What Happened
In January 2020, a New York Times investigation revealed that a small startup called Clearview AI had scraped more than 3 billion images from social media platforms, news sites, and other publicly accessible web pages to build a massive facial recognition database. The company sold access to this database to law enforcement agencies across the United States and internationally, allowing police to upload a photo of a person and find matches across the scraped database.
The scraping violated the terms of service of virtually every platform from which images were taken, including Facebook, Twitter, YouTube, and LinkedIn. Clearview had built its technology in secret, and most of the individuals whose faces were in the database had no knowledge of or consent to their inclusion.
Timeline
Clearview AI was founded in 2017 and operated in near-secrecy until the January 2020 NYT expose. Following the report, social media companies sent cease-and-desist letters. The ACLU filed a lawsuit under Illinois’ Biometric Information Privacy Act in May 2020. Multiple countries launched investigations, and by 2022, regulatory actions were underway across Europe, Australia, and Canada. Clearview settled the ACLU lawsuit in 2022, agreeing to restrictions on commercial sales.
Impact
The Clearview AI revelation transformed the facial recognition privacy debate. It demonstrated that in the absence of regulation, a private company could unilaterally create a surveillance tool of unprecedented scope from publicly available data. The tool was used by more than 600 law enforcement agencies before its existence was even publicly known.
Regulatory responses were swift and severe. The UK’s Information Commissioner fined Clearview over 7.5 million pounds. France’s CNIL fined the company 20 million euros. Australia and Canada ruled that Clearview’s practices violated their respective privacy laws. Italy imposed a 20 million euro fine.
Response
Clearview AI defended its practices by arguing that scraping publicly available information was protected under the First Amendment. CEO Hoan Ton-That compared the technology to a Google search for faces. The company continued to operate and sell to law enforcement while fighting legal challenges.
In the ACLU settlement, Clearview agreed not to sell its database to most private companies but was permitted to continue working with government agencies. The company pivoted to position itself as a government-focused security tool.
Lessons Learned
The Clearview case demonstrated that the absence of facial recognition regulation created a vacuum that private companies could exploit to build surveillance infrastructure with minimal oversight. It showed that “publicly available” data does not mean “freely usable for any purpose” and that aggregation of public data can create privacy harms far exceeding any individual data point.
The incident accelerated facial recognition regulation worldwide and established that scraping publicly posted photos for biometric surveillance without consent is a violation of privacy rights in most major jurisdictions.