Worldcoin’s Eye Scans Put European Privacy Rules to the Test

Worldcoin’s launch of eye-scanning sign-ups drew scrutiny from privacy authorities in the U.K., France and Germany. Their questions include whether people gave clear, freely given consent and how their biometric data is stored, protected and deleted.

WTF Index TERMINATOR
◄ Terminator 2 Idiocracy 1 ►

The story centers on biometric surveillance risks and regulatory scrutiny, with a mild Terminator lean.

Worldcoin’s Eye Scans Put European Privacy Rules to the Test

Worldcoin’s plan to verify people by scanning their eyes and offering digital tokens has prompted privacy questions in Europe. Authorities are examining whether the project’s handling of biometric data meets data protection requirements, including rules on consent, transparency, security and deletion.

Authorities focus on biometric data

Worldcoin began its official global rollout this week, with pop-up locations in the U.K., France, Germany and Spain. At these locations, people can provide biometric data through the project’s Orb devices in exchange for digital tokens.

The U.K.’s Information Commission Office said it was “making enquiries” about the launch. It also emphasized that organizations should assess high-risk data processing before it begins, establish a clear lawful basis for processing personal data, and ensure consent can be withdrawn without detriment when consent is the basis.

France’s data protection authority, the CNIL, went further. It said the legality of Worldcoin’s data collection and the conditions for storing biometric data seemed questionable, and confirmed that it had initiated investigations after Worldcoin collected data in France.

The CNIL passed its investigation to Bavaria’s data protection authority, which it identified as Worldcoin’s lead data supervisor in the EU. The Bavarian authority confirmed it was examining the project but declined to discuss the ongoing procedure in detail.

Consent must be clear and freely given

Worldcoin’s developer, Tools For Humanity, told TechCrunch that the project relies on users’ consent to create proof of personhood and to opt into data custody. Under the GDPR, biometric data used for identification is treated as special category data, which faces strict rules for lawful processing.

The U.K. regulator’s comments highlight a central question: can consent be freely given when people are offered a token in exchange for providing biometric information? The CNIL’s concerns and the Bavarian investigation put the clarity and conditions of that consent under scrutiny.

Tools For Humanity pointed to Worldcoin’s biometric data consent form and privacy notice. Together, the documents run to almost 3,800 words and almost 3,400 words, respectively. The source article notes that people must receive an extremely clear and specific explanation of how their biometric data will be used to give explicit consent.

The project’s organizational structure may also make it harder for people to understand who is handling their information. Tools For Humanity is a for-profit technology company that developed Worldcoin and operates the World App. The project also includes the Worldcoin Foundation and the Worldcoin Protocol, which the company’s spokesperson suggested are not for-profit entities.

Investigators examine safeguards and rights

The Bavarian authority said its investigation would consider whether a data protection impact assessment had been carried out and whether it clearly analyzed the effect of the planned processing and the safeguards addressing risks.

It also said the investigation was intended to clarify transparency and security questions. These include whether people receive enough information to understand how their data is processed and for what purposes, whether their rights are guaranteed, and whether protection against unauthorized access is sufficient to help prevent identity misuse.

Those rights include asking for personal data to be deleted, objecting to processing and revoking consent. Worldcoin’s biometric consent form says that after a person signs up with an Orb, a unique Iris Code will be created and cannot be deleted because the proof of uniqueness would no longer work.

The source article points out that the GDPR broadly defines personal data as information that could identify a person, including when combined with other data. That raises a question for investigators: whether the Iris Code is subject to personal data rights, including deletion requests.

Worldcoin says it will cooperate

Tools For Humanity said Worldcoin had completed a data protection impact assessment and described it as rigorously conducted. The company also said the project complies with applicable laws and would cooperate with governing bodies seeking more information about its privacy practices.

Worldcoin’s consent form lists the Worldcoin Foundation as controller of images and biometric data collected through the Orb. Tools For Humanity’s spokesperson said the Foundation is now the data controller and Tools For Humanity is a data processor. The Bavarian investigation is examining the processing arrangements and the safeguards around the data.

Regulators have raised questions, but the source article says it remains to be seen how quickly their concerns might lead to enforcement. For now, the scrutiny centers on whether people understand what they are agreeing to, whether consent meets the required standard, and whether the project can protect and manage biometric data in line with European privacy rules.