Submit a source
Surveillance watch
Aug 2026CAIR: CAIR-SFBA Director Zahra Billoo Comments on Automated License Plate Reader Cameras Lawsuit - CAIR Aug 2026Uprise RI: ACLU: Cancel Cumberland's Flock Camera Contract - Uprise RI Aug 2026AL.com: Springville questions value of Flock camera system, considers ending contract - AL.com Aug 2026TAPinto: What Are Flock Cameras? Franklin Council to Discuss Technology Already in Use in Township - TAPinto Aug 2026SteveAhlquist.news: After Flock Safety image led to false arrest, ACLU urges Cumberland Town Council to cancel contract - SteveAhlquist.news Aug 2026Arizona Daily Star: Pinal County cancels Flock Safety contract over privacy - Arizona Daily Star Aug 2026WOAI: Guadalupe County terminates Flock Safety contract amid rising vandalism costs - WOAI Aug 2026WOAI: Guadalupe County terminates Flock Safety contract amid rising vandalism costs - WOAI Aug 2026The Providence Journal: RI woman says Flock camera misidentified her, leading to arrest - The Providence Journal Aug 2026kens5.com: Guadalupe County ends Flock Safety Camera contract, citing cost savings - kens5.com Aug 2026KSAT: Guadalupe County approves terminating Flock camera contract, citing vandalism, ‘public scrutiny’ - KSAT Aug 2026The Washington Post: Mayor urges Los Angeles Police Department to end Flock Safety contract - The Washington Post Aug 2026KVUE: Lago Vista votes to remove Flock safety cameras as backlash over license plate reading cameras grows - KVUE Aug 2026kens5.com: Guadalupe County ends Flock Safety Camera contract, citing cost savings - kens5.com Aug 2026Uprise RI: Glocester Council Votes to Remove Flock License Plate Cameras After Residents Pack Meeting - Uprise RI Aug 2026Uprise RI: Glocester Council Votes to Remove Flock License Plate Cameras After Residents Object - Uprise RI Aug 2026WNBF: Binghamton City Council Calls for Ending Flock Safety License Plate Reader Deal - WNBF Aug 2026WSYX: Columbus group to demand removal of license plate readers at City Council hearing Monday - WSYX Aug 2026NBC Connecticut: Lamont calls for pause on ALPR camera installations as state comes up with guidance - NBC Connecticut Aug 2026KQED: Stanford Cuts Ties With Flock Safety, Shifts to New Surveillance Vendor - KQED Aug 2026CT.GOV-Connecticut's Off: Governor Lamont Calls for Review of Safety Cameras and Automated License Plate Reader Technology, Urges Municipalities To Pause Installation of Any New Equipment - CT.GOV-Connecticut's Official State Website (.gov) Aug 2026ktar.com: Arizona sheriff cancels Flock camera contract, citing Fourth Amendment worries - ktar.com Aug 2026The Mendocino Voice: Opinion: Ukiah operates 14 cameras under a contract with Flock Safety - The Mendocino Voice Aug 2026WFTV: Palm Bay officials halt FLOCK camera system pending investigation - WFTV Aug 2026WDBO: Palm Bay officials halt FLOCK camera system pending investigation - WDBO Aug 2026The Boston Globe: Glocester, R.I., town council votes to end Flock license plate camera program - The Boston Globe Aug 2026Macomb Daily: Sterling Heights to consider making improper use of Flock a crime - Macomb Daily Aug 2026WVXU: Oxford commission doesn't recommend ending Flock camera contract - WVXU Aug 2026ABC15 Arizona: For it or against it: What Chandler residents think about Flock license plate reader cameras - ABC15 Arizona Aug 2026CBS News: Judge weighs key privacy question in lawsuit over San Jose's license plate reader cameras - CBS News

Communities saying no

Surveillance worldwide: proposed, misused, and pushed back

A curated, sourced record of mass surveillance around the world: where it is being proposed, where it is being misused, and where people, courts, and regulators push it back. From ALPR camera networks and facial recognition to biometric and algorithmic systems, if it watches people, it belongs here.

Layers
Today

Scroll or pinch to zoom, drag to pan, and tap a marker for the story and source. Use the timeline to watch the pushback spread. 74 countries and regions on record so far. This list grows as cases are verified.

Documented stops & misuses 169

Every individual case mapped as a diamond: magenta wrongful stops from plate-reader errors, and cyan data misuse by officers, agencies, and vendors. Filter the list, then tap any source.

Judge and general jailed for spying on a journalistChile

Wrongful stop

A Chilean court on Jun 30, 2026 sentenced a former judge and a former army general to five years in prison for illegally spying on investigative journalist Mauricio Weibel Barahona while he was reporting Milicogate -- his 2015 investigation for The Clinic into the theft of the army's copper reserve fund. The Committee to Protect Journalists called the decision unprecedented for Chile. Two details give it weight beyond the country: the surveillance was run through the machinery of state -- a judge and a general, not a rogue operator -- against a journalist for the act of reporting on the military that employed one of them; and accountability took eleven years from publication and six years of judicial process to arrive. Custodial sentences for state officials over journalist surveillance remain rare enough worldwide that each one is a record; this is Latin America's counterpart to Greece's Feb 2026 Predatorgate convictions, and unlike Greece's suspended terms, these are prison sentences.

Jun 2026 Source →

Biometric 'digital profile' of foreign nationalsRussia

Wrongful stop

Russia moved to build a centralized 'digital profile' of foreign nationals and stateless people, expected by mid-2026, pulling extensive personal and biometric information from multiple agencies -- part of a broader expansion of surveillance targeting foreign visitors and residents.

Jun 2026 Source →

Met expands permanent facial recognition to the West EndUnited Kingdom

Data misuse

In June 2026 Metropolitan Police Commissioner Sir Mark Rowley announced the most significant expansion of live facial recognition in London to date: static LFR cameras mounted on street furniture across the West End and Soho by the end of 2026, meant to grow into a citywide infrastructure programme rather than time-limited van operations. It followed a six-month Croydon pilot (October 2025 to March 2026, 24 operations, 173 arrests, more than 470,000 faces scanned) and an April 2026 High Court ruling that the Met's LFR policy was lawful, now under appeal. Big Brother Watch urged the force to stop until Parliament legislates, noting the UK still has no specific statutory framework for LFR.

UK plugs its plate-reader network into EU-wide Prum sharingUnited Kingdom

Data misuse

In June 2026 the UK Home Office switched on number-plate checks through the EU's Prum data-sharing framework, letting officers query overseas-registered vehicles across EU member states and get vehicle-keeper details back in about ten seconds instead of days or months. It bolts cross-border reach onto Britain's already vast plate-reader system -- commonly cited at around 11,000 ANPR cameras reading roughly 50 million plates a day into the National ANPR Data Centre, where records are retained for a year. The government framed the link-up around border security, illegal migration and organised crime.

Jun 2026 Source →

80,000 protesters scanned; a worker wrongly flaggedUnited Kingdom

Data misuse

London's Metropolitan Police scanned the faces of about 80,000 people at a single protest and have run live facial recognition against millions of faces. Youth worker Shaun Thompson was wrongly flagged, detained, and threatened with arrest before being compensated. Campaigners call it stop and search on steroids.

Greek Watergate and the Predator convictionsGreece

Data misuse

In the Greek Watergate scandal, Intellexa's Predator spyware was used against politicians and journalists, and in 2026 a Greek court sentenced Intellexa founder Tal Dilian and others to eight years for illegal operations.

Mar 2026 Source →

National digital-ID system breached, biometric data stolenSenegal

Wrongful stop

In January 2026 a threat actor calling itself the Green Blood Group claimed to have breached Senegal's national digital-ID system and exfiltrated about 139 terabytes of data, including biometric records -- a stark illustration of the privacy risk when governments centralize biometric identity.

Jan 2026 Source →

Police tap a private plate network half a million times a yearNew Zealand

Data misuse

New Zealand police query Auror, an Auckland retail-crime ANPR platform, hundreds of times a day -- around half a million times a year -- with thousands of officers able to access it without stating a reason. Defence lawyers challenging it in the Court of Appeal call it 'surveillance capitalism.'

Sep 2025 Sourcesrnz.co.nznzherald.co.nz

Police in four states run Palantir 'dragnet' data-miningGermany

Data misuse

German state police have adopted Palantir's Gotham data-mining platform -- Hesse's HessenData since 2017, North Rhine-Westphalia's DAR, Bavaria's VeRA (live from late 2024) and Baden-Wurttemberg from 2025 -- to fuse names, addresses, phone and social-media records into instant profiles, including of people never suspected of a crime. In a 2023 landmark ruling the Federal Constitutional Court struck down the Hesse and Hamburg data-mining laws as too broad; civil-liberties groups GFF and the Chaos Computer Club have since filed constitutional complaints against Bavaria and North Rhine-Westphalia, calling it a 'Palantir dragnet.'

Biometric national ID mandated for all citizensMexico

Data misuse

In July 2025 a presidential decree made the biometric CURP -- face, fingerprints, and iris captured in a QR code -- the mandatory national ID for nearly all public and private services. A new Unified Identity Platform links it to other state databases for real-time cross-checks, and from 2026 every mobile line must be tied to it. The decree lets prosecutors, the National Intelligence Center, the National Guard, and the security ministry consult the database -- including bank and telecom data -- without notifying the person. Framed as a response to Mexico's missing-persons crisis, it drew warnings of a mass-surveillance ecosystem from digital-rights groups R3D and Article 19, and courts in several states issued injunctions pausing the rollout.

Paragon Graphite used against journalists in ItalyItaly

Data misuse

Italy's intelligence services used Paragon's Graphite spyware against journalists and migrant-rescue activists, confirmed by Citizen Lab in 2025, including Fanpage journalist Ciro Pellegrino and Mediterranea Saving Humans founders.

Jun 2025 Sourcescitizenlab.caamnesty.org

Facial recognition turned on Pride marchers and minor offendersHungary

Data misuse

In March 2025 Hungary's Parliament rushed through three amendments in 24 hours -- to the Assembly Act, the Infraction Act and the Facial Recognition Technology Act -- banning Pride events and authorising police to use live facial recognition to identify participants and anyone committing even minor infractions such as jaywalking. Effective April 15, 2025, it dramatically widened biometric surveillance of peaceful assembly. Rights groups (HCLU, EDRi, ECNL, Liberties for Europe) argue it violates the EU AI Act, which already bars real-time remote biometric identification in public, and the EU Charter; the European Commission has been slow to act. Budapest Pride went ahead in June 2025 as the country's largest anti-government demonstration in years.

Apr 2025 Sourcesedri.orgeuobserver.com

Serbia hacks activists' phones in police custodySerbia

Data misuse

An Amnesty International report found that Serbian police and the BIA intelligence agency used Cellebrite forensic tools to secretly unlock the phones of journalists and activists during detention, then installed a homegrown Android spyware called NoviSpy that can copy data and switch on the camera and microphone. Investigative journalist Slavisa Milanov and environmental campaigners were among those hacked after being held for routine-seeming interviews.

Automated welfare state flags 'atypical' lives for fraud probesDenmark

Data misuse

A November 2024 Amnesty International investigation, 'Coded Injustice,' found Denmark's welfare agency Udbetaling Danmark and its administrator ATP run some 60 fraud-detection algorithms -- including a 'Really Single' model that guesses a person's relationship status and the 'Gladsaxe Model' -- that mine vast personal data and flag 'unusual' or 'atypical' living and family patterns, disproportionately targeting people with disabilities, low incomes, migrants and foreigners. Denmark's Parliamentary Ombudsman opened an inquiry; the agency denies it amounts to social scoring.

Nov 2024 Source →

Legal challenge to the benefits agency's fraud-scoring algorithmFrance

Data misuse

In October 2024 a coalition of 15 organisations, including La Quadrature du Net and Amnesty International, filed a complaint before France's top administrative court against the risk-scoring algorithm used by the national family-benefits fund CNAF. The system assigns welfare recipients a fraud-suspicion score from data on their circumstances; analysis showed it effectively rated the poorest, single parents, disabled people and those born outside the EU as higher risk, singling them out for intrusive checks.

Oct 2024 Source →

Wrongful detentions from face-match errorsBrazil

Wrongful stop

Brazil's expanding police facial recognition has repeatedly detained innocent people, overwhelmingly Black. One man was tracked across fifteen train stations in Bahia before being held on a false match, another was detained in front of a stadium crowd, and in 2025 an 80-year-old volunteer was taken to a police station after cameras mistook him for a wanted man. A study found about 90 percent of those arrested through the technology in several states were Black Brazilians.

Apr 2024 Source →

Face recognition installed to catch unveiled studentsIran

Data misuse

Iranian authorities installed facial recognition at Amirkabir University of Technology in Tehran to identify and penalize women students who removed their headscarves, part of a wider rollout of cameras and drones to enforce hijab laws.

AI cameras and biometrics turn refugee camps into 'high-tech prisons'Greece

Data misuse

At Greece's EU-funded Closed Controlled Access Centres for asylum seekers, two systems -- Centaur (CCTV, drones and AI behavioural analytics that flag 'threats' and log incidents, monitored from Athens) and Hyperion (biometric fingerprint entry and exit) -- put residents under constant surveillance behind curfews, with cameras even in sleeping containers. Most residents interviewed said they were never told they were being filmed. In April 2024 the Greek Data Protection Authority fined the Migration Ministry 175,000 euros for GDPR breaches over the rollout.

Clearview expands face search across Latin AmericaEcuador

Data misuse

The American firm Clearview AI is expanding across Latin America, giving law enforcement in countries including Argentina, Brazil, Colombia, and Ecuador access to its database of billions of scraped faces, even as it faces fines and bans elsewhere. Rights advocates warn it puts much of the region in a perpetual police lineup, risking wrongful arrests and profiling.

Mar 2024 Source →

Wrongly flagged by live facial recognitionUnited Kingdom

Wrongful stop

London's Metropolitan Police scan millions of faces with live facial recognition. Youth worker Shaun Thompson was wrongly flagged in 2024, then stopped, detained, fingerprinted, and threatened with arrest over a false match. At one 2025 sporting event South Wales Police logged 2,470 alerts, 92 percent of them false, and the equality watchdog found the Met system disproportionately flags Black men.

Feb 2024 Source →

Biometric ID breaches exposed citizens' dataNigeria

Data misuse

Nigeria's biometric National Identification Number system, tied to SIM and bank registration, has suffered data breaches exposing citizens' personal records, alongside exclusion of those unable to enroll.

Jan 2024 Source →

Woman wrongly detained as a fugitiveBrazil

Data misuse

In Rio de Janeiro, a woman was wrongly detained after a facial-recognition database flagged her as a fugitive, even though she was already serving her sentence under an open regime.

Jan 2024 Source →

Clearview AI fined over scraped databaseNetherlands

Data misuse

The Dutch data-protection authority fined Clearview AI for building an illegal facial-recognition database from scraped photos of people in the Netherlands, one of several EU regulators to penalize the company.

2024 Source →

Predator spyware customerPhilippines

Data misuse

A Predator spyware customer assessed as highly likely linked to the Philippines was identified by Recorded Future, the first time the tool's use was tied to the country.

2024 Source →

Huawei Safe City cameras expand in BelgradeSerbia

Data misuse

Serbia is expanding Huawei's Safe City facial-recognition camera network in Belgrade, with leaked 2024 contracts showing capacity for up to 3,500 additional cameras despite public protests.

2024 Source →

Interior Ministry's secret use of Briefcam video analyticsFrance

Data misuse

In late 2023 investigative outlet Disclose revealed that France's national police and gendarmerie had for years quietly used Briefcam, an Israeli video-analytics system capable of facial recognition, to search and filter surveillance footage without public debate or, critics argued, a clear legal basis. A 2024 CNIL investigation concluded the Interior Ministry had not used the software for real-time facial recognition in public space, but the episode exposed how FR-capable tools were deployed in secrecy.

Nov 2023 Source →

Sao Paulo builds a 20,000-camera face networkBrazil

Data misuse

Sao Paulo's Smart Sampa program wires up to 20,000 cameras with facial recognition across a city of 12 million, watching streets, schools, and public spaces. Rights groups warn it could drive mass incarceration of Black residents, citing a 2019 study that found about 90 percent of those arrested through facial recognition in Brazil were Black. The Public Defender's Office sued to suspend it.

European court: metro face-recognition arrest violated rightsRussia

Data misuse

In July 2023 the European Court of Human Rights ruled that Russia violated Nikolay Glukhin's rights by using Moscow metro facial recognition to identify and arrest him over a peaceful solo protest. Glukhin had ridden the underground in August 2019 holding a life-sized cutout of jailed activist Konstantin Kotov; days later the system flagged him and police detained him. The court found the deployment incompatible with the values of a democratic society governed by the rule of law -- one of the first international rulings against live facial recognition.

Jul 2023 Source →

Red Wolf tracks Palestinians at checkpointsIsrael

Data misuse

In the occupied West Bank city of Hebron, an Israeli military facial-recognition system called Red Wolf scans Palestinians at checkpoints and enrolls their faces into surveillance databases without consent, deciding who may pass. Amnesty International's 2023 Automated Apartheid report documented how it automates movement restrictions and tracks residents, and how soldiers were rewarded for registering as many Palestinians as possible.

May 2023 Source →

Cameras track Palestinians' cars by plateIsrael

Data misuse

Israeli surveillance cameras in occupied East Jerusalem capture license plates on fixed and moving vehicles, feeding a database of Palestinians that records plates, permits, and addresses, restricting Palestinians' movement within their own neighborhoods. Researchers identified Hikvision and TKH cameras in the network.

May 2023 Sourcesamnesty.orgmei.edu

Soldiers scan Palestinians' faces at checkpointsPalestine

Data misuse

Israeli soldiers in Hebron use face-scanning cameras, known as Red Wolf, to identify Palestinians at checkpoints without checking IDs, feeding a database used to control their movement. Amnesty calls it automated apartheid.

May 2023 Sourcesamnesty.orgmei.edu

An app flags cars when a woman inside is unveiledIran

Data misuse

Iran's police run a phone app, Nazer, that lets officers and vetted civilians flag a vehicle's license plate when a woman inside is unveiled. The system sends the owner an automatic warning and then impounds the car. Amnesty documents hundreds of thousands of vehicles confiscated since 2023, and the app was later extended to taxis, ambulances, and buses.

Football club face scan wrongly fines a fanNetherlands

Data misuse

Dutch football clubs used retrospective facial recognition to scan crowds for banned supporters, and in one case wrongly issued a fine to a fan who had not even attended the match in question, a failure that drew warnings about expanding after-the-fact face surveillance in Europe.

Apr 2023 Sourcesedri.orgeuronews.com

Supermarkets built secret facial-recognition blacklists of shoppersUnited Kingdom

Data misuse

British retailers including Southern Co-op, Home Bargains and Mike Ashley's Frasers Group deployed Facewatch live facial recognition to scan shoppers entering stores and match them against private watchlists of suspected offenders. After a 2022 Big Brother Watch complaint, the ICO concluded in March 2023 that Facewatch's processing had breached data-protection law on multiple principles, forcing an overhaul; campaigners say people were blacklisted over trivial accusations and, in cases like a teenager wrongly flagged at Home Bargains in 2024, misidentified and publicly accused.

Rotterdam's 'suspicion machine' scored the poor for fraud raidsNetherlands

Data misuse

From 2017 to 2021 Rotterdam used an Accenture-built machine-learning model to score its roughly 30,000 welfare recipients for fraud risk, using about 315 inputs including age, gender, language skills, neighbourhood, marital status and subjective caseworker notes. A 2023 Lighthouse Reports and WIRED investigation ('Suspicion Machines') that reverse-engineered the model found it systematically ranked single mothers, non-Dutch speakers and people of certain ethnicities as higher risk, subjecting them to intrusive fraud investigations even when they had done nothing wrong.

Mar 2023 Source →

Blocked national IDs cut people off from servicesSouth Africa

Data misuse

In South Africa, the Home Affairs department's practice of blocking national IDs left many people unable to access banking, grants, and services, prompting legal challenges over the harms of digital identity systems.

Jan 2023 Source →

Journalists and rights workers hackedJordan

Data misuse

Pegasus was used against at least 16 Jordanian journalists and activists, including two Human Rights Watch staff and a Palestinian-American reporter hacked three times, many of whom had covered a teachers' strike the government crushed.

2023 Source →

Predator aimed at EU lawmakersVietnam

Data misuse

Vietnam deployed Predator spyware against targets including members of the European Parliament and used commercial spyware against bloggers, part of a broad surveillance campaign accompanying its jailing of online critics.

2023 Source →

Predator spyware infrastructureAngola

Data misuse

Angola was identified in the Predator Files as a likely customer of Intellexa's Predator spyware, with Amnesty International finding technical infrastructure tied to the tool active in the country.

2023 Source →

Predator spyware infrastructureMongolia

Data misuse

Mongolia appeared among the governments linked to Intellexa's Predator spyware in the Predator Files, with Amnesty International documenting infrastructure associated with the tool.

2023 Source →

Predator spyware shipmentsBotswana

Data misuse

Import records tied Botswana's Directorate of Intelligence and Security to shipments of Intellexa Predator spyware in 2023, the first identification of the tool's use in the country.

2023 Source →

Predator spyware infrastructureSudan

Data misuse

Sudan was among the countries where Amnesty International found technical infrastructure linked to Intellexa's Predator spyware in the Predator Files investigation.

2023 Source →

Mexico's army spied on journalists with PegasusMexico

Data misuse

Mexico is the most heavily targeted country in the Pegasus files. First exposed in 2017, the NSO spyware was used against journalists like Carmen Aristegui, whose teenage son was also hit, along with activists and lawyers for victims of disappearances. The Ejercito Espia investigation later showed the army kept using Pegasus against reporters and a human rights defender into 2021, even after the president pledged the practice had stopped.

Facial recognition used to hunt draft evadersRussia

Data misuse

After Russia's September 2022 mobilisation for its war on Ukraine, Moscow authorities turned the city's facial-recognition camera network on men avoiding the draft. Human Rights Watch documented at least seven men flagged as 'draft dodgers' and detained via surveillance cameras, taken to police stations and enlistment offices, with some ordered to the front. Enlistment offices even flag conscripts who legally challenge their call-up so they can be auto-detected on camera, and rights lawyers advise appellants to avoid the metro entirely.

Oct 2022 Sourceshrw.orgthemoscowtimes.com

Surveillance enforcing mandatory hijabIran

Data misuse

Iran uses facial recognition, road cameras, drones, and a citizen-reporting app to enforce mandatory hijab rules on women. A 2025 UN fact-finding mission documented facial recognition installed at a Tehran university gate to catch uncovered students, and metro screens in Mashhad displaying passengers' faces, age, and gender to frighten women out of defiance.

Sep 2022 Source →

Spanish football clubs scan fans' faces at the turnstileSpain

Data misuse

Spanish football clubs have rolled out facial recognition on supporters: Valencia CF deployed a FacePhi system to control stadium access and Atletico Madrid announced face-scanning and cashless entry from the 2022-23 season, while other clubs use fingerprint scanning at turnstiles. Fans and privacy advocates warned that mandatory biometric entry normalises tracking of ordinary spectators.

Aug 2022 Source →

Predator spyware targets Greece's journalists and politiciansGreece

Data misuse

In the scandal known as Predatorgate, the Predator spyware sold by the Israeli-founded firm Intellexa was used to target more than ninety journalists, the opposition leader Nikos Androulakis, ministers, and senior military officers between 2020 and 2022, alongside wiretaps by the national intelligence service. The case forced top resignations, and in 2026 an Athens court handed eight-year sentences to four people linked to Intellexa, a rare criminal reckoning for the spyware trade.

Jul 2022 Sourcesamnesty.orgen.wikipedia.org

Face scans track the Uyghur populationChina

Data misuse

In Xinjiang, authorities use facial recognition to monitor the mostly Muslim Uyghur population, with face scans required to enter shops, hotels, and stations and tens of thousands of cameras in Urumqi alone. Leaked police files showed Hikvision systems used to screen all 23 million residents and flag people with overseas ties for arrest.

Facial recognition ran searches on thousands not wantedArgentina

Data misuse

Buenos Aires's facial-recognition system was used to run unauthorized searches on more than 15,000 people not on any fugitive list, including journalists, politicians, and activists, and wrongly jailed a factory worker for nearly a week after a database error.

Apr 2022 Source →

CatalanGate spyware hits Catalan independence figuresSpain

Data misuse

Citizen Lab's CatalanGate report found at least sixty-five people tied to the Catalan independence movement, including every Catalan president since 2010, members of the European Parliament, lawyers, and activists, targeted or infected with Pegasus or Candiru spyware between 2017 and 2020. The lab pointed to strong circumstantial evidence of a Spanish state nexus; the government later acknowledged court-authorized surveillance of about two dozen people and denied a wider operation.

Metro face recognition used to detain protestersRussia

Data misuse

Moscow's metro facial recognition, part of a Safe City camera network, has been used to detain and question thousands of people on their way to and from anti-war protests, sometimes preventively. The European Court of Human Rights later ruled the practice violated human rights.

Clearview used to identify dead Russian soldiersUkraine

Data misuse

In March 2022 Ukraine's defence and digital-transformation ministries began using Clearview AI facial recognition -- provided free, drawing on billions of scraped images including from the Russian network VKontakte -- to identify the bodies of dead Russian soldiers and message their relatives, and to identify operatives. Critics warned of the wartime normalisation of a controversial scraping tool and the risk of deadly misidentification at checkpoints.

Mar 2022 Sourcesforbes.comamp.cbc.ca

Clearview AI fined 20 million eurosItaly

Data misuse

Italy's data-protection authority fined Clearview AI 20 million euros for processing biometric and location data of people in Italy without a legal basis, banned further collection, and ordered deletion of existing records.

Feb 2022 Source →

35 journalists infected with PegasusEl Salvador

Data misuse

Researchers confirmed Pegasus infections on 35 journalists and civil society members in El Salvador, with reporters at the outlet El Faro among the most heavily targeted as they investigated government corruption.

Jan 2022 Source →

Clearview AI fined for face scrapingFrance

Data misuse

France's data-protection regulator fined Clearview AI roughly 20 million euros and ordered it to stop collecting and to delete residents' data, after finding the company unlawfully scraped billions of faces into a recognition database sold to police.

2022 Source →

Clearview AI fined for face scrapingGreece

Data misuse

Greece's data-protection authority fined Clearview AI about 20 million euros for unlawfully scraping and processing residents' facial images, part of roughly 100 million euros in EU fines the company has largely ignored.

2022 Source →

ICO fines Clearview, orders deletionUnited Kingdom

Data misuse

The UK Information Commissioner's Office fined Clearview AI 7.5 million pounds in 2022 and ordered it to delete UK residents' data; after a tribunal initially overturned the action on jurisdiction, an appeals tribunal restored the regulator's authority in 2025.

Pegasus turned on Poland's oppositionPoland

Data misuse

Under the Law and Justice government, Polish services used NSO's Pegasus against the opposition. Senator Krzysztof Brejza was hacked dozens of times in 2019 while running the opposition's election campaign, and his stolen messages were doctored by state television for a smear campaign; a lawyer and a prosecutor critical of the government were also targeted. A Senate commission and the European Parliament found the spyware was deployed to entrench those in power, and prosecutors later seized the systems.

Court declared the biometric ID rollout illegalKenya

Data misuse

Kenya collected the fingerprints and facial images of tens of millions of people for its Huduma Namba (NIIMS) biometric ID before passing a data-protection law. The High Court declared the rollout illegal for skipping a privacy-risk assessment, and the successor Maisha Namba system faces similar criticism.

Facial recognition paused in Scottish school canteensUnited Kingdom

Data misuse

In October 2021 nine schools in North Ayrshire, Scotland switched on facial recognition to take payment in their canteens, scanning pupils' faces instead of fingerprints or cards. After public and regulatory backlash the ICO intervened, urging the schools to use a less intrusive method, and the rollout was paused -- an early flashpoint over normalising biometric identification of children for everyday transactions.

Oct 2021 Source →

Morocco named a top Pegasus user targeting journalists and leadersMorocco

Data misuse

The 2021 Pegasus Project named Morocco as one of the heaviest users of NSO's spyware, with around ten thousand numbers selected. They included Moroccan journalists such as Omar Radi, who was later jailed, as well as foreign figures, among them French President Emmanuel Macron and several of his ministers. Morocco denied buying or using Pegasus and sued the journalists and Amnesty International for defamation.

Police faked reports to track people with plate camerasNew Zealand

Data misuse

Just a month after the Privacy Commissioner warned police to do better on plate cameras, a detective pretended a car was stolen so they could track it, and officers filed a false report to use ANPR to track women linked to a Northland lockdown breach.

Jul 2021 Source →

Facial recognition used to hunt dissidentsRussia

Data misuse

Moscow's facial-recognition camera network, one of the world's largest, has been turned from catching criminals to hunting dissidents. Police have used it to identify and detain peaceful protesters, journalists covering them, and mourners at Alexei Navalny's 2024 funeral, tracing people right up to their door. In 2023 the European Court of Human Rights ruled its use against a protester unlawful.

Apr 2021 Source →

Junta expands Chinese safe-city camerasMyanmar

Data misuse

Myanmar's military junta expanded Chinese-supplied safe-city camera networks with facial recognition across cities, raising fears of tracking dissidents after the 2021 coup.

Face recognition built to sort people by ethnicityChina

Data misuse

Chinese authorities, working with surveillance firms including Hikvision, Dahua, and Uniview, drew up facial-recognition standards that sort people by traits such as ethnicity and skin color, which researchers warned opened wide scope to target minorities like the Uyghurs at scale.

Allot DPI throttled Telegram before a blackoutKazakhstan

Data misuse

Allot's deep-packet-inspection technology was used in Kazakhstan to throttle Telegram and other platforms ahead of a January 2021 nationwide internet blackout.

Jan 2021 Source →

Mandatory biometric ID excludes the elderlyUganda

Data misuse

Uganda's mandatory Ndaga Muntu biometric national ID has been challenged by civil-society groups for excluding elderly people from welfare benefits and blocking women's access to healthcare, amid wider use of biometrics to monitor dissent.

Police ran face recognition on CCTV and web imagesSouth Korea

Data misuse

South Korean police tracked suspects with Videmo 360 facial recognition software, analyzing images pulled from CCTV and the internet, in a case that raised concerns over the legality of the surveillance.

Jan 2021 Source →

Retailer fined 10.4M euros for spying on staff by CCTVGermany

Data misuse

In a decision made public in January 2021, the Lower Saxony data-protection authority fined online electronics retailer notebooksbilliger.de about 10.4 million euros for unlawfully video-monitoring its employees for at least two years. The regulator found blanket CCTV over workspaces and public areas, justified only by a general suspicion of theft, had no legal basis under the GDPR -- one of Germany's largest fines for workplace surveillance.

Jan 2021 Source →

Pegasus used against journalistsAzerbaijan

Data misuse

Azerbaijan was identified as a Pegasus operator with around 48 journalists selected for targeting, including OCCRP investigative reporter Khadija Ismayilova, whose phone was infected for nearly three years, and Meydan TV freelancer Sevinc Vaqifqizi.

State spyware on journalists and criticsHungary

Data misuse

Hungary's Interior Ministry bought Pegasus for about 6 million euros and used it against investigative journalists such as Szabolcs Panyi of Direkt36, along with opposition figures, lawyers, and a media-owning businessman, an EU member state turning spyware on its own critics.

Pegasus targeting of dissidents abroadRwanda

Data misuse

Rwanda was named among Pegasus operators, with targets including the daughter and nephew of Hotel Rwanda figure Paul Rusesabagina; the leaked list also flagged South Africa's president as a possible Rwandan target.

2021 Source →

Officials and journalists on Pegasus listLebanon

Data misuse

Phone numbers of senior Lebanese figures appeared on the Pegasus list, including the president, a former prime minister, ministers, security chiefs, and numerous journalists and ambassadors, according to the Pegasus Project.

2021 Source →

Zero-click hacking of activistsBahrain

Data misuse

Bahraini human-rights activists were hacked with Pegasus in zero-click attacks that defeated new Apple protections, part of the Gulf state's documented use of commercial spyware against dissidents.

Pegasus on pro-democracy protestersThailand

Data misuse

Forensic analysis confirmed Pegasus on the phones of at least 30 Thai pro-democracy protesters, academics, and rights defenders during the 2020 to 2021 mass demonstrations, the first confirmed use of the spyware in the country.

2021 Source →

Civil society activists targetedKazakhstan

Data misuse

Four Kazakh civil society activists were confirmed targets of Pegasus, part of the leaked list of tens of thousands of phone numbers selected by NSO Group government clients.

2021 Source →

Pegasus against critics and clergyTogo

Data misuse

Togo appeared among NSO Group's Pegasus clients in the Pegasus Project, which documented the spyware being used against journalists, opposition figures, and members of the clergy critical of the government.

2021 Source →

Politician doubly infected with spywareEgypt

Data misuse

Egypt is a documented user of Predator spyware; in one case the phone of an exiled Egyptian politician was found simultaneously infected with both Predator and Pegasus, run by two different government clients.

2021 Source →

Predator spyware customerArmenia

Data misuse

Armenia was identified by Citizen Lab as a Predator spyware customer, part of a cluster of governments deploying the Cytrox tool against phones alongside the better-known Pegasus.

2021 Source →

Predator spyware customerIndonesia

Data misuse

Indonesia was documented as a Predator spyware customer, one of several governments Citizen Lab linked to the Cytrox surveillance tool used against people of interest.

2021 Source →

Predator spyware customerMadagascar

Data misuse

Madagascar was named among the government customers of Predator spyware identified by Citizen Lab, part of a growing roster of states buying commercial surveillance tools.

2021 Source →

Predator spyware customerOman

Data misuse

Oman was documented as a Predator spyware customer by Citizen Lab, adding a Gulf state to the list of governments using the Cytrox tool against targets of interest.

2021 Source →

Privacy Act breach, deletion orderedAustralia

Data misuse

Australia's information commissioner found in 2021 that Clearview AI breached the Privacy Act by scraping residents' faces without consent and ordered it to stop and delete the data; a tribunal upheld the ruling in 2023.

Mass scraping ruled illegalCanada

Data misuse

Canada's privacy commissioners ruled in 2021 that Clearview AI's mass scraping of facial images amounted to illegal surveillance and called on the company to stop and to delete Canadians' data.

2021 Source →

Care home fined for filming a disabled resident's bedroomSweden

Data misuse

In November 2020 the Swedish data-protection authority fined Gnosjo Municipality 200,000 SEK for unlawful video surveillance in an LSS home for people with functional impairments, after a resident was filmed in their own bedroom. The regulator found no legal basis and no impact assessment, calling it a severe and unjustifiable intrusion into the most private sphere of the home.

Nov 2020 Source →

Statewide plate-reader fleet, pushed to police bordersAustralia

Data misuse

Every Australian state runs plate readers. New South Wales' mobile MANPR fleet scans every passing vehicle statewide, storing hundreds of thousands of records a day, and was pushed to profile drivers at closed state borders during COVID lockdowns. The Australian Privacy Foundation calls ANPR a mass-surveillance technique that breaches freedom of movement.

Sep 2020 Sourcesmals.auprivacy.org.au

Court rules police face recognition unlawfulUnited Kingdom

Data misuse

A UK Court of Appeal ruling in Bridges v South Wales Police found the force's live facial recognition unlawful. Its AFR Locate system scanned up to 50 faces per second against watchlists that could include anyone, with images drawn even from social media, breaching privacy, data-protection, and equality law.

Aug 2020 Sourcessimmons-simmons.comeff.org

Black man jailed 26 days on a face-match errorBrazil

Data misuse

In Bahia, a Black man was wrongly detained for 26 days over a robbery committed by someone else a decade earlier, after a facial-recognition system misidentified him. It is one of several mistaken-identity cases tied to face recognition in Brazil since 2020.

Jun 2020 Source →

Como's public-square facial recognition ruled unlawfulItaly

Data misuse

In 2019 the northern Italian city of Como quietly bought, installed and tested a live facial-recognition system in public squares near its train station, among the first Italian municipalities to do so. After a journalistic investigation, the Italian data-protection authority (Garante) found the deployment had no legal basis under GDPR and ordered it stopped in 2020 -- a case that helped drive Italy's later national moratorium on public-space facial recognition.

Jun 2020 Source →

Facial-recognition app enforced Covid home quarantinePoland

Data misuse

In March 2020 Poland made its 'Home Quarantine' app mandatory for people ordered to isolate, requiring a geolocated facial-recognition selfie within 20 minutes of a random prompt. Failing to verify by face on demand triggered a police visit and possible fine, turning biometric identity checks into a routine tool of movement control and setting an early template other governments studied.

Mar 2020 Source →

Facial recognition used to identify protestersIndia

Data misuse

Delhi police used facial recognition to identify and arrest people from the 2020 anti-CAA protests and the communal riots that followed, later saying scores of the riot arrests were traced by the technology, and turned it on Sikh farmers during the 2021 farmers' protests. Rights groups documented its disproportionate use against Muslims and other minorities and a chilling effect on the right to protest.

Feb 2020 Source →

Face recognition aimed hardest at MuslimsIndia

Data misuse

Delhi police rolled out facial recognition that researchers found would inevitably fall hardest on the city's Muslim community, and used it to identify protesters, with much of the deployment kept under wraps.

Jan 2020 Source →

Greek police buy live face and fingerprint scan devicesGreece

Data misuse

In 2019 the Hellenic Police signed a roughly 4 million euro contract with Intracom Telecom for 'smart policing' devices -- handheld tools that let officers run live facial recognition and automated fingerprint identification on people during street stops. Part-funded by the EU, the deal was signed with no data-protection impact assessment and without consulting the Greek DPA, prompting complaints from digital-rights group Homo Digitalis.

Jan 2020 Sourcesedri.orgalgorithmwatch.org

Prague police roll out facial-recognition camerasCzechia

Data misuse

Around 2019-2020 Prague police sought approval to switch on automatic facial-recognition cameras at six locations in the Czech capital and bought recognition software from the firm Cogniware, extending biometric identification into public space with little public debate or oversight.

Jan 2020 Source →

Dutch police hold a 1.4 million-face recognition databaseNetherlands

Data misuse

By 2020 the Dutch national police maintained a facial-recognition database holding images of around 1.4 million people, and municipalities were rolling out face recognition in public space under 'pilot' and 'smart city living lab' labels that sidestepped regulatory scrutiny and frustrated public debate.

Jan 2020 Source →

EU project scraped social media to build a face databaseEuropean Union

Data misuse

SPIRIT was an EU-funded project to scrape social-media images and build a facial-recognition database for police use, with partners including the Hellenic Police, two UK forces (West Midlands and Thames Valley), the Serbian Interior Ministry and Poland's police academy. Critics likened its face-extraction and matching tools to Clearview AI; trials were planned for 2020-2021 with little transparency.

Jan 2020 Source →

Facial recognition to identify protestersBelarus

Data misuse

Belarus deployed facial recognition to identify and arrest participants in the 2020 post-election protests.

2020 Source →

Sandvine DPI used to shut down the internetBelarus

Data misuse

During the disputed 2020 election, Belarus used Sandvine deep-packet-inspection technology to block social media, messaging apps, and news sites amid a violent crackdown; Sandvine later found custom code had been inserted and canceled the contract.

Belgrade wired with thousands of Huawei face camerasSerbia

Data misuse

Belgrade has been fitted with thousands of Huawei 'Safe City' cameras carrying facial-recognition and plate-reading software, rolled out from 2019 with little transparency. The digital-rights group SHARE Foundation's 'Thousands of Cameras' campaign and Amnesty warned the system was unlawful and used to identify protesters, and biometric provisions were later dropped from a draft police law after public outcry.

Austrian police quietly ran facial recognition on CCTVAustria

Data misuse

Austria's federal police began using facial-recognition software to search surveillance footage at the end of 2019, comparing camera images against stored photos of suspects for after-the-fact identification. Rolled out with little public debate and limited to retrospective (not live) use, it made Austria one of a growing group of EU states quietly normalising biometric identification in criminal investigations.

Dec 2019 Source →

France's Alicem facial-recognition national IDFrance

Data misuse

In 2019 France moved to become the first European country to build a nationwide facial-recognition digital identity, Alicem, letting citizens verify themselves to government services by matching a selfie against their biometric passport. Digital-rights group La Quadrature du Net challenged it in court over the lack of any non-biometric alternative, arguing that effectively mandatory face-matching for state services breached the GDPR.

Oct 2019 Source →

Huawei facial recognition turned on the oppositionUganda

Data misuse

Uganda built a Huawei Safe City network of facial-recognition cameras across Kampala. A 2019 Wall Street Journal investigation found Huawei technicians helped state agents crack the encrypted communications of opposition leader Bobi Wine, leading to his arrest, and police later confirmed using the cameras to track people detained during anti-government protests. Opposition figures call it a tool to hunt and persecute critics.

Aug 2019 Source →

Protesters tear down face-scanning smart lamppostsHong Kong

Data misuse

During the 2019 pro-democracy protests, Hong Kongers wore masks and carried umbrellas and tore down 'smart lampposts' in Kowloon, fearing they held facial recognition that could identify demonstrators and expose them to arrest. Police had access to AI able to match faces from video to databases, and the fear of being identified kept some people away from the streets.

Aug 2019 Sourcesscmp.comcnn.com

Huawei face cameras blanket KampalaUganda

Data misuse

Uganda installed a 126 million dollar Huawei facial-recognition camera system across the capital, Kampala, which the president framed as a tool to fight street crime. Opposition figures said the real aim was to deter and identify protesters against an increasingly unpopular government.

Aug 2019 Source →

EU's first facial-recognition fine over a school attendance trialSweden

Data misuse

In August 2019 the Swedish Data Protection Authority issued the EU's first GDPR facial-recognition fine -- 200,000 SEK (about 20,000 euros) against the Skelleftea municipal school board after Anderstorp High School piloted FR cameras to log the attendance of 22 students over three weeks. The regulator found consent could not be a valid legal basis given the power imbalance between school and pupils, that attendance could be tracked less intrusively, and that the school processed sensitive biometric data without an adequate impact assessment.

Aug 2019 Source →

EU pilots a biometric 'lie detector' on travellersEuropean Union

Data misuse

iBorderCtrl was an EU-funded research project that piloted an automated 'lie detector' at the Hungarian, Greek and Latvian borders, using biometric and facial analysis to score whether travellers -- including asylum seekers -- were being deceptive. Widely criticised as pseudoscientific and discriminatory, the project ran until August 2019 and became a symbol of biometric experimentation on migrants at Europe's frontier.

Aug 2019 Source →

Denmark's first face-scanning stadium, now joined by a bigger oneDenmark

Data misuse

In July 2019 the football club Brondby IF switched on Panasonic facial recognition at Brondby Stadium -- the first FR deployment in Denmark, approved by the Danish Data Protection Agency -- scanning roughly 14,000 fans per match against a ban list of about 50 people. Digital-rights group IT-Pol argued the system was disproportionate and set a dangerously low bar, and a University of Copenhagen law professor who sat on the deciding council agreed it should arguably never have been allowed. In 2025 the agency granted FC Copenhagen a more extensive stadium face-recognition system, deepening the normalisation of biometric surveillance in Danish sport.

Jul 2019 Sourcesedri.orgidtechwire.com

Top court struck down a mandatory biometric IDJamaica

Data misuse

Jamaica's Supreme Court struck down the National Identification and Registration Act in 2019, ruling that mandatory biometric registration for a national ID violated the constitutional right to privacy.

Apr 2019 Source →

Pegasus used against a Saudi dissident in CanadaCanada

Data misuse

Saudi dissident Omar Abdulaziz, a Canadian resident and confidant of Jamal Khashoggi, had his phone infected with Pegasus, and Citizen Lab detected suspected infections inside Canada.

Pegasus infected exiled journalists in LatviaLatvia

Data misuse

Exiled Russian journalists based in Latvia, including Meduza founder Galina Timchenko and Novaya Gazeta Europe's Maria Epifanova, were infected with Pegasus between 2020 and 2023.

Sep 2018 Sourcescpj.orgcitizenlab.ca

Pegasus targeted an investigative journalistDominican Republic

Data misuse

Investigative journalist Nuria Piera was repeatedly targeted with Pegasus between 2020 and 2023, confirmed by Amnesty International and Citizen Lab.

Pegasus used against journalists and lawyersPanama

Data misuse

Pegasus was used to surveil journalists, activists, and lawyers in Panama, with early deployments linked to the government under former president Ricardo Martinelli.

Sep 2018 Source →

Pegasus and the leaked target listPakistan

Data misuse

The phone number of then prime minister Imran Khan appeared on the leaked Pegasus target list, and Citizen Lab detected suspected Pegasus infections in Pakistan.

Pegasus infections tied to Khashoggi targetingTurkiye

Data misuse

Citizen Lab detected suspected Pegasus infections in Turkey, where associates of murdered journalist Jamal Khashoggi were among those targeted.

Sep 2018 Source →

Suspected Pegasus operator in BangladeshBangladesh

Data misuse

Citizen Lab detected suspected Pegasus infections in Bangladesh, where authorities have acquired a range of phone interception and surveillance systems.

Sep 2018 Source →

Suspected Pegasus operator in KenyaKenya

Data misuse

Citizen Lab detected suspected Pegasus infections linked to an operator in Kenya.

Sep 2018 Source →

Suspected Pegasus operator in South AfricaSouth Africa

Data misuse

Citizen Lab detected suspected Pegasus infections in South Africa.

Sep 2018 Source →

Suspected Pegasus operator in SingaporeSingapore

Data misuse

Citizen Lab detected suspected Pegasus infections in Singapore.

Sep 2018 Source →

Suspected Pegasus operator in TunisiaTunisia

Data misuse

Citizen Lab detected suspected Pegasus infections linked to an operator in Tunisia.

Sep 2018 Source →

Suspected Pegasus operator in QatarQatar

Data misuse

Citizen Lab detected suspected Pegasus infections linked to an operator in Qatar.

Sep 2018 Source →

Algeria opened a Pegasus inquiryAlgeria

Data misuse

After the Pegasus Project, Algeria's public prosecutor ordered an investigation into reports the country was targeted, and Citizen Lab detected suspected infections there.

Suspected Pegasus operator in IraqIraq

Data misuse

Citizen Lab detected suspected Pegasus infections linked to an operator in Iraq.

Sep 2018 Source →

Suspected Pegasus operator in UzbekistanUzbekistan

Data misuse

Citizen Lab detected suspected Pegasus infections linked to an operator in Uzbekistan.

Sep 2018 Source →

Suspected Pegasus operator in KuwaitKuwait

Data misuse

Citizen Lab detected suspected Pegasus infections linked to an operator in Kuwait.

Sep 2018 Source →

Suspected Pegasus operator in YemenYemen

Data misuse

Citizen Lab detected suspected Pegasus infections in Yemen.

Sep 2018 Source →

Suspected Pegasus infections in SwitzerlandSwitzerland

Data misuse

Citizen Lab detected suspected Pegasus infections in Switzerland.

Sep 2018 Source →

Suspected Pegasus operator in Ivory CoastCote d'Ivoire

Data misuse

Citizen Lab detected suspected Pegasus infections linked to an operator in Ivory Coast (Cote d'Ivoire).

Sep 2018 Source →

Suspected Pegasus operator in ZambiaZambia

Data misuse

Citizen Lab detected suspected Pegasus infections linked to an operator in Zambia.

Sep 2018 Source →

Suspected Pegasus operator in KyrgyzstanKyrgyzstan

Data misuse

Citizen Lab detected suspected Pegasus infections in Kyrgyzstan.

Sep 2018 Source →

Suspected Pegasus operator in TajikistanTajikistan

Data misuse

Citizen Lab detected suspected Pegasus infections linked to an operator in Tajikistan.

Sep 2018 Source →

Suspected Pegasus operator in LibyaLibya

Data misuse

Citizen Lab detected suspected Pegasus infections linked to an operator in Libya.

Sep 2018 Source →

Pegasus used against Palestinian rights defendersPalestine

Data misuse

Citizen Lab detected suspected Pegasus infections in Palestine, where Palestinian human rights defenders were later confirmed to have been hacked.

Sep 2018 Source →

World's largest biometric ID raises exclusion fearsIndia

Data misuse

India's Aadhaar program enrolled the biometrics of more than 1.3 billion people into the central CIDR database. Civil-society groups warn it drives surveillance and exclusion; India's Supreme Court recognized privacy as a fundamental right in 2017 and curbed mandatory Aadhaar use in 2018.

Wrongful stops from number-plate misreadsUnited Kingdom

Wrongful stop

Britain runs one of the world's largest automatic number-plate recognition networks, reading tens of millions of plates a day into a database of more than 20 billion records. The official surveillance camera commissioner warned that even at a claimed 97 percent accuracy the system misreads hundreds of thousands of plates a day, that police hold no meaningful data on its accuracy, and that misreads and cloned plates have led to wrongful stops and arrests of innocent motorists.

Jan 2018 Source →

Plate and vehicle tracking refined on UyghursChina

Data misuse

Hikvision, the world's largest maker of plate readers and surveillance cameras, refined vehicle and face tracking in Xinjiang, where checkpoints and cameras monitor Uyghurs' movements. Those battle-tested systems are now exported worldwide.

Facial-recognition trials at Berlin's Sudkreuz stationGermany

Data misuse

Germany's federal police ran live facial-recognition trials at Berlin's Sudkreuz station in 2017 and 2018, scanning volunteers against a watchlist to test automated identification in a busy transit hub. Interior Minister Horst Seehofer hailed the results and pushed to expand automatic facial recognition to more stations and airports, drawing fierce criticism from civil-liberties groups and data-protection officials over false positives and the normalisation of biometric mass surveillance in public space.

Jan 2018 Source →

Pegasus around the Khashoggi killingSaudi Arabia

Data misuse

Saudi Arabia used Pegasus against people close to murdered journalist Jamal Khashoggi, including an exiled dissident friend and his fiancee, whose phone was infected days after his 2018 killing.

2018 Source →

Chinese facial recognition for mass surveillanceZimbabwe

Data misuse

From 2018 Zimbabwe acquired facial-recognition technology from CloudWalk and Hikvision for border control and mass surveillance, with citizens' biometric data sent back to the Chinese vendors.

2018 Source →

DPI redirected users to government spywareTurkiye

Data misuse

Citizen Lab's 2018 Bad Traffic report found Sandvine PacketLogic devices on Turkey's network redirecting hundreds of users to malicious sites that delivered government spyware, alongside blocking of political and news content.

Italy's secretive SARI police facial-recognition systemItaly

Data misuse

In 2017 Italy's Interior Ministry commissioned the SARI (Automatic Image Recognition System) facial-recognition platform for the scientific police from vendor Parsec 3.26. Rolled out with extreme secrecy and little oversight, SARI was shown to be biased and to draw heavily on a database skewed toward foreign nationals; its real-time mode was later blocked by the Garante pending a proper legal framework.

Nov 2017 Source →

Biometric dragnet over Uyghurs and Turkic MuslimsChina

Data misuse

China has built a pervasive biometric surveillance system across Xinjiang to control Uyghurs and other Turkic Muslims, combining facial-recognition checkpoints, mandatory collection of iris scans and DNA, and a predictive-policing platform that flags ordinary behavior as suspicious. It has funneled people into a network of detention camps that a 2022 UN report said may amount to crimes against humanity, with up to a million held.

Jan 2017 Source →

Gantry cameras log every vehicle for a tax not chargedDenmark

Data misuse

Denmark built 180 highway gantries and roughly 250 fixed plate-reading cameras for a lorry eco-tax. The cameras log every passing vehicle even though the tax is not being levied, and the scheme has drawn opposition.

Jan 2016 Source →

Early heavy use against dissidentsUnited Arab Emirates

Data misuse

The UAE was an early and heavy Pegasus user, targeting activist Ahmed Mansoor with a zero-day exploit in 2016 and later the ex-wife and associates of Dubai's ruler, part of one of the most extensive deployments of the spyware.

Spyware used against Ethiopian diaspora journalistsEthiopia

Data misuse

Ethiopian diaspora journalists at the ESAT broadcaster were targeted with Hacking Team's Remote Control System and Gamma's FinSpy spyware, documented by Citizen Lab.

Jul 2015 Sourcescitizenlab.cablog.sekoia.io

Hacking Team spyware client in ColombiaColombia

Data misuse

Colombian security agencies were clients of Hacking Team's Remote Control System spyware, revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcescitizenlab.cablog.sekoia.io

Hacking Team spyware client in EcuadorEcuador

Data misuse

Ecuador's intelligence agency SENAIN purchased Hacking Team's Remote Control System spyware, revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcescitizenlab.cablog.sekoia.io

Hacking Team spyware client in ChileChile

Data misuse

Chile's investigative police were clients of Hacking Team's Remote Control System spyware, revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcesblog.sekoia.iocitizenlab.ca

Hacking Team spyware client in HondurasHonduras

Data misuse

Honduras was among the government clients of Hacking Team's Remote Control System spyware revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcesblog.sekoia.iocitizenlab.ca

Hacking Team spyware client in NigeriaNigeria

Data misuse

Nigerian government bodies were among the clients of Hacking Team's Remote Control System spyware revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcesblog.sekoia.iocitizenlab.ca

Hacking Team spyware client in MalaysiaMalaysia

Data misuse

Malaysian agencies were among the clients of Hacking Team's Remote Control System spyware revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcesblog.sekoia.iocitizenlab.ca

Hacking Team spyware client in South KoreaSouth Korea

Data misuse

South Korea's National Intelligence Service was a client of Hacking Team's Remote Control System spyware, revealed by the 2015 breach and sparking domestic controversy.

Jul 2015 Sourcescitizenlab.cablog.sekoia.io

A nationwide plate-reading network for the whole countryHungary

Data misuse

Hungary built a unified national plate-reading network of 365 fixed gantries and 160 mobile units, feeding a central system used for traffic enforcement, registration and insurance checks, and stopping wanted or flagged vehicles nationwide.

Jan 2015 Source →

'Ring of steel' tracked every car in and out of a townUnited Kingdom

Data misuse

Hertfordshire police ringed the small town of Royston with ANPR cameras, logging every vehicle entering or leaving. After complaints by Big Brother Watch, Privacy International, and No CCTV, the UK data regulator ruled the scheme unlawful and excessive and ordered it halted.

Jul 2013 Sourcestheregister.comedri.org

A national plate-reader network built without debateUnited Kingdom

Data misuse

The UK runs one of the world's largest ANPR networks, feeding a central database, yet it was constructed by police without any parliamentary debate or public consultation, and privacy regulators warned the blanket approach may be unlawful.

Jan 2013 Sourcesedri.orgtechdirt.com

A motorway network that tracks cars by plateItaly

Data misuse

Italy's Tutor system covers more than 2,500 km of motorway, run jointly by the toll operator and the state police. It reads plates to calculate average speed over long stretches and can even track cars as they change lanes, logging the movements of every vehicle that passes.

Jan 2012 Source →

A city that scans every car crossing its boundaryBelgium

Data misuse

The Belgian city of Mechelen scans every car crossing its boundary, inbound and outbound, against blacklists, automatically checking about a million vehicles a week and dispatching patrols to intercept flagged cars.

Sep 2011 Source →

1,000 police cars scan every passing plateFrance

Data misuse

France equipped around 1,000 gendarmerie, police, and customs vehicles with plate-reading lightbars from the Paris firm Survision that continuously scan passing cars without any officer input and check them against databases.

May 2011 Source →

Police put a critic on a plate-reader watch listCanada

Data misuse

After a columnist criticized Edmonton police for using traffic cameras to raise revenue, officers added him to a plate-reader watch list of high-risk drivers to monitor his movements and look for a reason to arrest him. The police chief and several officers were dismissed, and Canada's privacy commissioner raised concerns.

Jan 2005 Source →

A secretive national plate-reading network since the 1980sJapan

Data misuse

Japan's National Police Agency has run the secretive N-System since the late 1980s, reading and recording license plates at hundreds of sites on highways and major roads, including a ring around Tokyo's Kabukicho district. Police disclose little about how long the data is kept or how it is used, and privacy advocates call it part of an emerging surveillance society.

Jan 1987 Sourcescsmonitor.comubisurv.net

Cyprus and the Intellexa surveillance tradeCyprus

Data misuse

Cyprus hosted operations of the Intellexa alliance behind the Predator spyware and was a client of Hacking Team, tying the island to Europe's mercenary surveillance trade.

Fatherland card links data to state benefitsVenezuela

Data misuse

Venezuela built the ZTE-backed fatherland card (carnet de la patria) system linking citizens' personal data to access to subsidized food and services, alongside Chinese-supplied surveillance cameras.

Chinese-supplied facial recognition surveillanceSri Lanka

Data misuse

Sri Lanka received Chinese-made AI surveillance and facial-recognition technology as part of Huawei and partner safe-city deployments.

DPI middleboxes injected Predator spywareEgypt

Data misuse

Telecom Egypt used Sandvine PacketLogic deep-packet-inspection middleboxes to inject Intellexa's Predator spyware into the connection of opposition presidential candidate Ahmed Eltantawy, alongside mass web-monitoring and news censorship; the US added Sandvine to its Entity List in 2024.

Blue Coat and Sandvine gear filtered the internetSyria

Data misuse

Syria's telecom authority deployed deep-packet-inspection equipment, including Blue Coat and Sandvine gear, to filter and censor the internet and redirect users to malicious sites during the civil war.

Amesys Eagle system enabled mass interceptionLibya

Data misuse

Under Muammar Gaddafi, Libya deployed the French company Amesys's Eagle system for nationwide internet interception and mass surveillance of dissidents; French magistrates later charged Amesys executives over complicity in torture.

Closed state supplied with DPI gearEritrea

Data misuse

Eritrea, one of the world's most closed states, was among the authoritarian governments supplied with Sandvine deep-packet-inspection equipment for internet control.

DPI gear powered social-media blackoutsAzerbaijan

Data misuse

Sandvine and Allot deep-packet-inspection equipment was deployed in Azerbaijan to impose social-media blackouts during periods of unrest.

DPI censorship throttles VPNs and newsRussia

Data misuse

Sandvine equipment was among the technology linked to internet censorship in Russia, which also runs the domestic TSPU deep-packet-inspection system to throttle and block VPNs, social media, and independent news.

DPI used to censor an LGBTQ websiteJordan

Data misuse

In Jordan, Sandvine equipment was used to censor an LGBTQ news website.

Every country on record

Diamonds on the map mark individual incidents -- magenta for wrongful stops, cyan for data misuse -- listed under the country where each happened, alongside the community records for that place.

North America 15
Canada 5

Canada

Restricted

Canada's Privacy Commissioner found the national police force, the RCMP, broke the Privacy Act by using Clearview AI, after regulators separately ruled Clearview's scraping of more than three billion images was illegal mass surveillance. The RCMP had run far more searches than it first admitted, and Clearview stopped offering its service in Canada.

Jun 2021 Clearview AI Source →

Victoria, BCCanada

Restricted

British Columbia's privacy commissioner ruled that Victoria police must immediately delete plate-reader data on vehicles that do not match a hot list, and that the public must be told the system's full scope, an early limit on Canadian ALPR retention.

Apr 2012 Alpr Source →

Data misuse

Mass scraping ruled illegal

Data misuse

Canada's privacy commissioners ruled in 2021 that Clearview AI's mass scraping of facial images amounted to illegal surveillance and called on the company to stop and to delete Canadians' data.

2021 Source →

Pegasus used against a Saudi dissident in Canada

Data misuse

Saudi dissident Omar Abdulaziz, a Canadian resident and confidant of Jamal Khashoggi, had his phone infected with Pegasus, and Citizen Lab detected suspected infections inside Canada.

Police put a critic on a plate-reader watch list

Data misuse

After a columnist criticized Edmonton police for using traffic cameras to raise revenue, officers added him to a plate-reader watch list of high-risk drivers to monitor his movements and look for a reason to arrest him. The police chief and several officers were dismissed, and Canada's privacy commissioner raised concerns.

Jan 2005 Source →
Dominican Republic 1

Pegasus targeted an investigative journalist

Data misuse

Investigative journalist Nuria Piera was repeatedly targeted with Pegasus between 2020 and 2023, confirmed by Amnesty International and Citizen Lab.

El Salvador 2

El Salvador

Contesting

After Citizen Lab and Access Now confirmed Pegasus infections on the phones of more than 20 journalists and civil-society members, most of them from the newspaper El Faro, the targeted journalists sued NSO Group in a US federal court. The suit was dismissed on jurisdictional grounds, a setback the plaintiffs appealed.

Nov 2022 Pegasus (NSO Group) Source →

Data misuse

35 journalists infected with Pegasus

Data misuse

Researchers confirmed Pegasus infections on 35 journalists and civil society members in El Salvador, with reporters at the outlet El Faro among the most heavily targeted as they investigated government corruption.

Jan 2022 Source →
Honduras 1

Hacking Team spyware client in Honduras

Data misuse

Honduras was among the government clients of Hacking Team's Remote Control System spyware revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcesblog.sekoia.iocitizenlab.ca
Jamaica 1

Top court struck down a mandatory biometric ID

Data misuse

Jamaica's Supreme Court struck down the National Identification and Registration Act in 2019, ruling that mandatory biometric registration for a national ID violated the constitutional right to privacy.

Apr 2019 Source →
Mexico 4

Mexico

Removed

Mexico's Supreme Court struck down PANAUT on Apr 25, 2022 -- the law that would have tied every one of the country's 120-million-plus mobile lines to a government registry of fingerprints, face and iris data, collected by carriers at the point of sale and available to law enforcement on request. Nine of eleven justices ruled the decree wholly unconstitutional and the remaining two partially so; Justice Norma Lucia Pina Hernandez, who had suspended the rollout in Jun 2021, put the principle plainly: a national registry of mobile users is not a necessary measure in a democracy, because it does not balance limited investigative need against the right to privacy. The challenges came from every direction at once -- the transparency institute INAI, 48 senators, the telecom regulator IFT (which filed over the unfunded mandate), and digital-rights group R3D. The court found the scheme disproportionate: conditioning phone access on surrendering biometrics to fight kidnapping fails data-minimisation when the burden lands on every innocent user. Mexico's FIRST registry, RENAUT (2008), ended with millions of users' data leaked and allegedly sold by officials before being abandoned in 2012 -- the strike-down is the middle chapter, not the end: a 2026 law now routes the same ambition through the biometric CURP national ID, redesigned to dodge the court's centralised-database objection, with a Yucatan tribunal already suspending it. See the CURP record on this map for the third attempt.

Mexico

Contesting

In November 2021 Mexico made the first arrest anywhere in the global Pegasus scandal, jailing a technician at a private firm that had brokered NSO's spyware to Mexican agencies on charges of illegally tapping a journalist's phone. Mexico was one of NSO's earliest and heaviest clients, with the spyware turned on journalists and activists, and the case opened the first criminal accountability for that abuse.

Nov 2021 Pegasus (NSO Group) Source →

Data misuse

Biometric national ID mandated for all citizens

Data misuse

In July 2025 a presidential decree made the biometric CURP -- face, fingerprints, and iris captured in a QR code -- the mandatory national ID for nearly all public and private services. A new Unified Identity Platform links it to other state databases for real-time cross-checks, and from 2026 every mobile line must be tied to it. The decree lets prosecutors, the National Intelligence Center, the National Guard, and the security ministry consult the database -- including bank and telecom data -- without notifying the person. Framed as a response to Mexico's missing-persons crisis, it drew warnings of a mass-surveillance ecosystem from digital-rights groups R3D and Article 19, and courts in several states issued injunctions pausing the rollout.

Mexico's army spied on journalists with Pegasus

Data misuse

Mexico is the most heavily targeted country in the Pegasus files. First exposed in 2017, the NSO spyware was used against journalists like Carmen Aristegui, whose teenage son was also hit, along with activists and lawyers for victims of disappearances. The Ejercito Espia investigation later showed the army kept using Pegasus against reporters and a human rights defender into 2021, even after the president pledged the practice had stopped.

Panama 1

Pegasus used against journalists and lawyers

Data misuse

Pegasus was used to surveil journalists, activists, and lawyers in Panama, with early deployments linked to the government under former president Ricardo Martinelli.

Sep 2018 Source →
South America 14
Argentina 2

Buenos AiresArgentina

Paused

A court suspended Buenos Aires's live facial-recognition fugitive system in April 2022 and ruled it unconstitutional that September, upheld on appeal in 2023, after it was used to run unauthorized searches on thousands of people not on any wanted list, including journalists, politicians, and activists. It remains suspended pending audit safeguards.

Sep 2022 (approx.) Facial recognition Source →

Data misuse

Facial recognition ran searches on thousands not wanted

Data misuse

Buenos Aires's facial-recognition system was used to run unauthorized searches on more than 15,000 people not on any fugitive list, including journalists, politicians, and activists, and wrongly jailed a factory worker for nearly a week after a database error.

Apr 2022 Source →
Brazil 6

Brazil

Denied

Brazil's data authority banned Worldcoin in Jan 2025 on the same principle Kenya's court later reached: paying for biometrics breaks consent. The ANPD found that offering cryptocurrency for iris scans violates Brazil's data law, which requires consent for biometric collection to be free, informed and unequivocal -- a financial inducement aimed at people who need the money is none of those. In Mar 2025 the regulator reaffirmed the ban and attached a daily fine of 50,000 reais (about $8,800) should collection resume. Brazil is the largest economy to bar the program outright rather than suspend it, and its reasoning -- that the poorer the subject, the less voluntary the trade -- is the argument against biometrics-for-cash programs generally, not just this one.

Jan 2025 Worldcoin iris scanning Sourcesrestofworld.orgcoingeek.com

Brazil

Contesting

Courts suspended Sao Paulo Metro's facial-recognition system in 2022 after a public civil action by civil society groups, and a campaign backed by legislators across 13 states has pushed bills to ban facial recognition in public spaces. The city's larger Smart Sampa camera network has advanced despite the legal challenges.

Mar 2022 Facial recognition Source →

Wrongful stops & data misuse

Wrongful detentions from face-match errors

Wrongful stop

Brazil's expanding police facial recognition has repeatedly detained innocent people, overwhelmingly Black. One man was tracked across fifteen train stations in Bahia before being held on a false match, another was detained in front of a stadium crowd, and in 2025 an 80-year-old volunteer was taken to a police station after cameras mistook him for a wanted man. A study found about 90 percent of those arrested through the technology in several states were Black Brazilians.

Apr 2024 Source →

Woman wrongly detained as a fugitive

Data misuse

In Rio de Janeiro, a woman was wrongly detained after a facial-recognition database flagged her as a fugitive, even though she was already serving her sentence under an open regime.

Jan 2024 Source →

Sao Paulo builds a 20,000-camera face network

Data misuse

Sao Paulo's Smart Sampa program wires up to 20,000 cameras with facial recognition across a city of 12 million, watching streets, schools, and public spaces. Rights groups warn it could drive mass incarceration of Black residents, citing a 2019 study that found about 90 percent of those arrested through facial recognition in Brazil were Black. The Public Defender's Office sued to suspend it.

Black man jailed 26 days on a face-match error

Data misuse

In Bahia, a Black man was wrongly detained for 26 days over a robbery committed by someone else a decade earlier, after a facial-recognition system misidentified him. It is one of several mistaken-identity cases tied to face recognition in Brazil since 2020.

Jun 2020 Source →
Chile 2

Judge and general jailed for spying on a journalist

Wrongful stop

A Chilean court on Jun 30, 2026 sentenced a former judge and a former army general to five years in prison for illegally spying on investigative journalist Mauricio Weibel Barahona while he was reporting Milicogate -- his 2015 investigation for The Clinic into the theft of the army's copper reserve fund. The Committee to Protect Journalists called the decision unprecedented for Chile. Two details give it weight beyond the country: the surveillance was run through the machinery of state -- a judge and a general, not a rogue operator -- against a journalist for the act of reporting on the military that employed one of them; and accountability took eleven years from publication and six years of judicial process to arrive. Custodial sentences for state officials over journalist surveillance remain rare enough worldwide that each one is a record; this is Latin America's counterpart to Greece's Feb 2026 Predatorgate convictions, and unlike Greece's suspended terms, these are prison sentences.

Jun 2026 Source →

Hacking Team spyware client in Chile

Data misuse

Chile's investigative police were clients of Hacking Team's Remote Control System spyware, revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcesblog.sekoia.iocitizenlab.ca
Colombia 1

Hacking Team spyware client in Colombia

Data misuse

Colombian security agencies were clients of Hacking Team's Remote Control System spyware, revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcescitizenlab.cablog.sekoia.io
Ecuador 2

Clearview expands face search across Latin America

Data misuse

The American firm Clearview AI is expanding across Latin America, giving law enforcement in countries including Argentina, Brazil, Colombia, and Ecuador access to its database of billions of scraped faces, even as it faces fines and bans elsewhere. Rights advocates warn it puts much of the region in a perpetual police lineup, risking wrongful arrests and profiling.

Mar 2024 Source →

Hacking Team spyware client in Ecuador

Data misuse

Ecuador's intelligence agency SENAIN purchased Hacking Team's Remote Control System spyware, revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcescitizenlab.cablog.sekoia.io
Venezuela 1

Fatherland card links data to state benefits

Data misuse

Venezuela built the ZTE-backed fatherland card (carnet de la patria) system linking citizens' personal data to access to subsidized food and services, alongside Chinese-supplied surveillance cameras.

Europe 120
Austria 2

Austria

Contesting

Austria's DPA found Clearview AI acted illegally. The privacy group noyb filed a criminal complaint against the company and its managers.

Oct 2025 Facial recognition Source →

Data misuse

Austrian police quietly ran facial recognition on CCTV

Data misuse

Austria's federal police began using facial-recognition software to search surveillance footage at the end of 2019, comparing camera images against stored photos of suspects for after-the-fact identification. Rolled out with little public debate and limited to retrospective (not live) use, it made Austria one of a growing group of EU states quietly normalising biometric identification in criminal investigations.

Dec 2019 Source →
Belarus 2

Facial recognition to identify protesters

Data misuse

Belarus deployed facial recognition to identify and arrest participants in the 2020 post-election protests.

2020 Source →

Sandvine DPI used to shut down the internet

Data misuse

During the disputed 2020 election, Belarus used Sandvine deep-packet-inspection technology to block social media, messaging apps, and news sites amid a violent crackdown; Sandvine later found custom code had been inserted and canceled the contract.

Belgium 3

Police use of Clearview ruled unlawfulBelgium

Contesting

Belgium oversight body for police information, the COC, found in February 2022 that federal police use of Clearview AI facial recognition was not legal, not authorized, and not necessary, with no sufficient basis in police law. It followed a 2019 order to halt a facial-recognition trial at Brussels Airport for the same reason. The interior minister confirmed the tool was illegal under Belgian law, though lawmakers continue to debate a framework that could permit narrow police use.

Feb 2022 Facial recognition Source →

Belgium

Removed

In 2017 Brussels Airport (Zaventem) quietly installed four facial-recognition cameras for the airport police to match travellers against a blacklist, without informing Belgium's police-information oversight body (COC). When it found out, the COC ruled the deployment fell outside any lawful framework and it was stopped; the system had also proved unreliable, with false positives tied to skin colour and facial hair. Belgium remains one of the EU states that has not authorised police facial recognition.

Jan 2021 Facial recognition Source →

Data misuse

A city that scans every car crossing its boundary

Data misuse

The Belgian city of Mechelen scans every car crossing its boundary, inbound and outbound, against blacklists, automatically checking about a million vehicles a week and dispatching patrols to intercept flagged cars.

Sep 2011 Source →
Bulgaria 1

Bulgaria

Restricted

In Ekimdzhiev and Others v. Bulgaria (January 2022) the European Court of Human Rights found that Bulgaria's systems of secret surveillance and of bulk retention of communications data both violated the right to privacy under Article 8, citing weak authorisation, oversight and notification safeguards that left the regime open to abuse. It built directly on the Court's bulk-interception standards from Big Brother Watch.

Jan 2022 Secret surveillance & retention Source →
Cyprus 1

Cyprus and the Intellexa surveillance trade

Data misuse

Cyprus hosted operations of the Intellexa alliance behind the Predator spyware and was a client of Hacking Team, tying the island to Europe's mercenary surveillance trade.

Czechia 2

Prague airport facial recognition switched off, then leashedCzechia

Restricted

Czech police ran the country's only officially operating automatic facial-recognition system at Prague's Vaclav Havel Airport from 2018, converting travellers' faces into numeric 'bio-indexes' and matching them against wanted and missing-person databases. The digital-rights group Iuridicum Remedium complained to the Czech data-protection office in 2021, and its multi-year inspection concluded in mid-2025 that the deployment breached Czech and EU law. Once the EU AI Act's biometric provisions took effect in February 2025 the system needed judicial authorisation it had never obtained, and police switched it off on August 1, 2025 -- by the NGO's reckoning, six months of confirmed illegal operation. The Prague High Court let it back on February 26, 2026, but only on a leash: capture confined to non-Schengen exit passport lanes, no scanning of arrival halls or retail areas, deletion within 36 hours unless a match produces an investigative lead, raw images restricted to senior officers, the system isolated from the internet, quarterly independent audits, and standing power for the data-protection office to suspend it again.

  1. Jan 2021 Iuridicum Remedium filed a complaint with the Czech data-protection office, arguing police had no explicit legal basis to process biometric data through airport cameras. edri.org
  2. Feb 2025 The EU AI Act's biometric provisions took effect, making real-time biometric identification unlawful without judicial authorisation the airport system had never received. biometricupdate.com
  3. Aug 2025 Czech police shut the system down on August 1, 2025, the only officially running automatic facial-recognition deployment in the country. edri.org
  4. Feb 2026 The Prague High Court authorised a restart from mid-March 2026 under geofencing, 36-hour deletion, restricted access, and quarterly audit conditions. expats.cz
Feb 2026 Facial recognition Sourcesedri.orgbiometricupdate.comexpats.cz

Data misuse

Prague police roll out facial-recognition cameras

Data misuse

Around 2019-2020 Prague police sought approval to switch on automatic facial-recognition cameras at six locations in the Czech capital and bought recognition software from the firm Cogniware, extending biometric identification into public space with little public debate or oversight.

Jan 2020 Source →
Denmark 3

Automated welfare state flags 'atypical' lives for fraud probes

Data misuse

A November 2024 Amnesty International investigation, 'Coded Injustice,' found Denmark's welfare agency Udbetaling Danmark and its administrator ATP run some 60 fraud-detection algorithms -- including a 'Really Single' model that guesses a person's relationship status and the 'Gladsaxe Model' -- that mine vast personal data and flag 'unusual' or 'atypical' living and family patterns, disproportionately targeting people with disabilities, low incomes, migrants and foreigners. Denmark's Parliamentary Ombudsman opened an inquiry; the agency denies it amounts to social scoring.

Nov 2024 Source →

Denmark's first face-scanning stadium, now joined by a bigger one

Data misuse

In July 2019 the football club Brondby IF switched on Panasonic facial recognition at Brondby Stadium -- the first FR deployment in Denmark, approved by the Danish Data Protection Agency -- scanning roughly 14,000 fans per match against a ban list of about 50 people. Digital-rights group IT-Pol argued the system was disproportionate and set a dangerously low bar, and a University of Copenhagen law professor who sat on the deciding council agreed it should arguably never have been allowed. In 2025 the agency granted FC Copenhagen a more extensive stadium face-recognition system, deepening the normalisation of biometric surveillance in Danish sport.

Jul 2019 Sourcesedri.orgidtechwire.com

Gantry cameras log every vehicle for a tax not charged

Data misuse

Denmark built 180 highway gantries and roughly 250 fixed plate-reading cameras for a lorry eco-tax. The cameras log every passing vehicle even though the tax is not being levied, and the scheme has drawn opposition.

Jan 2016 Source →
Estonia 1

Estonia

Restricted

In Prokuratuur (2021) the EU Court of Justice ruled that police and prosecutors cannot freely reach into retained phone traffic and location data: access to communications metadata must be authorised in advance by a court or an independent authority, and a public prosecutor who directs the investigation is not independent enough. The Estonian case set an EU-wide guardrail on who can access retained data.

Mar 2021 Retained data access Source →
European Union 6

European Union

Restricted

The EU AI Act Article 5 bans real-time remote biometric identification (live facial recognition) by law enforcement in publicly accessible spaces, with narrow exceptions. The prohibited-practices rules took effect 2 February 2025.

Feb 2025 Facial recognition Source →

European Union

Contesting

The European Parliament set up a committee of inquiry, known as PEGA, into the use of Pegasus and equivalent spyware across member states. Active from April 2022, its final report in May 2023 found that spyware had been used to illegally target journalists, politicians, and critics in countries including Poland, Hungary, Greece, and Spain, and it called for a moratorium and binding safeguards on the sale and use of such tools in the EU.

May 2023 NSO Group, Intellexa Source →

European Union

Restricted

In Schrems II (Facebook Ireland and Schrems, 2020) the EU Court of Justice struck down the EU-US Privacy Shield data-transfer deal because US surveillance law -- letting agencies like the NSA access transferred data with no equivalent protection or redress for Europeans -- was incompatible with EU privacy rights. The EU's top court effectively ruled that US mass surveillance failed European fundamental-rights standards.

Jul 2020 US surveillance / data transfer Source →

European Union

Restricted

The EU's Court of Justice has repeatedly struck down blanket data retention -- the legal backbone that limits indiscriminate systems like ANPR. In Digital Rights Ireland (2014) it annulled the Data Retention Directive as a disproportionate mass intrusion; in Tele2 Sverige (2016) it held that national laws requiring general, indiscriminate retention of traffic and location data are unlawful; and in later rulings (La Quadrature du Net, SpaceNet) it kept the ban while allowing only narrow, targeted exceptions. The principle: mass retention of data, including vehicle-location reads, must be targeted, time-limited and independently overseen.

Apr 2014 Data retention Source →

Data misuse

EU project scraped social media to build a face database

Data misuse

SPIRIT was an EU-funded project to scrape social-media images and build a facial-recognition database for police use, with partners including the Hellenic Police, two UK forces (West Midlands and Thames Valley), the Serbian Interior Ministry and Poland's police academy. Critics likened its face-extraction and matching tools to Clearview AI; trials were planned for 2020-2021 with little transparency.

Jan 2020 Source →

EU pilots a biometric 'lie detector' on travellers

Data misuse

iBorderCtrl was an EU-funded research project that piloted an automated 'lie detector' at the Hungarian, Greek and Latvian borders, using biometric and facial analysis to score whether travellers -- including asylum seekers -- were being deceptive. Widely criticised as pseudoscientific and discriminatory, the project ran until August 2019 and became a symbol of biometric experimentation on migrants at Europe's frontier.

Aug 2019 Source →
Finland 1

Finland

Restricted

Finland Deputy Data Protection Ombudsman reprimanded the National Police Board in 2021 for unlawfully processing personal data when the National Bureau of Investigation trialed Clearview AI facial recognition during a child-abuse investigation. The ombudsman ordered the police to have Clearview erase the data they had transmitted and to notify affected people. The police had already dropped the tool, finding it unsuitable for their work.

Sep 2021 Clearview AI Source →
France 9

France

Restricted

France's data protection authority moved against Clearview AI in two stages. In December 2021 the CNIL ordered the company to stop collecting and using the face data of people in France and to delete what it held, finding the scraping had no legal basis. Clearview did not comply, and in October 2022 the CNIL fined it EUR 20 million for unlawful biometric processing -- one of a wave of European penalties the company has largely declined to pay, having no establishment in the EU for regulators to enforce against.

Oct 2022 Facial recognition Sourcestime.comedri.org

France

Removed

In February 2021 France's data-protection authority (CNIL) ruled that FC Metz's experimental stadium system -- meant to spot fans under civil stadium bans, detect abandoned objects and bolster counter-terror measures -- unlawfully processed biometric data. It was one of several French facial-recognition deployments, alongside school entry gates and a citizen-filming app in Nice, that regulators and courts struck down.

Feb 2021 Facial recognition Source →

School facial-recognition gates annulledFrance

Denied

A regional plan to install facial-recognition entry gates at two high schools in Nice and Marseille was struck down. The data-protection regulator CNIL warned in October 2019 that the trial was unlawful, and in February 2020 the Administrative Court of Marseille annulled it, ruling that the region had no authority to impose it, that students could not freely consent under school authority, and that the measure was disproportionate. It was the first French court decision applying the GDPR to facial recognition in a public space.

Feb 2020 Facial recognition Source →

France

Restricted

In Ben Faiza v. France (2018) the European Court of Human Rights found that real-time GPS tracking of a suspect's vehicle breached the right to privacy, because French law at the time gave no clear, foreseeable legal basis for such geolocation surveillance. The ruling pushed France to put covert location tracking on a proper statutory footing.

Feb 2018 GPS tracking Source →

Data misuse

Legal challenge to the benefits agency's fraud-scoring algorithm

Data misuse

In October 2024 a coalition of 15 organisations, including La Quadrature du Net and Amnesty International, filed a complaint before France's top administrative court against the risk-scoring algorithm used by the national family-benefits fund CNAF. The system assigns welfare recipients a fraud-suspicion score from data on their circumstances; analysis showed it effectively rated the poorest, single parents, disabled people and those born outside the EU as higher risk, singling them out for intrusive checks.

Oct 2024 Source →

Interior Ministry's secret use of Briefcam video analytics

Data misuse

In late 2023 investigative outlet Disclose revealed that France's national police and gendarmerie had for years quietly used Briefcam, an Israeli video-analytics system capable of facial recognition, to search and filter surveillance footage without public debate or, critics argued, a clear legal basis. A 2024 CNIL investigation concluded the Interior Ministry had not used the software for real-time facial recognition in public space, but the episode exposed how FR-capable tools were deployed in secrecy.

Nov 2023 Source →

Clearview AI fined for face scraping

Data misuse

France's data-protection regulator fined Clearview AI roughly 20 million euros and ordered it to stop collecting and to delete residents' data, after finding the company unlawfully scraped billions of faces into a recognition database sold to police.

2022 Source →

France's Alicem facial-recognition national ID

Data misuse

In 2019 France moved to become the first European country to build a nationwide facial-recognition digital identity, Alicem, letting citizens verify themselves to government services by matching a selfie against their biometric passport. Digital-rights group La Quadrature du Net challenged it in court over the lack of any non-biometric alternative, arguing that effectively mandatory face-matching for state services breached the GDPR.

Oct 2019 Source →

1,000 police cars scan every passing plate

Data misuse

France equipped around 1,000 gendarmerie, police, and customs vehicles with plate-reading lightbars from the Paris firm Survision that continuously scan passing cars without any officer input and check them against databases.

May 2011 Source →
Germany 7

Germany

Restricted

German data protection authorities ordered World in Dec 2024 to delete data that did not comply with the EU's General Data Protection Regulation -- the EU's consent and lawful-basis rules applied to an iris-scanning program headquartered partly in Berlin. Germany's move mattered less for its scope than for its venue: Tools for Humanity is a San Francisco and Berlin company, so this was the program's home-jurisdiction regulator finding its data holdings partly unlawful. Recorded as restricted rather than removed because collection was not barred outright; the order targeted non-compliant data. Marked approximate: the record is pinned at Berlin as a national-scope convention.

Dec 2024 (approx.) Worldcoin iris scanning Source →

Germany

Contesting

German data protection authorities found Clearview AI unlawful and ordered deletion, but the federal government has proposed a law granting police powers to match faces against public internet image databases. Legal scholars and civil society warn it breaches the constitution and EU law.

Oct 2024 (approx.) Facial recognition Source →

HamburgGermany

Removed

Hamburg police deleted their G20 facial-recognition database in 2020 -- a system that had biometrically templated roughly 100,000 people. After the 2017 G20 summit riots, police ran Videmo 360 face-recognition across uploaded private recordings, police video, S-Bahn station footage and media material, mathematically templating every identifiable face -- overwhelmingly bystanders never suspected of anything -- for automated matching against suspects. Data Protection Commissioner Johannes Caspar called it a new dimension of state investigation, warned the suspicionless material allowed inferences about behaviour patterns and preferences, objected in Aug 2018, and ordered deletion in Dec 2018 -- the first and only time he used his power to instruct the police. THE HONEST SEQUENCE, because this is not a clean regulator win: Hamburg's Administrative Court OVERTURNED the deletion order, ruling the DPA lacked competence to review the legal basis. The police then deleted the database anyway, telling the DPA it was simply no longer needed for the G20 prosecutions -- and the state government moved to strip the commissioner's instruction power in the new police law. The yield figures argue for themselves: 75 searches commissioned from the BKA after G20, three hits, one in five images unusable. A hundred thousand people templated for three matches, deleted without ever conceding it was unlawful.

May 2020 (approx.) Facial recognition (Videmo 360) Sourcesidentityweek.netdigit.site36.netgreens-efa.eu

Germany

Restricted

Germany's Federal Constitutional Court ruled automatic plate recognition unconstitutional in 2008 and again in 2019, striking down provisions in Bavaria, Baden-Wurttemberg, and Hesse as violating the right to informational self-determination. The systems were built by Jenoptik.

Data misuse

Police in four states run Palantir 'dragnet' data-mining

Data misuse

German state police have adopted Palantir's Gotham data-mining platform -- Hesse's HessenData since 2017, North Rhine-Westphalia's DAR, Bavaria's VeRA (live from late 2024) and Baden-Wurttemberg from 2025 -- to fuse names, addresses, phone and social-media records into instant profiles, including of people never suspected of a crime. In a 2023 landmark ruling the Federal Constitutional Court struck down the Hesse and Hamburg data-mining laws as too broad; civil-liberties groups GFF and the Chaos Computer Club have since filed constitutional complaints against Bavaria and North Rhine-Westphalia, calling it a 'Palantir dragnet.'

Retailer fined 10.4M euros for spying on staff by CCTV

Data misuse

In a decision made public in January 2021, the Lower Saxony data-protection authority fined online electronics retailer notebooksbilliger.de about 10.4 million euros for unlawfully video-monitoring its employees for at least two years. The regulator found blanket CCTV over workspaces and public areas, justified only by a general suspicion of theft, had no legal basis under the GDPR -- one of Germany's largest fines for workplace surveillance.

Jan 2021 Source →

Facial-recognition trials at Berlin's Sudkreuz station

Data misuse

Germany's federal police ran live facial-recognition trials at Berlin's Sudkreuz station in 2017 and 2018, scanning volunteers against a watchlist to test automated identification in a busy transit hub. Interior Minister Horst Seehofer hailed the results and pushed to expand automatic facial recognition to more stations and airports, drawing fierce criticism from civil-liberties groups and data-protection officials over false positives and the normalisation of biometric mass surveillance in public space.

Jan 2018 Source →
Greece 7

Greece

Contesting

The Predatorgate scandal broke in 2022 when Predator spyware, made by the Intellexa group, was found on the phones of a financial journalist and the leader of the opposition PASOK party, who was also a member of the European Parliament. The national intelligence chief and the general secretary to the prime minister resigned, parliament passed a 2022 law on lifting communications confidentiality, and in February 2026 a Greek court convicted figures behind the Predator operation, a rare instance of accountability in the spyware industry.

Aug 2022 Intellexa Source →

Greece

Restricted

Greece's Data Protection Authority fined Clearview AI EUR 20 million, its largest-ever penalty against a private company, for unlawfully processing Greek citizens' biometric data.

Jul 2022 Facial recognition Sourceswearesolomon.comeuronews.com

Data misuse

Greek Watergate and the Predator convictions

Data misuse

In the Greek Watergate scandal, Intellexa's Predator spyware was used against politicians and journalists, and in 2026 a Greek court sentenced Intellexa founder Tal Dilian and others to eight years for illegal operations.

Mar 2026 Source →

AI cameras and biometrics turn refugee camps into 'high-tech prisons'

Data misuse

At Greece's EU-funded Closed Controlled Access Centres for asylum seekers, two systems -- Centaur (CCTV, drones and AI behavioural analytics that flag 'threats' and log incidents, monitored from Athens) and Hyperion (biometric fingerprint entry and exit) -- put residents under constant surveillance behind curfews, with cameras even in sleeping containers. Most residents interviewed said they were never told they were being filmed. In April 2024 the Greek Data Protection Authority fined the Migration Ministry 175,000 euros for GDPR breaches over the rollout.

Predator spyware targets Greece's journalists and politicians

Data misuse

In the scandal known as Predatorgate, the Predator spyware sold by the Israeli-founded firm Intellexa was used to target more than ninety journalists, the opposition leader Nikos Androulakis, ministers, and senior military officers between 2020 and 2022, alongside wiretaps by the national intelligence service. The case forced top resignations, and in 2026 an Athens court handed eight-year sentences to four people linked to Intellexa, a rare criminal reckoning for the spyware trade.

Jul 2022 Sourcesamnesty.orgen.wikipedia.org

Clearview AI fined for face scraping

Data misuse

Greece's data-protection authority fined Clearview AI about 20 million euros for unlawfully scraping and processing residents' facial images, part of roughly 100 million euros in EU fines the company has largely ignored.

2022 Source →

Greek police buy live face and fingerprint scan devices

Data misuse

In 2019 the Hellenic Police signed a roughly 4 million euro contract with Intracom Telecom for 'smart policing' devices -- handheld tools that let officers run live facial recognition and automated fingerprint identification on people during street stops. Part-funded by the EU, the deal was signed with no data-protection impact assessment and without consulting the Greek DPA, prompting complaints from digital-rights group Homo Digitalis.

Jan 2020 Sourcesedri.orgalgorithmwatch.org
Hungary 5

Hungary

Contesting

Hungary used Pegasus against journalists, lawyers, and opposition figures, with more than 300 people reportedly targeted. The government's own data-protection authority found no wrongdoing, but targeted journalists, backed by the Hungarian Civil Liberties Union, filed the first lawsuits against the state in 2022, the European Court of Human Rights took up a related case in 2023, and the European Parliament's PEGA inquiry condemned Hungary's use and demanded independent judicial authorization.

Jan 2022 Pegasus (NSO Group) Source →

Hungary

Restricted

In Szabo and Vissy v. Hungary (January 2016) the European Court of Human Rights found Hungary's sweeping anti-terror secret-surveillance law unlawful under Article 8, because it let authorities order surveillance without a sufficient factual basis or meaningful judicial control -- effectively enabling untargeted monitoring of virtually anyone. The ruling reinforced the requirement of individualised suspicion and independent oversight for secret surveillance.

Jan 2016 Secret surveillance Source →

Data misuse

Facial recognition turned on Pride marchers and minor offenders

Data misuse

In March 2025 Hungary's Parliament rushed through three amendments in 24 hours -- to the Assembly Act, the Infraction Act and the Facial Recognition Technology Act -- banning Pride events and authorising police to use live facial recognition to identify participants and anyone committing even minor infractions such as jaywalking. Effective April 15, 2025, it dramatically widened biometric surveillance of peaceful assembly. Rights groups (HCLU, EDRi, ECNL, Liberties for Europe) argue it violates the EU AI Act, which already bars real-time remote biometric identification in public, and the EU Charter; the European Commission has been slow to act. Budapest Pride went ahead in June 2025 as the country's largest anti-government demonstration in years.

Apr 2025 Sourcesedri.orgeuobserver.com

State spyware on journalists and critics

Data misuse

Hungary's Interior Ministry bought Pegasus for about 6 million euros and used it against investigative journalists such as Szabolcs Panyi of Direkt36, along with opposition figures, lawyers, and a media-owning businessman, an EU member state turning spyware on its own critics.

A nationwide plate-reading network for the whole country

Data misuse

Hungary built a unified national plate-reading network of 365 fixed gantries and 160 mobile units, feeding a central system used for traffic enforcement, registration and insurance checks, and stopping wanted or flagged vehicles nationwide.

Jan 2015 Source →
Ireland 2

Ireland

Contesting

Civil society and oversight bodies in Ireland have contested government plans to give the national police, An Garda Siochana, facial recognition powers since 2022. The Irish Council for Civil Liberties, Digital Rights Ireland, the Data Protection Commission, and the Oireachtas Justice Committee all flagged serious deficiencies, and the committee issued dozens of recommended changes in 2024. The opposition delayed the measure for years, though a 2025 bill authorizing Garda biometric analysis was advancing through the Oireachtas in 2026.

Feb 2024 Facial recognition Source →

Ireland

Restricted

In Commissioner of An Garda Siochana (2022) the EU Court of Justice held that Ireland's regime of general and indiscriminate retention of traffic and location data to fight serious crime was contrary to EU law, reaffirming that blanket retention -- the kind that also underpins mass metadata and vehicle-tracking databases -- is permissible only when targeted and properly safeguarded.

Apr 2022 Blanket data retention Source →
Italy 7

Italy

Restricted

Italy's data protection authority (Garante) fined Clearview AI EUR 20 million, banned further collection and processing of residents' data, and ordered deletion of the biometric data it held.

Feb 2022 Facial recognition Sourcesedpb.europa.euedri.org

Public-space facial-recognition moratoriumItaly

Paused

In December 2021 Italy became the first EU country to pause facial recognition in public spaces, suspending installation and use of the technology by both public and private actors until a dedicated legal framework is passed. Police and judicial criminal investigations were exempted, which civil-society groups criticized, but the moratorium marked a national stand against biometric mass surveillance and was later extended while a permanent law was debated.

Dec 2021 Facial recognition Source →

Data misuse

Paragon Graphite used against journalists in Italy

Data misuse

Italy's intelligence services used Paragon's Graphite spyware against journalists and migrant-rescue activists, confirmed by Citizen Lab in 2025, including Fanpage journalist Ciro Pellegrino and Mediterranea Saving Humans founders.

Jun 2025 Sourcescitizenlab.caamnesty.org

Clearview AI fined 20 million euros

Data misuse

Italy's data-protection authority fined Clearview AI 20 million euros for processing biometric and location data of people in Italy without a legal basis, banned further collection, and ordered deletion of existing records.

Feb 2022 Source →

Como's public-square facial recognition ruled unlawful

Data misuse

In 2019 the northern Italian city of Como quietly bought, installed and tested a live facial-recognition system in public squares near its train station, among the first Italian municipalities to do so. After a journalistic investigation, the Italian data-protection authority (Garante) found the deployment had no legal basis under GDPR and ordered it stopped in 2020 -- a case that helped drive Italy's later national moratorium on public-space facial recognition.

Jun 2020 Source →

Italy's secretive SARI police facial-recognition system

Data misuse

In 2017 Italy's Interior Ministry commissioned the SARI (Automatic Image Recognition System) facial-recognition platform for the scientific police from vendor Parsec 3.26. Rolled out with extreme secrecy and little oversight, SARI was shown to be biased and to draw heavily on a database skewed toward foreign nationals; its real-time mode was later blocked by the Garante pending a proper legal framework.

Nov 2017 Source →

A motorway network that tracks cars by plate

Data misuse

Italy's Tutor system covers more than 2,500 km of motorway, run jointly by the toll operator and the state police. It reads plates to calculate average speed over long stretches and can even track cars as they change lanes, logging the movements of every vehicle that passes.

Jan 2012 Source →
Latvia 1

Pegasus infected exiled journalists in Latvia

Data misuse

Exiled Russian journalists based in Latvia, including Meduza founder Galina Timchenko and Novaya Gazeta Europe's Maria Epifanova, were infected with Pegasus between 2020 and 2023.

Sep 2018 Sourcescpj.orgcitizenlab.ca
Luxembourg 1

Luxembourg

Restricted

Luxembourg is one of the few European countries to have introduced legal restrictions on the use of facial recognition technology.

Facial recognition Source →
Netherlands 6

Netherlands

Contesting

The Dutch ANPR Act -- Article 126jj of the Code of Criminal Procedure, in force since 2019 -- has police log the plate and location of every passing vehicle and hold it for four weeks in a central database, whether or not anyone is suspected of anything. Privacy First has been litigating to have it declared unlawful since 2021, arguing the bulk retention of millions of motorists' movements is disproportionate under European privacy law, unsupervised, easy to abuse, and by several studies ineffective at what it claims to do. After summary proceedings, the District Court of The Hague cleared the case to proceed on the merits in early 2024. The appeal was heard at the Court of Appeal in The Hague on July 9, 2026 (Privacy First Foundation v. the State, case 200.347.782/01), in a hearing the foundation opened to the public, and it says it will carry the case to the highest European courts if it has to, citing recent European case law and the Dutch data protection authority's own positions. Judgment pending. Read this against Norfolk, Virginia, where a US federal judge held a 21-day ALPR retention window too short to amount to Carpenter-style surveillance: the Dutch window is twice that, nationwide, and statutory rather than contractual. Same technology, same question about how long is too long, two legal systems arriving from opposite directions.

Jul 2026 Alpr Source →

Netherlands

Restricted

The Dutch DPA fined Clearview AI EUR 30.5 million and warned Dutch companies against using its facial recognition database.

Sep 2024 Facial recognition Source →

Data misuse

Clearview AI fined over scraped database

Data misuse

The Dutch data-protection authority fined Clearview AI for building an illegal facial-recognition database from scraped photos of people in the Netherlands, one of several EU regulators to penalize the company.

2024 Source →

Football club face scan wrongly fines a fan

Data misuse

Dutch football clubs used retrospective facial recognition to scan crowds for banned supporters, and in one case wrongly issued a fine to a fan who had not even attended the match in question, a failure that drew warnings about expanding after-the-fact face surveillance in Europe.

Apr 2023 Sourcesedri.orgeuronews.com

Rotterdam's 'suspicion machine' scored the poor for fraud raids

Data misuse

From 2017 to 2021 Rotterdam used an Accenture-built machine-learning model to score its roughly 30,000 welfare recipients for fraud risk, using about 315 inputs including age, gender, language skills, neighbourhood, marital status and subjective caseworker notes. A 2023 Lighthouse Reports and WIRED investigation ('Suspicion Machines') that reverse-engineered the model found it systematically ranked single mothers, non-Dutch speakers and people of certain ethnicities as higher risk, subjecting them to intrusive fraud investigations even when they had done nothing wrong.

Mar 2023 Source →

Dutch police hold a 1.4 million-face recognition database

Data misuse

By 2020 the Dutch national police maintained a facial-recognition database holding images of around 1.4 million people, and municipalities were rolling out face recognition in public space under 'pilot' and 'smart city living lab' labels that sidestepped regulatory scrutiny and frustrated public debate.

Jan 2020 Source →
Poland 4

Poland

Restricted

In Pietrzak and Bychawska-Siniarska and Others v. Poland (2024) -- brought by lawyers and human-rights activists -- the European Court of Human Rights found Poland's secret-surveillance and communications-data-retention regime in breach of privacy rights, citing weak authorisation and oversight and the absence of any notification to those who had been spied on.

May 2024 Secret surveillance & retention Source →

Poland

Contesting

Poland is investigating how the previous Law and Justice government used NSO Group Pegasus spyware, which officials say was deployed against roughly 600 people between 2017 and 2022, including the opposition senator who ran the 2019 election campaign. After the government changed in late 2023, prosecutors opened investigations and parliament created a Pegasus and Illegal Surveillance commission in February 2024. In December 2024 a former security service chief was forcibly compelled to testify, a first in Polish history.

Feb 2024 NSO Group Source →

Data misuse

Pegasus turned on Poland's opposition

Data misuse

Under the Law and Justice government, Polish services used NSO's Pegasus against the opposition. Senator Krzysztof Brejza was hacked dozens of times in 2019 while running the opposition's election campaign, and his stolen messages were doctored by state television for a smear campaign; a lawyer and a prosecutor critical of the government were also targeted. A Senate commission and the European Parliament found the spyware was deployed to entrench those in power, and prosecutors later seized the systems.

Facial-recognition app enforced Covid home quarantine

Data misuse

In March 2020 Poland made its 'Home Quarantine' app mandatory for people ordered to isolate, requiring a geolocated facial-recognition selfie within 20 minutes of a random prompt. Failing to verify by face on demand triggered a police visit and possible fine, turning biometric identity checks into a routine tool of movement control and setting an early template other governments studied.

Mar 2020 Source →
Portugal 1

Portugal

Paused

Portugal's CNPD imposed a three-month ban on Worldcoin in Mar 2024, in step with Spain and on the same grounds: insufficient information provided to users, biometric collection from minors without consent, and no adequate age-verification mechanism. Two EU regulators independently reaching identical findings in the same month is itself evidence -- the failures were properties of the program's design, not of one country's rollout. The Iberian bans forced the company to halt orb operations across both countries while it answered the regulators.

Mar 2024 Worldcoin iris scanning Source →
Romania 1

Romania

Restricted

In Rotaru v. Romania (Grand Chamber, 2000) the European Court of Human Rights held that Romania violated privacy rights by keeping a secret intelligence-service file on a citizen -- containing old and partly false information about his student-era political activity -- with no way for him to challenge or correct it and no legal safeguards over what the security services stored. A foundational ruling on state files and databases.

May 2000 Secret intelligence file Source →
Russia 8

Russia

Restricted

In Podchasov v. Russia (2024) the European Court of Human Rights held that requiring a messaging service (Telegram) to give authorities the means to decrypt end-to-end encrypted communications violated the right to privacy. Weakening encryption for targeted users, the Court found, weakens it for everyone and is a disproportionate form of mass surveillance -- a landmark defence of encryption.

Feb 2024 Encryption backdoor Source →

Russia

Restricted

In Roman Zakharov v. Russia (Grand Chamber, December 2015) the European Court of Human Rights ruled that Russia's system of covert interception of mobile-phone communications (SORM), which let security services tap networks directly with weak oversight, violated the right to privacy under Article 8. The Court set benchmark standards for authorisation and independent supervision of secret surveillance -- standards Russia has since ignored.

Dec 2015 SORM interception Source →

Wrongful stops & data misuse

Biometric 'digital profile' of foreign nationals

Wrongful stop

Russia moved to build a centralized 'digital profile' of foreign nationals and stateless people, expected by mid-2026, pulling extensive personal and biometric information from multiple agencies -- part of a broader expansion of surveillance targeting foreign visitors and residents.

Jun 2026 Source →

European court: metro face-recognition arrest violated rights

Data misuse

In July 2023 the European Court of Human Rights ruled that Russia violated Nikolay Glukhin's rights by using Moscow metro facial recognition to identify and arrest him over a peaceful solo protest. Glukhin had ridden the underground in August 2019 holding a life-sized cutout of jailed activist Konstantin Kotov; days later the system flagged him and police detained him. The court found the deployment incompatible with the values of a democratic society governed by the rule of law -- one of the first international rulings against live facial recognition.

Jul 2023 Source →

Facial recognition used to hunt draft evaders

Data misuse

After Russia's September 2022 mobilisation for its war on Ukraine, Moscow authorities turned the city's facial-recognition camera network on men avoiding the draft. Human Rights Watch documented at least seven men flagged as 'draft dodgers' and detained via surveillance cameras, taken to police stations and enlistment offices, with some ordered to the front. Enlistment offices even flag conscripts who legally challenge their call-up so they can be auto-detected on camera, and rights lawyers advise appellants to avoid the metro entirely.

Oct 2022 Sourceshrw.orgthemoscowtimes.com

Metro face recognition used to detain protesters

Data misuse

Moscow's metro facial recognition, part of a Safe City camera network, has been used to detain and question thousands of people on their way to and from anti-war protests, sometimes preventively. The European Court of Human Rights later ruled the practice violated human rights.

Facial recognition used to hunt dissidents

Data misuse

Moscow's facial-recognition camera network, one of the world's largest, has been turned from catching criminals to hunting dissidents. Police have used it to identify and detain peaceful protesters, journalists covering them, and mourners at Alexei Navalny's 2024 funeral, tracing people right up to their door. In 2023 the European Court of Human Rights ruled its use against a protester unlawful.

Apr 2021 Source →

DPI censorship throttles VPNs and news

Data misuse

Sandvine equipment was among the technology linked to internet censorship in Russia, which also runs the domestic TSPU deep-packet-inspection system to throttle and block VPNs, social media, and independent news.

Serbia 5

Serbia

Contesting

Civil society led by the SHARE Foundation forced the withdrawal of draft laws that would have legalized mass biometric video surveillance in Belgrade, in 2021 and again in 2023. Facial recognition remains legally unauthorized in Serbia, though Huawei cameras are installed and rights groups say the software has been used during protests without a legal basis.

Feb 2023 (approx.) Facial recognition Source →

Serbia

Paused

In September 2021 Serbia withdrew its Draft Law on Internal Affairs, which would have legalised permanent, indiscriminate biometric video surveillance of Belgrade's public spaces and made Serbia the first country in the region with such a system. The reversal followed a sustained campaign by the SHARE Foundation (Thousands of Cameras / hiljadekamera), EDRi and pressure from members of the European Parliament. The interior ministry has kept trying since -- installing NEC NeoFace Watch and Russian FindFace and floating new draft laws -- but the 2021 win stalled full legalisation.

Sep 2021 Facial recognition Source →

Data misuse

Serbia hacks activists' phones in police custody

Data misuse

An Amnesty International report found that Serbian police and the BIA intelligence agency used Cellebrite forensic tools to secretly unlock the phones of journalists and activists during detention, then installed a homegrown Android spyware called NoviSpy that can copy data and switch on the camera and microphone. Investigative journalist Slavisa Milanov and environmental campaigners were among those hacked after being held for routine-seeming interviews.

Huawei Safe City cameras expand in Belgrade

Data misuse

Serbia is expanding Huawei's Safe City facial-recognition camera network in Belgrade, with leaked 2024 contracts showing capacity for up to 3,500 additional cameras despite public protests.

2024 Source →

Belgrade wired with thousands of Huawei face cameras

Data misuse

Belgrade has been fitted with thousands of Huawei 'Safe City' cameras carrying facial-recognition and plate-reading software, rolled out from 2019 with little transparency. The digital-rights group SHARE Foundation's 'Thousands of Cameras' campaign and Amnesty warned the system was unlawful and used to identify protesters, and biometric provisions were later dropped from a draft police law after public outcry.

Slovenia 1

Slovenia

Restricted

In Benedik v. Slovenia (2018) the European Court of Human Rights found a privacy violation because Slovenian police obtained the subscriber identity behind a dynamic IP address without a court order, under a law that lacked clarity and safeguards against abuse. A key ruling treating the link between an IP address and a named person as protected private data.

Apr 2018 IP / subscriber data Source →
Spain 6

AEPD turns the impact assessment into a weaponSpain

Restricted

Across 2025 and 2026 Spain's data-protection regulator built Europe's most aggressive line of biometric enforcement, and its lever was not consent but the data-protection impact assessment. In a decision dated November 6, 2025 the AEPD fined airport operator Aena just over 10 million euros for running facial-recognition boarding at eight airports, including Madrid-Barajas and Barcelona El Prat, on a centralised one-to-many template store, and ordered biometric processing suspended until an adequate assessment exists. Aena had already paused the programme in June 2024 after a complaint from the Eticas foundation and a single passenger, and is appealing. On March 4, 2026 the regulator fined FC Barcelona 500,000 euros over face and voice scans of roughly 143,000 members, minors included, during a 2023 membership census. Six days later it fined age-verification vendor Yoti 950,000 euros: 500,000 for having no lawful basis to process biometrics at account setup, 200,000 for a consent screen users could click past with research use pre-ticked, and 250,000 for holding geolocation data five years and retaining fraudulent ID documents to train its algorithms. Yoti is appealing to the Spanish High Court. The regulator's repeated finding was not that the paperwork was missing but that it was hollow -- and that convenience never establishes necessity.

  1. Jun 2024 Aena suspended its biometric boarding programme after a complaint to the AEPD from the Eticas foundation and a passenger. biometricupdate.com
  2. Nov 2025 The AEPD fined Aena just over 10 million euros for facial-recognition boarding at eight airports without a valid impact assessment, and ordered the biometric processing suspended. Aena is appealing. idtechwire.com
  3. Mar 2026 The AEPD fined FC Barcelona 500,000 euros over biometric face and voice verification of about 143,000 members, including minors, without a compliant impact assessment. idtechwire.com
  4. Mar 2026 The AEPD fined age-verification vendor Yoti 950,000 euros across three GDPR breaches and gave it six months to comply; Yoti rejected the finding and appealed to the Spanish High Court. yoti.com

Spain

Paused

Spain's AEPD issued an emergency three-month ban on Worldcoin's iris scanning in Mar 2024 -- the first European country to stop the orbs -- citing insufficient information given to users, collection from minors, and no adequate mechanism to verify age. An emergency order under the GDPR requires urgency and serious risk, and the AEPD found both in a program paying people, including teenagers who queued in shopping centres, to stare into a sphere. The Spanish ban opened the European front that Portugal joined the same month and Germany's deletion order extended in Dec 2024.

Mar 2024 Worldcoin iris scanning Source →

Spain

Contesting

After Citizen Lab documented Pegasus and Candiru infections on the phones of dozens of Catalan politicians, lawyers, and activists, and separate infections of the prime minister and defense minister, Spain opened judicial and parliamentary investigations and dismissed the director of its intelligence agency.

May 2022 Pegasus (NSO Group) Source →

Spain

Restricted

Spain data protection agency, the AEPD, fined supermarket chain Mercadona 2.5 million euros in 2021 for running facial recognition across 48 stores that scanned every shopper, including children, to flag people with restraining orders. The regulator ruled the system unlawful under the GDPR and it was ordered stopped.

  1. Jun 2020 Mercadona began a facial-recognition pilot across 48 supermarkets to flag people with restraining orders, scanning all shoppers including children. gdprhub.eu
  2. May 2021 After complaints and an AEPD interim order, Mercadona halted the pilot and removed the cameras. gdprhub.eu
  3. Jul 2021 The AEPD fined Mercadona 2.5 million euros, ruling the facial-recognition system unlawful under the GDPR. hunton.com
Jul 2021 Facial recognition Sourceshunton.comgdprhub.eu

Data misuse

Spanish football clubs scan fans' faces at the turnstile

Data misuse

Spanish football clubs have rolled out facial recognition on supporters: Valencia CF deployed a FacePhi system to control stadium access and Atletico Madrid announced face-scanning and cashless entry from the 2022-23 season, while other clubs use fingerprint scanning at turnstiles. Fans and privacy advocates warned that mandatory biometric entry normalises tracking of ordinary spectators.

Aug 2022 Source →

CatalanGate spyware hits Catalan independence figures

Data misuse

Citizen Lab's CatalanGate report found at least sixty-five people tied to the Catalan independence movement, including every Catalan president since 2010, members of the European Parliament, lawyers, and activists, targeted or infected with Pegasus or Candiru spyware between 2017 and 2020. The lab pointed to strong circumstantial evidence of a Spanish state nexus; the government later acknowledged court-authorized surveillance of about two dozen people and denied a wider operation.

Sweden 4

Sweden

Restricted

In Centrum for rattvisa v. Sweden (Grand Chamber, May 2021, decided alongside Big Brother Watch v. UK) the European Court of Human Rights examined Sweden's bulk signals-intelligence regime -- the mass interception of cross-border communications by the FRA agency -- and found it lacked adequate safeguards, in violation of the right to privacy under Article 8, particularly around oversight and the sharing of intercepted material with foreign partners.

May 2021 Bulk signals intelligence Source →

Sweden

Restricted

Sweden's data protection authority (IMY) fined the national police EUR 250,000 for using Clearview AI to identify people unlawfully and without a data protection assessment, and ordered the police to inform affected individuals and have their data deleted.

Feb 2021 Facial recognition Source →

Data misuse

Care home fined for filming a disabled resident's bedroom

Data misuse

In November 2020 the Swedish data-protection authority fined Gnosjo Municipality 200,000 SEK for unlawful video surveillance in an LSS home for people with functional impairments, after a resident was filmed in their own bedroom. The regulator found no legal basis and no impact assessment, calling it a severe and unjustifiable intrusion into the most private sphere of the home.

Nov 2020 Source →

EU's first facial-recognition fine over a school attendance trial

Data misuse

In August 2019 the Swedish Data Protection Authority issued the EU's first GDPR facial-recognition fine -- 200,000 SEK (about 20,000 euros) against the Skelleftea municipal school board after Anderstorp High School piloted FR cameras to log the attendance of 22 students over three weeks. The regulator found consent could not be a valid legal basis given the power imbalance between school and pupils, that attendance could be tracked less intrusively, and that the school processed sensitive biometric data without an adequate impact assessment.

Aug 2019 Source →
Switzerland 2

Switzerland

Restricted

In Amann v. Switzerland (Grand Chamber, 2000) the European Court of Human Rights found two privacy violations: the interception of a phone call to the applicant, and the secret card-index file the federal prosecutor then created and stored about him -- both without a clear legal basis. An early benchmark that even storing seemingly neutral data on a person engages the right to privacy.

Feb 2000 Interception & secret file Source →

Data misuse

Suspected Pegasus infections in Switzerland

Data misuse

Citizen Lab detected suspected Pegasus infections in Switzerland.

Sep 2018 Source →
Ukraine 1

Clearview used to identify dead Russian soldiers

Data misuse

In March 2022 Ukraine's defence and digital-transformation ministries began using Clearview AI facial recognition -- provided free, drawing on billions of scraped images including from the Russian network VKontakte -- to identify the bodies of dead Russian soldiers and message their relatives, and to identify operatives. Critics warned of the wartime normalisation of a controversial scraping tool and the risk of deadly misidentification at checkpoints.

Mar 2022 Sourcesforbes.comamp.cbc.ca
United Kingdom 20

United Kingdom

Contesting

On Jul 27, 2026 the UK Supreme Court ruled 3-2 that Bahrain cannot claim state immunity to block a spyware lawsuit -- holding that remotely infecting a computer physically located in the UK is an act carried out IN the UK. The precedent is the record: a foreign government that hacks a device in Britain from abroad now faces the same civil liability in English courts as one that sends agents in person, which closes the procedural shield transnational spyware campaigns have hidden behind. The claimants are Dr Saeed Shehabi, 71, a journalist and founder of a Bahraini opposition movement, and Moosa Mohammed, a Bahraini refugee, both in London; they allege agents acting for Bahrain infected their computers in Sep 2011 with FinSpy -- the commercial spyware of the now-defunct Munich firm FinFisher, capable of logging keystrokes, tracking location and monitoring communications. Bahrain denied the hacking and argued sovereign immunity; the High Court rejected that in 2023, the Court of Appeal upheld it in 2024, and the Supreme Court has now closed the question. Filed `contesting` because the win is jurisdictional, not final: the case returns to the High Court for full trial. It sits alongside WhatsApp v. NSO in the US as the second front testing whether spyware operations against exiles can be litigated where the victims live.

Jul 2026 Finspy spyware Sourcesaljazeera.comamnesty.org

National digital ID scrapped after three million signaturesUnited Kingdom

Denied

Keir Starmer announced a free national digital ID on 25 September 2025 -- branded BritCard, held in a GOV.UK wallet, mandatory for right-to-work checks and targeted for full rollout in 2029. The backlash was the largest of any recent UK digital policy: a parliamentary petition against it drew close to three million signatures, one of the biggest in British history, and thousands marched from Marble Arch to Whitehall on 18 October 2025 behind placards calling it a digital prison. Security specialists warned about concentrating that much identity data in a single store. In January 2026 the government dropped the mandatory element and made the scheme voluntary; that concession did not save it. Andy Burnham, sworn in as prime minister on 20 July 2026, confirmed on taking office that the roughly 1.8 billion pound programme is cancelled outright and the money redirected to cost-of-living measures. Separate digital public services and the wider government digital programme continue -- what died is the universal state identity credential. Unlike most wins on this map, this one came from sustained public opposition rather than a courtroom.

  1. Sep 2025 Starmer announced BritCard, a free national digital ID mandatory for right-to-work checks, with rollout targeted for 2029. bankinfosecurity.com
  2. Oct 2025 Thousands marched from Marble Arch to Whitehall against the scheme; the parliamentary petition against it neared three million signatures. computing.co.uk
  3. Jan 2026 Under sustained pressure the government dropped the mandatory element and made the scheme voluntary. aljazeera.com
  4. Jul 2026 Andy Burnham cancelled the programme outright on becoming prime minister, redirecting the funds to cost-of-living measures. techcrunch.com

National live facial recognition rolloutUnited Kingdom

Contesting

The Home Office set out its largest-ever facial-recognition expansion in a January 2026 policing white paper, funding 40 new live facial recognition (LFR) vans for a national rollout across England and Wales and pledging 115 million pounds for a National Centre for AI in Policing. LFR was in use by 13 of 43 forces by March 2026, and the first permanent LFR cameras went live in South London in October 2025. Rights groups and the Equality and Human Rights Commission have contested the deployments, with the EHRC joining a judicial review arguing the Metropolitan Police's use of LFR is unlawful.

Jan 2026 Facial recognition Source →

ICO fine and deletion order against ClearviewUnited Kingdom

Contesting

In May 2022 the UK Information Commissioner fined Clearview AI more than 7.5 million pounds and ordered it to stop scraping images of UK residents and to delete the data it already held, after a joint investigation with Australia regulator. Clearview appealed and a lower tribunal threw out the penalty in 2023 on jurisdiction grounds, but in October 2025 the Upper Tribunal restored most of the regulator case, ruling that Clearview does fall under UK data-protection law. The company may still seek further appeal.

May 2022 Facial recognition Source →

United Kingdom

Restricted

The UK Information Commissioner's Office fined Clearview AI GBP 7.5 million and ordered it to delete UK residents' data, finding the company built its database by scraping images from the web without consent. Clearview appealed.

May 2022 Clearview AI Source →

United Kingdom

Restricted

In Big Brother Watch and Others v. the United Kingdom (Grand Chamber, May 2021), the European Court of Human Rights found that the UK's bulk interception of communications -- the GCHQ mass-surveillance regime exposed by Edward Snowden -- violated the right to privacy (Article 8) and press freedom (Article 10) because it lacked sufficient end-to-end safeguards against abuse. It was the first Grand Chamber ruling on bulk interception in the post-Snowden era.

May 2021 Bulk interception Source →

United Kingdom

Contesting

In 2020 the Court of Appeal ruled South Wales Police live facial recognition unlawful in the Bridges case, the first successful legal challenge of its kind. In 2022 the ICO fined Clearview AI and ordered UK residents data deleted. Live facial recognition has since expanded to more police forces, and the fight over its limits continues.

  1. Sep 2019 The High Court dismissed Edward Bridges challenge to South Wales Police use of live facial recognition. libertyhumanrights.org.uk
  2. Aug 2020 The Court of Appeal ruled South Wales Police live facial recognition unlawful, the first successful legal challenge to the technology in the UK. The case was backed by the civil liberties group Liberty. libertyhumanrights.org.uk
  3. May 2022 The ICO fined Clearview AI over 7.5 million pounds and ordered it to delete UK residents data. time.com
Aug 2020 (approx.) Facial recognition Sourceslibertyhumanrights.org.uktime.com

United Kingdom

Restricted

In Catt v. the United Kingdom (January 2019) the European Court of Human Rights held that police violated the privacy of John Catt -- a lifelong peace activist in his 90s with no history of violence -- by retaining detailed records of his attendance at protests on a national police 'domestic extremism' database. The Court found the collection may have been justified but the open-ended retention, with no clear definition of 'domestic extremism' and no time limits, was not -- a significant check on the surveillance of peaceful protest.

Jan 2019 Police intelligence database Source →

United Kingdom

Restricted

In S. and Marper v. the United Kingdom (Grand Chamber, December 2008) the European Court of Human Rights unanimously ruled that the blanket, indefinite retention of DNA samples, cellular samples and fingerprints of people arrested but never convicted violated the right to privacy under Article 8. The two applicants from Sheffield had been arrested and then cleared, yet police kept their biometric data forever. The landmark ruling forced the UK to overhaul its DNA database; the Court reaffirmed it in Gaughran v. UK (2020), striking down indefinite biometric retention even for a minor conviction.

Dec 2008 DNA & fingerprint retention Source →

Wrongful stops & data misuse

Met expands permanent facial recognition to the West End

Data misuse

In June 2026 Metropolitan Police Commissioner Sir Mark Rowley announced the most significant expansion of live facial recognition in London to date: static LFR cameras mounted on street furniture across the West End and Soho by the end of 2026, meant to grow into a citywide infrastructure programme rather than time-limited van operations. It followed a six-month Croydon pilot (October 2025 to March 2026, 24 operations, 173 arrests, more than 470,000 faces scanned) and an April 2026 High Court ruling that the Met's LFR policy was lawful, now under appeal. Big Brother Watch urged the force to stop until Parliament legislates, noting the UK still has no specific statutory framework for LFR.

UK plugs its plate-reader network into EU-wide Prum sharing

Data misuse

In June 2026 the UK Home Office switched on number-plate checks through the EU's Prum data-sharing framework, letting officers query overseas-registered vehicles across EU member states and get vehicle-keeper details back in about ten seconds instead of days or months. It bolts cross-border reach onto Britain's already vast plate-reader system -- commonly cited at around 11,000 ANPR cameras reading roughly 50 million plates a day into the National ANPR Data Centre, where records are retained for a year. The government framed the link-up around border security, illegal migration and organised crime.

Jun 2026 Source →

80,000 protesters scanned; a worker wrongly flagged

Data misuse

London's Metropolitan Police scanned the faces of about 80,000 people at a single protest and have run live facial recognition against millions of faces. Youth worker Shaun Thompson was wrongly flagged, detained, and threatened with arrest before being compensated. Campaigners call it stop and search on steroids.

Wrongly flagged by live facial recognition

Wrongful stop

London's Metropolitan Police scan millions of faces with live facial recognition. Youth worker Shaun Thompson was wrongly flagged in 2024, then stopped, detained, fingerprinted, and threatened with arrest over a false match. At one 2025 sporting event South Wales Police logged 2,470 alerts, 92 percent of them false, and the equality watchdog found the Met system disproportionately flags Black men.

Feb 2024 Source →

Supermarkets built secret facial-recognition blacklists of shoppers

Data misuse

British retailers including Southern Co-op, Home Bargains and Mike Ashley's Frasers Group deployed Facewatch live facial recognition to scan shoppers entering stores and match them against private watchlists of suspected offenders. After a 2022 Big Brother Watch complaint, the ICO concluded in March 2023 that Facewatch's processing had breached data-protection law on multiple principles, forcing an overhaul; campaigners say people were blacklisted over trivial accusations and, in cases like a teenager wrongly flagged at Home Bargains in 2024, misidentified and publicly accused.

ICO fines Clearview, orders deletion

Data misuse

The UK Information Commissioner's Office fined Clearview AI 7.5 million pounds in 2022 and ordered it to delete UK residents' data; after a tribunal initially overturned the action on jurisdiction, an appeals tribunal restored the regulator's authority in 2025.

Facial recognition paused in Scottish school canteens

Data misuse

In October 2021 nine schools in North Ayrshire, Scotland switched on facial recognition to take payment in their canteens, scanning pupils' faces instead of fingerprints or cards. After public and regulatory backlash the ICO intervened, urging the schools to use a less intrusive method, and the rollout was paused -- an early flashpoint over normalising biometric identification of children for everyday transactions.

Oct 2021 Source →

Court rules police face recognition unlawful

Data misuse

A UK Court of Appeal ruling in Bridges v South Wales Police found the force's live facial recognition unlawful. Its AFR Locate system scanned up to 50 faces per second against watchlists that could include anyone, with images drawn even from social media, breaching privacy, data-protection, and equality law.

Aug 2020 Sourcessimmons-simmons.comeff.org

Wrongful stops from number-plate misreads

Wrongful stop

Britain runs one of the world's largest automatic number-plate recognition networks, reading tens of millions of plates a day into a database of more than 20 billion records. The official surveillance camera commissioner warned that even at a claimed 97 percent accuracy the system misreads hundreds of thousands of plates a day, that police hold no meaningful data on its accuracy, and that misreads and cloned plates have led to wrongful stops and arrests of innocent motorists.

Jan 2018 Source →

'Ring of steel' tracked every car in and out of a town

Data misuse

Hertfordshire police ringed the small town of Royston with ANPR cameras, logging every vehicle entering or leaving. After complaints by Big Brother Watch, Privacy International, and No CCTV, the UK data regulator ruled the scheme unlawful and excessive and ordered it halted.

Jul 2013 Sourcestheregister.comedri.org

A national plate-reader network built without debate

Data misuse

The UK runs one of the world's largest ANPR networks, feeding a central database, yet it was constructed by police without any parliamentary debate or public consultation, and privacy regulators warned the blanket approach may be unlawful.

Jan 2013 Sourcesedri.orgtechdirt.com
Africa 21
Algeria 1

Algeria opened a Pegasus inquiry

Data misuse

After the Pegasus Project, Algeria's public prosecutor ordered an investigation into reports the country was targeted, and Citizen Lab detected suspected infections there.

Botswana 1

Predator spyware shipments

Data misuse

Import records tied Botswana's Directorate of Intelligence and Security to shipments of Intellexa Predator spyware in 2023, the first identification of the tool's use in the country.

2023 Source →
Egypt 2

Politician doubly infected with spyware

Data misuse

Egypt is a documented user of Predator spyware; in one case the phone of an exiled Egyptian politician was found simultaneously infected with both Predator and Pegasus, run by two different government clients.

2021 Source →

DPI middleboxes injected Predator spyware

Data misuse

Telecom Egypt used Sandvine PacketLogic deep-packet-inspection middleboxes to inject Intellexa's Predator spyware into the connection of opposition presidential candidate Ahmed Eltantawy, alongside mass web-monitoring and news censorship; the US added Sandvine to its Entity List in 2024.

Ethiopia 1

Spyware used against Ethiopian diaspora journalists

Data misuse

Ethiopian diaspora journalists at the ESAT broadcaster were targeted with Hacking Team's Remote Control System and Gamma's FinSpy spyware, documented by Citizen Lab.

Jul 2015 Sourcescitizenlab.cablog.sekoia.io
Kenya 3

Kenya

Removed

The strongest Worldcoin outcome anywhere: declared illegal, and the data destroyed under supervision. On May 5, 2025 the Nairobi High Court (Justice Aburili Roselyne) ruled that Tools for Humanity -- the Sam Altman-cofounded operator of Worldcoin -- violated Kenya's Data Protection Act by collecting iris and facial biometrics without valid consent and without a data protection impact assessment. The court's core finding travels: consent obtained by paying people -- 25 WLD tokens, roughly $50-55, in a market where that money matters -- is not free, informed consent. The case was brought by the Katiba Institute after the 2023 Nairobi rollout drew queues long enough that the government suspended operations on public-safety grounds. The court gave the company seven days to delete everything under Office of the Data Protection Commissioner supervision, and in Jan 2026 the ODPC confirmed all Kenyan biometric data had been permanently erased. Counsel Joshua Malidzo Nyawa called it a win for privacy rights. The contrast is part of the record: the same month Kenya's court ruled the model unlawful, World launched sign-ups in six US cities.

May 2025 Worldcoin iris scanning Sourcesiclg.combusinessdailyafrica.comtech-ish.com

Data misuse

Court declared the biometric ID rollout illegal

Data misuse

Kenya collected the fingerprints and facial images of tens of millions of people for its Huduma Namba (NIIMS) biometric ID before passing a data-protection law. The High Court declared the rollout illegal for skipping a privacy-risk assessment, and the successor Maisha Namba system faces similar criticism.

Suspected Pegasus operator in Kenya

Data misuse

Citizen Lab detected suspected Pegasus infections linked to an operator in Kenya.

Sep 2018 Source →
Morocco 1

Morocco named a top Pegasus user targeting journalists and leaders

Data misuse

The 2021 Pegasus Project named Morocco as one of the heaviest users of NSO's spyware, with around ten thousand numbers selected. They included Moroccan journalists such as Omar Radi, who was later jailed, as well as foreign figures, among them French President Emmanuel Macron and several of his ministers. Morocco denied buying or using Pegasus and sued the journalists and Amnesty International for defamation.

Nigeria 2

Biometric ID breaches exposed citizens' data

Data misuse

Nigeria's biometric National Identification Number system, tied to SIM and bank registration, has suffered data breaches exposing citizens' personal records, alongside exclusion of those unable to enroll.

Jan 2024 Source →

Hacking Team spyware client in Nigeria

Data misuse

Nigerian government bodies were among the clients of Hacking Team's Remote Control System spyware revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcesblog.sekoia.iocitizenlab.ca
Rwanda 1

Pegasus targeting of dissidents abroad

Data misuse

Rwanda was named among Pegasus operators, with targets including the daughter and nephew of Hotel Rwanda figure Paul Rusesabagina; the leaked list also flagged South Africa's president as a possible Rwandan target.

2021 Source →
Senegal 1

National digital-ID system breached, biometric data stolen

Wrongful stop

In January 2026 a threat actor calling itself the Green Blood Group claimed to have breached Senegal's national digital-ID system and exfiltrated about 139 terabytes of data, including biometric records -- a stark illustration of the privacy risk when governments centralize biometric identity.

Jan 2026 Source →
South Africa 2

Blocked national IDs cut people off from services

Data misuse

In South Africa, the Home Affairs department's practice of blocking national IDs left many people unable to access banking, grants, and services, prompting legal challenges over the harms of digital identity systems.

Jan 2023 Source →

Suspected Pegasus operator in South Africa

Data misuse

Citizen Lab detected suspected Pegasus infections in South Africa.

Sep 2018 Source →
Tunisia 1

Suspected Pegasus operator in Tunisia

Data misuse

Citizen Lab detected suspected Pegasus infections linked to an operator in Tunisia.

Sep 2018 Source →
Uganda 3

Mandatory biometric ID excludes the elderly

Data misuse

Uganda's mandatory Ndaga Muntu biometric national ID has been challenged by civil-society groups for excluding elderly people from welfare benefits and blocking women's access to healthcare, amid wider use of biometrics to monitor dissent.

Huawei facial recognition turned on the opposition

Data misuse

Uganda built a Huawei Safe City network of facial-recognition cameras across Kampala. A 2019 Wall Street Journal investigation found Huawei technicians helped state agents crack the encrypted communications of opposition leader Bobi Wine, leading to his arrest, and police later confirmed using the cameras to track people detained during anti-government protests. Opposition figures call it a tool to hunt and persecute critics.

Aug 2019 Source →

Huawei face cameras blanket Kampala

Data misuse

Uganda installed a 126 million dollar Huawei facial-recognition camera system across the capital, Kampala, which the president framed as a tool to fight street crime. Opposition figures said the real aim was to deter and identify protesters against an increasingly unpopular government.

Aug 2019 Source →
Zambia 1

Suspected Pegasus operator in Zambia

Data misuse

Citizen Lab detected suspected Pegasus infections linked to an operator in Zambia.

Sep 2018 Source →
Zimbabwe 1

Chinese facial recognition for mass surveillance

Data misuse

From 2018 Zimbabwe acquired facial-recognition technology from CloudWalk and Hikvision for border control and mass surveillance, with citizens' biometric data sent back to the Chinese vendors.

2018 Source →
Asia 52
Armenia 1

Predator spyware customer

Data misuse

Armenia was identified by Citizen Lab as a Predator spyware customer, part of a cluster of governments deploying the Cytrox tool against phones alongside the better-known Pegasus.

2021 Source →
Azerbaijan 2

Pegasus used against journalists

Data misuse

Azerbaijan was identified as a Pegasus operator with around 48 journalists selected for targeting, including OCCRP investigative reporter Khadija Ismayilova, whose phone was infected for nearly three years, and Meydan TV freelancer Sevinc Vaqifqizi.

DPI gear powered social-media blackouts

Data misuse

Sandvine and Allot deep-packet-inspection equipment was deployed in Azerbaijan to impose social-media blackouts during periods of unrest.

Bahrain 1

Zero-click hacking of activists

Data misuse

Bahraini human-rights activists were hacked with Pegasus in zero-click attacks that defeated new Apple protections, part of the Gulf state's documented use of commercial spyware against dissidents.

Bangladesh 1

Suspected Pegasus operator in Bangladesh

Data misuse

Citizen Lab detected suspected Pegasus infections in Bangladesh, where authorities have acquired a range of phone interception and surveillance systems.

Sep 2018 Source →
China 4

Face scans track the Uyghur population

Data misuse

In Xinjiang, authorities use facial recognition to monitor the mostly Muslim Uyghur population, with face scans required to enter shops, hotels, and stations and tens of thousands of cameras in Urumqi alone. Leaked police files showed Hikvision systems used to screen all 23 million residents and flag people with overseas ties for arrest.

Face recognition built to sort people by ethnicity

Data misuse

Chinese authorities, working with surveillance firms including Hikvision, Dahua, and Uniview, drew up facial-recognition standards that sort people by traits such as ethnicity and skin color, which researchers warned opened wide scope to target minorities like the Uyghurs at scale.

Plate and vehicle tracking refined on Uyghurs

Data misuse

Hikvision, the world's largest maker of plate readers and surveillance cameras, refined vehicle and face tracking in Xinjiang, where checkpoints and cameras monitor Uyghurs' movements. Those battle-tested systems are now exported worldwide.

Biometric dragnet over Uyghurs and Turkic Muslims

Data misuse

China has built a pervasive biometric surveillance system across Xinjiang to control Uyghurs and other Turkic Muslims, combining facial-recognition checkpoints, mandatory collection of iris scans and DNA, and a predictive-policing platform that flags ordinary behavior as suspicious. It has funneled people into a network of detention camps that a 2022 UN report said may amount to crimes against humanity, with up to a million held.

Jan 2017 Source →
Hong Kong 1

Protesters tear down face-scanning smart lampposts

Data misuse

During the 2019 pro-democracy protests, Hong Kongers wore masks and carried umbrellas and tore down 'smart lampposts' in Kowloon, fearing they held facial recognition that could identify demonstrators and expose them to arrest. Police had access to AI able to match faces from video to databases, and the fear of being identified kept some people away from the streets.

Aug 2019 Sourcesscmp.comcnn.com
India 4

India

Contesting

After reports that about 300 Indian numbers, including those of journalists, opposition politicians, and activists, appeared in the leaked Pegasus list, the Supreme Court appointed an independent expert committee in October 2021 to investigate alleged government use of the spyware. The committee said the government did not cooperate, and its findings remain sealed.

Oct 2021 Pegasus (NSO Group) Source →

Data misuse

Facial recognition used to identify protesters

Data misuse

Delhi police used facial recognition to identify and arrest people from the 2020 anti-CAA protests and the communal riots that followed, later saying scores of the riot arrests were traced by the technology, and turned it on Sikh farmers during the 2021 farmers' protests. Rights groups documented its disproportionate use against Muslims and other minorities and a chilling effect on the right to protest.

Feb 2020 Source →

Face recognition aimed hardest at Muslims

Data misuse

Delhi police rolled out facial recognition that researchers found would inevitably fall hardest on the city's Muslim community, and used it to identify protesters, with much of the deployment kept under wraps.

Jan 2020 Source →

World's largest biometric ID raises exclusion fears

Data misuse

India's Aadhaar program enrolled the biometrics of more than 1.3 billion people into the central CIDR database. Civil-society groups warn it drives surveillance and exclusion; India's Supreme Court recognized privacy as a fundamental right in 2017 and curbed mandatory Aadhaar use in 2018.

Indonesia 2

Indonesia

Paused

Indonesia suspended World (formerly Worldcoin) and World ID in May 2025 after public complaints, with the Ministry of Communication and Digital pausing the operator's permit as what its director general for digital supervision, Alexander Sabar, called a preventative measure to mitigate risks to the public. The ministry's investigation gave the suspension its edge: officials said retina data had been collected from Indonesians since 2021, while the local operator only registered as a foreign electronic system provider in 2025 -- four years of collection before the paperwork existed. The app had been offering people between Rp200,000 and Rp800,000 for scans. Two local entities were put under investigation over licensing and unlawful operations.

May 2025 Worldcoin iris scanning Sourcesbiometricupdate.comen.tempo.co

Data misuse

Predator spyware customer

Data misuse

Indonesia was documented as a Predator spyware customer, one of several governments Citizen Lab linked to the Cytrox surveillance tool used against people of interest.

2021 Source →
Iran 3

Face recognition installed to catch unveiled students

Data misuse

Iranian authorities installed facial recognition at Amirkabir University of Technology in Tehran to identify and penalize women students who removed their headscarves, part of a wider rollout of cameras and drones to enforce hijab laws.

An app flags cars when a woman inside is unveiled

Data misuse

Iran's police run a phone app, Nazer, that lets officers and vetted civilians flag a vehicle's license plate when a woman inside is unveiled. The system sends the owner an automatic warning and then impounds the car. Amnesty documents hundreds of thousands of vehicles confiscated since 2023, and the app was later extended to taxis, ambulances, and buses.

Surveillance enforcing mandatory hijab

Data misuse

Iran uses facial recognition, road cameras, drones, and a citizen-reporting app to enforce mandatory hijab rules on women. A 2025 UN fact-finding mission documented facial recognition installed at a Tehran university gate to catch uncovered students, and metro screens in Mashhad displaying passengers' faces, age, and gender to frighten women out of defiance.

Sep 2022 Source →
Iraq 1

Suspected Pegasus operator in Iraq

Data misuse

Citizen Lab detected suspected Pegasus infections linked to an operator in Iraq.

Sep 2018 Source →
Israel 3

Israel

Restricted

After the Pegasus revelations and the US blacklisting of NSO Group and Candiru, Israel's Defense Ministry cut the list of countries its cyber firms may sell surveillance and hacking tools to from 102 to 37 in November 2021, dropping clients with poor rights records such as Morocco, Mexico, Saudi Arabia, and the UAE, and reportedly revoked thousands of export licenses over the following year. It is a rare case of the source country reining in its own spyware industry.

Nov 2021 NSO Group, Candiru Source →

Data misuse

Red Wolf tracks Palestinians at checkpoints

Data misuse

In the occupied West Bank city of Hebron, an Israeli military facial-recognition system called Red Wolf scans Palestinians at checkpoints and enrolls their faces into surveillance databases without consent, deciding who may pass. Amnesty International's 2023 Automated Apartheid report documented how it automates movement restrictions and tracks residents, and how soldiers were rewarded for registering as many Palestinians as possible.

May 2023 Source →

Cameras track Palestinians' cars by plate

Data misuse

Israeli surveillance cameras in occupied East Jerusalem capture license plates on fixed and moving vehicles, feeding a database of Palestinians that records plates, permits, and addresses, restricting Palestinians' movement within their own neighborhoods. Researchers identified Hikvision and TKH cameras in the network.

May 2023 Sourcesamnesty.orgmei.edu
Japan 1

A secretive national plate-reading network since the 1980s

Data misuse

Japan's National Police Agency has run the secretive N-System since the late 1980s, reading and recording license plates at hundreds of sites on highways and major roads, including a ring around Tokyo's Kabukicho district. Police disclose little about how long the data is kept or how it is used, and privacy advocates call it part of an emerging surveillance society.

Jan 1987 Sourcescsmonitor.comubisurv.net
Jordan 2

Journalists and rights workers hacked

Data misuse

Pegasus was used against at least 16 Jordanian journalists and activists, including two Human Rights Watch staff and a Palestinian-American reporter hacked three times, many of whom had covered a teachers' strike the government crushed.

2023 Source →

DPI used to censor an LGBTQ website

Data misuse

In Jordan, Sandvine equipment was used to censor an LGBTQ news website.

Kazakhstan 2

Allot DPI throttled Telegram before a blackout

Data misuse

Allot's deep-packet-inspection technology was used in Kazakhstan to throttle Telegram and other platforms ahead of a January 2021 nationwide internet blackout.

Jan 2021 Source →

Civil society activists targeted

Data misuse

Four Kazakh civil society activists were confirmed targets of Pegasus, part of the leaked list of tens of thousands of phone numbers selected by NSO Group government clients.

2021 Source →
Kuwait 1

Suspected Pegasus operator in Kuwait

Data misuse

Citizen Lab detected suspected Pegasus infections linked to an operator in Kuwait.

Sep 2018 Source →
Kyrgyzstan 1

Suspected Pegasus operator in Kyrgyzstan

Data misuse

Citizen Lab detected suspected Pegasus infections in Kyrgyzstan.

Sep 2018 Source →
Lebanon 1

Officials and journalists on Pegasus list

Data misuse

Phone numbers of senior Lebanese figures appeared on the Pegasus list, including the president, a former prime minister, ministers, security chiefs, and numerous journalists and ambassadors, according to the Pegasus Project.

2021 Source →
Malaysia 1

Hacking Team spyware client in Malaysia

Data misuse

Malaysian agencies were among the clients of Hacking Team's Remote Control System spyware revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcesblog.sekoia.iocitizenlab.ca
Mongolia 1

Predator spyware infrastructure

Data misuse

Mongolia appeared among the governments linked to Intellexa's Predator spyware in the Predator Files, with Amnesty International documenting infrastructure associated with the tool.

2023 Source →
Myanmar 1

Junta expands Chinese safe-city cameras

Data misuse

Myanmar's military junta expanded Chinese-supplied safe-city camera networks with facial recognition across cities, raising fears of tracking dissidents after the 2021 coup.

Oman 1

Predator spyware customer

Data misuse

Oman was documented as a Predator spyware customer by Citizen Lab, adding a Gulf state to the list of governments using the Cytrox tool against targets of interest.

2021 Source →
Pakistan 1

Pegasus and the leaked target list

Data misuse

The phone number of then prime minister Imran Khan appeared on the leaked Pegasus target list, and Citizen Lab detected suspected Pegasus infections in Pakistan.

Philippines 2

Philippines

Paused

The Philippines' National Privacy Commission ordered Tools for Humanity to immediately halt operations in Oct 2025, citing consent failures and the exploitation of vulnerable populations -- the regulator saying out loud what the token model implies: the program's growth ran through people for whom the payout was the point. The Philippine order made it the fourth Asia-Pacific jurisdiction to stop the program in a single year, after Indonesia's suspension and amid continuing scrutiny in Hong Kong, and it landed while the company was signing identity-verification partnerships with Tinder, Zoom and Docusign in the US -- the same biometric network regulators were halting abroad being sold as fraud protection at home.

Oct 2025 Worldcoin iris scanning Source →

Data misuse

Predator spyware customer

Data misuse

A Predator spyware customer assessed as highly likely linked to the Philippines was identified by Recorded Future, the first time the tool's use was tied to the country.

2024 Source →
Qatar 1

Suspected Pegasus operator in Qatar

Data misuse

Citizen Lab detected suspected Pegasus infections linked to an operator in Qatar.

Sep 2018 Source →
Saudi Arabia 1

Pegasus around the Khashoggi killing

Data misuse

Saudi Arabia used Pegasus against people close to murdered journalist Jamal Khashoggi, including an exiled dissident friend and his fiancee, whose phone was infected days after his 2018 killing.

2018 Source →
Singapore 1

Suspected Pegasus operator in Singapore

Data misuse

Citizen Lab detected suspected Pegasus infections in Singapore.

Sep 2018 Source →
South Korea 2

Police ran face recognition on CCTV and web images

Data misuse

South Korean police tracked suspects with Videmo 360 facial recognition software, analyzing images pulled from CCTV and the internet, in a case that raised concerns over the legality of the surveillance.

Jan 2021 Source →

Hacking Team spyware client in South Korea

Data misuse

South Korea's National Intelligence Service was a client of Hacking Team's Remote Control System spyware, revealed by the 2015 breach and sparking domestic controversy.

Jul 2015 Sourcescitizenlab.cablog.sekoia.io
Sri Lanka 1

Chinese-supplied facial recognition surveillance

Data misuse

Sri Lanka received Chinese-made AI surveillance and facial-recognition technology as part of Huawei and partner safe-city deployments.

Syria 1

Blue Coat and Sandvine gear filtered the internet

Data misuse

Syria's telecom authority deployed deep-packet-inspection equipment, including Blue Coat and Sandvine gear, to filter and censor the internet and redirect users to malicious sites during the civil war.

Thailand 2

Thailand

Contesting

Pro-democracy activist Jatupat Boonpattararaksa, whose phone was infected with Pegasus three times in 2021, sued NSO Group in the Bangkok Civil Court. Amnesty International filed an expert brief in the case in September 2024, part of a wider effort to hold the spyware industry accountable in Thai courts.

Sep 2024 Pegasus (NSO Group) Source →

Data misuse

Pegasus on pro-democracy protesters

Data misuse

Forensic analysis confirmed Pegasus on the phones of at least 30 Thai pro-democracy protesters, academics, and rights defenders during the 2020 to 2021 mass demonstrations, the first confirmed use of the spyware in the country.

2021 Source →
Turkiye 2

Pegasus infections tied to Khashoggi targeting

Data misuse

Citizen Lab detected suspected Pegasus infections in Turkey, where associates of murdered journalist Jamal Khashoggi were among those targeted.

Sep 2018 Source →

DPI redirected users to government spyware

Data misuse

Citizen Lab's 2018 Bad Traffic report found Sandvine PacketLogic devices on Turkey's network redirecting hundreds of users to malicious sites that delivered government spyware, alongside blocking of political and news content.

United Arab Emirates 1

Early heavy use against dissidents

Data misuse

The UAE was an early and heavy Pegasus user, targeting activist Ahmed Mansoor with a zero-day exploit in 2016 and later the ex-wife and associates of Dubai's ruler, part of one of the most extensive deployments of the spyware.

Vietnam 1

Predator aimed at EU lawmakers

Data misuse

Vietnam deployed Predator spyware against targets including members of the European Parliament and used commercial spyware against bloggers, part of a broad surveillance campaign accompanying its jailing of online critics.

2023 Source →
Yemen 1

Suspected Pegasus operator in Yemen

Data misuse

Citizen Lab detected suspected Pegasus infections in Yemen.

Sep 2018 Source →
Oceania 9
Australia 6

Australia

Restricted

Australia privacy regulator, the OAIC, ruled Clearview AI breached privacy law by scraping Australians images and ordered it to stop and delete the data. In 2024 the regulator also found retailer Bunnings breached privacy by running in-store facial recognition on hundreds of thousands of shoppers, a finding a tribunal later softened in part on appeal.

  1. Nov 2021 The OAIC found Clearview AI breached the Privacy Act by scraping Australians faces and ordered it to stop collecting and to delete the data. theconversation.com
  2. Nov 2024 The Privacy Commissioner ruled Bunnings breached privacy by running facial recognition on shoppers across more than 60 stores, and ordered it to stop and destroy the data. oaic.gov.au
  3. Feb 2026 A review tribunal upheld the notification and governance breaches but found Bunnings could use the technology for the limited purpose of fighting serious retail crime. The Commissioner did not appeal. oaic.gov.au
Nov 2024 (approx.) Facial recognition Sourcesoaic.gov.autheconversation.com

Australia (Bunnings)Australia

Removed

Australia's Privacy Commissioner ruled on Nov 19, 2024 that Bunnings -- the country's biggest home-improvement chain -- breached privacy law by running facial recognition on likely hundreds of thousands of customers across 62-63 stores in New South Wales and Victoria between Nov 2018 and Nov 2021, without consent and without telling anyone. The system compared every entering face against a database of people flagged for past crime or violent behaviour, deleting non-matches automatically -- and Commissioner Carly Kind's finding is the one that travels: efficient and well-intentioned does not mean lawful, because the technology interfered with the privacy of everyone who walked in, not just the flagged. The orders after a two-year investigation: stop, never repeat, destroy all retained personal and sensitive data after 12 months, and publish a public statement of the mishandling within 30 days. No fine was imposed. Bunnings called itself deeply disappointed, released CCTV of staff being assaulted in its defence, and is seeking Administrative Review Tribunal review -- so the orders stand but the fight continues. Pinned at Melbourne (company HQ) as a national-chain convention.

Nov 2024 (approx.) Retail facial recognition Sourcesitnews.com.autherecord.mediatheconversation.com

Australia (The Good Guys)Australia

Paused

Electronics chain The Good Guys, owned by JB Hi-Fi, paused its facial-recognition trial in Jun 2022 within a day of consumer group CHOICE naming it in a complaint to the Office of the Australian Information Commissioner -- the complaint called the use unreasonably intrusive and potentially unlawful, and named Bunnings and Kmart alongside it. The company said it was confident it had complied with the law and paused anyway pending OAIC clarification, which is the point of recording it: the pause came from a consumer-group complaint and press attention, before any regulator ruled. The three chains named in that one complaint ran to about A$25 billion in annual sales across 800 stores; the Bunnings arm of it produced the landmark 2024 determination. Pinned at Melbourne as a national-chain convention.

Jun 2022 Retail facial recognition Source →

Australia (7-Eleven)Australia

Removed

The Australian Information Commissioner ordered the 7-Eleven chain in 2021 to destroy the faceprints it had collected at roughly 700 convenience stores -- gathered through iPads set up to run customer feedback surveys, which photographed the faces of the people filling them in. A survey tablet doubling as a biometric collector is the detail that makes this record generalise: the collection surface was disguised as something mundane, and nobody tapping a satisfaction screen understood they were being faceprinted. The destruction order made 7-Eleven an early marker in what became the OAIC's retail-biometrics line -- the same regulator ordered Clearview AI to destroy Australian data and stop scraping the same year, and reached the landmark Bunnings determination in 2024. Date marked approximate: sourced reporting places the order in 2021 without a confirmed day. Pinned at Melbourne as a national-chain convention.

Oct 2021 (approx.) Retail facial recognition Source →

Data misuse

Privacy Act breach, deletion ordered

Data misuse

Australia's information commissioner found in 2021 that Clearview AI breached the Privacy Act by scraping residents' faces without consent and ordered it to stop and delete the data; a tribunal upheld the ruling in 2023.

Statewide plate-reader fleet, pushed to police borders

Data misuse

Every Australian state runs plate readers. New South Wales' mobile MANPR fleet scans every passing vehicle statewide, storing hundreds of thousands of records a day, and was pushed to profile drivers at closed state borders during COVID lockdowns. The Australian Privacy Foundation calls ANPR a mass-surveillance technique that breaches freedom of movement.

Sep 2020 Sourcesmals.auprivacy.org.au
New Zealand 3

New Zealand

Paused

New Zealand Police secretly trialed Clearview AI in 2020 without sign-off from the Police Commissioner, the Privacy Commissioner, or Cabinet. After the trial was exposed and halted, an independent review led police to commit not to use live facial recognition until its privacy, legal, and ethical impacts are understood.

  1. May 2020 Reporting revealed police had secretly trialed Clearview AI without authorization. The trial was halted and the Police Commissioner ordered a stocktake of surveillance tools. rnz.co.nz
  2. Dec 2021 An independent review prompted police to halt plans for live facial recognition, with police stating they will not use it until the impacts are fully understood. rnz.co.nz
May 2020 Facial recognition Sourcesrnz.co.nzrnz.co.nz

Data misuse

Police tap a private plate network half a million times a year

Data misuse

New Zealand police query Auror, an Auckland retail-crime ANPR platform, hundreds of times a day -- around half a million times a year -- with thousands of officers able to access it without stating a reason. Defence lawyers challenging it in the Court of Appeal call it 'surveillance capitalism.'

Sep 2025 Sourcesrnz.co.nznzherald.co.nz

Police faked reports to track people with plate cameras

Data misuse

Just a month after the Privacy Commissioner warned police to do better on plate cameras, a detective pretended a car was stolen so they could track it, and officers filed a false report to use ANPR to track women linked to a Northland lockdown breach.

Jul 2021 Source →
Other 12
Angola 1

Predator spyware infrastructure

Data misuse

Angola was identified in the Predator Files as a likely customer of Intellexa's Predator spyware, with Amnesty International finding technical infrastructure tied to the tool active in the country.

2023 Source →
Cote d'Ivoire 1

Suspected Pegasus operator in Ivory Coast

Data misuse

Citizen Lab detected suspected Pegasus infections linked to an operator in Ivory Coast (Cote d'Ivoire).

Sep 2018 Source →
Eritrea 1

Closed state supplied with DPI gear

Data misuse

Eritrea, one of the world's most closed states, was among the authoritarian governments supplied with Sandvine deep-packet-inspection equipment for internet control.

Libya 2

Suspected Pegasus operator in Libya

Data misuse

Citizen Lab detected suspected Pegasus infections linked to an operator in Libya.

Sep 2018 Source →

Amesys Eagle system enabled mass interception

Data misuse

Under Muammar Gaddafi, Libya deployed the French company Amesys's Eagle system for nationwide internet interception and mass surveillance of dissidents; French magistrates later charged Amesys executives over complicity in torture.

Madagascar 1

Predator spyware customer

Data misuse

Madagascar was named among the government customers of Predator spyware identified by Citizen Lab, part of a growing roster of states buying commercial surveillance tools.

2021 Source →
Palestine 2

Soldiers scan Palestinians' faces at checkpoints

Data misuse

Israeli soldiers in Hebron use face-scanning cameras, known as Red Wolf, to identify Palestinians at checkpoints without checking IDs, feeding a database used to control their movement. Amnesty calls it automated apartheid.

May 2023 Sourcesamnesty.orgmei.edu

Pegasus used against Palestinian rights defenders

Data misuse

Citizen Lab detected suspected Pegasus infections in Palestine, where Palestinian human rights defenders were later confirmed to have been hacked.

Sep 2018 Source →
Sudan 1

Predator spyware infrastructure

Data misuse

Sudan was among the countries where Amnesty International found technical infrastructure linked to Intellexa's Predator spyware in the Predator Files investigation.

2023 Source →
Tajikistan 1

Suspected Pegasus operator in Tajikistan

Data misuse

Citizen Lab detected suspected Pegasus infections linked to an operator in Tajikistan.

Sep 2018 Source →
Togo 1

Pegasus against critics and clergy

Data misuse

Togo appeared among NSO Group's Pegasus clients in the Pegasus Project, which documented the spyware being used against journalists, opposition figures, and members of the clergy critical of the government.

2021 Source →
Uzbekistan 1

Suspected Pegasus operator in Uzbekistan

Data misuse

Citizen Lab detected suspected Pegasus infections linked to an operator in Uzbekistan.

Sep 2018 Source →

What counts, and what does not

This map is deliberately narrow. The big deployment trackers, like DeFlock and the EFF Atlas of Surveillance, map where the cameras are. This one maps where communities decided they did not want them: a council vote to terminate a contract, a moratorium pending review, a proposed system voted down, or an expansion rejected. Each entry is tied to a primary or reputable secondary source, and is verified before it goes on the map rather than added from memory.

Know of a community that removed, paused, denied, or restricted ALPRs and is not here yet? Send a sourced article and it will be reviewed.

Most shared

Top 5 surveillance stories

The most-shared reporting on license-plate readers and police surveillance right now.

  1. 1 LAPD lets its Flock Safety contract expire over privacy concerns The LAPD let its three-year agreement with Flock Safety lapse over civil-liberties and privacy concerns and is renegotiating narrower terms -- the largest U.S. department yet to step back from the ALPR network. ABC7 Los Angeles Jul 2026
  2. 2 GBI arrests five former Albany officers for misusing Flock license-plate data Five former Albany, GA officers were arrested for running unauthorized Flock searches -- the first charges out of Flock's own audit-assistance program, amid a wider Georgia wave of misuse cases. Georgia Bureau of Investigation Jul 2026
  3. 3 Flock Safety crosses 100,000 cameras as 53 cities cancel over federal data access License-plate-reader data routed to ICE and federal agencies without cities' authorization triggered a wave of cancellations, lawsuits, and a constitutional fight over ALPR mass surveillance. Tech Times Jun 2026
  4. 4 Framingham police won't renew Flock contract after months of resident opposition After sustained privacy and data-sharing concerns raised at public meetings, the city let its ALPR contract lapse. Boston.com Jun 2026
  5. 5 ACLU: Flock Safety repeatedly lied to city councils, police, and the public After Oshkosh caught the company misrepresenting its 'heat map' tracking, the ACLU documented a pattern of misleading statements. ACLU Jun 2026

Want your town on this map?

Here is how communities get the cameras out

Every removal on this map started with a few residents who learned how the contract worked and showed up. We put together a plain-language guide to starting that process where you live, who to contact, and what has actually worked.

Read the take-action guide →