A Korean regulator fined a chatbot maker over reused chat logs
PIPC's 2021 decision documents how ScatterLab trained Iruda on KakaoTalk chats collected for other apps.
- Historical event
- April 28, 2021
- First source published
- April 28, 2021
- Site publication
- September 18, 2026

What happened
On 28 April 2021, South Korea's Personal Information Protection Commission (PIPC) held its seventh plenary session and fined ScatterLab, developer of the chatbot Iruda, a combined 103.3 million won in fines and penalties. The commission's press release and its attached enforcement notice describe it as the country's first sanction of an AI firm's data handling. PIPC says it opened its inquiry on 12 January 2021 after press reports, a date confirmed by contemporaneous coverage from AI Times, published the same day as the decision.
What the documents show
The enforcement notice sets out eight violations. ScatterLab had collected KakaoTalk conversation logs through two older apps, Text At and Science of Love, and used roughly 9.4 billion sentences from about 600,000 users to train and operate Iruda without a separate, explicit consent for that new purpose. Around 100 million sentences drawn from young women's conversations were built into a response database the chatbot could select from, and the commission found no names, phone numbers or addresses in that training data had been removed or encrypted. A further violation covered code-sharing site postings that paired the AI model with excerpts of real users' chats, including names and location detail. AI Times' report adds that the investigation followed specific press allegations, corroborating the sequence PIPC's own notice implies.
The mechanism
The case turns on purpose limitation, a core data-protection principle: information gathered under one stated purpose cannot be repurposed for another without fresh consent. ScatterLab's terms mentioned 'new service development' in general terms, but the commission judged that language too vague for a user to have anticipated their private chats would train a public-facing companion bot. This is distinct from a security breach; nothing was stolen or hacked. The failure was in reuse, not access control, which is why the fine covers both a data-protection fine and separate administrative penalties for related lapses such as not deleting withdrawn users' data.
What it leaves open
The notice does not say how long the disputed response database had been in production use before removal, nor does it quantify harm to individuals whose chats appeared on the code-sharing site. It is silent on any later civil claims users may have pursued separately; this record covers only the regulatory penalty. Editorially, the case is most useful as a boundary marker for one-sided chat collection: PIPC's own guidance treats a chat log as the collecting party's personal data when only one participant consents, a narrower protection than many users likely assume.
- Does a companion app's privacy policy name the specific product that will use your conversation data, or only a general phrase like 'service improvement'?
- If a chatbot is trained partly on real users' messages, were those messages collected for that stated purpose or repurposed from an earlier product?
- Does the developer distinguish between a security failure and a consent failure when describing what went wrong?
The Iruda decision reads less as a story about a chatbot behaving badly and more about where its training data came from, a distinction worth carrying into any later claim that a companion model was built responsibly.
Sources & reading trail
Official notice of the plenary session, the total fine and the case's status as the first of its kind.
Source published: 28 April 2021 · Retrieved: 16 September 2026
Itemised table of the eight violations, fine and penalty amounts, and the commission's reasoning on purpose limitation.
Source published: 28 April 2021 · Retrieved: 16 September 2026
Contemporaneous reporting dating the start of PIPC's investigation to 12 January 2021 and summarising the training-data scale.
Source published: 28 April 2021 · Retrieved: 16 September 2026
Company documents, filings, studies and official records establish the record; the reading and the questions are Lovebot Journal editorial analysis. This retrospective draft does not imply the site published on the event date.
Continue reading
- Three companion privacy policies diverge on chat data
- A privacy review found every romantic chatbot it tested fell short
- Wellbeing studies on chatbots differ in size and funding
- Browse the complete the archive
Sources & reading trail
- PIPC imposes fines and penalties on Scatter Lab, developer of 'Iruda'
Source published: April 28, 2021 · Retrieved: September 16, 2026 - Press release attachment: administrative sanction detail and Q&A on Scatter Lab / Iruda
Source published: April 28, 2021 · Retrieved: September 16, 2026 - PIPC, AI chatbot 'Iruda' developer Scatter Lab fined 103.3 million won
Source published: April 28, 2021 · Retrieved: September 16, 2026
The documents above establish the record. The reading and the questions are this publication’s editorial analysis, written after the fact.
Published September 18, 2026, not on the date of the event described.