A UK tribunal has overturned a privacy sanction against Clearview AI, the US facial recognition company. The decision turned on jurisdiction: the tribunal accepted that Clearview served only non-UK and non-EU law enforcement or national security bodies and their contractors, placing its activities within an exemption for foreign law enforcement.
The appeal turned on who Clearview serves
In May 2022, the Information Commissioner’s Office (ICO) issued an enforcement notice against Clearview. The action included a fine of around £7.5 million (~$10 million) and required the company to delete information it held on UK citizens. The ICO had concluded that Clearview committed multiple breaches of local privacy laws.
Clearview challenged that decision. The tribunal agreed with the ICO that the company’s data processing related to monitoring people’s behavior by its clients, and found Clearview to be a joint controller for that processing. But it ruled that the ICO could not apply the UK GDPR in this case because of the foreign law enforcement exemption.
The UK GDPR excludes personal data processing by competent authorities for law enforcement purposes from its scope. Such processing is instead covered by Part 3 of the Data Protection Act 2018. The tribunal accepted Clearview’s position that it provides its service exclusively to foreign law enforcement and national security bodies, and to contractors performing those functions.
The ICO has not decided what comes next
After the ruling, the ICO said it would review the judgment and consider its next steps. It emphasized that the decision does not remove its ability to act against internationally based companies processing UK residents’ data, especially businesses scraping information about people in the UK. The judgment, it said, addresses a specific exemption for foreign law enforcement.
The ICO did not say whether it would appeal, but said it had 28 days to decide. The report also raised an unanswered question: why the ICO brought its case under the UK GDPR rather than the Data Protection Act 2018. The regulator declined to comment on that point.
Clearview welcomed the result. Its general counsel, Jack Mulcaire, said the company was pleased with the tribunal’s decision to reverse what he called the ICO’s unlawful order.
European enforcement remains difficult
The UK case is one of several actions taken against Clearview under regional data protection laws. Authorities in France, Italy and Greece have found the company in breach of the EU’s GDPR. The UK has its own distinct version of GDPR since Brexit, so the tribunal’s decision may not directly determine the outcome of those separate proceedings.
In France, the CNIL had ordered Clearview to delete data on French citizens and stop unlawful processing. It also imposed penalties. The authority later confirmed that Clearview had not paid them and had not appealed the regulatory sanction. A CNIL spokesperson described the company as “non-cooperative.”
The report said European data protection authorities have struggled to make their decisions stick. GDPR can apply to companies based outside Europe when they process local residents’ data, but Clearview’s focus on foreign government clients adds a jurisdictional obstacle. The case illustrates the gap that can emerge between rules that reach across borders and the practical ability to enforce them.
Facial recognition faces wider legal scrutiny
Clearview’s model relies on collecting photographs and facial images from the public internet to build a database for identity matching. European data protection bodies have raised concerns about this kind of mass, indiscriminate collection, including when the technology is used for law enforcement.
The European Data Protection Board and the European Data Protection Supervisor have called for a ban on law enforcement processing that relies on databases built through mass collection of personal data. Their guidance also says authorities considering facial recognition must assess necessity, proportionality and effects on other fundamental rights.
EU lawmakers backed amendments to the draft AI Act that would prohibit indiscriminate scraping of biometric data to create facial recognition databases. Whether that prohibition will appear in the final text remained unresolved in the source report. Even if new rules are adopted, the case leaves an enforcement question: how effectively can regional authorities compel a foreign company to change its practices?