Case Study · Regulatory Compliance

Clearview AI was fined €20 million for scraping faces without a legal basis

What happened

Italy's data protection authority fined Clearview AI €20 million. Clearview collected facial images scraped from the internet and used them in a facial-recognition system.

The authority found the processing of personal and biometric data lacked an adequate legal basis and violated transparency, purpose-limitation, and storage-limitation principles. Beyond the fine, Clearview was ordered to delete data on people located in Italy and barred from further collecting or processing certain data.

The business problem

AI can create GDPR exposure not because "AI is risky," but because an organization doesn't know what data it's processing, lacks a legal basis for it, has no retention policy, or isn't controlling its AI vendors.

What could have helped

  • Map what data an AI system actually processes before deploying it
  • Confirm a legal basis exists for every category of data used
  • Set retention limits and honor deletion requests
  • Vet AI vendors on data handling, not just capability

Where this points

AI Vendor AssessmentAI Data MappingAI Governance

Want to know where your organization stands?

Book a Consultation