---
title: "Clearview AI: a face database built by scraping"
description: "The Dutch data protection authority fined Clearview AI EUR 30.5 million in 2024 for building a facial-recognition database from scraped photos."
canonical: https://aigovernanceengineer.com/cases/clearview-ai
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-26
---

# Clearview AI: a face database built by scraping

> The Dutch data protection authority fined Clearview AI EUR 30.5 million in 2024 for building a facial-recognition database from scraped photos.

- Year: 2024
- Jurisdiction: Netherlands (EU)
- Sector: Biometrics: facial recognition
- Evidence base: Primary sources
- Incident record: [AIID 267](https://incidentdatabase.ai/cite/267/) · [AIID 781](https://incidentdatabase.ai/cite/781/)
- Harm: [Privacy intrusion and biometric surveillance](https://aigovernanceengineer.com/resources/harms#harm-privacy-intrusion) · [Regulatory enforcement and forced suspension](https://aigovernanceengineer.com/resources/harms#harm-regulatory-enforcement)

## In short

Clearview AI collects photos of faces from the internet and converts each into a unique biometric code, without the people concerned knowing or consenting. On 3 Sep 2024 the Dutch data protection authority announced a fine of EUR 30.5 million and orders subject to penalties of up to more than EUR 5 million, finding that Clearview should never have built the database and informs the people in it insufficiently. The harms are privacy intrusion and biometric surveillance, and regulatory enforcement. The failure mode sits at the source for the provider and in procurement for every buyer that integrates such a service without asking how its data was obtained. A Vendor / Model Due-Diligence Gate, an AIBOM recording dataset provenance and FRIA-as-Code with a DPIA before biometric use would have kept buyers out of the harm. The case touches GDPR Arts. 6, 9, 12 and 15 and the EU AI Act Art. 5(1)(e) ban on facial recognition databases built by untargeted scraping.

## What happened

Clearview AI collects photos of faces from the internet and converts each into a unique biometric code, without the people concerned knowing or consenting [1].

On 3 Sep 2024 the Dutch data protection authority (AP) announced a fine of EUR 30.5 million and orders subject to penalties of up to more than EUR 5 million. It found that Clearview should never have built the database and informs the people in it insufficiently; Clearview did not object to the decision and so cannot appeal the fine [1].

The European Data Protection Board's summary of the decision lists, among other violations, processing of biometric data contrary to Art. 9(1) GDPR, processing without a lawful basis under Art. 6(1), and failure to answer access requests under Art. 12 and 15 [2]. The AI Incident Database records both the scraping and the fine [3][4].

## Failure mode

For the provider, the failure is at the source: personal and biometric data gathered at scale without a lawful basis. For every organisation that buys such a service, the failure is procurement: integrating a capability without asking how its data was obtained.

## Which control would have caught it

A vendor due-diligence gate that asks for the provider's lawful basis for its reference data, and treats biometric processing as a stop condition pending a DPIA, keeps a buyer out of the harm. An AIBOM that records the provenance of each dataset gives the provider the same check at build time.

Patterns: [Vendor / Model Due-Diligence Gate](https://aigovernanceengineer.com/bok/patterns#pattern-vendor--model-due-diligence-gate) · [AIBOM](https://aigovernanceengineer.com/bok/patterns#pattern-aibom) · [FRIA-as-Code](https://aigovernanceengineer.com/bok/patterns#pattern-fria-as-code)

## The evidence that would have existed

What an auditor could have read, and the stack layer that produces it.

- Layer 2 (Inventory & Transparency): Due-diligence record with the provider's lawful-basis and provenance answers and the reject decision
- Layer 2 (Inventory & Transparency): AIBOM dataset entries with source, collection method, licence and lawful basis
- Layer 1 (Govern-as-Code): DPIA for any biometric use, signed before integration

## Obligations it touches today

As of 2026-09-24. Mappings are illustrative, not a claim of conformity.

- GDPR Art. 6, 9, 12, 15: Lawful basis, special-category biometric data, and the right of access: the provisions the AP decision applies [1][2][5].
- EU AI Act [Art. 5(1)(e)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art5): Placing on the market, putting into service or using AI systems that create or expand facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage is prohibited [6]; the prohibitions apply from 2 Feb 2025 [7].

## How to read this case

Each case is an illustrative engineering analysis of public records, not a legal determination, not a finding of fact beyond what the cited sources state, and not a claim of conformity. Mappings to obligations are illustrative.

## Sources

[1] Dutch DPA imposes a fine on Clearview because of illegal data collection for facial recognition (EUR 30.5 million fine; orders subject to penalties). Autoriteit Persoonsgegevens (Dutch Data Protection Authority). 2024-09-03. https://www.autoriteitpersoonsgegevens.nl/en/current/dutch-dpa-imposes-a-fine-on-clearview-because-of-illegal-data-collection-for-facial-recognition (verified: primary)
[2] Dutch Supervisory Authority imposes a fine on Clearview because of illegal data collection for facial recognition (national news summary listing the GDPR articles found infringed). European Data Protection Board. 2024-09-03. https://www.edpb.europa.eu/news/national-news/2024/dutch-supervisory-authority-imposes-fine-clearview-because-illegal-data_en (verified: primary)
[3] AI Incident Database, Incident 267: Clearview AI Algorithm Built on Photos Scraped from Social Media Profiles without Consent. Responsible AI Collaborative. 2026. https://incidentdatabase.ai/cite/267/ (verified: primary)
[4] AI Incident Database, Incident 781: Clearview AI Reportedly Faces $33.7 Million Fine for Violating GDPR with Biometric Data Harvesting. Responsible AI Collaborative. 2026. https://incidentdatabase.ai/cite/781/ (verified: primary)
[5] Regulation (EU) 2016/679 (General Data Protection Regulation) (Art. 5 principles, Art. 6 lawfulness, Art. 8 child's consent, Art. 9 special categories, Arts. 12-15 transparency and access, Art. 22 automated individual decision-making, Art. 33 breach notification, Art. 35 DPIA). Official Journal of the European Union (EUR-Lex). 2016-04-27. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (verified: primary)
[6] EU AI Act Art. 5 (prohibited AI practices; 5(1)(c) social scoring leading to unjustified or disproportionate detrimental treatment; 5(1)(e) facial recognition databases built by untargeted scraping). Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_5 (verified: primary)
[7] EU AI Act Art. 113 (entry into force and application; Chapters I and II apply from 2 Feb 2025, except the Art. 5 bans added by Reg. (EU) 2026/1744 (from 2 Dec 2026)). Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_113 (verified: primary)
