The encyclopedia · Legal & Compliance · Legal decision · 2022–2025
Clearview AI scraped billions of faces and Europe fined it country by country
Clearview hoovered up people's faces for a facial-recognition tool, and one regulator after another said it was processing with no lawful basis.
Clearview AI · 2022-02-10
What happened
Clearview AI scraped billions of images of faces from social media and the open web to build a facial-recognition database sold to law enforcement. National data-protection authorities across Europe concluded the company processed that data with no lawful basis, and fined it in jurisdiction after jurisdiction.
Italy's Garante imposed a €20 million fine on 10 February 2022, banned further scraping of images of people in Italy, ordered the erasure of the biometric data in its system, and required the company to designate a representative in the EU. France fined Clearview €20 million the same year, Greece €20 million in 2022, and the Netherlands €30.5 million in 2024, with the UK and Australia adding smaller penalties and tougher remedial orders.
The fines were cumulative rather than a single settlement. Clearview largely declined to pay the European penalties, and by 2025 it was still contesting or dodging collection in several countries even as more regulators lined up behind the same conclusion.
Why it happened
- Treating a face as public data removed consent from the calculation — but a face is identifiable personal data, and scraping it at scale is a processing act that GDPR requires a basis for.
- Betting that a US company could ignore EU enforcement underestimated the reach of the GDPR, which applies to any processor handling the data of people in the Union.
- Having a single product that every regulator rejected meant there was no fallback and no way to settle once; each country's fine was a separate bill Clearview could not absorb and move on.
The lesson
Scraping personal data at scale without a lawful basis earns a fine in every jurisdiction, and a business built on a ground regulators everywhere reject has no plan B.
Sources
- Facial recognition — the Italian SA fines Clearview AI €20 million — EU DPOS (efdpo.eu)
- Italian supervisory authority imposes €20 million fine on a controller outside of Europe — Alston & Bird Privacy
spotted an error? The club wants to know.
More like this
The MOVEit breach hit 2,500 organizations — because one file transfer tool had a zero-day
Hackers hid in SolarWinds' update — 18,000 organizations installed the backdoor
HP India rigged government tenders through its resellers — ₹142.37 crore CCI fine
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.