The ICO has imposed a fine of £7,552,800 on Clearview AI for committing numerous infringements of the UK GDPR. Clearview, which describes itself as "the World’s largest facial network" has systematically scraped billions of images from social media and other websites, without obtaining individuals' consent or informing them that this data collection was taking place. The ICO concluded that this practice infringes the rights of UK data subjects. It has also demanded that Clearview stops collecting images of UK citizens.
The ICO is the third European regulator to take action against Clearview for breaches of data protection law, after the Supervisory Authorities (SAs) in France and Italy also concluded their investigations in December and March. Both have insisted that Clearview stops processing data relating to their citizens, and the Italian Garante also imposed a €2 million fine.
There are a couple of very noteworthy elements of the case. First, the final penalty issued by the ICO represents a substantial reduction of the £17.5 million figure that it provisionally indicated it would fine Clearview in November last year. This means that each of the ICO's top three fines for data protection breaches have been subject to deep discounts (though the impact of the COVID-19 pandemic played a significant role in the ICO's concessions to Marriot and British Airways).
Second, the case raises fundamental questions about the jurisdictional scope of the (UK) GDPR. Clearview has stated that it does not intend to comply with the decisions of the ICO and Italy's Garante, arguing that neither the regulator has jurisdiction. Clearview is headquartered in New York, claims that it does not offer its services to customers in the UK or Italy, and that it does not "monitor" individuals located there. In the event of any formal appeal lodged by Clearview, much is likely to turn on whether capturing facial images through scraping is deemed monitoring (a term not defined by the (UK) GDPR). Whatever the outcome of such an appeal collecting the fine from Clearview will not be easy, given that it has not appointed an EU representative under Article 27 GDPR – another apparent breach.
This will be a very interesting one to watch, with further investigations into Clearview underway in several other jurisdictions. If Clearview – which the New York Times described as "a secretive company that might end privacy as we know it” – cannot be effectively sanctioned despite widespread failures to observe universal principles of privacy, it could indicate that the jurisdictional test for the application of European data protection laws might require reform.