infringing Articles 5.1 (a) and 6; Articles 5.1 (a), 12, 13, 5.1 (c), 24 and 25.1 of the GDPR.

Additionally, the Italian SA reserves the right to investigate and assess in a separate and autonomous proceeding, the aspects concerning the lawfulness of the processing operations carried out by Luka Inc., with specific reference to the legal bases for processing applicable throughout the entire lifecycle of the generative AI system underlying the Replika service.

For further information: 
•   AI: Il Garante sanziona la società che gestisce il chatbot “Replika” 

Source: EDPB.  The news published here does not constitute official EDPB communication, nor an EDPB endorsement. This news item was originally published by the national supervisory authority and was published here at the request of the SA for information purposes. Any questions regarding this news item should be directed to the supervisory authority concerned.

No related posts.

Category: Artificial IntelligenceBreachesBusinessLawsNon-U.S.

Post navigation

← D.C. Federal Court Rules Termination of Democrat PCLOB Members Is Unlawful
Period Tracking App Users Win Class Status in Google, Meta Suit →

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • PRIVACY—S.D. Cal.: Employee did not waive privacy right in personal email data on company provided laptop, (Dec 5, 2025)
  • EU justice chief draws red line on privacy reforms
  • Kaiser Permanente to Pay Up to $47.5M in Web Tracker Lawsuit
  • How Palantir shifted course to play key role in ICE deportations
  • U.S. Judge Blocks Trump From Cutting Medicaid Funding For Planned Parenthood In 22 States
  • India backs off mandatory ‘cyber safety’ app after surveillance backlash
  • Judge orders Trump administration to halt warrantless immigration arrests in District of Columbia

RSS Recent Posts at DataBreaches.net

  • Ex-teen hackers warn parents are clueless as children steal ‘millions’
  • UK Government Considers Computer Misuse Act Revision
  • Japan issues arrest warrant against teen suspected of cyberattack using AI
  • How old is the average hacker? What does a new research report suggest? (1)
  • Marquis data breach impacts over 74 US banks, credit unions
©2025 PogoWasRight.org. All rights reserved.