Submit a source
Surveillance watch
Oct 2026Urban Milwaukee: MKE County: Supervisors Pass Flock Ban - Urban Milwaukee Oct 2026NewsCord: Sanders, Ocasio-Cortez, and Merkley Unveil Ban Flock Act To Bar Federal ALPR Use: 11 outlets compared - NewsCord Oct 2026Межа. Новини України.: Bernie Sanders Introduces Bill to Ban Federal Use of License Plate Reader Data - Межа. Новини України. Oct 2026Gulf Coast News and Weat: Fort Myers Beach awaits removal of Flock Safety cameras - Gulf Coast News and Weather Oct 2026crosstimbersgazette.com: Justin considering ban of Flock and other license plate reading cameras - crosstimbersgazette.com Oct 2026Troy Record: Troy City Council sets guardrails for Flock cameras; mayor plans veto - Troy Record Oct 2026WSYR: Troy passes first New York law to restrict automated license plate reader data - WSYR Oct 2026WRGB: Troy City Council passes new restrictions on license plate reader technology - WRGB Oct 2026fortmyersbeachtalk.com: Flock Safety license plater reader cameras deactivated on Fort Myers Beach - fortmyersbeachtalk.com Oct 2026WJLA: Alexandria city publishes map of flock cameras and license plate readers - WJLA Oct 2026ClickOnDetroit | WDIV Lo: Lincoln Park turns off Flock cameras after police chief says several cameras damaged, cut down - ClickOnDetroit | WDIV Local 4 Oct 2026Cowboy State Daily: Wyoming Lawmakers Warned That Besides License Plates, Tech Can Track Faces, Phones - Cowboy State Daily Sep 202610news.com: ACLU files lawsuit over ALPR cameras & tech, citing privacy concerns - 10news.com Sep 2026Lowell Sun: Groton group holds forum on police cameras after ending Flock contract - Lowell Sun Sep 2026KHON2: ALPR tech spreading in Hawaii: ‘Where was our vote?’ - KHON2 Sep 2026KHON2: ALPR tech spreading in Hawaii: ‘Where was our vote?’ - KHON2 Sep 2026WBTV: Residents push back on license plate readers as Charlotte-Mecklenburg police seeks vendor contract - WBTV Sep 2026ClickOnDetroit | WDIV Lo: South Lyon ends Flock Safety contract, orders cameras covered - ClickOnDetroit | WDIV Local 4 Sep 2026Boston 25 News: North Attleborough Town Council votes to pause automated license plate reader cameras - Boston 25 News Sep 2026Reason Magazine: AI Facial Recognition Didn't Put This Tennessee Grandma in Jail for 6 Months. Bad Policing Did. - Reason Magazine Sep 2026Michigan Advance: Lansing protesters block Flock cameras over license plate reader contract - Michigan Advance Sep 2026WKYT: Frankfort weighs renewal of Flock license plate reader contract - WKYT Sep 2026Fox News: Grandmother sues after alleged AI facial recognition error led to months in jail, experts sound alarm - Fox News Sep 2026Salinas Valley Tribune: Monterey County supervisors reject Flock Safety deal, order cameras to be removed - Salinas Valley Tribune Sep 2026KMTR: VOTE: Do you support Automated License Plate Reader cameras? - KMTR Sep 2026WKYT: Frankfort weighs renewal of Flock license plate reader contract - WKYT Sep 2026TCH Daily News: Manawa Moves to End Flock Safety Contract Over Data Concerns - TCH Daily News Sep 2026The New York Times: N.Y.P.D. Officers Used Flock Safety to Track License Plates - The New York Times Sep 2026KATV: Camden police cancel Flock Safety contract - KATV Sep 2026Northwest Arkansas Democ: Camden will cancel contract with Flock Safety, cover cameras until they are removed, official says - Northwest Arkansas Democrat-Gazette

Communities saying no

Surveillance worldwide: proposed, misused, and pushed back

A curated, sourced record of mass surveillance around the world: where it's being proposed, where it's being misused, and where people, courts, and regulators push it back. ALPR camera networks, facial recognition, biometric and algorithmic systems. If it watches people, it belongs here.

Layers
26 more

Include United States on this map Off by default so the world map is about everywhere else. Switch it on before downloading if you want the full global picture in one image.

Today

Scroll or pinch to zoom, drag to pan, and tap a marker for the story and source. Use the timeline to watch the pushback spread. 78 countries and regions on record so far. This list grows as cases are verified.

Documented stops & misuses 186

Every individual case mapped as a diamond: magenta for wrongful stops and the other harms the systems cause, cyan for data misuse by officers, agencies and vendors. The filters below split those into what actually happened, because a plate misread and a face-recognition arrest aren't the same failure. Tap any source.

South Africa tenders face recognition for police body and dashboard camerasSouth Africa

Wrongful stop

SOUTH AFRICA'S POLICE MAY GET FACE RECOGNITION IN THEIR BODY CAMERAS. The State Information Technology Agency has put out a tender for police body-worn and dashboard cameras that must include facial recognition, both to unlock the devices and within the video analytics. Bids close on 29 September 2026 (tender RFB-3286-2026-ERP-496011, Gauteng). The tender gives no budget or camera count and does not say whether footage will be matched live against watchlists. Biometric Update notes the Protection of Personal Information Act appears unlikely to cover police body cameras. Ask SITA and SAPS what database faces would be matched against and under what legal authority.

Sep 2026 Source →

Pegasus and NoviSpy hit Serbia's student movement around local electionsSerbia

Data misuse

AT LEAST 14 SERBIAN STUDENTS, ACTIVISTS AND OPPOSITION POLITICIANS TARGETED WITH SPYWARE IN 2026. Citizen Lab, working with SHARE Foundation and Amnesty Tech, confirmed on 2 September 2026 that a member of the student protest movement had Pegasus on their iPhone between December 2025 and January 2026, delivered by a zero-click iMessage exploit. The same investigators found a new Android version of NoviSpy, the spyware previously installed on phones seized by Serbian police; EDRi reports it was set up to send data to the Security Information Agency. EDRi counts at least 14 targets since early 2026, including an opposition MP and a local councillor, clustered around the 29 March local elections. Citizen Lab does not formally attribute the Pegasus case to a government. No response from Serbian authorities is on record here.

Sep 2026 Sourcescitizenlab.caedri.org

Presidentially appointed cyber agency backed police cases against the president's criticsZambia

Wrongful stop

MISA Regional's preliminary statement on the 13 August 2026 general elections, published 17 August 2026, says the Zambia Cyber Security Agency supported police investigations into critics of the president and of the Electoral Commission of Zambia. The agency's head is appointed by the president, which MISA calls a structural conflict of interest. MISA also reports public warnings issued by the Zambia Police Service and the army that it describes as unlawful, and attributes a chilling effect to the Cyber Security Act 2025 and the Cyber Crimes Act 2025. MISA says a Constitutional Court challenge to both Acts is pending; the outcome is not established and no hearing date is recorded here. No government response is included in the statement. Ask the Agency for the number of investigations it supported and the statutory basis for each. Coordinates are Lusaka, not a specific facility.

Aug 2026 Source →

The spyware inquiry was itself spied on: Pegasus on a PEGA member's phoneGreece

Data misuse

THE SPYWARE INQUIRY WAS ITSELF SPIED ON. Citizen Lab reported on 3 July 2026 that Stelios Kouloglou, a Greek former MEP and substitute member of the European Parliament's PEGA committee investigating Pegasus, was infected with Pegasus twice while the committee sat -- on 21 October 2022 in Greece and on 6-7 March 2023 in Belgium. Apple sent him three threat notifications he reportedly did not recall. Citizen Lab does not name a government, says it found no sign the Greek government was responsible, and ties the operation to a campaign against exiled Russian- and Belarusian-speaking journalists in Europe -- pointing to a Pegasus customer able to operate in several EU countries. Whether the Parliament has opened an inquiry into the breach is not established here.

Jul 2026 Source →

Two Russian agencies gave different counts of detained chatbot usersRussia

Wrongful stop

On 29 July 2026 the FSB said Ukrainian intelligence had used the Telegram dating chatbot Daivinchik, also called Leo, to recruit Russians for sabotage and arson, and that 46 users aged 12 to 22 had been detained across 16 regions since July 2025. Russia's Investigative Committee, in a separate statement about the same chatbot, gave 19 teenagers aged 14 to 18, detained in Moscow, St Petersburg, Novosibirsk and the Rostov and Saratov regions. Both counts come from the agencies themselves. The record does not resolve which is correct or whether the two describe the same detentions. Meduza reported that the chat interfaces in videos the security services released as proof were from a Russian application rather than Telegram. The FSB charged Telegram founder Pavel Durov with aiding terrorism and he was placed on Rosfinmonitoring's register of terrorists and extremists; a separate terrorism case had been opened against him in February 2026. None of the allegations has been tested in an adversarial hearing. Coordinates are Moscow; the detentions were spread across regions.

Jul 2026 Sourcesmeduza.iojurist.org

Judge and general jailed for spying on a journalistChile

Wrongful stop

A Chilean court on Jun 30, 2026 sentenced a former judge and a former army general to five years in prison for illegally spying on investigative journalist Mauricio Weibel Barahona while he was reporting Milicogate -- his 2015 investigation for The Clinic into the theft of the army's copper reserve fund. The Committee to Protect Journalists called the decision unprecedented for Chile. Two details give it weight beyond the country: the surveillance was run through the machinery of state -- a judge and a general, not a rogue operator -- against a journalist for the act of reporting on the military that employed one of them; and accountability took eleven years from publication and six years of judicial process to arrive. Custodial sentences for state officials over journalist surveillance remain rare enough worldwide that each one is a record; this is Latin America's counterpart to Greece's Feb 2026 Predatorgate convictions, and unlike Greece's suspended terms, these are prison sentences.

Jun 2026 Source →

Canada gives cabinet secret orders over telecom networksCanada

Wrongful stop

CANADA'S CABINET CAN NOW ORDER TELECOM COMPANIES TO ACT -- AND ORDER THEM TO KEEP IT SECRET. Bill C-8 received Royal Assent on 15 June 2026. It lets the federal cabinet bar carriers from using named suppliers and lets the Industry Minister order a provider to do, or stop doing, anything needed to secure its network -- including cutting off service to specified persons -- with orders that can forbid disclosure of their own existence. The Minister can share what is collected with CSIS, the Communications Security Establishment, other departments, 'any other prescribed' body and foreign governments. Challenges go to court only after the fact, and the judge can hear evidence the challenger never sees: on 25 March the Speaker ruled out amendments that would have required a judge to approve orders first. The final law does bar ordering decryption of private communications or interception. A new Critical Cyber Systems Protection Act makes designated operators report incidents to CSE within 72 hours. The Privacy Commissioner, OpenMedia and the CCLA all said safeguards fall short. NOT ESTABLISHED: whether any secret order has been issued -- by design, the public may not learn. Read with Bill C-22, the lawful-access bill still in the Senate.

Biometric 'digital profile' of foreign nationalsRussia

Data misuse

Russia moved to build a centralized 'digital profile' of foreign nationals and stateless people, expected by mid-2026, pulling extensive personal and biometric information from multiple agencies -- part of a broader expansion of surveillance targeting foreign visitors and residents.

Jun 2026 Source →

Met expands permanent facial recognition to the West EndUnited Kingdom

Wrongful stop

In June 2026 Metropolitan Police Commissioner Sir Mark Rowley announced the most significant expansion of live facial recognition in London to date: static LFR cameras mounted on street furniture across the West End and Soho by the end of 2026, meant to grow into a citywide infrastructure programme rather than time-limited van operations. It followed a six-month Croydon pilot (October 2025 to March 2026, 24 operations, 173 arrests, more than 470,000 faces scanned) and an April 2026 High Court ruling that the Met's LFR policy was lawful, now under appeal. Big Brother Watch urged the force to stop until Parliament legislates, noting the UK still has no specific statutory framework for LFR.

UK plugs its plate-reader network into EU-wide Prum sharingUnited Kingdom

Data misuse

In June 2026 the UK Home Office switched on number-plate checks through the EU's Prum data-sharing framework, letting officers query overseas-registered vehicles across EU member states and get vehicle-keeper details back in about ten seconds instead of days or months. It bolts cross-border reach onto Britain's already vast plate-reader system -- commonly cited at around 11,000 ANPR cameras reading roughly 50 million plates a day into the National ANPR Data Centre, where records are retained for a year. The government framed the link-up around border security, illegal migration and organised crime.

Jun 2026 Source →

80,000 protesters scanned; a worker wrongly flaggedUnited Kingdom

Wrongful stop

London's Metropolitan Police scanned the faces of about 80,000 people at a single protest and have run live facial recognition against millions of faces. Youth worker Shaun Thompson was wrongly flagged, detained, and threatened with arrest before being compensated. Campaigners call it stop and search on steroids.

Greek Watergate and the Predator convictionsGreece

Wrongful stop

In the Greek Watergate scandal, Intellexa's Predator spyware was used against politicians and journalists, and in 2026 a Greek court sentenced Intellexa founder Tal Dilian and others to eight years for illegal operations.

Mar 2026 Source →

Public-space cameras where the study found no terrorism to counterZambia

Wrongful stop

Zambia is one of 11 countries in Smart City Surveillance in Africa, published 12 March 2026 by the Institute of Development Studies with the African Digital Rights Network. The report names Zambia and Senegal as places where mass public-space surveillance was deployed despite what the researchers describe as no terrorist threat or serious crime challenge, and says they found no compelling evidence across any of the 11 countries that smart surveillance reduced terrorism or serious crime. Governments present the systems as crime prevention, counter-terrorism, modernisation and urban management. IDS gives the 11-country total as at least USD 2 billion. Reporting of the study's country tables (Nairametrics, 23 March 2026) puts Zambia at USD 210 million for about 1,600 smart cameras -- the fourth-largest spend of the eleven, and roughly USD 131,000 per camera by simple division. The figures are the researchers' counts, drawn from public accounts they describe as incomplete, not an audit. Coordinates are Lusaka, not a specific site.

Africa's largest buyer of Chinese public-space surveillanceNigeria

Wrongful stop

IDS and the African Digital Rights Network, publishing 12 March 2026, put Nigeria's spending on facial recognition and automatic number plate recognition at over USD 470 million to date, the largest of the 11 African countries studied. A trade write-up of the same research (military.africa, April 2026) gives the 11-country total as USD 2.1 billion with Nigeria at nearly 23 per cent of it, against the IDS figure of at least USD 2 billion; the two are not reconciled and both are the researchers' counts rather than an audit. IDS says most of the technology is supplied and financed by Chinese companies, with Korea, Israel and the United States also supplying, and that no compelling evidence was found that these systems reduced terrorism or serious crime. Nigeria already appears on this map for the Hacking Team contract and the NIN biometric breaches; this record covers the camera programme. Coordinates are Abuja.

Second-largest buyer; Safe City images went missing in a death inquiryMauritius

Wrongful stop

IDS and the African Digital Rights Network place Mauritius second among the 11 African countries studied at USD 456 million on smart city surveillance, in research published 12 March 2026. The programme predates that figure: Huawei made an unsolicited bid in 2015, the Police Service signed two operating-lease contracts with Mauritius Telecom on 19 December 2017, and China Eximbank signed a preferential buyer's credit of USD 73,687,000 with Mauritius Telecom on 1 April 2018 at 2 per cent interest over a 20-year maturity with a 7-year grace period, according to AidData. Answering a parliamentary question on 11 August 2020, Prime Minister Pravind Kumar Jugnauth said 2,761 intelligent video surveillance cameras were installed at 1,429 sites and 140 traffic cameras at 68 sites, and that 101 cases requiring police enquiry had been detected through Safe City cameras. That detection figure is the government's own count and no audit of it is recorded here. Mauritius Times reported the system's total cost as Rs 19 billion with roughly Rs 350 million a year to operate; that comes from one newspaper and is not corroborated here, and it is not established how it relates to the USD 456 million figure. In the judicial inquiry into the death of Soopramanien Kistnen, Safe City images were reported missing and a Huawei representative was questioned. Coordinates are Port Louis.

Smart cameras deployed where political opposition is concentratedMozambique

Wrongful stop

The IDS and African Digital Rights Network report published 12 March 2026 says research in Mozambique found smart CCTV cameras deployed in locations where political opposition is concentrated. Mozambique is one of 11 countries in the study, which puts combined spending at at least USD 2 billion; Reporting of the study's country tables (Nairametrics, 23 March 2026) puts Mozambique at USD 147 million for about 450 smart cameras, roughly USD 327,000 a camera by simple division. These are the researchers' counts from incomplete public accounts, not an audit. The report says all 11 countries fail to provide adequate means for people to obtain remedy or redress for smart surveillance errors or abuse. The government's account of how camera sites were chosen is not established, and the report's siting claim has not been tested against procurement or deployment records. Ask the Mozambican police for the site list and the selection criteria. Coordinates are Maputo.

Third-largest buyer of smart city surveillanceKenya

Wrongful stop

IDS and the African Digital Rights Network put Kenya third among the 11 countries studied at USD 219 million on smart city surveillance technology, in research published 12 March 2026. The systems combine CCTV, facial recognition, number plate recognition and central command centres, and are mostly supplied and financed by Chinese firms. The researchers say they found no compelling evidence that such deployments reduced terrorism or serious crime, and that the countries studied lack laws defining who may conduct public-space surveillance, on what warrant and under whose oversight. The figure is the researchers' count, not an audit, and IDS notes the real total across the region is likely higher because surveillance spending is often secret. Kenya already appears on this map for Worldcoin, a suspected Pegasus deployment and the Huduma Namba ruling; this record covers the camera programme. Coordinates are Nairobi.

Mar 2026 Sourcesids.ac.ukopendocs.ids.ac.uk

Mass surveillance rolled out with no serious crime challenge citedSenegal

Wrongful stop

IDS and the African Digital Rights Network, publishing 12 March 2026, name Senegal alongside Zambia as countries where mass public-space surveillance was deployed despite what the researchers describe as no terrorist threat or serious crime challenge. Senegal is one of the 11 countries in the study; Reporting of the study's country tables puts Senegal at USD 167 million for about 500 smart cameras -- roughly USD 334,000 a camera, the highest unit cost among the countries where both figures are published, against about USD 9,700 in Egypt and USD 47,000 in Nigeria. Neither extreme is explained in the material reviewed. The report records that governments present these systems as crime prevention, counter-terrorism and urban management, and that the researchers found no compelling evidence of a reduction in terrorism or serious crime. Senegal already appears on this map for the 2026 national digital-ID breach; this record covers public-space cameras. Coordinates are Dakar.

Five thousand cameras and no published costAlgeria

Wrongful stop

FIVE THOUSAND CAMERAS AND NO PUBLISHED COST. Algeria is one of 11 countries in Smart City Surveillance in Africa, published 12 March 2026 by the Institute of Development Studies with the African Digital Rights Network. Reporting of the study puts roughly 5,000 smart cameras in Algeria, and NO SPENDING FIGURE IS AVAILABLE -- the researchers say figures could not be obtained for two of the eleven countries and that public accounts for the other nine were incomplete, which is why their at least USD 2 billion total is explicitly a floor. WHAT THE COUNTRY AUTHOR SAYS HAPPENED. Yosr Jouini, who wrote the report's Algeria section, says systems introduced as smart city projects promising to tackle crime and manage traffic became in practice primarily tools of the security forces, and that the framing is entirely a security one, dismissing other concerns and providing too few mechanisms for citizens to protect their rights. She notes that street protests in 2019 and 2021 were a significant part of Algerian political life, and warns expanded surveillance could make people hesitant to protest in future. THAT IS A FORECAST, NOT A FINDING, and is recorded as one -- no measurement of a chilling effect in Algeria appears in the coverage reviewed here. A CAUTION FROM WITHIN THE SAME RESEARCH worth carrying: Bulelani Jili of Georgetown University argues that even introducing legal frameworks to regulate this technology can be dangerous, because a framework can legitimise a deployment rather than constrain it. Coordinates are Algiers, not a specific installation.

Second-largest camera count at a fraction of the leading spendEgypt

Wrongful stop

SIX THOUSAND CAMERAS FOR FIFTY-EIGHT MILLION DOLLARS -- roughly $9,700 a camera, the cheapest per-unit deployment for which both numbers are reported. Egypt is one of 11 countries in the IDS and African Digital Rights Network report of 12 March 2026, which records USD 58 million spent and 6,000 smart cameras installed. FOR SCALE AGAINST THE REST OF THE STUDY: Nigeria spent over USD 470 million for about 10,000 cameras, Mauritius USD 456 million, Kenya USD 219 million, and the eleven countries averaged USD 240 million each. Egypt therefore has the second-largest camera count in the study at a fraction of the leading spend, which the sources do not explain -- it may reflect different equipment, different financing, or incomplete public accounts, and the researchers warn the accounts for nine of the eleven countries were incomplete. WHAT THE STUDY CONCLUDES ACROSS ALL ELEVEN: the systems are presented as crime prevention, counter-terrorism, modernisation and urban management; the researchers found little evidence that expanding digital surveillance reduces overall crime; much of the equipment is supplied or financed by Chinese companies and banks, often through loans; and none of the countries provides adequate means to obtain remedy for surveillance errors or abuse. Egypt already appears on this map for the Sandvine deep packet inspection deployment; this record covers public-space cameras. Coordinates are Cairo. THE SPREAD IS WIDER THAN EGYPT ALONE: by the same country tables as reported by Nairametrics, Senegal (USD 167 million, about 500 cameras) and Mozambique (USD 147 million, about 450) run at roughly USD 330,000 a camera -- so Egypt is one end of a thirty-fold range, not a lone anomaly. No source read explains either end; the report PDF could not be retrieved. WHAT WOULD SETTLE IT: the Egypt chapter of the report, or a question to its editors at IDS and the African Digital Rights Network. A POSSIBLE EXPLANATION, inferred rather than stated by the report: in February 2019 Honeywell signed to build a 6,000-camera IP system and command centre for Egypt's New Administrative Capital, reported at about USD 31 million (Global Construction Review). If the IDS figures come from that project, Egypt's low cost per camera reflects one US-built network in one new city, with video analytics rather than face recognition. The IDS report's Egypt chapter has still not been read.

The smallest deployment in the study, and still ungovernedRwanda

Wrongful stop

THE SMALLEST DEPLOYMENT IN THE STUDY, AND STILL UNGOVERNED. Rwanda is one of 11 countries in the IDS and African Digital Rights Network report published 12 March 2026, with approximately 849 smart cameras -- the lowest camera count reported among the eleven -- and NO SPENDING FIGURE AVAILABLE. Rwanda is one of the countries for which the researchers could not obtain figures, which is part of why they describe their USD 2 billion total as a floor rather than an estimate. WHY A SMALL DEPLOYMENT STILL BELONGS ON THIS MAP: the report's central finding is not about volume. It is that across all eleven countries these systems were rolled out WITHOUT the legal frameworks needed to define who may conduct public-space surveillance, on what authority, and under whose oversight, and without adequate means for a person to obtain remedy for an error or an abuse. A network of 849 AI-enabled cameras feeding a central command centre with no statutory basis is a governance problem at any size. The researchers add that the systems are mostly supplied and financed by Chinese firms and banks. NOT ESTABLISHED: no Rwanda-specific misuse finding appears in the coverage reviewed here, and this record should not be read as one. Coordinates are Kigali.

National digital-ID system breached, biometric data stolenSenegal

Data misuse

In January 2026 a threat actor calling itself the Green Blood Group claimed to have breached Senegal's national digital-ID system and exfiltrated about 139 terabytes of data, including biometric records -- a stark illustration of the privacy risk when governments centralize biometric identity.

Jan 2026 Source →

Cybercrime Bill would allow real-time traffic capture and content interceptionNamibia

Wrongful stop

A draft Namibia Cybercrime Bill dated 30 January 2026 gives an investigatory authority powers of access, search and seizure of stored data under a court warrant at clause 39, real-time collection of traffic data by technical means on the order of a Judge in Chambers at clause 40, interception of content data at clause 41, and expedited preservation of stored computer data at clause 47. Clause 3 provides that the Act prevails over any other written law on cybercrime and cybersecurity matters. The Council of Europe's Octopus country page assesses a draft Namibian bill as supplying most procedural powers the Budapest Convention requires while not setting out their scope, with some powers appearing to reach only offences under the bill rather than electronic evidence generally, and with no powers specific to traffic data. That page is undated and refers to a drafting mission held in February 2020, so whether its assessment describes this 30 January 2026 text or an earlier draft is not established. The bill is not enacted and no commencement date is established. Coordinates are Windhoek.

Jan 2026 Sourcesnmt.africacoe.int

Face recognition in 1,600 Parana schools, with no national rulesBrazil

Wrongful stop

1,600 SCHOOLS IN PARANA ALONE. InternetLab's November 2025 study found facial recognition running in public schools in at least seven Brazilian states -- Alagoas, Amazonas, Goias, Parana, Rio de Janeiro, Sao Paulo and Tocantins -- and earlier use in six more, mostly to take attendance. Parana has installed it in 1,600 schools. There are no national rules setting minimum safeguards for scanning children's faces, and the company supplying most of the systems did not answer the researchers. No ruling by Brazil's data protection authority on school use is recorded here. Ask each state education department for the contract, the retention period and the legal basis under the LGPD.

Nov 2025 Source →

Police tap a private plate network half a million times a yearNew Zealand

Data misuse

New Zealand police query Auror, an Auckland retail-crime ANPR platform, hundreds of times a day -- around half a million times a year -- with thousands of officers able to access it without stating a reason. Defence lawyers challenging it in the Court of Appeal call it 'surveillance capitalism.'

Sep 2025 Sourcesrnz.co.nznzherald.co.nz

Police in four states run Palantir 'dragnet' data-miningGermany

Data misuse

German state police have adopted Palantir's Gotham data-mining platform -- Hesse's HessenData since 2017, North Rhine-Westphalia's DAR, Bavaria's VeRA (live from late 2024) and Baden-Wurttemberg from 2025 -- to fuse names, addresses, phone and social-media records into instant profiles, including of people never suspected of a crime. In a 2023 landmark ruling the Federal Constitutional Court struck down the Hesse and Hamburg data-mining laws as too broad; civil-liberties groups GFF and the Chaos Computer Club have since filed constitutional complaints against Bavaria and North Rhine-Westphalia, calling it a 'Palantir dragnet.'

Biometric national ID mandated for all citizensMexico

Data misuse

In July 2025 a presidential decree made the biometric CURP -- face, fingerprints, and iris captured in a QR code -- the mandatory national ID for nearly all public and private services. A new Unified Identity Platform links it to other state databases for real-time cross-checks, and from 2026 every mobile line must be tied to it. The decree lets prosecutors, the National Intelligence Center, the National Guard, and the security ministry consult the database -- including bank and telecom data -- without notifying the person. Framed as a response to Mexico's missing-persons crisis, it drew warnings of a mass-surveillance ecosystem from digital-rights groups R3D and Article 19, and courts in several states issued injunctions pausing the rollout.

Paragon Graphite used against journalists in ItalyItaly

Wrongful stop

Italy's intelligence services used Paragon's Graphite spyware against journalists and migrant-rescue activists, confirmed by Citizen Lab in 2025, including Fanpage journalist Ciro Pellegrino and Mediterranea Saving Humans founders.

Jun 2025 Sourcescitizenlab.caamnesty.org

Facial recognition turned on Pride marchers and minor offendersHungary

Wrongful stop

In March 2025 Hungary's Parliament rushed through three amendments in 24 hours -- to the Assembly Act, the Infraction Act and the Facial Recognition Technology Act -- banning Pride events and authorising police to use live facial recognition to identify participants and anyone committing even minor infractions such as jaywalking. Effective April 15, 2025, it dramatically widened biometric surveillance of peaceful assembly. Rights groups (HCLU, EDRi, ECNL, Liberties for Europe) argue it violates the EU AI Act, which already bars real-time remote biometric identification in public, and the EU Charter; the European Commission has been slow to act. Budapest Pride went ahead in June 2025 as the country's largest anti-government demonstration in years.

Apr 2025 Sourcesedri.orgeuobserver.com

Serbia hacks activists' phones in police custodySerbia

Wrongful stop

An Amnesty International report found that Serbian police and the BIA intelligence agency used Cellebrite forensic tools to secretly unlock the phones of journalists and activists during detention, then installed a homegrown Android spyware called NoviSpy that can copy data and switch on the camera and microphone. Investigative journalist Slavisa Milanov and environmental campaigners were among those hacked after being held for routine-seeming interviews.

Automated welfare state flags 'atypical' lives for fraud probesDenmark

Wrongful stop

A November 2024 Amnesty International investigation, 'Coded Injustice,' found Denmark's welfare agency Udbetaling Danmark and its administrator ATP run some 60 fraud-detection algorithms -- including a 'Really Single' model that guesses a person's relationship status and the 'Gladsaxe Model' -- that mine vast personal data and flag 'unusual' or 'atypical' living and family patterns, disproportionately targeting people with disabilities, low incomes, migrants and foreigners. Denmark's Parliamentary Ombudsman opened an inquiry; the agency denies it amounts to social scoring.

Nov 2024 Source →

Legal challenge to the benefits agency's fraud-scoring algorithmFrance

Data misuse

In October 2024 a coalition of 15 organisations, including La Quadrature du Net and Amnesty International, filed a complaint before France's top administrative court against the risk-scoring algorithm used by the national family-benefits fund CNAF. The system assigns welfare recipients a fraud-suspicion score from data on their circumstances; analysis showed it effectively rated the poorest, single parents, disabled people and those born outside the EU as higher risk, singling them out for intrusive checks.

Oct 2024 Source →

Wrongful detentions from face-match errorsBrazil

Wrongful stop

Brazil's expanding police facial recognition has repeatedly detained innocent people, overwhelmingly Black. One man was tracked across fifteen train stations in Bahia before being held on a false match, another was detained in front of a stadium crowd, and in 2025 an 80-year-old volunteer was taken to a police station after cameras mistook him for a wanted man. A study found about 90 percent of those arrested through the technology in several states were Black Brazilians.

Apr 2024 Source →

Face recognition installed to catch unveiled studentsIran

Wrongful stop

Iranian authorities installed facial recognition at Amirkabir University of Technology in Tehran to identify and penalize women students who removed their headscarves, part of a wider rollout of cameras and drones to enforce hijab laws.

AI cameras and biometrics turn refugee camps into 'high-tech prisons'Greece

Wrongful stop

At Greece's EU-funded Closed Controlled Access Centres for asylum seekers, two systems -- Centaur (CCTV, drones and AI behavioural analytics that flag 'threats' and log incidents, monitored from Athens) and Hyperion (biometric fingerprint entry and exit) -- put residents under constant surveillance behind curfews, with cameras even in sleeping containers. Most residents interviewed said they were never told they were being filmed. In April 2024 the Greek Data Protection Authority fined the Migration Ministry 175,000 euros for GDPR breaches over the rollout.

Clearview expands face search across Latin AmericaEcuador

Wrongful stop

The American firm Clearview AI is expanding across Latin America, giving law enforcement in countries including Argentina, Brazil, Colombia, and Ecuador access to its database of billions of scraped faces, even as it faces fines and bans elsewhere. Rights advocates warn it puts much of the region in a perpetual police lineup, risking wrongful arrests and profiling.

Mar 2024 Source →

Wrongly flagged by live facial recognitionUnited Kingdom

Wrongful stop

London's Metropolitan Police scan millions of faces with live facial recognition. Youth worker Shaun Thompson was wrongly flagged in 2024, then stopped, detained, fingerprinted, and threatened with arrest over a false match. At one 2025 sporting event South Wales Police logged 2,470 alerts, 92 percent of them false, and the equality watchdog found the Met system disproportionately flags Black men.

Feb 2024 Source →

Biometric ID breaches exposed citizens' dataNigeria

Data misuse

Nigeria's biometric National Identification Number system, tied to SIM and bank registration, has suffered data breaches exposing citizens' personal records, alongside exclusion of those unable to enroll.

Jan 2024 Source →

Woman wrongly detained as a fugitiveBrazil

Data misuse

In Rio de Janeiro, a woman was wrongly detained after a facial-recognition database flagged her as a fugitive, even though she was already serving her sentence under an open regime.

Jan 2024 Source →

Clearview AI fined over scraped databaseNetherlands

Data misuse

The Dutch data-protection authority fined Clearview AI for building an illegal facial-recognition database from scraped photos of people in the Netherlands, one of several EU regulators to penalize the company.

2024 Source →

Predator spyware customerPhilippines

Wrongful stop

A Predator spyware customer assessed as highly likely linked to the Philippines was identified by Recorded Future, the first time the tool's use was tied to the country.

2024 Source →

Huawei Safe City cameras expand in BelgradeSerbia

Data misuse

Serbia is expanding Huawei's Safe City facial-recognition camera network in Belgrade, with leaked 2024 contracts showing capacity for up to 3,500 additional cameras despite public protests.

2024 Source →

Interior Ministry's secret use of Briefcam video analyticsFrance

Wrongful stop

In late 2023 investigative outlet Disclose revealed that France's national police and gendarmerie had for years quietly used Briefcam, an Israeli video-analytics system capable of facial recognition, to search and filter surveillance footage without public debate or, critics argued, a clear legal basis. A 2024 CNIL investigation concluded the Interior Ministry had not used the software for real-time facial recognition in public space, but the episode exposed how FR-capable tools were deployed in secrecy.

Nov 2023 Source →

Sao Paulo builds a 20,000-camera face networkBrazil

Wrongful stop

Sao Paulo's Smart Sampa program wires up to 20,000 cameras with facial recognition across a city of 12 million, watching streets, schools, and public spaces. Rights groups warn it could drive mass incarceration of Black residents, citing a 2019 study that found about 90 percent of those arrested through facial recognition in Brazil were Black. The Public Defender's Office sued to suspend it.

European court: metro face-recognition arrest violated rightsRussia

Wrongful stop

In July 2023 the European Court of Human Rights ruled that Russia violated Nikolay Glukhin's rights by using Moscow metro facial recognition to identify and arrest him over a peaceful solo protest. Glukhin had ridden the underground in August 2019 holding a life-sized cutout of jailed activist Konstantin Kotov; days later the system flagged him and police detained him. The court found the deployment incompatible with the values of a democratic society governed by the rule of law -- one of the first international rulings against live facial recognition.

Jul 2023 Source →

Red Wolf tracks Palestinians at checkpointsIsrael

Data misuse

In the occupied West Bank city of Hebron, an Israeli military facial-recognition system called Red Wolf scans Palestinians at checkpoints and enrolls their faces into surveillance databases without consent, deciding who may pass. Amnesty International's 2023 Automated Apartheid report documented how it automates movement restrictions and tracks residents, and how soldiers were rewarded for registering as many Palestinians as possible.

May 2023 Source →

Cameras track Palestinians' cars by plateIsrael

Data misuse

Israeli surveillance cameras in occupied East Jerusalem capture license plates on fixed and moving vehicles, feeding a database of Palestinians that records plates, permits, and addresses, restricting Palestinians' movement within their own neighborhoods. Researchers identified Hikvision and TKH cameras in the network.

May 2023 Sourcesamnesty.orgmei.edu

Soldiers scan Palestinians' faces at checkpointsPalestine

Data misuse

Israeli soldiers in Hebron use face-scanning cameras, known as Red Wolf, to identify Palestinians at checkpoints without checking IDs, feeding a database used to control their movement. Amnesty calls it automated apartheid.

May 2023 Sourcesamnesty.orgmei.edu

An app flags cars when a woman inside is unveiledIran

Data misuse

Iran's police run a phone app, Nazer, that lets officers and vetted civilians flag a vehicle's license plate when a woman inside is unveiled. The system sends the owner an automatic warning and then impounds the car. Amnesty documents hundreds of thousands of vehicles confiscated since 2023, and the app was later extended to taxis, ambulances, and buses.

Football club face scan wrongly fines a fanNetherlands

Wrongful stop

Dutch football clubs used retrospective facial recognition to scan crowds for banned supporters, and in one case wrongly issued a fine to a fan who had not even attended the match in question, a failure that drew warnings about expanding after-the-fact face surveillance in Europe.

Apr 2023 Sourcesedri.orgeuronews.com

Supermarkets built secret facial-recognition blacklists of shoppersUnited Kingdom

Wrongful stop

British retailers including Southern Co-op, Home Bargains and Mike Ashley's Frasers Group deployed Facewatch live facial recognition to scan shoppers entering stores and match them against private watchlists of suspected offenders. After a 2022 Big Brother Watch complaint, the ICO concluded in March 2023 that Facewatch's processing had breached data-protection law on multiple principles, forcing an overhaul; campaigners say people were blacklisted over trivial accusations and, in cases like a teenager wrongly flagged at Home Bargains in 2024, misidentified and publicly accused.

Rotterdam's 'suspicion machine' scored the poor for fraud raidsNetherlands

Data misuse

From 2017 to 2021 Rotterdam used an Accenture-built machine-learning model to score its roughly 30,000 welfare recipients for fraud risk, using about 315 inputs including age, gender, language skills, neighbourhood, marital status and subjective caseworker notes. A 2023 Lighthouse Reports and WIRED investigation ('Suspicion Machines') that reverse-engineered the model found it systematically ranked single mothers, non-Dutch speakers and people of certain ethnicities as higher risk, subjecting them to intrusive fraud investigations even when they had done nothing wrong.

Mar 2023 Source →

Blocked national IDs cut people off from servicesSouth Africa

Data misuse

In South Africa, the Home Affairs department's practice of blocking national IDs left many people unable to access banking, grants, and services, prompting legal challenges over the harms of digital identity systems.

Jan 2023 Source →

Journalists and rights workers hackedJordan

Wrongful stop

Pegasus was used against at least 16 Jordanian journalists and activists, including two Human Rights Watch staff and a Palestinian-American reporter hacked three times, many of whom had covered a teachers' strike the government crushed.

2023 Source →

Predator aimed at EU lawmakersVietnam

Wrongful stop

Vietnam deployed Predator spyware against targets including members of the European Parliament and used commercial spyware against bloggers, part of a broad surveillance campaign accompanying its jailing of online critics.

2023 Source →

Predator spyware infrastructureAngola

Wrongful stop

Angola was identified in the Predator Files as a likely customer of Intellexa's Predator spyware, with Amnesty International finding technical infrastructure tied to the tool active in the country.

2023 Source →

Predator spyware infrastructureMongolia

Wrongful stop

Mongolia appeared among the governments linked to Intellexa's Predator spyware in the Predator Files, with Amnesty International documenting infrastructure associated with the tool.

2023 Source →

Predator spyware shipmentsBotswana

Wrongful stop

Import records tied Botswana's Directorate of Intelligence and Security to shipments of Intellexa Predator spyware in 2023, the first identification of the tool's use in the country.

2023 Source →

Predator spyware infrastructureSudan

Wrongful stop

Sudan was among the countries where Amnesty International found technical infrastructure linked to Intellexa's Predator spyware in the Predator Files investigation.

2023 Source →

Mexico's army spied on journalists with PegasusMexico

Wrongful stop

Mexico is the most heavily targeted country in the Pegasus files. First exposed in 2017, the NSO spyware was used against journalists like Carmen Aristegui, whose teenage son was also hit, along with activists and lawyers for victims of disappearances. The Ejercito Espia investigation later showed the army kept using Pegasus against reporters and a human rights defender into 2021, even after the president pledged the practice had stopped.

Facial recognition used to hunt draft evadersRussia

Wrongful stop

After Russia's September 2022 mobilisation for its war on Ukraine, Moscow authorities turned the city's facial-recognition camera network on men avoiding the draft. Human Rights Watch documented at least seven men flagged as 'draft dodgers' and detained via surveillance cameras, taken to police stations and enlistment offices, with some ordered to the front. Enlistment offices even flag conscripts who legally challenge their call-up so they can be auto-detected on camera, and rights lawyers advise appellants to avoid the metro entirely.

Oct 2022 Sourceshrw.orgthemoscowtimes.com

Surveillance enforcing mandatory hijabIran

Wrongful stop

Iran uses facial recognition, road cameras, drones, and a citizen-reporting app to enforce mandatory hijab rules on women. A 2025 UN fact-finding mission documented facial recognition installed at a Tehran university gate to catch uncovered students, and metro screens in Mashhad displaying passengers' faces, age, and gender to frighten women out of defiance.

Sep 2022 Source →

Spanish football clubs scan fans' faces at the turnstileSpain

Wrongful stop

Spanish football clubs have rolled out facial recognition on supporters: Valencia CF deployed a FacePhi system to control stadium access and Atletico Madrid announced face-scanning and cashless entry from the 2022-23 season, while other clubs use fingerprint scanning at turnstiles. Fans and privacy advocates warned that mandatory biometric entry normalises tracking of ordinary spectators.

Aug 2022 Source →

Predator spyware targets Greece's journalists and politiciansGreece

Wrongful stop

In the scandal known as Predatorgate, the Predator spyware sold by the Israeli-founded firm Intellexa was used to target more than ninety journalists, the opposition leader Nikos Androulakis, ministers, and senior military officers between 2020 and 2022, alongside wiretaps by the national intelligence service. The case forced top resignations, and in 2026 an Athens court handed eight-year sentences to four people linked to Intellexa, a rare criminal reckoning for the spyware trade.

Jul 2022 Sourcesamnesty.orgen.wikipedia.org

Face scans track the Uyghur populationChina

Wrongful stop

In Xinjiang, authorities use facial recognition to monitor the mostly Muslim Uyghur population, with face scans required to enter shops, hotels, and stations and tens of thousands of cameras in Urumqi alone. Leaked police files showed Hikvision systems used to screen all 23 million residents and flag people with overseas ties for arrest.

Facial recognition ran searches on thousands not wantedArgentina

Wrongful stop

Buenos Aires's facial-recognition system was used to run unauthorized searches on more than 15,000 people not on any fugitive list, including journalists, politicians, and activists, and wrongly jailed a factory worker for nearly a week after a database error.

Apr 2022 Source →

CatalanGate spyware hits Catalan independence figuresSpain

Wrongful stop

Citizen Lab's CatalanGate report found at least sixty-five people tied to the Catalan independence movement, including every Catalan president since 2010, members of the European Parliament, lawyers, and activists, targeted or infected with Pegasus or Candiru spyware between 2017 and 2020. The lab pointed to strong circumstantial evidence of a Spanish state nexus; the government later acknowledged court-authorized surveillance of about two dozen people and denied a wider operation.

Metro face recognition used to detain protestersRussia

Wrongful stop

Moscow's metro facial recognition, part of a Safe City camera network, has been used to detain and question thousands of people on their way to and from anti-war protests, sometimes preventively. The European Court of Human Rights later ruled the practice violated human rights.

Clearview used to identify dead Russian soldiersUkraine

Wrongful stop

In March 2022 Ukraine's defence and digital-transformation ministries began using Clearview AI facial recognition -- provided free, drawing on billions of scraped images including from the Russian network VKontakte -- to identify the bodies of dead Russian soldiers and message their relatives, and to identify operatives. Critics warned of the wartime normalisation of a controversial scraping tool and the risk of deadly misidentification at checkpoints.

Mar 2022 Sourcesforbes.comamp.cbc.ca

Clearview AI fined 20 million eurosItaly

Data misuse

Italy's data-protection authority fined Clearview AI 20 million euros for processing biometric and location data of people in Italy without a legal basis, banned further collection, and ordered deletion of existing records.

Feb 2022 Source →

35 journalists infected with PegasusEl Salvador

Wrongful stop

Researchers confirmed Pegasus infections on 35 journalists and civil society members in El Salvador, with reporters at the outlet El Faro among the most heavily targeted as they investigated government corruption.

Jan 2022 Source →

Clearview AI fined for face scrapingFrance

Data misuse

France's data-protection regulator fined Clearview AI roughly 20 million euros and ordered it to stop collecting and to delete residents' data, after finding the company unlawfully scraped billions of faces into a recognition database sold to police.

2022 Source →

Clearview AI fined for face scrapingGreece

Data misuse

Greece's data-protection authority fined Clearview AI about 20 million euros for unlawfully scraping and processing residents' facial images, part of roughly 100 million euros in EU fines the company has largely ignored.

2022 Source →

ICO fines Clearview, orders deletionUnited Kingdom

Data misuse

The UK Information Commissioner's Office fined Clearview AI 7.5 million pounds in 2022 and ordered it to delete UK residents' data; after a tribunal initially overturned the action on jurisdiction, an appeals tribunal restored the regulator's authority in 2025.

Pegasus turned on Poland's oppositionPoland

Wrongful stop

Under the Law and Justice government, Polish services used NSO's Pegasus against the opposition. Senator Krzysztof Brejza was hacked dozens of times in 2019 while running the opposition's election campaign, and his stolen messages were doctored by state television for a smear campaign; a lawyer and a prosecutor critical of the government were also targeted. A Senate commission and the European Parliament found the spyware was deployed to entrench those in power, and prosecutors later seized the systems.

Court declared the biometric ID rollout illegalKenya

Data misuse

Kenya collected the fingerprints and facial images of tens of millions of people for its Huduma Namba (NIIMS) biometric ID before passing a data-protection law. The High Court declared the rollout illegal for skipping a privacy-risk assessment, and the successor Maisha Namba system faces similar criticism.

Facial recognition paused in Scottish school canteensUnited Kingdom

Wrongful stop

In October 2021 nine schools in North Ayrshire, Scotland switched on facial recognition to take payment in their canteens, scanning pupils' faces instead of fingerprints or cards. After public and regulatory backlash the ICO intervened, urging the schools to use a less intrusive method, and the rollout was paused -- an early flashpoint over normalising biometric identification of children for everyday transactions.

Oct 2021 Source →

Morocco named a top Pegasus user targeting journalists and leadersMorocco

Wrongful stop

The 2021 Pegasus Project named Morocco as one of the heaviest users of NSO's spyware, with around ten thousand numbers selected. They included Moroccan journalists such as Omar Radi, who was later jailed, as well as foreign figures, among them French President Emmanuel Macron and several of his ministers. Morocco denied buying or using Pegasus and sued the journalists and Amnesty International for defamation.

Police faked reports to track people with plate camerasNew Zealand

Data misuse

Just a month after the Privacy Commissioner warned police to do better on plate cameras, a detective pretended a car was stolen so they could track it, and officers filed a false report to use ANPR to track women linked to a Northland lockdown breach.

Jul 2021 Source →

Facial recognition used to hunt dissidentsRussia

Wrongful stop

Moscow's facial-recognition camera network, one of the world's largest, has been turned from catching criminals to hunting dissidents. Police have used it to identify and detain peaceful protesters, journalists covering them, and mourners at Alexei Navalny's 2024 funeral, tracing people right up to their door. In 2023 the European Court of Human Rights ruled its use against a protester unlawful.

Apr 2021 Source →

Junta expands Chinese safe-city camerasMyanmar

Wrongful stop

Myanmar's military junta expanded Chinese-supplied safe-city camera networks with facial recognition across cities, raising fears of tracking dissidents after the 2021 coup.

Face recognition built to sort people by ethnicityChina

Wrongful stop

Chinese authorities, working with surveillance firms including Hikvision, Dahua, and Uniview, drew up facial-recognition standards that sort people by traits such as ethnicity and skin color, which researchers warned opened wide scope to target minorities like the Uyghurs at scale.

Allot DPI throttled Telegram before a blackoutKazakhstan

Data misuse

Allot's deep-packet-inspection technology was used in Kazakhstan to throttle Telegram and other platforms ahead of a January 2021 nationwide internet blackout.

Jan 2021 Source →

Mandatory biometric ID excludes the elderlyUganda

Data misuse

Uganda's mandatory Ndaga Muntu biometric national ID has been challenged by civil-society groups for excluding elderly people from welfare benefits and blocking women's access to healthcare, amid wider use of biometrics to monitor dissent.

Police ran face recognition on CCTV and web imagesSouth Korea

Wrongful stop

South Korean police tracked suspects with Videmo 360 facial recognition software, analyzing images pulled from CCTV and the internet, in a case that raised concerns over the legality of the surveillance.

Jan 2021 Source →

Retailer fined 10.4M euros for spying on staff by CCTVGermany

Wrongful stop

In a decision made public in January 2021, the Lower Saxony data-protection authority fined online electronics retailer notebooksbilliger.de about 10.4 million euros for unlawfully video-monitoring its employees for at least two years. The regulator found blanket CCTV over workspaces and public areas, justified only by a general suspicion of theft, had no legal basis under the GDPR -- one of Germany's largest fines for workplace surveillance.

Jan 2021 Source →

Pegasus used against journalistsAzerbaijan

Wrongful stop

Azerbaijan was identified as a Pegasus operator with around 48 journalists selected for targeting, including OCCRP investigative reporter Khadija Ismayilova, whose phone was infected for nearly three years, and Meydan TV freelancer Sevinc Vaqifqizi.

State spyware on journalists and criticsHungary

Wrongful stop

Hungary's Interior Ministry bought Pegasus for about 6 million euros and used it against investigative journalists such as Szabolcs Panyi of Direkt36, along with opposition figures, lawyers, and a media-owning businessman, an EU member state turning spyware on its own critics.

Pegasus targeting of dissidents abroadRwanda

Wrongful stop

Rwanda was named among Pegasus operators, with targets including the daughter and nephew of Hotel Rwanda figure Paul Rusesabagina; the leaked list also flagged South Africa's president as a possible Rwandan target.

2021 Source →

Officials and journalists on Pegasus listLebanon

Wrongful stop

Phone numbers of senior Lebanese figures appeared on the Pegasus list, including the president, a former prime minister, ministers, security chiefs, and numerous journalists and ambassadors, according to the Pegasus Project.

2021 Source →

Zero-click hacking of activistsBahrain

Wrongful stop

Bahraini human-rights activists were hacked with Pegasus in zero-click attacks that defeated new Apple protections, part of the Gulf state's documented use of commercial spyware against dissidents.

Pegasus on pro-democracy protestersThailand

Wrongful stop

Forensic analysis confirmed Pegasus on the phones of at least 30 Thai pro-democracy protesters, academics, and rights defenders during the 2020 to 2021 mass demonstrations, the first confirmed use of the spyware in the country.

2021 Source →

Civil society activists targetedKazakhstan

Wrongful stop

Four Kazakh civil society activists were confirmed targets of Pegasus, part of the leaked list of tens of thousands of phone numbers selected by NSO Group government clients.

2021 Source →

Pegasus against critics and clergyTogo

Wrongful stop

Togo appeared among NSO Group's Pegasus clients in the Pegasus Project, which documented the spyware being used against journalists, opposition figures, and members of the clergy critical of the government.

2021 Source →

Politician doubly infected with spywareEgypt

Wrongful stop

Egypt is a documented user of Predator spyware; in one case the phone of an exiled Egyptian politician was found simultaneously infected with both Predator and Pegasus, run by two different government clients.

2021 Source →

Predator spyware customerArmenia

Wrongful stop

Armenia was identified by Citizen Lab as a Predator spyware customer, part of a cluster of governments deploying the Cytrox tool against phones alongside the better-known Pegasus.

2021 Source →

Predator spyware customerIndonesia

Wrongful stop

Indonesia was documented as a Predator spyware customer, one of several governments Citizen Lab linked to the Cytrox surveillance tool used against people of interest.

2021 Source →

Predator spyware customerMadagascar

Wrongful stop

Madagascar was named among the government customers of Predator spyware identified by Citizen Lab, part of a growing roster of states buying commercial surveillance tools.

2021 Source →

Predator spyware customerOman

Wrongful stop

Oman was documented as a Predator spyware customer by Citizen Lab, adding a Gulf state to the list of governments using the Cytrox tool against targets of interest.

2021 Source →

Privacy Act breach, deletion orderedAustralia

Data misuse

Australia's information commissioner found in 2021 that Clearview AI breached the Privacy Act by scraping residents' faces without consent and ordered it to stop and delete the data; a tribunal upheld the ruling in 2023.

Mass scraping ruled illegalCanada

Data misuse

Canada's privacy commissioners ruled in 2021 that Clearview AI's mass scraping of facial images amounted to illegal surveillance and called on the company to stop and to delete Canadians' data.

2021 Source →

Care home fined for filming a disabled resident's bedroomSweden

Wrongful stop

In November 2020 the Swedish data-protection authority fined Gnosjo Municipality 200,000 SEK for unlawful video surveillance in an LSS home for people with functional impairments, after a resident was filmed in their own bedroom. The regulator found no legal basis and no impact assessment, calling it a severe and unjustifiable intrusion into the most private sphere of the home.

Nov 2020 Source →

Statewide plate-reader fleet, pushed to police bordersAustralia

Data misuse

Every Australian state runs plate readers. New South Wales' mobile MANPR fleet scans every passing vehicle statewide, storing hundreds of thousands of records a day, and was pushed to profile drivers at closed state borders during COVID lockdowns. The Australian Privacy Foundation calls ANPR a mass-surveillance technique that breaches freedom of movement.

Sep 2020 Sourcesmals.auprivacy.org.au

Court rules police face recognition unlawfulUnited Kingdom

Wrongful stop

A UK Court of Appeal ruling in Bridges v South Wales Police found the force's live facial recognition unlawful. Its AFR Locate system scanned up to 50 faces per second against watchlists that could include anyone, with images drawn even from social media, breaching privacy, data-protection, and equality law.

Aug 2020 Sourcessimmons-simmons.comeff.org

Black man jailed 26 days on a face-match errorBrazil

Wrongful stop

In Bahia, a Black man was wrongly detained for 26 days over a robbery committed by someone else a decade earlier, after a facial-recognition system misidentified him. It is one of several mistaken-identity cases tied to face recognition in Brazil since 2020.

Jun 2020 Source →

Como's public-square facial recognition ruled unlawfulItaly

Wrongful stop

In 2019 the northern Italian city of Como quietly bought, installed and tested a live facial-recognition system in public squares near its train station, among the first Italian municipalities to do so. After a journalistic investigation, the Italian data-protection authority (Garante) found the deployment had no legal basis under GDPR and ordered it stopped in 2020 -- a case that helped drive Italy's later national moratorium on public-space facial recognition.

Jun 2020 Source →

Facial-recognition app enforced Covid home quarantinePoland

Data misuse

In March 2020 Poland made its 'Home Quarantine' app mandatory for people ordered to isolate, requiring a geolocated facial-recognition selfie within 20 minutes of a random prompt. Failing to verify by face on demand triggered a police visit and possible fine, turning biometric identity checks into a routine tool of movement control and setting an early template other governments studied.

Mar 2020 Source →

Facial recognition used to identify protestersIndia

Wrongful stop

Delhi police used facial recognition to identify and arrest people from the 2020 anti-CAA protests and the communal riots that followed, later saying scores of the riot arrests were traced by the technology, and turned it on Sikh farmers during the 2021 farmers' protests. Rights groups documented its disproportionate use against Muslims and other minorities and a chilling effect on the right to protest.

Feb 2020 Source →

Face recognition aimed hardest at MuslimsIndia

Wrongful stop

Delhi police rolled out facial recognition that researchers found would inevitably fall hardest on the city's Muslim community, and used it to identify protesters, with much of the deployment kept under wraps.

Jan 2020 Source →

Greek police buy live face and fingerprint scan devicesGreece

Wrongful stop

In 2019 the Hellenic Police signed a roughly 4 million euro contract with Intracom Telecom for 'smart policing' devices -- handheld tools that let officers run live facial recognition and automated fingerprint identification on people during street stops. Part-funded by the EU, the deal was signed with no data-protection impact assessment and without consulting the Greek DPA, prompting complaints from digital-rights group Homo Digitalis.

Jan 2020 Sourcesedri.orgalgorithmwatch.org

Prague police roll out facial-recognition camerasCzechia

Wrongful stop

Around 2019-2020 Prague police sought approval to switch on automatic facial-recognition cameras at six locations in the Czech capital and bought recognition software from the firm Cogniware, extending biometric identification into public space with little public debate or oversight.

Jan 2020 Source →

Dutch police hold a 1.4 million-face recognition databaseNetherlands

Wrongful stop

By 2020 the Dutch national police maintained a facial-recognition database holding images of around 1.4 million people, and municipalities were rolling out face recognition in public space under 'pilot' and 'smart city living lab' labels that sidestepped regulatory scrutiny and frustrated public debate.

Jan 2020 Source →

EU project scraped social media to build a face databaseEuropean Union

Data misuse

SPIRIT was an EU-funded project to scrape social-media images and build a facial-recognition database for police use, with partners including the Hellenic Police, two UK forces (West Midlands and Thames Valley), the Serbian Interior Ministry and Poland's police academy. Critics likened its face-extraction and matching tools to Clearview AI; trials were planned for 2020-2021 with little transparency.

Jan 2020 Source →

Facial recognition to identify protestersBelarus

Wrongful stop

Belarus deployed facial recognition to identify and arrest participants in the 2020 post-election protests.

2020 Source →

Sandvine DPI used to shut down the internetBelarus

Data misuse

During the disputed 2020 election, Belarus used Sandvine deep-packet-inspection technology to block social media, messaging apps, and news sites amid a violent crackdown; Sandvine later found custom code had been inserted and canceled the contract.

Belgrade wired with thousands of Huawei face camerasSerbia

Data misuse

Belgrade has been fitted with thousands of Huawei 'Safe City' cameras carrying facial-recognition and plate-reading software, rolled out from 2019 with little transparency. The digital-rights group SHARE Foundation's 'Thousands of Cameras' campaign and Amnesty warned the system was unlawful and used to identify protesters, and biometric provisions were later dropped from a draft police law after public outcry.

Austrian police quietly ran facial recognition on CCTVAustria

Wrongful stop

Austria's federal police began using facial-recognition software to search surveillance footage at the end of 2019, comparing camera images against stored photos of suspects for after-the-fact identification. Rolled out with little public debate and limited to retrospective (not live) use, it made Austria one of a growing group of EU states quietly normalising biometric identification in criminal investigations.

Dec 2019 Source →

France's Alicem facial-recognition national IDFrance

Data misuse

In 2019 France moved to become the first European country to build a nationwide facial-recognition digital identity, Alicem, letting citizens verify themselves to government services by matching a selfie against their biometric passport. Digital-rights group La Quadrature du Net challenged it in court over the lack of any non-biometric alternative, arguing that effectively mandatory face-matching for state services breached the GDPR.

Oct 2019 Source →

Huawei facial recognition turned on the oppositionUganda

Wrongful stop

Uganda built a Huawei Safe City network of facial-recognition cameras across Kampala. A 2019 Wall Street Journal investigation found Huawei technicians helped state agents crack the encrypted communications of opposition leader Bobi Wine, leading to his arrest, and police later confirmed using the cameras to track people detained during anti-government protests. Opposition figures call it a tool to hunt and persecute critics.

Aug 2019 Source →

Protesters tear down face-scanning smart lamppostsHong Kong

Wrongful stop

During the 2019 pro-democracy protests, Hong Kongers wore masks and carried umbrellas and tore down 'smart lampposts' in Kowloon, fearing they held facial recognition that could identify demonstrators and expose them to arrest. Police had access to AI able to match faces from video to databases, and the fear of being identified kept some people away from the streets.

Aug 2019 Sourcesscmp.comcnn.com

Huawei face cameras blanket KampalaUganda

Data misuse

Uganda installed a 126 million dollar Huawei facial-recognition camera system across the capital, Kampala, which the president framed as a tool to fight street crime. Opposition figures said the real aim was to deter and identify protesters against an increasingly unpopular government. MEASURED AGAIN SEVEN YEARS LATER: the IDS and African Digital Rights Network study of 12 March 2026 counts approximately 5,000 smart cameras in Uganda, one of 11 African countries surveyed. Set against the USD 126 million reported for the original Huawei installation, Uganda is one of the larger deployments in that study by camera count while Nigeria leads on spend at over USD 470 million for about 10,000 cameras. The 2026 researchers found little evidence across all eleven countries that expanding digital surveillance reduces overall crime -- which speaks directly to the street-crime justification given here in 2019 -- and found that none of the eleven provides adequate means to obtain remedy for surveillance errors or abuse. The 2026 study's country figures, as reported by Nairametrics and military.africa, put Uganda's spend at USD 189 million for about 5,000 smart cameras -- roughly USD 37,800 a camera, and above the USD 126 million reported for the original 2019 Huawei installation.

EU's first facial-recognition fine over a school attendance trialSweden

Wrongful stop

In August 2019 the Swedish Data Protection Authority issued the EU's first GDPR facial-recognition fine -- 200,000 SEK (about 20,000 euros) against the Skelleftea municipal school board after Anderstorp High School piloted FR cameras to log the attendance of 22 students over three weeks. The regulator found consent could not be a valid legal basis given the power imbalance between school and pupils, that attendance could be tracked less intrusively, and that the school processed sensitive biometric data without an adequate impact assessment.

Aug 2019 Source →

EU pilots a biometric 'lie detector' on travellersEuropean Union

Data misuse

iBorderCtrl was an EU-funded research project that piloted an automated 'lie detector' at the Hungarian, Greek and Latvian borders, using biometric and facial analysis to score whether travellers -- including asylum seekers -- were being deceptive. Widely criticised as pseudoscientific and discriminatory, the project ran until August 2019 and became a symbol of biometric experimentation on migrants at Europe's frontier.

Aug 2019 Source →

Denmark's first face-scanning stadium, now joined by a bigger oneDenmark

Wrongful stop

In July 2019 the football club Brondby IF switched on Panasonic facial recognition at Brondby Stadium -- the first FR deployment in Denmark, approved by the Danish Data Protection Agency -- scanning roughly 14,000 fans per match against a ban list of about 50 people. Digital-rights group IT-Pol argued the system was disproportionate and set a dangerously low bar, and a University of Copenhagen law professor who sat on the deciding council agreed it should arguably never have been allowed. In 2025 the agency granted FC Copenhagen a more extensive stadium face-recognition system, deepening the normalisation of biometric surveillance in Danish sport.

Jul 2019 Sourcesedri.orgidtechwire.com

Top court struck down a mandatory biometric IDJamaica

Data misuse

Jamaica's Supreme Court struck down the National Identification and Registration Act in 2019, ruling that mandatory biometric registration for a national ID violated the constitutional right to privacy.

Apr 2019 Source →

Pegasus used against a Saudi dissident in CanadaCanada

Wrongful stop

Saudi dissident Omar Abdulaziz, a Canadian resident and confidant of Jamal Khashoggi, had his phone infected with Pegasus, and Citizen Lab detected suspected infections inside Canada.

Pegasus infected exiled journalists in LatviaLatvia

Wrongful stop

Exiled Russian journalists based in Latvia, including Meduza founder Galina Timchenko and Novaya Gazeta Europe's Maria Epifanova, were infected with Pegasus between 2020 and 2023.

Sep 2018 Sourcescpj.orgcitizenlab.ca

Pegasus targeted an investigative journalistDominican Republic

Wrongful stop

Investigative journalist Nuria Piera was repeatedly targeted with Pegasus between 2020 and 2023, confirmed by Amnesty International and Citizen Lab.

Pegasus used against journalists and lawyersPanama

Wrongful stop

Pegasus was used to surveil journalists, activists, and lawyers in Panama, with early deployments linked to the government under former president Ricardo Martinelli.

Sep 2018 Source →

Pegasus and the leaked target listPakistan

Wrongful stop

The phone number of then prime minister Imran Khan appeared on the leaked Pegasus target list, and Citizen Lab detected suspected Pegasus infections in Pakistan.

Pegasus infections tied to Khashoggi targetingTurkiye

Wrongful stop

Citizen Lab detected suspected Pegasus infections in Turkey, where associates of murdered journalist Jamal Khashoggi were among those targeted.

Sep 2018 Source →

Suspected Pegasus operator in BangladeshBangladesh

Wrongful stop

Citizen Lab detected suspected Pegasus infections in Bangladesh, where authorities have acquired a range of phone interception and surveillance systems.

Sep 2018 Source →

Suspected Pegasus operator in KenyaKenya

Wrongful stop

Citizen Lab detected suspected Pegasus infections linked to an operator in Kenya.

Sep 2018 Source →

Suspected Pegasus operator in South AfricaSouth Africa

Wrongful stop

Citizen Lab detected suspected Pegasus infections in South Africa.

Sep 2018 Source →

Suspected Pegasus operator in SingaporeSingapore

Wrongful stop

Citizen Lab detected suspected Pegasus infections in Singapore.

Sep 2018 Source →

Suspected Pegasus operator in TunisiaTunisia

Wrongful stop

Citizen Lab detected suspected Pegasus infections linked to an operator in Tunisia.

Sep 2018 Source →

Suspected Pegasus operator in QatarQatar

Wrongful stop

Citizen Lab detected suspected Pegasus infections linked to an operator in Qatar.

Sep 2018 Source →

Algeria opened a Pegasus inquiryAlgeria

Wrongful stop

After the Pegasus Project, Algeria's public prosecutor ordered an investigation into reports the country was targeted, and Citizen Lab detected suspected infections there.

Suspected Pegasus operator in IraqIraq

Wrongful stop

Citizen Lab detected suspected Pegasus infections linked to an operator in Iraq.

Sep 2018 Source →

Suspected Pegasus operator in UzbekistanUzbekistan

Wrongful stop

Citizen Lab detected suspected Pegasus infections linked to an operator in Uzbekistan.

Sep 2018 Source →

Suspected Pegasus operator in KuwaitKuwait

Wrongful stop

Citizen Lab detected suspected Pegasus infections linked to an operator in Kuwait.

Sep 2018 Source →

Suspected Pegasus operator in YemenYemen

Wrongful stop

Citizen Lab detected suspected Pegasus infections in Yemen.

Sep 2018 Source →

Suspected Pegasus infections in SwitzerlandSwitzerland

Wrongful stop

Citizen Lab detected suspected Pegasus infections in Switzerland.

Sep 2018 Source →

Suspected Pegasus operator in Ivory CoastCote d'Ivoire

Wrongful stop

Citizen Lab detected suspected Pegasus infections linked to an operator in Ivory Coast (Cote d'Ivoire).

Sep 2018 Source →

Suspected Pegasus operator in ZambiaZambia

Wrongful stop

Citizen Lab detected suspected Pegasus infections linked to an operator in Zambia.

Sep 2018 Source →

Suspected Pegasus operator in KyrgyzstanKyrgyzstan

Wrongful stop

Citizen Lab detected suspected Pegasus infections in Kyrgyzstan.

Sep 2018 Source →

Suspected Pegasus operator in TajikistanTajikistan

Wrongful stop

Citizen Lab detected suspected Pegasus infections linked to an operator in Tajikistan.

Sep 2018 Source →

Suspected Pegasus operator in LibyaLibya

Wrongful stop

Citizen Lab detected suspected Pegasus infections linked to an operator in Libya.

Sep 2018 Source →

Pegasus used against Palestinian rights defendersPalestine

Wrongful stop

Citizen Lab detected suspected Pegasus infections in Palestine, where Palestinian human rights defenders were later confirmed to have been hacked.

Sep 2018 Source →

World's largest biometric ID raises exclusion fearsIndia

Data misuse

India's Aadhaar program enrolled the biometrics of more than 1.3 billion people into the central CIDR database. Civil-society groups warn it drives surveillance and exclusion; India's Supreme Court recognized privacy as a fundamental right in 2017 and curbed mandatory Aadhaar use in 2018.

Wrongful stops from number-plate misreadsUnited Kingdom

Data misuse

Britain runs one of the world's largest automatic number-plate recognition networks, reading tens of millions of plates a day into a database of more than 20 billion records. The official surveillance camera commissioner warned that even at a claimed 97 percent accuracy the system misreads hundreds of thousands of plates a day, that police hold no meaningful data on its accuracy, and that misreads and cloned plates have led to wrongful stops and arrests of innocent motorists.

Jan 2018 Source →

Plate and vehicle tracking refined on UyghursChina

Data misuse

Hikvision, the world's largest maker of plate readers and surveillance cameras, refined vehicle and face tracking in Xinjiang, where checkpoints and cameras monitor Uyghurs' movements. Those battle-tested systems are now exported worldwide.

Facial-recognition trials at Berlin's Sudkreuz stationGermany

Wrongful stop

Germany's federal police ran live facial-recognition trials at Berlin's Sudkreuz station in 2017 and 2018, scanning volunteers against a watchlist to test automated identification in a busy transit hub. Interior Minister Horst Seehofer hailed the results and pushed to expand automatic facial recognition to more stations and airports, drawing fierce criticism from civil-liberties groups and data-protection officials over false positives and the normalisation of biometric mass surveillance in public space.

Jan 2018 Source →

Pegasus around the Khashoggi killingSaudi Arabia

Wrongful stop

Saudi Arabia used Pegasus against people close to murdered journalist Jamal Khashoggi, including an exiled dissident friend and his fiancee, whose phone was infected days after his 2018 killing.

2018 Source →

Chinese facial recognition for mass surveillanceZimbabwe

Wrongful stop

From 2018 Zimbabwe acquired facial-recognition technology from CloudWalk and Hikvision for border control and mass surveillance, with citizens' biometric data sent back to the Chinese vendors. QUANTIFIED IN 2026: the IDS and African Digital Rights Network study of 12 March 2026 records USD 10 million spent by Zimbabwe on smart city surveillance, the smallest published figure among the eleven countries studied, with the camera count not specified. That is a useful corrective to reading deployment scale from spending alone -- Zimbabwe's earlier significance on this map is the DATA FLOW, citizens' biometric data returning to the Chinese vendors, not the size of the contract. The 2026 study found the same pattern of Chinese supply and financing across all eleven countries, and no adequate means anywhere to obtain remedy for surveillance errors or abuse.

DPI redirected users to government spywareTurkiye

Wrongful stop

Citizen Lab's 2018 Bad Traffic report found Sandvine PacketLogic devices on Turkey's network redirecting hundreds of users to malicious sites that delivered government spyware, alongside blocking of political and news content.

Italy's secretive SARI police facial-recognition systemItaly

Wrongful stop

In 2017 Italy's Interior Ministry commissioned the SARI (Automatic Image Recognition System) facial-recognition platform for the scientific police from vendor Parsec 3.26. Rolled out with extreme secrecy and little oversight, SARI was shown to be biased and to draw heavily on a database skewed toward foreign nationals; its real-time mode was later blocked by the Garante pending a proper legal framework.

Nov 2017 Source →

Biometric dragnet over Uyghurs and Turkic MuslimsChina

Data misuse

China has built a pervasive biometric surveillance system across Xinjiang to control Uyghurs and other Turkic Muslims, combining facial-recognition checkpoints, mandatory collection of iris scans and DNA, and a predictive-policing platform that flags ordinary behavior as suspicious. It has funneled people into a network of detention camps that a 2022 UN report said may amount to crimes against humanity, with up to a million held.

Jan 2017 Source →

Gantry cameras log every vehicle for a tax not chargedDenmark

Data misuse

Denmark built 180 highway gantries and roughly 250 fixed plate-reading cameras for a lorry eco-tax. The cameras log every passing vehicle even though the tax is not being levied, and the scheme has drawn opposition.

Jan 2016 Source →

Early heavy use against dissidentsUnited Arab Emirates

Wrongful stop

The UAE was an early and heavy Pegasus user, targeting activist Ahmed Mansoor with a zero-day exploit in 2016 and later the ex-wife and associates of Dubai's ruler, part of one of the most extensive deployments of the spyware.

Spyware used against Ethiopian diaspora journalistsEthiopia

Wrongful stop

Ethiopian diaspora journalists at the ESAT broadcaster were targeted with Hacking Team's Remote Control System and Gamma's FinSpy spyware, documented by Citizen Lab.

Jul 2015 Sourcescitizenlab.cablog.sekoia.io

Hacking Team spyware client in ColombiaColombia

Wrongful stop

Colombian security agencies were clients of Hacking Team's Remote Control System spyware, revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcescitizenlab.cablog.sekoia.io

Hacking Team spyware client in EcuadorEcuador

Wrongful stop

Ecuador's intelligence agency SENAIN purchased Hacking Team's Remote Control System spyware, revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcescitizenlab.cablog.sekoia.io

Hacking Team spyware client in ChileChile

Wrongful stop

Chile's investigative police were clients of Hacking Team's Remote Control System spyware, revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcesblog.sekoia.iocitizenlab.ca

Hacking Team spyware client in HondurasHonduras

Wrongful stop

Honduras was among the government clients of Hacking Team's Remote Control System spyware revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcesblog.sekoia.iocitizenlab.ca

Hacking Team spyware client in NigeriaNigeria

Wrongful stop

Nigerian government bodies were among the clients of Hacking Team's Remote Control System spyware revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcesblog.sekoia.iocitizenlab.ca

Hacking Team spyware client in MalaysiaMalaysia

Wrongful stop

Malaysian agencies were among the clients of Hacking Team's Remote Control System spyware revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcesblog.sekoia.iocitizenlab.ca

Hacking Team spyware client in South KoreaSouth Korea

Wrongful stop

South Korea's National Intelligence Service was a client of Hacking Team's Remote Control System spyware, revealed by the 2015 breach and sparking domestic controversy.

Jul 2015 Sourcescitizenlab.cablog.sekoia.io

A nationwide plate-reading network for the whole countryHungary

Data misuse

Hungary built a unified national plate-reading network of 365 fixed gantries and 160 mobile units, feeding a central system used for traffic enforcement, registration and insurance checks, and stopping wanted or flagged vehicles nationwide.

Jan 2015 Source →

'Ring of steel' tracked every car in and out of a townUnited Kingdom

Wrongful stop

Hertfordshire police ringed the small town of Royston with ANPR cameras, logging every vehicle entering or leaving. After complaints by Big Brother Watch, Privacy International, and No CCTV, the UK data regulator ruled the scheme unlawful and excessive and ordered it halted.

Jul 2013 Sourcestheregister.comedri.org

A national plate-reader network built without debateUnited Kingdom

Data misuse

The UK runs one of the world's largest ANPR networks, feeding a central database, yet it was constructed by police without any parliamentary debate or public consultation, and privacy regulators warned the blanket approach may be unlawful.

Jan 2013 Sourcesedri.orgtechdirt.com

A motorway network that tracks cars by plateItaly

Data misuse

Italy's Tutor system covers more than 2,500 km of motorway, run jointly by the toll operator and the state police. It reads plates to calculate average speed over long stretches and can even track cars as they change lanes, logging the movements of every vehicle that passes.

Jan 2012 Source →

A city that scans every car crossing its boundaryBelgium

Data misuse

The Belgian city of Mechelen scans every car crossing its boundary, inbound and outbound, against blacklists, automatically checking about a million vehicles a week and dispatching patrols to intercept flagged cars.

Sep 2011 Source →

1,000 police cars scan every passing plateFrance

Data misuse

France equipped around 1,000 gendarmerie, police, and customs vehicles with plate-reading lightbars from the Paris firm Survision that continuously scan passing cars without any officer input and check them against databases.

May 2011 Source →

Police put a critic on a plate-reader watch listCanada

Data misuse

After a columnist criticized Edmonton police for using traffic cameras to raise revenue, officers added him to a plate-reader watch list of high-risk drivers to monitor his movements and look for a reason to arrest him. The police chief and several officers were dismissed, and Canada's privacy commissioner raised concerns.

Jan 2005 Source →

A secretive national plate-reading network since the 1980sJapan

Data misuse

Japan's National Police Agency has run the secretive N-System since the late 1980s, reading and recording license plates at hundreds of sites on highways and major roads, including a ring around Tokyo's Kabukicho district. Police disclose little about how long the data is kept or how it is used, and privacy advocates call it part of an emerging surveillance society.

Jan 1987 Sourcescsmonitor.comubisurv.net

Cyprus and the Intellexa surveillance tradeCyprus

Wrongful stop

Cyprus hosted operations of the Intellexa alliance behind the Predator spyware and was a client of Hacking Team, tying the island to Europe's mercenary surveillance trade.

Fatherland card links data to state benefitsVenezuela

Data misuse

Venezuela built the ZTE-backed fatherland card (carnet de la patria) system linking citizens' personal data to access to subsidized food and services, alongside Chinese-supplied surveillance cameras.

Chinese-supplied facial recognition surveillanceSri Lanka

Wrongful stop

Sri Lanka received Chinese-made AI surveillance and facial-recognition technology as part of Huawei and partner safe-city deployments.

DPI middleboxes injected Predator spywareEgypt

Wrongful stop

Telecom Egypt used Sandvine PacketLogic deep-packet-inspection middleboxes to inject Intellexa's Predator spyware into the connection of opposition presidential candidate Ahmed Eltantawy, alongside mass web-monitoring and news censorship; the US added Sandvine to its Entity List in 2024.

Blue Coat and Sandvine gear filtered the internetSyria

Data misuse

Syria's telecom authority deployed deep-packet-inspection equipment, including Blue Coat and Sandvine gear, to filter and censor the internet and redirect users to malicious sites during the civil war.

Amesys Eagle system enabled mass interceptionLibya

Data misuse

Under Muammar Gaddafi, Libya deployed the French company Amesys's Eagle system for nationwide internet interception and mass surveillance of dissidents; French magistrates later charged Amesys executives over complicity in torture.

Closed state supplied with DPI gearEritrea

Data misuse

Eritrea, one of the world's most closed states, was among the authoritarian governments supplied with Sandvine deep-packet-inspection equipment for internet control.

DPI gear powered social-media blackoutsAzerbaijan

Data misuse

Sandvine and Allot deep-packet-inspection equipment was deployed in Azerbaijan to impose social-media blackouts during periods of unrest.

DPI censorship throttles VPNs and newsRussia

Data misuse

Sandvine equipment was among the technology linked to internet censorship in Russia, which also runs the domestic TSPU deep-packet-inspection system to throttle and block VPNs, social media, and independent news.

DPI used to censor an LGBTQ websiteJordan

Data misuse

In Jordan, Sandvine equipment was used to censor an LGBTQ news website.

Every country on record

Diamonds on the map mark individual incidents (magenta for wrongful stops, cyan for data misuse), listed under the country where each happened, alongside the community records for that place.

North America 16
Canada 6

Canada

Restricted

Canada's Privacy Commissioner found the national police force, the RCMP, broke the Privacy Act by using Clearview AI, after regulators separately ruled Clearview's scraping of more than three billion images was illegal mass surveillance. The RCMP had run far more searches than it first admitted, and Clearview stopped offering its service in Canada.

Jun 2021 Clearview AI Source →

Victoria, BCCanada

Restricted

British Columbia's privacy commissioner ruled that Victoria police must immediately delete plate-reader data on vehicles that do not match a hot list, and that the public must be told the system's full scope, an early limit on Canadian ALPR retention.

Apr 2012 Alpr Source →

Wrongful stops & data misuse

Canada gives cabinet secret orders over telecom networks

Wrongful stop

CANADA'S CABINET CAN NOW ORDER TELECOM COMPANIES TO ACT -- AND ORDER THEM TO KEEP IT SECRET. Bill C-8 received Royal Assent on 15 June 2026. It lets the federal cabinet bar carriers from using named suppliers and lets the Industry Minister order a provider to do, or stop doing, anything needed to secure its network -- including cutting off service to specified persons -- with orders that can forbid disclosure of their own existence. The Minister can share what is collected with CSIS, the Communications Security Establishment, other departments, 'any other prescribed' body and foreign governments. Challenges go to court only after the fact, and the judge can hear evidence the challenger never sees: on 25 March the Speaker ruled out amendments that would have required a judge to approve orders first. The final law does bar ordering decryption of private communications or interception. A new Critical Cyber Systems Protection Act makes designated operators report incidents to CSE within 72 hours. The Privacy Commissioner, OpenMedia and the CCLA all said safeguards fall short. NOT ESTABLISHED: whether any secret order has been issued -- by design, the public may not learn. Read with Bill C-22, the lawful-access bill still in the Senate.

Mass scraping ruled illegal

Data misuse

Canada's privacy commissioners ruled in 2021 that Clearview AI's mass scraping of facial images amounted to illegal surveillance and called on the company to stop and to delete Canadians' data.

2021 Source →

Pegasus used against a Saudi dissident in Canada

Wrongful stop

Saudi dissident Omar Abdulaziz, a Canadian resident and confidant of Jamal Khashoggi, had his phone infected with Pegasus, and Citizen Lab detected suspected infections inside Canada.

Police put a critic on a plate-reader watch list

Data misuse

After a columnist criticized Edmonton police for using traffic cameras to raise revenue, officers added him to a plate-reader watch list of high-risk drivers to monitor his movements and look for a reason to arrest him. The police chief and several officers were dismissed, and Canada's privacy commissioner raised concerns.

Jan 2005 Source →
Dominican Republic 1

Pegasus targeted an investigative journalist

Wrongful stop

Investigative journalist Nuria Piera was repeatedly targeted with Pegasus between 2020 and 2023, confirmed by Amnesty International and Citizen Lab.

El Salvador 2

El Salvador

Contesting

After Citizen Lab and Access Now confirmed Pegasus infections on the phones of more than 20 journalists and civil-society members, most of them from the newspaper El Faro, the targeted journalists sued NSO Group in a US federal court. The suit was dismissed on jurisdictional grounds, a setback the plaintiffs appealed.

Nov 2022 Pegasus (NSO Group) Source →

Wrongful stops

35 journalists infected with Pegasus

Wrongful stop

Researchers confirmed Pegasus infections on 35 journalists and civil society members in El Salvador, with reporters at the outlet El Faro among the most heavily targeted as they investigated government corruption.

Jan 2022 Source →
Honduras 1

Hacking Team spyware client in Honduras

Wrongful stop

Honduras was among the government clients of Hacking Team's Remote Control System spyware revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcesblog.sekoia.iocitizenlab.ca
Jamaica 1

Top court struck down a mandatory biometric ID

Data misuse

Jamaica's Supreme Court struck down the National Identification and Registration Act in 2019, ruling that mandatory biometric registration for a national ID violated the constitutional right to privacy.

Apr 2019 Source →
Mexico 4

Mexico

Removed

Mexico's Supreme Court struck down PANAUT on Apr 25, 2022 -- the law that would have tied every one of the country's 120-million-plus mobile lines to a government registry of fingerprints, face and iris data, collected by carriers at the point of sale and available to law enforcement on request. Nine of eleven justices ruled the decree wholly unconstitutional and the remaining two partially so; Justice Norma Lucia Pina Hernandez, who had suspended the rollout in Jun 2021, put the principle plainly: a national registry of mobile users is not a necessary measure in a democracy, because it does not balance limited investigative need against the right to privacy. The challenges came from every direction at once -- the transparency institute INAI, 48 senators, the telecom regulator IFT (which filed over the unfunded mandate), and digital-rights group R3D. The court found the scheme disproportionate: conditioning phone access on surrendering biometrics to fight kidnapping fails data-minimisation when the burden lands on every innocent user. Mexico's FIRST registry, RENAUT (2008), ended with millions of users' data leaked and allegedly sold by officials before being abandoned in 2012 -- the strike-down is the middle chapter, not the end: a 2026 law now routes the same ambition through the biometric CURP national ID, redesigned to dodge the court's centralised-database objection, with a Yucatan tribunal already suspending it. See the CURP record on this map for the third attempt.

Mexico

Contesting

In November 2021 Mexico made the first arrest anywhere in the global Pegasus scandal, jailing a technician at a private firm that had brokered NSO's spyware to Mexican agencies on charges of illegally tapping a journalist's phone. Mexico was one of NSO's earliest and heaviest clients, with the spyware turned on journalists and activists, and the case opened the first criminal accountability for that abuse.

Nov 2021 Pegasus (NSO Group) Source →

Wrongful stops & data misuse

Biometric national ID mandated for all citizens

Data misuse

In July 2025 a presidential decree made the biometric CURP -- face, fingerprints, and iris captured in a QR code -- the mandatory national ID for nearly all public and private services. A new Unified Identity Platform links it to other state databases for real-time cross-checks, and from 2026 every mobile line must be tied to it. The decree lets prosecutors, the National Intelligence Center, the National Guard, and the security ministry consult the database -- including bank and telecom data -- without notifying the person. Framed as a response to Mexico's missing-persons crisis, it drew warnings of a mass-surveillance ecosystem from digital-rights groups R3D and Article 19, and courts in several states issued injunctions pausing the rollout.

Mexico's army spied on journalists with Pegasus

Wrongful stop

Mexico is the most heavily targeted country in the Pegasus files. First exposed in 2017, the NSO spyware was used against journalists like Carmen Aristegui, whose teenage son was also hit, along with activists and lawyers for victims of disappearances. The Ejercito Espia investigation later showed the army kept using Pegasus against reporters and a human rights defender into 2021, even after the president pledged the practice had stopped.

Panama 1

Pegasus used against journalists and lawyers

Wrongful stop

Pegasus was used to surveil journalists, activists, and lawyers in Panama, with early deployments linked to the government under former president Ricardo Martinelli.

Sep 2018 Source →
South America 15
Argentina 2

Buenos AiresArgentina

Paused

A court suspended Buenos Aires's live facial-recognition fugitive system in April 2022 and ruled it unconstitutional that September, upheld on appeal in 2023, after it was used to run unauthorized searches on thousands of people not on any wanted list, including journalists, politicians, and activists. It remains suspended pending audit safeguards.

Sep 2022 (approx.) Facial recognition Source →

Wrongful stops

Facial recognition ran searches on thousands not wanted

Wrongful stop

Buenos Aires's facial-recognition system was used to run unauthorized searches on more than 15,000 people not on any fugitive list, including journalists, politicians, and activists, and wrongly jailed a factory worker for nearly a week after a database error.

Apr 2022 Source →
Brazil 7

Brazil

Denied

Brazil's data authority banned Worldcoin in Jan 2025 on the same principle Kenya's court later reached: paying for biometrics breaks consent. The ANPD found that offering cryptocurrency for iris scans violates Brazil's data law, which requires consent for biometric collection to be free, informed and unequivocal -- a financial inducement aimed at people who need the money is none of those. In Mar 2025 the regulator reaffirmed the ban and attached a daily fine of 50,000 reais (about $8,800) should collection resume. Brazil is the largest economy to bar the program outright rather than suspend it, and its reasoning -- that the poorer the subject, the less voluntary the trade -- is the argument against biometrics-for-cash programs generally, not just this one.

Jan 2025 Worldcoin iris scanning Sourcesrestofworld.orgcoingeek.com

Brazil

Contesting

Courts suspended Sao Paulo Metro's facial-recognition system in 2022 after a public civil action by civil society groups, and a campaign backed by legislators across 13 states has pushed bills to ban facial recognition in public spaces. The city's larger Smart Sampa camera network has advanced despite the legal challenges.

Mar 2022 Facial recognition Source →

Wrongful stops & data misuse

Face recognition in 1,600 Parana schools, with no national rules

Wrongful stop

1,600 SCHOOLS IN PARANA ALONE. InternetLab's November 2025 study found facial recognition running in public schools in at least seven Brazilian states -- Alagoas, Amazonas, Goias, Parana, Rio de Janeiro, Sao Paulo and Tocantins -- and earlier use in six more, mostly to take attendance. Parana has installed it in 1,600 schools. There are no national rules setting minimum safeguards for scanning children's faces, and the company supplying most of the systems did not answer the researchers. No ruling by Brazil's data protection authority on school use is recorded here. Ask each state education department for the contract, the retention period and the legal basis under the LGPD.

Nov 2025 Source →

Wrongful detentions from face-match errors

Wrongful stop

Brazil's expanding police facial recognition has repeatedly detained innocent people, overwhelmingly Black. One man was tracked across fifteen train stations in Bahia before being held on a false match, another was detained in front of a stadium crowd, and in 2025 an 80-year-old volunteer was taken to a police station after cameras mistook him for a wanted man. A study found about 90 percent of those arrested through the technology in several states were Black Brazilians.

Apr 2024 Source →

Woman wrongly detained as a fugitive

Data misuse

In Rio de Janeiro, a woman was wrongly detained after a facial-recognition database flagged her as a fugitive, even though she was already serving her sentence under an open regime.

Jan 2024 Source →

Sao Paulo builds a 20,000-camera face network

Wrongful stop

Sao Paulo's Smart Sampa program wires up to 20,000 cameras with facial recognition across a city of 12 million, watching streets, schools, and public spaces. Rights groups warn it could drive mass incarceration of Black residents, citing a 2019 study that found about 90 percent of those arrested through facial recognition in Brazil were Black. The Public Defender's Office sued to suspend it.

Black man jailed 26 days on a face-match error

Wrongful stop

In Bahia, a Black man was wrongly detained for 26 days over a robbery committed by someone else a decade earlier, after a facial-recognition system misidentified him. It is one of several mistaken-identity cases tied to face recognition in Brazil since 2020.

Jun 2020 Source →
Chile 2

Judge and general jailed for spying on a journalist

Wrongful stop

A Chilean court on Jun 30, 2026 sentenced a former judge and a former army general to five years in prison for illegally spying on investigative journalist Mauricio Weibel Barahona while he was reporting Milicogate -- his 2015 investigation for The Clinic into the theft of the army's copper reserve fund. The Committee to Protect Journalists called the decision unprecedented for Chile. Two details give it weight beyond the country: the surveillance was run through the machinery of state -- a judge and a general, not a rogue operator -- against a journalist for the act of reporting on the military that employed one of them; and accountability took eleven years from publication and six years of judicial process to arrive. Custodial sentences for state officials over journalist surveillance remain rare enough worldwide that each one is a record; this is Latin America's counterpart to Greece's Feb 2026 Predatorgate convictions, and unlike Greece's suspended terms, these are prison sentences.

Jun 2026 Source →

Hacking Team spyware client in Chile

Wrongful stop

Chile's investigative police were clients of Hacking Team's Remote Control System spyware, revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcesblog.sekoia.iocitizenlab.ca
Colombia 1

Hacking Team spyware client in Colombia

Wrongful stop

Colombian security agencies were clients of Hacking Team's Remote Control System spyware, revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcescitizenlab.cablog.sekoia.io
Ecuador 2

Clearview expands face search across Latin America

Wrongful stop

The American firm Clearview AI is expanding across Latin America, giving law enforcement in countries including Argentina, Brazil, Colombia, and Ecuador access to its database of billions of scraped faces, even as it faces fines and bans elsewhere. Rights advocates warn it puts much of the region in a perpetual police lineup, risking wrongful arrests and profiling.

Mar 2024 Source →

Hacking Team spyware client in Ecuador

Wrongful stop

Ecuador's intelligence agency SENAIN purchased Hacking Team's Remote Control System spyware, revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcescitizenlab.cablog.sekoia.io
Venezuela 1

Fatherland card links data to state benefits

Data misuse

Venezuela built the ZTE-backed fatherland card (carnet de la patria) system linking citizens' personal data to access to subsidized food and services, alongside Chinese-supplied surveillance cameras.

Europe 126
Austria 2

Austria

Contesting

Austria's DPA found Clearview AI acted illegally. The privacy group noyb filed a criminal complaint against the company and its managers.

Oct 2025 Facial recognition Source →

Wrongful stops

Austrian police quietly ran facial recognition on CCTV

Wrongful stop

Austria's federal police began using facial-recognition software to search surveillance footage at the end of 2019, comparing camera images against stored photos of suspects for after-the-fact identification. Rolled out with little public debate and limited to retrospective (not live) use, it made Austria one of a growing group of EU states quietly normalising biometric identification in criminal investigations.

Dec 2019 Source →
Belarus 2

Facial recognition to identify protesters

Wrongful stop

Belarus deployed facial recognition to identify and arrest participants in the 2020 post-election protests.

2020 Source →

Sandvine DPI used to shut down the internet

Data misuse

During the disputed 2020 election, Belarus used Sandvine deep-packet-inspection technology to block social media, messaging apps, and news sites amid a violent crackdown; Sandvine later found custom code had been inserted and canceled the contract.

Belgium 4

EU-US Enhanced Border Security Partnership frameworkBelgium

Contesting

THE EU IS ABOUT TO LET US BORDER AUTHORITIES SEARCH EUROPEAN FINGERPRINT DATABASES -- THE PRICE OF VISA-FREE TRAVEL. Negotiations on an EU-US framework for Enhanced Border Security Partnerships closed on 23 July 2026, and on 10 September the Commission asked the Council to sign it and apply it provisionally. It allows reciprocal fingerprint and identity searches of national databases when an official records a serious risk to public security; Biometric Update reports face images are excluded as a search key. Each member state then signs its own deal with the US naming its databases. Washington made these partnerships a Visa Waiver Program condition in 2022 and set 31 December 2026 as its assessment cutoff. The European Data Protection Supervisor warned this would be the EU's first large-scale biometric sharing deal for a foreign border service; Statewatch says the text exceeds the Council's own mandate and weakens protection against profiling. Ireland and Denmark are outside the framework. Not established: when the Council and the European Parliament will vote.

Police use of Clearview ruled unlawfulBelgium

Contesting

Belgium oversight body for police information, the COC, found in February 2022 that federal police use of Clearview AI facial recognition was not legal, not authorized, and not necessary, with no sufficient basis in police law. It followed a 2019 order to halt a facial-recognition trial at Brussels Airport for the same reason. The interior minister confirmed the tool was illegal under Belgian law, though lawmakers continue to debate a framework that could permit narrow police use.

Feb 2022 Facial recognition Source →

Belgium

Removed

In 2017 Brussels Airport (Zaventem) quietly installed four facial-recognition cameras for the airport police to match travellers against a blacklist, without informing Belgium's police-information oversight body (COC). When it found out, the COC ruled the deployment fell outside any lawful framework and it was stopped; the system had also proved unreliable, with false positives tied to skin colour and facial hair. Belgium remains one of the EU states that has not authorised police facial recognition.

Jan 2021 Facial recognition Source →

Data misuse

A city that scans every car crossing its boundary

Data misuse

The Belgian city of Mechelen scans every car crossing its boundary, inbound and outbound, against blacklists, automatically checking about a million vehicles a week and dispatching patrols to intercept flagged cars.

Sep 2011 Source →
Bulgaria 1

Bulgaria

Restricted

In Ekimdzhiev and Others v. Bulgaria (January 2022) the European Court of Human Rights found that Bulgaria's systems of secret surveillance and of bulk retention of communications data both violated the right to privacy under Article 8, citing weak authorisation, oversight and notification safeguards that left the regime open to abuse. It built directly on the Court's bulk-interception standards from Big Brother Watch.

Jan 2022 Secret surveillance & retention Source →
Cyprus 1

Cyprus and the Intellexa surveillance trade

Wrongful stop

Cyprus hosted operations of the Intellexa alliance behind the Predator spyware and was a client of Hacking Team, tying the island to Europe's mercenary surveillance trade.

Czechia 2

Prague airport facial recognition switched off, then leashedCzechia

Restricted

Czech police ran the country's only officially operating automatic facial-recognition system at Prague's Vaclav Havel Airport from 2018, converting travellers' faces into numeric 'bio-indexes' and matching them against wanted and missing-person databases. The digital-rights group Iuridicum Remedium complained to the Czech data-protection office in 2021, and its multi-year inspection concluded in mid-2025 that the deployment breached Czech and EU law. Once the EU AI Act's biometric provisions took effect in February 2025 the system needed judicial authorisation it had never obtained, and police switched it off on August 1, 2025 -- by the NGO's reckoning, six months of confirmed illegal operation. The Prague High Court let it back on February 26, 2026, but only on a leash: capture confined to non-Schengen exit passport lanes, no scanning of arrival halls or retail areas, deletion within 36 hours unless a match produces an investigative lead, raw images restricted to senior officers, the system isolated from the internet, quarterly independent audits, and standing power for the data-protection office to suspend it again.

  1. Jan 2021 Iuridicum Remedium filed a complaint with the Czech data-protection office, arguing police had no explicit legal basis to process biometric data through airport cameras. edri.org
  2. Feb 2025 The EU AI Act's biometric provisions took effect, making real-time biometric identification unlawful without judicial authorisation the airport system had never received. biometricupdate.com
  3. Aug 2025 Czech police shut the system down on August 1, 2025, the only officially running automatic facial-recognition deployment in the country. edri.org
  4. Feb 2026 The Prague High Court authorised a restart from mid-March 2026 under geofencing, 36-hour deletion, restricted access, and quarterly audit conditions. expats.cz
Feb 2026 Facial recognition Sourcesedri.orgbiometricupdate.comexpats.cz

Wrongful stops

Prague police roll out facial-recognition cameras

Wrongful stop

Around 2019-2020 Prague police sought approval to switch on automatic facial-recognition cameras at six locations in the Czech capital and bought recognition software from the firm Cogniware, extending biometric identification into public space with little public debate or oversight.

Jan 2020 Source →
Denmark 3

Automated welfare state flags 'atypical' lives for fraud probes

Wrongful stop

A November 2024 Amnesty International investigation, 'Coded Injustice,' found Denmark's welfare agency Udbetaling Danmark and its administrator ATP run some 60 fraud-detection algorithms -- including a 'Really Single' model that guesses a person's relationship status and the 'Gladsaxe Model' -- that mine vast personal data and flag 'unusual' or 'atypical' living and family patterns, disproportionately targeting people with disabilities, low incomes, migrants and foreigners. Denmark's Parliamentary Ombudsman opened an inquiry; the agency denies it amounts to social scoring.

Nov 2024 Source →

Denmark's first face-scanning stadium, now joined by a bigger one

Wrongful stop

In July 2019 the football club Brondby IF switched on Panasonic facial recognition at Brondby Stadium -- the first FR deployment in Denmark, approved by the Danish Data Protection Agency -- scanning roughly 14,000 fans per match against a ban list of about 50 people. Digital-rights group IT-Pol argued the system was disproportionate and set a dangerously low bar, and a University of Copenhagen law professor who sat on the deciding council agreed it should arguably never have been allowed. In 2025 the agency granted FC Copenhagen a more extensive stadium face-recognition system, deepening the normalisation of biometric surveillance in Danish sport.

Jul 2019 Sourcesedri.orgidtechwire.com

Gantry cameras log every vehicle for a tax not charged

Data misuse

Denmark built 180 highway gantries and roughly 250 fixed plate-reading cameras for a lorry eco-tax. The cameras log every passing vehicle even though the tax is not being levied, and the scheme has drawn opposition.

Jan 2016 Source →
Estonia 1

Estonia

Restricted

In Prokuratuur (2021) the EU Court of Justice ruled that police and prosecutors cannot freely reach into retained phone traffic and location data: access to communications metadata must be authorised in advance by a court or an independent authority, and a public prosecutor who directs the investigation is not independent enough. The Estonian case set an EU-wide guardrail on who can access retained data.

Mar 2021 Retained data access Source →
European Union 6

European Union

Restricted

The EU AI Act Article 5 bans real-time remote biometric identification (live facial recognition) by law enforcement in publicly accessible spaces, with narrow exceptions. The prohibited-practices rules took effect 2 February 2025.

Feb 2025 Facial recognition Source →

European Union

Contesting

The European Parliament set up a committee of inquiry, known as PEGA, into the use of Pegasus and equivalent spyware across member states. Active from April 2022, its final report in May 2023 found that spyware had been used to illegally target journalists, politicians, and critics in countries including Poland, Hungary, Greece, and Spain, and it called for a moratorium and binding safeguards on the sale and use of such tools in the EU.

May 2023 NSO Group, Intellexa Source →

European Union

Restricted

In Schrems II (Facebook Ireland and Schrems, 2020) the EU Court of Justice struck down the EU-US Privacy Shield data-transfer deal because US surveillance law -- letting agencies like the NSA access transferred data with no equivalent protection or redress for Europeans -- was incompatible with EU privacy rights. The EU's top court effectively ruled that US mass surveillance failed European fundamental-rights standards.

Jul 2020 US surveillance / data transfer Source →

European Union

Restricted

The EU's Court of Justice has repeatedly struck down blanket data retention -- the legal backbone that limits indiscriminate systems like ANPR. In Digital Rights Ireland (2014) it annulled the Data Retention Directive as a disproportionate mass intrusion; in Tele2 Sverige (2016) it held that national laws requiring general, indiscriminate retention of traffic and location data are unlawful; and in later rulings (La Quadrature du Net, SpaceNet) it kept the ban while allowing only narrow, targeted exceptions. The principle: mass retention of data, including vehicle-location reads, must be targeted, time-limited and independently overseen.

Apr 2014 Data retention Source →

Data misuse

EU project scraped social media to build a face database

Data misuse

SPIRIT was an EU-funded project to scrape social-media images and build a facial-recognition database for police use, with partners including the Hellenic Police, two UK forces (West Midlands and Thames Valley), the Serbian Interior Ministry and Poland's police academy. Critics likened its face-extraction and matching tools to Clearview AI; trials were planned for 2020-2021 with little transparency.

Jan 2020 Source →

EU pilots a biometric 'lie detector' on travellers

Data misuse

iBorderCtrl was an EU-funded research project that piloted an automated 'lie detector' at the Hungarian, Greek and Latvian borders, using biometric and facial analysis to score whether travellers -- including asylum seekers -- were being deceptive. Widely criticised as pseudoscientific and discriminatory, the project ran until August 2019 and became a symbol of biometric experimentation on migrants at Europe's frontier.

Aug 2019 Source →
Finland 1

Finland

Restricted

Finland Deputy Data Protection Ombudsman reprimanded the National Police Board in 2021 for unlawfully processing personal data when the National Bureau of Investigation trialed Clearview AI facial recognition during a child-abuse investigation. The ombudsman ordered the police to have Clearview erase the data they had transmitted and to notify affected people. The police had already dropped the tool, finding it unsuitable for their work.

Sep 2021 Clearview AI Source →
France 9

France

Restricted

France's data protection authority moved against Clearview AI in two stages. In December 2021 the CNIL ordered the company to stop collecting and using the face data of people in France and to delete what it held, finding the scraping had no legal basis. Clearview did not comply, and in October 2022 the CNIL fined it EUR 20 million for unlawful biometric processing -- one of a wave of European penalties the company has largely declined to pay, having no establishment in the EU for regulators to enforce against.

Oct 2022 Facial recognition Sourcestime.comedri.org

France

Removed

In February 2021 France's data-protection authority (CNIL) ruled that FC Metz's experimental stadium system -- meant to spot fans under civil stadium bans, detect abandoned objects and bolster counter-terror measures -- unlawfully processed biometric data. It was one of several French facial-recognition deployments, alongside school entry gates and a citizen-filming app in Nice, that regulators and courts struck down.

Feb 2021 Facial recognition Source →

School facial-recognition gates annulledFrance

Denied

A regional plan to install facial-recognition entry gates at two high schools in Nice and Marseille was struck down. The data-protection regulator CNIL warned in October 2019 that the trial was unlawful, and in February 2020 the Administrative Court of Marseille annulled it, ruling that the region had no authority to impose it, that students could not freely consent under school authority, and that the measure was disproportionate. It was the first French court decision applying the GDPR to facial recognition in a public space.

Feb 2020 Facial recognition Source →

France

Restricted

In Ben Faiza v. France (2018) the European Court of Human Rights found that real-time GPS tracking of a suspect's vehicle breached the right to privacy, because French law at the time gave no clear, foreseeable legal basis for such geolocation surveillance. The ruling pushed France to put covert location tracking on a proper statutory footing.

Feb 2018 GPS tracking Source →

Wrongful stops & data misuse

Legal challenge to the benefits agency's fraud-scoring algorithm

Data misuse

In October 2024 a coalition of 15 organisations, including La Quadrature du Net and Amnesty International, filed a complaint before France's top administrative court against the risk-scoring algorithm used by the national family-benefits fund CNAF. The system assigns welfare recipients a fraud-suspicion score from data on their circumstances; analysis showed it effectively rated the poorest, single parents, disabled people and those born outside the EU as higher risk, singling them out for intrusive checks.

Oct 2024 Source →

Interior Ministry's secret use of Briefcam video analytics

Wrongful stop

In late 2023 investigative outlet Disclose revealed that France's national police and gendarmerie had for years quietly used Briefcam, an Israeli video-analytics system capable of facial recognition, to search and filter surveillance footage without public debate or, critics argued, a clear legal basis. A 2024 CNIL investigation concluded the Interior Ministry had not used the software for real-time facial recognition in public space, but the episode exposed how FR-capable tools were deployed in secrecy.

Nov 2023 Source →

Clearview AI fined for face scraping

Data misuse

France's data-protection regulator fined Clearview AI roughly 20 million euros and ordered it to stop collecting and to delete residents' data, after finding the company unlawfully scraped billions of faces into a recognition database sold to police.

2022 Source →

France's Alicem facial-recognition national ID

Data misuse

In 2019 France moved to become the first European country to build a nationwide facial-recognition digital identity, Alicem, letting citizens verify themselves to government services by matching a selfie against their biometric passport. Digital-rights group La Quadrature du Net challenged it in court over the lack of any non-biometric alternative, arguing that effectively mandatory face-matching for state services breached the GDPR.

Oct 2019 Source →

1,000 police cars scan every passing plate

Data misuse

France equipped around 1,000 gendarmerie, police, and customs vehicles with plate-reading lightbars from the Paris firm Survision that continuously scan passing cars without any officer input and check them against databases.

May 2011 Source →
Germany 7

Germany

Restricted

German data protection authorities ordered World in Dec 2024 to delete data that did not comply with the EU's General Data Protection Regulation -- the EU's consent and lawful-basis rules applied to an iris-scanning program headquartered partly in Berlin. Germany's move mattered less for its scope than for its venue: Tools for Humanity is a San Francisco and Berlin company, so this was the program's home-jurisdiction regulator finding its data holdings partly unlawful. Recorded as restricted rather than removed because collection was not barred outright; the order targeted non-compliant data. Marked approximate: the record is pinned at Berlin as a national-scope convention.

Dec 2024 (approx.) Worldcoin iris scanning Source →

Germany

Contesting

German data protection authorities found Clearview AI unlawful and ordered deletion, but the federal government has proposed a law granting police powers to match faces against public internet image databases. Legal scholars and civil society warn it breaches the constitution and EU law.

Oct 2024 (approx.) Facial recognition Source →

HamburgGermany

Removed

Hamburg police deleted their G20 facial-recognition database in 2020 -- a system that had biometrically templated roughly 100,000 people. After the 2017 G20 summit riots, police ran Videmo 360 face-recognition across uploaded private recordings, police video, S-Bahn station footage and media material, mathematically templating every identifiable face -- overwhelmingly bystanders never suspected of anything -- for automated matching against suspects. Data Protection Commissioner Johannes Caspar called it a new dimension of state investigation, warned the suspicionless material allowed inferences about behaviour patterns and preferences, objected in Aug 2018, and ordered deletion in Dec 2018 -- the first and only time he used his power to instruct the police. THE HONEST SEQUENCE, because this is not a clean regulator win: Hamburg's Administrative Court OVERTURNED the deletion order, ruling the DPA lacked competence to review the legal basis. The police then deleted the database anyway, telling the DPA it was simply no longer needed for the G20 prosecutions -- and the state government moved to strip the commissioner's instruction power in the new police law. The yield figures argue for themselves: 75 searches commissioned from the BKA after G20, three hits, one in five images unusable. A hundred thousand people templated for three matches, deleted without ever conceding it was unlawful.

May 2020 (approx.) Facial recognition (Videmo 360) Sourcesidentityweek.netdigit.site36.netgreens-efa.eu

Germany

Restricted

Germany's Federal Constitutional Court ruled automatic plate recognition unconstitutional in 2008 and again in 2019, striking down provisions in Bavaria, Baden-Wurttemberg, and Hesse as violating the right to informational self-determination. The systems were built by Jenoptik.

Wrongful stops & data misuse

Police in four states run Palantir 'dragnet' data-mining

Data misuse

German state police have adopted Palantir's Gotham data-mining platform -- Hesse's HessenData since 2017, North Rhine-Westphalia's DAR, Bavaria's VeRA (live from late 2024) and Baden-Wurttemberg from 2025 -- to fuse names, addresses, phone and social-media records into instant profiles, including of people never suspected of a crime. In a 2023 landmark ruling the Federal Constitutional Court struck down the Hesse and Hamburg data-mining laws as too broad; civil-liberties groups GFF and the Chaos Computer Club have since filed constitutional complaints against Bavaria and North Rhine-Westphalia, calling it a 'Palantir dragnet.'

Retailer fined 10.4M euros for spying on staff by CCTV

Wrongful stop

In a decision made public in January 2021, the Lower Saxony data-protection authority fined online electronics retailer notebooksbilliger.de about 10.4 million euros for unlawfully video-monitoring its employees for at least two years. The regulator found blanket CCTV over workspaces and public areas, justified only by a general suspicion of theft, had no legal basis under the GDPR -- one of Germany's largest fines for workplace surveillance.

Jan 2021 Source →

Facial-recognition trials at Berlin's Sudkreuz station

Wrongful stop

Germany's federal police ran live facial-recognition trials at Berlin's Sudkreuz station in 2017 and 2018, scanning volunteers against a watchlist to test automated identification in a busy transit hub. Interior Minister Horst Seehofer hailed the results and pushed to expand automatic facial recognition to more stations and airports, drawing fierce criticism from civil-liberties groups and data-protection officials over false positives and the normalisation of biometric mass surveillance in public space.

Jan 2018 Source →
Greece 8

Greece

Contesting

The Predatorgate scandal broke in 2022 when Predator spyware, made by the Intellexa group, was found on the phones of a financial journalist and the leader of the opposition PASOK party, who was also a member of the European Parliament. The national intelligence chief and the general secretary to the prime minister resigned, parliament passed a 2022 law on lifting communications confidentiality, and in February 2026 a Greek court convicted figures behind the Predator operation, a rare instance of accountability in the spyware industry.

Aug 2022 Intellexa Source →

Greece

Restricted

Greece's Data Protection Authority fined Clearview AI EUR 20 million, its largest-ever penalty against a private company, for unlawfully processing Greek citizens' biometric data.

Jul 2022 Facial recognition Sourceswearesolomon.comeuronews.com

Wrongful stops & data misuse

The spyware inquiry was itself spied on: Pegasus on a PEGA member's phone

Data misuse

THE SPYWARE INQUIRY WAS ITSELF SPIED ON. Citizen Lab reported on 3 July 2026 that Stelios Kouloglou, a Greek former MEP and substitute member of the European Parliament's PEGA committee investigating Pegasus, was infected with Pegasus twice while the committee sat -- on 21 October 2022 in Greece and on 6-7 March 2023 in Belgium. Apple sent him three threat notifications he reportedly did not recall. Citizen Lab does not name a government, says it found no sign the Greek government was responsible, and ties the operation to a campaign against exiled Russian- and Belarusian-speaking journalists in Europe -- pointing to a Pegasus customer able to operate in several EU countries. Whether the Parliament has opened an inquiry into the breach is not established here.

Jul 2026 Source →

Greek Watergate and the Predator convictions

Wrongful stop

In the Greek Watergate scandal, Intellexa's Predator spyware was used against politicians and journalists, and in 2026 a Greek court sentenced Intellexa founder Tal Dilian and others to eight years for illegal operations.

Mar 2026 Source →

AI cameras and biometrics turn refugee camps into 'high-tech prisons'

Wrongful stop

At Greece's EU-funded Closed Controlled Access Centres for asylum seekers, two systems -- Centaur (CCTV, drones and AI behavioural analytics that flag 'threats' and log incidents, monitored from Athens) and Hyperion (biometric fingerprint entry and exit) -- put residents under constant surveillance behind curfews, with cameras even in sleeping containers. Most residents interviewed said they were never told they were being filmed. In April 2024 the Greek Data Protection Authority fined the Migration Ministry 175,000 euros for GDPR breaches over the rollout.

Predator spyware targets Greece's journalists and politicians

Wrongful stop

In the scandal known as Predatorgate, the Predator spyware sold by the Israeli-founded firm Intellexa was used to target more than ninety journalists, the opposition leader Nikos Androulakis, ministers, and senior military officers between 2020 and 2022, alongside wiretaps by the national intelligence service. The case forced top resignations, and in 2026 an Athens court handed eight-year sentences to four people linked to Intellexa, a rare criminal reckoning for the spyware trade.

Jul 2022 Sourcesamnesty.orgen.wikipedia.org

Clearview AI fined for face scraping

Data misuse

Greece's data-protection authority fined Clearview AI about 20 million euros for unlawfully scraping and processing residents' facial images, part of roughly 100 million euros in EU fines the company has largely ignored.

2022 Source →

Greek police buy live face and fingerprint scan devices

Wrongful stop

In 2019 the Hellenic Police signed a roughly 4 million euro contract with Intracom Telecom for 'smart policing' devices -- handheld tools that let officers run live facial recognition and automated fingerprint identification on people during street stops. Part-funded by the EU, the deal was signed with no data-protection impact assessment and without consulting the Greek DPA, prompting complaints from digital-rights group Homo Digitalis.

Jan 2020 Sourcesedri.orgalgorithmwatch.org
Hungary 5

Hungary

Contesting

Hungary used Pegasus against journalists, lawyers, and opposition figures, with more than 300 people reportedly targeted. The government's own data-protection authority found no wrongdoing, but targeted journalists, backed by the Hungarian Civil Liberties Union, filed the first lawsuits against the state in 2022, the European Court of Human Rights took up a related case in 2023, and the European Parliament's PEGA inquiry condemned Hungary's use and demanded independent judicial authorization.

Jan 2022 Pegasus (NSO Group) Source →

Hungary

Restricted

In Szabo and Vissy v. Hungary (January 2016) the European Court of Human Rights found Hungary's sweeping anti-terror secret-surveillance law unlawful under Article 8, because it let authorities order surveillance without a sufficient factual basis or meaningful judicial control -- effectively enabling untargeted monitoring of virtually anyone. The ruling reinforced the requirement of individualised suspicion and independent oversight for secret surveillance.

Jan 2016 Secret surveillance Source →

Wrongful stops & data misuse

Facial recognition turned on Pride marchers and minor offenders

Wrongful stop

In March 2025 Hungary's Parliament rushed through three amendments in 24 hours -- to the Assembly Act, the Infraction Act and the Facial Recognition Technology Act -- banning Pride events and authorising police to use live facial recognition to identify participants and anyone committing even minor infractions such as jaywalking. Effective April 15, 2025, it dramatically widened biometric surveillance of peaceful assembly. Rights groups (HCLU, EDRi, ECNL, Liberties for Europe) argue it violates the EU AI Act, which already bars real-time remote biometric identification in public, and the EU Charter; the European Commission has been slow to act. Budapest Pride went ahead in June 2025 as the country's largest anti-government demonstration in years.

Apr 2025 Sourcesedri.orgeuobserver.com

State spyware on journalists and critics

Wrongful stop

Hungary's Interior Ministry bought Pegasus for about 6 million euros and used it against investigative journalists such as Szabolcs Panyi of Direkt36, along with opposition figures, lawyers, and a media-owning businessman, an EU member state turning spyware on its own critics.

A nationwide plate-reading network for the whole country

Data misuse

Hungary built a unified national plate-reading network of 365 fixed gantries and 160 mobile units, feeding a central system used for traffic enforcement, registration and insurance checks, and stopping wanted or flagged vehicles nationwide.

Jan 2015 Source →
Ireland 2

Ireland

Contesting

Civil society and oversight bodies in Ireland have contested government plans to give the national police, An Garda Siochana, facial recognition powers since 2022. The Irish Council for Civil Liberties, Digital Rights Ireland, the Data Protection Commission, and the Oireachtas Justice Committee all flagged serious deficiencies, and the committee issued dozens of recommended changes in 2024. The opposition delayed the measure for years, though a 2025 bill authorizing Garda biometric analysis was advancing through the Oireachtas in 2026.

Feb 2024 Facial recognition Source →

Ireland

Restricted

In Commissioner of An Garda Siochana (2022) the EU Court of Justice held that Ireland's regime of general and indiscriminate retention of traffic and location data to fight serious crime was contrary to EU law, reaffirming that blanket retention -- the kind that also underpins mass metadata and vehicle-tracking databases -- is permissible only when targeted and properly safeguarded.

Apr 2022 Blanket data retention Source →
Italy 7

Italy

Restricted

Italy's data protection authority (Garante) fined Clearview AI EUR 20 million, banned further collection and processing of residents' data, and ordered deletion of the biometric data it held.

Feb 2022 Facial recognition Sourcesedpb.europa.euedri.org

Public-space facial-recognition moratoriumItaly

Paused

In December 2021 Italy became the first EU country to pause facial recognition in public spaces, suspending installation and use of the technology by both public and private actors until a dedicated legal framework is passed. Police and judicial criminal investigations were exempted, which civil-society groups criticized, but the moratorium marked a national stand against biometric mass surveillance and was later extended while a permanent law was debated.

Dec 2021 Facial recognition Source →

Wrongful stops & data misuse

Paragon Graphite used against journalists in Italy

Wrongful stop

Italy's intelligence services used Paragon's Graphite spyware against journalists and migrant-rescue activists, confirmed by Citizen Lab in 2025, including Fanpage journalist Ciro Pellegrino and Mediterranea Saving Humans founders.

Jun 2025 Sourcescitizenlab.caamnesty.org

Clearview AI fined 20 million euros

Data misuse

Italy's data-protection authority fined Clearview AI 20 million euros for processing biometric and location data of people in Italy without a legal basis, banned further collection, and ordered deletion of existing records.

Feb 2022 Source →

Como's public-square facial recognition ruled unlawful

Wrongful stop

In 2019 the northern Italian city of Como quietly bought, installed and tested a live facial-recognition system in public squares near its train station, among the first Italian municipalities to do so. After a journalistic investigation, the Italian data-protection authority (Garante) found the deployment had no legal basis under GDPR and ordered it stopped in 2020 -- a case that helped drive Italy's later national moratorium on public-space facial recognition.

Jun 2020 Source →

Italy's secretive SARI police facial-recognition system

Wrongful stop

In 2017 Italy's Interior Ministry commissioned the SARI (Automatic Image Recognition System) facial-recognition platform for the scientific police from vendor Parsec 3.26. Rolled out with extreme secrecy and little oversight, SARI was shown to be biased and to draw heavily on a database skewed toward foreign nationals; its real-time mode was later blocked by the Garante pending a proper legal framework.

Nov 2017 Source →

A motorway network that tracks cars by plate

Data misuse

Italy's Tutor system covers more than 2,500 km of motorway, run jointly by the toll operator and the state police. It reads plates to calculate average speed over long stretches and can even track cars as they change lanes, logging the movements of every vehicle that passes.

Jan 2012 Source →
Latvia 1

Pegasus infected exiled journalists in Latvia

Wrongful stop

Exiled Russian journalists based in Latvia, including Meduza founder Galina Timchenko and Novaya Gazeta Europe's Maria Epifanova, were infected with Pegasus between 2020 and 2023.

Sep 2018 Sourcescpj.orgcitizenlab.ca
Luxembourg 1

Luxembourg

Restricted

Luxembourg is one of the few European countries to have introduced legal restrictions on the use of facial recognition technology.

Facial recognition Source →
Netherlands 6

Netherlands

Contesting

The Dutch ANPR Act -- Article 126jj of the Code of Criminal Procedure, in force since 2019 -- has police log the plate and location of every passing vehicle and hold it for four weeks in a central database, whether or not anyone is suspected of anything. Privacy First has been litigating to have it declared unlawful since 2021, arguing the bulk retention of millions of motorists' movements is disproportionate under European privacy law, unsupervised, easy to abuse, and by several studies ineffective at what it claims to do. After summary proceedings, the District Court of The Hague cleared the case to proceed on the merits in early 2024. The appeal was heard at the Court of Appeal in The Hague on July 9, 2026 (Privacy First Foundation v. the State, case 200.347.782/01), in a hearing the foundation opened to the public, and it says it will carry the case to the highest European courts if it has to, citing recent European case law and the Dutch data protection authority's own positions. Judgment pending. Read this against Norfolk, Virginia, where a US federal judge held a 21-day ALPR retention window too short to amount to Carpenter-style surveillance: the Dutch window is twice that, nationwide, and statutory rather than contractual. Same technology, same question about how long is too long, two legal systems arriving from opposite directions.

Jul 2026 Alpr Source →

Netherlands

Restricted

The Dutch DPA fined Clearview AI EUR 30.5 million and warned Dutch companies against using its facial recognition database.

Sep 2024 Facial recognition Source →

Wrongful stops & data misuse

Clearview AI fined over scraped database

Data misuse

The Dutch data-protection authority fined Clearview AI for building an illegal facial-recognition database from scraped photos of people in the Netherlands, one of several EU regulators to penalize the company.

2024 Source →

Football club face scan wrongly fines a fan

Wrongful stop

Dutch football clubs used retrospective facial recognition to scan crowds for banned supporters, and in one case wrongly issued a fine to a fan who had not even attended the match in question, a failure that drew warnings about expanding after-the-fact face surveillance in Europe.

Apr 2023 Sourcesedri.orgeuronews.com

Rotterdam's 'suspicion machine' scored the poor for fraud raids

Data misuse

From 2017 to 2021 Rotterdam used an Accenture-built machine-learning model to score its roughly 30,000 welfare recipients for fraud risk, using about 315 inputs including age, gender, language skills, neighbourhood, marital status and subjective caseworker notes. A 2023 Lighthouse Reports and WIRED investigation ('Suspicion Machines') that reverse-engineered the model found it systematically ranked single mothers, non-Dutch speakers and people of certain ethnicities as higher risk, subjecting them to intrusive fraud investigations even when they had done nothing wrong.

Mar 2023 Source →

Dutch police hold a 1.4 million-face recognition database

Wrongful stop

By 2020 the Dutch national police maintained a facial-recognition database holding images of around 1.4 million people, and municipalities were rolling out face recognition in public space under 'pilot' and 'smart city living lab' labels that sidestepped regulatory scrutiny and frustrated public debate.

Jan 2020 Source →
Norway 1

Norway -- government moves to regulate camera smart glassesNorway

Contesting

NORWAY SAYS IT WILL REGULATE CAMERA SMART GLASSES -- WITH AN EXPERT GROUP AND NO DEADLINE. On 25 August 2026 Digitalisation Minister Karianne Tung said she wants stricter rules for smart glasses and other wearables that combine AI with cameras and microphones, saying they must not be used to watch people in public. An expert group will advise the ministry and any proposal will go to public consultation. Outlets differ on how far she went: Biometric Update and AFP report a ban on facial recognition, or on the devices, is being considered; the Norwegian tech site digi.no says she did not specifically announce one. The next day Education Minister Kari Nessa Nordtun said schools and municipalities should set their own rules and rejected a national ban in schools. Not established: who sits on the expert group, what it is asked to do, or when it reports.

Poland 4

Poland

Restricted

In Pietrzak and Bychawska-Siniarska and Others v. Poland (2024) -- brought by lawyers and human-rights activists -- the European Court of Human Rights found Poland's secret-surveillance and communications-data-retention regime in breach of privacy rights, citing weak authorisation and oversight and the absence of any notification to those who had been spied on.

May 2024 Secret surveillance & retention Source →

Poland

Contesting

Poland is investigating how the previous Law and Justice government used NSO Group Pegasus spyware, which officials say was deployed against roughly 600 people between 2017 and 2022, including the opposition senator who ran the 2019 election campaign. After the government changed in late 2023, prosecutors opened investigations and parliament created a Pegasus and Illegal Surveillance commission in February 2024. In December 2024 a former security service chief was forcibly compelled to testify, a first in Polish history.

Feb 2024 NSO Group Source →

Wrongful stops & data misuse

Pegasus turned on Poland's opposition

Wrongful stop

Under the Law and Justice government, Polish services used NSO's Pegasus against the opposition. Senator Krzysztof Brejza was hacked dozens of times in 2019 while running the opposition's election campaign, and his stolen messages were doctored by state television for a smear campaign; a lawyer and a prosecutor critical of the government were also targeted. A Senate commission and the European Parliament found the spyware was deployed to entrench those in power, and prosecutors later seized the systems.

Facial-recognition app enforced Covid home quarantine

Data misuse

In March 2020 Poland made its 'Home Quarantine' app mandatory for people ordered to isolate, requiring a geolocated facial-recognition selfie within 20 minutes of a random prompt. Failing to verify by face on demand triggered a police visit and possible fine, turning biometric identity checks into a routine tool of movement control and setting an early template other governments studied.

Mar 2020 Source →
Portugal 1

Portugal

Paused

Portugal's CNPD imposed a three-month ban on Worldcoin in Mar 2024, in step with Spain and on the same grounds: insufficient information provided to users, biometric collection from minors without consent, and no adequate age-verification mechanism. Two EU regulators independently reaching identical findings in the same month is itself evidence -- the failures were properties of the program's design, not of one country's rollout. The Iberian bans forced the company to halt orb operations across both countries while it answered the regulators.

Mar 2024 Worldcoin iris scanning Source →
Romania 1

Romania

Restricted

In Rotaru v. Romania (Grand Chamber, 2000) the European Court of Human Rights held that Romania violated privacy rights by keeping a secret intelligence-service file on a citizen -- containing old and partly false information about his student-era political activity -- with no way for him to challenge or correct it and no legal safeguards over what the security services stored. A foundational ruling on state files and databases.

May 2000 Secret intelligence file Source →
Russia 9

Russia

Restricted

In Podchasov v. Russia (2024) the European Court of Human Rights held that requiring a messaging service (Telegram) to give authorities the means to decrypt end-to-end encrypted communications violated the right to privacy. Weakening encryption for targeted users, the Court found, weakens it for everyone and is a disproportionate form of mass surveillance -- a landmark defence of encryption.

Feb 2024 Encryption backdoor Source →

Russia

Restricted

In Roman Zakharov v. Russia (Grand Chamber, December 2015) the European Court of Human Rights ruled that Russia's system of covert interception of mobile-phone communications (SORM), which let security services tap networks directly with weak oversight, violated the right to privacy under Article 8. The Court set benchmark standards for authorisation and independent supervision of secret surveillance -- standards Russia has since ignored.

Dec 2015 SORM interception Source →

Wrongful stops & data misuse

Two Russian agencies gave different counts of detained chatbot users

Wrongful stop

On 29 July 2026 the FSB said Ukrainian intelligence had used the Telegram dating chatbot Daivinchik, also called Leo, to recruit Russians for sabotage and arson, and that 46 users aged 12 to 22 had been detained across 16 regions since July 2025. Russia's Investigative Committee, in a separate statement about the same chatbot, gave 19 teenagers aged 14 to 18, detained in Moscow, St Petersburg, Novosibirsk and the Rostov and Saratov regions. Both counts come from the agencies themselves. The record does not resolve which is correct or whether the two describe the same detentions. Meduza reported that the chat interfaces in videos the security services released as proof were from a Russian application rather than Telegram. The FSB charged Telegram founder Pavel Durov with aiding terrorism and he was placed on Rosfinmonitoring's register of terrorists and extremists; a separate terrorism case had been opened against him in February 2026. None of the allegations has been tested in an adversarial hearing. Coordinates are Moscow; the detentions were spread across regions.

Jul 2026 Sourcesmeduza.iojurist.org

Biometric 'digital profile' of foreign nationals

Data misuse

Russia moved to build a centralized 'digital profile' of foreign nationals and stateless people, expected by mid-2026, pulling extensive personal and biometric information from multiple agencies -- part of a broader expansion of surveillance targeting foreign visitors and residents.

Jun 2026 Source →

European court: metro face-recognition arrest violated rights

Wrongful stop

In July 2023 the European Court of Human Rights ruled that Russia violated Nikolay Glukhin's rights by using Moscow metro facial recognition to identify and arrest him over a peaceful solo protest. Glukhin had ridden the underground in August 2019 holding a life-sized cutout of jailed activist Konstantin Kotov; days later the system flagged him and police detained him. The court found the deployment incompatible with the values of a democratic society governed by the rule of law -- one of the first international rulings against live facial recognition.

Jul 2023 Source →

Facial recognition used to hunt draft evaders

Wrongful stop

After Russia's September 2022 mobilisation for its war on Ukraine, Moscow authorities turned the city's facial-recognition camera network on men avoiding the draft. Human Rights Watch documented at least seven men flagged as 'draft dodgers' and detained via surveillance cameras, taken to police stations and enlistment offices, with some ordered to the front. Enlistment offices even flag conscripts who legally challenge their call-up so they can be auto-detected on camera, and rights lawyers advise appellants to avoid the metro entirely.

Oct 2022 Sourceshrw.orgthemoscowtimes.com

Metro face recognition used to detain protesters

Wrongful stop

Moscow's metro facial recognition, part of a Safe City camera network, has been used to detain and question thousands of people on their way to and from anti-war protests, sometimes preventively. The European Court of Human Rights later ruled the practice violated human rights.

Facial recognition used to hunt dissidents

Wrongful stop

Moscow's facial-recognition camera network, one of the world's largest, has been turned from catching criminals to hunting dissidents. Police have used it to identify and detain peaceful protesters, journalists covering them, and mourners at Alexei Navalny's 2024 funeral, tracing people right up to their door. In 2023 the European Court of Human Rights ruled its use against a protester unlawful.

Apr 2021 Source →

DPI censorship throttles VPNs and news

Data misuse

Sandvine equipment was among the technology linked to internet censorship in Russia, which also runs the domestic TSPU deep-packet-inspection system to throttle and block VPNs, social media, and independent news.

Serbia 6

Serbia

Contesting

Civil society led by the SHARE Foundation forced the withdrawal of draft laws that would have legalized mass biometric video surveillance in Belgrade, in 2021 and again in 2023. Facial recognition remains legally unauthorized in Serbia, though Huawei cameras are installed and rights groups say the software has been used during protests without a legal basis.

Feb 2023 (approx.) Facial recognition Source →

Serbia

Paused

In September 2021 Serbia withdrew its Draft Law on Internal Affairs, which would have legalised permanent, indiscriminate biometric video surveillance of Belgrade's public spaces and made Serbia the first country in the region with such a system. The reversal followed a sustained campaign by the SHARE Foundation (Thousands of Cameras / hiljadekamera), EDRi and pressure from members of the European Parliament. The interior ministry has kept trying since -- installing NEC NeoFace Watch and Russian FindFace and floating new draft laws -- but the 2021 win stalled full legalisation.

Sep 2021 Facial recognition Source →

Wrongful stops & data misuse

Pegasus and NoviSpy hit Serbia's student movement around local elections

Data misuse

AT LEAST 14 SERBIAN STUDENTS, ACTIVISTS AND OPPOSITION POLITICIANS TARGETED WITH SPYWARE IN 2026. Citizen Lab, working with SHARE Foundation and Amnesty Tech, confirmed on 2 September 2026 that a member of the student protest movement had Pegasus on their iPhone between December 2025 and January 2026, delivered by a zero-click iMessage exploit. The same investigators found a new Android version of NoviSpy, the spyware previously installed on phones seized by Serbian police; EDRi reports it was set up to send data to the Security Information Agency. EDRi counts at least 14 targets since early 2026, including an opposition MP and a local councillor, clustered around the 29 March local elections. Citizen Lab does not formally attribute the Pegasus case to a government. No response from Serbian authorities is on record here.

Sep 2026 Sourcescitizenlab.caedri.org

Serbia hacks activists' phones in police custody

Wrongful stop

An Amnesty International report found that Serbian police and the BIA intelligence agency used Cellebrite forensic tools to secretly unlock the phones of journalists and activists during detention, then installed a homegrown Android spyware called NoviSpy that can copy data and switch on the camera and microphone. Investigative journalist Slavisa Milanov and environmental campaigners were among those hacked after being held for routine-seeming interviews.

Huawei Safe City cameras expand in Belgrade

Data misuse

Serbia is expanding Huawei's Safe City facial-recognition camera network in Belgrade, with leaked 2024 contracts showing capacity for up to 3,500 additional cameras despite public protests.

2024 Source →

Belgrade wired with thousands of Huawei face cameras

Data misuse

Belgrade has been fitted with thousands of Huawei 'Safe City' cameras carrying facial-recognition and plate-reading software, rolled out from 2019 with little transparency. The digital-rights group SHARE Foundation's 'Thousands of Cameras' campaign and Amnesty warned the system was unlawful and used to identify protesters, and biometric provisions were later dropped from a draft police law after public outcry.

Slovenia 1

Slovenia

Restricted

In Benedik v. Slovenia (2018) the European Court of Human Rights found a privacy violation because Slovenian police obtained the subscriber identity behind a dynamic IP address without a court order, under a law that lacked clarity and safeguards against abuse. A key ruling treating the link between an IP address and a named person as protected private data.

Apr 2018 IP / subscriber data Source →
Spain 6

AEPD turns the impact assessment into a weaponSpain

Restricted

Across 2025 and 2026 Spain's data-protection regulator built Europe's most aggressive line of biometric enforcement, and its lever was not consent but the data-protection impact assessment. In a decision dated November 6, 2025 the AEPD fined airport operator Aena just over 10 million euros for running facial-recognition boarding at eight airports, including Madrid-Barajas and Barcelona El Prat, on a centralised one-to-many template store, and ordered biometric processing suspended until an adequate assessment exists. Aena had already paused the programme in June 2024 after a complaint from the Eticas foundation and a single passenger, and is appealing. On March 4, 2026 the regulator fined FC Barcelona 500,000 euros over face and voice scans of roughly 143,000 members, minors included, during a 2023 membership census. Six days later it fined age-verification vendor Yoti 950,000 euros: 500,000 for having no lawful basis to process biometrics at account setup, 200,000 for a consent screen users could click past with research use pre-ticked, and 250,000 for holding geolocation data five years and retaining fraudulent ID documents to train its algorithms. Yoti is appealing to the Spanish High Court. The regulator's repeated finding was not that the paperwork was missing but that it was hollow -- and that convenience never establishes necessity.

  1. Jun 2024 Aena suspended its biometric boarding programme after a complaint to the AEPD from the Eticas foundation and a passenger. biometricupdate.com
  2. Nov 2025 The AEPD fined Aena just over 10 million euros for facial-recognition boarding at eight airports without a valid impact assessment, and ordered the biometric processing suspended. Aena is appealing. idtechwire.com
  3. Mar 2026 The AEPD fined FC Barcelona 500,000 euros over biometric face and voice verification of about 143,000 members, including minors, without a compliant impact assessment. idtechwire.com
  4. Mar 2026 The AEPD fined age-verification vendor Yoti 950,000 euros across three GDPR breaches and gave it six months to comply; Yoti rejected the finding and appealed to the Spanish High Court. yoti.com

Spain

Paused

Spain's AEPD issued an emergency three-month ban on Worldcoin's iris scanning in Mar 2024 -- the first European country to stop the orbs -- citing insufficient information given to users, collection from minors, and no adequate mechanism to verify age. An emergency order under the GDPR requires urgency and serious risk, and the AEPD found both in a program paying people, including teenagers who queued in shopping centres, to stare into a sphere. The Spanish ban opened the European front that Portugal joined the same month and Germany's deletion order extended in Dec 2024.

Mar 2024 Worldcoin iris scanning Source →

Spain

Contesting

After Citizen Lab documented Pegasus and Candiru infections on the phones of dozens of Catalan politicians, lawyers, and activists, and separate infections of the prime minister and defense minister, Spain opened judicial and parliamentary investigations and dismissed the director of its intelligence agency.

May 2022 Pegasus (NSO Group) Source →

Spain

Restricted

Spain data protection agency, the AEPD, fined supermarket chain Mercadona 2.5 million euros in 2021 for running facial recognition across 48 stores that scanned every shopper, including children, to flag people with restraining orders. The regulator ruled the system unlawful under the GDPR and it was ordered stopped.

  1. Jun 2020 Mercadona began a facial-recognition pilot across 48 supermarkets to flag people with restraining orders, scanning all shoppers including children. gdprhub.eu
  2. May 2021 After complaints and an AEPD interim order, Mercadona halted the pilot and removed the cameras. gdprhub.eu
  3. Jul 2021 The AEPD fined Mercadona 2.5 million euros, ruling the facial-recognition system unlawful under the GDPR. hunton.com
Jul 2021 Facial recognition Sourceshunton.comgdprhub.eu

Wrongful stops

Spanish football clubs scan fans' faces at the turnstile

Wrongful stop

Spanish football clubs have rolled out facial recognition on supporters: Valencia CF deployed a FacePhi system to control stadium access and Atletico Madrid announced face-scanning and cashless entry from the 2022-23 season, while other clubs use fingerprint scanning at turnstiles. Fans and privacy advocates warned that mandatory biometric entry normalises tracking of ordinary spectators.

Aug 2022 Source →

CatalanGate spyware hits Catalan independence figures

Wrongful stop

Citizen Lab's CatalanGate report found at least sixty-five people tied to the Catalan independence movement, including every Catalan president since 2010, members of the European Parliament, lawyers, and activists, targeted or infected with Pegasus or Candiru spyware between 2017 and 2020. The lab pointed to strong circumstantial evidence of a Spanish state nexus; the government later acknowledged court-authorized surveillance of about two dozen people and denied a wider operation.

Sweden 4

Sweden

Restricted

In Centrum for rattvisa v. Sweden (Grand Chamber, May 2021, decided alongside Big Brother Watch v. UK) the European Court of Human Rights examined Sweden's bulk signals-intelligence regime -- the mass interception of cross-border communications by the FRA agency -- and found it lacked adequate safeguards, in violation of the right to privacy under Article 8, particularly around oversight and the sharing of intercepted material with foreign partners.

May 2021 Bulk signals intelligence Source →

Sweden

Restricted

Sweden's data protection authority (IMY) fined the national police EUR 250,000 for using Clearview AI to identify people unlawfully and without a data protection assessment, and ordered the police to inform affected individuals and have their data deleted.

Feb 2021 Facial recognition Source →

Wrongful stops

Care home fined for filming a disabled resident's bedroom

Wrongful stop

In November 2020 the Swedish data-protection authority fined Gnosjo Municipality 200,000 SEK for unlawful video surveillance in an LSS home for people with functional impairments, after a resident was filmed in their own bedroom. The regulator found no legal basis and no impact assessment, calling it a severe and unjustifiable intrusion into the most private sphere of the home.

Nov 2020 Source →

EU's first facial-recognition fine over a school attendance trial

Wrongful stop

In August 2019 the Swedish Data Protection Authority issued the EU's first GDPR facial-recognition fine -- 200,000 SEK (about 20,000 euros) against the Skelleftea municipal school board after Anderstorp High School piloted FR cameras to log the attendance of 22 students over three weeks. The regulator found consent could not be a valid legal basis given the power imbalance between school and pupils, that attendance could be tracked less intrusively, and that the school processed sensitive biometric data without an adequate impact assessment.

Aug 2019 Source →
Switzerland 2

Switzerland

Restricted

In Amann v. Switzerland (Grand Chamber, 2000) the European Court of Human Rights found two privacy violations: the interception of a phone call to the applicant, and the secret card-index file the federal prosecutor then created and stored about him -- both without a clear legal basis. An early benchmark that even storing seemingly neutral data on a person engages the right to privacy.

Feb 2000 Interception & secret file Source →

Wrongful stops

Suspected Pegasus infections in Switzerland

Wrongful stop

Citizen Lab detected suspected Pegasus infections in Switzerland.

Sep 2018 Source →
Ukraine 1

Clearview used to identify dead Russian soldiers

Wrongful stop

In March 2022 Ukraine's defence and digital-transformation ministries began using Clearview AI facial recognition -- provided free, drawing on billions of scraped images including from the Russian network VKontakte -- to identify the bodies of dead Russian soldiers and message their relatives, and to identify operatives. Critics warned of the wartime normalisation of a controversial scraping tool and the risk of deadly misidentification at checkpoints.

Mar 2022 Sourcesforbes.comamp.cbc.ca
United Kingdom 21

National live facial recognition rolloutUnited Kingdom

Contesting

The Home Office set out its largest-ever facial-recognition expansion in a January 2026 policing white paper, funding 40 new live facial recognition (LFR) vans for a national rollout across England and Wales and pledging 115 million pounds for a National Centre for AI in Policing. LFR was in use by 13 of 43 forces by March 2026, and the first permanent LFR cameras went live in South London in October 2025. Rights groups and the Equality and Human Rights Commission have contested the deployments, with the EHRC joining a judicial review arguing the Metropolitan Police's use of LFR is unlawful. NORTH YORKSHIRE WENT LIVE ON 23 SEPTEMBER 2026. North Yorkshire Police ran its first live facial recognition deployment in York city centre, scanning for people wanted for offences or by the courts and those judged a risk of harm; the force says non-matches are deleted within a fifth of a second. Deputy Mayor Jo Coles said she had sought assurances on oversight and mission creep and would question the force at her public meetings. By June, Statewatch counted 12 force areas using LFR, four of them for the first time in the previous six months. Which forces receive the 40 promised vans, and when, has not been published. Results of the York deployment are not yet reported.

Scotland -- police LFR business case vs call for a law firstUnited Kingdom

Contesting

POLICE SCOTLAND WANTS LIVE FACIAL RECOGNITION; ITS BIOMETRICS WATCHDOG WANTS A LAW FIRST. Police Scotland has not used LFR operationally but is building a business case, and the Chief Inspector of Constabulary's 2025-26 annual report urged it to adopt LFR, AI and drones faster. Scottish Biometrics Commissioner Brian Plastow wrote to the Justice Secretary in May 2026 asking for primary legislation before any deployment, so Scotland avoids the legal vacuum he says LFR grew up in south of the border. Justice Secretary Neil Gray answered that committing to legislation now would be premature. On 1 September Plastow called Scotland's 2011 CCTV strategy hopelessly outdated and asked ministers for a national public-space surveillance strategy, a wider remit for his office and a new code of practice. Not established: any government decision on legislation or a deployment date. Coordinates are Edinburgh.

United Kingdom

Contesting

On Jul 27, 2026 the UK Supreme Court ruled 3-2 that Bahrain cannot claim state immunity to block a spyware lawsuit -- holding that remotely infecting a computer physically located in the UK is an act carried out IN the UK. The precedent is the record: a foreign government that hacks a device in Britain from abroad now faces the same civil liability in English courts as one that sends agents in person, which closes the procedural shield transnational spyware campaigns have hidden behind. The claimants are Dr Saeed Shehabi, 71, a journalist and founder of a Bahraini opposition movement, and Moosa Mohammed, a Bahraini refugee, both in London; they allege agents acting for Bahrain infected their computers in Sep 2011 with FinSpy -- the commercial spyware of the now-defunct Munich firm FinFisher, capable of logging keystrokes, tracking location and monitoring communications. Bahrain denied the hacking and argued sovereign immunity; the High Court rejected that in 2023, the Court of Appeal upheld it in 2024, and the Supreme Court has now closed the question. Filed `contesting` because the win is jurisdictional, not final: the case returns to the High Court for full trial. It sits alongside WhatsApp v. NSO in the US as the second front testing whether spyware operations against exiles can be litigated where the victims live.

Jul 2026 Finspy spyware Sourcesaljazeera.comamnesty.org

National digital ID scrapped after three million signaturesUnited Kingdom

Denied

Keir Starmer announced a free national digital ID on 25 September 2025 -- branded BritCard, held in a GOV.UK wallet, mandatory for right-to-work checks and targeted for full rollout in 2029. The backlash was the largest of any recent UK digital policy: a parliamentary petition against it drew close to three million signatures, one of the biggest in British history, and thousands marched from Marble Arch to Whitehall on 18 October 2025 behind placards calling it a digital prison. Security specialists warned about concentrating that much identity data in a single store. In January 2026 the government dropped the mandatory element and made the scheme voluntary; that concession did not save it. Andy Burnham, sworn in as prime minister on 20 July 2026, confirmed on taking office that the roughly 1.8 billion pound programme is cancelled outright and the money redirected to cost-of-living measures. Separate digital public services and the wider government digital programme continue -- what died is the universal state identity credential. Unlike most wins on this map, this one came from sustained public opposition rather than a courtroom.

  1. Sep 2025 Starmer announced BritCard, a free national digital ID mandatory for right-to-work checks, with rollout targeted for 2029. bankinfosecurity.com
  2. Oct 2025 Thousands marched from Marble Arch to Whitehall against the scheme; the parliamentary petition against it neared three million signatures. computing.co.uk
  3. Jan 2026 Under sustained pressure the government dropped the mandatory element and made the scheme voluntary. aljazeera.com
  4. Jul 2026 Andy Burnham cancelled the programme outright on becoming prime minister, redirecting the funds to cost-of-living measures. techcrunch.com

ICO fine and deletion order against ClearviewUnited Kingdom

Contesting

In May 2022 the UK Information Commissioner fined Clearview AI more than 7.5 million pounds and ordered it to stop scraping images of UK residents and to delete the data it already held, after a joint investigation with Australia regulator. Clearview appealed and a lower tribunal threw out the penalty in 2023 on jurisdiction grounds, but in October 2025 the Upper Tribunal restored most of the regulator case, ruling that Clearview does fall under UK data-protection law. The company may still seek further appeal.

May 2022 Facial recognition Source →

United Kingdom

Restricted

The UK Information Commissioner's Office fined Clearview AI GBP 7.5 million and ordered it to delete UK residents' data, finding the company built its database by scraping images from the web without consent. Clearview appealed.

May 2022 Clearview AI Source →

United Kingdom

Restricted

In Big Brother Watch and Others v. the United Kingdom (Grand Chamber, May 2021), the European Court of Human Rights found that the UK's bulk interception of communications -- the GCHQ mass-surveillance regime exposed by Edward Snowden -- violated the right to privacy (Article 8) and press freedom (Article 10) because it lacked sufficient end-to-end safeguards against abuse. It was the first Grand Chamber ruling on bulk interception in the post-Snowden era.

May 2021 Bulk interception Source →

United Kingdom

Contesting

In 2020 the Court of Appeal ruled South Wales Police live facial recognition unlawful in the Bridges case, the first successful legal challenge of its kind. In 2022 the ICO fined Clearview AI and ordered UK residents data deleted. Live facial recognition has since expanded to more police forces, and the fight over its limits continues.

  1. Sep 2019 The High Court dismissed Edward Bridges challenge to South Wales Police use of live facial recognition. libertyhumanrights.org.uk
  2. Aug 2020 The Court of Appeal ruled South Wales Police live facial recognition unlawful, the first successful legal challenge to the technology in the UK. The case was backed by the civil liberties group Liberty. libertyhumanrights.org.uk
  3. May 2022 The ICO fined Clearview AI over 7.5 million pounds and ordered it to delete UK residents data. time.com
Aug 2020 (approx.) Facial recognition Sourceslibertyhumanrights.org.uktime.com

United Kingdom

Restricted

In Catt v. the United Kingdom (January 2019) the European Court of Human Rights held that police violated the privacy of John Catt -- a lifelong peace activist in his 90s with no history of violence -- by retaining detailed records of his attendance at protests on a national police 'domestic extremism' database. The Court found the collection may have been justified but the open-ended retention, with no clear definition of 'domestic extremism' and no time limits, was not -- a significant check on the surveillance of peaceful protest.

Jan 2019 Police intelligence database Source →

United Kingdom

Restricted

In S. and Marper v. the United Kingdom (Grand Chamber, December 2008) the European Court of Human Rights unanimously ruled that the blanket, indefinite retention of DNA samples, cellular samples and fingerprints of people arrested but never convicted violated the right to privacy under Article 8. The two applicants from Sheffield had been arrested and then cleared, yet police kept their biometric data forever. The landmark ruling forced the UK to overhaul its DNA database; the Court reaffirmed it in Gaughran v. UK (2020), striking down indefinite biometric retention even for a minor conviction.

Dec 2008 DNA & fingerprint retention Source →

Wrongful stops & data misuse

Met expands permanent facial recognition to the West End

Wrongful stop

In June 2026 Metropolitan Police Commissioner Sir Mark Rowley announced the most significant expansion of live facial recognition in London to date: static LFR cameras mounted on street furniture across the West End and Soho by the end of 2026, meant to grow into a citywide infrastructure programme rather than time-limited van operations. It followed a six-month Croydon pilot (October 2025 to March 2026, 24 operations, 173 arrests, more than 470,000 faces scanned) and an April 2026 High Court ruling that the Met's LFR policy was lawful, now under appeal. Big Brother Watch urged the force to stop until Parliament legislates, noting the UK still has no specific statutory framework for LFR.

UK plugs its plate-reader network into EU-wide Prum sharing

Data misuse

In June 2026 the UK Home Office switched on number-plate checks through the EU's Prum data-sharing framework, letting officers query overseas-registered vehicles across EU member states and get vehicle-keeper details back in about ten seconds instead of days or months. It bolts cross-border reach onto Britain's already vast plate-reader system -- commonly cited at around 11,000 ANPR cameras reading roughly 50 million plates a day into the National ANPR Data Centre, where records are retained for a year. The government framed the link-up around border security, illegal migration and organised crime.

Jun 2026 Source →

80,000 protesters scanned; a worker wrongly flagged

Wrongful stop

London's Metropolitan Police scanned the faces of about 80,000 people at a single protest and have run live facial recognition against millions of faces. Youth worker Shaun Thompson was wrongly flagged, detained, and threatened with arrest before being compensated. Campaigners call it stop and search on steroids.

Wrongly flagged by live facial recognition

Wrongful stop

London's Metropolitan Police scan millions of faces with live facial recognition. Youth worker Shaun Thompson was wrongly flagged in 2024, then stopped, detained, fingerprinted, and threatened with arrest over a false match. At one 2025 sporting event South Wales Police logged 2,470 alerts, 92 percent of them false, and the equality watchdog found the Met system disproportionately flags Black men.

Feb 2024 Source →

Supermarkets built secret facial-recognition blacklists of shoppers

Wrongful stop

British retailers including Southern Co-op, Home Bargains and Mike Ashley's Frasers Group deployed Facewatch live facial recognition to scan shoppers entering stores and match them against private watchlists of suspected offenders. After a 2022 Big Brother Watch complaint, the ICO concluded in March 2023 that Facewatch's processing had breached data-protection law on multiple principles, forcing an overhaul; campaigners say people were blacklisted over trivial accusations and, in cases like a teenager wrongly flagged at Home Bargains in 2024, misidentified and publicly accused.

ICO fines Clearview, orders deletion

Data misuse

The UK Information Commissioner's Office fined Clearview AI 7.5 million pounds in 2022 and ordered it to delete UK residents' data; after a tribunal initially overturned the action on jurisdiction, an appeals tribunal restored the regulator's authority in 2025.

Facial recognition paused in Scottish school canteens

Wrongful stop

In October 2021 nine schools in North Ayrshire, Scotland switched on facial recognition to take payment in their canteens, scanning pupils' faces instead of fingerprints or cards. After public and regulatory backlash the ICO intervened, urging the schools to use a less intrusive method, and the rollout was paused -- an early flashpoint over normalising biometric identification of children for everyday transactions.

Oct 2021 Source →

Court rules police face recognition unlawful

Wrongful stop

A UK Court of Appeal ruling in Bridges v South Wales Police found the force's live facial recognition unlawful. Its AFR Locate system scanned up to 50 faces per second against watchlists that could include anyone, with images drawn even from social media, breaching privacy, data-protection, and equality law.

Aug 2020 Sourcessimmons-simmons.comeff.org

Wrongful stops from number-plate misreads

Data misuse

Britain runs one of the world's largest automatic number-plate recognition networks, reading tens of millions of plates a day into a database of more than 20 billion records. The official surveillance camera commissioner warned that even at a claimed 97 percent accuracy the system misreads hundreds of thousands of plates a day, that police hold no meaningful data on its accuracy, and that misreads and cloned plates have led to wrongful stops and arrests of innocent motorists.

Jan 2018 Source →

'Ring of steel' tracked every car in and out of a town

Wrongful stop

Hertfordshire police ringed the small town of Royston with ANPR cameras, logging every vehicle entering or leaving. After complaints by Big Brother Watch, Privacy International, and No CCTV, the UK data regulator ruled the scheme unlawful and excessive and ordered it halted.

Jul 2013 Sourcestheregister.comedri.org

A national plate-reader network built without debate

Data misuse

The UK runs one of the world's largest ANPR networks, feeding a central database, yet it was constructed by police without any parliamentary debate or public consultation, and privacy regulators warned the blanket approach may be unlawful.

Jan 2013 Sourcesedri.orgtechdirt.com
Africa 32
Algeria 2

Five thousand cameras and no published cost

Wrongful stop

FIVE THOUSAND CAMERAS AND NO PUBLISHED COST. Algeria is one of 11 countries in Smart City Surveillance in Africa, published 12 March 2026 by the Institute of Development Studies with the African Digital Rights Network. Reporting of the study puts roughly 5,000 smart cameras in Algeria, and NO SPENDING FIGURE IS AVAILABLE -- the researchers say figures could not be obtained for two of the eleven countries and that public accounts for the other nine were incomplete, which is why their at least USD 2 billion total is explicitly a floor. WHAT THE COUNTRY AUTHOR SAYS HAPPENED. Yosr Jouini, who wrote the report's Algeria section, says systems introduced as smart city projects promising to tackle crime and manage traffic became in practice primarily tools of the security forces, and that the framing is entirely a security one, dismissing other concerns and providing too few mechanisms for citizens to protect their rights. She notes that street protests in 2019 and 2021 were a significant part of Algerian political life, and warns expanded surveillance could make people hesitant to protest in future. THAT IS A FORECAST, NOT A FINDING, and is recorded as one -- no measurement of a chilling effect in Algeria appears in the coverage reviewed here. A CAUTION FROM WITHIN THE SAME RESEARCH worth carrying: Bulelani Jili of Georgetown University argues that even introducing legal frameworks to regulate this technology can be dangerous, because a framework can legitimise a deployment rather than constrain it. Coordinates are Algiers, not a specific installation.

Algeria opened a Pegasus inquiry

Wrongful stop

After the Pegasus Project, Algeria's public prosecutor ordered an investigation into reports the country was targeted, and Citizen Lab detected suspected infections there.

Botswana 1

Predator spyware shipments

Wrongful stop

Import records tied Botswana's Directorate of Intelligence and Security to shipments of Intellexa Predator spyware in 2023, the first identification of the tool's use in the country.

2023 Source →
Egypt 3

Second-largest camera count at a fraction of the leading spend

Wrongful stop

SIX THOUSAND CAMERAS FOR FIFTY-EIGHT MILLION DOLLARS -- roughly $9,700 a camera, the cheapest per-unit deployment for which both numbers are reported. Egypt is one of 11 countries in the IDS and African Digital Rights Network report of 12 March 2026, which records USD 58 million spent and 6,000 smart cameras installed. FOR SCALE AGAINST THE REST OF THE STUDY: Nigeria spent over USD 470 million for about 10,000 cameras, Mauritius USD 456 million, Kenya USD 219 million, and the eleven countries averaged USD 240 million each. Egypt therefore has the second-largest camera count in the study at a fraction of the leading spend, which the sources do not explain -- it may reflect different equipment, different financing, or incomplete public accounts, and the researchers warn the accounts for nine of the eleven countries were incomplete. WHAT THE STUDY CONCLUDES ACROSS ALL ELEVEN: the systems are presented as crime prevention, counter-terrorism, modernisation and urban management; the researchers found little evidence that expanding digital surveillance reduces overall crime; much of the equipment is supplied or financed by Chinese companies and banks, often through loans; and none of the countries provides adequate means to obtain remedy for surveillance errors or abuse. Egypt already appears on this map for the Sandvine deep packet inspection deployment; this record covers public-space cameras. Coordinates are Cairo. THE SPREAD IS WIDER THAN EGYPT ALONE: by the same country tables as reported by Nairametrics, Senegal (USD 167 million, about 500 cameras) and Mozambique (USD 147 million, about 450) run at roughly USD 330,000 a camera -- so Egypt is one end of a thirty-fold range, not a lone anomaly. No source read explains either end; the report PDF could not be retrieved. WHAT WOULD SETTLE IT: the Egypt chapter of the report, or a question to its editors at IDS and the African Digital Rights Network. A POSSIBLE EXPLANATION, inferred rather than stated by the report: in February 2019 Honeywell signed to build a 6,000-camera IP system and command centre for Egypt's New Administrative Capital, reported at about USD 31 million (Global Construction Review). If the IDS figures come from that project, Egypt's low cost per camera reflects one US-built network in one new city, with video analytics rather than face recognition. The IDS report's Egypt chapter has still not been read.

Politician doubly infected with spyware

Wrongful stop

Egypt is a documented user of Predator spyware; in one case the phone of an exiled Egyptian politician was found simultaneously infected with both Predator and Pegasus, run by two different government clients.

2021 Source →

DPI middleboxes injected Predator spyware

Wrongful stop

Telecom Egypt used Sandvine PacketLogic deep-packet-inspection middleboxes to inject Intellexa's Predator spyware into the connection of opposition presidential candidate Ahmed Eltantawy, alongside mass web-monitoring and news censorship; the US added Sandvine to its Entity List in 2024.

Ethiopia 1

Spyware used against Ethiopian diaspora journalists

Wrongful stop

Ethiopian diaspora journalists at the ESAT broadcaster were targeted with Hacking Team's Remote Control System and Gamma's FinSpy spyware, documented by Citizen Lab.

Jul 2015 Sourcescitizenlab.cablog.sekoia.io
Kenya 4

Kenya

Removed

The strongest Worldcoin outcome anywhere: declared illegal, and the data destroyed under supervision. On May 5, 2025 the Nairobi High Court (Justice Aburili Roselyne) ruled that Tools for Humanity -- the Sam Altman-cofounded operator of Worldcoin -- violated Kenya's Data Protection Act by collecting iris and facial biometrics without valid consent and without a data protection impact assessment. The court's core finding travels: consent obtained by paying people -- 25 WLD tokens, roughly $50-55, in a market where that money matters -- is not free, informed consent. The case was brought by the Katiba Institute after the 2023 Nairobi rollout drew queues long enough that the government suspended operations on public-safety grounds. The court gave the company seven days to delete everything under Office of the Data Protection Commissioner supervision, and in Jan 2026 the ODPC confirmed all Kenyan biometric data had been permanently erased. Counsel Joshua Malidzo Nyawa called it a win for privacy rights. The contrast is part of the record: the same month Kenya's court ruled the model unlawful, World launched sign-ups in six US cities.

May 2025 Worldcoin iris scanning Sourcesiclg.combusinessdailyafrica.comtech-ish.com

Wrongful stops & data misuse

Third-largest buyer of smart city surveillance

Wrongful stop

IDS and the African Digital Rights Network put Kenya third among the 11 countries studied at USD 219 million on smart city surveillance technology, in research published 12 March 2026. The systems combine CCTV, facial recognition, number plate recognition and central command centres, and are mostly supplied and financed by Chinese firms. The researchers say they found no compelling evidence that such deployments reduced terrorism or serious crime, and that the countries studied lack laws defining who may conduct public-space surveillance, on what warrant and under whose oversight. The figure is the researchers' count, not an audit, and IDS notes the real total across the region is likely higher because surveillance spending is often secret. Kenya already appears on this map for Worldcoin, a suspected Pegasus deployment and the Huduma Namba ruling; this record covers the camera programme. Coordinates are Nairobi.

Mar 2026 Sourcesids.ac.ukopendocs.ids.ac.uk

Court declared the biometric ID rollout illegal

Data misuse

Kenya collected the fingerprints and facial images of tens of millions of people for its Huduma Namba (NIIMS) biometric ID before passing a data-protection law. The High Court declared the rollout illegal for skipping a privacy-risk assessment, and the successor Maisha Namba system faces similar criticism.

Suspected Pegasus operator in Kenya

Wrongful stop

Citizen Lab detected suspected Pegasus infections linked to an operator in Kenya.

Sep 2018 Source →
Morocco 1

Morocco named a top Pegasus user targeting journalists and leaders

Wrongful stop

The 2021 Pegasus Project named Morocco as one of the heaviest users of NSO's spyware, with around ten thousand numbers selected. They included Moroccan journalists such as Omar Radi, who was later jailed, as well as foreign figures, among them French President Emmanuel Macron and several of his ministers. Morocco denied buying or using Pegasus and sued the journalists and Amnesty International for defamation.

Mozambique 1

Smart cameras deployed where political opposition is concentrated

Wrongful stop

The IDS and African Digital Rights Network report published 12 March 2026 says research in Mozambique found smart CCTV cameras deployed in locations where political opposition is concentrated. Mozambique is one of 11 countries in the study, which puts combined spending at at least USD 2 billion; Reporting of the study's country tables (Nairametrics, 23 March 2026) puts Mozambique at USD 147 million for about 450 smart cameras, roughly USD 327,000 a camera by simple division. These are the researchers' counts from incomplete public accounts, not an audit. The report says all 11 countries fail to provide adequate means for people to obtain remedy or redress for smart surveillance errors or abuse. The government's account of how camera sites were chosen is not established, and the report's siting claim has not been tested against procurement or deployment records. Ask the Mozambican police for the site list and the selection criteria. Coordinates are Maputo.

Namibia 1

Cybercrime Bill would allow real-time traffic capture and content interception

Wrongful stop

A draft Namibia Cybercrime Bill dated 30 January 2026 gives an investigatory authority powers of access, search and seizure of stored data under a court warrant at clause 39, real-time collection of traffic data by technical means on the order of a Judge in Chambers at clause 40, interception of content data at clause 41, and expedited preservation of stored computer data at clause 47. Clause 3 provides that the Act prevails over any other written law on cybercrime and cybersecurity matters. The Council of Europe's Octopus country page assesses a draft Namibian bill as supplying most procedural powers the Budapest Convention requires while not setting out their scope, with some powers appearing to reach only offences under the bill rather than electronic evidence generally, and with no powers specific to traffic data. That page is undated and refers to a drafting mission held in February 2020, so whether its assessment describes this 30 January 2026 text or an earlier draft is not established. The bill is not enacted and no commencement date is established. Coordinates are Windhoek.

Jan 2026 Sourcesnmt.africacoe.int
Nigeria 3

Africa's largest buyer of Chinese public-space surveillance

Wrongful stop

IDS and the African Digital Rights Network, publishing 12 March 2026, put Nigeria's spending on facial recognition and automatic number plate recognition at over USD 470 million to date, the largest of the 11 African countries studied. A trade write-up of the same research (military.africa, April 2026) gives the 11-country total as USD 2.1 billion with Nigeria at nearly 23 per cent of it, against the IDS figure of at least USD 2 billion; the two are not reconciled and both are the researchers' counts rather than an audit. IDS says most of the technology is supplied and financed by Chinese companies, with Korea, Israel and the United States also supplying, and that no compelling evidence was found that these systems reduced terrorism or serious crime. Nigeria already appears on this map for the Hacking Team contract and the NIN biometric breaches; this record covers the camera programme. Coordinates are Abuja.

Biometric ID breaches exposed citizens' data

Data misuse

Nigeria's biometric National Identification Number system, tied to SIM and bank registration, has suffered data breaches exposing citizens' personal records, alongside exclusion of those unable to enroll.

Jan 2024 Source →

Hacking Team spyware client in Nigeria

Wrongful stop

Nigerian government bodies were among the clients of Hacking Team's Remote Control System spyware revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcesblog.sekoia.iocitizenlab.ca
Rwanda 2

The smallest deployment in the study, and still ungoverned

Wrongful stop

THE SMALLEST DEPLOYMENT IN THE STUDY, AND STILL UNGOVERNED. Rwanda is one of 11 countries in the IDS and African Digital Rights Network report published 12 March 2026, with approximately 849 smart cameras -- the lowest camera count reported among the eleven -- and NO SPENDING FIGURE AVAILABLE. Rwanda is one of the countries for which the researchers could not obtain figures, which is part of why they describe their USD 2 billion total as a floor rather than an estimate. WHY A SMALL DEPLOYMENT STILL BELONGS ON THIS MAP: the report's central finding is not about volume. It is that across all eleven countries these systems were rolled out WITHOUT the legal frameworks needed to define who may conduct public-space surveillance, on what authority, and under whose oversight, and without adequate means for a person to obtain remedy for an error or an abuse. A network of 849 AI-enabled cameras feeding a central command centre with no statutory basis is a governance problem at any size. The researchers add that the systems are mostly supplied and financed by Chinese firms and banks. NOT ESTABLISHED: no Rwanda-specific misuse finding appears in the coverage reviewed here, and this record should not be read as one. Coordinates are Kigali.

Pegasus targeting of dissidents abroad

Wrongful stop

Rwanda was named among Pegasus operators, with targets including the daughter and nephew of Hotel Rwanda figure Paul Rusesabagina; the leaked list also flagged South Africa's president as a possible Rwandan target.

2021 Source →
Senegal 2

Mass surveillance rolled out with no serious crime challenge cited

Wrongful stop

IDS and the African Digital Rights Network, publishing 12 March 2026, name Senegal alongside Zambia as countries where mass public-space surveillance was deployed despite what the researchers describe as no terrorist threat or serious crime challenge. Senegal is one of the 11 countries in the study; Reporting of the study's country tables puts Senegal at USD 167 million for about 500 smart cameras -- roughly USD 334,000 a camera, the highest unit cost among the countries where both figures are published, against about USD 9,700 in Egypt and USD 47,000 in Nigeria. Neither extreme is explained in the material reviewed. The report records that governments present these systems as crime prevention, counter-terrorism and urban management, and that the researchers found no compelling evidence of a reduction in terrorism or serious crime. Senegal already appears on this map for the 2026 national digital-ID breach; this record covers public-space cameras. Coordinates are Dakar.

National digital-ID system breached, biometric data stolen

Data misuse

In January 2026 a threat actor calling itself the Green Blood Group claimed to have breached Senegal's national digital-ID system and exfiltrated about 139 terabytes of data, including biometric records -- a stark illustration of the privacy risk when governments centralize biometric identity.

Jan 2026 Source →
South Africa 3

South Africa tenders face recognition for police body and dashboard cameras

Wrongful stop

SOUTH AFRICA'S POLICE MAY GET FACE RECOGNITION IN THEIR BODY CAMERAS. The State Information Technology Agency has put out a tender for police body-worn and dashboard cameras that must include facial recognition, both to unlock the devices and within the video analytics. Bids close on 29 September 2026 (tender RFB-3286-2026-ERP-496011, Gauteng). The tender gives no budget or camera count and does not say whether footage will be matched live against watchlists. Biometric Update notes the Protection of Personal Information Act appears unlikely to cover police body cameras. Ask SITA and SAPS what database faces would be matched against and under what legal authority.

Sep 2026 Source →

Blocked national IDs cut people off from services

Data misuse

In South Africa, the Home Affairs department's practice of blocking national IDs left many people unable to access banking, grants, and services, prompting legal challenges over the harms of digital identity systems.

Jan 2023 Source →

Suspected Pegasus operator in South Africa

Wrongful stop

Citizen Lab detected suspected Pegasus infections in South Africa.

Sep 2018 Source →
Tunisia 1

Suspected Pegasus operator in Tunisia

Wrongful stop

Citizen Lab detected suspected Pegasus infections linked to an operator in Tunisia.

Sep 2018 Source →
Uganda 3

Mandatory biometric ID excludes the elderly

Data misuse

Uganda's mandatory Ndaga Muntu biometric national ID has been challenged by civil-society groups for excluding elderly people from welfare benefits and blocking women's access to healthcare, amid wider use of biometrics to monitor dissent.

Huawei facial recognition turned on the opposition

Wrongful stop

Uganda built a Huawei Safe City network of facial-recognition cameras across Kampala. A 2019 Wall Street Journal investigation found Huawei technicians helped state agents crack the encrypted communications of opposition leader Bobi Wine, leading to his arrest, and police later confirmed using the cameras to track people detained during anti-government protests. Opposition figures call it a tool to hunt and persecute critics.

Aug 2019 Source →

Huawei face cameras blanket Kampala

Data misuse

Uganda installed a 126 million dollar Huawei facial-recognition camera system across the capital, Kampala, which the president framed as a tool to fight street crime. Opposition figures said the real aim was to deter and identify protesters against an increasingly unpopular government. MEASURED AGAIN SEVEN YEARS LATER: the IDS and African Digital Rights Network study of 12 March 2026 counts approximately 5,000 smart cameras in Uganda, one of 11 African countries surveyed. Set against the USD 126 million reported for the original Huawei installation, Uganda is one of the larger deployments in that study by camera count while Nigeria leads on spend at over USD 470 million for about 10,000 cameras. The 2026 researchers found little evidence across all eleven countries that expanding digital surveillance reduces overall crime -- which speaks directly to the street-crime justification given here in 2019 -- and found that none of the eleven provides adequate means to obtain remedy for surveillance errors or abuse. The 2026 study's country figures, as reported by Nairametrics and military.africa, put Uganda's spend at USD 189 million for about 5,000 smart cameras -- roughly USD 37,800 a camera, and above the USD 126 million reported for the original 2019 Huawei installation.

Zambia 3

Presidentially appointed cyber agency backed police cases against the president's critics

Wrongful stop

MISA Regional's preliminary statement on the 13 August 2026 general elections, published 17 August 2026, says the Zambia Cyber Security Agency supported police investigations into critics of the president and of the Electoral Commission of Zambia. The agency's head is appointed by the president, which MISA calls a structural conflict of interest. MISA also reports public warnings issued by the Zambia Police Service and the army that it describes as unlawful, and attributes a chilling effect to the Cyber Security Act 2025 and the Cyber Crimes Act 2025. MISA says a Constitutional Court challenge to both Acts is pending; the outcome is not established and no hearing date is recorded here. No government response is included in the statement. Ask the Agency for the number of investigations it supported and the statutory basis for each. Coordinates are Lusaka, not a specific facility.

Aug 2026 Source →

Public-space cameras where the study found no terrorism to counter

Wrongful stop

Zambia is one of 11 countries in Smart City Surveillance in Africa, published 12 March 2026 by the Institute of Development Studies with the African Digital Rights Network. The report names Zambia and Senegal as places where mass public-space surveillance was deployed despite what the researchers describe as no terrorist threat or serious crime challenge, and says they found no compelling evidence across any of the 11 countries that smart surveillance reduced terrorism or serious crime. Governments present the systems as crime prevention, counter-terrorism, modernisation and urban management. IDS gives the 11-country total as at least USD 2 billion. Reporting of the study's country tables (Nairametrics, 23 March 2026) puts Zambia at USD 210 million for about 1,600 smart cameras -- the fourth-largest spend of the eleven, and roughly USD 131,000 per camera by simple division. The figures are the researchers' counts, drawn from public accounts they describe as incomplete, not an audit. Coordinates are Lusaka, not a specific site.

Suspected Pegasus operator in Zambia

Wrongful stop

Citizen Lab detected suspected Pegasus infections linked to an operator in Zambia.

Sep 2018 Source →
Zimbabwe 1

Chinese facial recognition for mass surveillance

Wrongful stop

From 2018 Zimbabwe acquired facial-recognition technology from CloudWalk and Hikvision for border control and mass surveillance, with citizens' biometric data sent back to the Chinese vendors. QUANTIFIED IN 2026: the IDS and African Digital Rights Network study of 12 March 2026 records USD 10 million spent by Zimbabwe on smart city surveillance, the smallest published figure among the eleven countries studied, with the camera count not specified. That is a useful corrective to reading deployment scale from spending alone -- Zimbabwe's earlier significance on this map is the DATA FLOW, citizens' biometric data returning to the Chinese vendors, not the size of the contract. The 2026 study found the same pattern of Chinese supply and financing across all eleven countries, and no adequate means anywhere to obtain remedy for surveillance errors or abuse.

Asia 53
Armenia 1

Predator spyware customer

Wrongful stop

Armenia was identified by Citizen Lab as a Predator spyware customer, part of a cluster of governments deploying the Cytrox tool against phones alongside the better-known Pegasus.

2021 Source →
Azerbaijan 2

Pegasus used against journalists

Wrongful stop

Azerbaijan was identified as a Pegasus operator with around 48 journalists selected for targeting, including OCCRP investigative reporter Khadija Ismayilova, whose phone was infected for nearly three years, and Meydan TV freelancer Sevinc Vaqifqizi.

DPI gear powered social-media blackouts

Data misuse

Sandvine and Allot deep-packet-inspection equipment was deployed in Azerbaijan to impose social-media blackouts during periods of unrest.

Bahrain 1

Zero-click hacking of activists

Wrongful stop

Bahraini human-rights activists were hacked with Pegasus in zero-click attacks that defeated new Apple protections, part of the Gulf state's documented use of commercial spyware against dissidents.

Bangladesh 1

Suspected Pegasus operator in Bangladesh

Wrongful stop

Citizen Lab detected suspected Pegasus infections in Bangladesh, where authorities have acquired a range of phone interception and surveillance systems.

Sep 2018 Source →
China 4

Face scans track the Uyghur population

Wrongful stop

In Xinjiang, authorities use facial recognition to monitor the mostly Muslim Uyghur population, with face scans required to enter shops, hotels, and stations and tens of thousands of cameras in Urumqi alone. Leaked police files showed Hikvision systems used to screen all 23 million residents and flag people with overseas ties for arrest.

Face recognition built to sort people by ethnicity

Wrongful stop

Chinese authorities, working with surveillance firms including Hikvision, Dahua, and Uniview, drew up facial-recognition standards that sort people by traits such as ethnicity and skin color, which researchers warned opened wide scope to target minorities like the Uyghurs at scale.

Plate and vehicle tracking refined on Uyghurs

Data misuse

Hikvision, the world's largest maker of plate readers and surveillance cameras, refined vehicle and face tracking in Xinjiang, where checkpoints and cameras monitor Uyghurs' movements. Those battle-tested systems are now exported worldwide.

Biometric dragnet over Uyghurs and Turkic Muslims

Data misuse

China has built a pervasive biometric surveillance system across Xinjiang to control Uyghurs and other Turkic Muslims, combining facial-recognition checkpoints, mandatory collection of iris scans and DNA, and a predictive-policing platform that flags ordinary behavior as suspicious. It has funneled people into a network of detention camps that a 2022 UN report said may amount to crimes against humanity, with up to a million held.

Jan 2017 Source →
Hong Kong 2

Hong Kong -- SmartView CCTV to add facial recognitionHong Kong

Contesting

HONG KONG POLICE SAY FACE RECOGNITION IS COMING TO THEIR STREET CAMERAS IN 2026. Commissioner Joe Chow said in February 2026 that police aim to add facial recognition to the SmartView public CCTV network this year, after missing an end-2025 target because of what he called legal and technical issues. SmartView began in April 2024; police added about 2,000 camera units in 2025 and planned 2,000 more in 2026, and a second phase for 2026-28 would add some 20,000 cameras a year, partly by pulling other departments' cameras into the police network (Hong Kong Free Press, citing a Legislative Council paper). Police credit SmartView with a 42.5% fall in certain street crimes; that figure is theirs. There is no specific law governing police facial recognition in Hong Kong in any source read. Not established: whether face matching has been switched on, what watchlists it would use, or any rules from the Privacy Commissioner.

Wrongful stops

Protesters tear down face-scanning smart lampposts

Wrongful stop

During the 2019 pro-democracy protests, Hong Kongers wore masks and carried umbrellas and tore down 'smart lampposts' in Kowloon, fearing they held facial recognition that could identify demonstrators and expose them to arrest. Police had access to AI able to match faces from video to databases, and the fear of being identified kept some people away from the streets.

Aug 2019 Sourcesscmp.comcnn.com
India 4

India

Contesting

After reports that about 300 Indian numbers, including those of journalists, opposition politicians, and activists, appeared in the leaked Pegasus list, the Supreme Court appointed an independent expert committee in October 2021 to investigate alleged government use of the spyware. The committee said the government did not cooperate, and its findings remain sealed.

Oct 2021 Pegasus (NSO Group) Source →

Wrongful stops & data misuse

Facial recognition used to identify protesters

Wrongful stop

Delhi police used facial recognition to identify and arrest people from the 2020 anti-CAA protests and the communal riots that followed, later saying scores of the riot arrests were traced by the technology, and turned it on Sikh farmers during the 2021 farmers' protests. Rights groups documented its disproportionate use against Muslims and other minorities and a chilling effect on the right to protest.

Feb 2020 Source →

Face recognition aimed hardest at Muslims

Wrongful stop

Delhi police rolled out facial recognition that researchers found would inevitably fall hardest on the city's Muslim community, and used it to identify protesters, with much of the deployment kept under wraps.

Jan 2020 Source →

World's largest biometric ID raises exclusion fears

Data misuse

India's Aadhaar program enrolled the biometrics of more than 1.3 billion people into the central CIDR database. Civil-society groups warn it drives surveillance and exclusion; India's Supreme Court recognized privacy as a fundamental right in 2017 and curbed mandatory Aadhaar use in 2018.

Indonesia 2

Indonesia

Paused

Indonesia suspended World (formerly Worldcoin) and World ID in May 2025 after public complaints, with the Ministry of Communication and Digital pausing the operator's permit as what its director general for digital supervision, Alexander Sabar, called a preventative measure to mitigate risks to the public. The ministry's investigation gave the suspension its edge: officials said retina data had been collected from Indonesians since 2021, while the local operator only registered as a foreign electronic system provider in 2025 -- four years of collection before the paperwork existed. The app had been offering people between Rp200,000 and Rp800,000 for scans. Two local entities were put under investigation over licensing and unlawful operations.

May 2025 Worldcoin iris scanning Sourcesbiometricupdate.comen.tempo.co

Wrongful stops

Predator spyware customer

Wrongful stop

Indonesia was documented as a Predator spyware customer, one of several governments Citizen Lab linked to the Cytrox surveillance tool used against people of interest.

2021 Source →
Iran 3

Face recognition installed to catch unveiled students

Wrongful stop

Iranian authorities installed facial recognition at Amirkabir University of Technology in Tehran to identify and penalize women students who removed their headscarves, part of a wider rollout of cameras and drones to enforce hijab laws.

An app flags cars when a woman inside is unveiled

Data misuse

Iran's police run a phone app, Nazer, that lets officers and vetted civilians flag a vehicle's license plate when a woman inside is unveiled. The system sends the owner an automatic warning and then impounds the car. Amnesty documents hundreds of thousands of vehicles confiscated since 2023, and the app was later extended to taxis, ambulances, and buses.

Surveillance enforcing mandatory hijab

Wrongful stop

Iran uses facial recognition, road cameras, drones, and a citizen-reporting app to enforce mandatory hijab rules on women. A 2025 UN fact-finding mission documented facial recognition installed at a Tehran university gate to catch uncovered students, and metro screens in Mashhad displaying passengers' faces, age, and gender to frighten women out of defiance.

Sep 2022 Source →
Iraq 1

Suspected Pegasus operator in Iraq

Wrongful stop

Citizen Lab detected suspected Pegasus infections linked to an operator in Iraq.

Sep 2018 Source →
Israel 3

Israel

Restricted

After the Pegasus revelations and the US blacklisting of NSO Group and Candiru, Israel's Defense Ministry cut the list of countries its cyber firms may sell surveillance and hacking tools to from 102 to 37 in November 2021, dropping clients with poor rights records such as Morocco, Mexico, Saudi Arabia, and the UAE, and reportedly revoked thousands of export licenses over the following year. It is a rare case of the source country reining in its own spyware industry.

Nov 2021 NSO Group, Candiru Source →

Data misuse

Red Wolf tracks Palestinians at checkpoints

Data misuse

In the occupied West Bank city of Hebron, an Israeli military facial-recognition system called Red Wolf scans Palestinians at checkpoints and enrolls their faces into surveillance databases without consent, deciding who may pass. Amnesty International's 2023 Automated Apartheid report documented how it automates movement restrictions and tracks residents, and how soldiers were rewarded for registering as many Palestinians as possible.

May 2023 Source →

Cameras track Palestinians' cars by plate

Data misuse

Israeli surveillance cameras in occupied East Jerusalem capture license plates on fixed and moving vehicles, feeding a database of Palestinians that records plates, permits, and addresses, restricting Palestinians' movement within their own neighborhoods. Researchers identified Hikvision and TKH cameras in the network.

May 2023 Sourcesamnesty.orgmei.edu
Japan 1

A secretive national plate-reading network since the 1980s

Data misuse

Japan's National Police Agency has run the secretive N-System since the late 1980s, reading and recording license plates at hundreds of sites on highways and major roads, including a ring around Tokyo's Kabukicho district. Police disclose little about how long the data is kept or how it is used, and privacy advocates call it part of an emerging surveillance society.

Jan 1987 Sourcescsmonitor.comubisurv.net
Jordan 2

Journalists and rights workers hacked

Wrongful stop

Pegasus was used against at least 16 Jordanian journalists and activists, including two Human Rights Watch staff and a Palestinian-American reporter hacked three times, many of whom had covered a teachers' strike the government crushed.

2023 Source →

DPI used to censor an LGBTQ website

Data misuse

In Jordan, Sandvine equipment was used to censor an LGBTQ news website.

Kazakhstan 2

Allot DPI throttled Telegram before a blackout

Data misuse

Allot's deep-packet-inspection technology was used in Kazakhstan to throttle Telegram and other platforms ahead of a January 2021 nationwide internet blackout.

Jan 2021 Source →

Civil society activists targeted

Wrongful stop

Four Kazakh civil society activists were confirmed targets of Pegasus, part of the leaked list of tens of thousands of phone numbers selected by NSO Group government clients.

2021 Source →
Kuwait 1

Suspected Pegasus operator in Kuwait

Wrongful stop

Citizen Lab detected suspected Pegasus infections linked to an operator in Kuwait.

Sep 2018 Source →
Kyrgyzstan 1

Suspected Pegasus operator in Kyrgyzstan

Wrongful stop

Citizen Lab detected suspected Pegasus infections in Kyrgyzstan.

Sep 2018 Source →
Lebanon 1

Officials and journalists on Pegasus list

Wrongful stop

Phone numbers of senior Lebanese figures appeared on the Pegasus list, including the president, a former prime minister, ministers, security chiefs, and numerous journalists and ambassadors, according to the Pegasus Project.

2021 Source →
Malaysia 1

Hacking Team spyware client in Malaysia

Wrongful stop

Malaysian agencies were among the clients of Hacking Team's Remote Control System spyware revealed by the 2015 breach of the Italian vendor.

Jul 2015 Sourcesblog.sekoia.iocitizenlab.ca
Mongolia 1

Predator spyware infrastructure

Wrongful stop

Mongolia appeared among the governments linked to Intellexa's Predator spyware in the Predator Files, with Amnesty International documenting infrastructure associated with the tool.

2023 Source →
Myanmar 1

Junta expands Chinese safe-city cameras

Wrongful stop

Myanmar's military junta expanded Chinese-supplied safe-city camera networks with facial recognition across cities, raising fears of tracking dissidents after the 2021 coup.

Oman 1

Predator spyware customer

Wrongful stop

Oman was documented as a Predator spyware customer by Citizen Lab, adding a Gulf state to the list of governments using the Cytrox tool against targets of interest.

2021 Source →
Pakistan 1

Pegasus and the leaked target list

Wrongful stop

The phone number of then prime minister Imran Khan appeared on the leaked Pegasus target list, and Citizen Lab detected suspected Pegasus infections in Pakistan.

Philippines 2

Philippines

Paused

The Philippines' National Privacy Commission ordered Tools for Humanity to immediately halt operations in Oct 2025, citing consent failures and the exploitation of vulnerable populations -- the regulator saying out loud what the token model implies: the program's growth ran through people for whom the payout was the point. The Philippine order made it the fourth Asia-Pacific jurisdiction to stop the program in a single year, after Indonesia's suspension and amid continuing scrutiny in Hong Kong, and it landed while the company was signing identity-verification partnerships with Tinder, Zoom and Docusign in the US -- the same biometric network regulators were halting abroad being sold as fraud protection at home.

Oct 2025 Worldcoin iris scanning Source →

Wrongful stops

Predator spyware customer

Wrongful stop

A Predator spyware customer assessed as highly likely linked to the Philippines was identified by Recorded Future, the first time the tool's use was tied to the country.

2024 Source →
Qatar 1

Suspected Pegasus operator in Qatar

Wrongful stop

Citizen Lab detected suspected Pegasus infections linked to an operator in Qatar.

Sep 2018 Source →
Saudi Arabia 1

Pegasus around the Khashoggi killing

Wrongful stop

Saudi Arabia used Pegasus against people close to murdered journalist Jamal Khashoggi, including an exiled dissident friend and his fiancee, whose phone was infected days after his 2018 killing.

2018 Source →
Singapore 1

Suspected Pegasus operator in Singapore

Wrongful stop

Citizen Lab detected suspected Pegasus infections in Singapore.

Sep 2018 Source →
South Korea 2

Police ran face recognition on CCTV and web images

Wrongful stop

South Korean police tracked suspects with Videmo 360 facial recognition software, analyzing images pulled from CCTV and the internet, in a case that raised concerns over the legality of the surveillance.

Jan 2021 Source →

Hacking Team spyware client in South Korea

Wrongful stop

South Korea's National Intelligence Service was a client of Hacking Team's Remote Control System spyware, revealed by the 2015 breach and sparking domestic controversy.

Jul 2015 Sourcescitizenlab.cablog.sekoia.io
Sri Lanka 1

Chinese-supplied facial recognition surveillance

Wrongful stop

Sri Lanka received Chinese-made AI surveillance and facial-recognition technology as part of Huawei and partner safe-city deployments.

Syria 1

Blue Coat and Sandvine gear filtered the internet

Data misuse

Syria's telecom authority deployed deep-packet-inspection equipment, including Blue Coat and Sandvine gear, to filter and censor the internet and redirect users to malicious sites during the civil war.

Thailand 2

Thailand

Contesting

Pro-democracy activist Jatupat Boonpattararaksa, whose phone was infected with Pegasus three times in 2021, sued NSO Group in the Bangkok Civil Court. Amnesty International filed an expert brief in the case in September 2024, part of a wider effort to hold the spyware industry accountable in Thai courts.

Sep 2024 Pegasus (NSO Group) Source →

Wrongful stops

Pegasus on pro-democracy protesters

Wrongful stop

Forensic analysis confirmed Pegasus on the phones of at least 30 Thai pro-democracy protesters, academics, and rights defenders during the 2020 to 2021 mass demonstrations, the first confirmed use of the spyware in the country.

2021 Source →
Turkiye 2

Pegasus infections tied to Khashoggi targeting

Wrongful stop

Citizen Lab detected suspected Pegasus infections in Turkey, where associates of murdered journalist Jamal Khashoggi were among those targeted.

Sep 2018 Source →

DPI redirected users to government spyware

Wrongful stop

Citizen Lab's 2018 Bad Traffic report found Sandvine PacketLogic devices on Turkey's network redirecting hundreds of users to malicious sites that delivered government spyware, alongside blocking of political and news content.

United Arab Emirates 1

Early heavy use against dissidents

Wrongful stop

The UAE was an early and heavy Pegasus user, targeting activist Ahmed Mansoor with a zero-day exploit in 2016 and later the ex-wife and associates of Dubai's ruler, part of one of the most extensive deployments of the spyware.

Vietnam 1

Predator aimed at EU lawmakers

Wrongful stop

Vietnam deployed Predator spyware against targets including members of the European Parliament and used commercial spyware against bloggers, part of a broad surveillance campaign accompanying its jailing of online critics.

2023 Source →
Yemen 1

Suspected Pegasus operator in Yemen

Wrongful stop

Citizen Lab detected suspected Pegasus infections in Yemen.

Sep 2018 Source →
Oceania 9
Australia 6

Australia

Restricted

Australia privacy regulator, the OAIC, ruled Clearview AI breached privacy law by scraping Australians images and ordered it to stop and delete the data. In 2024 the regulator also found retailer Bunnings breached privacy by running in-store facial recognition on hundreds of thousands of shoppers, a finding a tribunal later softened in part on appeal.

  1. Nov 2021 The OAIC found Clearview AI breached the Privacy Act by scraping Australians faces and ordered it to stop collecting and to delete the data. theconversation.com
  2. Nov 2024 The Privacy Commissioner ruled Bunnings breached privacy by running facial recognition on shoppers across more than 60 stores, and ordered it to stop and destroy the data. oaic.gov.au
  3. Feb 2026 A review tribunal upheld the notification and governance breaches but found Bunnings could use the technology for the limited purpose of fighting serious retail crime. The Commissioner did not appeal. oaic.gov.au
Nov 2024 (approx.) Facial recognition Sourcesoaic.gov.autheconversation.com

Australia (Bunnings)Australia

Removed

Australia's Privacy Commissioner ruled on Nov 19, 2024 that Bunnings -- the country's biggest home-improvement chain -- breached privacy law by running facial recognition on likely hundreds of thousands of customers across 62-63 stores in New South Wales and Victoria between Nov 2018 and Nov 2021, without consent and without telling anyone. The system compared every entering face against a database of people flagged for past crime or violent behaviour, deleting non-matches automatically -- and Commissioner Carly Kind's finding is the one that travels: efficient and well-intentioned does not mean lawful, because the technology interfered with the privacy of everyone who walked in, not just the flagged. The orders after a two-year investigation: stop, never repeat, destroy all retained personal and sensitive data after 12 months, and publish a public statement of the mishandling within 30 days. No fine was imposed. Bunnings called itself deeply disappointed, released CCTV of staff being assaulted in its defence, and is seeking Administrative Review Tribunal review -- so the orders stand but the fight continues. Pinned at Melbourne (company HQ) as a national-chain convention.

Nov 2024 (approx.) Retail facial recognition Sourcesitnews.com.autherecord.mediatheconversation.com

Australia (The Good Guys)Australia

Paused

Electronics chain The Good Guys, owned by JB Hi-Fi, paused its facial-recognition trial in Jun 2022 within a day of consumer group CHOICE naming it in a complaint to the Office of the Australian Information Commissioner -- the complaint called the use unreasonably intrusive and potentially unlawful, and named Bunnings and Kmart alongside it. The company said it was confident it had complied with the law and paused anyway pending OAIC clarification, which is the point of recording it: the pause came from a consumer-group complaint and press attention, before any regulator ruled. The three chains named in that one complaint ran to about A$25 billion in annual sales across 800 stores; the Bunnings arm of it produced the landmark 2024 determination. Pinned at Melbourne as a national-chain convention.

Jun 2022 Retail facial recognition Source →

Australia (7-Eleven)Australia

Removed

The Australian Information Commissioner ordered the 7-Eleven chain in 2021 to destroy the faceprints it had collected at roughly 700 convenience stores -- gathered through iPads set up to run customer feedback surveys, which photographed the faces of the people filling them in. A survey tablet doubling as a biometric collector is the detail that makes this record generalise: the collection surface was disguised as something mundane, and nobody tapping a satisfaction screen understood they were being faceprinted. The destruction order made 7-Eleven an early marker in what became the OAIC's retail-biometrics line -- the same regulator ordered Clearview AI to destroy Australian data and stop scraping the same year, and reached the landmark Bunnings determination in 2024. Date marked approximate: sourced reporting places the order in 2021 without a confirmed day. Pinned at Melbourne as a national-chain convention.

Oct 2021 (approx.) Retail facial recognition Source →

Data misuse

Privacy Act breach, deletion ordered

Data misuse

Australia's information commissioner found in 2021 that Clearview AI breached the Privacy Act by scraping residents' faces without consent and ordered it to stop and delete the data; a tribunal upheld the ruling in 2023.

Statewide plate-reader fleet, pushed to police borders

Data misuse

Every Australian state runs plate readers. New South Wales' mobile MANPR fleet scans every passing vehicle statewide, storing hundreds of thousands of records a day, and was pushed to profile drivers at closed state borders during COVID lockdowns. The Australian Privacy Foundation calls ANPR a mass-surveillance technique that breaches freedom of movement.

Sep 2020 Sourcesmals.auprivacy.org.au
New Zealand 3

New Zealand

Paused

New Zealand Police secretly trialed Clearview AI in 2020 without sign-off from the Police Commissioner, the Privacy Commissioner, or Cabinet. After the trial was exposed and halted, an independent review led police to commit not to use live facial recognition until its privacy, legal, and ethical impacts are understood.

  1. May 2020 Reporting revealed police had secretly trialed Clearview AI without authorization. The trial was halted and the Police Commissioner ordered a stocktake of surveillance tools. rnz.co.nz
  2. Dec 2021 An independent review prompted police to halt plans for live facial recognition, with police stating they will not use it until the impacts are fully understood. rnz.co.nz
May 2020 Facial recognition Sourcesrnz.co.nzrnz.co.nz

Data misuse

Police tap a private plate network half a million times a year

Data misuse

New Zealand police query Auror, an Auckland retail-crime ANPR platform, hundreds of times a day -- around half a million times a year -- with thousands of officers able to access it without stating a reason. Defence lawyers challenging it in the Court of Appeal call it 'surveillance capitalism.'

Sep 2025 Sourcesrnz.co.nznzherald.co.nz

Police faked reports to track people with plate cameras

Data misuse

Just a month after the Privacy Commissioner warned police to do better on plate cameras, a detective pretended a car was stolen so they could track it, and officers filed a false report to use ANPR to track women linked to a Northland lockdown breach.

Jul 2021 Source →
Other 13
Angola 1

Predator spyware infrastructure

Wrongful stop

Angola was identified in the Predator Files as a likely customer of Intellexa's Predator spyware, with Amnesty International finding technical infrastructure tied to the tool active in the country.

2023 Source →
Cote d'Ivoire 1

Suspected Pegasus operator in Ivory Coast

Wrongful stop

Citizen Lab detected suspected Pegasus infections linked to an operator in Ivory Coast (Cote d'Ivoire).

Sep 2018 Source →
Eritrea 1

Closed state supplied with DPI gear

Data misuse

Eritrea, one of the world's most closed states, was among the authoritarian governments supplied with Sandvine deep-packet-inspection equipment for internet control.

Libya 2

Suspected Pegasus operator in Libya

Wrongful stop

Citizen Lab detected suspected Pegasus infections linked to an operator in Libya.

Sep 2018 Source →

Amesys Eagle system enabled mass interception

Data misuse

Under Muammar Gaddafi, Libya deployed the French company Amesys's Eagle system for nationwide internet interception and mass surveillance of dissidents; French magistrates later charged Amesys executives over complicity in torture.

Madagascar 1

Predator spyware customer

Wrongful stop

Madagascar was named among the government customers of Predator spyware identified by Citizen Lab, part of a growing roster of states buying commercial surveillance tools.

2021 Source →
Mauritius 1

Second-largest buyer; Safe City images went missing in a death inquiry

Wrongful stop

IDS and the African Digital Rights Network place Mauritius second among the 11 African countries studied at USD 456 million on smart city surveillance, in research published 12 March 2026. The programme predates that figure: Huawei made an unsolicited bid in 2015, the Police Service signed two operating-lease contracts with Mauritius Telecom on 19 December 2017, and China Eximbank signed a preferential buyer's credit of USD 73,687,000 with Mauritius Telecom on 1 April 2018 at 2 per cent interest over a 20-year maturity with a 7-year grace period, according to AidData. Answering a parliamentary question on 11 August 2020, Prime Minister Pravind Kumar Jugnauth said 2,761 intelligent video surveillance cameras were installed at 1,429 sites and 140 traffic cameras at 68 sites, and that 101 cases requiring police enquiry had been detected through Safe City cameras. That detection figure is the government's own count and no audit of it is recorded here. Mauritius Times reported the system's total cost as Rs 19 billion with roughly Rs 350 million a year to operate; that comes from one newspaper and is not corroborated here, and it is not established how it relates to the USD 456 million figure. In the judicial inquiry into the death of Soopramanien Kistnen, Safe City images were reported missing and a Huawei representative was questioned. Coordinates are Port Louis.

Palestine 2

Soldiers scan Palestinians' faces at checkpoints

Data misuse

Israeli soldiers in Hebron use face-scanning cameras, known as Red Wolf, to identify Palestinians at checkpoints without checking IDs, feeding a database used to control their movement. Amnesty calls it automated apartheid.

May 2023 Sourcesamnesty.orgmei.edu

Pegasus used against Palestinian rights defenders

Wrongful stop

Citizen Lab detected suspected Pegasus infections in Palestine, where Palestinian human rights defenders were later confirmed to have been hacked.

Sep 2018 Source →
Sudan 1

Predator spyware infrastructure

Wrongful stop

Sudan was among the countries where Amnesty International found technical infrastructure linked to Intellexa's Predator spyware in the Predator Files investigation.

2023 Source →
Tajikistan 1

Suspected Pegasus operator in Tajikistan

Wrongful stop

Citizen Lab detected suspected Pegasus infections linked to an operator in Tajikistan.

Sep 2018 Source →
Togo 1

Pegasus against critics and clergy

Wrongful stop

Togo appeared among NSO Group's Pegasus clients in the Pegasus Project, which documented the spyware being used against journalists, opposition figures, and members of the clergy critical of the government.

2021 Source →
Uzbekistan 1

Suspected Pegasus operator in Uzbekistan

Wrongful stop

Citizen Lab detected suspected Pegasus infections linked to an operator in Uzbekistan.

Sep 2018 Source →

What counts, and what does not

This map is deliberately narrow. The big deployment trackers, like DeFlock and the EFF Atlas of Surveillance, map where the cameras are. This one maps where communities decided they didn't want them: a council vote to terminate a contract, a moratorium pending review, a proposed system voted down, or an expansion rejected. Each entry is tied to a primary or reputable secondary source, and it's verified before it goes on the map rather than added from memory.

Know of a community that removed, paused, denied, or restricted ALPRs and isn't here yet? Send a sourced article and it will be reviewed.

Most shared

Top 5 surveillance stories

The most-shared reporting on license-plate readers and police surveillance right now.

  1. 1 LAPD lets its Flock Safety contract expire over privacy concerns The LAPD let its three-year agreement with Flock Safety lapse over civil-liberties and privacy concerns and is renegotiating narrower terms -- the largest U.S. department yet to step back from the ALPR network. ABC7 Los Angeles Jul 2026
  2. 2 GBI arrests five former Albany officers for misusing Flock license-plate data Five former Albany, GA officers were arrested for running unauthorized Flock searches -- the first charges out of Flock's own audit-assistance program, amid a wider Georgia wave of misuse cases. Georgia Bureau of Investigation Jul 2026
  3. 3 Flock Safety crosses 100,000 cameras as 53 cities cancel over federal data access License-plate-reader data routed to ICE and federal agencies without cities' authorization triggered a wave of cancellations, lawsuits, and a constitutional fight over ALPR mass surveillance. Tech Times Jun 2026
  4. 4 Framingham police won't renew Flock contract after months of resident opposition After sustained privacy and data-sharing concerns raised at public meetings, the city let its ALPR contract lapse. Boston.com Jun 2026
  5. 5 ACLU: Flock Safety repeatedly lied to city councils, police, and the public After Oshkosh caught the company misrepresenting its 'heat map' tracking, the ACLU documented a pattern of misleading statements. ACLU Jun 2026

Want your town on this map?

Here is how communities get the cameras out

Every removal on this map started with a few residents who learned how the contract worked and showed up. We put together a plain-language guide to starting that process where you live, who to contact, and what's actually worked.

Read the take-action guide →