Illustration for: Privacy at the Border: Can Security and Data Protection Coexist?

The deployment of biometric systems at borders involves a fundamental tension. On one side: the security interest in accurately and efficiently identifying individuals, detecting fraud, and enforcing border controls. On the other: the privacy interest in limiting the collection of sensitive personal data, protecting individuals from surveillance, and ensuring that border crossings remain a dignified experience. These interests are not irreconcilable — but resolving them requires deliberate design choices.

Biometric data: the highest category of protection

Under the GDPR, biometric data used for the purpose of uniquely identifying a natural person is classified as special category data — the highest level of protection in EU data protection law. This is appropriate: biometric data is fundamentally different from other personal data in one critical respect — it cannot be changed. A compromised password can be reset. A compromised biometric cannot.

Privacy by design in practice

Privacy by design — the principle that data protection should be built into a system from its inception — is now a legal requirement under GDPR Article 25. For biometric systems, this means: collecting only the data strictly necessary for the specific purpose; storing biometric templates rather than raw images where possible; ensuring that data collected for one purpose cannot be repurposed for another; and applying cryptographic protection to stored data.

The fairness of algorithms

Biometric algorithms can perform differently across demographic groups. Face recognition accuracy can vary across ethnicities, ages, and genders. PAD systems trained predominantly on one demographic may underperform on others. The EU AI Act’s requirement that training data for high-risk AI systems be representative of the population the system will encounter is directly relevant here.

The EINSTEIN project works with ethics and legal experts from Trilateral Research to conduct ELSI impact assessments, run Living Lab sessions with community representatives, and ensure that privacy and fairness are built into every application from the earliest design stage.

© 2026 EINSTEIN Consortium. EINSTEIN is funded by the European Union’s Horizon Europe programme (GA No. 101121280) and by UKRI (IFS 10093453). Views expressed are those of the authors only. www.einstein-horizon.eu