The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

140 incidents closest to “IDEMIA Public Security (IDEMIA Group)” · matched on meaning · public reporting

WF-YRL6VW4 May 2025

Worldcoin halts ID verification in Indonesia after regulatory freeze

Worldcoin, the digital identity project developed by Tools for Humanity, voluntarily paused its identity verification services in Indonesia on May 5, 2025, following a regulatory freeze by the Ministry of Communication and Digital Application. The ministry acted after preliminary investigations found that operating companies lacked required electronic system provider licenses. Worldcoin uses its Orb device to scan faces and irises to create unique digital identities. The company said it is committed to addressing any regulatory shortcomings and awaits clearer guidance.

Company involved
Worldcoin
AI system involved
World ID

3 source articles · read the reporting →

WF-9VIXU423 Mar 2026

Woman denied state welfare card groceries after face scan fails

A grandmother rode her motorcycle several kilometres to a shop in Sapphaya district, Chai Nat province, to use her state welfare card to buy groceries for her family. After selecting items, she failed repeated facial recognition scans because her ID card photo was years old and no longer matched her appearance. She left the shop empty-handed and in tears.

Company involved
Government of Thailand (state welfare card system)

2 source articles · read the reporting →

WF-03V5V41 Jan 2021

PimEyes faces fine proceedings over biometric facial recognition in Baden-Württemberg

PimEyes, a facial recognition search engine, is accused of scraping images from the internet and processing biometric data without a valid legal basis under the GDPR. The data protection authority of Baden-Württemberg (LfDI) opened fine proceedings after it found PimEyes's response to its questions inadequate. PimEyes argues that the images it processes are publicly available and not personal data. The LfDI says the processing endangers citizens' rights and freedoms and is not covered by the GDPR exceptions.

Company involved
PimEyes
AI system involved
PimEyes

9 source articles · read the reporting →

WF-DLNNBB1 Jan 2015

French police secretly used Briefcam facial recognition since 2015

The French National Police has been using Briefcam's Video Synopsis software since 2015, according to internal documents obtained by Disclose. The software, which includes facial recognition capabilities, was deployed without the required data protection impact assessment or notification to the CNIL. The Ministry of the Interior concealed the use of this tool for eight years. The police hierarchy allegedly used the software for facial recognition without judicial requisition, and the DGPN did not respond to requests for comment.

Company involved
French National Police
AI system involved
Briefcam Video Synopsis

10 source articles · read the reporting →

WF-8UTONQ22 Dec 2019

Delhi Police use facial recognition to screen PM Modi rally attendees

Delhi Police used an Automated Facial Recognition System (AFRS) to screen crowds at Prime Minister Narendra Modi's rally on December 22, 2019. The system, originally installed to find missing children, was used to identify possible disruptions. Privacy advocates called the move illegal and unconstitutional, saying it amounts to mass surveillance. Police defended the use, citing credible intelligence about possible disruptions.

Company involved
Delhi Police
AI system involved
Automated Facial Recognition System (AFRS)

6 source articles · read the reporting →

Outabox hack exposes biometric data of patrons at bars, clubs and casinos

Hackers claiming to be former employees published a website allowing searches of Outabox's facial recognition database, exposing biometric and other sensitive data of patrons used for age verification at bars, clubs and casinos. The Surveillance Technology Oversight Project warns that the breach demonstrates the danger of facial recognition for age verification. S.T.O.P. has launched a campaign to ban facial recognition in public accommodations.

Company involved
Outabox

8 source articles · read the reporting →

WF-PECTZC3 Sep 2024

Dutch DPA fines Clearview AI €30.5 million for GDPR violations

The Dutch Data Protection Authority fined Clearview AI €30.5 million for creating an illegal database of biometric codes scraped from social media without consent. The regulator accused the company of failing to inform individuals about how their data is used and continuing violations after investigation. Clearview AI denies the allegations, stating it has no presence in the Netherlands or EU and that the fine is unenforceable.

Company involved
Clearview AI
AI system involved
Clearview AI facial recognition database

7 source articles · read the reporting →

AENA fined €10m for GDPR breach over facial recognition pilot

AENA, Spain's state-owned airport manager, was fined just over €10 million by the Spanish data protection agency for breaching the GDPR. During a pilot project of a new facial recognition system, AENA failed to submit a data protection impact assessment that complied with GDPR requirements. The company has one month from notification to lodge an appeal for reconsideration.

Company involved
AENA

6 source articles · read the reporting →

PimEyes facial recognition search engine identifies individuals from public photos

PimEyes, a Polish facial recognition search engine, allows users to upload a photo and find matching images from across the internet. The system scrapes billions of photos and creates biometric profiles without consent. A banker named Dylan (pseudonym) discovered that an old party photo of him was found by the system, potentially outing his private life. Privacy advocates and platforms like Instagram and YouTube are taking action against PimEyes, alleging violations of the GDPR.

Company involved
PimEyes
AI system involved
PimEyes

6 source articles · read the reporting →

WF-2LAYJ824 Apr 2019

Buenos Aires city government uses live facial recognition to track minors in criminal database

The Buenos Aires city government deployed a live facial recognition system in April 2019 that scans subway passengers and matches them against CONARC, a national database of alleged offenders. Human Rights Watch found that the database includes at least 166 children, some as young as one to three years old, and that the system has led to numerous false arrests. The system was implemented without public consultation, and there is no mechanism to correct mistakes. A civil rights organization filed a lawsuit, and the government is pushing a bill to legalize the technology.

Company involved
Buenos Aires city government

1 source article · read the reporting →

WF-3RBX5G1 Jan 2021

Ukrainian Hacker Pleads Guilty to Operating OnlyFake AI ID Scam Site

Yurii Nazarenko, a Ukrainian national, pleaded guilty to running OnlyFake, an AI-powered website that generated and sold over 10,000 counterfeit identification documents globally. The site allowed users to create realistic fake IDs, including driver's licenses and passports, to bypass identity verification at banks and cryptocurrency exchanges. Nazarenko faces up to 15 years in prison and agreed to forfeit $1.2 million. Sentencing is scheduled for June 2026.

Company involved
OnlyFake
AI system involved
OnlyFake

3 source articles · read the reporting →

Italian DPA fines Municipality of Trento over AI surveillance projects

The Italian data protection authority (Garante) fined the Municipality of Trento €50,000 for two research projects, Marvel and Protector, that used AI to analyze video, audio, and social media data for public security purposes. The projects involved automated detection of risk events from surveillance cameras and microphones in public spaces, as well as monitoring social media for hate speech. The Garante found multiple violations of privacy law, including lack of a valid legal basis, insufficient anonymization, failure to conduct a data protection impact assessment, and inadequate transparency. The municipality is required to delete the unlawfully processed data.

Company involved
Comune di Trento
AI system involved
Marvel and Protector

9 source articles · read the reporting →

WF-A73KVP29 Jan 2023

Telangana Police facial recognition error leads to wrongful arrest and custodial death

Mohammed Khadeer, a 35-year-old man from Medak, was arrested by Telangana Police after a facial recognition system falsely matched his face to a suspect in a chain-snatching case. He was allegedly subjected to custodial torture and later died in hospital on 18 February 2023. The police acknowledged the error and released him after verifying his innocence, but he had already suffered severe injuries. The incident has raised concerns about the lack of transparency and accountability in the use of facial recognition technology by the police.

Company involved
Telangana Police
AI system involved
Telangana Police Facial Recognition System

1 source article · read the reporting →

Bahia Facial Recognition System Misidentifies Black Man as Wanted Criminal

Davi, a black administrative assistant, was tracked across 15 metro stations and approached by police after Bahia's facial recognition system falsely matched him to a wanted person. He was released after officers verified his identity. The system, supplied by Iecisa and Huawei, has a low accuracy rate and disproportionately affects black people. The government plans to expand it despite concerns over racial bias and errors.

Company involved
Secretaria de Segurança Pública da Bahia

2 source articles · read the reporting →

WF-67SP4W1 Jan 2016

Duke University MTMC Dataset Used in Authoritarian Surveillance Research

Duke University created and openly distributed the Duke MTMC dataset, containing surveillance footage of approximately 2,000 students and visitors on campus. The dataset was used by numerous organisations, including Chinese military-linked companies like SenseTime and Hikvision, for developing person re-identification and facial recognition technologies. Following an investigation by exposing.ai and the Financial Times, Duke University terminated the dataset in May 2019. The incident highlights the privacy risks of academic datasets being repurposed for mass surveillance without consent.

Company involved
Duke University
AI system involved
Duke MTMC

1 source article · read the reporting →

WF-P9E72631 Dec 2021

Greek Data Protection Authority fines Ministry of Migration and Asylum for AI surveillance systems

The Hellenic Data Protection Authority (HDPA) imposed an administrative fine of €175,000 on the Ministry of Migration and Asylum (MMA) for GDPR violations related to the 'Centaur' and 'Hyperion' programmes. These systems use AI behavioral analytics, CCTV, drones, and biometric data to monitor and control access to reception facilities for asylum seekers on Greek islands. The HDPA found that the MMA failed to conduct proper Data Protection Impact Assessments and did not cooperate with the authority. The MMA has been ordered to comply with GDPR within three months.

Company involved
Ministry of Migration and Asylum
AI system involved
Centaur and Hyperion programmes

10 source articles · read the reporting →

Manchester City to Trial Facial Recognition at Etihad Stadium

Manchester City are set to trial facial recognition software supplied by Blink Identity at the Etihad Stadium. The system would scan fans' faces to check whether they have bought tickets and allow entry, with the aim of reducing matchday queues. Fans would need to sign up using a picture of their face. The article notes concerns about the potential security of users, but the club and vendor say they are committed to protecting fans.

Company involved
Manchester City

1 source article · read the reporting →

Clearview AI facial recognition app scrapes billions of images and is used by police

Clearview AI, a secretive start-up, built a facial recognition app that matches photos to a database of more than three billion images scraped from social media and websites. More than 600 law enforcement agencies, including the FBI and Department of Homeland Security, have used the tool to identify suspects in crimes such as shoplifting, identity theft and murder. The company monitored officers who ran a reporter's photo through the app, and its founder acknowledged designing an augmented-reality prototype but said there were no plans to release it. Critics warned the tool could end anonymity and enable misuse.

Company involved
Clearview AI
AI system involved
Clearview AI facial recognition app

2 source articles · read the reporting →

WF-HF1YRW1 Sep 2023

Xuhui police expand facial recognition surveillance to profile 1.1 million residents

The Xuhui District branch of the Shanghai Municipal Bureau of Public Security is expanding its Intelligent Image Recognition System, adding 2,500 facial recognition cameras and increased computing capacity to build profiles of residents and flag deviations. The project, contracted to US-sanctioned FiberHome, is designed to match each face to files on more than 50 million people. Officials say the system will analyse behaviour patterns and trigger early warnings.

Company involved
Shanghai Municipal Bureau of Public Security, Xuhui District Branch
AI system involved
Intelligent Image Recognition System

3 source articles · read the reporting →

WF-04DJR81 Jun 2020

Kmart's facial recognition system for refund fraud found unlawful by Privacy Commissioner

Kmart Australia deployed facial recognition technology in 28 stores from June 2020 to July 2022, capturing biometric data of every customer entering the stores and those at returns counters to detect refund fraud. The system collected sensitive information without notifying customers or obtaining their consent. The Australian Privacy Commissioner found that Kmart breached the Privacy Act, as the exemption for unlawful activity did not justify the indiscriminate and disproportionate collection of biometric data from thousands of individuals. Kmart has ceased using the system and cooperated with the investigation.

Company involved
Kmart Australia Limited

7 source articles · read the reporting →

WF-ZUBAPG1 Apr 2025

NYPD Facial Recognition Leads to Wrongful Arrest of Trevis Williams

In April 2025, Trevis Williams was arrested by the NYPD after a facial recognition program matched his mug shot to a suspect in a February flashing incident, despite an eight-inch height difference and alibi evidence. The victim identified him from the AI-suggested photo array. Mr. Williams spent over two days in jail before the case was dismissed in July. The incident highlights the risks of using facial recognition on low-quality surveillance images.

Company involved
New York Police Department

2 source articles · read the reporting →

WF-NTJTJM27 May 2021

Privacy International challenges Clearview AI's facial recognition database in Europe

Privacy International filed complaints against Clearview AI with five European data protection authorities in May 2021, alleging that the company's scraping of facial images from the web and building a biometric database without consent violates data protection laws. The regulators in the UK, France, Italy, Greece, and Austria have since found Clearview's practices unlawful, imposed fines, and ordered deletion of data. Clearview has appealed the UK fine, and the case is ongoing.

Company involved
Clearview AI
AI system involved
Clearview

10 source articles · read the reporting →

WF-1MQMSR21 Apr 2020

Dahua Exposed for Uyghur Tracking Software in Surveillance Systems

Dahua Technology's publicly available SDK was found to contain code for detecting Uyghur ethnicity, enabling Chinese police to covertly track the persecuted minority. The revelation led to widespread criticism, and Dahua removed the SDK after being contacted by IPVM but did not comment. The company had previously been sanctioned by the US for complicity in human rights abuses against Uyghurs, and its software is part of a massive surveillance apparatus in Xinjiang.

Company involved
Dahua Technology
AI system involved
Dahua SDK

1 source article · read the reporting →

Apple sued for $1 billion after facial recognition allegedly misidentifies teen as thief

Ousmane Bah, an 18-year-old student, alleges that Apple and its security firm used facial recognition software to incorrectly identify him as a shoplifter in multiple Apple Store thefts. He was arrested at his home and missed school, causing emotional distress and academic harm. While charges in New York and Boston were dropped after a detective noted Bah looked nothing like the suspect, a case in New Jersey remains pending. Apple denies using facial recognition in its stores, but the lawsuit claims the technology was used by its security contractor.

Company involved
Apple

5 source articles · read the reporting →

← Newerpage 5 of 6Older →