Corporations

Clearview AI: The FTC Order That Found the Facial Recognition Company Built Its Database by Scraping Billions of Photos Without Consent

The FTC found Clearview AI had built its facial recognition database by scraping billions of photos from social media and websites without user consent, and had deceptively restricted individuals' legal rights to access and delete their biometric data — imposing restrictions on how the company can use the data and requiring deletion of data from non-law enforcement sources.

Clearview AI Inc., the controversial facial recognition company that built the world's largest facial recognition database by scraping billions of photographs from social media platforms, news websites, and other internet sources without users' knowledge or consent, reached a Federal Trade Commission order resolving charges that the company had violated the FTC Act through deceptive practices related to individuals' rights to access and delete their biometric data — and prohibiting the company from selling its facial recognition database to most commercial entities while imposing restrictions on its law enforcement uses.DOCUMENTED

The Clearview AI case became one of the most significant privacy enforcement actions involving biometric data in U.S. regulatory history — not because Clearview was the first company to use facial recognition, but because the scale of its photo scraping operation, its business model of selling access to the resulting database to law enforcement and commercial clients, and its practices around individuals' data rights brought together multiple dimensions of the emerging biometric privacy regulatory landscape in a single enforcement action.

Key facts
  • Clearview AI scraped more than three billion photographs from the internet without user consent to build its facial recognition database.
  • The company sold access to the database to law enforcement agencies, private investigators, and commercial clients.
  • The FTC found Clearview had deceptively restricted individuals' legal rights to access and delete their biometric data.
  • The order prohibited Clearview from selling its database to most commercial clients and imposed restrictions on law enforcement sales.
  • Clearview faced parallel enforcement in multiple states and countries, including FTC coordination with state attorneys general.

How Clearview Built Its Database

Clearview AI's technology is built on a database of billions of photographs scraped from social media platforms including Facebook, Instagram, and LinkedIn, from news websites, from government records, and from virtually any publicly accessible source on the internet. The photographs were processed through machine learning algorithms to extract facial recognition data — mathematical representations of each face's unique features that can be used to identify the same person across different photographs. The resulting database, when queried with a photograph of an unknown person's face, could return matching images of the same person from across the scraped sources, along with URLs indicating where those images had been found.REVIEWED

The photo scraping that built this database was conducted without the knowledge or consent of the individuals pictured in the scraped photographs. Social media platforms prohibit scraping in their terms of service, and most of the individuals whose photographs were scraped had no knowledge that their images were being used to build a commercial facial recognition product. The database effectively converted the billions of photographs that individuals had posted on the internet for personal and social purposes into biometric data assets held by a private company and sold to law enforcement and commercial clients — a transformation of the photographs' purpose that the individuals who created them had not authorized and could not have anticipated.DOCUMENTED

The Deceptive Practices Finding

The FTC's enforcement action against Clearview focused specifically on deceptive practices the company had engaged in related to individuals' rights to access and delete their biometric data. Some U.S. states — including Illinois, under the Biometric Information Privacy Act — provide individuals with rights to access, correct, and delete biometric data held about them. Clearview had represented to individuals seeking to exercise these rights that it would honor requests, while implementing processes that the FTC found effectively frustrated individuals' ability to exercise their rights — for example, by requiring individuals to take additional steps that the company used to justify not honoring deletion requests, or by providing misleading information about the status of data deletion requests.REVIEWED

The deceptive practices charge framed Clearview's conduct in terms that allowed the FTC to act under its general unfair and deceptive practices authority even in the absence of a comprehensive federal biometric privacy law — a strategic choice that allowed the agency to address one dimension of Clearview's conduct within its existing authority while parallel state enforcement and litigation addressed other dimensions. The Illinois Biometric Information Privacy Act litigation, in particular, resulted in a separate settlement that addressed the photo scraping itself under state biometric privacy law.

Taking a person's photograph from the internet and turning it into a biometric data point in a commercial database is not a privacy-neutral act just because the photo was publicly posted. The person who shared a photo on Facebook did not consent to becoming a searchable entry in a law enforcement facial recognition tool — and that matters.

The Commercial Client Prohibition

One of the most significant elements of the FTC order was the prohibition on Clearview selling access to its facial recognition database to most commercial clients — limiting the company's market primarily to law enforcement and government agencies. This restriction addressed the concern that commercial availability of a facial recognition database covering billions of people could enable uses — by employers tracking workers, private investigators surveilling individuals, debt collectors locating people, and others — that would not be subject to the legal constraints applicable to law enforcement use and that could produce significant privacy harms across a broad range of commercial contexts.DOCUMENTED

The commercial client prohibition represented a structural remedy that went beyond the deceptive practices that served as the formal basis for the FTC's jurisdiction — effectively limiting Clearview's business model based on the FTC's assessment of the privacy risks posed by commercial availability of the database. This type of forward-looking business restriction, while unusual for the FTC in privacy cases, reflected the agency's recognition that the deceptive practices finding provided a basis for ordering relief that addressed the broader harm the company's practices had created, not merely the specific deceptive conduct itself.

Law Enforcement Use and Accountability

The Clearview FTC order's treatment of law enforcement use reflected the more complex policy and constitutional landscape surrounding government use of facial recognition technology. Law enforcement agencies across the United States had become significant Clearview customers, using the technology to identify individuals from photographs obtained during investigations — a use that has proven both effective in solving crimes and controversial in terms of accuracy, racial bias, and civil liberties implications. The order's restrictions on law enforcement use were more limited than its commercial prohibitions, recognizing the law enforcement mission while imposing requirements on how Clearview managed and disclosed its law enforcement relationships.REVIEWED

The accuracy and bias concerns around facial recognition technology — particularly the documented higher error rates for darker-skinned individuals and women that have been found in independent studies of facial recognition systems — add a dimension to the Clearview case that goes beyond the privacy practices addressed by the FTC order. Law enforcement use of facial recognition technology that is less accurate for certain demographic groups creates risks of wrongful identification and investigation that the FTC's commercial privacy framework does not directly address. Congressional legislation and state regulatory initiatives focused specifically on law enforcement facial recognition use have been proposed as complementary policy responses to the issues that enforcement actions against companies like Clearview have illuminated.

Implications for the Biometric Privacy Landscape

The Clearview AI FTC order contributed to an evolving biometric privacy regulatory landscape in which the absence of a comprehensive federal biometric privacy law has been partially filled by state legislation — most significantly Illinois's BIPA, which has generated substantial litigation — and by the FTC's exercise of its general deceptive practices authority to address specific biometric data handling violations. Companies that collect, process, or sell biometric data — including facial recognition data derived from photographs — should understand that the current regulatory environment, while not as comprehensive as consumer credit or healthcare data protection frameworks, includes meaningful legal risk through state biometric privacy statutes, FTC enforcement authority, and the prospect of federal legislation. The Clearview case established that the FTC views deceptive practices in biometric data rights as within its enforcement mandate, and the scale and profile of the action signal the agency's seriousness about this space as biometric technology becomes more pervasive in commercial and government applications.

Have documents relevant to this story? Reach us through our tips channel.

Every Watchdog Journal investigation is built on primary documents and classified under our evidence standard.

Browse All Investigations →