Skip to content
  • AUDIT & CERTIFICATION
    • ISO 42001
    • ISO 27001
    • ISO 27701
    • EU AI ACT
  • TRAINING
    • ISO 42001 LEAD AUDITOR
    • EU AI ACT
  • PARTNERS
    • GLOBAL NETWORK
    • AUDITOR COMMUNITY
  • RESOURCES
  • ABOUT US
  • AUDIT & CERTIFICATION
    • ISO 42001
    • ISO 27001
    • ISO 27701
    • EU AI ACT
  • TRAINING
    • ISO 42001 LEAD AUDITOR
    • EU AI ACT
  • PARTNERS
    • GLOBAL NETWORK
    • AUDITOR COMMUNITY
  • RESOURCES
  • ABOUT US
    • Español
Contact us
    • Español
  • AUDIT & CERTIFICATION
    • ISO 42001
    • ISO 27001
    • ISO 27701
    • EU AI ACT
  • TRAINING
    • ISO 42001 LEAD AUDITOR
    • EU AI ACT
  • PARTNERS
    • GLOBAL NETWORK
    • AUDITOR COMMUNITY
  • RESOURCES
  • ABOUT US
Contact us
October 21, 2024

Clearview AI Fined €30.5 Million for GDPR Violations: Largest Penalty in Europe

Clearview AI has been fined €30.5 million by the Netherlands for violating the GDPR. The penalty could rise to €35.6 million if the company doesn't comply, and executives may face personal liability.

Share:

A Historic Fine in Europe

The Autoriteit Persoonsgegevens (AP), the Netherlands’ Data Protection Authority, has imposed a record-breaking fine of €30.5 million on Clearview AI, a U.S.-based facial recognition company. This is the largest fine Clearview AI has faced in Europe for violating the General Data Protection Regulation (GDPR). The fine relates to the company’s illegal collection and storage of biometric data without proper consent, marking a significant enforcement action in Europe.

The Largest GDPR Fine to Date

This €30.5 million fine imposed by the Netherlands’ AP surpasses all previous fines levied against Clearview AI by data protection authorities in countries such as France, Italy, Greece, and the United Kingdom. In addition, the AP warned that if Clearview AI continues to ignore GDPR requirements, an additional €5.1 million penalty will be enforced, potentially raising the total fine to €35.6 million.

Investigations Leading to the Fine

The AP launched its investigation into Clearview AI in March 2023 after receiving complaints from Dutch citizens who were denied access to their personal data, a clear violation of the GDPR. Under GDPR rules, EU citizens have the right to access their data or request its deletion. Clearview AI has been found to repeatedly ignore these requests, breaching multiple provisions of the GDPR.

GDPR Violations by Clearview AI

Clearview AI’s core violation involved building a biometric database from millions of images scraped from the internet without obtaining consent from the individuals depicted. This unauthorized data collection violated GDPR regulations, which require a valid legal basis for collecting and processing personal data, particularly biometric data. The AP highlighted that Clearview’s actions were not only illegal but also lacked transparency, further compounding the violation.

Lack of Transparency and Legal Basis

Clearview AI’s failure to provide transparency in its data collection practices is a major concern under GDPR, which demands that companies inform individuals about how their data is being used. In this case, the AP emphasized that Clearview AI had no valid justification for collecting biometric information from millions of people and never informed those individuals about the existence of this database.

Potential Personal Liability for Clearview AI Executives

Despite facing multiple fines across Europe, Clearview AI has shown little willingness to comply with European privacy laws. The company has failed to appoint a legal representative in the EU, a GDPR requirement for non-EU companies processing European citizens’ data. This non-cooperation has made enforcing fines more difficult.

Holding Executives Personally Accountable

In response to Clearview AI’s lack of compliance, the AP is considering an unprecedented step: personal liability for the company’s executives. Aleid Wolfsen, the president of the AP, has suggested that if it is proven that Clearview’s executives were aware of the GDPR violations and had the power to stop them but chose not to, they could face individual penalties. This approach could put pressure on the company to take GDPR compliance seriously, as it may prevent executives from traveling freely to Europe without facing legal consequences.

Conclusion: A Landmark GDPR Enforcement Case

Clearview AI’s record-breaking €30.5 million fine marks a significant moment in GDPR enforcement, underscoring the importance of data privacy and the EU’s commitment to upholding its regulations. With potential fines reaching €35.6 million and the possibility of personal liability for executives, this case sets a new precedent for companies handling biometric data and operating in violation of European privacy laws. The clear message to companies is that non-compliance with the GDPR will not be tolerated, and enforcement measures will only become stricter.

You May Also Be Interested In

US Congress Cracks Down on Deepfakes

DeepMind Employees Unite Against Military-Linked AI Projects

U.S. and China Race to Bring AI into the Classroom

EU AI Act Setback:Standards Won’t Arrive Until 2026

Contact Us

Let us know how we can assist you by completing this short form.

Zertia
  • About us
  • Contact Us
  • Resources
Services
  • ISO 42001
  • ISO 27001
  • ISO 27701
  • EU AI Act
Partners
  • Global Network
  • Auditor Comunity
Information
  • Certification Procedures​
  • Impartiality Policy
  • Media
Social
  • LinkedIn
  • Youtube
Memberships
  • IAPP
  • INCITS
  • EU AI Pact
  • AI & Partners
  • © 2025 Zertia | All Rights Reserved
  • Legal Notice
  • Terms and Conditions of Use
  • Privacy Policy
  • Cookies Policy
We Care About Your Privacy

We use our own and third-party cookies to compile statistics on the use of the website in order to identify faults and improve the content and configuration of the website. We also use own and third party cookies to remember some options you have chosen (language, for example) and to show you advertising related to your preferences, based on a profile developed from your browsing habits (for example, from the web pages visited).

Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
3rd Party Cookies
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc. Keeping this cookie enabled helps us to improve our website.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
Show Purposes
{title} {title} {title}
We Care About Your Privacy
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
3rd Party Cookies
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc. Keeping this cookie enabled helps us to improve our website.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
Show Purposes
{title} {title} {title}
Thank you for contacting us
Your message has been sent successfully, we will contact you as soon as possible.