Site navigation

Dutch Regulator Fines Clearview AI £25.6M Over “Illegal Database”

Thom Carter

,

dutch regulator fines clearview ai millions over facial recognition database
The news comes nearly a year after Clearview AI successfully won an appeal to have a £7.5m fine from the UK’s Information Commissioner’s Office overturned.

American facial recognition company Clearview AI has been imposed a €30.5 million (£25.6m~) fine from the Dutch Data Protection Authority (DPA).

The Dutch regulator is fining the US-based firm, which offers facial recognition services to law enforcement and government agencies, but not in locations such as the EU and UK, as it has allegedly “seriously violated the privacy law General Data Protection Regulation (GDPR) on several points.”

The watchdog said that Clearview has an “illegal database” with more than 30 billion photos of people, including Dutch citizens, with these photos automatically scraped from the internet and then converted into unique biometric codes.

“Collecting and using them is prohibited,” the regulator noted. “There are some statutory exceptions to this prohibition, but Clearview cannot rely on them.”

The watchdog also stated that there’s insufficient transparency when it comes to informing people whose photos and biometric data are being used.

“People who are in the database also have the right to access their data,” added the DPA. “This means that Clearview has to show people which data the company has about them, if they ask for this. But Clearview does not cooperate in requests for access.”

According to the regulator, Clearview did not stop the privacy violations after its investigation, with the watchdog saying that it’s ordered the firm to “stop those violations” and that it could impose a penalty of non-compliance of up to €5m (£4.2m~) if Clearview “fails to do this.”

“Facial recognition is a highly intrusive technology, that you cannot simply unleash on anyone in the world,” Aleid Wolfsen, chairman of the Dutch watchdog, said.

“If there is a photo of you on the Internet – and doesn’t that apply to all of us? – then you can end up in the database of Clearview and be tracked. This is not a doom scenario from a scary film. Nor is it something that could only be done in China.”

“Such [a] company cannot continue to violate the rights of Europeans and get away with it. Certainly not in this serious manner and on this massive scale,” added Wolfsen.

“We are now going to investigate if we can hold the management of the company personally liable and fine them for directing those violations.

“That liability already exists if directors know that the GDPR is being violated, have the authority to stop that, but omit to do so, and in this way consciously accept those violations.”

The news comes nearly a year after Clearview AI successfully won an appeal to have a £7.5m fine from the UK’s Information Commissioner’s Office (ICO) overturned.

The fine was overturned as it was ruled that Clearview AI was used solely by law enforcement bodies outside of the UK, with the three-member tribunal who handled the appeal stating that the company did not carry out data processing related to the monitoring of people’s behaviour in the UK.


Recommended reading


Just last week, the Dutch DPA also hit ride-hailing tech company Uber with a €290 million (£245m) fine.

The watchdog claimed the tech firm sent personal data of European taxi drivers to the United States and failed to appropriately safeguard that transferred data—a violation of GDPR.

An Uber spokesperson said that “This flawed decision and extraordinary fine are completely unjustified.”

Thom Carter

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data