Independent · Updated continuously
Artificial Intelligence in Law Enforcement
Facial recognition

Clearview AI facial recognition

Facial recognition matching against a database of tens of billions of images scraped from the public internet without consent, sold to police and intelligence agencies, and found unlawful by regulators across Europe.

Clearview AI (United States) Supplier's own site ↗

Clearview AI is the most heavily sanctioned technology company in this catalogue, and it is still operating. Its business is simple to describe: scrape photographs of faces from the public internet, convert each into a biometric code, and sell police, military and intelligence agencies the ability to upload an image of an unknown person and get back a name.

The company was founded in the United States and is led by Hoan Ton-That. What distinguishes it from every other facial recognition supplier here is the source of its gallery. NEC and Idemia match against custody images a force already holds. Clearview matches against the internet — Facebook photographs, LinkedIn headshots, Instagram selfies, images from news articles and personal blogs, collected from people who never encountered the criminal justice system and never consented.

HOW THE COMPANY DESCRIBES IT

Clearview's own material states that its platform includes the largest known database of more than 50 billion facial images, sourced from public-only web sources including news media, mugshot websites, public social media and other open sources. The "public-only" framing is the core of its defence: that photographs already visible on the open web are fair to collect.

Its stated use case is investigative lead generation. The company positions results as indicative rather than definitive, requiring further verification — a framing this site's tracker entry already records.

THE SIZE OF THE DATABASE

Figures vary by source and by date, and the variation is itself informative. The UK regulator worked from around 20 billion images in 2022. Dutch and other regulators cited 30 billion in 2024. The privacy organisation noyb put it above 60 billion in 2025. Clearview's own site claims more than 50 billion. The database grows continuously, so no single figure is stable, but every source agrees the order of magnitude is tens of billions — several images for every person alive.

THE REGULATORY RECORD

No other system in this catalogue has been found unlawful by this many authorities.

The Dutch Data Protection Authority fined Clearview €30.5 million in September 2024, the largest GDPR penalty against the company, with a further non-compliance order of up to €5.1 million. Its reasoning was that Clearview should never have built the database at all: the biometric codes are, like fingerprints, biometric data whose collection is prohibited absent a statutory exception the company cannot rely on. The regulator also stated that use of Clearview's services within the Netherlands is itself prohibited, and warned that company directors can be held personally liable where they know the GDPR is being violated, have authority to stop it, and consciously accept the violations.

Italy, Greece and France each imposed fines of around €20 million. Greece's, in July 2022, was described at the time as record-breaking. Authorities in Germany and Austria ruled the company's processing unlawful without financial penalty — the Hamburg commissioner concluding in January 2021 that the extracted hash constituted biometric data under Article 4(14) GDPR. Regulators variously ordered deletion of European data and cessation of collection.

The United Kingdom's case is the most legally interesting. The ICO fined Clearview £7.5 million in May 2022. In October 2023 the First-tier Tribunal set that aside, finding the processing fell outside the material scope of UK and EU data protection law because it was carried out exclusively in support of foreign governments. The ICO appealed, with Privacy International intervening. In 2025 the Upper Tribunal reinstated the fine. Information Commissioner John Edwards said the ruling upheld the regulator's ability to protect UK residents from having their images unlawfully scraped into a global database without their knowledge, and confirmed the regulator can act regardless of where the company is based.

Taken together, European authorities have imposed roughly €100 million in penalties.

THE ENFORCEMENT PROBLEM

That total is the point at which the story becomes about regulation rather than about technology. Clearview is a US company with no establishment in Europe. The Dutch regulator acknowledged directly that compelling an American company without a European presence to obey the law has proven difficult. Reporting indicates the company has largely ignored the orders.

In October 2025 the privacy organisation noyb filed a criminal complaint, on the reasoning that administrative fines had failed. Max Schrems argued that cross-border criminal procedures are run for stolen bicycles, and asked why not for the personal data of billions of people.

THE CASE FOR IT

The investigative argument is real and should not be dismissed. A photograph of an unknown suspect, or of an unidentified child in abuse material, is a genuine dead end for an investigation, and a tool that generates a candidate identity where none existed can move a case that would otherwise stall. Several documented uses concern victim identification rather than suspect identification.

The company's stated discipline — that a result is an investigative lead requiring corroboration — is the correct one, and matches how forces using it publicly describe their practice.

THE CASE AGAINST

The objection is not primarily about accuracy. It is that the gallery was assembled without consent from people with no connection to any investigation, which is what every regulator that has examined it has concluded, and which no accuracy improvement addresses.

There is also a documented harm record. This site's tracker records wrongful arrests attributed to Clearview searches, including a Georgia man arrested over a Louisiana offence he had no connection to, and a case settled for $200,000. A caution that matters for accuracy: not every US facial recognition wrongful arrest is a Clearview case, and this site is careful not to attribute them all to one vendor.

The regulatory record raises a distinct question for any force using it. Where a supplier's database has been found unlawful by multiple European authorities, a force procuring its services is relying on evidence derived from processing that regulators in its own or neighbouring jurisdictions have declared illegal. That is a live problem for admissibility and for public confidence, quite separate from whether the match was correct.

The enforcement gap also sets a precedent visible to every other vendor: that a company operating from outside the EU can absorb roughly €100 million in fines and continue.

WHAT IS NOT ESTABLISHED

The current database size is unverifiable independently; every figure originates with the company or with regulators relying on the company's disclosures.

Whether any European deletion order has been complied with is not established.

The number of active police customers is unclear. The roughly 3,100 US agency figure recorded on this site's tracker is a historical company estimate, not a verified current count.

Whether the Upper Tribunal's reinstatement of the UK fine has resulted in payment is not established by the sources reviewed.

Related subject: Facial Recognition in Policing

Where this is deployed

Full tracker →
CountryForceStatus
US~3,100 US police departments (company estimate)United StatesOperational
CARoyal Canadian Mounted Police (National Child Exploitation Crime Centre)CanadaDiscontinued
AUAustralian Federal Police and state police (Queensland, Victoria, South Australia)Australia, national and state forcesDiscontinued
FINational Bureau of InvestigationFinland, nationalDiscontinued
NZNew Zealand PoliceNew Zealand (national)Discontinued
ARPolicía Federal Argentina (Ministerio de Seguridad de la Nación)NationalOperational
ARMinisterio Público Fiscal de la Ciudad Autónoma de Buenos AiresCiudad Autónoma de Buenos AiresOperational
Operational: 3Discontinued: 4
Operational 3Discontinued 4

Sources

  1. Clearview AI — official site
  2. Autoriteit Persoonsgegevens (Dutch DPA) — fine and reasoning, including director liability
  3. Biometric Update — UK Upper Tribunal reinstates the ICO fine and clarifies GDPR scope
  4. noyb — criminal complaint against Clearview AI, with the cumulative European fine total
  5. Forbes — Dutch fine, comparison with Italian, Greek and French penalties, and the enforcement difficulty
  6. Solomon — investigation into how Clearview evaded European enforcement
  7. TIME — early coverage of the UK fine and the scale of scraping
  8. ACM — academic analysis of the Hamburg decision on biometric hash values under GDPR Article 4(14)