
The design
On 2 February 2023, Italy's data protection authority, the Garante per la protezione dei dati personali, adopted an emergency order against Luka Inc., the US company that develops and operates the Replika chatbot, imposing what its own text calls a “provisional limitation” on processing the personal data of users in Italy, with immediate effect. The Garante announced the measure the next day in an English-language press release titled “Artificial intelligence: Italian SA clamps down on 'Replika' chatbot.” The order itself, issued under the GDPR's urgency power at Article 58(2)(f), states it found no age-verification mechanism at signup or during use, App Store reviews from users describing sexually inappropriate replies, and a privacy policy that failed the Regulation's transparency requirements under Article 13.
What the evidence says
Both documents are the Garante's own account; this entry describes what the regulator's order and press release state, not a court's finding, since no court had ruled on Replika at this stage. The order reasons that because Replika's features act on a user's mood and emotional state, they can raise the risk of harm to children and “emotionally fragile” people, and that processing a minor's data could not lawfully rest on a contract, since Italian law holds minors incapable of validly entering into one. On that basis the Garante found violations of Articles 5, 6, 8, 9 and 25 of the GDPR.
What it asks of people
The order required Luka Inc. to stop processing Italian users' personal data immediately and to report back to the Garante within 20 days on what measures it had taken, under threat of a fine of up to €20 million or 4% of the company's global annual turnover for failing to comply with the order itself, a separate question from any fine for the underlying conduct.
Privacy and safeguards
The order is explicit that it is a provisional, urgent measure: it states the Garante's decision is taken with full reservation of any activity to ascertain further violations, meaning the formal investigation into the underlying conduct continued after this order and was not resolved by it. No monetary sanction was imposed at this stage; that came later, in a separate 2025 decision covered elsewhere in this archive.
- What specific evidence did the Garante rely on beyond app-store reviews when assessing risk to minors?
- How quickly did Luka Inc. comply with the reporting deadline the order set?
- Did the provisional limitation actually stop Italian users from accessing Replika, or only from having new data processed?
An emergency order is a regulator acting on an urgent finding, not a final verdict; the Garante's own text here describes immediate risk and immediate remedy, leaving the fuller legal assessment to the investigation it says was still underway.
Sources & reading trail
The Garante's own English-language press release announcing the emergency order and summarizing its grounds.
Source published: 3 February 2023 · Retrieved: 16 September 2026
The Garante's formal order text (in Italian), citing the specific GDPR articles found violated and the urgency power invoked.
Source published: 2 February 2023 · Retrieved: 16 September 2026
Product documents, regulator records and studies establish the entry; the design reading is AI Companions editorial analysis. This retrospective draft does not imply the site published on the event date.