Clearview AI is a US company that scraped billions of facial images from the open web and social media and sold facial-recognition lookups on that database. It has no establishment in the European Union. Between 2022 and 2024 four EU data protection authorities fined it under GDPR — and Clearview has, in practice, paid and complied with none of it.
This is the registry of those decisions: the exact amounts, the articles, the orders, and the part regulators rarely advertise — what happens when a company outside the EU simply ignores a European fine. Every figure and date below links to the issuing authority.
Why these are GDPR cases — and where the AI Act now stands
All four decisions are GDPR cases (lawfulness, special-category data, transparency, the duty to appoint an EU representative). They predate AI Act enforcement, and GDPR was the only operational tool at the time.
What changed since: the AI Act now prohibits the practice outright. Article 5(1)(e) of the AI Act bans “the placing on the market, the putting into service for this specific purpose, or the use of AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage” — a near-verbatim description of Clearview’s business model, prohibited from 2 February 2025. So the same conduct now sits in two regimes at once: a GDPR violation (how the data is processed) and a prohibited AI practice (what the system is). This registry tracks the GDPR track, where the actual fines live.
The four EU fines
1. Garante (Italy) — €20,000,000 — 10 February 2022
The Italian authority found Clearview in breach of Articles 5(1)(a)(b)(e), 6, 9, 12–15 and 27 GDPR: unlawful processing without a legal basis, breach of purpose- and storage-limitation, and no EU representative. Beyond the fine it ordered Clearview to stop scraping images of people in Italy, erase the data already held (including biometric data), and designate an EU representative (EDPB, official summary of the Garante decision).
2. Hellenic DPA (Greece) — €20,000,000 — 13 July 2022
Greece’s authority found breaches of Articles 5(1)(a) and (2), 6, 9(1) and 9(2)(e), and 12, 14, 15 and 27 GDPR. It was the largest fine the Greek DPA had ever issued. It ordered Clearview to delete the data of people located in Greece and prohibited any further collection or processing of data of subjects on Greek territory by its facial-recognition methods (EDPB, official summary of the Hellenic DPA decision).
3. CNIL (France) — €20,000,000 + a €5,200,000 overdue penalty
On 17 October 2022 the French CNIL imposed €20 million and ordered Clearview to stop collecting and using data of people in France without a legal basis and to delete the data already held, adding a penalty of €100,000 per day of delay beyond two months (CNIL, official decision). Clearview did not demonstrate compliance. On 13 April 2023 the CNIL’s restricted committee therefore imposed an overdue penalty payment of €5,200,000 (EDPB, official summary of the French penalty payment).
4. Dutch DPA (AP) (Netherlands) — €30,500,000 — 16 May 2024
The largest of the four. The Dutch authority found breaches of Article 6 (no lawful basis), Article 9 (biometric special-category data with no legal ground), Articles 12 and 14 (transparency), Articles 12 and 15 (failure to act on two access requests) and Article 27 (no EU representative). It imposed four compliance orders with non-compliance penalties and warned that directors can be held personally liable for continued breaches (EDPB, official summary of the Dutch DPA decision).
What the four cases have in common
The same pattern repeats across every decision: biometric data of essentially everyone, collected with no legal basis, no transparency to the people in the database, and no EU representative (Article 27) — the formal point of contact a non-EU controller must appoint. Total exposure: €90.5 million in fines across four EU authorities, plus a further €5.2 million French overdue penalty for non-compliance (Dutch DPA decision, the largest single fine). Clearview’s consistent position is that, as a US company with no EU establishment, it is not subject to GDPR — which is precisely the question the orders, and the litigation below, turn on. It is the clearest live test of whether a European fine means anything against a company that refuses to engage at all.
Beyond the EU: the UK ICO (comparison, not EU law)
The UK is outside the EU scope here, but the parallel UK case sharpens the EU story, so it belongs here as contrast.
In May 2022 the UK Information Commissioner fined Clearview £7.5 million and issued an enforcement notice for scraping UK residents’ images. Clearview appealed. On 17 October 2023 the First-tier Tribunal ruled the ICO lacked jurisdiction — Clearview’s processing fell outside the material scope of UK GDPR (IAPP). The ICO appealed, and on 7 October 2025 the Upper Tribunal overturned that ruling, holding the ICO did have jurisdiction (Clearview’s processing related to behavioural monitoring) and remitting the case to the First-tier Tribunal for the substantive appeal; on 19 December 2025 Clearview was granted permission to take it to the Court of Appeal (ICO, official statement on the Upper Tribunal judgment).
The contrast is the point: in the EU the violations and amounts were never seriously in doubt — enforcement stalls on collection, not on legitimacy. In the UK the case spent years stuck on the prior question of whether the regulator could act at all, and is still unresolved.
If you scrape data or build recognition systems
- “We’re not in the EU” is not a shield. Four authorities applied GDPR jurisdiction to a US company with no EU office. The dispute is about enforcement reach — whether a European fine can actually be collected — not about whether GDPR applied in the first place.
- Biometric data has almost no lawful route at scale. Article 9 treats facial templates as special-category data: processing them is prohibited unless a narrow exception applies, and “it was public on the internet” is not one of those exceptions and is not a valid legal basis. That exact finding — processing biometric data with no lawful basis — was the core violation in all four decisions (Italy, Greece, France, the Netherlands), not an incidental point.
- Appoint an EU representative (Article 27) if you process EU data without an establishment. A non-EU controller must name a formal EU point of contact; Clearview’s failure to do so was charged as a separate breach in each of the four decisions.
- The conduct is now a prohibited AI practice too. Since 2 February 2025, building or expanding a face-recognition database by untargeted scraping is banned under Article 5 of the AI Act — a violation in its own right, regardless of any GDPR liability.
Sources and method
Amounts, dates, articles and orders are taken from the issuing authorities and their official EDPB summaries: the Italian Garante, the Hellenic DPA, the French CNIL and its overdue penalty, and the Dutch DPA; the UK strand from the ICO. This is a living registry — updated when a decision’s status or the UK litigation changes. Related: the GDPR pillar, the AI Act pillar, and the sibling registries for Garante AI cases and AKI fines — the same pattern of fines issued but not collected.