Your Chatbot Might Be Talking to a Minor
Italy's privacy regulator this week fined the owner of the AI platform Character.AI €158,000, roughly $180,500, over data protection breaches with age-check failures at the heart of the case. Your support chatbot is not Character.AI, and nobody is suggesting otherwise. But the precedent is worth two minutes of your attention, because a regulator has now treated inadequate age handling on an AI service as a data protection matter. And your website does not check ID at the door.
The door nobody checks
Think about who actually lands on your website. If you sell anything families buy, sports, tutoring, retail, entertainment, health, travel, restaurants, then young people reach your pages regularly, and the chat widget in the corner does not distinguish. If that chatbot captures names, email addresses, phone numbers, or stores conversation history, you may be collecting a minor's personal information without ever having made a decision about it. That is the uncomfortable bit: not that anyone acted badly, but that most businesses have simply never considered the question.
Where Canada is heading
Canadian privacy law already governs how you handle personal information, including anything your chatbot collects. What is changing is emphasis. Bill C-36, the proposed Protecting Privacy and Consumer Data Act, would set higher standards for children's information and treat data about anyone under 18 as inherently sensitive, with stronger deletion rights for young people. To be clear, that bill is not law yet and its obligations are not in force, a point we made in our look at C-36. But between today's existing law and that unmistakable direction of travel, assuming nobody will ever ask is a poor bet.
Proportionality beats gates
The instinct is to reach for an age gate or ID check. For most ordinary businesses that is the wrong answer, it adds friction, collects more sensitive data, and solves little. The better principle is proportionality, matched to who realistically uses your service.
| Your situation | Reasonable response |
|---|---|
| B2B only, minors unlikely | Basic data hygiene, note it and move on |
| Consumer service families use | Collect less, retain briefly, be transparent |
| Aimed at or popular with youth | Deliberate design and proper advice |
The middle row covers most businesses reading this, and the actions there are cheap: do not have the bot ask for personal details it does not need, do not keep transcripts longer than useful, and say plainly what gets recorded.
A fifteen-minute check
Ask three questions and answer them honestly. Could a minor plausibly interact with our chatbot, given who we serve? What personal information does it collect, and how long do we keep it? Would we be comfortable explaining that to a parent, or to a regulator? Most businesses find the first answer is "probably yes," the second is "more than we need, for longer than we thought," and the third produces a small wince. That wince is the useful signal, and the fixes it points to are all inexpensive.
Where this leaves you
This is not a reason to pull down your chatbot, they are genuinely useful and most businesses should keep them. It is a reason to make a deliberate decision about something that was probably never decided at all. Collect only what you need, keep it only as long as it is useful, say plainly what the bot records, and be ready to explain it. Fifteen minutes now removes a category of risk that is clearly moving up regulators' priority lists, in Italy this week and, on the current trajectory, in Canada before long.
Frequently Asked Questions
What happened in Italy?
Italy’s data protection authority fined Character Technologies, the US owner of the AI platform Character.AI, €158,000 (about $180,500) for breaches of data protection rules, with age-check failures at the centre of the case. The specific company matters less than the precedent: a regulator treated inadequate age verification on an AI service as a data-protection violation, not merely a content-moderation issue. That is a meaningful signal about where enforcement attention is heading, and it lands as Canada advances privacy reforms that would treat information about young people as inherently sensitive.
Why would this affect my ordinary business chatbot?
Because the internet does not check ID at your door. If you have a chatbot on a public website, young people can reach it, especially if you sell anything families buy: sports, tutoring, retail, entertainment, health, travel, restaurants. If that chatbot collects names, contact details, or conversation history, you may be collecting a minor’s personal information without realizing it. Nobody is suggesting your support bot is Character.AI. The point is that the category of "AI service collecting data from someone who might be underage" now has regulatory attention on it.
What is Canada doing about young people’s data?
Canada already applies privacy law to how businesses handle personal information, and the direction of reform is clear. Bill C-36, the proposed Protecting Privacy and Consumer Data Act, would set higher standards for handling children’s information and treat data about anyone under 18 as inherently sensitive, with stronger deletion rights for young people. That bill is not law yet and its obligations are not in force. But between existing privacy law today and that clear direction of travel, it is a poor bet to assume nobody will ever ask how your AI handles a minor’s data.
Do I need to add age verification to my website?
For most ordinary businesses, no, and heavy-handed ID checks would be a bad answer anyway. Proportionality is the principle: the more sensitive the service and the more likely minors are to use it, the more you should do. A hardware supplier selling to contractors is in a very different position from a tutoring service or a gaming retailer. Practical measures usually beat gates: collect less, retain less, avoid asking a chatbot user for personal details you do not need, and make sure your bot does not push young users toward sharing more than necessary.
What should a Canadian business actually do?
Spend fifteen minutes on three questions. Could a minor plausibly interact with our chatbot, given who we serve? What personal information does it collect and how long do we keep it? Would we be comfortable explaining that to a parent or a regulator? If the honest answers make you uneasy, tighten the obvious things: stop collecting details you do not need, shorten retention, add a plain-language note about what the bot records, and keep transcripts out of places they should not be. Small, sensible steps here cost almost nothing and remove a category of risk most businesses have never considered.
Know what your AI collects, and why
We help Canadian businesses review and tighten what their chatbots and AI tools capture, so you stay useful to customers and comfortable with regulators.
Related Articles
AI Browser Agents Are Getting Safer to Use
What to Ask Your AI Vendor After an Incident
Always-On AI: When Devices Record Everything
AI consultants with 100+ custom GPT builds and automation projects for 50+ Canadian businesses across 20+ industries. Based in Markham, Ontario. PIPEDA-compliant solutions.