Published Build3 min read
Five regulators, one database: what EUR 90.5m in Clearview fines actually buys
Three EUR 20 million decisions, one at EUR 30.5 million, and a British penalty still in the courts. The sum is territorial, not collective.
Written for builders.See today for builders

What happened
- Five European authorities have penalised Clearview AI over the same conduct: scraping facial images from the public web and social media into a searchable biometric database. The decisions are separate and the amounts differ.
- Italy's Garante imposed EUR 20 million, in a decision adopted 10 February 2022 and announced 9 March 2022, finding that Clearview monitored and processed the biometric data of people in Italy without a legal basis, and ordering deletion of the data of people in Italy plus a prohibition on further collection.
- Greece's Hellenic DPA imposed EUR 20 million in Decision 35/2022, issued 13 July 2022 on a complaint brought with the support of Homo Digitalis, finding breaches of the lawfulness and transparency principles and of Articles 12, 14, 15 and 27, prohibiting collection and processing of the data of people in Greece and ordering deletion.
- France's CNIL imposed EUR 20 million by sanction adopted by its restricted committee in October 2022, following an earlier order to comply that Clearview did not answer, and ordered the company to stop collecting and to delete the data it held on people in France.
- The Netherlands' Autoriteit Persoonsgegevens imposed EUR 30.5 million, decided in May 2024 and made public on 3 September 2024, the largest of the set, with an order to stop the violations and an announced possibility of further penalty payments for continued non-compliance.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
Five European data protection authorities have each penalised Clearview AI over the same conduct: scraping facial images from the public web and social media into a searchable biometric database [1]. The four EU decisions add up to roughly EUR 90.5 million [7], which reads like a continental verdict and is in fact four unconnected territorial actions plus a British penalty that no court has yet confirmed. The itemised list is less uniform than the round numbers suggest. Italy's Garante adopted its EUR 20 million decision on 10 February 2022 and announced it on 9 March, finding that Clearview had monitored and processed the biometric data of people in Italy with no legal basis, ordering deletion of that data and prohibiting further collection [2]. The Hellenic DPA reached EUR 20 million in Decision 35/2022 on 13 July 2022, on a complaint brought with the support of Homo Digitalis, citing failures of lawfulness and transparency and breaches of Articles 12, 14, 15 and 27 [3]. France's CNIL added EUR 20 million in October 2022 [4]. Three identical amounts, EUR 60 million between them [1]. The Dutch Autoriteit Persoonsgegevens is the outlier at EUR 30.5 million, decided in May 2024 and made public on 3 September 2024, with an order to stop and a stated possibility of further penalty payments [5]. The UK ICO's notice, GBP 7,552,800 in May 2022, sits outside the euro tally entirely [6]. These stack rather than combine, and the reason is structural. Clearview has no establishment in the Union, so no one-stop-shop lead authority exists to concentrate the file, and each regulator acted on its own territory [8]. That bounds the remedies as well as the fines: the Garante's deletion order covers people in Italy [2], the Greek prohibition covers people in Greece [3], the CNIL's order covers data on people in France [4]. No single decision reaches the database. The first and last of the four decisions are about two years and seven months apart [6]. The French sequence shows what the headline number omits. The CNIL had ordered Clearview to comply within two months, got no answer, and attached to the fine an injunction to cease collection and delete, backed by a daily penalty payment [9]. In May 2023 it announced that the accrued overdue payment had crystallised at EUR 5.2 million [10]. That astreinte is a separate instrument that keeps accumulating for as long as the order is ignored [11], so French exposure stands at EUR 25.2 million [4], 26 per cent above the fine [3]. Treating a European regulator as unreachable does not freeze the number. The British figure moves the other way. In October 2023 the First-tier Tribunal allowed Clearview's appeal, holding that the processing fell outside the territorial reach of the UK GDPR because its clients were foreign law enforcement and national security bodies whose activities fall outside the regulation's material scope [12]. In October 2025 the Upper Tribunal allowed the Commissioner's appeal on three of four grounds, held that the processing does relate to monitoring the behaviour of people in the UK and does not escape UK data protection law merely because the service went to foreign state clients, and remitted the substantive appeal on the basis that the Commissioner had jurisdiction, reported as [2025] UKUT 319 (AAC) [13]. Clearview was granted permission to appeal to the Court of Appeal in December 2025, so the penalty has been neither quashed nor upheld [14], three years and seven months after it was issued [5]. Two things to watch. Whether the Court of Appeal engages the jurisdiction point or sends the substance back down, and whether the Dutch authority actually triggers the further penalty payments it flagged in September 2024 [5]; on the evidence of the French file, the recurring payment, not the one-off fine, is the instrument that responds to silence [11].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Five European authorities have penalised Clearview AI over the same conduct: scraping facial images from the public web and social media into a searchable biometric database. The decisions are separate and the amounts differ.
- [2]
Italy's Garante imposed EUR 20 million, in a decision adopted 10 February 2022 and announced 9 March 2022, finding that Clearview monitored and processed the biometric data of people in Italy without a legal basis, and ordering deletion of the data of people in Italy plus a prohibition on further collection.
ReportedView cited source - [3]
Greece's Hellenic DPA imposed EUR 20 million in Decision 35/2022, issued 13 July 2022 on a complaint brought with the support of Homo Digitalis, finding breaches of the lawfulness and transparency principles and of Articles 12, 14, 15 and 27, prohibiting collection and processing of the data of people in Greece and ordering deletion.
ReportedView cited source - [4]
France's CNIL imposed EUR 20 million by sanction adopted by its restricted committee in October 2022, following an earlier order to comply that Clearview did not answer, and ordered the company to stop collecting and to delete the data it held on people in France.
ReportedView cited source - [5]
The Netherlands' Autoriteit Persoonsgegevens imposed EUR 30.5 million, decided in May 2024 and made public on 3 September 2024, the largest of the set, with an order to stop the violations and an announced possibility of further penalty payments for continued non-compliance.
ReportedView cited source - [6]
The UK ICO issued a monetary penalty notice of GBP 7,552,800 in May 2022 under the UK GDPR, with an enforcement notice requiring deletion of UK residents' data.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- dev.toMultigridAug 12Clearview AI's GDPR Fines: a Dated, Multi-Country Tally
Cited in this coverage: dev.to tally of published decisions
