World

EU-US Visa Deal Would Hand Over Biometric Data of Millions

A leaked draft reveals the EU may agree to share citizens' biometric data with US border agencies. Privacy groups warn the deal undermines fundamental rights.

The European Commission is negotiating a deal with the US that would allow American border agencies to access EU biometric databases and receive automated personal data transfers from European systems. A leaked May 2026 draft of the Enhanced Border Security Partnership framework has been analysed by digital rights group EDRi, which warns the terms fall below EU data protection standards and could be struck down by the Court of Justice of the European Union. The agreement is tied to continued visa-free travel for EU citizens to the United States, and individual member states would sign bilateral deals based on the framework.

The European Commission is close to finalising a deal with the United States that would allow American border agencies to screen European travellers against biometric databases and receive automated transfers of personal data. A leaked draft of the "Enhanced Border Security Partnership" (EBSP) Framework Agreement, obtained by digital rights group EDRi, suggests Brussels has accepted terms that privacy advocates say fall well below EU legal standards.

The stakes are high. The US made clear in 2022 that countries wishing to keep their citizens in the Visa Waiver Programme would need to open their biometric databases to American authorities. For the EU, that means automated exchanges of fingerprints, facial recognition data, and subjective risk indicators drawn from national law enforcement and migration systems. The Commission received its formal negotiating mandate from EU member states only in late 2024, yet the leaked May 2026 draft already points to a framework that EDRi warns could be struck down by the Court of Justice of the European Union.

What the leaked draft actually contains

The Framework Agreement is intended to set the ground rules for how EU countries share traveller data with US agencies. Individual member states would then sign their own bilateral deals, or update existing ones, on that basis.

According to EDRi's analysis of the leaked text, the draft departs significantly from the mandate given by EU governments. Key provisions appear to allow the US to receive not just raw biometric identifiers but also individual risk assessments generated by European systems. These assessments can flag people based on behavioural patterns, travel history, or intelligence tips, categories that are notoriously broad and prone to error.

The document also raises questions about data retention periods, oversight mechanisms, and whether EU citizens would have any meaningful right to challenge incorrect information once it sits in American databases.

Why privacy groups are alarmed

EDRi, which published its assessment of the leaked text, argues that the proposed safeguards do not meet the EU's own requirement of "essential equivalence" in data protection. That standard has torpedoed previous transatlantic data deals. The Court of Justice invalidated the Privacy Shield framework in 2020 on precisely those grounds, ruling that US surveillance laws gave European citizens insufficient protection.

The same court has already shown it will not hesitate to strike down international agreements that fail to respect the Charter of Fundamental Rights. If the EBSP framework goes through in its current form, legal challenges seem almost certain.

Beyond the courtroom, there is a practical concern. The US has sharply tightened its border policies in recent years, including expanded detention of migrants and visitors. Handing over biometric data and risk scores to an administration with that track record, EDRi argues, exposes Europeans and third-country nationals registered in EU databases to profiling, questioning, or even detention at US ports of entry.

A pattern of US pressure on European data rules

This is not the first time Washington has used visa access as leverage to reshape European data practices. The original Passenger Name Record (PNR) agreement, struck after the September 2001 attacks, faced years of legal pushback before being renegotiated. The SWIFT banking data deal and the Safe Harbour privacy framework both collapsed under judicial scrutiny after similar complaints about inadequate protections.

What makes the EBSP different is the nature of the data. Biometric identifiers are immutable. A mistaken risk score tied to your fingerprint or face is far harder to correct than a wrong entry in a flight manifest. Once shared, that data can be copied, cross-referenced, and retained across multiple US agencies with limited transparency.

What happens next

The Commission has not publicly confirmed the authenticity of the leaked draft, nor has it set a timeline for concluding negotiations. However, the direction of travel is clear: Brussels is under pressure to secure a deal before any disruption to visa-free travel for EU citizens.

Member states will ultimately need to approve the framework, either through the Council or through national parliamentary processes for the bilateral agreements that follow. Privacy campaigners are already lobbying capitals to reject terms that they say sacrifice fundamental rights for convenience at the border. The European Parliament, which has no formal vote on this type of international security agreement, may still use its political weight to force a public debate.

Watch for signals from the Court of Justice. If the framework is signed, a legal challenge could come within months. The court's previous rulings suggest it will not be sympathetic to arguments that border security trumps data protection when the safeguards are this thin.