AI | The Italian DPA fines Character.AI for unlawful processing of minors’ data

With a press release dated 9 July 2026, the Italian Data Protection Authority (Italian DPA) announced the issuance of a fine of euro 158,000 against Character Technologies, Inc., the provider of the generative artificial intelligence (AI) system Character.AI which enables users to interact with AI-generated characters, including both pre-existing and user-created figures. A key point of the decision concerns the adequacy of the company’s age verification measures. According to the Italian DPA, the current system, introduced in November 2025, provides an adequate level of protection because it combines an age gate with a multi-layered age-assurance mechanism that verifies the plausibility of users’ declared age during their use of the service through a proprietary age prediction model. Where necessary, a secondary verification process carried out by an independent third-party provider is triggered. Additional safeguards, including a dedicated experience for minors, restrictions on content and functionalities, and parental supervision tools, have also been implemented. By contrast, the previous system, which relied solely on an age gate based on users’ self-declaration, was considered ineffective.

The Italian DPA clarified that, although the GDPR does not expressly require controllers to implement age verification systems and no harmonised EU standard currently exists on the matter, controllers remain under an obligation to adopt appropriate and demonstrably effective measures to protect minors, taking into account the nature of the processing, the risks involved and the principles of privacy by design and by default. To this extent, age verification systems play a crucial role in ensuring compliance with the key principles of data protection.

Newsletter n. 120 – July 2026