Reverse face search is the idea that a single photograph of a face can be used to find other pictures of the same person. Understanding how it works matters, because the mechanism explains both why it is effective and why European law treats it as one of the most tightly restricted things you can build. This article explains the technology and the legal position. It deliberately names no service, recommends none, and contains nothing about identifying anybody.
Updated October 2026. Legal provisions and enforcement decisions are quoted from the regulators and standards bodies listed in Sources. This is general information about the technology and the rules, not legal advice, and no tool is named or endorsed.

How reverse face search works: numbers, not pictures
Nothing in the process compares photographs. A model converts each face into a short list of numbers, usually called an embedding, positioned so that distance corresponds to similarity. The research that popularised the approach describes learning a mapping from face images to a compact Euclidean space where distances directly correspond to a measure of face similarity, and reports strong benchmark accuracy using only 128 bytes per face.
Two consequences follow immediately. Searching becomes a nearest neighbour problem over numbers, which is fast and cheap at enormous scale. And the number, not the photograph, is the asset. It survives the deletion of the original image, it can be copied between systems, and it does not need your name attached to be useful.
Benchmark accuracy is also not operational accuracy. NIST, which runs the standard evaluations, distinguishes one-to-one verification from one-to-many identification, and its report on demographic effects processed 18.27 million images of 8.49 million people through 189 mostly commercial algorithms from 99 developers. Its main result was that false positive differentials are much larger than false negative ones and exist broadly across many algorithms tested, with false positive rates often varying across demographic groups by factors of 10 to beyond 100, while false negatives usually vary by factors below three. It also found false positives higher in women than men, and elevated in the elderly and in children.
The legal position in Europe is unusually clear
Under the GDPR, biometric data processed for the purpose of uniquely identifying a natural person is a special category, and Article 9(1) prohibits that processing unless a specific exception applies. Consent, in practice, is the only route that could plausibly cover a general purpose face index, and it is not obtainable from people whose photographs were collected without their knowledge.
The EU AI Act goes further. Article 5(1)(e) prohibits AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage, and Article 5 has been applicable since 2 February 2025. The same article prohibits biometric categorisation systems that infer characteristics such as political opinions, religious beliefs or sexual orientation, and emotion recognition in workplaces and education, with narrow exceptions.
Enforcement has followed the law. A Dutch regulator decision of 16 May 2024 imposed a fine of 30.5 million euro, with orders carrying further penalties for non-compliance, on a company that had built a database of billions of face photographs scraped from the internet and converted into a unique biometric code per face. The decision cited breaches including Article 5(1)(a), Article 6(1), Article 9(1), the transparency obligations in Articles 12 and 14, the right of access in Article 15, and the failure to designate an EU representative under Article 27(1). The United Kingdom’s regulator had previously issued a penalty of 7,552,800 pounds against the same operation.
5 real privacy risks
- You cannot change your face. A leaked password is replaceable and a card can be reissued. An embedding derived from your face is not revocable, which makes it a permanent identifier rather than a credential.
- You do not have to have posted anything. Appearing in someone else’s public photograph, a group shot, a news picture or a club page is enough to be indexed by a system that scrapes broadly.
- The number is portable. Embeddings can be transferred between systems and retained after source images are removed, so deleting a photograph does not necessarily undo the indexing.
- Errors are not evenly distributed. NIST found false positive rates varying across demographic groups by factors of 10 to beyond 100 in many algorithms, higher in women than men, and elevated in children and the elderly. A false match is a real harm to a real person.
- It erodes practical anonymity. Being unremarkable in a crowd has always been a privacy mechanism. Cheap one-to-many search over scraped images removes it without anyone deciding that it should be removed.
What you can actually do
- Use your access and erasure rights. In the EU and UK, Articles 15 and 17 of the GDPR give you the right to ask what an organisation holds about you and to request erasure. The Dutch decision turned partly on failures to answer exactly these requests.
- Complain to your data protection authority. Regulators act on complaints, and the enforcement described above began that way. This is the lever with real force behind it.
- Reduce the public supply. Make old profiles private, ask to be untagged from public group photographs, and think about club, school and employer pages, which are a common source of clear frontal images.
- Be precise about what you are protecting. Face recognition on your own phone compares a template stored on the device against you. That is a different activity from indexing scraped photographs of strangers, and conflating the two leads to bad decisions.
- Expect limits. Removal processes vary, some operators are outside your jurisdiction, and none of this gives you a clean deletion. Lowering exposure is realistic; disappearing is not.
The wider pattern is worth seeing. Automated recognition of people and objects in public has moved from specialist systems to commodity infrastructure, which is the same story as number plate recognition and of what smart glasses record. If an image of you turns up somewhere unexpected, spotting AI generated images and recovering a hacked account are the practical next steps.
Common questions
How does reverse face search work technically? A model converts a face into an embedding, a compact list of numbers placed so that distance corresponds to similarity. Searching then means finding the nearest numbers in an index, not comparing photographs. Published research describes doing this with as little as 128 bytes per face.
Is building a face search database legal in the EU? Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage is prohibited by Article 5(1)(e) of the EU AI Act, applicable since 2 February 2025, and biometric identification data is a special category under Article 9(1) of the GDPR.
Have regulators actually fined anyone? Yes. A Dutch decision of 16 May 2024 imposed a 30.5 million euro fine, with further penalties attached to compliance orders, over a scraped database of billions of face photographs, and the UK regulator had already issued a penalty of 7,552,800 pounds against the same operation.
How accurate is face recognition? It varies enormously by algorithm and by conditions. NIST evaluations of 189 algorithms from 99 developers found false positive rates differing across demographic groups by factors of 10 to beyond 100 in many cases, with false negative differentials usually below three.
Can I get my face removed from these systems? You can exercise access and erasure rights and complain to your data protection authority, which is how the enforcement above started. Complete removal is not realistic, because embeddings persist independently of the original images.
Sources and further reading
Where the figures and rules above come from, so you can check them:
- Face embeddings, Euclidean distance as similarity and 128 bytes per face: Schroff, Kalenichenko and Philbin, FaceNet, 2015
- Demographic differentials, evaluation scale and the one-to-one against one-to-many distinction: NISTIR 8280, Face Recognition Vendor Test Part 3, NIST
- Biometric data as a special category and the prohibition in Article 9(1): GDPR Article 9
- Prohibition on untargeted scraping of facial images and the application date: EU AI Act, Article 5
- Fine, orders and the GDPR articles breached: Dutch supervisory authority decision via the EDPB
Photo credit: Surveillance cameras in a shopping street, Veendam (2020) 01 by Donald Trung Quoc Don (Chữ Hán: 徵國單) – Wikimedia Commons – © CC BY-SA 4.0 International.(Want to use this image?)Original publication 📤: –Donald Trung 『徵國單』 (No Fake News 💬) (WikiProject Numismatics 💴) (Articles 📚) 16:28, 12 January 2020 (UTC), CC BY-SA 4.0, via Wikimedia Commons.
Join the discussion