EU Enforcement Gap Risks Your Biometric Data
Based on research by NOYB
The Hamburg data protection authority is being sued for inaction after five years of ignoring clear GDPR violations by PimEyes, a facial recognition engine that scrapes billions of biometric images from the web. The authority admits the company’s practices are illegal but refuses to enforce penalties, citing that PimEyes is based in Dubai and unresponsive to inquiries.
The core issue here is not just about facial recognition, but about the failure to enforce data protection laws against third-country entities. The Hamburg DPA argues that because PimEyes claims to be in Dubai, Poland, or the Seychelles, it cannot take effective measures like freezing funds or ordering service providers to delete data. This creates a legal gray zone where companies can allegedly evade accountability by shifting their registered addresses, leaving individuals with no recourse and authorities with no leverage.
For CTOs and CISOs, the practical risk is severe. If your organization uses similar biometric data processing or relies on APIs that scrape public data, you are operating in a high-risk zone. The precedent set by Clearview AI shows that fines can reach millions, but this case highlights a different danger: the erosion of enforcement. If authorities decide they cannot act against foreign entities, the burden of compliance shifts entirely to you. You must ensure your data processing activities are robustly documented and that you are not inadvertently relying on services that operate in legal limbo. Ignoring the source of your data or the jurisdiction of your provider is no longer a viable strategy.
This situation reinforces the critical importance of processing data locally within the EU. When data stays within European borders, you maintain direct control and legal recourse. Relying on third-country services introduces uncertainty, especially when those services actively resist regulatory oversight. By keeping data processing local, you avoid the nightmare of chasing enforcement against uncooperative foreign entities. It is a strategic move that reduces legal exposure and ensures that your compliance efforts are not undermined by jurisdictional loopholes. The message is clear: control your data, control your risk.