Skip to content

Italy's Garante and Replika: the 2023 Order and the 2025 Fine

9 min read · updated August 11, 2026

The Replika measure is usually described as Italy banning an AI chatbot. What the Garante actually issued was an urgent limitation on one company’s processing of one country’s users’ personal data, and the difference in shape matters if you are trying to work out whether the same thing could happen to you.

What the 2 February 2023 measure was

On 2 February 2023 the Garante per la protezione dei dati personali, the Italian data protection authority, adopted a provvedimento against Luka Inc., the US company that develops and operates the Replika companion chatbot. The measure imposed an immediate temporary limitation on Luka’s processing of the personal data of users located in Italian territory, effective on receipt. The order is published in the Garante’s document archive.

The instrument is Article 58(2)(f) of the GDPR, which gives a supervisory authority the power to impose a temporary or definitive limitation including a ban on processing. Two features of that power explain the shape of what happened. It is a corrective measure rather than a penalty, so it can be imposed urgently and without the procedural apparatus a fine requires. And it operates on processing, not on a product: the authority tells a controller to stop handling data, and what that means commercially is the controller’s problem to work out.

A summary of a published regulatory decision, not legal advice. If you operate a consumer AI product reaching Italian or other EU users, the exposure depends on your lawful basis, your age assurance and your establishment position — take advice on those rather than reasoning from this order.

The grounds the Garante cited

The order cites Articles 5, 6, 8, 9, 13 and 25 of the GDPR alongside the Article 58(2)(f) power, and the substance clusters into two problems.

Children and age assurance. The Garante found no mechanism capable of verifying users’ age. Registration asked for little more than a name, an email address and a gender; nothing in the flow gated access by age; and nothing blocked a user whose declared age indicated a minor. The authority connected that to the nature of the service — a companion presented as improving emotional wellbeing, capable of replies that were sexually explicit or otherwise unsuited to a developing user — and to reports from users describing content of that kind. Article 8 of the GDPR conditions a child’s consent for information society services, and Italy has set the relevant age at fourteen in its national implementation, which makes an unverified sign up a direct problem rather than a theoretical one.

Lawful basis and transparency. The privacy information did not address the processing of children’s data, and the authority took the view that the reliance on contract as a basis was unsatisfactory, not least because a minor cannot conclude a valid contract under Italian law. Article 25, data protection by design and by default, appears because an absent age gate is a design choice rather than an operational oversight.

The order required Luka to notify the authority of the measures taken to comply, with a short deadline, and warned of the penalties available for failure — the Article 83(5) tier of up to €20 million or 4% of worldwide annual turnover.

What it did and did not prohibit

It prohibited the processing of the personal data of users established in Italy. It did not order an app store removal, it did not order the model destroyed, it did not fine anyone in February 2023, and it did not adjudicate whether Replika’s underlying model was lawfully trained. Those are different questions with different procedures, and two of them came back later.

The distinction has a practical consequence people miss. A limitation on processing is satisfied by stopping the processing, which for a consumer service usually means geoblocking the country — and a company that geoblocks is complying with the order, not being banned by it. That in turn is why the measure took effect on receipt rather than after an appeal window: the authority is not shutting a business, it is suspending a data flow it considers unlawful, and the reversal path is to fix the basis and come back.

The 2025 penalty decision

The February 2023 measure was interim. The Garante ran a full inquiry alongside it, and on 10 April 2025 it adopted a penalty decision against Luka Inc., announcing it on 19 May 2025: a fine of €5 million. The Garante’s press release on the Replika fine sets out its account of the findings.

Two elements of that decision are worth stating precisely. First, the authority assessed compliance as it stood at 2 February 2023 — the date of the original measure — and the findings concern the absence of a lawful basis for the processing and the absence of any age verification mechanism, alongside transparency and data-protection-by-design failings. Second, the Garante stated that it was continuing to investigate the personal data processing involved in the training and operation of the language model underneath the product, which is a separate question from how the front end handled sign-ups.

That second thread is the one to watch, because it is the question with general application. Whether a companion product can rely on legitimate interests for model training, and what an assessment of that has to contain, is unsettled across the EU rather than decided by this case — the legitimate interest assessment for training is where that argument actually lives.

Administrative fines in Italy are appealable to the ordinary courts, and an appeal can suspend or annul a penalty without disturbing the findings of the regulator’s other measures — which is precisely what happened to the Garante’s OpenAI fine in 2026. Check the current status of this penalty before describing it as final.

What carries to other companion products

Three things generalise, and one does not.

Age assurance is now a design requirement, not a policy one. A terms-of-service clause saying users must be over thirteen is not an age verification mechanism, and the Garante treated the absence of a mechanism as an independent failing. Any product whose content could be unsuitable for minors, and whose sign-up asks nothing that tests age, is in the same position Luka was.

Contract is a weak basis for a consumer AI service. The argument that processing is necessary for performance of the contract gets thinner the further you move from delivering the service the user asked for, and it collapses entirely where the user could not have formed a contract. This is the same weakness the Garante pressed in the ChatGPT proceedings.

Urgency is available to regulators and speed is not symmetrical. A limitation under Article 58(2)(f) can be imposed in days on a company with no EU establishment, while the penalty decision took over two years. If you are planning around regulatory risk, the fast instrument is the one that affects your service.

What does not straightforwardly generalise is the jurisdictional position. Luka had no establishment in the EU, so no one-stop-shop lead authority stood between it and the Italian regulator. A company with a main establishment in an EU Member State is in a materially different procedural position, and that difference is not a detail — it is what unwound a €15 million fine in the ChatGPT case three years later.