EU Regulation 2016/679 - Decision Register

DECISION OF THE GARANTE / PROVV. 9751362 / 10 FEBRUARY 2022

Clearview AI €20 Million Garante Fine, 2022 Italian Decision Explained

Italy's data protection authority fined the US facial-recognition firm Clearview AI €20 million for scraping images of Italian residents and building a biometric search engine without lawful basis. The decision established extraterritorial GDPR application to AI scraping.

Fine amount

€20,000,000

Issuing DPA

Italian Garante

Decision date

10 February 2022

Status

Final (collection contested)

Articles cited

3, 5, 6, 9, 13, 14, 15

EDUCATIONAL ONLY

This page is a reference summary of a published regulator decision. It is not legal advice. Consult a qualified data protection lawyer for advice on your specific situation. The UK GDPR is a separate regime from the EU GDPR following Brexit. Always read the source decision in full before relying on any figure or quote.

DECISION SUMMARY

What happened

On 10 February 2022, Italy's Garante per la Protezione dei Dati Personali adopted Decision 9751362, imposing a €20 million administrative fine on Clearview AI Inc, a US-based facial-recognition company. Alongside the fine, the Garante ordered Clearview to delete all data relating to individuals in Italy, prohibited any further processing of personal data of individuals in Italy, ordered Clearview to designate a representative in the EU under Article 27 GDPR, and required Clearview to pay a separate procedural penalty for failure to cooperate.

The investigation followed complaints by the Italian digital-rights group Hermes Center for Transparency and Digital Human Rights and others, who alleged that Clearview's scraping operations had collected facial images of Italian residents and made them searchable to Clearview's commercial and government customers. The Garante undertook a coordinated investigation alongside the French CNIL, the UK ICO, the Greek HDPA, and the Dutch AP. Each authority reached substantively similar conclusions and imposed parallel sanctions in 2022-2023; the Italian decision came first chronologically.

Clearview's business model, as described in the decision, involves systematically crawling publicly accessible web pages (social media profiles, news articles, blog posts) to download photographs, extracting biometric facial vectors from each photograph using a proprietary computer-vision model, and indexing the vectors in a searchable database. A customer (typically a law enforcement agency, but Clearview's commercial customer base has been broader at various times) submits a query photograph; the Clearview system returns the set of indexed photographs whose biometric vectors are closest matches, along with the source URLs and any associated metadata. The database is reported by Clearview to contain more than 30 billion images.

What the Garante found

The first substantive finding is Article 3 extraterritoriality. Clearview has no establishment in the EU. Article 3(2)(b) extends GDPR application to controllers not established in the EU where they process personal data of data subjects who are in the EU in connection with the monitoring of their behaviour as far as their behaviour takes place within the EU. The Garante found that scraping the publicly available images of Italian residents and indexing them for identification searches constitutes monitoring of behaviour, particularly because the system enables retrospective and ongoing identification of individuals based on their physical appearance, location and depicted activities. Article 3 jurisdiction was therefore established.

The Article 6 lawful-basis finding is straightforward: Clearview could not identify any Article 6(1) basis. Consent (6(1)(a)) was not obtained from the data subjects whose images were scraped. Contract (6(1)(b)) was not applicable because there was no contract with the data subjects. Legal obligation (6(1)(c)) did not apply. Vital interests (6(1)(d)) did not apply. Public task (6(1)(e)) might be argued for narrow law-enforcement purposes under Member State law, but not for Clearview's general commercial database. Legitimate interests (6(1)(f)) requires a balancing test; the Garante found that the data subjects' fundamental-rights interests in not being subjected to biometric identification outweighed Clearview's commercial interest.

The Article 9 finding is structurally independent. Article 9(1) prohibits processing of special categories of personal data, including biometric data for the purpose of uniquely identifying a natural person. None of the Article 9(2) exceptions applied. The Garante also found infringements of Article 5 (fairness, transparency, purpose limitation, storage limitation), Article 13/14 (information to data subjects), Article 15 (data subject access), and Article 27 (failure to designate an EU representative). The cluster of findings reflects the comprehensive incompatibility of Clearview's business model with the GDPR framework.

Why this case matters

The Clearview decisions across Italy, France, UK, Greece, the Netherlands and (subsequently) Germany establish two doctrinally significant points. First, the GDPR has extraterritorial bite: a US company with no EU establishment can be fined for processing the data of EU residents collected from publicly available web sources. Second, the publicly-available nature of source data does not cure a lawful-basis problem: scraping images that were originally posted publicly does not create consent for biometric processing of those images for unrelated identification purposes.

The enforcement-collection challenge remains. Clearview disputes EU jurisdiction and has not paid the fines. Cross-border collection mechanisms under the Hague Conventions and bilateral treaties are slow and uncertain. The practical effect of the decisions is therefore primarily prohibitive: Clearview is barred from processing the data of EU residents, and its EU customer base has dwindled to effectively zero. The financial fine is symbolic rather than collected.

For the doctrinal lineage to the EU AI Act, the Clearview decisions are the regulatory ancestors of Article 5(1)(e) of Regulation (EU) 2024/1689, which prohibits placing on the market or putting into service of AI systems that create or expand facial-recognition databases through untargeted scraping of facial images from the internet or CCTV footage. The Clearview decisions established that this was prohibited under the GDPR, and the AI Act lifts the prohibition into a directly-applicable AI-system-specific rule. The two regulatory regimes now overlap, with the GDPR applying to processing operations and the AI Act applying to placing on the market.

FREQUENTLY ASKED

About the Clearview €20 million Italian fine

What is Clearview AI?
Clearview AI is a US company that scrapes publicly available images from social media, news sites and other web sources, applies facial recognition to extract biometric vectors, and sells a search engine that allows law enforcement and other customers to identify a person from a photograph. Clearview claims a database of more than 30 billion images, much of it collected without notice to or consent from the individuals depicted.
Why does the GDPR apply to a US company?
Article 3 GDPR establishes extraterritorial application: the Regulation applies to controllers and processors not established in the EU where they process personal data of data subjects in the EU in connection with the offering of goods or services to those subjects, or the monitoring of their behaviour in the EU. The Garante found that Clearview's collection and processing of images of Italian residents constituted monitoring of behaviour in Italy, bringing it within Article 3(2)(b).
Has Clearview paid the fine?
Clearview disputes the Garante's jurisdiction over its activities and has not, as of public reporting, paid the €20 million fine. Enforcement of GDPR fines against entities with no EU establishment and no EU assets is a known structural challenge. Parallel fines have been issued by the French CNIL, the UK ICO, the Greek HDPA and the Dutch AP, totalling roughly €100 million; collection of any of those fines remains contested.
What did the Garante actually order?
Beyond the fine, the Garante ordered Clearview to delete all data relating to individuals in Italy, prohibited further collection and processing of biometric data of individuals in Italy, and designated a representative in the EU under Article 27 GDPR. The deletion and prohibition orders are the operationally significant elements of the decision.
Why is this an Article 9 case?
Facial biometric vectors derived from photographs are biometric data uniquely identifying a natural person, which fall within the Article 9(1) special-category prohibition. Processing of biometric data for the purpose of uniquely identifying a natural person is generally prohibited unless one of the Article 9(2) exceptions applies. None of those exceptions applied to Clearview's commercial face-recognition product, and the Garante found Article 9 was infringed independently of the Article 6 lawful-basis findings.
Is this related to the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689), in force from 2024-2027 by phased application, prohibits the placing on the market or use of AI systems that create or expand facial-recognition databases through untargeted scraping of facial images. Clearview's business model would be explicitly prohibited under Article 5(1)(e) of the AI Act. The Garante's 2022 decision is the doctrinal ancestor of that AI Act provision.

CROSS-REFERENCES

Related entries on this register

SUPERVISORY AUTHORITY

Italian Garante Profile

Europe's most-active DPA on AI/biometric cases. Clearview, ChatGPT, Replika and more.

Open reference →

ARTICLE 5

Article 5 GDPR Fines

Purpose-limitation and minimisation, both central to the Clearview reasoning.

Open reference →

RELATED CASE

Meta €1.2B DPC Fine (2023)

Different doctrinal area but same extraterritoriality theme.

Open reference →

SUPERVISORY AUTHORITY

French CNIL Profile

Parallel Clearview decision from the French authority.

Open reference →

SUPERVISORY AUTHORITY

UK ICO Profile

The UK GDPR-equivalent Clearview decision (£7.5M).

Open reference →

REGISTER

Full Decision Register

Every major indexed GDPR fine.

Open reference →

SOURCES & CITATIONS

Primary sources

Figures as of May 2026. Verified against published DPA decisions.

REGISTER UPDATED 2026-04-28