France's CNIL fined Clearview AI the maximum €20 million for facial-recognition scraping, then added a €5.2 million penalty when it did not comply
On 17 October 2022 the French data-protection regulator (the CNIL) imposed a €20 million fine — the maximum available — on Clearview AI for processing French residents' biometric data without a legal basis, and ordered it to stop collecting and to delete existing data within two months or pay €100,000 per day. When Clearview provided no proof of compliance, the CNIL liquidated the penalty and imposed a further €5.2 million overdue penalty on 17 April 2023 (published 10 May 2023). Every figure here is quoted verbatim from the CNIL's own decisions on Légifrance (the French government legal database) and corroborated by independent press and legal-industry reporting.
| Metric | Before | After |
|---|---|---|
| The fine | ||
| The order | ||
| The overdue penalty | ||
Verification status: VERIFIED — every figure is quoted verbatim from the CNIL’s own decisions on Légifrance (the French government legal database) and corroborated by independent press and legal-industry reporting (TechCrunch, Hunton, the National Law Review, Willkie). Green granted by the checker against the public record; awaits the owner’s final validation.
The problem
Clearview AI did not deploy facial recognition for a client so much as build the underlying database by scraping the open web. In the CNIL’s own words, the company “utilise une technologie propre pour indexer les pages web librement accessibles” and “collecte toutes les images sur lesquelles apparaissent des visages, sur des millions de sites web”, having “ainsi collecté plus de vingt milliards d’images à travers le monde” (source). Independent reporting described the same scraping in English: Clearview’s “facial recognition technology collects publicly available pictures from online websites, including social media, and extracts images from videos available online” (source). To make those images searchable, the CNIL found, “à partir de chaque photographie collectée, la société calcule un gabarit biométrique” — a unique biometric template per face (source); the National Law Review rendered the same point as “Clearview AI creates a biometric template which consists of a digital representation of a person’s physical characteristics” (source). The regulator’s objection was not a model error but the corpus itself: it held that Clearview had no legal basis for the processing, “en méconnaissance de l’article 6 du Règlement”, and had breached data-subject rights “en violation des articles 12 et 15” and “de l’article 17 du Règlement” (source). This is a verified negative: an independent European regulator investigated a deployed AI system and priced the violation, with no vendor narrative in the chain.
What the regulator ordered
The CNIL paired money with a behavioural remedy. In deliberation SAN-2022-019 of 17 October 2022 it resolved to “prononcer à l’encontre de la société […] une amende administrative d’un montant de 20 000 000 (vingt millions) euros” — a €20 million fine (source). That this was the maximum is written into the decision itself: the breaches of Articles 6, 12, 15 and 17 were “des manquements à des principes fondamentaux susceptibles de faire l’objet … d’une amende administrative pouvant s’élever jusqu’à 20 000 000 d’euros” under GDPR Article 83 (source); the National Law Review and Hunton both reported the €20 million as imposed on 17 October 2022 (source). Alongside the fine the CNIL issued “une injonction de ne pas procéder sans base légale à la collecte et au traitement de données à caractère personnel relatives à des personnes concernées qui se trouvent sur le territoire français … et supprimer l’ensemble des données à caractère personnel de ces personnes” (source), which Hunton summarised as an order to “stop collecting and processing data of individuals residing in France and delete the data already collected within a period of two months” (source). To give the deadline teeth, the regulator attached “une astreinte de cent mille euros (100 000 euros) par jour de retard à l’issue d’un délai de deux mois” — a €100,000-per-day penalty beyond the two-month deletion deadline (source). Independent technology press carried the same headline penalty, listing the “€20 million fine (October 2022)” as the anchor of the French enforcement (source).
The outcome
Clearview treated the order as optional, and the CNIL escalated. In deliberation SAN-2023-005 of 17 April 2023 the restricted committee recorded that “la société ne lui a transmis aucun élément permettant d’attester de sa mise en conformité à l’injonction” and so “n’a pas satisfait à l’injonction prononcée par la délibération n° 2022-019 du 17 octobre 2022” (source). It therefore decided to “procéder à la liquidation de l’astreinte … pour un montant de cinq millions deux cent mille euros (5 200 000 euros) au titre de la période du 19 décembre 2022 au 9 février 2023” — a €5.2 million overdue penalty (source). Independent reporting confirmed the escalation: Clearview “had two months to comply with the order and justify compliance to the CNIL,” but “did not send any proof of compliance within this time limit” (source), and Willkie Farr’s Compliance Concourse recorded the same €5.2 million overdue-penalty payment for the GDPR violations (source).
Weakest load-bearing link. Every critical figure here is now quoted directly from the CNIL’s own decisions on Légifrance, the French government legal database, so the amounts, dates and order text sit on a Tier-1 regulator-origin primary rather than on press summaries. The residual weakness is one of identity, not figures: the live Légifrance decisions are now anonymised to “la société X”, because each decision ordered that it “n’identifiera plus nommément la société à l’expiration d’un délai de deux ans à compter de sa publication” (source), and that two-year window has passed. The name “Clearview AI” therefore no longer appears in the primary text itself; the tie between “société X” and Clearview rests on the deliberation numbers SAN-2022-019 and SAN-2023-005, which the independent secondaries (Hunton, the National Law Review, TechCrunch and Willkie) all cite as the Clearview decisions (source), and on the CNIL’s own press release, “Facial recognition: 20 million euros penalty against CLEARVIEW AI”, which has since been withdrawn under the same anonymisation rule. Two reporting details are corrected against the primary rather than left as conflicts: the €20 million decision is dated 17 October 2022 (published on Légifrance 20 October 2022, which is the “20 October” some outlets reported), and the overdue-penalty decision is dated 17 April 2023 in the primary, not the “13 April 2023” carried by some secondaries.
How this was verified. Method: every load-bearing figure is quoted verbatim from the CNIL’s own decisions on Légifrance, fetched live this session through a rendered browser, and corroborated by independent secondary reporting fetched and saved to sources/. The €20 million maximum fine, the 17 October 2022 decision date, the cease-and-delete injunction and the €100,000/day astreinte after a two-month deadline come from CNIL deliberation SAN-2022-019 du 17 octobre 2022 (Légifrance CNILTEXT000046444859; Tier 1; saved to sources/legifrance-san-2022-019.txt) and are corroborated by Hunton Andrews Kurth’s Privacy & Information Security Law Blog (October 2022, Tier 2; sources/hunton-2022-10.txt) and The National Law Review (October 2022, Tier 2; sources/natlawreview-2022-10.txt). The €5.2 million overdue penalty and its 17 April 2023 decision date (published 10 May 2023, for the period 19 December 2022 to 9 February 2023) come from CNIL deliberation SAN-2023-005 du 17 avril 2023 (Légifrance CNILTEXT000047527412; Tier 1; saved to sources/legifrance-san-2023-005.txt) and are corroborated by TechCrunch (10 May 2023, Tier 2; sources/techcrunch-2023-05-10.txt) and Willkie Farr’s Compliance Concourse (2023, Tier 2; sources/willkie-2023.txt). The live Légifrance decisions are anonymised to “la société X” under the CNIL’s two-year de-identification rule, so the identity of the sanctioned company is tied to Clearview AI through the deliberation numbers cited by every secondary and the CNIL’s own now-removed press release, not through the anonymised primary text. web.archive.org was unreachable from this session, so no third-party archived snapshot could be captured; verbatim primary captures are held in sources/. No confirmation was sought from Clearview or the CNIL; only already-public records are used. Checked 2026-09-02 (round 2).
Related case files
- The Dutch DPA’s final €30.5 million GDPR fine on Clearview AI for an illegal facial-recognition database — the same company and the same scraping model, priced by a different EU regulator; read together they show a pattern of national fines Clearview has largely ignored.
- The FTC’s five-year ban on Rite Aid’s AI facial recognition — the parallel US enforcement track, where the remedy is a behavioural ban rather than a monetary fine.
- The FTC’s 20-year consent order against IntelliVision over ‘zero bias’ facial-recognition claims — another regulator policing facial-recognition vendors, here for the accuracy claims rather than the data supply chain.
- The UK ICO orders Serco Leisure to halt unlawful facial-recognition and fingerprint attendance monitoring — the same legal theory (biometric processing without a valid basis) applied to a deployer rather than the scraping vendor.
Sources
- Légifrance (Journal officiel / French government legal database) · Délibération de la formation restreinte n° SAN-2022-019 du 17 octobre 2022 · decision 17 October 2022, published on Légifrance 20 October 2022 · https://www.legifrance.gouv.fr/cnil/id/CNILTEXT000046444859 — Tier 1 (the CNIL’s own sanction decision; states the €20,000,000 fine, the Article 83 maximum, the Article 6/12/15/17 breaches, the cease-and-delete injunction and the €100,000/day astreinte after two months, and the “plus de vingt milliards d’images” / “gabarit biométrique” findings. Live text is anonymised to “la société […]” under the CNIL’s two-year de-identification rule; identity to Clearview AI carried by the deliberation number and the secondaries below. Saved to sources/legifrance-san-2022-019.txt).
- Légifrance · Délibération de la formation restreinte n° SAN-2023-005 du 17 avril 2023 · decision 17 April 2023, published on Légifrance 10 May 2023 · https://www.legifrance.gouv.fr/cnil/id/CNILTEXT000047527412/ — Tier 1 (the CNIL’s own liquidation decision; states the €5,200,000 overdue penalty for the period 19 December 2022 to 9 February 2023 and the finding that the company gave no proof of compliance with SAN-2022-019. Anonymised to “la société X”; identity carried as above. Saved to sources/legifrance-san-2023-005.txt).
- Hunton Andrews Kurth — Privacy & Information Security Law Blog · CNIL Fines Clearview AI 20 Million Euros for Unlawful Use of Facial Recognition Technology · October 2022 · https://www.hunton.com/privacy-and-cybersecurity-law-blog/cnil-fines-clearview-ai-20-million-euros-for-unlawful-use-of-facial-recognition-technology — Tier 2 (reputable independent legal-industry reporting corroborating the €20 million fine, the 17 October 2022 date, the two-month cease-and-delete order, the €100,000/day penalty, and the description of Clearview’s scraping; saved to sources/hunton-2022-10.txt).
- The National Law Review · CNIL Fines Clearview AI 20 Million Euros for Unlawful Use of Facial Recognition Technology · October 2022 · https://natlawreview.com/article/cnil-fines-clearview-ai-20-million-euros-unlawful-use-facial-recognition-technology — Tier 2 (reputable independent legal-industry reporting corroborating the €20 million fine and 17 October 2022 date, the cease-and-delete order, the €100,000/day penalty, and the “biometric template” description; saved to sources/natlawreview-2022-10.txt).
- TechCrunch · Clearview AI hit with another €5.2M fine in France for failing to comply with privacy orders · May 10, 2023 · https://techcrunch.com/2023/05/10/clearview-ai-another-cnil-gspr-fine/ — Tier 2 (independent technology journalism carrying both the €20 million October 2022 fine and the €5.2 million April 2023 overdue penalty, and Clearview’s failure to send proof of compliance; saved to sources/techcrunch-2023-05-10.txt).
- Willkie Farr & Gallagher — Compliance Concourse · France Imposes Overdue Penalty Payment of €5.2 Million upon Clearview AI for GDPR Violations · 2023 · https://complianceconcourse.willkie.com/articles/france-imposes-overdue-penalty-payment-of-e5-2-million-upon-clearview-ai-for-gdpr-violations/ — Tier 2 (reputable independent legal-industry reporting corroborating the €5.2 million overdue penalty, the reference to the maximum €20 million fine, and the €100,000/day term; reported the decision as “13 April 2023”, corrected here against the primary to 17 April 2023; saved to sources/willkie-2023.txt).
Clearview AI facial-recognition search: web-scraped public images converted into a per-face biometric template ('un gabarit biométrique' / 'a digital representation of a person's physical characteristics'), queried by uploading a probe photo
- Status
- verified
- Method
- Every load-bearing figure is quoted verbatim from the CNIL's own decisions, published on Légifrance (the French government legal database, Tier 1), and corroborated by independent secondary reporting. The €20 million maximum fine, the 17 October 2022 decision date, the cease-and-delete injunction and the €100,000/day astreinte after a two-month deadline are quoted from CNIL deliberation SAN-2022-019 du 17 octobre 2022 (Légifrance CNILTEXT000046444859) and corroborated by Hunton Andrews Kurth (October 2022, Tier 2) and The National Law Review (October 2022, Tier 2), with TechCrunch also carrying the €20M figure. The €5.2 million overdue penalty and its 17 April 2023 decision date (published 10 May 2023) are quoted from CNIL deliberation SAN-2023-005 du 17 avril 2023 (Légifrance CNILTEXT000047527412) and corroborated by TechCrunch (10 May 2023, Tier 2) and Willkie Farr's Compliance Concourse (2023, Tier 2). No confirmation was sought from Clearview or the CNIL; only already-public records are used. Note: the live Légifrance decisions are now anonymised to 'la société X' under the CNIL's rule that a published sanction stops naming the company two years after publication; the identity that these decisions are Clearview's rests on the deliberation numbers cited as Clearview's by every secondary and on the CNIL's own now-removed press release. Checked 2026-09-02 (round 2).
- Provider
- Clearview AI Inc. (New York) — commercial facial-recognition search; scrapes public images, builds a biometric template per face, and sells search access. The CNIL was the enforcing regulator.
- Client
- Commission Nationale de l'Informatique et des Libertés (CNIL, French Data Protection Authority) — the enforcing regulator; regulator-origin honest-negative, no deployer-client exists · biometrics
- Disclosure
- named
How much did the CNIL fine Clearview AI?
The CNIL imposed a €20 million fine on Clearview AI on 17 October 2022, the maximum available under the GDPR, for processing French residents' biometric data without a legal basis. It later liquidated a daily penalty and imposed a €5.2 million overdue penalty on 17 April 2023 for non-compliance with its order.
What did the CNIL order Clearview to do?
The CNIL ordered Clearview not to collect or process, without a legal basis, the personal data of people on French territory, and to delete the data already collected within two months, with a penalty of €100,000 per day of delay beyond that deadline.
Why did Clearview get a second, €5.2 million penalty?
Clearview sent no proof of compliance within the two-month limit set by the October 2022 order, so on 17 April 2023 (deliberation SAN-2023-005, published 10 May 2023) the CNIL liquidated the daily penalty and imposed an overdue penalty payment of €5.2 million for the period 19 December 2022 to 9 February 2023.