DEV Community

Multigrid
Multigrid

Posted on • Originally published at multigrid.ai

Clearview AI's GDPR Fines: a Dated, Multi-Country Tally

Five European authorities have penalised Clearview AI over the same conduct: scraping facial images from the public web and social media into a searchable biometric database. The decisions are separate, the amounts differ, and the enforcement outcome is not what the sum suggests.

The tally, by authority and date

  • Italy — Garante, €20 million. Decision adopted 10 February 2022 and announced on 9 March 2022. The authority found that Clearview monitored and processed the biometric data of people in Italy without a legal basis, and ordered deletion of the data of people in Italy along with a prohibition on further collection. The EDPB’s national news entry for the Italian decision summarises it.
  • Greece — Hellenic DPA, €20 million. Decision 35/2022, issued 13 July 2022 on a complaint brought with the support of the digital rights organisation Homo Digitalis. The authority found breaches of the lawfulness and transparency principles and of the obligations in Articles 12, 14, 15 and 27, prohibited collection and processing of the data of people in Greece, and ordered deletion. The Hellenic DPA’s own announcement is the primary record.
  • France — CNIL, €20 million. Sanction adopted by the CNIL’s restricted committee in October 2022, following an earlier order to comply that Clearview did not answer. The decision also ordered the company to stop collecting and to delete the data it held on people in France. The CNIL’s English summary of the sanction is published on its site.
  • Netherlands — Autoriteit Persoonsgegevens, €30.5 million. Decision taken in May 2024 and made public on 3 September 2024, the largest of the set, with an order to stop the violations and an announced possibility of further penalty payments for continued non-compliance. The EDPB’s entry for the Dutch decision records the amount.
  • United Kingdom — ICO, £7,552,800. Monetary penalty notice issued in May 2022 under the UK GDPR, with an enforcement notice requiring deletion of UK residents’ data. This one is not final: see below.

The EU decisions come to roughly €90.5 million in headline penalties, plus the UK notice. Each was taken by a national authority acting on its own territory, which is possible because Clearview has no establishment in the Union and so no one-stop-shop lead authority exists to concentrate the file.

A tally of published decisions as at the date on this page, not legal advice, and not a complete list of every complaint or proceeding worldwide. Amounts and statuses change — check each authority’s own register before citing a figure.

France added a penalty payment on top

The French sequence is the one that shows what happens when a company simply does not respond. The CNIL had ordered Clearview to comply within two months, and when it did not, imposed the €20 million sanction along with an injunction to cease collection and to delete the data, backed by a daily penalty payment for continued non-compliance. In May 2023 the CNIL announced that the accrued overdue penalty payment had crystallised at €5.2 million.

That is a separate instrument from the fine and it is worth understanding on its own: an astreinte accumulates for as long as the order is ignored, so a company that treats a European regulator as unreachable does not freeze its exposure at the headline number. It grows.

The UK penalty is still being litigated

The ICO’s May 2022 penalty took a different path, and it is the reason the UK figure should never be quoted as settled.

In October 2023 the First-tier Tribunal allowed Clearview’s appeal, holding that the processing fell outside the territorial reach of the UK GDPR because Clearview’s clients were foreign law enforcement and national security bodies, whose activities fall outside the material scope of the regulation. The ICO appealed. In October 2025 the Upper Tribunal allowed the Commissioner’s appeal on three of four grounds, holding that Clearview’s processing does relate to monitoring the behaviour of people in the UK and does not escape UK data protection law merely because the service was supplied to foreign state clients, and remitted the substantive appeal to the First-tier Tribunal on the basis that the Commissioner did have jurisdiction. The judgment is reported as [2025] UKUT 319 (AAC), and the ICO’s statement on the judgment sets out its reading; the judgment itself is published on GOV.UK.

Clearview was granted permission to appeal to the Court of Appeal in December 2025. So the position at the time of writing is that the penalty has not been quashed and has not been upheld: a jurisdictional ruling is under appeal, and the merits have not been decided by anyone. Anybody citing the ICO fine as an established outcome is describing a case that is still running.

Why the totals are misleading

The arithmetic is easy and the collection is not. Clearview has no establishment, no assets and no designated Article 27 representative in the jurisdictions that fined it, and a GDPR fine is an administrative penalty rather than a court judgment — so enforcing it against a US company requires a mechanism that does not straightforwardly exist. Reporting through 2024 and 2025 indicated that the European fines had gone substantially unpaid, and the Italian regulator was still publicly discussing collection years after its decision.

Three consequences follow, and they are the useful part of this page for anyone doing risk assessment.

  • The deterrent here is market access, not the money.Each decision carries a prohibition on processing and an order to delete. Those bind whether or not the fine is collected, and they are what makes the European market effectively closed to the product.
  • The exposure follows the customers. A US company with no EU footprint can ignore a penalty in a way that a company with EU customers, EU staff or EU cloud spend cannot. If you have anything in Europe to enforce against, the Clearview outcome is not your outcome.
  • The record persists. Five published findings of unlawful processing are a fact about the company that shows up in every procurement review, every DPIA that names it and every subsequent proceeding, regardless of collection.

What actually transfers to other AI companies

Clearview is an outlier in its product and not an outlier in its legal theory, which is why the decisions matter to companies doing nothing like face search.

The finding that runs through all of them is that scraping publicly accessible material does not make the resulting processing lawful. Public availability is not a lawful basis; it is a fact about where the data was. The authorities that reached legitimate interests as a question found the balancing failed, given that the people concerned had no relationship with the company and no expectation of being enrolled in a search index — the same analysis that any web-scraping lawful basis assessment has to survive.

The second transferable point is the special category one. Facial images processed for the purpose of uniquely identifying a person are biometric data under Article 9, which starts from a prohibition and requires one of the narrow Article 9(2) conditions to lift it. Several of these decisions turn on that structure rather than on the Article 6 basis, and it is a materially harder test — the Article 9 position for biometric AI is the one to check first if your system touches faces, voices or fingerprints.

The third is procedural: with no EU establishment, Clearview faced five regulators instead of one. Establishment is usually discussed as a tax and corporate question. In data protection it is also the difference between one supervisory relationship and a queue of them.

Related

Top comments (0)