Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 1,370 cases from 35 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

1case from 1 jurisdiction
€158,000Total of monetary amounts
€158,000Largest single case: Character Technologies, Inc. (Character.AI)
€158,000Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20240—
Q4 20240—
Q1 20250—
Q2 20250—
Q3 20250—
Q4 20250—
Q1 20260—
Q2 20260—
Q3 20261€158,000

1 case

3 Jul 2026 Character Technologies, Inc. (Character.AI)Garante: €158,000 fine for Character.AI over transparency and age-verification failings ItalyData subject rights and transparency €158,000

The Garante (Italian data protection authority) fined the US operator of the generative AI service Character.AI, on which users – including minors – chat with virtual characters, 158,000 EUR, among other things for deficient privacy information, a data protection impact assessment prepared late and the late appointment of a representative in the EU. It also criticised weaknesses in the protection of minors and in age verification; within 120 days the company must ensure working age verification, an effective cooling-off period preventing blocked minors from re-registering and private-by-default profiles for minors.

What organisations can take from it

Anyone offering generative AI services in the EU needs complete privacy notices, an impact assessment, an EU representative and effective age verification before launch.

Relevance to training and awareness

Data protection by design and age verification for AI services

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 2, 12 Abs. 1, 13 Abs. 1 und 2, 14 Abs. 1 und 2, 24 Abs. 1, 25 Abs. 2, 27 Abs. 1 und 35 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
negligent
Repeat case
no
Mitigating circumstances
Mitigating: progressively strengthened age checks (a dedicated service for minors, age verification by a third-party provider), no previous relevant infringements, cooperation and amendments to the privacy policy during the proceedings.
Published
9 Jul 2026

Checked against the official source on 28 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial