Enforcement
Clearview AI: 30.5 million euro fine and penalty orders for illegal facial database
- Date
- Status
- final
- Body
- Autoriteit Persoonsgegevens
- Reference
- Besluit tot opleggen boetes en lasten onder dwangsom Clearview AI Inc., AP, 16 mei 2024 (kenmerk niet gepubliceerd; bekendgemaakt 3 september 2024)
- Amount
- €30,500,000
What it is about
Clearview scrapes more than 30 billion face photos from the internet, including of Dutch people, and converts them into biometric codes for intelligence and law enforcement clients. The Dutch DPA imposed two fines. The first, 20 million euros, covers processing without a legal basis (Article 5(1)(a) with Article 6(1)), processing biometric data (Article 9(1)) and failing to inform data subjects (Article 12(1) with Article 14). The second, 10.5 million euros, covers ignoring access requests and not facilitating the right of access (Article 12(2) and (3) with Article 15). Four penalty orders, including one for having no EU representative (Article 27), add up to a maximum of 5.1 million euros. Clearview did not object, so the decision is final. The DPA warns that using Clearview's services is also prohibited.
What this means in practice
Harvesting biometric data from public sources is prohibited even when the photos are public; the internet is not a free source. According to the DPA, Dutch organisations that use Clearview can expect substantial fines. A non EU company processing data of people in the EU falls under the GDPR and must appoint a representative. The DPA is examining whether directors can be held personally liable.
The GDPR articles concerned
- Article 5: Principles relating to processing of personal data
- Article 6: Lawfulness of processing
- Article 9: Processing of special categories of personal data
- Article 12: Transparent information, communication and modalities for the exercise of the rights of the data subject
- Article 14: Information to be provided where personal data have not been obtained from the data subject
- Article 15: Right of access by the data subject
- Article 27: Representatives of controllers or processors not established in the Union
Source: Autoriteit Persoonsgegevens, besluit boete en lasten onder dwangsom Clearview AIchecked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Themes where this returns
- Automated decisions and human oversight
- Biometrics and emotion recognition
- Data quality, minimisation and data governance
- Keeping records: record of processing, technical documentation and logs
- Rights of people: access and explanation of decisions
- Transparency: informing people
- Using special categories of personal data to detect bias
The counterpart in the other law
- Article 2 AI Act: Scope
via Using special categories of personal data to detect bias
- Article 3 AI Act: Definitions
- Article 5 AI Act: Prohibited AI practices
- Article 6 AI Act: Classification rules for high-risk AI systems
- Article 10 AI Act: Data and data governance
- Article 11 AI Act: Technical documentation
via Keeping records: record of processing, technical documentation and logs
- Article 12 AI Act: Record-keeping
via Keeping records: record of processing, technical documentation and logs
- Article 14 AI Act: Human oversight
- Article 18 AI Act: Documentation keeping
via Keeping records: record of processing, technical documentation and logs
- Article 19 AI Act: Automatically generated logs
via Keeping records: record of processing, technical documentation and logs
- Article 26 AI Act: Obligations of deployers of high-risk AI systems
via Keeping records: record of processing, technical documentation and logs
- Article 50 AI Act: Transparency obligations for providers and deployers of certain AI systems
- Article 86 AI Act: Right to explanation of individual decision-making
Case law8 of 17
- Interim relief judge: DPA must redact fine amount when giving an enforcement decision to complainants
2024-05-31 · status not established, Rechtbank Den Haag, voorzieningenrechter (kort geding, team handel)
- Noord-Nederland District Court upholds DPA fine for village livestream, reduces it to 375 euros
2025-01-09 · status not established, Rechtbank Noord-Nederland
- Schrems v Meta: no unlimited retention and aggregation of data for targeted advertising
2024-10-04 · final, Hof van Justitie van de EU (Vierde kamer), Maximilian Schrems tegen Meta Platforms Ireland Limited
- Council of State: 600,000 euro fine for wifi tracking in Enschede stays annulled
2026-07-29 · final, Raad van State, Afdeling bestuursrechtspraak
- Brillen Rottler: even a first access request can be abusive if made solely to claim compensation
2026-03-19 · final, Hof van Justitie van de EU (Vierde kamer), Brillen Rottler GmbH & Co. KG tegen TC
- Dun & Bradstreet: right to an intelligible explanation of an automated decision, trade secrets are no absolute ground for refusal
2025-02-27 · final, Hof van Justitie van de EU (Eerste kamer), CK tegen Magistrat der Stadt Wien, met Dun & Bradstreet Austria GmbH als andere partij
- Mousse: asking for Mr or Ms when selling a train ticket is not necessary
2025-01-09 · final, Hof van Justitie van de EU (Eerste kamer), Mousse tegen Commission nationale de l'informatique et des libertés (CNIL) en SNCF Connect
- Overijssel District Court revokes DPA fine for wifi tracking in Enschede
2024-02-02 · final, Rechtbank Overijssel
Guidelines8 of 14
- Guidelines 03/2026 on web scraping in the context of generative AI
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR (legitimate interest)
2024-10-08 · adopted, European Data Protection Board (EDPB)
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
2024-12-17 · final, European Data Protection Board (EDPB)
- Guidelines on transparency under Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
- Guidelines 05/2020 on consent under Regulation 2016/679
2020-05-04 · final, European Data Protection Board (EDPB)
- Guidelines 1/2026 on processing of personal data for scientific research purposes
2026-04-15 · adopted, European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
- Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
Enforcement and fines8 of 13
- Experian Netherlands fined 2.7 million euros for credit scoring without legal basis or information
2025-10-16 · final, Autoriteit Persoonsgegevens
- Ten municipalities fined a total of 250,000 euros for unlawful files on Muslim residents
2026-02-03 · final, Autoriteit Persoonsgegevens
- Netflix fined 4.75 million euros for failing to properly inform customers
2024-11-26 · under appeal, Autoriteit Persoonsgegevens
- Dutch DPA and tennis federation KNLTB end litigation: fine cut from 525,000 to at most 250,000 euros
2025-10-18 · status not established, Autoriteit Persoonsgegevens
- 600,000 euro fine for AS Watson (Kruidvat) over tracking cookies without consent
2024-05-02 · annulled, Autoriteit Persoonsgegevens
- 500 euro fine and penalty order for Stichting Oud Lemmer over webcam livestream
2021-07-09 · status not established, Autoriteit Persoonsgegevens
- DPA cuts Kruidvat fine to 50,000 euros on objection
2025-05-27 · status not established, Autoriteit Persoonsgegevens
- Coolblue fined 40,000 euros on objection for cookies without consent
2024-12-23 · status not established, Autoriteit Persoonsgegevens
Legislation in motion6 of 9
- Proposal: exception for biometric verification under the data subject's sole control (Article 9(2)(l) GDPR)
2025-11-19 · proposal, Europese Commissie
- Proposal: refusing requests that abuse the right of access (Article 12(5) GDPR)
2025-11-19 · proposal, Europese Commissie
- Council: Irish Presidency continues with a revised compromise, Antici Group 11 September 2026
2026-09-11 · under negotiation, Raad van de Europese Unie, Iers voorzitterschap
- Proposal: definition of scientific research, purpose limitation and information duty for research (Article 4(38), 5(1)(b) and 13(5) GDPR)
2025-11-19 · under negotiation, Europese Commissie
- Proposal: exception for incidental special category data in AI development (Article 9(2)(k) and 9(5) GDPR)
2025-11-19 · proposal, Europese Commissie
- Proposal: legitimate interest for development and operation of AI (new Article 88c GDPR)
2025-11-19 · proposal, Europese Commissie