A practical analysis of the Dutch DPA's €30.5m Clearview AI fine and the data governance lessons for organisations developing or procuring AI.

01

What happened

In September 2024, the Dutch Data Protection Authority announced a €30.5 million fine against Clearview AI and orders subject to further penalty for non-compliance. The regulator said Clearview had built a database containing billions of facial images and converted them into biometric codes without a lawful basis under the GDPR.

The decision is a GDPR enforcement matter, not an EU AI Act enforcement decision. That distinction is important: organisations using AI can face legal exposure under existing data protection law independently of the AI Act classification of a system.

02

Why it matters

AI systems are often discussed in terms of model capability, but data provenance can be the more fundamental governance question. If an organisation cannot explain where training, reference or input data came from and why it may lawfully be processed, technical sophistication does not cure the underlying problem.

03

Who may be affected

The lesson extends beyond facial recognition providers. AI developers, buyers and organisations integrating external datasets should understand data origin, processing roles, legal basis, transparency, retention and the rights of affected individuals before scale makes remediation difficult.

04

Relevant governance and regulatory issues

  • Data provenance and evidence of a lawful basis for personal data processing.
  • Special-category biometric data and the additional protections that apply.
  • Transparency to people whose information is processed.
  • Ability to support data subject rights and deletion requirements.
  • Vendor or dataset due diligence before integrating external data into AI workflows.
05

What businesses should check

  • Can the supplier explain the origin of material datasets and the contractual rights around them?
  • Has privacy review been performed before personal data is used to build or enrich AI systems?
  • Are biometric or other special-category data explicitly identified rather than hidden inside a generic data field?
  • Can the organisation respond if a person asks how their information reached an AI system?
06

Practical actions

Add data provenance to AI procurement and system review. Escalate biometric and large-scale personal data uses for specialist privacy assessment. Require evidence where risk is material rather than relying only on supplier assurances.

07

Blanche perspective

The compliance lesson is broader than one company or one technology. AI governance has to connect to data governance. An inventory that records the provider but ignores the origin and sensitivity of data leaves a significant blind spot.

S

Sources

Primary and authoritative sources used for this Insight.

  1. Dutch Data Protection Authority: Clearview AI fine, 3 September 2024
  2. Dutch DPA: Clearview AI enforcement decision