Italian Watchdog Fines Clearview AI 20 Million Euros Over GDPR Violations
Italy's data protection authority fines U.S. facial recognition firm Clearview AI 20 million euros for unlawfully scraping and processing biometric data of EU citizens.
The Italian data protection authority issues a 20 million euro fine against Clearview AI, a U.S.-based facial recognition company. Clearview AI builds its database by scraping publicly accessible photos and videos from social networks and websites without the knowledge of the individuals involved. The Italian regulator determines that the company violates several core principles of the EU General Data Protection Regulation (GDPR).
Because Clearview AI operates outside of Europe, the Italian watchdog first establishes that the GDPR applies to the company's activities. The authority confirms this territorial reach by concluding that Clearview AI both offers services to individuals in the EU and monitors their behavior. This finding allows the regulator to hold the foreign company accountable under European privacy law.
The investigation reveals that Clearview AI lacks a legal basis for processing personal, biometric, and geolocation data. Furthermore, the company fails to uphold key GDPR principles such as transparency, purpose limitation, and storage limitation. In addition to the substantial financial penalty, the Italian authority orders Clearview AI to permanently delete all personal data pertaining to individuals located in Italy.