Skip to content
Enforcement · Italian Data Protection Authority (Garante) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Clearview Al Inc.: Non-compliance with general data processing principles

The Italian DPA has fined U.S.-based Clearview AI EUR 20 million after it was revealed that the company had been applying biometric surveillance techniques on Italian territory.

Full text 2 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

The Italian DPA has fined U.S.-based Clearview AI EUR 20 million after it was revealed that the company had been applying biometric surveillance techniques on Italian territory. The company owns a database of over 10 billion facial images from around the world. The company offers a search service that allows profiles to be created based on the biometric data extracted from the images. The profiles can be enriched with information associated with these images, such as image tags and geolocation. The DPA launched an investigation into the company after it became known that Clearview - contrary to initial claims - also enabled searches of Italian nationals and residents. The DPA found that the personal data contained in the company's database had been processed unlawfully and without a valid legal basis. In addition, the DPA found that the company had violated several principles of the GDPR.

§

For example, the company had violated the principle of transparency by failing to adequately inform users about the processing of their data. Clearview had also violated the principle of purpose limitation, by processing users' data for purposes other than those for which they had been made available online. Finally, it violated the principle of storage limitation by not specifying a time period for data storage. GDPR Articles: Art. 5 (1) a), b), e) GDPR, Art. 6 GDPR, Art. 9 GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 14 GDPR, Art. 15 GDPR, Art. 27 GDPR Industry: Industry and Commerce

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-740/22 Endemol Shine Finland Oy In Case C-740/22, the Court of Justice of the European Union (Sixth Chamber) ruled on a preliminary reference from the Itä-Suomen hovioikeus (Court of Appeal, Eastern Finland)… Sixth Chamber Mar 7, 2024 Criminal Data Personal Data Types of Special Categories of Personal Data
C-175/20 SIA 'SS' v Valsts ieņēmumu dienests In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a… Fifth Chamber Feb 24, 2022 Retention Period Personal Data Legitimate Interest
C-634/21 OQ v Land Hessen In Case C-634/21, the CJEU addressed a preliminary ruling from the Verwaltungsgericht Wiesbaden concerning OQ's challenge against Land Hessen's refusal to order SCHUFA Holding AG… First Chamber Dec 7, 2023 Profiling Automated Decision-Making Marketing
C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) Jan 12, 2023 Supervisory Authorities IP Address Supervision
C-60/22 UZ v Bundesrepublik Deutschland In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik… Fifth Chamber May 4, 2023 Right to Restriction Right to be Forgotten Personal Data