Activists and researchers file a GDPR complaint against Pornhub in Italy, claiming the company is “illegally” handling users' data; the process could take years
Complaints filed in the European Union claim the porn site fails to follow basic data-collection policies under GDPR.
Context & Ripple Effects
Italy's privacy establishment has been willing to move first against big platforms: in 2023 the same regulator temporarily banned ChatGPT over mass collection of personal data. This new GDPR complaint, filed by activists and researchers rather than the regulator itself, extends that pressure to MindGeek-owned Pornhub — the secretive operator behind 115M+ daily visitors whose ownership structure was only mapped out in a 2020 investigation.
The complaint lands while Pornhub is already fighting a multi-front battle in Europe: it challenged the EU over new DSA moderation rules alongside Xvideos and Stripchat, and the Commission later opened a priority probe that ended in preliminary findings accusing the four platforms of failing to protect kids. Italy separately moved to force age verification for every visit to sites including Pornhub, YouPorn, and OnlyFans.
First-order effects
- Italy's privacy regulator must now triage a complaint alleging illegal data handling by Pornhub — a process the filing itself says could take years, meaning no immediate enforcement action but a formal record that constrains the company's future claims of compliance.
- Pornhub now faces overlapping legal exposure in Europe: GDPR data-handling allegations in Italy stacked on top of the Commission's DSA child-safety investigation into the same platform.
Second-order effects
- If Italy follows its ChatGPT precedent from inquiry toward blocking or fines, Pornhub's response will be watched by Stripchat, XNXX, and XVideos — the same cohort named in the DSA probe — who face copycat GDPR filings from activist researchers in other member states.
- A years-long GDPR track running in parallel with faster DSA enforcement shifts the burden onto Pornhub's compliance operations, which must satisfy two regimes with different timelines for the same user-data practices.
Third-order effects
- The pattern points toward adult platforms being regulated not by one law but by layered regimes — GDPR on data handling, the DSA on child safety, national laws on age verification — where activists can seed national cases that Brussels then formalizes.
- If national regulators keep acting ahead of the Commission, as Italy did with both OpenAI and this complaint, GDPR enforcement becomes decentralized: platform risk depends less on EU-level rules than on which member state's regulator moves first.
The trend: European regulators are converging on large adult platforms from three directions at once — GDPR data protection, DSA child-safety enforcement, and national age-verification mandates — with Italy repeatedly the first mover.