Companion Scout blog

Replika GDPR Fine Explained: What It Means for Users

replikaprivacyregulation

Replika’s GDPR fine is the clearest privacy warning in the AI companion market because it is not a rumor, a Reddit thread, or a creator complaint. It is a completed regulator action.

The short version: Italy’s data protection authority fined Luka Inc., the company behind Replika, 5 million euros after finding problems with legal basis, privacy transparency, and age verification. The regulator also opened a separate inquiry into how personal data is handled across the lifecycle of the generative AI system behind the service.

That does not mean every adult should immediately delete Replika. It does mean users should stop treating AI companion privacy as a vague “trust us” question. Replika is not just a chatbot. It is a service where people may share emotional history, voice interactions, romantic context, private routines, and identity details. The regulatory record matters because the data is intimate.

Key Takeaways

  • Italy’s regulator fined Luka Inc. 5 million euros over Replika
  • The findings centered on legal basis, privacy-policy transparency, and age verification
  • The decision relates to issues found as of February 2, 2023, with later technical concerns about age checks
  • A separate Italian inquiry was opened into data handling across the generative AI system’s lifecycle
  • The 2025 FTC complaint is separate: it was filed by advocacy groups and is not an FTC enforcement action

What happened in the Replika GDPR case

The case started with Italy’s privacy regulator, the Garante, investigating Replika after press reports and preliminary fact-finding. Replika was described in the regulator materials as a chatbot with written and voice interfaces that lets users generate a virtual companion in roles such as confidant, therapist, romantic partner, or mentor.

In February 2023, the Garante ordered a temporary block on Replika’s data processing in Italy. In April 2025, the regulator finalized an enforcement decision. The European Data Protection Board summary says the Italian authority imposed a 5 million euro administrative fine and ordered Luka to bring its processing into compliance with GDPR.

The key finding is not “AI companion apps are illegal.” That would be too broad. The finding was narrower and more useful for users: the regulator said Luka had not properly identified the legal basis for the data processing operations carried out through Replika, had provided an inadequate privacy policy, and had not implemented age verification mechanisms at the time the 2023 order was issued.

The Garante’s own English press release also says technical assessments found the age-verification system currently implemented by the controller continued to be deficient in several respects. That is one reason this case still matters in 2026, even though the original issues were tied to the service as it stood in early 2023.

The three findings that matter

GDPR does not allow a company to process personal data simply because the product is interesting. A controller needs a lawful basis for each processing purpose.

The EDPB summary says the Italian authority found that, until February 2, 2023, Luka had failed to identify the legal basis for the data processing operations carried out through Replika. For an ordinary app, that would already be serious. For an AI companion app, the stakes are higher because the product encourages ongoing personal disclosure.

Companion apps can process several kinds of information at once: account details, chat text, voice input, companion memories, safety signals, payment data, usage analytics, device information, and sometimes images. If the policy does not clearly explain why each category is processed, users cannot make a meaningful privacy decision.

2. The privacy notice was inadequate

The regulator also found that Luka’s privacy policy was inadequate in several respects. That matters because “we have a privacy policy” is not the same thing as “users can understand what happens to their data.”

For AI companion users, useful privacy language should answer practical questions:

  • Are chats used to train or improve AI models?
  • Are humans able to review conversations, and when?
  • Are voice, image, and memory features handled differently from text chat?
  • Can users export or permanently delete their data?
  • Are third-party model providers involved?
  • What happens to deleted data in backups?

If an app answers these in general corporate language, treat that as a risk signal. The more intimate the use case, the less acceptable vague language becomes.

3. Age verification was missing or weak

The age-verification issue is especially important because companion apps can blur entertainment, romance, emotional support, and sexual content.

The EDPB summary says Luka had not implemented age verification mechanisms, either at registration or during use, despite declaring that minors were excluded from potential users. The Garante press release says later technical assessments still found deficiencies in the current age-verification system.

This is not just a child-safety issue. Adults should care too because age checks shape the whole product: what data gets collected, what identity checks are introduced, what content is blocked, and how much trust users need to place in the platform. The same category problem now shows up in other services, including Character.AI age verification privacy.

What the fine does not prove

The fine does not prove that every Replika conversation was read by a human. It does not prove that every current Replika policy is unchanged from 2023. It does not prove that Replika is unusable.

It proves something narrower: a European regulator found serious enough GDPR issues to fine Luka and order compliance changes. That is still meaningful. In a market full of vague privacy claims, confirmed enforcement is a different class of evidence.

The separate FTC complaint is also worth keeping in the right box. In January 2025, the Tech Justice Law Project, Young People’s Alliance, and Encode said they filed a complaint and petition asking the FTC to investigate Replika over allegedly deceptive marketing and product design. That is not the same as an FTC enforcement action. It is a public complaint by advocacy groups.

Both facts can matter to a buyer, but they should not be described as the same kind of event.

What users should check before using Replika

If you already use Replika, the practical question is not “should I panic?” It is “what data am I comfortable placing here from now on?”

Start with the current Replika privacy policy and look for these terms: train, improve, model, conversation, voice, memory, delete, export, human review, third party, legal basis, and consent. If you cannot tell whether your chats can be used for model improvement, treat the answer as unclear.

Then check your account settings. Export any data you would regret losing. Delete old material you no longer want stored. Avoid using Replika as a private journal for details that would harm you if exposed, subpoenaed, reviewed, breached, or used in a way you did not expect.

If privacy is the main reason you are reconsidering, compare AI companion apps that do not train on your chats. In CompanionScout’s current scoring, Kindroid has the strongest public privacy posture, while Nomi is the stronger default if you mainly care about memory and emotional continuity.

For Replika specifically, read our Replika review and Replika alternatives before paying annually. The point is not that Replika has no value. It is that long-term companion use creates switching costs, so the privacy decision should come before the relationship history does.

A simple privacy checklist

Before you subscribe to any AI companion app, answer these questions:

QuestionWhy it matters
What is the lawful basis for processing my chat data?Shows whether the company has a clear legal theory, not just a product need
Are chats used for AI training or model improvement?The biggest privacy concern for many companion users
Can I export and delete my data?Exit rights matter once the app holds emotional history
Are voice, image, and memory data handled differently?Richer media can carry more sensitive signals than text
Is human review limited and explained?Safety review may be necessary, but vague access is a risk
How does age verification work?Age systems can add sensitive identity checks and account restrictions
Has the company faced regulatory action?Enforcement history is not everything, but it belongs in the decision

No app will answer every question perfectly. But the answer should be specific enough that you understand the trade.

Bottom line

The Replika GDPR fine matters because it shows how quickly AI companion privacy becomes more than a boilerplate policy issue. A companion app is designed to collect trust. That trust often turns into sensitive personal data.

Italy’s regulator found that Luka had problems with legal basis, privacy transparency, and age verification, then imposed a 5 million euro fine and ordered compliance. It also opened a separate inquiry into the data lifecycle of the generative AI system behind Replika.

For users, the lesson is straightforward: do not judge AI companion privacy by how warm the chat feels. Judge it by what the company says it collects, how clearly it explains the legal basis, whether chats can train or improve models, what deletion really means, and whether there is a regulatory record you should factor into the risk.

Sources & references

Frequently asked questions

Why was Replika fined under GDPR?

Italy's data protection authority found that Luka, Replika's operator, had failed to identify valid legal bases for certain data processing, provided an inadequate privacy policy, and lacked age-verification mechanisms as of February 2, 2023.

How much was the Replika GDPR fine?

The Italian data protection authority imposed an administrative fine of 5 million euros on Luka Inc. The European Data Protection Board published the decision summary in May 2025.

Does the Replika fine mean Replika is unsafe?

No single fine proves an app is unsafe for every user. It does mean Replika has a confirmed regulatory record, so privacy-sensitive users should read the current policy, age checks, deletion options, and training-language carefully before relying on it.

Is the FTC complaint against Replika the same as the GDPR fine?

No. The GDPR fine is a completed enforcement action by Italy's data protection authority. The January 2025 FTC complaint was filed by advocacy groups asking the FTC to investigate; it is not the same as an FTC enforcement action.