Clearview AI
bd_e6e013e657c6e949 · schema v1 · pii pii-v1
Full breach record for Clearview AI →Regulator's decision — not a breach notification
This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.
The CNIL (France) issued a investigation regarding Clearview AI. A fine of EUR 20,000,000 was imposed. Outcome: Violation Found. GDPR articles: Article 3(2) GDPR, Article 6 GDPR, Article 12 GDPR, Article 15 GDPR, Article 17 GDPR, Article 32 GDPR, Article 9 GDPR.
P pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Oct 17, 2022
Filed
—
No linked breach filing · watching
Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
If an SEC 8-K, state-AG notice or victim statement lands, DisclosureLens merges it into an incident and links it here.
Source ceiling
- data categories
- cross-border scope
- outcome + articles (decisions)
- discovery date
- affected count
- notification clock
See the underlying breach notice, if filed.