# Clearview AI's GDPR Fines: a Dated, Multi-Country Tally

> Source: <https://dev.to/multigrid/clearview-ais-gdpr-fines-a-dated-multi-country-tally-48f0>
> Published: 2026-08-12 22:21:30+00:00

Five European authorities have penalised Clearview AI over the same conduct: scraping facial images from the public web and social media into a searchable biometric database. The decisions are separate, the amounts differ, and the enforcement outcome is not what the sum suggests.

The EU decisions come to roughly €90.5 million in headline penalties, plus the UK notice. Each was taken by a national authority acting on its own territory, which is possible because Clearview has no establishment in the Union and so no one-stop-shop lead authority exists to concentrate the file.

A tally of published decisions as at the date on this page, not legal advice, and not a complete list of every complaint or proceeding worldwide. Amounts and statuses change — check each authority’s own register before citing a figure.

The French sequence is the one that shows what happens when a company simply does not respond. The CNIL had ordered Clearview to comply within two months, and when it did not, imposed the €20 million sanction along with an injunction to cease collection and to delete the data, backed by a daily penalty payment for continued non-compliance. In May 2023 the CNIL announced that the accrued overdue penalty payment had crystallised at €5.2 million.

That is a separate instrument from the fine and it is worth understanding on its own: an astreinte accumulates for as long as the order is ignored, so a company that treats a European regulator as unreachable does not freeze its exposure at the headline number. It grows.

The ICO’s May 2022 penalty took a different path, and it is the reason the UK figure should never be quoted as settled.

In October 2023 the First-tier Tribunal allowed Clearview’s appeal, holding that the processing fell outside the territorial reach of the UK GDPR because Clearview’s clients were foreign law enforcement and national security bodies, whose activities fall outside the material scope of the regulation. The ICO appealed. In October 2025 the Upper Tribunal allowed the Commissioner’s appeal on three of four grounds, holding that Clearview’s processing does relate to monitoring the behaviour of people in the UK and does not escape UK data protection law merely because the service was supplied to foreign state clients, and remitted the substantive appeal to the First-tier Tribunal on the basis that the Commissioner did have jurisdiction. The judgment is reported as [2025] UKUT 319 (AAC), and [the ICO’s statement on the judgment](https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/10/uk-upper-tribunal-hands-down-judgment-on-clearview-ai-inc/) sets out its reading; [the judgment itself is published on GOV.UK](https://assets.publishing.service.gov.uk/media/68ee6e4af159f887526bbe48/UA-2024-001563-GIA.pdf).

Clearview was granted permission to appeal to the Court of Appeal in December 2025. So the position at the time of writing is that the penalty has not been quashed and has not been upheld: a jurisdictional ruling is under appeal, and the merits have not been decided by anyone. Anybody citing the ICO fine as an established outcome is describing a case that is still running.

The arithmetic is easy and the collection is not. Clearview has no establishment, no assets and no designated Article 27 representative in the jurisdictions that fined it, and a GDPR fine is an administrative penalty rather than a court judgment — so enforcing it against a US company requires a mechanism that does not straightforwardly exist. Reporting through 2024 and 2025 indicated that the European fines had gone substantially unpaid, and the Italian regulator was still publicly discussing collection years after its decision.

Three consequences follow, and they are the useful part of this page for anyone doing risk assessment.

Clearview is an outlier in its product and not an outlier in its legal theory, which is why the decisions matter to companies doing nothing like face search.

The finding that runs through all of them is that scraping publicly accessible material does not make the resulting processing lawful. Public availability is not a lawful basis; it is a fact about where the data was. The authorities that reached legitimate interests as a question found the balancing failed, given that the people concerned had no relationship with the company and no expectation of being enrolled in a search index — the same analysis that any [web-scraping lawful basis assessment](https://multigrid.ai/learn/gdpr-web-scraping-lawful-basis) has to survive.

The second transferable point is the special category one. Facial images processed for the purpose of uniquely identifying a person are biometric data under Article 9, which starts from a prohibition and requires one of the narrow Article 9(2) conditions to lift it. Several of these decisions turn on that structure rather than on the Article 6 basis, and it is a materially harder test — [the Article 9 position for biometric AI](https://multigrid.ai/learn/gdpr-article-9-biometric-ai) is the one to check first if your system touches faces, voices or fingerprints.

The third is procedural: with no EU establishment, Clearview faced five regulators instead of one. Establishment is usually discussed as a tax and corporate question. In data protection it is also the difference between one supervisory relationship and a queue of them.
