2025-W22 Replica with EUR 5M Fine, Meta Wins Big, EU Commision Indecisive episode artwork

EPISODE · May 29, 2025 · 24 MIN

2025-W22 Replica with EUR 5M Fine, Meta Wins Big, EU Commision Indecisive

from Privacy Navigator: Weekly Insights on Privacy, AI, and Compliance · host Elislav Atanasov

Garante Slams Replika with a EUR 5M FineThe Italian Data Protection Authority (Garante) has imposed significant corrective measures, including EUR 5M fine and a potential ban on processing Italian users' data, against Luka Inc., the company behind the AI chatbot Replika.According to the decision, the Garante found multiple GDPR breaches:Lack of Legal Basis: Particularly for processing sensitive data inferred from user conversations, including emotional and health-related information (violating Articles 6 and 9).Transparency Failures: Insufficient information provided to users about how their data, especially chat content, would be used for training AI models (Article 13).Risks to Minors: Inadequate age verification systems, leading to the unlawful processing of children's data (Article 8).No DPIA: Failure to conduct a Data Protection Impact Assessment for what is clearly high-risk processing activity (Article 35).Data Protection by Design/Default Deficiencies: Principles of Article 25 not adequately implemented.The "black box" nature of some AI models won't fly if the fundamentals of GDPR – legal basis, transparency, risk assessment, and data protection by design – are not robustly addressed from the outset.For AI companions and similar services, inferred data is increasingly seen as sensitive, requiring explicit consent.Meta Pushes Ahead with EU User Data for AI TrainingThis is the first time we report privacy news in favour of Meta. It’s odd. It seems that legitimate interest could be the way to go, after all, for AI trainingFirst, the Cologne Higher Regional Court in Germany made a significant ruling concerning Meta's use of publicly available user data for training its artificial intelligence systems. The court found that Meta's actions were lawful under Article 6(1)(f) of the General Data Protection Regulation (GDPR).The court recognized Meta's interest in training its AI as a legitimate aim. A key point in the ruling was the acknowledgement that training effective AI models requires vast quantities of data.Additionally, Meta has signaled its intention to train its AI with user data to the Irish DPC, which is the leading DPA. Again, Meta is expected to rely on "legitimate interests" (Article 6(1)(f) GDPR) as the legal basis for this processing.The Irish DPC issued a statement confirming it is engaging with Meta on these plans.Using opt-out for AI training data is raises many questions. Once data is ingested and used to train a foundational model, can it truly be "unlearned" or its influence fully erased if a user objects later?How to opt out?If you haven't already, here is how to opt out from Meta using your personal data for AI training.Here’s the direct link to submit your request to Meta.If for some reason the link doesn't work make sure to go to Privacy > Privacy Center > Privacy Topics > Submit an objection requestYou will have to do the same for each social media platform you use...Yes, it's infuriating. It's called malicous compliance.EU Commision Suggests EU AI Act Pause and GDPR SimplificationWhile the EU AI Act is formally adopted and its phased entry into force continues, the path to full practical implementation is hitting some turbulence.Recent reports indicate that the development of harmonized technical standards, which are vital for companies to demonstrate compliance for high-risk AI systems, is taking longer than initially anticipated, with some now expected in 2026. Similarly, the Code of Practice for General-Purpose AI (GPAI) models has faced pushback and delays in finalization.Separately, but related to the AI ecosystem, on May 21, 2025, the European Commission announced a series of simplification measures aimed at reducing administrative burdens and cutting red tape for EU businesses, particularly Small and Medium-sized Enterprises (SMEs).

Garante Slams Replika with a EUR 5M FineThe Italian Data Protection Authority (Garante) has imposed significant corrective measures, including EUR 5M fine and a potential ban on processing Italian users' data, against Luka Inc., the company behind the AI chatbot Replika.According to the decision, the Garante found multiple GDPR breaches:Lack of Legal Basis: Particularly for processing sensitive data inferred from user conversations, including emotional and health-related information (violating Articles 6 and 9).Transparency Failures: Insufficient information provided to users about how their data, especially chat content, would be used for training AI models (Article 13).Risks to Minors: Inadequate age verification systems, leading to the unlawful processing of children's data (Article 8).No DPIA: Failure to conduct a Data Protection Impact Assessment for what is clearly high-risk processing activity (Article 35).Data Protection by Design/Default Deficiencies: Principles of Article 25 not adequately implemented.The "black box" nature of some AI models won't fly if the fundamentals of GDPR – legal basis, transparency, risk assessment, and data protection by design – are not robustly addressed from the outset.For AI companions and similar services, inferred data is increasingly seen as sensitive, requiring explicit consent.Meta Pushes Ahead with EU User Data for AI TrainingThis is the first time we report privacy news in favour of Meta. It’s odd. It seems that legitimate interest could be the way to go, after all, for AI trainingFirst, the Cologne Higher Regional Court in Germany made a significant ruling concerning Meta's use of publicly available user data for training its artificial intelligence systems. The court found that Meta's actions were lawful under Article 6(1)(f) of the General Data Protection Regulation (GDPR).The court recognized Meta's interest in training its AI as a legitimate aim. A key point in the ruling was the acknowledgement that training effective AI models requires vast quantities of data.Additionally, Meta has signaled its intention to train its AI with user data to the Irish DPC, which is the leading DPA. Again, Meta is expected to rely on "legitimate interests" (Article 6(1)(f) GDPR) as the legal basis for this processing.The Irish DPC issued a statement confirming it is engaging with Meta on these plans.Using opt-out for AI training data is raises many questions. Once data is ingested and used to train a foundational model, can it truly be "unlearned" or its influence fully erased if a user objects later?How to opt out?If you haven't already, here is how to opt out from Meta using your personal data for AI training.Here’s the direct link to submit your request to Meta.If for some reason the link doesn't work make sure to go to Privacy > Privacy Center > Privacy Topics > Submit an objection requestYou will have to do the same for each social media platform you use...Yes, it's infuriating. It's called malicous compliance.EU Commision Suggests EU AI Act Pause and GDPR SimplificationWhile the EU AI Act is formally adopted and its phased entry into force continues, the path to full practical implementation is hitting some turbulence.Recent reports indicate that the development of harmonized technical standards, which are vital for companies to demonstrate compliance for high-risk AI systems, is taking longer than initially anticipated, with some now expected in 2026. Similarly, the Code of Practice for General-Purpose AI (GPAI) models has faced pushback and delays in finalization.Separately, but related to the AI ecosystem, on May 21, 2025, the European Commission announced a series of simplification measures aimed at reducing administrative burdens and cutting red tape for EU businesses, particularly Small and Medium-sized Enterprises (SMEs).

NOW PLAYING

2025-W22 Replica with EUR 5M Fine, Meta Wins Big, EU Commision Indecisive

0:00 24:03

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

MG Show MG Show The MG Show, hosted by Jeffrey Pedersen and Shannon Townsend, is a leading alternative media platform dedicated to uncovering the truth behind today’s most pressing political issues. Launched in 2019, the show has grown exponentially, offering unfiltered insights, comprehensive research, and real-time analysis. With a commitment to independent journalism and factual integrity, the MG Show empowers its audience with knowledge and encourages active participation in the political discourse. Breaking News Show | eTurboNews Juergen Thomas Steinmetz News is relevant to the global travel and tourism industry, human rights and global issues.Breaking news when it happens and only from the source. Eat to Live Jenna Fuhrman, Dr. Fuhrman Our health is our most precious gift and smart nutrition can change your life. Each month, join Dr. Fuhrman and his daughter, Jenna Fuhrman as they discuss important topics in the world of nutrition. Eat to Live will change the way you eat and think about food. French Your Way Jessica: Native French teacher founder of French Your Way Boost your French listening skills and test your comprehension with this one of a kind series of podcasts. Get the chance to listen to a real conversation between native speakers talking at normal speed AND customise your learning experience through carefully designed sets of questions (2 levels of difficulty) available for download at www.frenchvoicespodcast.com. All interviews also come with the transcript. French teacher Jessica interviews native speakers of French from around the world who share a bit of their life and passion. Where else would you meet in one same place a French yoga teacher based in Melbourne, a soap manufacturer from Provence, or a couple cycling around the world?

Frequently Asked Questions

How long is this episode of Privacy Navigator: Weekly Insights on Privacy, AI, and Compliance?

This episode is 24 minutes long.

When was this Privacy Navigator: Weekly Insights on Privacy, AI, and Compliance episode published?

This episode was published on May 29, 2025.

What is this episode about?

Garante Slams Replika with a EUR 5M FineThe Italian Data Protection Authority (Garante) has imposed significant corrective measures, including EUR 5M fine and a potential ban on processing Italian users' data, against Luka Inc., the company behind...

Can I download this Privacy Navigator: Weekly Insights on Privacy, AI, and Compliance episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!