South Africa tenders face recognition for police body and dashboard camerasSouth Africa
Wrongful stop
SOUTH AFRICA'S POLICE MAY GET FACE RECOGNITION IN THEIR BODY CAMERAS. The State Information Technology Agency has put out a tender for police body-worn and dashboard cameras that must include facial recognition, both to unlock the devices and within the video analytics. Bids close on 29 September 2026 (tender RFB-3286-2026-ERP-496011, Gauteng). The tender gives no budget or camera count and does not say whether footage will be matched live against watchlists. Biometric Update notes the Protection of Personal Information Act appears unlikely to cover police body cameras. Ask SITA and SAPS what database faces would be matched against and under what legal authority.
Pegasus and NoviSpy hit Serbia's student movement around local electionsSerbia
Data misuse
AT LEAST 14 SERBIAN STUDENTS, ACTIVISTS AND OPPOSITION POLITICIANS TARGETED WITH SPYWARE IN 2026. Citizen Lab, working with SHARE Foundation and Amnesty Tech, confirmed on 2 September 2026 that a member of the student protest movement had Pegasus on their iPhone between December 2025 and January 2026, delivered by a zero-click iMessage exploit. The same investigators found a new Android version of NoviSpy, the spyware previously installed on phones seized by Serbian police; EDRi reports it was set up to send data to the Security Information Agency. EDRi counts at least 14 targets since early 2026, including an opposition MP and a local councillor, clustered around the 29 March local elections. Citizen Lab does not formally attribute the Pegasus case to a government. No response from Serbian authorities is on record here.
Presidentially appointed cyber agency backed police cases against the president's criticsZambia
Wrongful stop
MISA Regional's preliminary statement on the 13 August 2026 general elections, published 17 August 2026, says the Zambia Cyber Security Agency supported police investigations into critics of the president and of the Electoral Commission of Zambia. The agency's head is appointed by the president, which MISA calls a structural conflict of interest. MISA also reports public warnings issued by the Zambia Police Service and the army that it describes as unlawful, and attributes a chilling effect to the Cyber Security Act 2025 and the Cyber Crimes Act 2025. MISA says a Constitutional Court challenge to both Acts is pending; the outcome is not established and no hearing date is recorded here. No government response is included in the statement. Ask the Agency for the number of investigations it supported and the statutory basis for each. Coordinates are Lusaka, not a specific facility.
The spyware inquiry was itself spied on: Pegasus on a PEGA member's phoneGreece
Data misuse
THE SPYWARE INQUIRY WAS ITSELF SPIED ON. Citizen Lab reported on 3 July 2026 that Stelios Kouloglou, a Greek former MEP and substitute member of the European Parliament's PEGA committee investigating Pegasus, was infected with Pegasus twice while the committee sat -- on 21 October 2022 in Greece and on 6-7 March 2023 in Belgium. Apple sent him three threat notifications he reportedly did not recall. Citizen Lab does not name a government, says it found no sign the Greek government was responsible, and ties the operation to a campaign against exiled Russian- and Belarusian-speaking journalists in Europe -- pointing to a Pegasus customer able to operate in several EU countries. Whether the Parliament has opened an inquiry into the breach is not established here.
Two Russian agencies gave different counts of detained chatbot usersRussia
Wrongful stop
On 29 July 2026 the FSB said Ukrainian intelligence had used the Telegram dating chatbot Daivinchik, also called Leo, to recruit Russians for sabotage and arson, and that 46 users aged 12 to 22 had been detained across 16 regions since July 2025. Russia's Investigative Committee, in a separate statement about the same chatbot, gave 19 teenagers aged 14 to 18, detained in Moscow, St Petersburg, Novosibirsk and the Rostov and Saratov regions. Both counts come from the agencies themselves. The record does not resolve which is correct or whether the two describe the same detentions. Meduza reported that the chat interfaces in videos the security services released as proof were from a Russian application rather than Telegram. The FSB charged Telegram founder Pavel Durov with aiding terrorism and he was placed on Rosfinmonitoring's register of terrorists and extremists; a separate terrorism case had been opened against him in February 2026. None of the allegations has been tested in an adversarial hearing. Coordinates are Moscow; the detentions were spread across regions.
Judge and general jailed for spying on a journalistChile
Wrongful stop
A Chilean court on Jun 30, 2026 sentenced a former judge and a former army general to five years in prison for illegally spying on investigative journalist Mauricio Weibel Barahona while he was reporting Milicogate -- his 2015 investigation for The Clinic into the theft of the army's copper reserve fund. The Committee to Protect Journalists called the decision unprecedented for Chile. Two details give it weight beyond the country: the surveillance was run through the machinery of state -- a judge and a general, not a rogue operator -- against a journalist for the act of reporting on the military that employed one of them; and accountability took eleven years from publication and six years of judicial process to arrive. Custodial sentences for state officials over journalist surveillance remain rare enough worldwide that each one is a record; this is Latin America's counterpart to Greece's Feb 2026 Predatorgate convictions, and unlike Greece's suspended terms, these are prison sentences.
Canada gives cabinet secret orders over telecom networksCanada
Wrongful stop
CANADA'S CABINET CAN NOW ORDER TELECOM COMPANIES TO ACT -- AND ORDER THEM TO KEEP IT SECRET. Bill C-8 received Royal Assent on 15 June 2026. It lets the federal cabinet bar carriers from using named suppliers and lets the Industry Minister order a provider to do, or stop doing, anything needed to secure its network -- including cutting off service to specified persons -- with orders that can forbid disclosure of their own existence. The Minister can share what is collected with CSIS, the Communications Security Establishment, other departments, 'any other prescribed' body and foreign governments. Challenges go to court only after the fact, and the judge can hear evidence the challenger never sees: on 25 March the Speaker ruled out amendments that would have required a judge to approve orders first. The final law does bar ordering decryption of private communications or interception. A new Critical Cyber Systems Protection Act makes designated operators report incidents to CSE within 72 hours. The Privacy Commissioner, OpenMedia and the CCLA all said safeguards fall short. NOT ESTABLISHED: whether any secret order has been issued -- by design, the public may not learn. Read with Bill C-22, the lawful-access bill still in the Senate.
Biometric 'digital profile' of foreign nationalsRussia
Data misuse
Russia moved to build a centralized 'digital profile' of foreign nationals and stateless people, expected by mid-2026, pulling extensive personal and biometric information from multiple agencies -- part of a broader expansion of surveillance targeting foreign visitors and residents.
Met expands permanent facial recognition to the West EndUnited Kingdom
Wrongful stop
In June 2026 Metropolitan Police Commissioner Sir Mark Rowley announced the most significant expansion of live facial recognition in London to date: static LFR cameras mounted on street furniture across the West End and Soho by the end of 2026, meant to grow into a citywide infrastructure programme rather than time-limited van operations. It followed a six-month Croydon pilot (October 2025 to March 2026, 24 operations, 173 arrests, more than 470,000 faces scanned) and an April 2026 High Court ruling that the Met's LFR policy was lawful, now under appeal. Big Brother Watch urged the force to stop until Parliament legislates, noting the UK still has no specific statutory framework for LFR.
UK plugs its plate-reader network into EU-wide Prum sharingUnited Kingdom
Data misuse
In June 2026 the UK Home Office switched on number-plate checks through the EU's Prum data-sharing framework, letting officers query overseas-registered vehicles across EU member states and get vehicle-keeper details back in about ten seconds instead of days or months. It bolts cross-border reach onto Britain's already vast plate-reader system -- commonly cited at around 11,000 ANPR cameras reading roughly 50 million plates a day into the National ANPR Data Centre, where records are retained for a year. The government framed the link-up around border security, illegal migration and organised crime.
80,000 protesters scanned; a worker wrongly flaggedUnited Kingdom
Wrongful stop
London's Metropolitan Police scanned the faces of about 80,000 people at a single protest and have run live facial recognition against millions of faces. Youth worker Shaun Thompson was wrongly flagged, detained, and threatened with arrest before being compensated. Campaigners call it stop and search on steroids.
Greek Watergate and the Predator convictionsGreece
Wrongful stop
In the Greek Watergate scandal, Intellexa's Predator spyware was used against politicians and journalists, and in 2026 a Greek court sentenced Intellexa founder Tal Dilian and others to eight years for illegal operations.
Public-space cameras where the study found no terrorism to counterZambia
Wrongful stop
Zambia is one of 11 countries in Smart City Surveillance in Africa, published 12 March 2026 by the Institute of Development Studies with the African Digital Rights Network. The report names Zambia and Senegal as places where mass public-space surveillance was deployed despite what the researchers describe as no terrorist threat or serious crime challenge, and says they found no compelling evidence across any of the 11 countries that smart surveillance reduced terrorism or serious crime. Governments present the systems as crime prevention, counter-terrorism, modernisation and urban management. IDS gives the 11-country total as at least USD 2 billion. Reporting of the study's country tables (Nairametrics, 23 March 2026) puts Zambia at USD 210 million for about 1,600 smart cameras -- the fourth-largest spend of the eleven, and roughly USD 131,000 per camera by simple division. The figures are the researchers' counts, drawn from public accounts they describe as incomplete, not an audit. Coordinates are Lusaka, not a specific site.
Africa's largest buyer of Chinese public-space surveillanceNigeria
Wrongful stop
IDS and the African Digital Rights Network, publishing 12 March 2026, put Nigeria's spending on facial recognition and automatic number plate recognition at over USD 470 million to date, the largest of the 11 African countries studied. A trade write-up of the same research (military.africa, April 2026) gives the 11-country total as USD 2.1 billion with Nigeria at nearly 23 per cent of it, against the IDS figure of at least USD 2 billion; the two are not reconciled and both are the researchers' counts rather than an audit. IDS says most of the technology is supplied and financed by Chinese companies, with Korea, Israel and the United States also supplying, and that no compelling evidence was found that these systems reduced terrorism or serious crime. Nigeria already appears on this map for the Hacking Team contract and the NIN biometric breaches; this record covers the camera programme. Coordinates are Abuja.
Second-largest buyer; Safe City images went missing in a death inquiryMauritius
Wrongful stop
IDS and the African Digital Rights Network place Mauritius second among the 11 African countries studied at USD 456 million on smart city surveillance, in research published 12 March 2026. The programme predates that figure: Huawei made an unsolicited bid in 2015, the Police Service signed two operating-lease contracts with Mauritius Telecom on 19 December 2017, and China Eximbank signed a preferential buyer's credit of USD 73,687,000 with Mauritius Telecom on 1 April 2018 at 2 per cent interest over a 20-year maturity with a 7-year grace period, according to AidData. Answering a parliamentary question on 11 August 2020, Prime Minister Pravind Kumar Jugnauth said 2,761 intelligent video surveillance cameras were installed at 1,429 sites and 140 traffic cameras at 68 sites, and that 101 cases requiring police enquiry had been detected through Safe City cameras. That detection figure is the government's own count and no audit of it is recorded here. Mauritius Times reported the system's total cost as Rs 19 billion with roughly Rs 350 million a year to operate; that comes from one newspaper and is not corroborated here, and it is not established how it relates to the USD 456 million figure. In the judicial inquiry into the death of Soopramanien Kistnen, Safe City images were reported missing and a Huawei representative was questioned. Coordinates are Port Louis.
Smart cameras deployed where political opposition is concentratedMozambique
Wrongful stop
The IDS and African Digital Rights Network report published 12 March 2026 says research in Mozambique found smart CCTV cameras deployed in locations where political opposition is concentrated. Mozambique is one of 11 countries in the study, which puts combined spending at at least USD 2 billion; Reporting of the study's country tables (Nairametrics, 23 March 2026) puts Mozambique at USD 147 million for about 450 smart cameras, roughly USD 327,000 a camera by simple division. These are the researchers' counts from incomplete public accounts, not an audit. The report says all 11 countries fail to provide adequate means for people to obtain remedy or redress for smart surveillance errors or abuse. The government's account of how camera sites were chosen is not established, and the report's siting claim has not been tested against procurement or deployment records. Ask the Mozambican police for the site list and the selection criteria. Coordinates are Maputo.
Third-largest buyer of smart city surveillanceKenya
Wrongful stop
IDS and the African Digital Rights Network put Kenya third among the 11 countries studied at USD 219 million on smart city surveillance technology, in research published 12 March 2026. The systems combine CCTV, facial recognition, number plate recognition and central command centres, and are mostly supplied and financed by Chinese firms. The researchers say they found no compelling evidence that such deployments reduced terrorism or serious crime, and that the countries studied lack laws defining who may conduct public-space surveillance, on what warrant and under whose oversight. The figure is the researchers' count, not an audit, and IDS notes the real total across the region is likely higher because surveillance spending is often secret. Kenya already appears on this map for Worldcoin, a suspected Pegasus deployment and the Huduma Namba ruling; this record covers the camera programme. Coordinates are Nairobi.
Mass surveillance rolled out with no serious crime challenge citedSenegal
Wrongful stop
IDS and the African Digital Rights Network, publishing 12 March 2026, name Senegal alongside Zambia as countries where mass public-space surveillance was deployed despite what the researchers describe as no terrorist threat or serious crime challenge. Senegal is one of the 11 countries in the study; Reporting of the study's country tables puts Senegal at USD 167 million for about 500 smart cameras -- roughly USD 334,000 a camera, the highest unit cost among the countries where both figures are published, against about USD 9,700 in Egypt and USD 47,000 in Nigeria. Neither extreme is explained in the material reviewed. The report records that governments present these systems as crime prevention, counter-terrorism and urban management, and that the researchers found no compelling evidence of a reduction in terrorism or serious crime. Senegal already appears on this map for the 2026 national digital-ID breach; this record covers public-space cameras. Coordinates are Dakar.
Five thousand cameras and no published costAlgeria
Wrongful stop
FIVE THOUSAND CAMERAS AND NO PUBLISHED COST. Algeria is one of 11 countries in Smart City Surveillance in Africa, published 12 March 2026 by the Institute of Development Studies with the African Digital Rights Network. Reporting of the study puts roughly 5,000 smart cameras in Algeria, and NO SPENDING FIGURE IS AVAILABLE -- the researchers say figures could not be obtained for two of the eleven countries and that public accounts for the other nine were incomplete, which is why their at least USD 2 billion total is explicitly a floor. WHAT THE COUNTRY AUTHOR SAYS HAPPENED. Yosr Jouini, who wrote the report's Algeria section, says systems introduced as smart city projects promising to tackle crime and manage traffic became in practice primarily tools of the security forces, and that the framing is entirely a security one, dismissing other concerns and providing too few mechanisms for citizens to protect their rights. She notes that street protests in 2019 and 2021 were a significant part of Algerian political life, and warns expanded surveillance could make people hesitant to protest in future. THAT IS A FORECAST, NOT A FINDING, and is recorded as one -- no measurement of a chilling effect in Algeria appears in the coverage reviewed here. A CAUTION FROM WITHIN THE SAME RESEARCH worth carrying: Bulelani Jili of Georgetown University argues that even introducing legal frameworks to regulate this technology can be dangerous, because a framework can legitimise a deployment rather than constrain it. Coordinates are Algiers, not a specific installation.
Second-largest camera count at a fraction of the leading spendEgypt
Wrongful stop
SIX THOUSAND CAMERAS FOR FIFTY-EIGHT MILLION DOLLARS -- roughly $9,700 a camera, the cheapest per-unit deployment for which both numbers are reported. Egypt is one of 11 countries in the IDS and African Digital Rights Network report of 12 March 2026, which records USD 58 million spent and 6,000 smart cameras installed. FOR SCALE AGAINST THE REST OF THE STUDY: Nigeria spent over USD 470 million for about 10,000 cameras, Mauritius USD 456 million, Kenya USD 219 million, and the eleven countries averaged USD 240 million each. Egypt therefore has the second-largest camera count in the study at a fraction of the leading spend, which the sources do not explain -- it may reflect different equipment, different financing, or incomplete public accounts, and the researchers warn the accounts for nine of the eleven countries were incomplete. WHAT THE STUDY CONCLUDES ACROSS ALL ELEVEN: the systems are presented as crime prevention, counter-terrorism, modernisation and urban management; the researchers found little evidence that expanding digital surveillance reduces overall crime; much of the equipment is supplied or financed by Chinese companies and banks, often through loans; and none of the countries provides adequate means to obtain remedy for surveillance errors or abuse. Egypt already appears on this map for the Sandvine deep packet inspection deployment; this record covers public-space cameras. Coordinates are Cairo. THE SPREAD IS WIDER THAN EGYPT ALONE: by the same country tables as reported by Nairametrics, Senegal (USD 167 million, about 500 cameras) and Mozambique (USD 147 million, about 450) run at roughly USD 330,000 a camera -- so Egypt is one end of a thirty-fold range, not a lone anomaly. No source read explains either end; the report PDF could not be retrieved. WHAT WOULD SETTLE IT: the Egypt chapter of the report, or a question to its editors at IDS and the African Digital Rights Network. A POSSIBLE EXPLANATION, inferred rather than stated by the report: in February 2019 Honeywell signed to build a 6,000-camera IP system and command centre for Egypt's New Administrative Capital, reported at about USD 31 million (Global Construction Review). If the IDS figures come from that project, Egypt's low cost per camera reflects one US-built network in one new city, with video analytics rather than face recognition. The IDS report's Egypt chapter has still not been read.
The smallest deployment in the study, and still ungovernedRwanda
Wrongful stop
THE SMALLEST DEPLOYMENT IN THE STUDY, AND STILL UNGOVERNED. Rwanda is one of 11 countries in the IDS and African Digital Rights Network report published 12 March 2026, with approximately 849 smart cameras -- the lowest camera count reported among the eleven -- and NO SPENDING FIGURE AVAILABLE. Rwanda is one of the countries for which the researchers could not obtain figures, which is part of why they describe their USD 2 billion total as a floor rather than an estimate. WHY A SMALL DEPLOYMENT STILL BELONGS ON THIS MAP: the report's central finding is not about volume. It is that across all eleven countries these systems were rolled out WITHOUT the legal frameworks needed to define who may conduct public-space surveillance, on what authority, and under whose oversight, and without adequate means for a person to obtain remedy for an error or an abuse. A network of 849 AI-enabled cameras feeding a central command centre with no statutory basis is a governance problem at any size. The researchers add that the systems are mostly supplied and financed by Chinese firms and banks. NOT ESTABLISHED: no Rwanda-specific misuse finding appears in the coverage reviewed here, and this record should not be read as one. Coordinates are Kigali.
National digital-ID system breached, biometric data stolenSenegal
Data misuse
In January 2026 a threat actor calling itself the Green Blood Group claimed to have breached Senegal's national digital-ID system and exfiltrated about 139 terabytes of data, including biometric records -- a stark illustration of the privacy risk when governments centralize biometric identity.
Cybercrime Bill would allow real-time traffic capture and content interceptionNamibia
Wrongful stop
A draft Namibia Cybercrime Bill dated 30 January 2026 gives an investigatory authority powers of access, search and seizure of stored data under a court warrant at clause 39, real-time collection of traffic data by technical means on the order of a Judge in Chambers at clause 40, interception of content data at clause 41, and expedited preservation of stored computer data at clause 47. Clause 3 provides that the Act prevails over any other written law on cybercrime and cybersecurity matters. The Council of Europe's Octopus country page assesses a draft Namibian bill as supplying most procedural powers the Budapest Convention requires while not setting out their scope, with some powers appearing to reach only offences under the bill rather than electronic evidence generally, and with no powers specific to traffic data. That page is undated and refers to a drafting mission held in February 2020, so whether its assessment describes this 30 January 2026 text or an earlier draft is not established. The bill is not enacted and no commencement date is established. Coordinates are Windhoek.
Face recognition in 1,600 Parana schools, with no national rulesBrazil
Wrongful stop
1,600 SCHOOLS IN PARANA ALONE. InternetLab's November 2025 study found facial recognition running in public schools in at least seven Brazilian states -- Alagoas, Amazonas, Goias, Parana, Rio de Janeiro, Sao Paulo and Tocantins -- and earlier use in six more, mostly to take attendance. Parana has installed it in 1,600 schools. There are no national rules setting minimum safeguards for scanning children's faces, and the company supplying most of the systems did not answer the researchers. No ruling by Brazil's data protection authority on school use is recorded here. Ask each state education department for the contract, the retention period and the legal basis under the LGPD.
Police tap a private plate network half a million times a yearNew Zealand
Data misuse
New Zealand police query Auror, an Auckland retail-crime ANPR platform, hundreds of times a day -- around half a million times a year -- with thousands of officers able to access it without stating a reason. Defence lawyers challenging it in the Court of Appeal call it 'surveillance capitalism.'
Police in four states run Palantir 'dragnet' data-miningGermany
Data misuse
German state police have adopted Palantir's Gotham data-mining platform -- Hesse's HessenData since 2017, North Rhine-Westphalia's DAR, Bavaria's VeRA (live from late 2024) and Baden-Wurttemberg from 2025 -- to fuse names, addresses, phone and social-media records into instant profiles, including of people never suspected of a crime. In a 2023 landmark ruling the Federal Constitutional Court struck down the Hesse and Hamburg data-mining laws as too broad; civil-liberties groups GFF and the Chaos Computer Club have since filed constitutional complaints against Bavaria and North Rhine-Westphalia, calling it a 'Palantir dragnet.'
Biometric national ID mandated for all citizensMexico
Data misuse
In July 2025 a presidential decree made the biometric CURP -- face, fingerprints, and iris captured in a QR code -- the mandatory national ID for nearly all public and private services. A new Unified Identity Platform links it to other state databases for real-time cross-checks, and from 2026 every mobile line must be tied to it. The decree lets prosecutors, the National Intelligence Center, the National Guard, and the security ministry consult the database -- including bank and telecom data -- without notifying the person. Framed as a response to Mexico's missing-persons crisis, it drew warnings of a mass-surveillance ecosystem from digital-rights groups R3D and Article 19, and courts in several states issued injunctions pausing the rollout.
Paragon Graphite used against journalists in ItalyItaly
Wrongful stop
Italy's intelligence services used Paragon's Graphite spyware against journalists and migrant-rescue activists, confirmed by Citizen Lab in 2025, including Fanpage journalist Ciro Pellegrino and Mediterranea Saving Humans founders.
Facial recognition turned on Pride marchers and minor offendersHungary
Wrongful stop
In March 2025 Hungary's Parliament rushed through three amendments in 24 hours -- to the Assembly Act, the Infraction Act and the Facial Recognition Technology Act -- banning Pride events and authorising police to use live facial recognition to identify participants and anyone committing even minor infractions such as jaywalking. Effective April 15, 2025, it dramatically widened biometric surveillance of peaceful assembly. Rights groups (HCLU, EDRi, ECNL, Liberties for Europe) argue it violates the EU AI Act, which already bars real-time remote biometric identification in public, and the EU Charter; the European Commission has been slow to act. Budapest Pride went ahead in June 2025 as the country's largest anti-government demonstration in years.
Serbia hacks activists' phones in police custodySerbia
Wrongful stop
An Amnesty International report found that Serbian police and the BIA intelligence agency used Cellebrite forensic tools to secretly unlock the phones of journalists and activists during detention, then installed a homegrown Android spyware called NoviSpy that can copy data and switch on the camera and microphone. Investigative journalist Slavisa Milanov and environmental campaigners were among those hacked after being held for routine-seeming interviews.
Automated welfare state flags 'atypical' lives for fraud probesDenmark
Wrongful stop
A November 2024 Amnesty International investigation, 'Coded Injustice,' found Denmark's welfare agency Udbetaling Danmark and its administrator ATP run some 60 fraud-detection algorithms -- including a 'Really Single' model that guesses a person's relationship status and the 'Gladsaxe Model' -- that mine vast personal data and flag 'unusual' or 'atypical' living and family patterns, disproportionately targeting people with disabilities, low incomes, migrants and foreigners. Denmark's Parliamentary Ombudsman opened an inquiry; the agency denies it amounts to social scoring.
Legal challenge to the benefits agency's fraud-scoring algorithmFrance
Data misuse
In October 2024 a coalition of 15 organisations, including La Quadrature du Net and Amnesty International, filed a complaint before France's top administrative court against the risk-scoring algorithm used by the national family-benefits fund CNAF. The system assigns welfare recipients a fraud-suspicion score from data on their circumstances; analysis showed it effectively rated the poorest, single parents, disabled people and those born outside the EU as higher risk, singling them out for intrusive checks.
Wrongful detentions from face-match errorsBrazil
Wrongful stop
Brazil's expanding police facial recognition has repeatedly detained innocent people, overwhelmingly Black. One man was tracked across fifteen train stations in Bahia before being held on a false match, another was detained in front of a stadium crowd, and in 2025 an 80-year-old volunteer was taken to a police station after cameras mistook him for a wanted man. A study found about 90 percent of those arrested through the technology in several states were Black Brazilians.
Face recognition installed to catch unveiled studentsIran
Wrongful stop
Iranian authorities installed facial recognition at Amirkabir University of Technology in Tehran to identify and penalize women students who removed their headscarves, part of a wider rollout of cameras and drones to enforce hijab laws.
AI cameras and biometrics turn refugee camps into 'high-tech prisons'Greece
Wrongful stop
At Greece's EU-funded Closed Controlled Access Centres for asylum seekers, two systems -- Centaur (CCTV, drones and AI behavioural analytics that flag 'threats' and log incidents, monitored from Athens) and Hyperion (biometric fingerprint entry and exit) -- put residents under constant surveillance behind curfews, with cameras even in sleeping containers. Most residents interviewed said they were never told they were being filmed. In April 2024 the Greek Data Protection Authority fined the Migration Ministry 175,000 euros for GDPR breaches over the rollout.
Clearview expands face search across Latin AmericaEcuador
Wrongful stop
The American firm Clearview AI is expanding across Latin America, giving law enforcement in countries including Argentina, Brazil, Colombia, and Ecuador access to its database of billions of scraped faces, even as it faces fines and bans elsewhere. Rights advocates warn it puts much of the region in a perpetual police lineup, risking wrongful arrests and profiling.
Wrongly flagged by live facial recognitionUnited Kingdom
Wrongful stop
London's Metropolitan Police scan millions of faces with live facial recognition. Youth worker Shaun Thompson was wrongly flagged in 2024, then stopped, detained, fingerprinted, and threatened with arrest over a false match. At one 2025 sporting event South Wales Police logged 2,470 alerts, 92 percent of them false, and the equality watchdog found the Met system disproportionately flags Black men.
Biometric ID breaches exposed citizens' dataNigeria
Data misuse
Nigeria's biometric National Identification Number system, tied to SIM and bank registration, has suffered data breaches exposing citizens' personal records, alongside exclusion of those unable to enroll.
Woman wrongly detained as a fugitiveBrazil
Data misuse
In Rio de Janeiro, a woman was wrongly detained after a facial-recognition database flagged her as a fugitive, even though she was already serving her sentence under an open regime.
Clearview AI fined over scraped databaseNetherlands
Data misuse
The Dutch data-protection authority fined Clearview AI for building an illegal facial-recognition database from scraped photos of people in the Netherlands, one of several EU regulators to penalize the company.
Predator spyware customerPhilippines
Wrongful stop
A Predator spyware customer assessed as highly likely linked to the Philippines was identified by Recorded Future, the first time the tool's use was tied to the country.
Huawei Safe City cameras expand in BelgradeSerbia
Data misuse
Serbia is expanding Huawei's Safe City facial-recognition camera network in Belgrade, with leaked 2024 contracts showing capacity for up to 3,500 additional cameras despite public protests.
Interior Ministry's secret use of Briefcam video analyticsFrance
Wrongful stop
In late 2023 investigative outlet Disclose revealed that France's national police and gendarmerie had for years quietly used Briefcam, an Israeli video-analytics system capable of facial recognition, to search and filter surveillance footage without public debate or, critics argued, a clear legal basis. A 2024 CNIL investigation concluded the Interior Ministry had not used the software for real-time facial recognition in public space, but the episode exposed how FR-capable tools were deployed in secrecy.
Sao Paulo builds a 20,000-camera face networkBrazil
Wrongful stop
Sao Paulo's Smart Sampa program wires up to 20,000 cameras with facial recognition across a city of 12 million, watching streets, schools, and public spaces. Rights groups warn it could drive mass incarceration of Black residents, citing a 2019 study that found about 90 percent of those arrested through facial recognition in Brazil were Black. The Public Defender's Office sued to suspend it.
European court: metro face-recognition arrest violated rightsRussia
Wrongful stop
In July 2023 the European Court of Human Rights ruled that Russia violated Nikolay Glukhin's rights by using Moscow metro facial recognition to identify and arrest him over a peaceful solo protest. Glukhin had ridden the underground in August 2019 holding a life-sized cutout of jailed activist Konstantin Kotov; days later the system flagged him and police detained him. The court found the deployment incompatible with the values of a democratic society governed by the rule of law -- one of the first international rulings against live facial recognition.
Red Wolf tracks Palestinians at checkpointsIsrael
Data misuse
In the occupied West Bank city of Hebron, an Israeli military facial-recognition system called Red Wolf scans Palestinians at checkpoints and enrolls their faces into surveillance databases without consent, deciding who may pass. Amnesty International's 2023 Automated Apartheid report documented how it automates movement restrictions and tracks residents, and how soldiers were rewarded for registering as many Palestinians as possible.
Cameras track Palestinians' cars by plateIsrael
Data misuse
Israeli surveillance cameras in occupied East Jerusalem capture license plates on fixed and moving vehicles, feeding a database of Palestinians that records plates, permits, and addresses, restricting Palestinians' movement within their own neighborhoods. Researchers identified Hikvision and TKH cameras in the network.
Soldiers scan Palestinians' faces at checkpointsPalestine
Data misuse
Israeli soldiers in Hebron use face-scanning cameras, known as Red Wolf, to identify Palestinians at checkpoints without checking IDs, feeding a database used to control their movement. Amnesty calls it automated apartheid.
An app flags cars when a woman inside is unveiledIran
Data misuse
Iran's police run a phone app, Nazer, that lets officers and vetted civilians flag a vehicle's license plate when a woman inside is unveiled. The system sends the owner an automatic warning and then impounds the car. Amnesty documents hundreds of thousands of vehicles confiscated since 2023, and the app was later extended to taxis, ambulances, and buses.
Football club face scan wrongly fines a fanNetherlands
Wrongful stop
Dutch football clubs used retrospective facial recognition to scan crowds for banned supporters, and in one case wrongly issued a fine to a fan who had not even attended the match in question, a failure that drew warnings about expanding after-the-fact face surveillance in Europe.
Supermarkets built secret facial-recognition blacklists of shoppersUnited Kingdom
Wrongful stop
British retailers including Southern Co-op, Home Bargains and Mike Ashley's Frasers Group deployed Facewatch live facial recognition to scan shoppers entering stores and match them against private watchlists of suspected offenders. After a 2022 Big Brother Watch complaint, the ICO concluded in March 2023 that Facewatch's processing had breached data-protection law on multiple principles, forcing an overhaul; campaigners say people were blacklisted over trivial accusations and, in cases like a teenager wrongly flagged at Home Bargains in 2024, misidentified and publicly accused.
Rotterdam's 'suspicion machine' scored the poor for fraud raidsNetherlands
Data misuse
From 2017 to 2021 Rotterdam used an Accenture-built machine-learning model to score its roughly 30,000 welfare recipients for fraud risk, using about 315 inputs including age, gender, language skills, neighbourhood, marital status and subjective caseworker notes. A 2023 Lighthouse Reports and WIRED investigation ('Suspicion Machines') that reverse-engineered the model found it systematically ranked single mothers, non-Dutch speakers and people of certain ethnicities as higher risk, subjecting them to intrusive fraud investigations even when they had done nothing wrong.
Blocked national IDs cut people off from servicesSouth Africa
Data misuse
In South Africa, the Home Affairs department's practice of blocking national IDs left many people unable to access banking, grants, and services, prompting legal challenges over the harms of digital identity systems.
Journalists and rights workers hackedJordan
Wrongful stop
Pegasus was used against at least 16 Jordanian journalists and activists, including two Human Rights Watch staff and a Palestinian-American reporter hacked three times, many of whom had covered a teachers' strike the government crushed.
Predator aimed at EU lawmakersVietnam
Wrongful stop
Vietnam deployed Predator spyware against targets including members of the European Parliament and used commercial spyware against bloggers, part of a broad surveillance campaign accompanying its jailing of online critics.
Predator spyware infrastructureAngola
Wrongful stop
Angola was identified in the Predator Files as a likely customer of Intellexa's Predator spyware, with Amnesty International finding technical infrastructure tied to the tool active in the country.
Predator spyware infrastructureMongolia
Wrongful stop
Mongolia appeared among the governments linked to Intellexa's Predator spyware in the Predator Files, with Amnesty International documenting infrastructure associated with the tool.
Predator spyware shipmentsBotswana
Wrongful stop
Import records tied Botswana's Directorate of Intelligence and Security to shipments of Intellexa Predator spyware in 2023, the first identification of the tool's use in the country.
Predator spyware infrastructureSudan
Wrongful stop
Sudan was among the countries where Amnesty International found technical infrastructure linked to Intellexa's Predator spyware in the Predator Files investigation.
Mexico's army spied on journalists with PegasusMexico
Wrongful stop
Mexico is the most heavily targeted country in the Pegasus files. First exposed in 2017, the NSO spyware was used against journalists like Carmen Aristegui, whose teenage son was also hit, along with activists and lawyers for victims of disappearances. The Ejercito Espia investigation later showed the army kept using Pegasus against reporters and a human rights defender into 2021, even after the president pledged the practice had stopped.
Facial recognition used to hunt draft evadersRussia
Wrongful stop
After Russia's September 2022 mobilisation for its war on Ukraine, Moscow authorities turned the city's facial-recognition camera network on men avoiding the draft. Human Rights Watch documented at least seven men flagged as 'draft dodgers' and detained via surveillance cameras, taken to police stations and enlistment offices, with some ordered to the front. Enlistment offices even flag conscripts who legally challenge their call-up so they can be auto-detected on camera, and rights lawyers advise appellants to avoid the metro entirely.
Surveillance enforcing mandatory hijabIran
Wrongful stop
Iran uses facial recognition, road cameras, drones, and a citizen-reporting app to enforce mandatory hijab rules on women. A 2025 UN fact-finding mission documented facial recognition installed at a Tehran university gate to catch uncovered students, and metro screens in Mashhad displaying passengers' faces, age, and gender to frighten women out of defiance.
Spanish football clubs scan fans' faces at the turnstileSpain
Wrongful stop
Spanish football clubs have rolled out facial recognition on supporters: Valencia CF deployed a FacePhi system to control stadium access and Atletico Madrid announced face-scanning and cashless entry from the 2022-23 season, while other clubs use fingerprint scanning at turnstiles. Fans and privacy advocates warned that mandatory biometric entry normalises tracking of ordinary spectators.
Predator spyware targets Greece's journalists and politiciansGreece
Wrongful stop
In the scandal known as Predatorgate, the Predator spyware sold by the Israeli-founded firm Intellexa was used to target more than ninety journalists, the opposition leader Nikos Androulakis, ministers, and senior military officers between 2020 and 2022, alongside wiretaps by the national intelligence service. The case forced top resignations, and in 2026 an Athens court handed eight-year sentences to four people linked to Intellexa, a rare criminal reckoning for the spyware trade.
Face scans track the Uyghur populationChina
Wrongful stop
In Xinjiang, authorities use facial recognition to monitor the mostly Muslim Uyghur population, with face scans required to enter shops, hotels, and stations and tens of thousands of cameras in Urumqi alone. Leaked police files showed Hikvision systems used to screen all 23 million residents and flag people with overseas ties for arrest.
Facial recognition ran searches on thousands not wantedArgentina
Wrongful stop
Buenos Aires's facial-recognition system was used to run unauthorized searches on more than 15,000 people not on any fugitive list, including journalists, politicians, and activists, and wrongly jailed a factory worker for nearly a week after a database error.
CatalanGate spyware hits Catalan independence figuresSpain
Wrongful stop
Citizen Lab's CatalanGate report found at least sixty-five people tied to the Catalan independence movement, including every Catalan president since 2010, members of the European Parliament, lawyers, and activists, targeted or infected with Pegasus or Candiru spyware between 2017 and 2020. The lab pointed to strong circumstantial evidence of a Spanish state nexus; the government later acknowledged court-authorized surveillance of about two dozen people and denied a wider operation.
Metro face recognition used to detain protestersRussia
Wrongful stop
Moscow's metro facial recognition, part of a Safe City camera network, has been used to detain and question thousands of people on their way to and from anti-war protests, sometimes preventively. The European Court of Human Rights later ruled the practice violated human rights.
Clearview used to identify dead Russian soldiersUkraine
Wrongful stop
In March 2022 Ukraine's defence and digital-transformation ministries began using Clearview AI facial recognition -- provided free, drawing on billions of scraped images including from the Russian network VKontakte -- to identify the bodies of dead Russian soldiers and message their relatives, and to identify operatives. Critics warned of the wartime normalisation of a controversial scraping tool and the risk of deadly misidentification at checkpoints.
Clearview AI fined 20 million eurosItaly
Data misuse
Italy's data-protection authority fined Clearview AI 20 million euros for processing biometric and location data of people in Italy without a legal basis, banned further collection, and ordered deletion of existing records.
35 journalists infected with PegasusEl Salvador
Wrongful stop
Researchers confirmed Pegasus infections on 35 journalists and civil society members in El Salvador, with reporters at the outlet El Faro among the most heavily targeted as they investigated government corruption.
Clearview AI fined for face scrapingFrance
Data misuse
France's data-protection regulator fined Clearview AI roughly 20 million euros and ordered it to stop collecting and to delete residents' data, after finding the company unlawfully scraped billions of faces into a recognition database sold to police.
Clearview AI fined for face scrapingGreece
Data misuse
Greece's data-protection authority fined Clearview AI about 20 million euros for unlawfully scraping and processing residents' facial images, part of roughly 100 million euros in EU fines the company has largely ignored.
ICO fines Clearview, orders deletionUnited Kingdom
Data misuse
The UK Information Commissioner's Office fined Clearview AI 7.5 million pounds in 2022 and ordered it to delete UK residents' data; after a tribunal initially overturned the action on jurisdiction, an appeals tribunal restored the regulator's authority in 2025.
Pegasus turned on Poland's oppositionPoland
Wrongful stop
Under the Law and Justice government, Polish services used NSO's Pegasus against the opposition. Senator Krzysztof Brejza was hacked dozens of times in 2019 while running the opposition's election campaign, and his stolen messages were doctored by state television for a smear campaign; a lawyer and a prosecutor critical of the government were also targeted. A Senate commission and the European Parliament found the spyware was deployed to entrench those in power, and prosecutors later seized the systems.
Court declared the biometric ID rollout illegalKenya
Data misuse
Kenya collected the fingerprints and facial images of tens of millions of people for its Huduma Namba (NIIMS) biometric ID before passing a data-protection law. The High Court declared the rollout illegal for skipping a privacy-risk assessment, and the successor Maisha Namba system faces similar criticism.
Facial recognition paused in Scottish school canteensUnited Kingdom
Wrongful stop
In October 2021 nine schools in North Ayrshire, Scotland switched on facial recognition to take payment in their canteens, scanning pupils' faces instead of fingerprints or cards. After public and regulatory backlash the ICO intervened, urging the schools to use a less intrusive method, and the rollout was paused -- an early flashpoint over normalising biometric identification of children for everyday transactions.
Morocco named a top Pegasus user targeting journalists and leadersMorocco
Wrongful stop
The 2021 Pegasus Project named Morocco as one of the heaviest users of NSO's spyware, with around ten thousand numbers selected. They included Moroccan journalists such as Omar Radi, who was later jailed, as well as foreign figures, among them French President Emmanuel Macron and several of his ministers. Morocco denied buying or using Pegasus and sued the journalists and Amnesty International for defamation.
Police faked reports to track people with plate camerasNew Zealand
Data misuse
Just a month after the Privacy Commissioner warned police to do better on plate cameras, a detective pretended a car was stolen so they could track it, and officers filed a false report to use ANPR to track women linked to a Northland lockdown breach.
Facial recognition used to hunt dissidentsRussia
Wrongful stop
Moscow's facial-recognition camera network, one of the world's largest, has been turned from catching criminals to hunting dissidents. Police have used it to identify and detain peaceful protesters, journalists covering them, and mourners at Alexei Navalny's 2024 funeral, tracing people right up to their door. In 2023 the European Court of Human Rights ruled its use against a protester unlawful.
Junta expands Chinese safe-city camerasMyanmar
Wrongful stop
Myanmar's military junta expanded Chinese-supplied safe-city camera networks with facial recognition across cities, raising fears of tracking dissidents after the 2021 coup.
Face recognition built to sort people by ethnicityChina
Wrongful stop
Chinese authorities, working with surveillance firms including Hikvision, Dahua, and Uniview, drew up facial-recognition standards that sort people by traits such as ethnicity and skin color, which researchers warned opened wide scope to target minorities like the Uyghurs at scale.
Allot DPI throttled Telegram before a blackoutKazakhstan
Data misuse
Allot's deep-packet-inspection technology was used in Kazakhstan to throttle Telegram and other platforms ahead of a January 2021 nationwide internet blackout.
Mandatory biometric ID excludes the elderlyUganda
Data misuse
Uganda's mandatory Ndaga Muntu biometric national ID has been challenged by civil-society groups for excluding elderly people from welfare benefits and blocking women's access to healthcare, amid wider use of biometrics to monitor dissent.
Police ran face recognition on CCTV and web imagesSouth Korea
Wrongful stop
South Korean police tracked suspects with Videmo 360 facial recognition software, analyzing images pulled from CCTV and the internet, in a case that raised concerns over the legality of the surveillance.
Retailer fined 10.4M euros for spying on staff by CCTVGermany
Wrongful stop
In a decision made public in January 2021, the Lower Saxony data-protection authority fined online electronics retailer notebooksbilliger.de about 10.4 million euros for unlawfully video-monitoring its employees for at least two years. The regulator found blanket CCTV over workspaces and public areas, justified only by a general suspicion of theft, had no legal basis under the GDPR -- one of Germany's largest fines for workplace surveillance.
Pegasus used against journalistsAzerbaijan
Wrongful stop
Azerbaijan was identified as a Pegasus operator with around 48 journalists selected for targeting, including OCCRP investigative reporter Khadija Ismayilova, whose phone was infected for nearly three years, and Meydan TV freelancer Sevinc Vaqifqizi.
State spyware on journalists and criticsHungary
Wrongful stop
Hungary's Interior Ministry bought Pegasus for about 6 million euros and used it against investigative journalists such as Szabolcs Panyi of Direkt36, along with opposition figures, lawyers, and a media-owning businessman, an EU member state turning spyware on its own critics.
Pegasus targeting of dissidents abroadRwanda
Wrongful stop
Rwanda was named among Pegasus operators, with targets including the daughter and nephew of Hotel Rwanda figure Paul Rusesabagina; the leaked list also flagged South Africa's president as a possible Rwandan target.
Officials and journalists on Pegasus listLebanon
Wrongful stop
Phone numbers of senior Lebanese figures appeared on the Pegasus list, including the president, a former prime minister, ministers, security chiefs, and numerous journalists and ambassadors, according to the Pegasus Project.
Zero-click hacking of activistsBahrain
Wrongful stop
Bahraini human-rights activists were hacked with Pegasus in zero-click attacks that defeated new Apple protections, part of the Gulf state's documented use of commercial spyware against dissidents.
Pegasus on pro-democracy protestersThailand
Wrongful stop
Forensic analysis confirmed Pegasus on the phones of at least 30 Thai pro-democracy protesters, academics, and rights defenders during the 2020 to 2021 mass demonstrations, the first confirmed use of the spyware in the country.
Civil society activists targetedKazakhstan
Wrongful stop
Four Kazakh civil society activists were confirmed targets of Pegasus, part of the leaked list of tens of thousands of phone numbers selected by NSO Group government clients.
Pegasus against critics and clergyTogo
Wrongful stop
Togo appeared among NSO Group's Pegasus clients in the Pegasus Project, which documented the spyware being used against journalists, opposition figures, and members of the clergy critical of the government.
Politician doubly infected with spywareEgypt
Wrongful stop
Egypt is a documented user of Predator spyware; in one case the phone of an exiled Egyptian politician was found simultaneously infected with both Predator and Pegasus, run by two different government clients.
Predator spyware customerArmenia
Wrongful stop
Armenia was identified by Citizen Lab as a Predator spyware customer, part of a cluster of governments deploying the Cytrox tool against phones alongside the better-known Pegasus.
Predator spyware customerIndonesia
Wrongful stop
Indonesia was documented as a Predator spyware customer, one of several governments Citizen Lab linked to the Cytrox surveillance tool used against people of interest.
Predator spyware customerMadagascar
Wrongful stop
Madagascar was named among the government customers of Predator spyware identified by Citizen Lab, part of a growing roster of states buying commercial surveillance tools.
Predator spyware customerOman
Wrongful stop
Oman was documented as a Predator spyware customer by Citizen Lab, adding a Gulf state to the list of governments using the Cytrox tool against targets of interest.
Privacy Act breach, deletion orderedAustralia
Data misuse
Australia's information commissioner found in 2021 that Clearview AI breached the Privacy Act by scraping residents' faces without consent and ordered it to stop and delete the data; a tribunal upheld the ruling in 2023.
Mass scraping ruled illegalCanada
Data misuse
Canada's privacy commissioners ruled in 2021 that Clearview AI's mass scraping of facial images amounted to illegal surveillance and called on the company to stop and to delete Canadians' data.
Care home fined for filming a disabled resident's bedroomSweden
Wrongful stop
In November 2020 the Swedish data-protection authority fined Gnosjo Municipality 200,000 SEK for unlawful video surveillance in an LSS home for people with functional impairments, after a resident was filmed in their own bedroom. The regulator found no legal basis and no impact assessment, calling it a severe and unjustifiable intrusion into the most private sphere of the home.
Statewide plate-reader fleet, pushed to police bordersAustralia
Data misuse
Every Australian state runs plate readers. New South Wales' mobile MANPR fleet scans every passing vehicle statewide, storing hundreds of thousands of records a day, and was pushed to profile drivers at closed state borders during COVID lockdowns. The Australian Privacy Foundation calls ANPR a mass-surveillance technique that breaches freedom of movement.
Court rules police face recognition unlawfulUnited Kingdom
Wrongful stop
A UK Court of Appeal ruling in Bridges v South Wales Police found the force's live facial recognition unlawful. Its AFR Locate system scanned up to 50 faces per second against watchlists that could include anyone, with images drawn even from social media, breaching privacy, data-protection, and equality law.
Black man jailed 26 days on a face-match errorBrazil
Wrongful stop
In Bahia, a Black man was wrongly detained for 26 days over a robbery committed by someone else a decade earlier, after a facial-recognition system misidentified him. It is one of several mistaken-identity cases tied to face recognition in Brazil since 2020.
Como's public-square facial recognition ruled unlawfulItaly
Wrongful stop
In 2019 the northern Italian city of Como quietly bought, installed and tested a live facial-recognition system in public squares near its train station, among the first Italian municipalities to do so. After a journalistic investigation, the Italian data-protection authority (Garante) found the deployment had no legal basis under GDPR and ordered it stopped in 2020 -- a case that helped drive Italy's later national moratorium on public-space facial recognition.
Facial-recognition app enforced Covid home quarantinePoland
Data misuse
In March 2020 Poland made its 'Home Quarantine' app mandatory for people ordered to isolate, requiring a geolocated facial-recognition selfie within 20 minutes of a random prompt. Failing to verify by face on demand triggered a police visit and possible fine, turning biometric identity checks into a routine tool of movement control and setting an early template other governments studied.
Facial recognition used to identify protestersIndia
Wrongful stop
Delhi police used facial recognition to identify and arrest people from the 2020 anti-CAA protests and the communal riots that followed, later saying scores of the riot arrests were traced by the technology, and turned it on Sikh farmers during the 2021 farmers' protests. Rights groups documented its disproportionate use against Muslims and other minorities and a chilling effect on the right to protest.
Face recognition aimed hardest at MuslimsIndia
Wrongful stop
Delhi police rolled out facial recognition that researchers found would inevitably fall hardest on the city's Muslim community, and used it to identify protesters, with much of the deployment kept under wraps.
Greek police buy live face and fingerprint scan devicesGreece
Wrongful stop
In 2019 the Hellenic Police signed a roughly 4 million euro contract with Intracom Telecom for 'smart policing' devices -- handheld tools that let officers run live facial recognition and automated fingerprint identification on people during street stops. Part-funded by the EU, the deal was signed with no data-protection impact assessment and without consulting the Greek DPA, prompting complaints from digital-rights group Homo Digitalis.
Prague police roll out facial-recognition camerasCzechia
Wrongful stop
Around 2019-2020 Prague police sought approval to switch on automatic facial-recognition cameras at six locations in the Czech capital and bought recognition software from the firm Cogniware, extending biometric identification into public space with little public debate or oversight.
Dutch police hold a 1.4 million-face recognition databaseNetherlands
Wrongful stop
By 2020 the Dutch national police maintained a facial-recognition database holding images of around 1.4 million people, and municipalities were rolling out face recognition in public space under 'pilot' and 'smart city living lab' labels that sidestepped regulatory scrutiny and frustrated public debate.
EU project scraped social media to build a face databaseEuropean Union
Data misuse
SPIRIT was an EU-funded project to scrape social-media images and build a facial-recognition database for police use, with partners including the Hellenic Police, two UK forces (West Midlands and Thames Valley), the Serbian Interior Ministry and Poland's police academy. Critics likened its face-extraction and matching tools to Clearview AI; trials were planned for 2020-2021 with little transparency.
Facial recognition to identify protestersBelarus
Wrongful stop
Belarus deployed facial recognition to identify and arrest participants in the 2020 post-election protests.
Sandvine DPI used to shut down the internetBelarus
Data misuse
During the disputed 2020 election, Belarus used Sandvine deep-packet-inspection technology to block social media, messaging apps, and news sites amid a violent crackdown; Sandvine later found custom code had been inserted and canceled the contract.
Belgrade wired with thousands of Huawei face camerasSerbia
Data misuse
Belgrade has been fitted with thousands of Huawei 'Safe City' cameras carrying facial-recognition and plate-reading software, rolled out from 2019 with little transparency. The digital-rights group SHARE Foundation's 'Thousands of Cameras' campaign and Amnesty warned the system was unlawful and used to identify protesters, and biometric provisions were later dropped from a draft police law after public outcry.
Austrian police quietly ran facial recognition on CCTVAustria
Wrongful stop
Austria's federal police began using facial-recognition software to search surveillance footage at the end of 2019, comparing camera images against stored photos of suspects for after-the-fact identification. Rolled out with little public debate and limited to retrospective (not live) use, it made Austria one of a growing group of EU states quietly normalising biometric identification in criminal investigations.
France's Alicem facial-recognition national IDFrance
Data misuse
In 2019 France moved to become the first European country to build a nationwide facial-recognition digital identity, Alicem, letting citizens verify themselves to government services by matching a selfie against their biometric passport. Digital-rights group La Quadrature du Net challenged it in court over the lack of any non-biometric alternative, arguing that effectively mandatory face-matching for state services breached the GDPR.
Huawei facial recognition turned on the oppositionUganda
Wrongful stop
Uganda built a Huawei Safe City network of facial-recognition cameras across Kampala. A 2019 Wall Street Journal investigation found Huawei technicians helped state agents crack the encrypted communications of opposition leader Bobi Wine, leading to his arrest, and police later confirmed using the cameras to track people detained during anti-government protests. Opposition figures call it a tool to hunt and persecute critics.
Protesters tear down face-scanning smart lamppostsHong Kong
Wrongful stop
During the 2019 pro-democracy protests, Hong Kongers wore masks and carried umbrellas and tore down 'smart lampposts' in Kowloon, fearing they held facial recognition that could identify demonstrators and expose them to arrest. Police had access to AI able to match faces from video to databases, and the fear of being identified kept some people away from the streets.
Huawei face cameras blanket KampalaUganda
Data misuse
Uganda installed a 126 million dollar Huawei facial-recognition camera system across the capital, Kampala, which the president framed as a tool to fight street crime. Opposition figures said the real aim was to deter and identify protesters against an increasingly unpopular government. MEASURED AGAIN SEVEN YEARS LATER: the IDS and African Digital Rights Network study of 12 March 2026 counts approximately 5,000 smart cameras in Uganda, one of 11 African countries surveyed. Set against the USD 126 million reported for the original Huawei installation, Uganda is one of the larger deployments in that study by camera count while Nigeria leads on spend at over USD 470 million for about 10,000 cameras. The 2026 researchers found little evidence across all eleven countries that expanding digital surveillance reduces overall crime -- which speaks directly to the street-crime justification given here in 2019 -- and found that none of the eleven provides adequate means to obtain remedy for surveillance errors or abuse. The 2026 study's country figures, as reported by Nairametrics and military.africa, put Uganda's spend at USD 189 million for about 5,000 smart cameras -- roughly USD 37,800 a camera, and above the USD 126 million reported for the original 2019 Huawei installation.
EU's first facial-recognition fine over a school attendance trialSweden
Wrongful stop
In August 2019 the Swedish Data Protection Authority issued the EU's first GDPR facial-recognition fine -- 200,000 SEK (about 20,000 euros) against the Skelleftea municipal school board after Anderstorp High School piloted FR cameras to log the attendance of 22 students over three weeks. The regulator found consent could not be a valid legal basis given the power imbalance between school and pupils, that attendance could be tracked less intrusively, and that the school processed sensitive biometric data without an adequate impact assessment.
EU pilots a biometric 'lie detector' on travellersEuropean Union
Data misuse
iBorderCtrl was an EU-funded research project that piloted an automated 'lie detector' at the Hungarian, Greek and Latvian borders, using biometric and facial analysis to score whether travellers -- including asylum seekers -- were being deceptive. Widely criticised as pseudoscientific and discriminatory, the project ran until August 2019 and became a symbol of biometric experimentation on migrants at Europe's frontier.
Denmark's first face-scanning stadium, now joined by a bigger oneDenmark
Wrongful stop
In July 2019 the football club Brondby IF switched on Panasonic facial recognition at Brondby Stadium -- the first FR deployment in Denmark, approved by the Danish Data Protection Agency -- scanning roughly 14,000 fans per match against a ban list of about 50 people. Digital-rights group IT-Pol argued the system was disproportionate and set a dangerously low bar, and a University of Copenhagen law professor who sat on the deciding council agreed it should arguably never have been allowed. In 2025 the agency granted FC Copenhagen a more extensive stadium face-recognition system, deepening the normalisation of biometric surveillance in Danish sport.
Top court struck down a mandatory biometric IDJamaica
Data misuse
Jamaica's Supreme Court struck down the National Identification and Registration Act in 2019, ruling that mandatory biometric registration for a national ID violated the constitutional right to privacy.
Pegasus used against a Saudi dissident in CanadaCanada
Wrongful stop
Saudi dissident Omar Abdulaziz, a Canadian resident and confidant of Jamal Khashoggi, had his phone infected with Pegasus, and Citizen Lab detected suspected infections inside Canada.
Pegasus infected exiled journalists in LatviaLatvia
Wrongful stop
Exiled Russian journalists based in Latvia, including Meduza founder Galina Timchenko and Novaya Gazeta Europe's Maria Epifanova, were infected with Pegasus between 2020 and 2023.
Pegasus targeted an investigative journalistDominican Republic
Wrongful stop
Investigative journalist Nuria Piera was repeatedly targeted with Pegasus between 2020 and 2023, confirmed by Amnesty International and Citizen Lab.
Pegasus used against journalists and lawyersPanama
Wrongful stop
Pegasus was used to surveil journalists, activists, and lawyers in Panama, with early deployments linked to the government under former president Ricardo Martinelli.
Pegasus and the leaked target listPakistan
Wrongful stop
The phone number of then prime minister Imran Khan appeared on the leaked Pegasus target list, and Citizen Lab detected suspected Pegasus infections in Pakistan.
Pegasus infections tied to Khashoggi targetingTurkiye
Wrongful stop
Citizen Lab detected suspected Pegasus infections in Turkey, where associates of murdered journalist Jamal Khashoggi were among those targeted.
Suspected Pegasus operator in BangladeshBangladesh
Wrongful stop
Citizen Lab detected suspected Pegasus infections in Bangladesh, where authorities have acquired a range of phone interception and surveillance systems.
Suspected Pegasus operator in KenyaKenya
Wrongful stop
Citizen Lab detected suspected Pegasus infections linked to an operator in Kenya.
Suspected Pegasus operator in South AfricaSouth Africa
Wrongful stop
Citizen Lab detected suspected Pegasus infections in South Africa.
Suspected Pegasus operator in SingaporeSingapore
Wrongful stop
Citizen Lab detected suspected Pegasus infections in Singapore.
Suspected Pegasus operator in TunisiaTunisia
Wrongful stop
Citizen Lab detected suspected Pegasus infections linked to an operator in Tunisia.
Suspected Pegasus operator in QatarQatar
Wrongful stop
Citizen Lab detected suspected Pegasus infections linked to an operator in Qatar.
Algeria opened a Pegasus inquiryAlgeria
Wrongful stop
After the Pegasus Project, Algeria's public prosecutor ordered an investigation into reports the country was targeted, and Citizen Lab detected suspected infections there.
Suspected Pegasus operator in IraqIraq
Wrongful stop
Citizen Lab detected suspected Pegasus infections linked to an operator in Iraq.
Suspected Pegasus operator in UzbekistanUzbekistan
Wrongful stop
Citizen Lab detected suspected Pegasus infections linked to an operator in Uzbekistan.
Suspected Pegasus operator in KuwaitKuwait
Wrongful stop
Citizen Lab detected suspected Pegasus infections linked to an operator in Kuwait.
Suspected Pegasus operator in YemenYemen
Wrongful stop
Citizen Lab detected suspected Pegasus infections in Yemen.
Suspected Pegasus infections in SwitzerlandSwitzerland
Wrongful stop
Citizen Lab detected suspected Pegasus infections in Switzerland.
Suspected Pegasus operator in Ivory CoastCote d'Ivoire
Wrongful stop
Citizen Lab detected suspected Pegasus infections linked to an operator in Ivory Coast (Cote d'Ivoire).
Suspected Pegasus operator in ZambiaZambia
Wrongful stop
Citizen Lab detected suspected Pegasus infections linked to an operator in Zambia.
Suspected Pegasus operator in KyrgyzstanKyrgyzstan
Wrongful stop
Citizen Lab detected suspected Pegasus infections in Kyrgyzstan.
Suspected Pegasus operator in TajikistanTajikistan
Wrongful stop
Citizen Lab detected suspected Pegasus infections linked to an operator in Tajikistan.
Suspected Pegasus operator in LibyaLibya
Wrongful stop
Citizen Lab detected suspected Pegasus infections linked to an operator in Libya.
Pegasus used against Palestinian rights defendersPalestine
Wrongful stop
Citizen Lab detected suspected Pegasus infections in Palestine, where Palestinian human rights defenders were later confirmed to have been hacked.
World's largest biometric ID raises exclusion fearsIndia
Data misuse
India's Aadhaar program enrolled the biometrics of more than 1.3 billion people into the central CIDR database. Civil-society groups warn it drives surveillance and exclusion; India's Supreme Court recognized privacy as a fundamental right in 2017 and curbed mandatory Aadhaar use in 2018.
Wrongful stops from number-plate misreadsUnited Kingdom
Data misuse
Britain runs one of the world's largest automatic number-plate recognition networks, reading tens of millions of plates a day into a database of more than 20 billion records. The official surveillance camera commissioner warned that even at a claimed 97 percent accuracy the system misreads hundreds of thousands of plates a day, that police hold no meaningful data on its accuracy, and that misreads and cloned plates have led to wrongful stops and arrests of innocent motorists.
Plate and vehicle tracking refined on UyghursChina
Data misuse
Hikvision, the world's largest maker of plate readers and surveillance cameras, refined vehicle and face tracking in Xinjiang, where checkpoints and cameras monitor Uyghurs' movements. Those battle-tested systems are now exported worldwide.
Facial-recognition trials at Berlin's Sudkreuz stationGermany
Wrongful stop
Germany's federal police ran live facial-recognition trials at Berlin's Sudkreuz station in 2017 and 2018, scanning volunteers against a watchlist to test automated identification in a busy transit hub. Interior Minister Horst Seehofer hailed the results and pushed to expand automatic facial recognition to more stations and airports, drawing fierce criticism from civil-liberties groups and data-protection officials over false positives and the normalisation of biometric mass surveillance in public space.
Pegasus around the Khashoggi killingSaudi Arabia
Wrongful stop
Saudi Arabia used Pegasus against people close to murdered journalist Jamal Khashoggi, including an exiled dissident friend and his fiancee, whose phone was infected days after his 2018 killing.
Chinese facial recognition for mass surveillanceZimbabwe
Wrongful stop
From 2018 Zimbabwe acquired facial-recognition technology from CloudWalk and Hikvision for border control and mass surveillance, with citizens' biometric data sent back to the Chinese vendors. QUANTIFIED IN 2026: the IDS and African Digital Rights Network study of 12 March 2026 records USD 10 million spent by Zimbabwe on smart city surveillance, the smallest published figure among the eleven countries studied, with the camera count not specified. That is a useful corrective to reading deployment scale from spending alone -- Zimbabwe's earlier significance on this map is the DATA FLOW, citizens' biometric data returning to the Chinese vendors, not the size of the contract. The 2026 study found the same pattern of Chinese supply and financing across all eleven countries, and no adequate means anywhere to obtain remedy for surveillance errors or abuse.
DPI redirected users to government spywareTurkiye
Wrongful stop
Citizen Lab's 2018 Bad Traffic report found Sandvine PacketLogic devices on Turkey's network redirecting hundreds of users to malicious sites that delivered government spyware, alongside blocking of political and news content.
Italy's secretive SARI police facial-recognition systemItaly
Wrongful stop
In 2017 Italy's Interior Ministry commissioned the SARI (Automatic Image Recognition System) facial-recognition platform for the scientific police from vendor Parsec 3.26. Rolled out with extreme secrecy and little oversight, SARI was shown to be biased and to draw heavily on a database skewed toward foreign nationals; its real-time mode was later blocked by the Garante pending a proper legal framework.
Biometric dragnet over Uyghurs and Turkic MuslimsChina
Data misuse
China has built a pervasive biometric surveillance system across Xinjiang to control Uyghurs and other Turkic Muslims, combining facial-recognition checkpoints, mandatory collection of iris scans and DNA, and a predictive-policing platform that flags ordinary behavior as suspicious. It has funneled people into a network of detention camps that a 2022 UN report said may amount to crimes against humanity, with up to a million held.
Gantry cameras log every vehicle for a tax not chargedDenmark
Data misuse
Denmark built 180 highway gantries and roughly 250 fixed plate-reading cameras for a lorry eco-tax. The cameras log every passing vehicle even though the tax is not being levied, and the scheme has drawn opposition.
Early heavy use against dissidentsUnited Arab Emirates
Wrongful stop
The UAE was an early and heavy Pegasus user, targeting activist Ahmed Mansoor with a zero-day exploit in 2016 and later the ex-wife and associates of Dubai's ruler, part of one of the most extensive deployments of the spyware.
Spyware used against Ethiopian diaspora journalistsEthiopia
Wrongful stop
Ethiopian diaspora journalists at the ESAT broadcaster were targeted with Hacking Team's Remote Control System and Gamma's FinSpy spyware, documented by Citizen Lab.
Hacking Team spyware client in ColombiaColombia
Wrongful stop
Colombian security agencies were clients of Hacking Team's Remote Control System spyware, revealed by the 2015 breach of the Italian vendor.
Hacking Team spyware client in EcuadorEcuador
Wrongful stop
Ecuador's intelligence agency SENAIN purchased Hacking Team's Remote Control System spyware, revealed by the 2015 breach of the Italian vendor.
Hacking Team spyware client in ChileChile
Wrongful stop
Chile's investigative police were clients of Hacking Team's Remote Control System spyware, revealed by the 2015 breach of the Italian vendor.
Hacking Team spyware client in HondurasHonduras
Wrongful stop
Honduras was among the government clients of Hacking Team's Remote Control System spyware revealed by the 2015 breach of the Italian vendor.
Hacking Team spyware client in NigeriaNigeria
Wrongful stop
Nigerian government bodies were among the clients of Hacking Team's Remote Control System spyware revealed by the 2015 breach of the Italian vendor.
Hacking Team spyware client in MalaysiaMalaysia
Wrongful stop
Malaysian agencies were among the clients of Hacking Team's Remote Control System spyware revealed by the 2015 breach of the Italian vendor.
Hacking Team spyware client in South KoreaSouth Korea
Wrongful stop
South Korea's National Intelligence Service was a client of Hacking Team's Remote Control System spyware, revealed by the 2015 breach and sparking domestic controversy.
A nationwide plate-reading network for the whole countryHungary
Data misuse
Hungary built a unified national plate-reading network of 365 fixed gantries and 160 mobile units, feeding a central system used for traffic enforcement, registration and insurance checks, and stopping wanted or flagged vehicles nationwide.
'Ring of steel' tracked every car in and out of a townUnited Kingdom
Wrongful stop
Hertfordshire police ringed the small town of Royston with ANPR cameras, logging every vehicle entering or leaving. After complaints by Big Brother Watch, Privacy International, and No CCTV, the UK data regulator ruled the scheme unlawful and excessive and ordered it halted.
A national plate-reader network built without debateUnited Kingdom
Data misuse
The UK runs one of the world's largest ANPR networks, feeding a central database, yet it was constructed by police without any parliamentary debate or public consultation, and privacy regulators warned the blanket approach may be unlawful.
A motorway network that tracks cars by plateItaly
Data misuse
Italy's Tutor system covers more than 2,500 km of motorway, run jointly by the toll operator and the state police. It reads plates to calculate average speed over long stretches and can even track cars as they change lanes, logging the movements of every vehicle that passes.
A city that scans every car crossing its boundaryBelgium
Data misuse
The Belgian city of Mechelen scans every car crossing its boundary, inbound and outbound, against blacklists, automatically checking about a million vehicles a week and dispatching patrols to intercept flagged cars.
1,000 police cars scan every passing plateFrance
Data misuse
France equipped around 1,000 gendarmerie, police, and customs vehicles with plate-reading lightbars from the Paris firm Survision that continuously scan passing cars without any officer input and check them against databases.
Police put a critic on a plate-reader watch listCanada
Data misuse
After a columnist criticized Edmonton police for using traffic cameras to raise revenue, officers added him to a plate-reader watch list of high-risk drivers to monitor his movements and look for a reason to arrest him. The police chief and several officers were dismissed, and Canada's privacy commissioner raised concerns.
A secretive national plate-reading network since the 1980sJapan
Data misuse
Japan's National Police Agency has run the secretive N-System since the late 1980s, reading and recording license plates at hundreds of sites on highways and major roads, including a ring around Tokyo's Kabukicho district. Police disclose little about how long the data is kept or how it is used, and privacy advocates call it part of an emerging surveillance society.
Cyprus and the Intellexa surveillance tradeCyprus
Wrongful stop
Cyprus hosted operations of the Intellexa alliance behind the Predator spyware and was a client of Hacking Team, tying the island to Europe's mercenary surveillance trade.
Fatherland card links data to state benefitsVenezuela
Data misuse
Venezuela built the ZTE-backed fatherland card (carnet de la patria) system linking citizens' personal data to access to subsidized food and services, alongside Chinese-supplied surveillance cameras.
Chinese-supplied facial recognition surveillanceSri Lanka
Wrongful stop
Sri Lanka received Chinese-made AI surveillance and facial-recognition technology as part of Huawei and partner safe-city deployments.
DPI middleboxes injected Predator spywareEgypt
Wrongful stop
Telecom Egypt used Sandvine PacketLogic deep-packet-inspection middleboxes to inject Intellexa's Predator spyware into the connection of opposition presidential candidate Ahmed Eltantawy, alongside mass web-monitoring and news censorship; the US added Sandvine to its Entity List in 2024.
Blue Coat and Sandvine gear filtered the internetSyria
Data misuse
Syria's telecom authority deployed deep-packet-inspection equipment, including Blue Coat and Sandvine gear, to filter and censor the internet and redirect users to malicious sites during the civil war.
Amesys Eagle system enabled mass interceptionLibya
Data misuse
Under Muammar Gaddafi, Libya deployed the French company Amesys's Eagle system for nationwide internet interception and mass surveillance of dissidents; French magistrates later charged Amesys executives over complicity in torture.
Closed state supplied with DPI gearEritrea
Data misuse
Eritrea, one of the world's most closed states, was among the authoritarian governments supplied with Sandvine deep-packet-inspection equipment for internet control.
DPI gear powered social-media blackoutsAzerbaijan
Data misuse
Sandvine and Allot deep-packet-inspection equipment was deployed in Azerbaijan to impose social-media blackouts during periods of unrest.
DPI censorship throttles VPNs and newsRussia
Data misuse
Sandvine equipment was among the technology linked to internet censorship in Russia, which also runs the domestic TSPU deep-packet-inspection system to throttle and block VPNs, social media, and independent news.
DPI used to censor an LGBTQ websiteJordan
Data misuse
In Jordan, Sandvine equipment was used to censor an LGBTQ news website.