7 ms·
Clearview AI faces $45.6M fine in the Netherlands for 'illegal database of faces
- ryanisnan 2y agoIf identification of dutch citizens are a part of the product for services rendered by Clearview AI, they should be punished severely for this. Same goes with any country, or person, who doesn't want to be a part of their scheme.
- mhitza 2y agoSince they don't operate directly in the EU, there is not much else they can do aside from collaborating with other countries DPAs to ban any EU company from integrating with them (per the article currently only companies in the Netherlands are banned). Even the fine itself is a bit problematic because it looks like unenforceable as they don't operate in the EU thus not subject to EU law. However if it were to be discovered that the user images where not only retrieved by scrapping publicly available information, but involved data brokerage or other forms of personal information selling all those involved throughout that chain could be fined.
- Teever 2y agoThey can also arrest the employees of the company who is breaking their laws the next time they step foot in the EU.
- ronsor 2y agoThis is not a practice you want to normalize.
- gjsman-1000 2y agoWhy not? Sends a strong message; and also forces employees to think about what they are doing instead of passing the buck. This is also not like some stupid patent dispute or DMA compliance argument. These employees are directly responsible for stockpiling personal identities of millions of people for the express purposes of making the surveillance efforts of their government easier. That's a very political action, which is directly aggressive against a country's citizens, and they should feel that.
- kiratp 2y agoAre you sure you haven't violated the laws of any of the other 190+ countries? sure enough to risk taking another vacation?
- gjsman-1000 2y agoDepends on where I'm going. If I go to Saudi Arabia after having called for their leader to be executed on X for his treatment of women, yeah, probably not a good idea to go. If I go to Iran after saying Khamenei deserves a rocket to his mansion, yeah, probably not a good idea to go. If I go to Europe after having run a multi-million dollar scheme affecting European countries by white-labelling services from North Korea (legal in Brazil), and I'm a Brazilian citizen and know Brazil almost never extradites, yeah, probably not a good idea to go. If I go to the US with my two 12 year old brides from Niger, yeah, probably not a good idea to go.
- Mordisquitos 2y agoIn addition to the examples you mention, if you become involved in doping at an international competition in which US American athletes were competing, it's probably not a good idea to travel there: https://en.wikipedia.org/wiki/Rodchenkov_Anti-Doping_Act_of_2019 https://en.wikipedia.org/wiki/Rodchenkov_Anti-Doping_Act_of_...
- Teever 2y agoIs it really so unreasonable to expect that countries prosecute people who commit crimes against their citizens with expectation of impunity the next time they visit their country? You're proposing an alternative where people can just commit crimes with no recourse from the victims simply because a border exists somewhere and they commit the crimes on one side of the border. Would you expect it to be reasonable for Canadian citizens to be shooting at Americans on the border and it unreasonable for American authorities to arrest them if they came to America?
- ronsor 2y ago
- Mordisquitos 2y agoNeither do you want to normalise organisations violating the rights of a given state's citizens with impunity because they operate from outside of their jurisdiction and refuse to engage. If there's no other recourse than to arrest the members of the (for all intents and purposes) criminal organisation if they step foot in the affected state then so be it.
- btbuildem 2y agoA little bit of consequences for the C-suites would go a long way, actually.
- sensanaty 2y agoI think you'll find most people would be more than happy to see a few scummy C-suites landing behind bars. I certainly welcome it and can't wait for the day when these psychopaths actually get punished for their greedy behaviour.
- CalRobert 2y agoYou're getting downvoted, but it's an interesting idea. Violating the GDPR is illegal. You can break your home country's laws when you go abroad and it's usually OK. You can smoke cannabis when you visit the Netherlands* from Ireland, for instance, and go back home to Ireland without worry. Violating GDPR is illegal. It's acceptable to arrest people who do things that are against the law. And if, say, I write a lambda that runs hourly and violates the GDPR from my home in California, and then take a holiday to the Netherlands while the lambda is still running, should I be immune from arrest? The offense is still ongoing in that instance. If we truly take privacy seriously then this should be treated like a crime. If I had something that scammed people in Europe and then holidayed in Europe I'd expect to risk arrest. Or is that somehow less important than violating people's privacy? * (It's actually technically still illegal but that's a different story). Gedoofd is weird.
- yadaeno 2y agoArresting tourists for crimes they did not commit is hostage taking and could be considered an act of war. The US is willing to prison swap terrorists with Russia, we definitely wouldn’t tolerate some EU country (that we spend billions of dollars defending) arbitrarily arresting tourists so they can hold a foreign company hostage.
- CalRobert 2y agoWhat do you mean "did not commit"? Anyway I think you're right that the US would strongarm EU governments in to getting their way (look at privacy shield, etc.) but I still think "you're allowed to continue breaking our laws that affect people in our country while you visit us because it happens to be running on a computer you left at home" is a weak defence.
- yadaeno 2y agoWe’re talking about xx million dollar dispute between allied countries, it’s not a reasonable method of conflict resolution to start throwing people in cages that work for x company until the EU gets their way. > what do you mean “did not commit” It’s standard around the world that employees are not held personally responsible for the crimes of the corporation they work for. Edit: if we’re talking about an individual US citizen that’s found guilty in the EU, then the EU will go through the extradition process to have them arrested.
- deleted 2y ago[deleted]
- stanleykm 2y ago> Clearview AI does not have a place of business in the Netherlands or the EU, it does not have any customers in the Netherlands or the EU, and does not undertake any activities that would otherwise mean it is subject to the GDPR That’s cute. I wonder where all the faces are coming from.
- exe34 2y agoThe US and UK governments already claim international jurisdiction in some cases - I hope the EU starts doing to protect their citizens against this sort of thing.
- johnchristopher 2y ago‘Furious 7’ Is the Perfect Commentary on the Surveillance State https://www.vice.com/en/article/furious-7-is-the-perfect-commentary-on-the-surveillance-state/ https://www.vice.com/en/article/furious-7-is-the-perfect-com...
- dmitrygr 2y agoI rarely root for EU’s heavy handed approach to tech regulation. But in this case, I am willing to pick up Pom-poms and cheer for them as loud as I am capable of “Go eu go. Bankrupt those bastards and jail them all. Go eu go. Give it to them hard”
- 0cf8612b2e1e 2y agoIn what cases do you not like the EU’s approach? By and large, some good moves happening there. The only negative that really jumps out to me are cookie consent banners, but those are more malicious compliance than the fault of the EU.
- hcfman 2y agoYeah the perception of the EU approach is not bad. Reality… not so much.
- fsndz 2y agoCan't the government already do the same using images from identity cards, passports, etc.? Is the problem mainly because it's a private company doing it? I genuinely want to better understand this issue.
- piva00 2y agoYes, the problem is that a private company doing it against data privacy regulations in the EU; collecting personally identifiable information and biometrics is regulated through the GDPR, the article clearly states the issue: > The Dutch agency said that building the database and insufficiently informing people whose images appear in the database amounted to serious breaches of the European Union's General Data Protection Regulation, or GDPR.
- fsndz 2y agoOkay I get it now, GDPR. But is it bad if it is used to catch criminals ? What's a potential misuse of that technology ? Maybe I watched too much of Person Of Internet...
- arlort 2y ago> What's a potential misuse of that technology ? Off the top of my head it telling that someone is a criminal when they aren't and ruining their lives
- fsndz 2y agoeven without tech, justice system is already ruining people's lives unjustly. so maybe we have to discuss failure rate, processes in place to correctly use the tech, instead of just saying it has to be bad ? the question is will the tech help ruin more people lives that was already the case or not or improve the odds in some cases even
- rsynnott 2y ago> even without tech, justice system is already ruining people's lives unjustly Sure, but as with a lot of this stuff, this allows that to be done _at scale_. "[bad thing] happens anyway" isn't a great argument against "we should ban this thing where [bad thing] is likely to happen at massive frequency".
- briandw 2y agoIf having a facial recognition system of your citizens is immoral, then maybe the Netherlands government shouldn't have one either? Are the facial recognition systems of the Netherlands auditable? How can anyone be certain that they aren't being abused and used for political persecution?
- Anonbrit 2y agoEU has pretty strong controls on government use of facial recognition (multiple police programs shut down etc) and strong whistle-blower protections to allow people to report them
- sensanaty 2y agoI trust the Dutch government infinitely more than any US corporate entity.
- hcfman 2y agoThis is giving a misleading impression. I can see why you are saying it, however it's giving an impression that the Netherlands has high integrity. Read my comments above. The word infinite here is probably a little out of place. But it's a statement of your feelings so it can well be an accurate reflection of them.
- deleted 2y ago[deleted]
- htrp 2y agoFrom the actual article: >[Clearview Chief Legal Officer] Mulcaire said in his statement that Clearview doesn't fall under EU data protection regulations. >"Clearview AI does not have a place of business in the Netherlands or the EU, it does not have any customers in the Netherlands or the EU, and does not undertake any activities that would otherwise mean it is subject to the GDPR," he said. ------------- >The Dutch agency said that building the database and insufficiently informing people whose images appear in the database amounted to serious breaches of the European Union's General Data Protection Regulation, or GDPR. > "Facial recognition is a highly intrusive technology, that you cannot simply unleash on anyone in the world," DPA chairman Aleid Wolfsen said in a statement. > "If there is a photo of you on the Internet — and doesn't that apply to all of us? — then you can end up in the database of Clearview and be tracked. This is not a doom scenario from a scary film. Nor is it something that could only be done in China," he said. ----------------- If you're pulling data from European Citizens from all over the internet, I'd imagine that the EU does get a say (since it's literally data processing of EU citizen data). I'd also expect that the EU could just make one of the other upstream suppliers of Clearview data responsible for enforcement.
- mike_d 2y agoClearview is a perfect example of how to avoid EU-nexus. They don't have any corporate presence, employees, assets, or customers in the EU. They are even careful to only pull photos from US based servers. Because they only do facial matching on photos, they have no idea if someone is or is not an EU citizen. To seek any sort of judgement or criminal charge against them the EU would need to find an applicable law in the US that covers the activity. While some people might be upset because GDPR isn't a stick they can use to beat Clearview with, this legal framework is the same that allows you to post material critical of the Chinese government without facing financial penalties or extradition.
- ryanisnan 2y agoWhy is the burden of proof on the users? Why shouldn't the burden of proof be on Clearview? They should be required to know that a person is in a place they can legally operate before doing so.
- lacker 2y agoI think one day we will look back on this era, and think it is crazy that so much crime was committed in public and caught on video, and yet the government would usually not be able to take any action. They wouldn't be able to figure out who it was, and they wouldn't be able to find the criminal. One day all of these things will be taken for granted because we will capture more and more video of public spaces, and AI facial recognition will be more accurate than human facial recognition.
- deleted 2y ago[deleted]
- svl 2y agoDirect from the source: https://www.autoriteitpersoonsgegevens.nl/en/current/dutch-dpa-imposes-a-fine-on-clearview-because-of-illegal-data-collection-for-facial-recognition https://www.autoriteitpersoonsgegevens.nl/en/current/dutch-d... The full PDF with the investigation results e.a. as sent to clearview: https://www.autoriteitpersoonsgegevens.nl/en/system/files?file=2024-09/Decision%20fines%20and%20orders%20subject%20to%20a%20penalty%20Clearview.pdf https://www.autoriteitpersoonsgegevens.nl/en/system/files?fi...