€30.5 million for an illegal AI face database: the Dutch DPA's final, unappealable GDPR fine on Clearview AI
By decision of 16 May 2024, published 3 September 2024, the Autoriteit Persoonsgegevens (Dutch Data Protection Authority) fined Clearview AI Inc. a total of €30,500,000 — €20,000,000 for building an illegal biometric database and failing to inform data subjects, plus €10,500,000 for refusing to honor access rights — and imposed four cease orders backed by non-compliance penalties up to €5.1 million on top of the fine. The regulator found that Clearview's database holds more than 30 billion photos scraped automatically from the internet and converted into 'a unique biometric code per face', without the knowledge or consent of the people in them. Clearview did not object to the decision and is therefore unable to appeal against the fine; its chief legal officer nonetheless calls the decision 'unlawful, devoid of due process and... unenforceable.'
| Metric | Before | After |
|---|---|---|
| The fine (total) | ||
| What the regulator found the system does | ||
| The violations | ||
| Cease orders on top of the fine | ||
| Finality | ||
The problem
Clearview AI built a commercial facial-recognition service the way a scraper builds a search index: crawlers harvested photos of faces from social media, websites, news articles and public databases — over 30 billion of them, per the regulator’s findings — and converted each face into a biometric vector. Intelligence and investigative agencies could then upload a camera image and get back matching photos and source links. The people in the database were never asked, and never told.
This is a verified negative: an independent European regulator investigated a deployed AI system, made formal findings about what it does, and priced the violations in a signed, final decision. No vendor narrative is involved at any point in the chain.
What the regulator found
The Autoriteit Persoonsgegevens found five violations of the GDPR. Clearview “processes, without a legal basis to do so, personal data of data subjects who are within the territory of the Netherlands”; it processes “a special category of personal data (biometric data)” in violation of the outright prohibition of Article 9(1); it fails to inform the people in its database; and it neither answered two individual access requests nor facilitates access rights at all. In the release’s summary: “the company should never have built the database and is insufficiently transparent.”
The outcome
The decision of 16 May 2024, published 3 September 2024, imposes two administrative fines totalling €30,500,000 — €20,000,000 for the illegal-database violations and €10,500,000 for the access-rights violations — plus four cease orders backed by monthly non-compliance penalties capped at €5.1 million in total. Because Clearview did not object within the objection period, the regulator states it “is therefore unable to appeal against the fine.”
The honest caveats
- Imposed, not collected. Nothing in the record shows Clearview has paid. The decision itself notes collection runs through the Dutch Central Judicial Collection Agency and awaits the end of any follow-up proceedings, and Clearview’s chief legal officer calls the decision “unlawful, devoid of due process and… unenforceable,” saying the company has no EU business or customers.
- The €5.1M is exposure, not a levy — the maximum if Clearview ignores the four cease orders.
- The 30-billion figure is the regulator’s finding but ultimately traces to Clearview’s own description of its database — it is context here, not the headline claim.
- Other European fines on Clearview (UK, Italy, Greece, France) are separate actions and are never added to the €30.5M in this story.
Why this matters for AI-led ops
The AP decision is the EU’s plainest pricing of an AI data-supply chain built on scraping: the violation was not a model error but the training/search corpus itself. For anyone deploying face-matching or scraped-data AI in Europe, the €30.5M figure — final and unappealable — is the reference number, and the regulator’s warning extends to customers: Dutch organisations that use Clearview “may therefore expect hefty fines.”
- Status
- verified
- Method
- The AP's 53-page decision PDF byte-tied to Wayback (SHA-1-b32 of the committed bytes = AXNZLSRSFUQA7ZYEU3ZNUJSILVMUX5EE = the CDX digest of every good capture since announcement day 2024-09-03); official English release plus two distinct archive-bound independent newsrooms (Associated Press via CBC, capture 20240903160117; Forbes, capture 20240903143925) each carry the €30.5M fine, the €5.1M non-compliance exposure and the violation findings firsthand; every quote verified mechanically against stored captures (quotecheck 23/23). Checker-graduated to pending-quality (two_independent, confidence 1.000) — awaits HUMAN client-confirmation before any green/verified badge.
- Verified on
- 2026-08-02
- Provider
- Clearview AI Inc. (New York) — commercial facial-recognition search for intelligence and investigative authorities ('Clearview for law-enforcement and public defenders')
- Client
- Autoriteit Persoonsgegevens (Dutch Data Protection Authority) — the enforcing regulator; honest-negative, no deployer-client exists · Data-protection regulation — GDPR enforcement
- Disclosure
- named