{
  "node_id": "eu-ai-act-prohibited-facial-scraping",
  "title": "EU AI Act - Prohibition on Untargeted Scraping of Facial Images to Create Facial Recognition Databases (Article 5(1)(e))",
  "domain": "AI Governance & Law",
  "version": "1.0.0",
  "last_updated": "2026-04-28",
  "bluf": "EU AI Act (Regulation 2024/1689) Article 5(1)(e) prohibits AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage; applicable from 2 February 2025 per Article 113; the prohibition targets the data collection and database building practice rather than the use of existing lawfully assembled facial recognition databases - it specifically prohibits the creation or expansion of such databases through mass untargeted harvesting of facial images from publicly accessible online sources or physical surveillance infrastructure; 'untargeted scraping' means the mass collection of facial images without a specific individual identification target - collecting billions of facial images from social media, news archives, public websites, or CCTV footage to build a general-purpose facial recognition training dataset or reference database; the prohibition applies to: commercial facial recognition providers (such as Clearview AI and comparable services) that have built databases by scraping billions of faces from the internet without individual consent; law enforcement agencies building post-hoc facial identification databases by scraping social media at mass scale; government agencies building population-level facial recognition datasets from CCTV networks without specific investigation targets; private security companies building facial recognition reference datasets from online sources; the prohibition does not prohibit targeted collection of specific individual facial images for specific identified investigative purposes - it prohibits mass untargeted collection as a general database-building practice; the Article 5(1)(e) prohibition operates alongside existing GDPR restrictions on biometric data processing without consent and Directive 2016/680 law enforcement biometric data restrictions.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
    "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-prohibited-facial-scraping.json"
  },
  "crosswalks": {
    "_available_keys": [
      "gdpr",
      "iso_27001",
      "nist_csf"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "eu-ai-act-2024",
    "eu-ai-act-article-5-prohibited-practices",
    "eu-ai-act-article-3-definitions",
    "eu-ai-act-article-113-entry-into-force-application",
    "eu-ai-act-high-risk-biometric-systems",
    "eu-ai-act-prohibited-biometric-categorisation",
    "eu-ai-act-prohibited-realtime-biometric-id"
  ],
  "primary_citations_count": 5
}