abusesaffiliationarrow-downarrow-leftarrow-rightarrow-upattack-typeblueskyburgerchevron-downchevron-leftchevron-rightchevron-upClock iconclosedeletedevelopment-povertydiscriminationdollardownloademailenvironmentexternal-linkfacebookfilterflaggenderglobeglobegroupshealthC4067174-3DD9-4B9E-AD64-284FDAAE6338@1xinformation-outlineinformationinstagraminvestment-trade-globalisationissueslabourlanguagesShapeCombined Shapeline, chart, up, arrow, graphLinkedInlocationmap-pinminusnewsorganisationotheroverviewpluspreviewArtboard 185profilerefreshIconnewssearchsecurityPathStock downStock steadyStock uptagticktooltiptriangletwitteruniversalitywebwhatsappxIcons / Social / YouTube

Cette page n’est pas disponible en Français et est affichée en English

Article

16 déc 2021

Auteur:
Natasha Lomas, TechCrunch

France: Facial recognition firm Clearview AI breaks EU data privacy rules, says data protection watchdog

Controversial facial recognition company, Clearview AI, which has amassed a database of some 10 billion images by scraping selfies off the Internet so it can sell an identity-matching service to law enforcement, has been hit with another order to delete people’s data.

France’s privacy watchdog said today that Clearview has breached Europe’s General Data Protection Regulation (GDPR).

In an announcement of the breach finding, the CNIL also gives Clearview formal notice to stop its “unlawful processing” and says it must delete user data within two months...

The US company does not have an established base in the EU — meaning its business is open to regulatory action across the EU, by any of the bloc’s data protection supervisors. So while the CNIL’s order only applies to data it holds on people from French territories — which the CNIL estimates covers “several” tens of millions of Internet users — more such orders are likely from other EU agencies...

This year Clearview’s service has already been ruled in breach of privacy rules in Canada, Australia and the UK (which, post-Brexit, sits outside the EU but retains the GDPR in national law for now) — where it’s facing a possible fine and was also ordered to delete user data last month.

... In a statement attributed to CEO and founder Hoan Ton-That, Clearview sought to suggest the company is not subject to the GDPR — although the regulation is extraterritorial in scope, meaning it is applicable and (at least in theory) enforceable outside the EU’s borders in instances when EU people’s data has been processed in violation of the rules.

... “Clearview AI does not have a place of business in France or the EU, it does not have any customers in France or the EU, and does not undertake any activities that would otherwise mean it is subject to the GDPR.

“I grew up in Australia and have long viewed France as a world capitol of beauty and excellence. I have deep respect for the country and its people. I created the consequential facial recognition technology known the world over with the purpose of helping to make communities safer and assisting law enforcement in solving heinous crimes against children, seniors and other victims of unscrupulous acts. We only collect public data from the open internet and comply with all standards of privacy and law. I am heartbroken by the misinterpretation by some in France, where we do no business, of Clearview AI’s technology to society. My intentions and those of my company have always been to help communities and their people to live better, safer lives.”