The Netherlands' data protection authority fined the facial-recognition company Clearview AI EUR 30.5 million in a decision dated 16 May 2024, according to a joint statement from the regulator and the European Data Protection Board. It is the largest confirmed GDPR-related fine tied to camera-based surveillance technology on record. That fine is only the newest entry in a six-year run of CCTV and facial-recognition cases stretching from a Swedish high school to a Polish hospital ward.

How large was the biggest GDPR fine for facial recognition or CCTV surveillance?

The Dutch DPA fined Clearview AI EUR 30.5 million for unlawful facial-recognition data collection, May 2024 EUR 30.5M Dutch DPA fine against Clearview AIfor facial-recognition data collection, 2024

The Dutch Autoriteit Persoonsgegevens fined Clearview AI EUR 30.5 million after finding the company had built a facial-recognition database by scraping billions of photos, including images of people in the Netherlands, without a lawful basis, adequate transparency, or an EU representative. The decision cited violations of GDPR Articles 5, 6, 9, 12, 14, 15, and 27, and layered on four separate compliance orders, each carrying its own penalty for non-compliance, up to a combined EUR 5.1 million if Clearview keeps ignoring them.

That fine did not happen in isolation. Italy's Garante had already fined Clearview EUR 20 million in February 2022 over the same scraping practice applied to people in Italy, and Greece's Hellenic Data Protection Authority fined it another EUR 20 million in July 2022. Three regulators, three separate decisions, one facial-recognition database.

Figure 1: The three confirmed EU fines against Clearview AI, largest first. Sources: Autoriteit Persoonsgegevens and EDPB (2024), Garante per la protezione dei dati personali (2022), Hellenic Data Protection Authority (2022).

A site that installs any camera covering staff, customers, or public space carries the same basic obligations Clearview was fined for skipping: a documented lawful basis and a clear, accessible notice telling people the recording is happening. A privacy policy generator built for GDPR can add that camera-surveillance disclosure alongside the rest of a site's data practices, rather than leaving it as a separate notice nobody maintains.

Why did three regulators fine the same facial-recognition company, and what happened in the UK?

Clearview's EUR 70.5 million combined EU total is not the end of its GDPR history. The UK's Information Commissioner's Office issued its own monetary penalty notice against Clearview for GBP 7,552,800 on 18 May 2022. Clearview appealed on jurisdictional grounds, arguing its processing fell outside UK GDPR because its customers were foreign law-enforcement and government bodies. The First-tier Tribunal agreed in October 2023 and overturned the fine entirely.

CCTV fines against ordinary institutions, not Big Tech (EUR thousands, approx.) Poland (2025)267.7KFrance (2021)20KSweden (2019)17.9K

Figure 2: Everyday CCTV fines against ordinary institutions, converted to approximate EUR for comparison. Sources: CNIL (2021), Datainspektionen/IMY (2019), UODO (2025).

That was not the final word. On 6 October 2025, the Upper Tribunal ruled in the ICO's favor on three of four grounds, in the case cited as [2025] UKUT 319 (AAC), finding that Clearview's facial-recognition activity did fall within UK GDPR's territorial scope because it related to monitoring the behavior of UK residents. The Upper Tribunal did not reinstate the GBP 7,552,800 fine outright. It remitted the case to the First-tier Tribunal to decide the substantive appeal now that the jurisdiction question is settled, so the fine remains unresolved more than three years after it was first issued.

Clearview's combined confirmed EU total ranks among the handful of fines that make up a disproportionate share of GDPR's overall enforcement history, a pattern our biggest GDPR fines of all time post found holds across nearly every large-scale case, not just surveillance ones. For the full picture of how GDPR fines total up across every violation category, see our GDPR fines overview for 2026.

Does an ordinary CCTV camera trigger a GDPR fine too?

Yes, and the fines are much older than Clearview's case. France's CNIL fined Uniontrad Company, a nine-employee Paris translation firm, EUR 20,000 in a decision dated 13 June 2021 (SAN-2021-013) after finding the company filmed its staff continuously at their desks between 2013 and 2017, with no break in the recording during the working day.

Figure 3: The lawful-basis and proportionality test regulators applied in the Uniontrad and Skellefteå decisions. Source: GDPR Articles 5 and 6, and Recital 18's household exemption.

Sweden's Datainspektionen, now the Integritetsskyddsmyndigheten (IMY), fined Skellefteå municipality SEK 200,000 (roughly EUR 17,900) in August 2019, Europe's first GDPR fine tied to facial recognition. A local secondary school had used facial-recognition cameras to track attendance for 22 students over a roughly three-week trial, working with IT vendor Tieto. The regulator found the school lacked a valid lawful basis for processing biometric data and could not rely on consent, since students were in a dependent position relative to the school.

Like the marketing-email fines we have tracked separately, camera-based violations show regulators are just as willing to fine a nine-person company or a single school district as a multinational platform. The marketing-email fines cluster follows the same pattern: the legal test matters more than the size of the organization being tested. Uniontrad's EUR 20,000 and Skellefteå's SEK 200,000 are also nowhere near the floor of GDPR enforcement; regulators across the EU have confirmed individual penalties well below those figures for smaller, first-offense violations, a separate part of this fines cluster we track on its own.

Poland's Urząd Ochrony Danych Osobowych fined Centrum Medyczne Ujastek, a Krakow medical facility, a combined 1,145,891.25 PLN (roughly EUR 267,700) in a decision dated 17 January 2025 (case DKN.5131.4.2024). The regulator found the facility had installed hidden cameras disguised as wall clocks in two neonatal ward rooms, recording for three weeks between 1 and 23 July 2023, without informing patients, guardians, or staff.

The penalty split into two fines: 687,534.75 PLN for processing special-category health data without a lawful basis and without proper transparency, and 458,356.50 PLN for failing to implement adequate security measures after memory cards containing the recordings were lost or stolen, exposing footage tied to 190 people, including 30 patients, 60 guardians, and 97 staff and students. The decision was still non-final as of its listing in UODO's own case database, so the final enforceable amount may still change on appeal.

That combined figure sits between the Uniontrad and Skellefteå fines and the Clearview-scale penalties, and it shows the same violation categories driving both ends of the scale: no lawful basis, no transparency, and inadequate security once something went wrong.

CountryCaseFineYear
NetherlandsClearview AI, facial recognitionEUR 30.5 million2024
ItalyClearview AI, facial recognitionEUR 20 million2022
GreeceClearview AI, facial recognitionEUR 20 million2022
United KingdomClearview AI, facial recognition, unresolvedGBP 7,552,8002022
PolandCentrum Medyczne Ujastek, hidden ward camerasPLN 1,145,891.252025
FranceUniontrad Company, workplace CCTVEUR 20,0002021
SwedenSkellefteå municipality, school facial recognitionSEK 200,0002019

Sources: Autoriteit Persoonsgegevens, Garante per la protezione dei dati personali, Hellenic Data Protection Authority, UK Upper Tribunal, Urząd Ochrony Danych Osobowych, CNIL, Datainspektionen/IMY.

Figure 4: Six years of camera-based GDPR enforcement, from a Swedish classroom to a Dutch tribunal-scale fine. Sources: as listed in Where the Numbers Come From, below.

Spain shows a different kind of scale entirely. The AEPD's own public resolution-search database lists 7,065 entries tagged "Videovigilancia" as of mid-2026, by a wide margin its single largest concept category. That figure blends monetary sanctions with rights requests and other resolution types rather than counting fines alone, so it should be read as evidence of how often camera surveillance generates a regulatory case in Spain specifically, not as a fine total to compare directly against the country-level totals above.

The Bottom Line

CCTV and facial-recognition enforcement spans a wider range than almost any other GDPR category this cluster has covered: a EUR 20,000 fine against a nine-person translation firm sits in the same body of case law as a EUR 30.5 million fine against a facial-recognition company with a global customer base. The common thread across every case here, from Skellefteå's school cameras to Ujastek's hidden clock cameras, is the same two-part test: was there a documented lawful basis before the camera started recording, and was the amount of footage kept proportionate to that basis. Clearview's saga also shows enforcement can stay unsettled for years. Its UK fine has been open since May 2022 and, as of the October 2025 Upper Tribunal ruling, is still not a final, collectible penalty. Any site or business running cameras, whether a retail storefront, an office, or a waiting room, is better served by documenting that lawful basis and disclosing it clearly than by waiting to find out which side of this range its own camera setup lands on.

Frequently Asked Questions

What is the largest GDPR fine ever issued for facial recognition or CCTV-style surveillance? EUR 30.5 million, imposed by the Netherlands' data protection authority against Clearview AI in a decision dated 16 May 2024, with up to a further EUR 5.1 million possible if the company keeps failing to comply with the regulator's orders.

Has Clearview AI been fined by more than one European regulator? Yes. Italy's Garante fined Clearview EUR 20 million in February 2022, Greece's HDPA fined it EUR 20 million in July 2022, and the Netherlands' DPA fined it EUR 30.5 million in 2024, a combined EUR 70.5 million. The UK's ICO also fined Clearview GBP 7,552,800 in 2022, but that fine was overturned in 2023 and remains unresolved after an Upper Tribunal ruling in October 2025.

Can a small business be fined under GDPR just for having a CCTV camera? Yes. France's CNIL fined a nine-employee Paris translation company EUR 20,000 in 2021 for filming staff continuously at their desks, and Sweden's regulator fined a school SEK 200,000 (roughly EUR 17,900) in 2019 over facial-recognition attendance tracking, Europe's first GDPR fine tied to camera-based facial recognition.

What is the worst CCTV-related GDPR violation on record? Poland's UODO fined a Krakow medical center a combined 1,145,891.25 PLN (roughly EUR 267,700) in a decision dated 17 January 2025, after finding hidden cameras disguised as clocks recording two neonatal ward rooms without patient or staff knowledge.

Where the Numbers Come From

  1. European Data Protection Board / Autoriteit Persoonsgegevens. (2024). "Dutch Supervisory Authority Imposes a Fine on Clearview Because of Illegal Data Collection for Facial Recognition." EUR 30.5 million fine, decision dated 16 May 2024, plus compliance orders carrying up to EUR 5.1 million in further penalties.
  2. Garante per la protezione dei dati personali. (2022). Administrative sanction against Clearview AI Inc. EUR 20 million fine, decision dated 10 February 2022, published 9 March 2022.
  3. Hellenic Data Protection Authority. (2022). "Imposition of Fine on Clearview AI Inc." Decision No. 35/2022, EUR 20 million fine, dated 13 July 2022.
  4. UK Upper Tribunal (Administrative Appeals Chamber). (2025). "The Information Commissioner's Office v Clearview AI Inc." [2025] UKUT 319 (AAC), judgment dated 6 October 2025, restoring the ICO's jurisdiction and remitting the case; original GBP 7,552,800 penalty notice issued 18 May 2022, overturned by the First-tier Tribunal in October 2023.
  5. Legifrance / CNIL. (2021). Deliberation SAN-2021-013 against Uniontrad Company. EUR 20,000 fine, sanction dated 13 June 2021, for continuous video surveillance of employees between 2013 and 2017.
  6. GDPRhub / Datainspektionen (Sweden). (2019). Decision against Skellefteå municipality. SEK 200,000 fine, issued August 2019, over facial-recognition attendance tracking of 22 students at Anderstorp secondary school.
  7. Urzad Ochrony Danych Osobowych. (2025). Decision DKN.5131.4.2024 against Centrum Medyczne Ujastek. Combined 1,145,891.25 PLN fine, decision dated 17 January 2025, non-final at time of publication, over hidden cameras in two neonatal ward rooms.
  8. Agencia Espanola de Proteccion de Datos. Public resolution-search database, "Videovigilancia" concept filter, 7,065 resolutions listed as of the database's mid-2026 state.

Note: All figures verified as of September 2026. The Polish UODO fine against Centrum Medyczne Ujastek was non-final as of its listing in the regulator's own decision database and may change on appeal. The UK's GBP 7,552,800 Clearview fine is not currently a final, collectible penalty pending the First-tier Tribunal's substantive rehearing. SEK and PLN figures are converted to approximate EUR values using rates current in 2026 for comparison only; see each source for the original currency amount. This post is refreshed at least twice a year as new decisions are published.