fineConcluded€20,000,000
Hellenic Data Protection Authority (HDPA) — Clearview AI Inc.
July 13, 2022 · Greece · Technology
HDPA imposed a €20 million fine on Clearview AI for violating GDPR by unlawfully collecting and processing facial images (biometric data) from public websites for facial recognition, and ordered the deletion of data on Greek data subjects and prohibition of further processing.
Key takeaway — how to prevent this
Biometric data (faces, iris, fingerprints) needs an explicit lawful basis or consent. Scraping or capturing it without one is unlawful across the EU/UK and many US states (e.g. Illinois BIPA) — and draws the largest fines.
Inclusion does not imply wrongdoing or liability. Status reflects the latest information we have — always check the official source for current status.