← All case files
verified deployment technology · Netherlands · ops

€30.5 million for an illegal AI face database: the Dutch DPA's final, unappealable GDPR fine on Clearview AI

By decision of 16 May 2024, published 3 September 2024, the Autoriteit Persoonsgegevens (Dutch Data Protection Authority) fined Clearview AI Inc. a total of €30,500,000: €20,000,000 for building an illegal biometric database and failing to inform data subjects, plus €10,500,000 for refusing to honor access rights, and imposed four cease orders backed by non-compliance penalties up to €5.1 million on top of the fine. The regulator found that Clearview's database holds more than 30 billion photos scraped automatically from the internet and converted into 'a unique biometric code per face', without the knowledge or consent of the people in them. Clearview did not object to the decision and is therefore unable to appeal against the fine; its chief legal officer nonetheless calls the decision 'unlawful, devoid of due process and... unenforceable.'

MetricBeforeAfter
The fine (total)
What the regulator found the system does
The violations
Cease orders on top of the fine
Finality

The problem

Clearview AI built a commercial facial-recognition service the way a scraper builds a search index: crawlers harvested photos of faces from the open internet and converted each face into a biometric code, so that intelligence and investigative agencies could upload a camera image and get back matching photos and source links (source). The Dutch Data Protection Authority found the database holds “more than 30 billion photos of people,” scraped automatically and converted “into a unique biometric code per face,” collected “without these people knowing this and without them having given consent for this” (source).

This is a verified negative, not a deployment story: an independent European regulator investigated a deployed AI system, made formal findings about what it does, and priced the violations in a signed, final decision, with no vendor narrative anywhere in the chain (source).

What the regulator found

The Autoriteit Persoonsgegevens found five violations of the GDPR, spanning lawfulness of processing (Article 6), the prohibition on processing special-category biometric data (Article 9), transparency (Articles 12 and 14), and the right of access (Articles 12 and 15) (source). In the regulator’s own summary, “the company should never have built the database and is insufficiently transparent” (source). The investigation began after complaints from data subjects whose individual access requests Clearview did not answer (source).

The Dutch DPA also said it is investigating whether the company’s directors can be held personally responsible, with chairman Aleid Wolfsen indicating it would look at whether it “can hold the management of the company personally liable and fine them for directing those violations” (source).

The outcome

The headline figure: €30.5 million, final and unappealable. By decision of 16 May 2024, published 3 September 2024, the Dutch DPA imposed a total fine of €30,500,000 on Clearview AI (source). Per the AP’s decision the total splits into €20 million for the illegal-database and transparency violations and €10.5 million for the access-rights violations (source).

The exposure on top: up to €5.1 million. The AP attached four cease orders backed by monthly non-compliance penalties, with a maximum of €5.1 million on top of the fine if Clearview keeps violating (source, source). Because Clearview did not object within the objection period, the regulator states it “is therefore unable to appeal against the fine” (source).

The company’s on-record response. Clearview’s chief legal officer Jack Mulcaire said “Clearview AI does not have a place of business in the Netherlands or the EU, it does not have any customers in the Netherlands or the EU,” and called the decision “unlawful, devoid of due process and is unenforceable” (source).

The honest caveats

Read the outcome with three limits stated in the prose, not buried in a list. First, the fine is imposed, not shown collected: nothing in the public record confirms Clearview has paid, and the company describes itself as an “American company without an establishment in Europe” that it says is outside the GDPR’s reach (source). Second, the €5.1 million is a ceiling of exposure, not a levy, triggered only if Clearview ignores the four cease orders (source). Third, other European fines on Clearview, such as the €20 million imposed separately by the Greek DPA, are distinct actions and are never added to the €30.5 million in this story (source).

For anyone deploying face-matching or scraped-data AI in Europe, the €30.5 million figure is the reference number, and the regulator warned that Dutch organisations using Clearview “may therefore expect hefty fines” (source).

How this was verified

The origin is the Dutch DPA’s own decision and press release, which are self-authenticating regulatory records; green here never depends on the sanctioned company confirming anything (source). Re-checked live on 2026-08-15 against the AP English release and two independent newsrooms (TechCrunch and CSO Online): the €30.5 million total, the €5.1 million non-compliance exposure, the more-than-30-billion-photo finding, the “unique biometric code per face” and “should never have built the database” quotes, the “unable to appeal” statement, and Jack Mulcaire’s response all re-confirmed on the live pages. The one figure not re-confirmed on a live secondary this pass is the internal €20 million / €10.5 million split of the total, which is stated in the AP’s own decision (Tier 1) and is presented with that source; the €30.5 million total that every source carries is the headline. The honest limit: the fine is final but there is no public artifact showing it has been collected, and this file makes no claim that it has been.

The same regulator-priced-AI-harm pattern, where an enforcement body puts a dollar figure on an AI system rather than a vendor selling its results, runs through the FTC’s five-year facial-recognition ban on Rite Aid, where a US regulator barred a deployer outright rather than fining it. It also mirrors the FTC’s twenty-year consent order against IntelliVision, another facial-recognition action turning on claims the company could not support. And for a court, rather than a data-protection authority, pricing an algorithmic data harm, see Louis v. SafeRent, a $2.275 million class settlement over algorithmic tenant screening.


Sources

Checked live on 2026-08-15. Tier 1 = the Dutch DPA’s own decision and press release; Tier 2 = independent press and the EDPB cross-authority record naming the parties.

  1. Autoriteit Persoonsgegevens (Dutch DPA), “Dutch DPA imposes a fine on Clearview because of illegal data collection for facial recognition,” 2024-09-03 (Tier 1, the enforcing regulator’s own release). https://www.autoriteitpersoonsgegevens.nl/en/current/dutch-dpa-imposes-a-fine-on-clearview-because-of-illegal-data-collection-for-facial-recognition
  2. Autoriteit Persoonsgegevens, “Decision fine Clearview AI” (the 53-page decision of 16 May 2024), published 2024-09-03 (Tier 1, primary decision; source of the €20M/€10.5M split and the four cease orders). https://www.autoriteitpersoonsgegevens.nl/en/documents/decision-fine-clearview-ai
  3. European Data Protection Board, “Dutch Supervisory Authority imposes a fine on Clearview because of illegal data collection,” 2024 (Tier 2, official cross-authority record of the €30.5M fine and the GDPR articles). https://www.edpb.europa.eu/news/national-news/2024/dutch-supervisory-authority-imposes-fine-clearview-because-illegal-data_en
  4. TechCrunch, “Clearview AI hit with its largest GDPR fine yet, as Dutch regulator considers holding execs personally liable,” 2024-09-03 (Tier 2, independent, carries the €5.1M exposure, the personal-liability investigation, and Jack Mulcaire’s quote). https://techcrunch.com/2024/09/03/clearview-ai-hit-with-its-largest-gdpr-fine-yet-as-dutch-regulator-considers-holding-execs-personally-liable/
  5. CSO Online, “Dutch regulator fines Clearview €30 million… or more,” 2024 (Tier 2, independent, carries the “unable to appeal” statement and Clearview’s no-EU-establishment position). https://www.csoonline.com/article/3504697/dutch-regulator-fines-clearview-e30-million-or-more.html
  6. European Data Protection Board, “Hellenic DPA fines Clearview AI 20 million euros,” 2022 (Tier 2, cited only to keep the separate Greek fine distinct from the Dutch one). https://edpb.europa.eu/news/national-news/2022/hellenic-dpa-fines-clearview-ai-20-million-euros_pl
Verification record
Status
verified
Method
The AP's 53-page decision PDF byte-tied to Wayback (SHA-1-b32 of the committed bytes = AXNZLSRSFUQA7ZYEU3ZNUJSILVMUX5EE = the CDX digest of every good capture since announcement day 2024-09-03); official English release plus independent newsrooms each carry the €30.5M fine, the €5.1M non-compliance exposure and the violation findings firsthand (two_independent, confidence 1.000). Re-checked live on 2026-08-15 against the AP release, TechCrunch and CSO Online: the €30.5M total, the €5.1M exposure, the 30-billion-photo finding, the key quotes, the unable-to-appeal statement and Clearview's response all re-confirmed; the internal €20M/€10.5M split is carried from the AP decision (Tier 1).
Verified on
2026-08-15
Provider
Clearview AI Inc. (New York), commercial facial-recognition search for intelligence and investigative authorities ('Clearview for law-enforcement and public defenders')
Client
Autoriteit Persoonsgegevens (Dutch Data Protection Authority), the enforcing regulator; honest-negative, no deployer-client exists · Data-protection regulation, GDPR enforcement
Disclosure
named
Questions this file answers
How much did the Dutch DPA fine Clearview AI?

The Autoriteit Persoonsgegevens fined Clearview AI a total of €30,500,000, plus cease orders carrying non-compliance penalties of up to €5.1 million on top of the fine. Because Clearview did not object, the regulator states it is unable to appeal.

Why was Clearview AI fined in the Netherlands?

The Dutch DPA found Clearview built an illegal database of more than 30 billion photos scraped from the internet and converted into a unique biometric code per face, without a legal basis or consent, and that it failed to be transparent and to honour access rights, five GDPR violations in all.