Clearview Al Inc.

€20,000,000

Non-compliance with general data processing principles

Fecha de la decisión

10 de febrero de 2022

Autoridad

Italian Data Protection Authority (Garante)

IT

Sector

Industry and Commerce

País

IT

Ley

GDPR

Estado

FINAL

Descripción

The Italian DPA has fined U.S.-based Clearview AI EUR 20 million after it was revealed that the company had been applying biometric surveillance techniques on Italian territory. The company owns a database of over 10 billion facial images from around the world. The company offers a search service that allows profiles to be created based on the biometric data extracted from the images. The profiles can be enriched with information associated with these images, such as image tags and geolocation. The DPA launched an investigation into the company after it became known that Clearview - contrary to initial claims - also enabled searches of Italian nationals and residents. The DPA found that the personal data contained in the company's database had been processed unlawfully and without a valid legal basis. In addition, the DPA found that the company had violated several principles of the GDPR. For example, the company had violated the principle of transparency by failing to adequately inform users about the processing of their data. Clearview had also violated the principle of purpose limitation, by processing users' data for purposes other than those for which they had been made available online. Finally, it violated the principle of storage limitation by not specifying a time period for data storage.

Citas legales

Art. 5 (1)Art. 6Art. 9Art. 12Art. 13Art. 14Art. 15Art. 27

Problemas e infracciones

Non-compliance with general data processing principles

Manténgase al día sobre la aplicación de las normas de protección de la intimidad

Respetamos su intimidad. Un correo electrónico al mes, sin spam, darse de baja en cualquier momento.