Border Surveillance and Biometrics
EU and US adoption of similar strategies and technologies to manage and surveil their borders remains an area of transatlantic convergence amid fractious relations. Data collection has acquired paramount importance in this regard, with large-scale biometric databases now essential to border management on either side of the Atlantic. Despite an initial, marked difference in system architectures, the EU has undertaken reforms in the last decade that widen and increase the centralization of collected data. The bloc’s approach now increasingly mirrors Washington’s.
But the United States is now going a step further. It is pushing for unprecedented biometric data exchange by weaponizing its visa-free travel program to gain access to EU member states’ databases.
The All-in-One American Approach
The US Department of Homeland Security (DHS) has been collecting biometric data of foreign nationals since 1994 through its Automated Biometric Identity System (IDENT). Initially designed to store records of unauthorized entrants, IDENT was expanded after 9/11. Profiles once collected only for undocumented migrants are now compiled for all individuals entering the country. IDENT’s role has consequently evolved from migration management to a broader mix of migration control, law enforcement, and counterterrorism. The system is now one of the world’s largest biometric databases, storing up to 320 million identity records for US citizens and non-citizens, criminal or not, with data collected at every port of entry and exit. The system follows a “one-stop-shop” approach, gathering biometric data for a wide range of reasons and making it all searchable to many authorities.
Since 2016, DHS has also been developing IDENT's successor, the Homeland Advanced Recognition Technology (HART). It is due to enter into force in 2027. HART will add iris patterns, DNA, and voice prints to biometrics already collected (fingerprints and facial images). Building on IDENT's one-stop-shop rationale, HART will also be searchable by many US federal, state, and local agencies even outside DHS.
HART may not yet be implemented, but recent developments have intensified concerns about its use. A 2025 presidential proclamation regarding the US southern border broadened federal authority to collect and analyze non-citizens’ biometric data. The proclamation could also further integrate biometric databases for surveillance as DHS has started exploring a unified platform for large government databases, including those of the Transportation Security Administration and Secret Service, to search faces and fingerprints.
All these developments point toward a more integrated US surveillance architecture with limited privacy protections for non-citizens, especially at the country’s borders.
A Shift in European Thinking
Brussels initially chose to avoid a single, all-purpose migration database, opting instead for a compartmentalized architecture of three isolated databases, each with distinct legal bases, purpose, and strict access rights.
The 2004 and 2005 terrorist attacks in London and Madrid reinforced the debate on stronger migration monitoring, yet Brussels did not repurpose existing databases for law enforcement or counterterrorism. Biometric databases for migration increasingly supported security objectives, but access and retrievable information for law-enforcement agencies remained tightly managed. This was possible due to the system’s architecture, which hindered centralizing data and using it for reasons beyond the original purpose of its collection.
Despite this, growing polarization around migration brought calls to amend the architecture. EU policymakers began pushing for more database integration to close information gaps and uphold security, resulting in new regulations that streamline law-enforcement access, increase data collected, and establish new databases.
The turning point was the 2015 border management crisis, after which the overhaul of the compartmentalized, minimum-data approach began. Rising arrivals at EU external borders, and terrorist attacks in Paris and Brussels, cemented the link between migration databases and security, pushing Europeans closer to the American approach. Interoperability, the process of easing access and searchability across all large-scale databases, became a priority. EU Regulation 2019/817 and Regulation 2019/818 implemented interoperability and established three new databases (see Table 1).
|
Table 1: Initial Databases for the EU Large-Scale IT System for Asylum and Migration |
|||
|---|---|---|---|
| Schengen Information System (SIS) | European Asylum Dactyloscopy Database (EURODAC) | Visa Information System (VIS) | |
|
Purpose |
Established in 1995, it includes alerts on people and objects sought for law enforcement purposes and on third-country nationals to be refused admission to the Schengen area. Return decisions are included in the information stored. | Established in 2003, it includes information on asylum seekers used to determine the member state responsible for handling an asylum request. | Established in 2011, it aims to implement the EU common visa policy by collecting information about third-country nationals seeking entry into the Schengen area on a short-term visa. |
| Data Stored | Fingerprints, facial images, biographic data; after latest reform, also palm prints and DNA records (for missing persons only) | Fingerprints; since 2023 also facial images, biographic data, time/date/place of application; latest reform allows minors from age 6 (previously 14) to be profiled | Fingerprints, facial image, biographic data; latest reform allows copy of travel document |
| Authorities With Access | Law enforcement authorities, border authorities, Europol; after latest reform, also immigration authorities, Frontex, ETIAS Central Unit | Asylum and law enforcement authorities; after 2013, Europol (only for strong, terrorism-linked reasons); after latest reform, intelligence services and law enforcement have broader access | Consular authorities, border authorities, immigration and asylum authorities, law enforcement, Europol |
Under this scheme, authorities with access to one EU database can run cross-system searches via centralized portals and a hit/no-hit system to see if an individual’s information appears in any other EU biometric database. Though European safeguards remain much stronger than those in the United States, such centralization and broader access to databases is becoming more common on both sides of the Atlantic.
Connecting the Dots
Data gathering at borders on both sides of the Atlantic is converging. Profiles now span nearly all individuals, collected biometrics are growing, retention periods are lengthening, and access rights are broadening. All of this is raising concerns about privacy and data usage. Such concerns may grow. The 2025 ProtectEU Strategy calls for improved information-exchange arrangements with non-EU countries, including on biometric data, to enhance law enforcement and border management.
Meanwhile, since 2022, Washington has pressed all Visa Waiver Program (VWP) countries, including 24 EU member states, to grant access to their biometric databases under an Enhanced Border Security Partnership (EBSP). The US government has threatened to revoke visa-free travel for citizens of noncompliant countries.
In December 2025, the Council of the EU authorized the European Commission to negotiate, with the United States, a framework setting conditions for each member state’s bilateral agreement for database access. If achieved, this would be the first EU agreement of its kind, and the Commission already presented a final version of the framework to the Council in September. It provides for an exchange of biometric data to support screening and identity verification, and determine if an individual’s entry or stay poses a “serious and genuine risk to security or public order”. During a border check or visa assessment, therefore, if the competent authority finds the individual suspicious and their entry a potential “risk”, that authority could submit a query to the relevant national database to determine if it finds a biometric match. The ambiguity of the definitions used, however, rises concerns about acceptable use and mass profiling. A recent DHS request in cases of a match to obtain even greater information—potentially spanning racial or ethnic origin, political opinions, or religious beliefs, all of which is considered “special category” data that deserves extra protection under the EU’s General Data Protection Regulation—is one reason for these concerns. Although information transfers are meant to occur only when strictly necessary and under appropriate safeguards, questions about the purpose of DHS’s request persist, as does unease about its procedures for storing the additional information. A provision acceding to the DHS request was nevertheless included in the final framework agreement the Commission published in September. A June draft released by Statewatch noted that the “US strongly insisted on not introducing additional limitations related to the usage of data, including for special categories of personal data.”
If approved, EBSP would create an unprecedented data pipeline between EU member-state systems and DHS. Data would be transferred whenever a check found a match. This would even apply to third-country nationals’ data processed by EU member states, despite their ineligibility for the VWP.
The Pitfalls Ahead
Despite all these issues, the Commission and Council seem eager to negotiate a framework that, according to a coalition of over 30 NGOs and independent experts, does not align with EU standards. Instead, the bloc remains focused on securing reciprocity to query US databases.
The United States has set a December 31 deadline to reach agreement on an EBSP. It is unclear if it will be met. Some member states seem willing to cooperate (some are even open to involving EU large-scale systems), while others demand stronger safeguards. The prospect of ejection from the VWP could sway positions. European Parliament approval will also be needed. Personal data has always been a sensitive issue for legislators in Brussels. Yet, given recent voting patterns on migration issues, including approval of measures such as the recent “Return Regulation”, parliamentary consent may be forthcoming. And even if an agreement is approved, it could fall foul in the European Court of Justice, as the 2020 EU-US Privacy Shield did.
If a deal is not reached in time, or deemed insufficient by US authorities, or invalidated, an unprecedented weaponization of US visa policy toward the EU could arise. EU reaction to American pressure—whether conceding, negotiating better safeguards, or retaliating for US actions on the VWP—will shape the future of border crossings on both sides of the Atlantic and the use of biometrics in migration management.
The views expressed herein are those solely of the author(s). GMF as an institution does not take positions.