Azimuth Legal
The Information Commissioner v Clearview AI Incorporated [2025] UKUT 319 (AAC) (06 October 2025)
Executive summary
The Upper Tribunal allowed the Information Commissioner’s appeal, held that the First-tier Tribunal had materially erred in law on the material-scope question, and set aside and remitted the case for the First-tier Tribunal to decide the substantive appeal on the basis that the ICO had jurisdiction to issue the enforcement and monetary penalty notices. It held that Clearview’s processing fell within the territorial scope of the GDPR/UK GDPR, and interpreted Article 2(2)(a) and Article 3(2)(b) broadly enough to capture the company’s facial-recognition database operations.
Key points
- Parties: Information Commissioner v Clearview AI Incorporated; Privacy International intervened.
- Holding: appeal allowed; FTT decision set aside and remitted; ICO treated as having jurisdiction to issue the notices.
- Article 2(2)(a): exclusion for activities outside Union law is narrow and does not extend to Clearview’s processing on the Tribunal’s reading.
- Article 3(2)(b): 'behavioural monitoring' is interpreted broadly and can include automated collection, sorting, classification, storing, and profiling.
- Article 3(2): 'related to' is expansive and can cover a controller whose processing is related to monitoring carried out by another controller.
- Context: Clearview’s service was used by clients in national security or criminal law enforcement; the decision addresses data processing in that setting, not sanctions enforcement directly.
Why it matters
The decision strengthens UK regulatory reach over a foreign technology company whose service supports national-security and law-enforcement use cases, reducing the space for offshore firms to argue they are outside UK/EU data-protection jurisdiction. For sanctions and sovereign-risk analysis, it signals a willingness to regulate cross-border digital services tied to state-security functions, even where the provider is outside the UK.
Implications
Compliance teams for foreign AI, surveillance, and facial-recognition vendors should assume UK GDPR exposure where UK data subjects are processed and the service is linked to monitoring or profiling, including through another controller’s use. Litigation strategy for jurisdictional challenges will need to confront the Tribunal’s narrow reading of Article 2(2)(a) and its broad territorial-scope analysis, while enforcement authorities gain stronger footing to pursue monetary penalties against offshore operators.
- Parties: Information Commissioner v Clearview AI Incorporated; Privacy International intervened.
- Holding: appeal allowed; FTT decision set aside and remitted; ICO treated as having jurisdiction to issue the notices.
- Article 2(2)(a): exclusion for activities outside Union law is narrow and does not extend to Clearview’s processing on the Tribunal’s reading.
- Article 3(2)(b): 'behavioural monitoring' is interpreted broadly and can include automated collection, sorting, classification, storing, and profiling.
- Article 3(2): 'related to' is expansive and can cover a controller whose processing is related to monitoring carried out by another controller.
- Context: Clearview’s service was used by clients in national security or criminal law enforcement; the decision addresses data processing in that setting, not sanctions enforcement directly.
The decision strengthens UK regulatory reach over a foreign technology company whose service supports national-security and law-enforcement use cases, reducing the space for offshore firms to argue they are outside UK/EU data-protection jurisdiction. For sanctions and sovereign-risk analysis, it signals a willingness to regulate cross-border digital services tied to state-security functions, even where the provider is outside the UK.