Clearview AI: a face database built by scraping

The Dutch data protection authority fined Clearview AI EUR 30.5 million in 2024 for building a facial-recognition database from scraped photos.

Year
2024
Jurisdiction
Netherlands (EU)
Sector
Biometrics: facial recognition
Evidence base
Primary sources
Incident record
AIID 267 · AIID 781
Harm
Privacy intrusion and biometric surveillance · Regulatory enforcement and forced suspension

What happened

Clearview AI collects photos of faces from the internet and converts each into a unique biometric code, without the people concerned knowing or consenting 1.

On 3 Sep 2024 the Dutch data protection authority (AP) announced a fine of EUR 30.5 million and orders subject to penalties of up to more than EUR 5 million. It found that Clearview should never have built the database and informs the people in it insufficiently; Clearview did not object to the decision and so cannot appeal the fine 1.

The European Data Protection Board's summary of the decision lists, among other violations, processing of biometric data contrary to Art. 9(1) GDPR, processing without a lawful basis under Art. 6(1), and failure to answer access requests under Art. 12 and 15 2. The AI Incident Database records both the scraping and the fine 34.

Failure mode

For the provider, the failure is at the source: personal and biometric data gathered at scale without a lawful basis. For every organisation that buys such a service, the failure is procurement: integrating a capability without asking how its data was obtained.

Which control would have caught it

A vendor due-diligence gate that asks for the provider's lawful basis for its reference data, and treats biometric processing as a stop condition pending a DPIA, keeps a buyer out of the harm. An AIBOM that records the provenance of each dataset gives the provider the same check at build time.

Patterns: Vendor / Model Due-Diligence Gate · AIBOM · FRIA-as-Code

The evidence that would have existed

What an auditor could have read, and the stack layer that produces it.

  • L2 Due-diligence record with the provider's lawful-basis and provenance answers and the reject decision
  • L2 AIBOM dataset entries with source, collection method, licence and lawful basis
  • L1 DPIA for any biometric use, signed before integration

Obligations it touches today

As of 2026-09-24. Mappings are illustrative, not a claim of conformity.

  • GDPR Art. 6, 9, 12, 15 Lawful basis, special-category biometric data, and the right of access: the provisions the AP decision applies 125.
  • EU AI Act Art. 5(1)(e) Placing on the market, putting into service or using AI systems that create or expand facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage is prohibited 6; the prohibitions apply from 2 Feb 2025 7.

Sources

  1. [1] Dutch DPA imposes a fine on Clearview because of illegal data collection for facial recognition (EUR 30.5 million fine; orders subject to penalties). Autoriteit Persoonsgegevens (Dutch Data Protection Authority). 2024-09-03. https://www.autoriteitpersoonsgegevens.nl/en/current/dutch-dpa-imposes-a-fine-on-clearview-because-of-illegal-data-collection-for-facial-recognition (verified: primary)
  2. [2] Dutch Supervisory Authority imposes a fine on Clearview because of illegal data collection for facial recognition (national news summary listing the GDPR articles found infringed). European Data Protection Board. 2024-09-03. https://www.edpb.europa.eu/news/national-news/2024/dutch-supervisory-authority-imposes-fine-clearview-because-illegal-data_en (verified: primary)
  3. [3] AI Incident Database, Incident 267: Clearview AI Algorithm Built on Photos Scraped from Social Media Profiles without Consent. Responsible AI Collaborative. 2026. https://incidentdatabase.ai/cite/267/ (verified: primary)
  4. [4] AI Incident Database, Incident 781: Clearview AI Reportedly Faces $33.7 Million Fine for Violating GDPR with Biometric Data Harvesting. Responsible AI Collaborative. 2026. https://incidentdatabase.ai/cite/781/ (verified: primary)
  5. [5] Regulation (EU) 2016/679 (General Data Protection Regulation) (Art. 5 principles, Art. 6 lawfulness, Art. 8 child's consent, Art. 9 special categories, Arts. 12-15 transparency and access, Art. 22 automated individual decision-making, Art. 33 breach notification, Art. 35 DPIA). Official Journal of the European Union (EUR-Lex). 2016-04-27. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (verified: primary)
  6. [6] EU AI Act Art. 5 (prohibited AI practices; 5(1)(c) social scoring leading to unjustified or disproportionate detrimental treatment; 5(1)(e) facial recognition databases built by untargeted scraping). Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_5 (verified: primary)
  7. [7] EU AI Act Art. 113 (entry into force and application; Chapters I and II apply from 2 Feb 2025, except the Art. 5 bans added by Reg. (EU) 2026/1744 (from 2 Dec 2026)). Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_113 (verified: primary)