Case Study · Regulatory Compliance
Clearview AI was fined €20 million for scraping faces without a legal basis
What happened
Italy's data protection authority fined Clearview AI €20 million. Clearview collected facial images scraped from the internet and used them in a facial-recognition system.
The authority found the processing of personal and biometric data lacked an adequate legal basis and violated transparency, purpose-limitation, and storage-limitation principles. Beyond the fine, Clearview was ordered to delete data on people located in Italy and barred from further collecting or processing certain data.
The business problem
AI can create GDPR exposure not because "AI is risky," but because an organization doesn't know what data it's processing, lacks a legal basis for it, has no retention policy, or isn't controlling its AI vendors.
What could have helped
- Map what data an AI system actually processes before deploying it
- Confirm a legal basis exists for every category of data used
- Set retention limits and honor deletion requests
- Vet AI vendors on data handling, not just capability
Where this points
AI Vendor AssessmentAI Data MappingAI Governance