What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
The Dutch Data Protection Authority (Autoriteit Persoonsgegevens, or AP) fined Clearview AI Inc. €30.5 million for unlawfully processing facial images and biometric data linked to people in the Netherlands. The May 16, 2024 decision, announced September 3, 2024, also imposed orders to stop the processing, delete unlawfully obtained data and honor access requests. Continued non-compliance could add as much as €5.1 million in penalty payments, bringing reported maximum exposure to €35.6 million. The AP was exploring whether executives could be held personally accountable; it did not announce personal fines, criminal charges or arrest warrants.
The decision at a glance
| Item | What the record shows |
|---|---|
| Regulator | Autoriteit Persoonsgegevens (Dutch Data Protection Authority) |
| Formal decision | May 16, 2024 |
| Public announcement | September 3, 2024 |
| Administrative fines | €20 million for unlawful processing, biometric-data and transparency violations; €10.5 million for access-right failures |
| Total administrative fine | €30.5 million |
| Possible coercive penalties | Up to €5.1 million if orders are not satisfied, according to contemporary reporting |
| Potential combined exposure | Up to €35.6 million, not an amount established as collected |
The AP’s formal decision and the European Data Protection Board summary are the primary sources for the findings.
How the Dutch investigation began
The AP received complaints on January 3 and January 24, 2023, followed by a data-subject tip on April 11. It notified Clearview on March 6, 2023, that it had opened an investigation on its own initiative. The initial issue was Clearview’s handling of people’s requests to see their data; the inquiry expanded to the company’s facial-recognition database and underlying processing.
What the AP found Clearview had done
No lawful basis for processing
According to the AP, Clearview processed personal data of people in the Netherlands for a facial-recognition service used by law-enforcement and public defenders without a valid GDPR Article 6 legal basis. Clearview disputed that the GDPR applied, saying it had no EU establishment, EU customers or relevant EU activities. Those are the company’s objections, not findings accepted by the AP.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match#1 Best Overall
Biometric data under stricter rules
A photograph can be personal data without automatically being special-category biometric data. The legal concern becomes more serious when technical processing turns a face into a template, vector or other code used to uniquely identify someone. The AP’s biometrics guidance explains that distinction. The EDPB summary describes Clearview’s practice as combining scraped facial images with face-derived identifiers and searchable identity information, bringing GDPR Article 9’s restrictive biometric-data rules into play.
Insufficient transparency
The AP found failures under Articles 12 and 14, which require organizations to provide clear information about processing, including where data was obtained indirectly. Public availability of an image does not by itself authorize repurposing it for biometric identification or eliminate information duties.
Failure to honor access rights
The decision says Clearview did not properly respond to two access requests or adequately facilitate the rights guaranteed by Article 15. That conduct generated the separate €10.5 million fine.
Rank #2
No EU representative
The EDPB summary says the AP also found a breach of Article 27, which can require a non-EU organization subject to the GDPR to designate a representative in the European Union.
Why the headline can reach €35.6 million
The €30.5 million is the administrative fine for past violations. The orders are different: they are compliance measures requiring Clearview to end and not resume the unlawful processing, remove unlawfully obtained personal data, answer access requests and facilitate data-subject rights. Penalty payments attached to those orders are intended to compel future action. TechCrunch reported a possible additional €5.1 million, producing a maximum exposure of €35.6 million. That figure is not the initial fine and is not automatically payable merely because the decision includes penalty mechanisms.
The decision also states that collection of the fines would not proceed until related legal follow-up proceedings had concluded. The available material does not establish that Clearview has paid the €30.5 million or that the full potential amount has been collected.
Rank #3
What “personal liability” for executives means
The AP’s discussion was prospective. The regulator was examining whether executives who knowingly allowed continuing violations, while having the power to stop them, could be held responsible under applicable national law. The Dutch decision itself imposed the €30.5 million fine on Clearview AI Inc., not on named individuals.
Three different forms of exposure
- Corporate administrative liability: the penalty and compliance orders issued against the company.
- Personal administrative or civil liability: a possible future case against individuals involved in directing or permitting the conduct, subject to Dutch law and procedural authority.
- Criminal liability: a separate prosecution under national criminal law, requiring proof of different legal elements and potentially carrying criminal sanctions.
Any personal case would face practical hurdles: identifying the decision-makers, proving knowledge and control, establishing a continuing failure to act, asserting jurisdiction over U.S.-based people, serving proceedings and enforcing an outcome across borders. Travel or assets in a jurisdiction able to act could become relevant, but the AP announcement did not say that executives had been charged or fined.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Can the Netherlands collect from a U.S. company?
A large administrative penalty is not the same as money in the regulator’s account. Clearview’s lack of a Dutch or EU establishment can complicate service, asset tracing and collection. The company’s reported position was that the GDPR did not apply and that the decision was unlawful, lacked due process and was unenforceable; it also said it had no EU customers or place of business. Those arguments could be pursued through legal challenges.
Rank #4
In practical terms, an order to stop EU-related processing may be more immediately significant than collection of the fine. If enforceable, it can affect the company’s ability to maintain or use its database for people in the Netherlands, while penalty payments accrue only when the specified non-compliance is established.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why this matters for facial-recognition and AI companies
The case is not a blanket rule that every company handling public web material violates the GDPR. The AP’s reasoning turns on the people affected, the purpose of processing, the creation of searchable biometric identifiers, the service offered and the organization’s relevant activities. It nevertheless shows why “publicly available” is not the same as “free to collect, identify and reuse.”
It also separates image collection from the more sensitive step of converting faces into identifiers that can be searched against identity information. Companies building AI datasets or biometric products must assess legal basis, Article 9 conditions, transparency, data-subject rights and any Article 27 representation obligation before offering services involving people in the EU.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Best Value
“Largest GDPR fine yet” needs a qualification
Contemporary coverage described the Dutch penalty as Clearview’s largest individual European privacy penalty at the time, larger than separate actions reported in France, Italy, Greece and the United Kingdom. That wording does not mean it was the largest GDPR fine ever imposed on any company. Database-size claims also varied widely in reporting—figures such as 30 billion or more than 50 billion images were attributed to Clearview or secondary reports, not presented as an independently audited constant.
Separate Austrian development
October 28, 2025: Austrian privacy group noyb announced a separate criminal complaint against Clearview. Noyb argued that Austrian law could expose executives to personal liability or imprisonment, a position also reported by Reuters. That proceeding is distinct from the Dutch AP’s 2024 administrative decision and is not evidence that Dutch authorities prosecuted Clearview executives.
Quick Recap
What to watch next
- Whether Clearview’s legal challenges alter, stay or uphold the Dutch decision.
- Whether the AP establishes non-compliance and triggers any penalty payments.
- Whether Dutch authorities identify a lawful route to pursue individuals, rather than only the company.
- Whether other regulators or courts rely on the same reasoning for biometric databases built from publicly accessible images.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




