[AI Library] Chapter 7. GDPR and EU Regulation
Artificial Intelligence on Trial
Part 2. Algorithmic Discrimination and Regulatory Enforcement
Chapter 7. GDPR and EU Regulation
Attorney Kyungjin Kim
A. The Company That Stole 30 Billion Facial Photos (Clearview AI)
(1) Netherlands: 30.5 Million Euro Fine
On May 16, 2024, Aleid Wolfsen, chair of the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), signed the decision.
It imposed a fine of 30.5 million euros on Clearview AI, a facial recognition company headquartered in New York. When the decision was made public on September 3 of the same year, Wolfsen told reporters: "Facial recognition is a highly intrusive technology. You cannot simply unleash it on everyone in the world."
To understand what Clearview AI did, you first need to understand their business model.
The company crawls the internet collecting photos of people's faces. From Facebook, Instagram, LinkedIn, news sites, every publicly accessible webpage. Automated programs called crawlers perform this work. Each collected facial image is converted through an algorithm into a unique biometric code, a combination of numbers that can identify each person like a fingerprint. As of 2024, Clearview's database held more than 30 billion facial photos. The company's website boasted 50 billion.
This database was sold to law enforcement agencies.
When police capture a face from CCTV footage at a crime scene, they upload it to the Clearview system. The system searches through 30 billion photos for a matching face. It then reveals where that photo came from, the person's name, and which social media accounts are linked to them. A useful tool for criminal investigations.
The problem is that not a single one of the billions of people in this database knew their face was being collected. No one was ever asked for consent. The Dutch Data Protection Authority determined this violated multiple GDPR provisions.
First, a violation of Article 6. Processing personal data requires a lawful basis. It must fall under one of six grounds: consent, contract performance, legal obligation, legitimate interest, and so on. Clearview met none of them.
Second, a violation of Article 9. Biometric data is classified as sensitive information. It requires stricter protection. Collection itself is prohibited without explicit consent.
Third, a violation of Article 14. When personal data is collected from third parties, the data subject must be informed. Clearview never informed anyone.
Beyond the 30.5 million euro fine, the Dutch Data Protection Authority issued four corrective orders. If the violations are not stopped, an additional 5.1 million euros in penalty payments will be imposed. Chair Wolfsen went a step further: "We are now investigating whether we can hold company executives personally liable. Directors who knew about these violations and failed to prevent them can be held personally responsible."
Clearview's response was predictable. The company's chief legal officer, Jack Mulcaire, called the decision "unlawful, lacking due process, and unenforceable." His logic ran like this: Clearview has no establishment in the Netherlands. It has no customers in the EU. Therefore GDPR does not apply.
This is where the concept of GDPR's extraterritorial application comes in. Article 3 of GDPR stipulates that even companies outside the EU are subject to the law if they process the personal data of EU residents. The moment Clearview collected Dutch citizens' faces, the Dutch Data Protection Authority's jurisdiction was triggered. Clearview did not challenge the decision. It therefore lost its right to appeal. But it showed no intention of paying the fine either.
(2) Sanctions in the UK, France, and Italy
The Netherlands was not alone. Clearview AI faced a barrage of fines across Europe.
France's data protection authority, CNIL, imposed a 20 million euro fine on Clearview in October 2022. It also ordered the company to stop collecting and processing data of individuals within French territory and to delete data already collected.
Clearview was required to submit evidence of compliance within two months. In May 2023, CNIL announced that Clearview had failed to comply and imposed an additional fine of 5.2 million euros.
The European Data Protection Board (EDPB) confirmed in a 2023 report that Clearview had not submitted any evidence of compliance.
Italy's data protection authority (Garante) imposed 20 million euros in March 2022. The UK Information Commissioner's Office (ICO) imposed 7.5 million pounds (approximately 9 million euros) in May of the same year. The Greek Data Protection Authority also imposed sanctions in 2022. The cumulative total approached 100 million euros.
The UK case followed a legally complex path. When the ICO issued its fine and enforcement notice in May 2022, Clearview appealed. The company's argument was this: we only provide services to law enforcement and national security agencies outside the UK. Such activities fall outside the scope of GDPR. In October 2023, the First-tier Tribunal sided with Clearview, ruling that the ICO had no jurisdiction.
The ICO appealed. On January 31, 2025, the Upper Tribunal granted permission to appeal. Hearings took place from June 9 to 11 of the same year. Privacy International, a civil society organization, participated as an intervener. On October 6, 2025, the Upper Tribunal delivered its judgment. It accepted three of the ICO's four grounds of appeal.
The Upper Tribunal's reasoning addressed three key issues. First, whether Clearview's data processing relates to 'behavioral monitoring' of UK residents. The tribunal found that it does. The concept of 'behavioral monitoring' must be interpreted broadly. It includes not only real-time surveillance but also passive data collection, categorization, and storage for future profiling purposes. The very act of Clearview collecting facial images, generating biometric codes, and storing them in a database constitutes behavioral monitoring.
Second, whether Clearview is exempt from UK data protection law because it provides services to foreign law enforcement agencies. The tribunal found it is not. Clearview itself is not a law enforcement body. It is a private company providing a commercial service. It cannot claim exemption simply because its customers happen to be law enforcement agencies.
Third, whether the First-tier Tribunal misapplied the law. The Upper Tribunal found that it did. The case was remanded to the First-tier Tribunal. A hearing on the merits will proceed on the premise that the ICO has jurisdiction.
On December 19, 2025, the Upper Tribunal granted Clearview permission to proceed to the next stage of appeal. The case is set to move to the Court of Appeal. UK Information Commissioner John Edwards said: "The Upper Tribunal's decision confirms our ability to protect against the unauthorized collection of UK residents' data for use in a global online database."
(3) Limits and Effectiveness of GDPR's Extraterritorial Application
Fines totaling close to 100 million euros have been imposed across Europe. But there is one uncomfortable truth. Clearview has not paid a single cent.
This is the fundamental limitation of GDPR's extraterritorial application. The law applies to companies outside the EU. But if a company outside the EU has no assets within the EU, how can fines be collected? Clearview is in New York. It has no offices in Europe, no bank accounts, no equipment. The Dutch Data Protection Authority has nothing to seize.
That does not mean these sanctions are meaningless. They produce real effects.
First, market access is blocked. Clearview can no longer legally enter the EU market. Any organization within the EU that uses Clearview's services risks GDPR sanctions itself. Chair Wolfsen issued a clear warning: "Dutch organizations that use Clearview's services should expect a substantial fine from the Dutch Data Protection Authority."
Second, there is a de facto business ban. Clearview's website now states: "Clearview AI does not provide its technology in the EU, the UK, Australia, or Canada." This is not a voluntary withdrawal. It is a retreat under regulatory pressure.
In October 2025, the Austrian digital rights organization noyb (None of Your Business) tried a new strategy. It filed a criminal complaint with Austrian prosecutors. The charge: illegal collection of civilians' biometric data. noyb's argument was this: if administrative fines don't work, criminal prosecution must be attempted. If international arrest warrants are issued for Clearview executives, they will be unable to visit any European country.
This signals a new phase in data protection enforcement. A shift from administrative sanctions to criminal penalties. An expansion from fines against companies to personal accountability for individuals. The Clearview case exposes the gap between GDPR's ambition and reality. At the same time, it shows that creative attempts to close that gap are underway. But the fundamental question remains: how can regulators confined by borders control companies that transcend them in the digital age? Clearview proves that this question still has no answer.
B. Other GDPR Enforcement Cases
(1) Budapest Bank AI Credit Scoring Sanction
In 2022, Hungary's National Authority for Data Protection and Freedom of Information (NAIH) imposed a fine of approximately 250 million forints (about 670,000 euros) on Budapest Bank.
The reason: the bank used AI to analyze customer emotions during customer service calls.
The bank's system worked like this.
When a customer called the call center, the conversation was recorded. AI analyzed the recording to determine the customer's emotional state. Angry, satisfied, anxious. This information was added to the customer profile and used for future services and marketing.
The problem was that customers did not know. There was a notice that calls were being recorded. But there was no notice that AI was analyzing their emotions. Articles 12 through 14 of GDPR establish transparency obligations. Data subjects must be clearly informed about how their personal data is processed. Budapest Bank failed to meet this obligation.
A larger issue relates to Article 22 of GDPR. This provision concerns automated decision-making. Decisions that produce legal effects or significantly affect an individual must not be based solely on automated processing. The final decisions were made by human employees, yes. But if AI emotion analysis influenced those decisions, does that not circumvent the intent of Article 22?
The Hungarian authority determined that it does. Even if AI does not make the decision directly, transparency obligations arise when AI profiling influences human decisions. This ruling became an important precedent. It established the principle that even when AI is used as an auxiliary tool, customers must be informed of its use.
(2) LinkedIn Data Processing Violation
On October 24, 2024, Ireland's Data Protection Commission (DPC) imposed a fine of 310 million euros on LinkedIn. The decision found that the Microsoft-owned business networking platform had violated the GDPR.
The case traces back six years. On August 20, 2018, the French digital rights organization La Quadrature du Net filed a complaint with France's data protection authority, CNIL.
The complaint alleged that LinkedIn was unlawfully using personal data for behavioral analysis and targeted advertising. CNIL transferred the complaint to Ireland's DPC because LinkedIn's European headquarters is in Dublin.
The investigation took six years.
What the DPC examined was how LinkedIn processed user data. LinkedIn collects two types of data.
First, there is first-party data that users provide directly: profile information, posts, connections, and so on.
Second, there is third-party data collected through partner organizations: records of users visiting other websites, app usage patterns, and similar information.
LinkedIn analyzes this data to identify behavioral patterns. What content does a user engage with? Which ads do they respond to? Based on this information, LinkedIn serves targeted advertising.
The problem was that LinkedIn lacked a lawful basis for this processing.
Article 6 of the GDPR limits the lawful bases for processing personal data to six. LinkedIn claimed three. First, consent (Article 6(1)(a)). The DPC found that the consent LinkedIn obtained was "not freely given, not sufficiently informed, not specific, and not unambiguous." Second, contractual necessity (Article 6(1)(b)). The DPC determined that behavioral analysis and targeted advertising were not contractually necessary to provide LinkedIn's service. Third, legitimate interests (Article 6(1)(f)). The DPC concluded that LinkedIn's interests were "overridden by the interests and fundamental rights and freedoms of the data subjects."
LinkedIn had processed personal data without a lawful basis. This is a violation of the most fundamental principle of the GDPR. DPC Deputy Commissioner Graham Doyle stated: "The lawfulness of processing is a fundamental aspect of data protection law. Processing personal data without an appropriate legal basis is a clear and serious violation of the data subjects' fundamental rights."
The 310 million euro fine was imposed for three separate violations. 105 million euros for the consent-related violation. 110 million euros for the legitimate interests violation. 95 million euros for breaching transparency obligations. Microsoft had already set aside 425 million dollars in 2023 as a provision for potential fines in this case. The actual penalty came in lower than that.
LinkedIn issued a statement: "We believe we have been in compliance with the GDPR. However, we are working to ensure our advertising practices meet this decision within its deadlines." The company did not clearly state whether it would appeal.
(3) Meta's Texas Settlement: $1.4 Billion for Facial Recognition
On July 30, 2024, Texas Attorney General Ken Paxton announced a historic settlement. Meta (formerly Facebook) agreed to pay $1.4 billion to the state of Texas. It was the largest privacy-related settlement with a single U.S. state in American history.
At the heart of this case was a feature called "Tag Suggestions." From 2011 to 2021, when users uploaded photos to Facebook, the platform automatically recognized faces and asked, "Is this [friend's name]?" It was a convenient feature. The problem was that it collected and stored facial geometry data without users' consent.
Texas enacted its biometric privacy law, the Capture or Use of Biometric Identifier Act (CUBI), in 2009. The law requires companies to obtain written consent before collecting an individual's biometric information. Facebook's Tag Suggestions feature did not meet this requirement.
Attorney General Paxton filed the lawsuit in February 2022. His argument was this: Facebook had illegally collected the biometric data of millions of Texas residents for a decade. This violated both CUBI and the Texas consumer protection statute. In the 2024 settlement, Meta did not admit liability. But it agreed to pay $1.4 billion, spread over five years, with $500 million due in the first year.
This case does not involve the GDPR. It is a sanction under U.S. state law. But it carries the same message. Unauthorized collection of biometric data is producing increasingly severe legal consequences worldwide.
Meta had already settled an Illinois BIPA (Biometric Information Privacy Act) class action for $650 million in 2020. Adding the $1.4 billion Texas settlement, the legal costs from the Tag Suggestions feature alone exceeded $2 billion. It was no coincidence that Meta discontinued the feature entirely in 2021.
C. The EU AI Act Framework
(1) Implementation Timeline and Penalty Structure
On August 1, 2024, the EU AI Act entered into force. It is the world's first comprehensive AI regulation. But entry into force does not mean immediate application. The law applies in phases, giving companies time to prepare.
The first application date was February 2, 2025. From that day, prohibited AI practices became illegal. What was banned? Social scoring, meaning systems that rate people based on their social behavior. Manipulative AI that exploits vulnerable groups. Real-time remote biometric identification for law enforcement purposes. These AI systems had to be removed from the EU market.
The second application date was August 2, 2025. Regulations for General-Purpose AI (GPAI) models began to apply. Large language models like ChatGPT, Claude, and Gemini fall into this category. Any new GPAI model released after this date must meet the law's requirements.
The third application date is August 2, 2026. Regulations for high-risk AI systems will be fully enforced. The European Commission's AI Office will have full enforcement powers, including the authority to request information, access models, and order model recalls.
The fourth application date is August 2, 2027. The grace period for high-risk AI systems embedded in regulated products expires. GPAI models released before August 2, 2025 must also comply with the law by this date.
The penalty structure is divided into three tiers based on the severity of the violation. For the most serious violations, using prohibited AI practices, the maximum fine is 35 million euros or 7% of global annual revenue, whichever is higher. For violations of high-risk AI requirements, the maximum is 15 million euros or 3% of revenue. For providing false information, the maximum is 7.5 million euros or 1.5% of revenue. Industry lobbied for an enforcement moratorium. There were calls to "stop the clock." The European Commission refused, stating that the timeline was final and would not change. In 2025, however, the Commission's "Digital Simplification Package" proposed that the application date for high-risk rules could be adjusted by up to 16 months. This was intended to give companies time until standards and support tools are ready.
(2) High-Risk AI Regulatory Requirements
The EU AI Act adopts a risk-based approach. It does not regulate all AI equally. Regulatory intensity varies according to risk level. The strictest regulation applies to "high-risk" AI systems.
What qualifies an AI system as high-risk? It is AI used in sectors listed in the law's annexes.
Safety components of medical devices. AI used in educational institutions for student assessment or admission decisions.
AI used in employment processes for recruitment, promotion, or termination decisions.
AI used for credit scoring or insurance underwriting.
AI used in law enforcement for criminal risk assessment.
AI used in immigration management for visa application screening.
These high-risk AI systems must meet strict requirements before being placed on the market.
First, a risk management system must be established. A continuous process for identifying, analyzing, evaluating, and mitigating risks throughout the AI system's lifecycle is required.
Second, data governance is required. Training data quality must be managed, and bias must be prevented.
Third, technical documentation must be prepared. How the system works and what data it was trained on must be documented.
Fourth, transparency and explainability must be ensured. Users must be able to understand the AI's decisions.
Fifth, human oversight must be guaranteed. Even if AI operates autonomously, humans must be able to intervene.
Sixth, accuracy, resilience, and cybersecurity must be ensured. A conformity assessment must be completed before market placement. In some cases, a third-party assessment is required. Systems that meet the requirements can carry the CE mark. The CE mark is a mandatory condition for entering the EU market.
(3) Regulation of General-Purpose AI Models
General-Purpose AI (GPAI) models have their own separate regulatory framework.
What is a GPAI model? It is a general-purpose AI model capable of performing a variety of tasks: generating text, creating images, writing code, and more. ChatGPT is the most prominent example. The EU AI Act defines these models as those trained with computing power of 10^23 FLOP (floating-point operations) or more.
All GPAI model providers have transparency obligations. They must prepare and maintain technical documentation. They must establish copyright policies. They must publish a summary of training data. They must provide downstream providers with the information they need.
Some GPAI models are classified as posing 'systemic risk.'
These are models trained with 10^25 FLOP or more, or models with high-impact capabilities.
Providers of such models bear additional obligations.
They must conduct adversarial testing (red teaming).
They must report serious incidents to the AI Office.
They must implement reinforced cybersecurity measures.
They must report energy consumption.
On July 10, 2025, the European Commission published the GPAI Code of Practice. This is a voluntary tool that guides GPAI providers on how to comply with their legal obligations.
It consists of three chapters: transparency, copyright, and safety and security.
Companies that sign the Code of Practice receive a 'presumption of conformity.' In other words, they are deemed to be in compliance with the law.
This reduces the administrative burden and increases legal certainty. As of August 1, 2025, major AI companies including Amazon, Google, Microsoft, OpenAI, and Anthropic have signed on. Notably, xAI (Elon Musk's company) signed only the safety and security chapter, declining to sign the transparency and copyright chapters. The company must demonstrate compliance with those obligations through other means. The AI Office is housed within DG CONNECT at the European Commission. It holds supervisory authority over GPAI models. Full enforcement powers take effect on August 2, 2026. Until then, the AI Office works informally with providers to support compliance.
The multi-jurisdictional sanctions against Clearview AI revealed both the ambition and the limits of GDPR's extraterritorial reach. The EU AI Act was designed with that experience in mind. If AI companies want access to the EU market, they must follow EU rules. This is the 'Brussels Effect,' the phenomenon by which EU regulation becomes a global standard. Whether this effect will hold in the AI sector should become clear within the next few years.
Kim Kyung-jin
Attorney · Former Member of the National Assembly · AI Policy Researcher
© 2026 Kim Kyung-jin. All rights reserved.



