{
  "total": 33,
  "limit": 50,
  "offset": 0,
  "records": [
    {
      "fields": {
        "action_type": "fine",
        "amount": 2520000,
        "currency": "EUR",
        "data_subject_matter": "biometric",
        "date_decided": "2021-07-27",
        "legal_basis": "GDPR Art 5(1)(c), 9(1), 22 and 35; procedure PS/00120/2021",
        "name": "AEPD v. Mercadona (2021)",
        "note": "amount is the 2,520,000 EUR actually charged after a 20 percent reduction for voluntary payment; the sanction as first proposed was 3,150,000 EUR. The url follows the AEPD's standard resolution path for PS/00120/2021 and was NOT opened in this round, so it should be checked before publication; the three cited sources all state the figures and the file number. appealed is null: not established.",
        "orgs": [
          "Agencia Espanola de Proteccion de Datos",
          "Mercadona S.A."
        ],
        "regulator": "Agencia Espanola de Proteccion de Datos",
        "regulator_country": "ES",
        "target": "Mercadona S.A.",
        "url": "https://www.aepd.es/documento/ps-00120-2021.pdf",
        "what_it_concerned": "Mercadona ran facial recognition in 48 supermarkets to spot people under restraining orders, which processed the biometric data of every shopper who walked in."
      },
      "id": "enforcement:aepd-v-mercadona-2021",
      "name": "AEPD v. Mercadona (2021)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Agencia Espanola de Proteccion de Datos": [
            "regulator"
          ],
          "Mercadona S.A.": [
            "target"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "aepd.es"
        ],
        "source_urls": [
          "https://www.aepd.es/documento/ps-00120-2021.pdf"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 1,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.aepd.es/documento/ps-00120-2021.pdf"
    },
    {
      "fields": {
        "action_type": "ban",
        "appealed": true,
        "data_subject_matter": "biometric",
        "date_decided": "2024-03-04",
        "legal_basis": "GDPR Art 66 urgency procedure; precautionary measure ahead of any finding",
        "name": "AEPD v. Tools for Humanity (Worldcoin) (2024)",
        "note": "The AEPD's specific press release URL for this measure was not resolved in this round, so url points at the AEPD press index and must be replaced with the exact note before publication. Communicated to the company on 2024-03-04 with 72 hours to comply, so collection was unlawful from 2024-03-07. The measure ran three months, extendable to six. amount is null: precautionary, no penalty.",
        "orgs": [
          "Agencia Espanola de Proteccion de Datos",
          "Tools for Humanity Corporation"
        ],
        "outcome_on_appeal": "Worldcoin sought an injunction against the suspension and failed; the measure stood. Reported around 2024-03-11.",
        "regulator": "Agencia Espanola de Proteccion de Datos",
        "regulator_country": "ES",
        "target": "Tools for Humanity Corporation",
        "url": "https://www.aepd.es/prensa-y-comunicacion/notas-de-prensa",
        "what_it_concerned": "Worldcoin paid people in Spain to have their irises scanned by its Orb, and the AEPD ordered it to stop collecting and to block what it already had."
      },
      "id": "enforcement:aepd-v-tools-for-humanity-worldcoin-2024",
      "name": "AEPD v. Tools for Humanity (Worldcoin) (2024)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Agencia Espanola de Proteccion de Datos": [
            "regulator"
          ],
          "Tools for Humanity Corporation": [
            "target"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "aepd.es"
        ],
        "source_urls": [
          "https://www.aepd.es/prensa-y-comunicacion/notas-de-prensa"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 0.8,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.aepd.es/prensa-y-comunicacion/notas-de-prensa"
    },
    {
      "fields": {
        "action_type": "order",
        "appealed": true,
        "data_subject_matter": "personal_data",
        "date_decided": "2024-07-02",
        "legal_basis": "LGPD (Lei 13.709/2018) preventive measure; inadequate legal basis, transparency failures, and children's data without safeguards",
        "name": "ANPD v. Meta (2024)",
        "note": "amount is null: no penalty was charged. The order carried a threatened daily fine of 50,000 BRL for non compliance, which is a contingent figure and is not recorded as an amount because it was never triggered. The clearest example in this table of a regulator stopping AI training outright at zero monetary cost.",
        "orgs": [
          "Autoridade Nacional de Protecao de Dados",
          "Meta Platforms"
        ],
        "outcome_on_appeal": "Meta asked the ANPD to reconsider and the ANPD kept the preventive measure in place. Meta later met the ANPD's conditions and was allowed to resume AI training in Brazil with restrictions.",
        "regulator": "Autoridade Nacional de Protecao de Dados",
        "regulator_country": "BR",
        "target": "Meta Platforms",
        "url": "https://www.gov.br/anpd/pt-br/assuntos/noticias/anpd-determina-suspensao-cautelar-do-tratamento-de-dados-pessoais-para-treinamento-da-ia-da-meta",
        "what_it_concerned": "Meta's new privacy policy let it train AI on the public posts of Facebook, Instagram and Messenger users in Brazil, and the ANPD suspended that immediately."
      },
      "id": "enforcement:anpd-v-meta-2024",
      "name": "ANPD v. Meta (2024)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Autoridade Nacional de Protecao de Dados": [
            "regulator"
          ],
          "Meta Platforms": [
            "target"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "gov.br"
        ],
        "source_urls": [
          "https://www.gov.br/anpd/pt-br/assuntos/noticias/anpd-determina-suspensao-cautelar-do-tratamento-de-dados-pessoais-para-treinamento-da-ia-da-meta"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 0.8,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.gov.br/anpd/pt-br/assuntos/noticias/anpd-determina-suspensao-cautelar-do-tratamento-de-dados-pessoais-para-treinamento-da-ia-da-meta"
    },
    {
      "fields": {
        "action_type": "fine",
        "amount": 30500000,
        "currency": "EUR",
        "data_subject_matter": "biometric",
        "date_decided": "2024-05-16",
        "legal_basis": "GDPR Art 5, 6, 9, 12, 14, 15 and 27",
        "name": "Autoriteit Persoonsgegevens v. Clearview AI (2024)",
        "note": "The AP decision is dated 16 May 2024 and was published on 3 September 2024; the decision date is used here. On top of the 30,500,000 EUR fine the AP attached orders subject to a penalty of up to 5,100,000 EUR more, which is not added to amount because it is contingent. The AP also warned that using Clearview's service is itself unlawful. The largest single fine in this table.",
        "orgs": [
          "Autoriteit Persoonsgegevens",
          "Clearview AI Inc."
        ],
        "regulator": "Autoriteit Persoonsgegevens",
        "regulator_country": "NL",
        "target": "Clearview AI Inc.",
        "url": "https://www.autoriteitpersoonsgegevens.nl/en/documents/decision-fine-clearview-ai",
        "what_it_concerned": "Clearview built a database of billions of scraped face photos, converted each to a biometric code, and included Dutch residents without any lawful basis."
      },
      "id": "enforcement:autoriteit-persoonsgegevens-v-clearview-ai-2024",
      "name": "Autoriteit Persoonsgegevens v. Clearview AI (2024)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Autoriteit Persoonsgegevens": [
            "regulator"
          ],
          "Clearview AI Inc.": [
            "target"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "autoriteitpersoonsgegevens.nl"
        ],
        "source_urls": [
          "https://www.autoriteitpersoonsgegevens.nl/en/documents/decision-fine-clearview-ai"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 1,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.autoriteitpersoonsgegevens.nl/en/documents/decision-fine-clearview-ai"
    },
    {
      "fields": {
        "action_type": "order",
        "appealed": true,
        "data_subject_matter": "biometric",
        "date_decided": "2024-12-19",
        "legal_basis": "GDPR; deletion order requiring a compliant erasure procedure for iris derived biometric data",
        "name": "BayLDA v. Tools for Humanity (World) (2024)",
        "note": "Read from BayLDA's own English press release. amount is null: the remedy is deletion and consent, not money. BayLDA was the GDPR lead supervisory authority for World in the EU, so this is the EU-wide decision on the iris programme.",
        "orgs": [
          "Bayerisches Landesamt fuer Datenschutzaufsicht",
          "Tools for Humanity GmbH",
          "Worldcoin"
        ],
        "outcome_on_appeal": "World appealed immediately, arguing the findings concern practices replaced in 2024. No appeal outcome established as of 2026-09-18.",
        "regulator": "Bayerisches Landesamt fuer Datenschutzaufsicht",
        "regulator_country": "DE",
        "target": [
          "Tools for Humanity GmbH",
          "Worldcoin"
        ],
        "url": "https://www.lda.bayern.de/media/pm/pm2024_08_en.pdf",
        "what_it_concerned": "World's iris scanning enrolment stored iris codes centrally without a sufficient legal basis, and the Bavarian regulator ordered a GDPR compliant deletion procedure within a month."
      },
      "id": "enforcement:baylda-v-tools-for-humanity-world-2024",
      "name": "BayLDA v. Tools for Humanity (World) (2024)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Bayerisches Landesamt fuer Datenschutzaufsicht": [
            "regulator"
          ],
          "Tools for Humanity GmbH": [
            "target"
          ],
          "Worldcoin": [
            "target"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "lda.bayern.de"
        ],
        "source_urls": [
          "https://www.lda.bayern.de/media/pm/pm2024_08_en.pdf"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 0.8,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.lda.bayern.de/media/pm/pm2024_08_en.pdf"
    },
    {
      "fields": {
        "action_type": "fine",
        "amount": 20000000,
        "currency": "EUR",
        "data_subject_matter": "biometric",
        "date_decided": "2022-10-17",
        "legal_basis": "GDPR Art 6, 12, 15 and 17 (deliberation SAN-2022-019)",
        "name": "CNIL v. Clearview AI (2022)",
        "note": "The CNIL's own news page for this sanction now returns 'Cet article n'est plus disponible', so the EDPB national-news mirror is used as the url. The decision reference SAN-2022-019 of 17 October 2022 is consistent across every source read. The injunction carried a periodic penalty of 100,000 EUR per day of delay, which is a separate action (see the 2023 row).",
        "orgs": [
          "Commission nationale de l'informatique et des libertes",
          "Clearview AI Inc."
        ],
        "regulator": "Commission nationale de l'informatique et des libertes",
        "regulator_country": "FR",
        "target": "Clearview AI Inc.",
        "url": "https://edpb.europa.eu/news/national-news/2022/french-sa-fines-clearview-ai-eur-20-million_nl",
        "what_it_concerned": "Clearview collected face images of people in France without consent and failed to answer access and erasure requests, after ignoring a 2021 formal notice."
      },
      "id": "enforcement:cnil-v-clearview-ai-2022",
      "name": "CNIL v. Clearview AI (2022)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Clearview AI Inc.": [
            "target"
          ],
          "Commission nationale de l'informatique et des libertes": [
            "regulator"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "edpb.europa.eu"
        ],
        "source_urls": [
          "https://edpb.europa.eu/news/national-news/2022/french-sa-fines-clearview-ai-eur-20-million_nl"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 1,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://edpb.europa.eu/news/national-news/2022/french-sa-fines-clearview-ai-eur-20-million_nl"
    },
    {
      "fields": {
        "action_type": "fine",
        "amount": 5200000,
        "currency": "EUR",
        "data_subject_matter": "biometric",
        "date_decided": "2023-04-13",
        "legal_basis": "GDPR Art 58(2); liquidation of the astreinte attached to deliberation SAN-2022-019",
        "name": "CNIL v. Clearview AI, penalty payment liquidation (2023)",
        "note": "This is a second, separate charge on top of the 20,000,000 EUR fine, computed as 100,000 EUR per day over the 52 days from 19 December 2022 to 9 February 2023. The CNIL announced it on 10 May 2023; the decision date used here is 13 April 2023 as reported. Whether any of it has been collected is not established: Clearview has not engaged with EU regulators.",
        "orgs": [
          "Commission nationale de l'informatique et des libertes",
          "Clearview AI Inc."
        ],
        "regulator": "Commission nationale de l'informatique et des libertes",
        "regulator_country": "FR",
        "target": "Clearview AI Inc.",
        "url": "https://www.edpb.europa.eu/news/national-news/2023/facial-recognition-french-sa-imposes-penalty-payment-clearview-ai_en",
        "what_it_concerned": "Clearview produced no proof it had complied with the CNIL's 2022 injunction, so the CNIL cashed in the daily penalty it had attached to that order."
      },
      "id": "enforcement:cnil-v-clearview-ai-penalty-payment-liquidation-2023",
      "name": "CNIL v. Clearview AI, penalty payment liquidation (2023)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Clearview AI Inc.": [
            "target"
          ],
          "Commission nationale de l'informatique et des libertes": [
            "regulator"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "edpb.europa.eu"
        ],
        "source_urls": [
          "https://www.edpb.europa.eu/news/national-news/2023/facial-recognition-french-sa-imposes-penalty-payment-clearview-ai_en"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 1,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.edpb.europa.eu/news/national-news/2023/facial-recognition-french-sa-imposes-penalty-payment-clearview-ai_en"
    },
    {
      "fields": {
        "action_type": "undertaking",
        "appealed": false,
        "data_subject_matter": "personal_data",
        "date_decided": "2024-08-08",
        "legal_basis": "Section 134 of the Irish Data Protection Act 2018, urgent High Court application; GDPR Art 66 style urgency over training on EU users' posts",
        "name": "DPC Ireland v. X (Grok) (2024)",
        "note": "amount is null and that is the point: the first time any GDPR lead supervisory authority used urgent court powers over AI training, and it cost the company nothing in money. The first use of section 134 by the DPC.",
        "orgs": [
          "Data Protection Commission",
          "X Internet Unlimited Company"
        ],
        "outcome_on_appeal": "Not appealed. The proceedings were struck out on 2024-09-04 after X agreed to make the undertaking permanent.",
        "regulator": "Data Protection Commission",
        "regulator_country": "IE",
        "target": "X Internet Unlimited Company",
        "url": "https://www.dataprotection.ie/en/news-media/press-releases/dpc-welcomes-xs-agreement-suspend-its-processing-personal-data-purpose-training-ai-tool-grok",
        "what_it_concerned": "X was training its Grok model on the public posts of EU and EEA users, and agreed in court to suspend that use of data collected between 7 May and 1 August 2024."
      },
      "id": "enforcement:dpc-ireland-v-x-grok-2024",
      "name": "DPC Ireland v. X (Grok) (2024)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Data Protection Commission": [
            "regulator"
          ],
          "X Internet Unlimited Company": [
            "target"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "dataprotection.ie"
        ],
        "source_urls": [
          "https://www.dataprotection.ie/en/news-media/press-releases/dpc-welcomes-xs-agreement-suspend-its-processing-personal-data-purpose-training-ai-tool-grok"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 0.8,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.dataprotection.ie/en/news-media/press-releases/dpc-welcomes-xs-agreement-suspend-its-processing-personal-data-purpose-training-ai-tool-grok"
    },
    {
      "fields": {
        "action_type": "settlement",
        "amount": 25000000,
        "appealed": false,
        "currency": "USD",
        "data_subject_matter": "biometric",
        "date_decided": "2023-05-31",
        "legal_basis": "COPPA Rule (16 CFR Part 312) and Section 5 of the FTC Act; FTC matter 192-3128",
        "name": "FTC and DOJ v. Amazon (Alexa) (2023)",
        "note": "The order also bars Amazon from using the unlawfully retained data to train its algorithms and requires deletion of inactive child accounts, voice recordings and geolocation data. date_decided is the date the FTC and DOJ filed and announced; the court entered the order later in 2023. Classified as biometric because the subject matter is voiceprints and speech data used to improve a speech model.",
        "orgs": [
          "Federal Trade Commission",
          "with the Department of Justice",
          "Amazon.com Inc."
        ],
        "outcome_on_appeal": "Settled by stipulated federal court order; not contested.",
        "regulator": [
          "Federal Trade Commission",
          "with the Department of Justice"
        ],
        "regulator_country": "US",
        "target": "Amazon.com Inc.",
        "url": "https://www.ftc.gov/legal-library/browse/cases-proceedings/192-3128-amazoncom-alexa-us-v",
        "what_it_concerned": "Amazon kept children's Alexa voice recordings indefinitely after parents asked for deletion, and the retained recordings were valuable for training Alexa to understand children."
      },
      "id": "enforcement:ftc-and-doj-v-amazon-alexa-2023",
      "name": "FTC and DOJ v. Amazon (Alexa) (2023)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Amazon.com Inc.": [
            "target"
          ],
          "Federal Trade Commission": [
            "regulator"
          ],
          "with the Department of Justice": [
            "regulator"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "ftc.gov"
        ],
        "source_urls": [
          "https://www.ftc.gov/legal-library/browse/cases-proceedings/192-3128-amazoncom-alexa-us-v"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 1,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.ftc.gov/legal-library/browse/cases-proceedings/192-3128-amazoncom-alexa-us-v"
    },
    {
      "fields": {
        "action_type": "settlement",
        "amount": 1500000,
        "appealed": false,
        "currency": "USD",
        "data_subject_matter": "personal_data",
        "date_decided": "2022-03-03",
        "legal_basis": "COPPA Rule (16 CFR Part 312); FTC matter 1923228",
        "name": "FTC and DOJ v. WW International and Kurbo (2022)",
        "note": "Included because the order requires destruction of any algorithms or affected work product derived from the unlawfully collected children's data, which is the rare case where model deletion is ordered alongside a stated civil penalty. date_decided is the court approval date; the FTC announced it on 2022-03-04.",
        "orgs": [
          "Federal Trade Commission",
          "with the Department of Justice",
          "WW International Inc.",
          "Kurbo Inc."
        ],
        "outcome_on_appeal": "Settled by stipulated order approved by the court on 2022-03-03.",
        "regulator": [
          "Federal Trade Commission",
          "with the Department of Justice"
        ],
        "regulator_country": "US",
        "target": [
          "WW International Inc.",
          "Kurbo Inc."
        ],
        "url": "https://www.ftc.gov/legal-library/browse/cases-proceedings/1923228-weight-watchersww",
        "what_it_concerned": "A weight loss app marketed to children as young as eight collected their personal and health data without parental consent, and the models built from it had to be destroyed."
      },
      "id": "enforcement:ftc-and-doj-v-ww-international-and-kurbo-2022",
      "name": "FTC and DOJ v. WW International and Kurbo (2022)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Federal Trade Commission": [
            "regulator"
          ],
          "Kurbo Inc.": [
            "target"
          ],
          "WW International Inc.": [
            "target"
          ],
          "with the Department of Justice": [
            "regulator"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "ftc.gov"
        ],
        "source_urls": [
          "https://www.ftc.gov/legal-library/browse/cases-proceedings/1923228-weight-watchersww"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 1,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.ftc.gov/legal-library/browse/cases-proceedings/1923228-weight-watchersww"
    },
    {
      "fields": {
        "action_type": "order",
        "appealed": false,
        "data_subject_matter": "biometric",
        "date_decided": "2021-01-11",
        "legal_basis": "Section 5 of the FTC Act, deception; FTC matter 192-3172",
        "name": "FTC in re Everalbum (Paravision) (2021)",
        "note": "amount is null. This is the origin of algorithmic disgorgement: the order requires deletion of the models and algorithms developed from users' photos and videos, not just the photos. The price of unlawfully trained models here was the models themselves, with no cash attached.",
        "orgs": [
          "Federal Trade Commission",
          "Everalbum Inc."
        ],
        "outcome_on_appeal": "Consent order; finalised by the Commission on 2021-05-06.",
        "regulator": "Federal Trade Commission",
        "regulator_country": "US",
        "target": "Everalbum Inc.",
        "url": "https://www.ftc.gov/legal-library/browse/cases-proceedings/192-3172-everalbum-inc-matter",
        "what_it_concerned": "Everalbum turned on face recognition by default in its Ever photo app, kept deactivated users' photos, and used those photos to build face recognition models it sold to businesses."
      },
      "id": "enforcement:ftc-in-re-everalbum-paravision-2021",
      "name": "FTC in re Everalbum (Paravision) (2021)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Everalbum Inc.": [
            "target"
          ],
          "Federal Trade Commission": [
            "regulator"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "ftc.gov"
        ],
        "source_urls": [
          "https://www.ftc.gov/legal-library/browse/cases-proceedings/192-3172-everalbum-inc-matter"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 0.8,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.ftc.gov/legal-library/browse/cases-proceedings/192-3172-everalbum-inc-matter"
    },
    {
      "fields": {
        "action_type": "settlement",
        "amount": 5800000,
        "appealed": false,
        "currency": "USD",
        "data_subject_matter": "personal_data",
        "date_decided": "2023-05-31",
        "legal_basis": "Section 5 of the FTC Act; FTC matter 2023113",
        "name": "FTC v. Ring (2023)",
        "note": "The 5,800,000 USD is monetary relief paid out as consumer refunds, not a civil penalty. The order requires Ring to delete data products including models and algorithms derived from the videos it unlawfully reviewed, which is the algorithmic disgorgement remedy attached to a price.",
        "orgs": [
          "Federal Trade Commission",
          "Ring LLC"
        ],
        "outcome_on_appeal": "Settled by stipulated order; not contested. Refunds to customers began in April 2024.",
        "regulator": "Federal Trade Commission",
        "regulator_country": "US",
        "target": "Ring LLC",
        "url": "https://www.ftc.gov/legal-library/browse/cases-proceedings/2023113-ring-llc",
        "what_it_concerned": "Ring let employees and hundreds of contractors in Ukraine watch and download customers' home camera video, including to train algorithms, on a check the box consent."
      },
      "id": "enforcement:ftc-v-ring-2023",
      "name": "FTC v. Ring (2023)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Federal Trade Commission": [
            "regulator"
          ],
          "Ring LLC": [
            "target"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "ftc.gov"
        ],
        "source_urls": [
          "https://www.ftc.gov/legal-library/browse/cases-proceedings/2023113-ring-llc"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 1,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.ftc.gov/legal-library/browse/cases-proceedings/2023113-ring-llc"
    },
    {
      "fields": {
        "action_type": "order",
        "appealed": false,
        "data_subject_matter": "biometric",
        "date_decided": "2024-03-08",
        "legal_basis": "Section 5 of the FTC Act, unfairness; FTC matter 2023190, docket 2:23-cv-5023 (E.D. Pa.)",
        "name": "FTC v. Rite Aid (2023)",
        "note": "amount is null: no monetary penalty, which matters because this is the FTC's flagship AI enforcement action. The remedy is a five year ban on facial recognition for security or surveillance plus an algorithmic fairness and safeguards programme. Announced 2023-12-19; the stipulated order was entered 2024-03-08 and that later date is used as date_decided.",
        "orgs": [
          "Federal Trade Commission",
          "Rite Aid Corporation"
        ],
        "outcome_on_appeal": "Settled; the stipulated order was entered by the court.",
        "regulator": "Federal Trade Commission",
        "regulator_country": "US",
        "target": "Rite Aid Corporation",
        "url": "https://www.ftc.gov/legal-library/browse/cases-proceedings/2023190-rite-aid-corporation-ftc-v",
        "what_it_concerned": "Rite Aid ran facial recognition in hundreds of stores to flag shoppers as security risks, with no reasonable safeguards, and the system misidentified people."
      },
      "id": "enforcement:ftc-v-rite-aid-2023",
      "name": "FTC v. Rite Aid (2023)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Federal Trade Commission": [
            "regulator"
          ],
          "Rite Aid Corporation": [
            "target"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "ftc.gov"
        ],
        "source_urls": [
          "https://www.ftc.gov/legal-library/browse/cases-proceedings/2023190-rite-aid-corporation-ftc-v"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 0.8,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.ftc.gov/legal-library/browse/cases-proceedings/2023190-rite-aid-corporation-ftc-v"
    },
    {
      "fields": {
        "action_type": "fine",
        "amount": 20000000,
        "currency": "EUR",
        "data_subject_matter": "biometric",
        "date_decided": "2022-02-10",
        "legal_basis": "GDPR Art 5, 6, 9, 12, 14, 15 and 27",
        "name": "Garante v. Clearview AI (2022)",
        "note": "The cited Garante page is the 9 March 2022 press release; the provvedimento itself is dated 10 February 2022 and that is the date recorded here. The article list is read from the press release summary and is not a line by line citation of the decision. appealed is null: no appeal outcome was established from a source in this round.",
        "orgs": [
          "Garante per la protezione dei dati personali",
          "Clearview AI Inc."
        ],
        "regulator": "Garante per la protezione dei dati personali",
        "regulator_country": "IT",
        "target": "Clearview AI Inc.",
        "url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9751323",
        "what_it_concerned": "Clearview scraped face images from the open web into a biometric search database that could be used to track people in Italy, with no legal basis."
      },
      "id": "enforcement:garante-v-clearview-ai-2022",
      "name": "Garante v. Clearview AI (2022)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Clearview AI Inc.": [
            "target"
          ],
          "Garante per la protezione dei dati personali": [
            "regulator"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "garanteprivacy.it"
        ],
        "source_urls": [
          "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9751323"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 1,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9751323"
    },
    {
      "fields": {
        "action_type": "ban",
        "data_subject_matter": "personal_data",
        "date_decided": "2025-10-01",
        "legal_basis": "GDPR Art 58(2)(f) urgent provisional limitation on processing of data of people in Italy",
        "name": "Garante v. Clothoff (2025)",
        "note": "amount is null: a provisional limitation, not a fine. Included because it is a regulator acting on the output side of a generative model that uses a real person's likeness as its input, which is the same consent question as training. Marginal on the training data filter and flagged as such.",
        "orgs": [
          "Garante per la protezione dei dati personali",
          "Clothoff"
        ],
        "regulator": "Garante per la protezione dei dati personali",
        "regulator_country": "IT",
        "target": "Clothoff",
        "url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10174164",
        "what_it_concerned": "A generative app that turns a clothed photo of a real person into a fake nude, with no consent check on the person depicted and no working age check."
      },
      "id": "enforcement:garante-v-clothoff-2025",
      "name": "Garante v. Clothoff (2025)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Clothoff": [
            "target"
          ],
          "Garante per la protezione dei dati personali": [
            "regulator"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "garanteprivacy.it"
        ],
        "source_urls": [
          "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10174164"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 0.8,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10174164"
    },
    {
      "fields": {
        "action_type": "ban",
        "data_subject_matter": "personal_data",
        "date_decided": "2025-01-30",
        "legal_basis": "GDPR Art 58(2)(f) urgent limitation on processing; the companies' reply was found to breach Art 31 duty to cooperate",
        "name": "Garante v. DeepSeek (2025)",
        "note": "amount is null because an urgent limitation order carries no penalty. The app was removed from Italian stores. The companies asserted that they do not operate in Italy and that EU law does not apply to them. An investigation was opened at the same time and no fine had been imposed as of 2026-09-18.",
        "orgs": [
          "Garante per la protezione dei dati personali",
          "Hangzhou DeepSeek Artificial Intelligence and Beijing DeepSeek Artificial Intelligence"
        ],
        "regulator": "Garante per la protezione dei dati personali",
        "regulator_country": "IT",
        "target": "Hangzhou DeepSeek Artificial Intelligence and Beijing DeepSeek Artificial Intelligence",
        "url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10098477",
        "what_it_concerned": "The Chinese operators of the DeepSeek chatbot would not explain what data they process or on what basis, and published an English only privacy notice, so Italian users' data was blocked."
      },
      "id": "enforcement:garante-v-deepseek-2025",
      "name": "Garante v. DeepSeek (2025)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Garante per la protezione dei dati personali": [
            "regulator"
          ],
          "Hangzhou DeepSeek Artificial Intelligence and Beijing DeepSeek Artificial Intelligence": [
            "target"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "garanteprivacy.it"
        ],
        "source_urls": [
          "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10098477"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 0.8,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10098477"
    },
    {
      "fields": {
        "action_type": "fine",
        "amount": 5000000,
        "currency": "EUR",
        "data_subject_matter": "personal_data",
        "date_decided": "2025-04-10",
        "legal_basis": "GDPR; no legal basis identified for the processing, inadequate privacy notice, no age verification",
        "name": "Garante v. Luka Inc. (Replika) (2025)",
        "note": "Read from the Garante's own press release of 19 May 2025 announcing the 10 April 2025 provvedimento. The fine is for data handling, not for training: alongside it the Garante opened a separate investigation into how the underlying generative model was developed and trained, which had not concluded as of 2026-09-18. The press release does not itemise the GDPR articles, so legal_basis is a description rather than a citation.",
        "orgs": [
          "Garante per la protezione dei dati personali",
          "Luka Inc."
        ],
        "regulator": "Garante per la protezione dei dati personali",
        "regulator_country": "IT",
        "target": "Luka Inc.",
        "url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10132048",
        "what_it_concerned": "The company behind the Replika companion chatbot had no stated legal basis for its data processing and no working age check, despite claiming to exclude minors."
      },
      "id": "enforcement:garante-v-luka-inc-replika-2025",
      "name": "Garante v. Luka Inc. (Replika) (2025)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Garante per la protezione dei dati personali": [
            "regulator"
          ],
          "Luka Inc.": [
            "target"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "garanteprivacy.it"
        ],
        "source_urls": [
          "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10132048"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 1,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10132048"
    },
    {
      "fields": {
        "action_type": "fine",
        "amount": 15000000,
        "appealed": true,
        "currency": "EUR",
        "data_subject_matter": "personal_data",
        "date_decided": "2024-11-02",
        "legal_basis": "GDPR, including the legal basis for training (Art 6), transparency (Art 5(1)(a), 12, 13) and breach notification (Art 33); provvedimento n. 755",
        "name": "Garante v. OpenAI (2024)",
        "note": "The single most important row in this table and the reason the type is worth carrying with a denominator. Decision n. 755 of 2 November 2024, announced 20 December 2024; the decision date is used. It also ordered a six month public information campaign on radio, TV, press and internet, which has no cash value here. amount is the sum imposed, not the sum collected: nothing was collected, because the fine was annulled on a competence point in March 2026. As of 2026-09-18 this is the only final GDPR enforcement decision in Europe over a generative AI provider's training data, and it no longer stands.",
        "orgs": [
          "Garante per la protezione dei dati personali",
          "OpenAI"
        ],
        "outcome_on_appeal": "Suspended by the Tribunale di Roma in March 2025, then annulled in full by that court on 2026-03-18 (ruling no. 4153/2026) on the ground that once OpenAI established its Irish establishment on 2024-02-15 the one-stop-shop gave the lead authority competence. The merits of the GDPR findings were never examined. The Garante removed the decision from its own site because of that ruling.",
        "regulator": "Garante per la protezione dei dati personali",
        "regulator_country": "IT",
        "target": "OpenAI",
        "url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10085432",
        "what_it_concerned": "OpenAI used personal data to train ChatGPT with no identified legal basis, was not transparent with users, had no age check, and did not notify a March 2023 breach."
      },
      "id": "enforcement:garante-v-openai-2024",
      "name": "Garante v. OpenAI (2024)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Garante per la protezione dei dati personali": [
            "regulator"
          ],
          "OpenAI": [
            "target"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "garanteprivacy.it"
        ],
        "source_urls": [
          "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10085432"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 1,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10085432"
    },
    {
      "fields": {
        "action_type": "fine",
        "amount": 20000000,
        "currency": "EUR",
        "data_subject_matter": "biometric",
        "date_decided": "2022-07-13",
        "legal_basis": "GDPR Art 5(1)(a), 6, 9, 12, 14, 15 and 27 (Decision 35/2022)",
        "name": "Hellenic DPA v. Clearview AI (2022)",
        "note": "Read directly from the HDPA's own English decision page. Triggered by a complaint filed by Homo Digitalis. The decision also banned collection of Greek residents' data and ordered deletion.",
        "orgs": [
          "Hellenic Data Protection Authority",
          "Clearview AI Inc."
        ],
        "regulator": "Hellenic Data Protection Authority",
        "regulator_country": "GR",
        "target": "Clearview AI Inc.",
        "url": "https://www.dpa.gr/en/en/enimerwtiko/prakseisArxis/imposition-fine-clearview-ai-inc",
        "what_it_concerned": "Clearview processed the face images of people in Greece for its recognition service and did not answer a data subject's access request."
      },
      "id": "enforcement:hellenic-dpa-v-clearview-ai-2022",
      "name": "Hellenic DPA v. Clearview AI (2022)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Clearview AI Inc.": [
            "target"
          ],
          "Hellenic Data Protection Authority": [
            "regulator"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "dpa.gr"
        ],
        "source_urls": [
          "https://www.dpa.gr/en/en/enimerwtiko/prakseisArxis/imposition-fine-clearview-ai-inc"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 1,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.dpa.gr/en/en/enimerwtiko/prakseisArxis/imposition-fine-clearview-ai-inc"
    },
    {
      "fields": {
        "action_type": "fine",
        "amount": 7552800,
        "appealed": true,
        "currency": "GBP",
        "data_subject_matter": "scraping",
        "date_decided": "2022-05-18",
        "legal_basis": "UK GDPR Art 5(1)(a), 6, 9, 14, 15 and 17; monetary penalty notice plus enforcement notice",
        "name": "ICO v. Clearview AI (2022)",
        "note": "The ICO's own case page for the 2022 monetary penalty notice 404s now; the ICO page cited is its 2025 statement on the Upper Tribunal judgment, and the ICO hosts the judgment PDF itself. The penalty was expressed as 7,552,800 GBP, stated by the ICO as equivalent to 9 million EUR at the 25 April 2022 rate. No currency conversion is applied here. The money has not been shown to have been paid; the notices were void between October 2023 and October 2025.",
        "orgs": [
          "Information Commissioner's Office",
          "Clearview AI Inc."
        ],
        "outcome_on_appeal": "First-tier Tribunal held on 2023-10-17 that the processing fell outside UK GDPR, which voided the notices. The Upper Tribunal (Administrative Appeals Chamber) overturned that on 2025-10-07, NCN [2025] UKUT 319 (AAC), restoring the ICO's jurisdiction. Clearview was granted permission to appeal to the Court of Appeal; no Court of Appeal outcome established as of 2026-09-18.",
        "regulator": "Information Commissioner's Office",
        "regulator_country": "GB",
        "target": "Clearview AI Inc.",
        "url": "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/10/uk-upper-tribunal-hands-down-judgment-on-clearview-ai-inc",
        "what_it_concerned": "Clearview scraped images of UK residents into a facial recognition database sold to law enforcement customers, which the ICO treated as monitoring UK behaviour."
      },
      "id": "enforcement:ico-v-clearview-ai-2022",
      "name": "ICO v. Clearview AI (2022)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Clearview AI Inc.": [
            "target"
          ],
          "Information Commissioner's Office": [
            "regulator"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "ico.org.uk"
        ],
        "source_urls": [
          "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/10/uk-upper-tribunal-hands-down-judgment-on-clearview-ai-inc"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 1,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/10/uk-upper-tribunal-hands-down-judgment-on-clearview-ai-inc"
    },
    {
      "fields": {
        "action_type": "order",
        "data_subject_matter": "biometric",
        "date_decided": "2024-02-19",
        "legal_basis": "UK GDPR Art 5(1)(a), 6 and 9; nine enforcement notices",
        "name": "ICO v. Serco Leisure (2024)",
        "note": "amount is null: nine enforcement notices to stop processing and destroy the biometric data within three months, no fine. Included as the clearest employer side biometric AI action with a regulator's own notice PDF behind it.",
        "orgs": [
          "Information Commissioner's Office",
          "Serco Leisure Operating Limited",
          "Serco Jersey and seven associated community trusts"
        ],
        "regulator": "Information Commissioner's Office",
        "regulator_country": "GB",
        "target": [
          "Serco Leisure Operating Limited",
          "Serco Jersey and seven associated community trusts"
        ],
        "url": "https://ico.org.uk/action-weve-taken/enforcement/2024/02/serco-leisure-operating-limited-and-relevant-associated-trusts",
        "what_it_concerned": "More than 2,000 staff at 38 leisure centres had to scan their faces and fingers to clock in and get paid, with no alternative offered, so consent could not be free."
      },
      "id": "enforcement:ico-v-serco-leisure-2024",
      "name": "ICO v. Serco Leisure (2024)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Information Commissioner's Office": [
            "regulator"
          ],
          "Serco Jersey and seven associated community trusts": [
            "target"
          ],
          "Serco Leisure Operating Limited": [
            "target"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "ico.org.uk"
        ],
        "source_urls": [
          "https://ico.org.uk/action-weve-taken/enforcement/2024/02/serco-leisure-operating-limited-and-relevant-associated-trusts"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 0.8,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://ico.org.uk/action-weve-taken/enforcement/2024/02/serco-leisure-operating-limited-and-relevant-associated-trusts"
    },
    {
      "fields": {
        "action_type": "fine",
        "amount": 2500000,
        "currency": "SEK",
        "data_subject_matter": "biometric",
        "date_decided": "2021-02-11",
        "legal_basis": "Swedish Criminal Data Act (Brottsdatalagen), the national implementation of the Law Enforcement Directive (EU) 2016/680",
        "name": "IMY v. Swedish Police Authority over Clearview AI (2021)",
        "note": "Read from IMY's own English page. This is the customer side of the Clearview story rather than the vendor side: a public buyer charged for using the tool. IMY also ordered the police to train staff, inform affected people and get the transferred data erased by 15 September 2021.",
        "orgs": [
          "Integritetsskyddsmyndigheten",
          "Swedish Police Authority"
        ],
        "regulator": "Integritetsskyddsmyndigheten",
        "regulator_country": "SE",
        "target": "Swedish Police Authority",
        "url": "https://www.imy.se/en/news/police-unlawfully-used-facial-recognition-app",
        "what_it_concerned": "Police staff ran face searches through Clearview AI without authorisation and with no data protection impact assessment, which unlawfully processed biometric data."
      },
      "id": "enforcement:imy-v-swedish-police-authority-over-clearview-ai-2021",
      "name": "IMY v. Swedish Police Authority over Clearview AI (2021)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Integritetsskyddsmyndigheten": [
            "regulator"
          ],
          "Swedish Police Authority": [
            "target"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "imy.se"
        ],
        "source_urls": [
          "https://www.imy.se/en/news/police-unlawfully-used-facial-recognition-app"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 1,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.imy.se/en/news/police-unlawfully-used-facial-recognition-app"
    },
    {
      "fields": {
        "action_type": "fine",
        "amount": 250000000,
        "currency": "HUF",
        "data_subject_matter": "biometric",
        "date_decided": "2022-02-08",
        "legal_basis": "GDPR Art 5, 6, 12, 13, 15, 21 and 22; decision NAIH-85-3/2022",
        "name": "NAIH v. Budapest Bank (2022)",
        "note": "url is not the regulator's own page: neither naih.hu nor the GDPRhub entry for NAIH-85-3/2022 was reachable in this round (GDPRhub returned an access control page), so the CMS legal update is used. The decision number and the 250,000,000 HUF figure are consistent across all three sources. The article list is drawn from those summaries, not from the decision text. The largest AI specific fine by a DPA outside the Clearview cluster. No currency conversion applied.",
        "orgs": [
          "Nemzeti Adatvedelmi es Informacioszabadsag Hatosag",
          "Budapest Bank Zrt."
        ],
        "regulator": "Nemzeti Adatvedelmi es Informacioszabadsag Hatosag",
        "regulator_country": "HU",
        "target": "Budapest Bank Zrt.",
        "url": "https://cms.law/en/hun/legal-updates/Hungary-data-authority-issues-heavy-fine-for-the-use-of-AI-voice-recording-analysis",
        "what_it_concerned": "The bank ran AI speech analytics over recorded customer service calls to score callers' emotional state, with no valid legal basis, no balancing test and no way to object."
      },
      "id": "enforcement:naih-v-budapest-bank-2022",
      "name": "NAIH v. Budapest Bank (2022)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Budapest Bank Zrt.": [
            "target"
          ],
          "Nemzeti Adatvedelmi es Informacioszabadsag Hatosag": [
            "regulator"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "cms.law"
        ],
        "source_urls": [
          "https://cms.law/en/hun/legal-updates/Hungary-data-authority-issues-heavy-fine-for-the-use-of-AI-voice-recording-analysis"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 1,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://cms.law/en/hun/legal-updates/Hungary-data-authority-issues-heavy-fine-for-the-use-of-AI-voice-recording-analysis"
    },
    {
      "fields": {
        "action_type": "order",
        "appealed": true,
        "data_subject_matter": "biometric",
        "date_decided": "2024-11-19",
        "legal_basis": "Privacy Act 1988 (Cth), Australian Privacy Principles 1.2, 3.3 and 5",
        "name": "OAIC v. Bunnings (2024)",
        "note": "amount is null: an OAIC determination carries declarations and orders, not a civil penalty. date_decided is the determination date as announced; the exact day should be checked against the determination text before publication.",
        "orgs": [
          "Office of the Australian Information Commissioner",
          "Bunnings Group Limited"
        ],
        "outcome_on_appeal": "Bunnings sought review. In February 2026 the Administrative Review Tribunal affirmed aspects of the determination and confirmed a high bar for retail facial recognition in Australia.",
        "regulator": "Office of the Australian Information Commissioner",
        "regulator_country": "AU",
        "target": "Bunnings Group Limited",
        "url": "https://www.oaic.gov.au/news/media-centre/bunnings-breached-australians-privacy-with-facial-recognition-tool",
        "what_it_concerned": "Bunnings ran facial recognition on every customer entering 62 stores between 2018 and 2021, collecting sensitive biometric information without consent or notice."
      },
      "id": "enforcement:oaic-v-bunnings-2024",
      "name": "OAIC v. Bunnings (2024)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Bunnings Group Limited": [
            "target"
          ],
          "Office of the Australian Information Commissioner": [
            "regulator"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "oaic.gov.au"
        ],
        "source_urls": [
          "https://www.oaic.gov.au/news/media-centre/bunnings-breached-australians-privacy-with-facial-recognition-tool"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 0.8,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.oaic.gov.au/news/media-centre/bunnings-breached-australians-privacy-with-facial-recognition-tool"
    },
    {
      "fields": {
        "action_type": "order",
        "data_subject_matter": "scraping",
        "date_decided": "2021-10-14",
        "legal_basis": "Privacy Act 1988 (Cth), Australian Privacy Principles 1.2, 3.3, 3.5, 5 and 10.2; determination [2021] AICmr 54",
        "name": "OAIC v. Clearview AI (2021)",
        "note": "amount is null: the determination ordered Clearview to stop collecting and to destroy existing Australian images and templates, with no civil penalty. Determination dated 14 October 2021, announced 3 November 2021. A joint investigation with the UK ICO. appealed is null: Clearview lodged an AAT review that sources in this round did not confirm the outcome of.",
        "orgs": [
          "Office of the Australian Information Commissioner",
          "Clearview AI Inc."
        ],
        "regulator": "Office of the Australian Information Commissioner",
        "regulator_country": "AU",
        "target": "Clearview AI Inc.",
        "url": "https://www.oaic.gov.au/news/media-centre/clearview-ai-breached-australians-privacy",
        "what_it_concerned": "Clearview collected Australians' sensitive biometric information by scraping the web without consent and disclosed it through its face matching tool."
      },
      "id": "enforcement:oaic-v-clearview-ai-2021",
      "name": "OAIC v. Clearview AI (2021)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Clearview AI Inc.": [
            "target"
          ],
          "Office of the Australian Information Commissioner": [
            "regulator"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "oaic.gov.au"
        ],
        "source_urls": [
          "https://www.oaic.gov.au/news/media-centre/clearview-ai-breached-australians-privacy"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 0.8,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.oaic.gov.au/news/media-centre/clearview-ai-breached-australians-privacy"
    },
    {
      "fields": {
        "action_type": "order",
        "appealed": true,
        "data_subject_matter": "biometric",
        "date_decided": "2025-08-01",
        "legal_basis": "Privacy Act 1988 (Cth), Australian Privacy Principles on collection of sensitive information and notice",
        "name": "OAIC v. Kmart Australia (2025)",
        "note": "date_decided is set to 2025-08-01 as a month level placeholder: sources in this round give August 2025 without a day, and the exact determination date is not established. amount is null: no civil penalty. Lowest confidence row in this set on the date field.",
        "orgs": [
          "Office of the Australian Information Commissioner",
          "Kmart Australia Limited"
        ],
        "outcome_on_appeal": "Under review at the Administrative Review Tribunal, with hearings listed for early 2027. No outcome as of 2026-09-18.",
        "regulator": "Office of the Australian Information Commissioner",
        "regulator_country": "AU",
        "target": "Kmart Australia Limited",
        "url": "https://www.oaic.gov.au/news/media-centre/18-kmarts-use-of-facial-recognition-to-tackle-refund-fraud-unlawful,-privacy-commissioner-finds",
        "what_it_concerned": "Kmart used facial recognition in 28 stores between June 2020 and July 2022 to detect refund fraud, collecting shoppers' biometric information unlawfully."
      },
      "id": "enforcement:oaic-v-kmart-australia-2025",
      "name": "OAIC v. Kmart Australia (2025)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Kmart Australia Limited": [
            "target"
          ],
          "Office of the Australian Information Commissioner": [
            "regulator"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "oaic.gov.au"
        ],
        "source_urls": [
          "https://www.oaic.gov.au/news/media-centre/18-kmarts-use-of-facial-recognition-to-tackle-refund-fraud-unlawful,-privacy-commissioner-finds"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 0.8,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.oaic.gov.au/news/media-centre/18-kmarts-use-of-facial-recognition-to-tackle-refund-fraud-unlawful,-privacy-commissioner-finds"
    },
    {
      "fields": {
        "action_type": "order",
        "data_subject_matter": "scraping",
        "date_decided": "2021-02-02",
        "legal_basis": "PIPEDA (federal) and the Quebec, British Columbia and Alberta private sector privacy acts; PIPEDA Findings #2021-001",
        "name": "OPC Canada and provincial commissioners v. Clearview AI (2021)",
        "note": "amount is null because none of these authorities had the power to fine: the OPC can only make findings and recommendations. Clearview refused the recommendations, so on 14 December 2021 the three provincial commissioners issued binding orders to stop collecting and to delete. Finding date 2 February 2021, announced 3 February 2021.",
        "orgs": [
          "Office of the Privacy Commissioner of Canada",
          "with CAI Quebec",
          "OIPC British Columbia and OIPC Alberta",
          "Clearview AI Inc."
        ],
        "regulator": [
          "Office of the Privacy Commissioner of Canada",
          "with CAI Quebec",
          "OIPC British Columbia and OIPC Alberta"
        ],
        "regulator_country": "CA",
        "target": "Clearview AI Inc.",
        "url": "https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2021/pipeda-2021-001",
        "what_it_concerned": "Four Canadian authorities jointly found that scraping billions of images into a face search tool was mass surveillance and could not be made lawful by consent."
      },
      "id": "enforcement:opc-canada-and-provincial-commissioners-v-clearview-ai-2021",
      "name": "OPC Canada and provincial commissioners v. Clearview AI (2021)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Clearview AI Inc.": [
            "target"
          ],
          "OIPC British Columbia and OIPC Alberta": [
            "regulator"
          ],
          "Office of the Privacy Commissioner of Canada": [
            "regulator"
          ],
          "with CAI Quebec": [
            "regulator"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "priv.gc.ca"
        ],
        "source_urls": [
          "https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2021/pipeda-2021-001"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 0.8,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2021/pipeda-2021-001"
    },
    {
      "fields": {
        "action_type": "order",
        "data_subject_matter": "personal_data",
        "date_decided": "2025-04-24",
        "legal_basis": "Personal Information Protection Act (PIPA); cross-border transfer without consent or disclosure. Corrective recommendation that becomes a corrective order if accepted",
        "name": "PIPC v. DeepSeek (2025)",
        "note": "amount is null: no penalty surcharge was reported, only a corrective recommendation including immediate destruction of the prompt data sent to the ByteDance affiliate Volcano. The PIPC had already suspended DeepSeek downloads in Korea on 2025-02-17. url is the PIPC notice index because the specific release was not reachable.",
        "orgs": [
          "Personal Information Protection Commission",
          "Hangzhou DeepSeek Artificial Intelligence"
        ],
        "regulator": "Personal Information Protection Commission",
        "regulator_country": "KR",
        "target": "Hangzhou DeepSeek Artificial Intelligence",
        "url": "https://www.pipc.go.kr/eng/user/ltn/new/noticeList.do",
        "what_it_concerned": "DeepSeek sent Korean users' device data and the text they typed into AI prompts to three companies in China and one in the US without consent, affecting up to 1.5 million users."
      },
      "id": "enforcement:pipc-v-deepseek-2025",
      "name": "PIPC v. DeepSeek (2025)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Hangzhou DeepSeek Artificial Intelligence": [
            "target"
          ],
          "Personal Information Protection Commission": [
            "regulator"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "pipc.go.kr"
        ],
        "source_urls": [
          "https://www.pipc.go.kr/eng/user/ltn/new/noticeList.do"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 0.8,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.pipc.go.kr/eng/user/ltn/new/noticeList.do"
    },
    {
      "fields": {
        "action_type": "fine",
        "amount": 103300000,
        "currency": "KRW",
        "data_subject_matter": "personal_data",
        "date_decided": "2021-04-28",
        "legal_basis": "Personal Information Protection Act (PIPA); eight violations found, including use beyond the purpose of collection and processing without consent",
        "name": "PIPC v. ScatterLab (Iruda) (2021)",
        "note": "The oldest clean case anywhere of a regulator charging a company for the training set itself rather than for a downstream use, and the first time PIPA was applied to an AI system. 103,300,000 KRW is the combined penalty surcharge and fine. The PIPC's own English release was not reachable in this round, so url is the PIPC notice index and the specific article citations are not established.",
        "orgs": [
          "Personal Information Protection Commission",
          "ScatterLab Inc."
        ],
        "regulator": "Personal Information Protection Commission",
        "regulator_country": "KR",
        "target": "ScatterLab Inc.",
        "url": "https://www.pipc.go.kr/eng/user/ltn/new/noticeList.do",
        "what_it_concerned": "ScatterLab trained the Iruda chatbot on about 9.4 billion real KakaoTalk messages from 600,000 people collected through two unrelated apps, without consent and without deleting or anonymising them."
      },
      "id": "enforcement:pipc-v-scatterlab-iruda-2021",
      "name": "PIPC v. ScatterLab (Iruda) (2021)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Personal Information Protection Commission": [
            "regulator"
          ],
          "ScatterLab Inc.": [
            "target"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "pipc.go.kr"
        ],
        "source_urls": [
          "https://www.pipc.go.kr/eng/user/ltn/new/noticeList.do"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 1,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.pipc.go.kr/eng/user/ltn/new/noticeList.do"
    },
    {
      "fields": {
        "action_type": "fine",
        "amount": 1140000000,
        "currency": "KRW",
        "data_subject_matter": "biometric",
        "date_decided": "2024-09-25",
        "legal_basis": "Personal Information Protection Act (PIPA); notice and consent for sensitive data, cross-border transfer disclosure, and age verification",
        "name": "PIPC v. Worldcoin Foundation and Tools for Humanity (2024)",
        "note": "The PIPC's English press list was reachable but the specific release was not, so url is the PIPC notice index and should be replaced before publication. The amount needs care: sources report a combined 1.14 billion KRW while also splitting it as about 725 million KRW (Worldcoin Foundation) and about 379 million KRW (Tools for Humanity), which sums to 1.104 billion. The combined figure is recorded and the discrepancy is stated rather than resolved. No currency conversion applied.",
        "orgs": [
          "Personal Information Protection Commission",
          "Worldcoin Foundation and Tools for Humanity"
        ],
        "regulator": "Personal Information Protection Commission",
        "regulator_country": "KR",
        "target": "Worldcoin Foundation and Tools for Humanity",
        "url": "https://www.pipc.go.kr/eng/user/ltn/new/noticeList.do",
        "what_it_concerned": "The World project collected iris data from about 30,000 people in Korea and sent it abroad without saying why it was collected or where it was going."
      },
      "id": "enforcement:pipc-v-worldcoin-foundation-and-tools-for-humanity-2024",
      "name": "PIPC v. Worldcoin Foundation and Tools for Humanity (2024)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Personal Information Protection Commission": [
            "regulator"
          ],
          "Worldcoin Foundation and Tools for Humanity": [
            "target"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "pipc.go.kr"
        ],
        "source_urls": [
          "https://www.pipc.go.kr/eng/user/ltn/new/noticeList.do"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 1,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.pipc.go.kr/eng/user/ltn/new/noticeList.do"
    },
    {
      "fields": {
        "action_type": "reprimand",
        "appealed": false,
        "data_subject_matter": "personal_data",
        "date_decided": "2023-06-02",
        "legal_basis": "Act on the Protection of Personal Information (Act No. 57 of 2003), Art 147 administrative guidance",
        "name": "PPC Japan administrative guidance to OpenAI (2023)",
        "note": "url is not the regulator's own page: the PPC's site did not surface an English page for this guidance in this round, so a Japanese law firm's contemporaneous note carrying the Art 147 citation is used, with press corroboration. amount is null: Art 147 guidance carries no penalty. The first regulatory action anywhere aimed squarely at what a generative model may ingest for training.",
        "orgs": [
          "Personal Information Protection Commission",
          "OpenAI"
        ],
        "outcome_on_appeal": "Administrative guidance is not an appealable order.",
        "regulator": "Personal Information Protection Commission",
        "regulator_country": "JP",
        "target": "OpenAI",
        "url": "https://www.aplawjapan.com/en/publications/20230608",
        "what_it_concerned": "The PPC told OpenAI not to collect special care required (sensitive) personal information for machine learning without consent, and to delete any it does collect before it reaches a training set."
      },
      "id": "enforcement:ppc-japan-administrative-guidance-to-openai-2023",
      "name": "PPC Japan administrative guidance to OpenAI (2023)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "OpenAI": [
            "target"
          ],
          "Personal Information Protection Commission": [
            "regulator"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "aplawjapan.com"
        ],
        "source_urls": [
          "https://www.aplawjapan.com/en/publications/20230608"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 0.8,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.aplawjapan.com/en/publications/20230608"
    },
    {
      "fields": {
        "action_type": "settlement",
        "amount": 1375000000,
        "appealed": false,
        "currency": "USD",
        "data_subject_matter": "biometric",
        "date_decided": "2025-05-09",
        "legal_basis": "Texas Capture or Use of Biometric Identifier Act (CUBI), Tex. Bus. & Com. Code ch. 503, and the Texas Deceptive Trade Practices Act",
        "name": "Texas Attorney General v. Google (2025)",
        "note": "The settlement in principle was announced 2025-05-09 and covers geolocation and incognito claims as well as biometrics, so the amount is not attributable to the biometric count alone. That is stated rather than apportioned; no split is published. Second largest amount in this table.",
        "orgs": [
          "Office of the Attorney General of Texas",
          "Google LLC"
        ],
        "outcome_on_appeal": "Settled; finalised in a later announcement by the same office.",
        "regulator": "Office of the Attorney General of Texas",
        "regulator_country": "US",
        "target": "Google LLC",
        "url": "https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-secures-historic-1375-billion-settlement-google-related-texans-data",
        "what_it_concerned": "Google collected voiceprints and face geometry from Texans through Google Photos, Google Assistant and Nest Hub Max without the consent the state biometric law requires."
      },
      "id": "enforcement:texas-attorney-general-v-google-2025",
      "name": "Texas Attorney General v. Google (2025)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Google LLC": [
            "target"
          ],
          "Office of the Attorney General of Texas": [
            "regulator"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "texasattorneygeneral.gov"
        ],
        "source_urls": [
          "https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-secures-historic-1375-billion-settlement-google-related-texans-data"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 1,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-secures-historic-1375-billion-settlement-google-related-texans-data"
    },
    {
      "fields": {
        "action_type": "settlement",
        "amount": 1400000000,
        "appealed": false,
        "currency": "USD",
        "data_subject_matter": "biometric",
        "date_decided": "2024-07-30",
        "legal_basis": "Texas Capture or Use of Biometric Identifier Act (CUBI), Tex. Bus. & Com. Code ch. 503, and the Texas Deceptive Trade Practices Act",
        "name": "Texas Attorney General v. Meta (2024)",
        "note": "The largest amount in this table by two orders of magnitude, and it comes from a US state attorney general under a state biometric statute, not from a data protection authority. Payable as roughly 250 million USD a year over five years. First case ever brought under CUBI.",
        "orgs": [
          "Office of the Attorney General of Texas",
          "Meta Platforms Inc."
        ],
        "outcome_on_appeal": "Settled before trial; no appeal.",
        "regulator": "Office of the Attorney General of Texas",
        "regulator_country": "US",
        "target": "Meta Platforms Inc.",
        "url": "https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-secures-14-billion-settlement-meta-over-its-unauthorized-capture",
        "what_it_concerned": "Meta ran facial recognition over virtually every face in photos uploaded to Facebook for more than a decade, capturing face geometry from Texans without the notice and consent CUBI requires."
      },
      "id": "enforcement:texas-attorney-general-v-meta-2024",
      "name": "Texas Attorney General v. Meta (2024)",
      "notes": {
        "_date_decided_precision": "day",
        "_org_roles": {
          "Meta Platforms Inc.": [
            "target"
          ],
          "Office of the Attorney General of Texas": [
            "regulator"
          ]
        }
      },
      "provenance": {
        "consent_license": "third-party-derived",
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18",
        "method": "refinery-explore",
        "source_hosts": [
          "texasattorneygeneral.gov"
        ],
        "source_urls": [
          "https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-secures-14-billion-settlement-meta-over-its-unauthorized-capture"
        ]
      },
      "quality": {
        "age_days": 0,
        "completeness": 1,
        "confidence": "medium",
        "corroborated": false,
        "flags": [
          "single-source"
        ],
        "grade": "B",
        "hosts": 1,
        "independent_hosts": 1,
        "sources": 1,
        "stale": false,
        "stale_after_days": 120
      },
      "type": "enforcement",
      "url": "https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-secures-14-billion-settlement-meta-over-its-unauthorized-capture"
    }
  ],
  "_meta": {
    "source": "Blomega Data Refinery",
    "url": "https://data.blomega.com",
    "publisher": "Blomega",
    "publisher_url": "https://blomegalab.com",
    "wikidata": "Q141048865",
    "license": "CC BY 4.0",
    "license_url": "https://creativecommons.org/licenses/by/4.0/",
    "cite_as": "Blomega Data Refinery (https://data.blomega.com), CC BY 4.0. Cite the registry and the record id.",
    "attribution_required": true
  }
}
