Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
×
Privacy AI Technology

France Fines Clearview AI Maximum Possible For GDPR Breaches (techcrunch.com) 38

Clearview AI, the controversial facial recognition firm that scrapes selfies and other personal data off the Internet without consent to feed an AI-powered identity-matching service it sells to law enforcement and others, has been hit with another fine in Europe. From a report: This one comes after it failed to respond to an order last year from the CNIL, France's privacy watchdog, to stop its unlawful processing of French citizens' information and delete their data. Clearview responded to that order by, well, ghosting the regulator -- thereby adding a third GDPR breach (non-cooperation with the regulator) to its earlier tally.

Here's the CNIL's summary of Clearview's breaches:
Unlawful processing of personal data (breach of Article 6 of the GDPR)
Individuals' rights not respected (Articles 12, 15 and 17 of the GDPR)
Lack of cooperation with the CNIL (Article 31 of the RGPD)

"Clearview AI had two months to comply with the injunctions formulated in the formal notice and to justify them to the CNIL. However, it did not provide any response to this formal notice," the CNIL wrote in a press release today announcing the sanction [emphasis its].
The size of the fine is $19.57 million.
This discussion has been archived. No new comments can be posted.

France Fines Clearview AI Maximum Possible For GDPR Breaches

Comments Filter:
  • Fines mean nothing if the profits are more than them.

    These clowns need jail time.

    • by Sique ( 173459 )
      If the company does not comply within two month, it's another fine for each day they don't comply.
      • by satsuke ( 263225 )

        You'd think the initial 2 months was enough notice, and that they'd fine them every day they don't comply or have a plan of action on when they will comply.

        Of course the fine will mean nothing if the profits are higher, and thus should be increased to, say, some percentage of their annual revenue, per day.

        • Fines go up if ignored. There are systems in place to ensure compliance isn't optional

        • by Syberz ( 1170343 )
          Fining them is one thing. Collecting that fine is quite another.

          Considering that Clearview are US-based and without a French presence, I don't know how the EU could collect. Great test of the GDPR though.
          • Intercept any fees paid to Clearview by payment providers. Such as Visa, Mastercard, Banks, etc.

            Payment providers would have to comply, if THEY wanted to continue to do business in the EU.

    • Fines for GDPR violations are based on percentage of *global* gross income. That's the beauty of it.
  • by beernutz ( 16190 ) on Thursday October 20, 2022 @03:57PM (#62984039) Homepage Journal
    Beyond them not having a local presence in France?
    • by brunes69 ( 86786 ) <slashdot@nOSpam.keirstead.org> on Thursday October 20, 2022 @04:05PM (#62984051)

      It is an interesting test of the GDPR.

      The GDPR was crafted with an incredibly broad scope, in that it applies to you REGARDLESS of if you are present in Europe, and also REGARDLESS of if you do business in Europe. To be subject to GDPR all that matters is if the data subject is an EU citizen.

      IE - person from France travels to Utah. While there they enter their private information (email address, etc) to a regional Escape Room company. That data is now subject to GDPR regulations, including the right to be forgotten and everything else.

      The nit here is, if your business does not exist in Europe, then these civil penalties are hard to enforce. In theory failure to pay the penalties could make the officers of the company liable which would then prevent them from ever traveling to Europe either. But no one is ever going to extradited due to a GDPR violation - wonâ(TM)t happen.

      • This. I expect this to be a landmark case. Many companies are in limbo in regard to how can GDPR be enforced for a company with no presence in EU.

      • by AmiMoJo ( 196126 )

        Having used GDPR rules with some US companies, I find they are generally quite effective.

        Most US companies at the very least don't want to scupper any future business opportunities in Europe. When it comes to internet companies, they often have things like CDNs and advertising customers in Europe, even if they are a US centric site.

        Clearview AI have ensured that they won't get any customers who operate in the EU, or go anywhere near that market, or think they might in the future.

        • Clearview AI have ensured that they won't get any customers who operate in the EU, or go anywhere near that market, or think they might in the future.

          I'm not sure I believe that. It's too easy to hide both payments and transfers of data; it wouldn't surprise me if even EU law enforcement agencies find a way to make use of Clearview in total disregard of regulations and bans.

        • Other than âoesure, we will deactivate your accountâ, how far have you actually gotten?

          I know many large companies in the EU and in the US that simply donâ(TM)t care beyond lip service.

          • by AmiMoJo ( 196126 )

            Retaliating by deleting your account is illegal, unless that's what you asked them to do.

            Usually I do a DSAR, and then follow up with a deletion request.

            • by guruevi ( 827432 )

              But what proof do you have other than they said they complied. There is no mechanism in GDPR to verify. Besides that, many companies will run afoul of other financial regulation if they just up and comply with any deletion requests.

              Hence me saying, many companies will say "sure, we comply" just to get you to shut up but don't actually delete or even have an internal mechanism to do what you say. They'll just make sure you can't access your database entry.

              • by AmiMoJo ( 196126 )

                Think about the practicality of lying. If they lie and get caught, the consequences can be pretty dire. If they don't want to get caught, they can keep your data hidden away somewhere and cackle with evil laughter about it, but they can't monetize it.

                Don't left perfect be the enemy or really good.

    • Beyond them not having a local presence in France?

      I expect the GDPR breach to contaminate companies that uses it. Companies having presence in France will face similar fines if they use the product (since its use leads to obtain the physical name of a person based on a picture, both of which are private data, and some unlawfully obtained, a fact that a company purchasing the product could not claim in good faith to ignore).

      Also since the ruling is straightforward application of EU legislation, there is high probability that it will extend to other EU count

  • Jurisdiction? (Score:3, Informative)

    by Local ID10T ( 790134 ) <ID10T.L.USER@gmail.com> on Thursday October 20, 2022 @04:13PM (#62984069) Homepage

    I believe Clearview AI is an american company located in New York, with no presence in France.

    Clearview AI is not under French jurisdiction, therefore it has no responsibility to respond to any action by French regulators or courts.

    France would have to petition the US government for any action regarding Clearview AI. I doubt they will get a favorable response. Even tho Clearview AI is scummy, as a US corporate citizen they are legally protected from foreign interference by the full power of the US government.

    • by splutty ( 43475 )

      Clearview is storing biometrical data of French citizens without any for of consent, and thus needs to adhere to the GDPR. It does not matter how/what/where they're incorporated or based.

      • Re: Jurisdiction? (Score:5, Insightful)

        by crackerjack155 ( 1328815 ) on Thursday October 20, 2022 @04:35PM (#62984115)

        As an American company that doesn't operates in the EU, Clearview has no obligation to follow the GPDR or any other EU law. It doesn't matter if they have data on French citizens or not, France has no authority over them, which is why they are ignoring France.

        It's no different than if Iran made a law saying EU women had to wear hijabs and then Iranian courts started ordering them to comply or face fines/jail.

        • by splutty ( 43475 )

          I suppose my little company in Luxembourg selling social security numbers of every US citizen is perfectly fine then.

          • by djinn6 ( 1868030 )

            Morally? No. Legally? Yes.

            There's a reason "jurisdiction" is a widely recognized concept.

          • That would likely violate EU law, but even in America that's not illegal in most states, unless you either acquired then through either fraudulently or as a trusted entity like bank, or if you were intentionally selling them to criminals with the intent of committing crime.

            It's like group in I think New York posted the address of all concealed carry permit holders. They even made a Google map overlay of it

        • France has no authority over them, which is why they are ignoring France.

          A lot would depend on how the EU punishes non-compliance. Would non-compliance be punished by arrest or even jail time? If so, then Clearview executives should be careful about making any stopovers in the EU.

        • You are absolutely right, however: those women had better never set foot in Iran. The same here. Sure, the French fine is unenforceable - just as long as Clearview - and its corporate officers - never set foot (or have any contracts) on the EU. That market is closed to the company, and I sincerely hope that France does (as they apparently can) put out a European warrant on the company's officers personally.
        • by Ubi_NL ( 313657 )

          Ok, makes sense. But then why do americans feel it is completely in their right to sue the entire world on a constant basis! Maybe you should learn that your jurisdiction stops at the border too.

        • by AmiMoJo ( 196126 )

          Clearview AI has an obligation to follow the GDPR if they ever want to do business in Europe, or with European companies.

          They have effectively cut themselves off from one of the world's biggest markets.

        • As an American company that doesn't operates in the EU, Clearview has no obligation to follow the GPDR or any other EU law. It doesn't matter if they have data on French citizens or not, France has no authority over them, which is why they are ignoring France.

          Not true.

          Source: Does the GDPR apply to companies outside of the EU?

          "For example, you may be a US web development company based in Denver, Colorado, selling websites mainly to Colorado businesses. But if you track and analyze EU visitors to your company's website, then you may be subject to the provisions of the GDPR."

          "The whole point of the GDPR is to protect data belonging to EU citizens and residents. The law, therefore, applies to organizations that handle such data whether they are EU-based or

      • Of course it does. That is the concept of jurisdiction.

        Laws and courts only affect those under their jurisdiction.

        Otherwise everyone would be subject to Sharia law (as an example).

    • by nickovs ( 115935 )

      It's not uncommon for countries to have laws regarding crimes against their citizens, even when the action is committed outside the country. The USA has several such laws. Clearview broke a French law by violating the privacy of French citizens and sanctions have been imposed, in France.

      It will be hard for the French government to directly compel Clearview to pay the fine, but there are plenty of indirect methods at their disposal without having to resort to requesting extradition (which seems very unlikely

      • Thatâ(TM)s why companies are incorporated with limited liability. Officers of the company would have to violate the law within EU borders to be liable, just going on vacation, they wouldnâ(TM)t represent the company.

        • The limited liability applies mostly to debts. Even in the US company officers can be held personally criminally responsible for knowingly breaking the law.
  • by Sir Holo ( 531007 ) on Thursday October 20, 2022 @07:17PM (#62984397)

    A $20M fine is nothing for a company the size of ClearView. It's not even a slap on the wrist to them.

  • "scrapes selfies and other personal data off the Internet without consent"

    So, what, are we just supposed to pretend that pictures someone made available to the public, implicitly consenting to letting others see them, aren't publicly available? I'm sorry, but when you put a picture online for the world to see, you're making it available for the world to see. You don't get to complain about who looks at the thing, and you don't get to tell them to forget they saw it. That fundamental absurdity will be t

C'est magnifique, mais ce n'est pas l'Informatique. -- Bosquet [on seeing the IBM 4341]

Working...