All posts

EU may hand US biometric data of 460M citizens for visa-free travel

Manaal KhanJuly 22, 2026 at 7:02 AM5 min read
EU may hand US biometric data of 460M citizens for visa-free travel

Key Takeaways

EU may hand US biometric data of 460M citizens for visa-free travel
Source: Hacker News: Best
  • The US is requiring access to EU biometric databases as a condition for maintaining visa-free travel for European citizens
  • A leaked draft agreement shows the EU largely accepting US demands, potentially violating EU data protection laws
  • Civil rights groups warn the deal could enable discrimination based on political opinions and social media activity

The European Union is negotiating to share biometric data and sensitive risk assessments of its 460 million citizens with the United States. The price? Keeping visa-free travel. A leaked draft agreement reveals the EU has largely caved to US demands, raising questions about whether the deal can survive legal challenge under EU data protection law.

The US Department of Homeland Security announced these requirements in 2022 under what it calls Enhanced Border Security Partnerships (EBSP). Countries that want their citizens to travel to the US without a visa must provide automated access to national biometric databases. The EU received its formal negotiating mandate only in December 2025, and since then, talks have progressed largely out of public view.

Advertisements

What exactly would the US get access to?

The EBSP scheme involves systematic transfers of biometric data, fingerprints, facial recognition profiles, and what the draft agreement calls "indications of risk." That last category is where things get troubling. These risk indicators draw from national databases and can include subjective assessments about individuals.

According to analysis from European Digital Rights (EDRi), the leaked text does nothing to prevent discrimination based on political opinions. The US already screens travelers' social media profiles, a practice that has targeted journalists, activists, and researchers. Under this agreement, European databases would feed directly into that screening apparatus.

EDRi warns the risk assessments could be used to target people who have expressed support for transgender rights, opposition to the current US administration, or criticism of US foreign policy. Social media posts about the Gaza conflict, for example, could flag someone for additional scrutiny or detention at the border.

The legal problem the EU cannot ignore

The EU's highest court has already struck down two previous data-sharing agreements with the United States. In 2020, the Court of Justice of the European Union invalidated the Privacy Shield framework in the Schrems II decision, ruling that US surveillance laws failed to provide "essentially equivalent" protection to what EU citizens enjoy at home.

The leaked EBSP draft appears to run into the same problem. EDRi's analysis concludes the provisions are "in large parts, not compliant with EU primary and secondary law, notably the Charter of Fundamental Rights." The organization predicts the Court of Justice would declare the agreement incompatible with EU law.

The draft also departs significantly from the negotiating mandate that EU member states gave the Commission. This matters because any final agreement will need ratification. If the text strays too far from what member states authorized, approval becomes uncertain.

Why the US holds the leverage

Forty countries currently participate in the US Visa Waiver Program. The US is effectively telling all of them: share your databases or your citizens start needing visas. For European businesses and travelers accustomed to easy US access, that threat carries real weight.

EDRi calls this "blackmail." The framing might be blunt, but the dynamic is accurate. The US offers visa-free travel as a benefit, then attaches conditions that would be unacceptable if proposed by any other country. The EU finds itself weighing convenience against its own stated values on data protection.

The secrecy around negotiations compounds the problem. Citizens whose data would be shared have had no meaningful input. The draft only became public because Statewatch, an EDRi member organization, leaked it in May 2026.

Advertisements

What happens to third-country nationals?

The agreement would not just affect EU citizens. Anyone registered in European databases, refugees, asylum seekers, long-term residents, students, would have their data shared with US authorities. Given the current US administration's treatment of migrants and its expansion of deportation operations, this raises immediate concerns about data being used to facilitate removal proceedings.

The Schengen Information System alone contains over 14 million records. Many of those records belong to non-EU nationals who entered Europe seeking protection. Sharing that information with US immigration enforcement creates risks the EU has not publicly acknowledged.

ℹ️

Logicity's Take

This deal matters for any startup handling European user data. If the EU accepts US demands here, it signals a willingness to compromise on data protection when the stakes are high enough. That precedent affects how courts and regulators will interpret adequacy decisions, standard contractual clauses, and other transfer mechanisms. Companies building compliance programs should watch this closely. A deal that gets struck down by the CJEU creates uncertainty. A deal that survives lowers the bar for what counts as "essentially equivalent" protection, which affects every US company trying to serve European customers.

The timeline ahead

Negotiations are ongoing. The Commission has not announced a target date for completing the Framework Agreement. Once a draft is finalized, it will need approval from the European Council and likely the European Parliament. Given the political sensitivity and legal vulnerabilities, that process could take months or trigger a renegotiation.

EDRi is calling on the Commission and Council to reject the current terms outright. Whether that advice will be followed depends on whether EU leaders prioritize travel convenience or data protection. So far, the leaked draft suggests they are choosing convenience.

Frequently Asked Questions

Why is the US demanding access to EU biometric databases?

The US claims it needs the data for border security and traveler screening. Countries that refuse to provide automated database access will lose visa-free travel privileges for their citizens under the Visa Waiver Program.

Would the EU-US biometric data deal affect non-EU citizens?

Yes. Anyone registered in European databases, including refugees, asylum seekers, students, and long-term residents, would have their data shared with US authorities.

Has the EU Court struck down similar data deals before?

Yes. The Court of Justice of the EU invalidated the Safe Harbor and Privacy Shield agreements with the US, ruling that US surveillance laws did not provide adequate protection for EU citizens' data.

When would this EU-US data sharing agreement take effect?

No target date has been announced. The Framework Agreement must be finalized through ongoing negotiations, then approved by EU member states and potentially the European Parliament.

Also Read
Craneware breach exposes US hospital billing data

Another example of sensitive data exposure with cross-border implications

ℹ️

Need Help Implementing This?

If you're building compliance programs for EU-US data transfers and need to track regulatory developments, Logicity covers the policy changes that affect startup operations. Subscribe to our newsletter for updates on data protection law and cross-border compliance.

Source: Hacker News: Best

M

Manaal Khan

Tech & Innovation Writer

Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.