What happened
noyb has filed a lawsuit against the Hamburg Data Protection Authority, alleging that the authority has failed to act on illegal biometric data processing by PimEyes. The DPA considers PimEyes' facial recognition practices illegal but claims inaction due to the company's alleged location in Dubai. The case highlights enforcement challenges for GDPR violations involving cross‑border biometric data.
Why it matters for trust and compliance
- Its status is filed. The case is still open; the outcome may change what it means.
- The suit underscores gaps in GDPR enforcement when controllers operate from third countries and process biometric data.
- It relates to GDPR. The regulations library explains what that law requires.
Who is affected
technology controller data broker PimEyes Hamburg Data Protection Authority noyb
Recommended actions
- Check that privacy notices describe the practices this addresses.
- Revisit retention schedules and data minimisation for the data involved.
- Review the transfer mechanisms relied on for affected data flows.
- Inventory AI or automated decision systems in scope and their assessments.
- Confirm handling of sensitive data categories meets the stricter rules.