Netherlands DPA v. Clearview AI: €30.5M Fine for Illegal Biometric Database
Summary
The Dutch Data Protection Authority found Clearview AI built an illegal database of more than 30 billion facial images scraped from the internet, converting each into a unique biometric code, and processed Dutch residents' biometric data without any legal basis under the GDPR.
Details
- Violation: Illegal biometric data collection and processing
- Penalty: €30.5 million fine + additional penalty payments up to €5.1M for non-compliance
- Framework: GDPR (Articles 5, 6, 9 — special category data)
- Status: Fine issued May 2024; Clearview did not contest
Key Takeaways
- Scraping facial images from the internet for AI training is illegal under GDPR
- Biometric data is special category data requiring explicit consent
- Non-compliance penalties escalate with additional penalty payments
- Clearview AI has been fined across multiple EU countries and globally
Related Enforcement
UK ICO fined Clearview £7.5M. French CNIL fined Clearview €20M. Italy, Australia, Canada, and Greece also took enforcement action. Clearview was effectively banned from operating in Europe.
Related Enforcement Actions
Italy Garante v. Replika: €5M Fine for AI Companion Chatbot Privacy Violations
Luka Inc. (Replika) · EUR 5,000,000 · Feb 15, 2025
Italy Garante v. OpenAI: €15M Fine for ChatGPT GDPR Violations
OpenAI · EUR 15,000,000 · Dec 20, 2024
Ireland DPC v. X Corp: First EU Halt of AI Training Data Use
X Corp. (Grok AI) · EUR 0 · Aug 8, 2024