Operational notes Observatory

Clearview vs Europe: the €100 million fines nobody collects

6 min read

A corridor between two long rows of numbered archive drawers, in black and white
An archive is measured by how easily it can be searched. That is precisely what changes when faces become a search key.

There is an American company that five European data protection authorities have fined for a total exceeding €100 million. As far as is known, it has not paid a single one. Clearview AI built a facial recognition database by scraping billions of photographs from the web — social networks, news sites, public pages — turning every face into a searchable biometric fingerprint. It sells the tool to law enforcement and government agencies, almost all of them outside the Union. And that is precisely the point: with no premises, customer or asset in Europe, European fines have so far proved to be worth little more than paper. The case is the best available lesson on three issues that concern anyone adopting technology: the face as data, the practical limits of enforcement, and the prohibited practices under the AI Act.

The facts, in order

  • The database: over 30 billion photos according to the Dutch authority in 2024; court filings in the 2025 US litigation cite more than 60 billion. The images are automatically harvested from the web and converted into unique biometric codes, searchable by uploading a photo of a face.
  • Italy: in a ruling dated 10 February 2022, the Garante (Italy’s data protection authority) imposed a €20 million fine, ordered the deletion of data belonging to people in Italy, banned further collection and required the appointment of an EU representative.
  • United Kingdom: an ICO fine of £7.5 million in May 2022; quashed in 2023 by the First-tier Tribunal for lack of jurisdiction; on 7 October 2025 the Upper Tribunal overturned that ruling, finding in favour of the ICO. In December 2025 Clearview was granted permission to appeal to the Court of Appeal: the matter remains open.
  • Greece and France: €20 million each in 2022; in April 2023 the CNIL added a periodic penalty of €5.2 million for failing to comply with the deletion order.
  • Netherlands: the highest fine to date, €30.5 million in September 2024, plus penalties of up to €5.1 million. The authority stated it was considering the personal liability of the company’s executives, and in 2025 the organisation noyb filed a criminal complaint against the company and its leadership.
  • The company’s position: Clearview maintains it has no premises, customers or activity in the Union and is therefore not subject to the GDPR; it has described the Dutch decision as “unlawful, lacking due process and unenforceable”. It claims to process only publicly accessible images and to assist investigations into serious crimes.
  • In the United States: in March 2025 a federal judge approved the settlement of the Illinois class action (under the BIPA law): the class receives 23% of the company’s equity, worth around $51.75 million — a solution contested by 22 state attorneys general. Back in 2022, the settlement with the ACLU had already barred sales to most private parties in the US.

Lesson one: the face is data — and it cannot be revoked

A compromised password can be changed. A face cannot. Biometric data is the most sensitive category of personal data there is, and the GDPR treats it as such: a special category of data, processing prohibited save for narrow exceptions. The Clearview case shows that a face published online — a profile picture, a company award ceremony, a newspaper article — has become industrial raw material, without the knowledge of the people concerned. For anyone buying technology, the consequence is direct: if a supplier processes the faces of your employees or customers, the lawfulness of that collection is your problem too, not just theirs. A model trained on unlawfully sourced data contaminates the chain of everyone who uses it: compliance due diligence on AI suppliers is not bureaucracy, it is risk management.

Lesson two: an uncollected fine is no deterrent

Five authorities, one hundred million euros, zero euros collected. The GDPR has extraterritorial reach on paper, but enforcing it against a company with no EU establishment runs into a simple fact: the United States, like many countries, does not recognise foreign administrative penalties. The authorities know this — the Greek regulator has admitted it chose the maximum statutory fine for its symbolic value. The lesson for technology adopters cuts both ways. First: you cannot delegate your own protection to the regulator — if the supplier sits outside the jurisdiction, the only safeguards that actually work are contractual and architectural: where the data resides, which court has jurisdiction, what legally attachable presence exists. Second: for a public body using similar tools, the risk does not evaporate along with the supplier — it stays with whoever deploys them, as public administrations in several countries have discovered when called to account for their officers’ use of Clearview.

Lesson three: the AI Act has already drawn the line

Since 2 February 2025, Article 5 of the AI Act has expressly prohibited the untargeted scraping of facial images from the internet or CCTV footage to build or expand facial recognition databases. This is a prohibited practice: the fine can reach 7% of worldwide turnover, and liability extends to the deployer too — whoever uses the system, not only whoever builds it. In Europe, the Clearview model is therefore unlawful by definition, whatever the outcome of the GDPR appeals. Anyone designing operational AI systems on sensitive data must start here: first map the prohibited practices and the human-oversight safeguards, only then the technology.

What to do

  1. Map every biometric processing activity, including indirect ones: access control, “smart” video surveillance, supplier tools.
  2. Ask every recognition or AI supplier in writing for the provenance of their training data: contractual statements, not reassurances.
  3. Verify EU establishment and jurisdiction: without an attachable presence, even your contractual remedies are worth as much as the uncollected fines.
  4. Cross-check the project against Article 5 of the AI Act before signing: biometrics is the area with the most prohibited practices.
  5. Document the legal basis and human oversight for every security-related use: it is the first thing an authority will ask for.

Do you process biometric data, or are you evaluating a supplier that does? Half an hour with one of our experts to work out where your exposure lies.

Sources