Prefer to listen? Click play for AI narration

While headlines focus on the EU AI Act and its staggered 2026–2027 deadlines, a quieter story is unfolding: European data protection authorities aren't waiting around. They're using a law that's been fully enforceable since 2018 — GDPR — to punish exactly the kind of AI mistakes that small and mid-sized businesses could just as easily make.

Three recent cases show what that enforcement actually looks like in practice, and none of them required the AI Act to exist.

Clearview AI — €30.5 Million for Scraping Faces Without Asking

In September 2024, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) fined the US facial-recognition company Clearview AI €30.5 million — with the threat of a further €5.1 million if it didn't stop. Clearview had built its business by scraping billions of photos from the public web and turning them into biometric "faceprints" sold to law enforcement and other clients.

The Dutch regulator didn't accept Clearview's defense that it only served non-EU customers. It found the company had processed the biometric data of European residents on a "massive scale," without a legal basis, without informing people their photos had been collected, and without a way for those people to object or request deletion.

The lesson isn't really about facial recognition specifically — it's about the underlying assumption Clearview made: that if data is publicly visible online, it's fair game to scrape and reuse. GDPR has never agreed with that assumption, and regulators are now actively testing AI companies against it.

A German Fintech — €492,000 for Letting the Algorithm Decide Alone

In 2025, Hamburg's data protection authority (HmbBfDI) fined a financial services provider €492,000 after its automated system rejected credit card applications — including from applicants with demonstrably good creditworthiness — without any human review. When rejected customers asked why, the company couldn't give them a meaningful explanation.

That combination triggered two separate GDPR failures: a breach of Article 22, which gives people the right not to be subject to purely automated decisions with significant effects on them, and a breach of Articles 13–15, which require companies to explain, in real terms, how an automated decision was reached. Notably, the fine could have been higher — Hamburg's regulator explicitly reduced it because the company cooperated and fixed the process once flagged.

The takeaway for any business using AI to screen, score, or filter customers — credit checks, job applicants, insurance quotes, even automated fraud flags — is that "the algorithm decided" is not a legal shield. If the decision has a real effect on someone, a human needs to be able to step in, and the business needs to be able to explain the why.

Replika — €5 Million for Skipping the Basics

In April 2025, Italy's Garante fined Luka Inc., maker of the AI companion app Replika, €5 million. The core problems were unglamorous: the company couldn't point to a valid legal basis for processing users' data, its privacy notices didn't clearly explain what was happening with that data, and — despite technically barring minors from the app — it had no real mechanism to verify anyone's age.

This case is a useful reminder that most GDPR enforcement against AI products isn't about exotic algorithmic harms. It's about the same fundamentals that apply to any website or app: know your legal basis, write privacy notices people can actually understand, and don't claim age restrictions you have no way of enforcing.

€30.5M
Clearview AI fine, Netherlands, Sept 2024
€492K
German fintech fine, Hamburg, 2025
€5M
Replika fine, Italy, April 2025
0
New AI-specific laws needed for any of these three fines

What These Three Cases Have in Common

Different countries, different sectors, different technologies — but the pattern is consistent:

💬
GDPRGard Product
Don't let "the AI decided" become your compliance defense

GDPRChat is an AI customer chat widget built with Article 7 consent gates and automatic data deletion — compliance built into the architecture, not bolted on after a regulator starts asking questions.

See GDPRChat →

What This Means If You're a Smaller Business

It's tempting to read these as "big tech" stories — Clearview, a German bank, a Silicon Valley chatbot maker. But the obligations that tripped them up apply at any size. If your business uses an AI chatbot, a scoring tool, a recommendation engine, or anything that processes customer data, the same questions apply to you:

  1. Do you have a documented legal basis for what the AI does with customer data?
  2. Can you explain, in plain language, what happens to that data and for how long?
  3. If the AI makes a decision that affects a customer, is there a real human who can review it?
  4. If your product isn't meant for minors, do you actually have a way to check that — or just a checkbox?

GDPR enforcement against AI isn't waiting for new legislation to catch up. It's already here, and it's already writing checks. Building compliance in from the start — rather than retrofitting it after a regulator asks questions — is a lot cheaper than the alternative.

Book a free consultation with GDPRGard →

Sources

Share this article

Also read:

⚠️ This article is for informational purposes only and does not constitute legal advice. For complex compliance situations, consult a qualified data protection professional. GDPR and EU AI Act requirements are subject to ongoing regulatory guidance — verify current obligations with your legal adviser.