Article page checkbox is not checked in page info.
Enhanced Border Security Partnership
Enhanced Border Security Partnership Balancing US security demands and EU privacy protection
Steven Blaakman, Members' Research Service
Summary
To preserve visa-free travel under new United States (US) requirements, the European Commission has negotiated a framework agreement with the US for the Enhanced Border Security Partnership that would grant access to information stored in national databases, including biometric databases. This would have to be approved by the European Parliament and the Council.
With the exception of Bulgaria, Cyprus and Romania, all EU countries' citizens enjoy visa-free travel to the US by participating in its visa waiver programme.
The framework would stipulate the rules to follow when EU countries negotiate access to their national databases with the US in a bilateral agreement. It would be up to Member States to decide what data and databases they wish to include in the information exchange with US authorities. The framework would apply to all EU countries, except Ireland, which is not in the Schengen zone, and Denmark, which has an opt-out. Countries also have the option to revoke access should the US withdraw visa-free travel for their citizens.
One of the main challenges in the talks will be how to protect people's personal data, as the EU and the US have adopted very different approaches to this. The EU sees personal data protection as a fundamental right and has a single comprehensive data privacy law in the form of the General Data Protection Regulation (GDPR). The US considers it a consumer protection issue, which is covered by a panoply of legislation at both federal and state level. EU citizens also have more control over their personal data and rulings by the European Court of Justice and the European Court of Human Rights have further clarified the limits placed on the use of personal data over the past few years.
The European Data Protection Supervisor has voiced its concerns and emphasised that the processing of personal data should not exceed the limits of what is strictly necessary and proportionate.
The Commission has stressed the need for safeguards to prevent the misuse of personal data. In the past, Parliament has shown that it considers personal data an important issue when voting on international agreements.
What it is all about
The US requests access to information stored in EU countries' databases, including biometric databases, as a condition for maintaining visa-free US travel for EU citizens. The country has set a deadline of 31 December 2026 for concluding the Enhanced Border Security Partnership (EBSP) agreements.
The US sees its visa waiver programme as a security partnership with its closest allies and expects them to increase cooperation on counterterrorism, law enforcement and immigration enforcement. These expectations now also include sharing biometric data under the EBSP.
A 2024 update to a privacy impact assessment by the US Department of Homeland Security states that the EBSP would allow it to routinely screen the biometric data of travellers, asylum applicants or anyone encountered during US border screening and immigration procedures against partner countries' biometric databases.
The information exchanged, including biometric data such as fingerprints, would be used for screening and verifying the identity of travellers in order to identify those who may pose a risk to public security. In addition to travellers, the US is seeking access to information on applicants for immigration or humanitarian protection in the US, as well as all individuals whom the Department of Homeland Security law enforcement officers might come across in the course of their border and immigration work.
However, there are concerns about how the data could be used, leading to calls for safeguards to be included in any agreement.
In December 2025, the Council authorised the European Commission to negotiate a framework agreement that would set out the legal basis and conditions for the reciprocal exchange of information between the competent authorities of EU countries and the US. Under this agreement, EU countries could then negotiate bilateral agreements with the US to exchange information from their national information technology systems. However, the framework agreement would not apply to Ireland, as it is not part of the Schengen area, or Denmark, as it has an opt-out from the area of freedom, security and justice. The agreement could, however, apply to Ireland following an EU notification to the US.
Negotiations were completed on 23 July 2026.The European Parliament will now be asked to give its consent to the framework agreement. Once that happens, the Council could adopt a decision to conclude the agreement.
Legal basis
The legal bases for the framework agreement are Articles 16(2) and 77(2) of the Treaty on the Functioning of the European Union (TFEU).
Article 16(2) provides the constitutional legal basis for EU data protection legislation. It empowers the European Parliament and the Council to establish rules on the protection of individuals with regard to the processing of personal data by EU institutions, bodies, offices and agencies, and by Member States when acting within the scope of EU law, as well as rules on the free movement of personal data. Compliance with these rules is overseen by independent authorities.
Article 77(2) provides a legal basis for EU measures on the management of external borders. It enables the European Parliament and the Council to adopt measures concerning external border checks, short-stay visas and residence permits, the conditions under which third-country nationals may travel freely within the EU for a short period, the gradual development of an integrated external border management system, and the absence of controls on persons at internal borders.
Main points of the framework agreement
The agreement concerns the exchange of personal data between the US and EU countries if it is believed that someone's entry or stay would pose a serious and genuine risk to public security or public order.
An automated exchange of information is possible only as needed to identify a person in line with the principles of necessity and proportionality. A request for more information can be submitted; however, such a request would always have to be assessed by a human and the agreement sets out which grounds can be used to refuse such a request.
The first step would be the exchange of information through an automated query. This query could be sparked because there are indications of identity fraud or misuse of identity; doubts about the authenticity and validity of the travel documents; or signs that an application for a visa includes fraudulent or false information. It could also be because of risk assessments or scenarios identifying risk based on trend analysis of suspicious activity, law enforcement cases, or criminal intelligence. As part of the request, personal information included in the travel document or application can be sent, such as the full name, date of birth, national ID number, and/or the person’s fingerprints. If there is a match in the other database, then the other competent authority sends out an automated response to confirm the match as well as send alphanumeric data to identify the person, such as first name, last name, and date of birth.
The authority receiving the request should then assess if the person would pose a serious and genuine risk to public security or public order. This would be based on factors such as terrorist threats or immigration violations, criminal convictions, as well as their nature, seriousness and timing.It could then inform the other authority that it holds information of potential interest concerning a serious and genuine risk, and indicate the relevant factors.
If there is a match and procedures have been followed, the authority that sent out the initial request can ask for additional information. The exchange of additional information, including which national information systems can be used, the categories of information that can be transferred and the procedures for the transfer is up to EU countries to negotiate with the US in their bilateral agreements on this.
Special categories of personal information can only be transferred if the information is relevant to the serious and genuine risk to public security or public order. These categories include information revealing racial or ethnic origin, political opinions or religious or other beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, and personal information concerning health or sexual life. The processing of this information is also subject to safeguards, for example protective measures such as limiting access to authorised personnel or restricting the purposes for which the information may be processed.
A request can be refused if the response would put ongoing investigations at risk, conflict with applicable domestic law or international obligations, or prejudice sovereignty, security or public order of the state receiving the request. The state receiving the request may also impose additional conditions.
The personal information that has been received can only be forwarded to international organisations or other countries if the country sending the information agrees.
Personal data should only be kept as long as is needed and appropriate. At least once a year there should be a review of the retention period.
The agreement aims to meet the EU's principle of reciprocity for its visa policy with non-EU countries. If the citizens of a non-EU country benefit from visa-free travel to the EU, then EU citizens should be able to travel to that country without a visa as well. As part of the agreement, EU countries would be able to stop the exchange of information should the US not allow visa-free travel for its citizens. The agreement foresees reciprocity regarding maximum volume limits, type, and quality of the information exchanged.
Safeguards have been added to the framework agreement in a bid to meet the requirements under EU data protection laws, such as General Data Protection Regulation (GDPR), as well as Article 7 (respect for private and family life) and Article 8 (protection of personal data) of the Charter of Fundamental Rights of the EU. The agreements include provisions to ensure data protection principles and obligations that both the US and EU countries are required to respect.
Because of the tight deadline – the US wants to conclude negotiations by December 2026 – the Commission proposes to apply the agreement on a provisional basis as soon as possible.
Current visa situation
The citizens of all EU countries except Bulgaria, Cyprus and Romania enjoy visa-free travel to the US. The EU aims to ensure that all EU citizens are able to travel to the US without needing a visa.
Different approaches to personal data
The EU and the US have fundamentally different approaches to personal data privacy. The EU views it as a fundamental right, covered by the Charter's Articles 7 and 8 . To protect these rights, the EU has passed comprehensive data protection laws, including the GDPR, the Law Enforcement Directive (LED) and the ePrivacy Directive. Personal data can only be processed under certain conditions.
US federal law considers the protection of personal data more of a consumer protection issue. Instead of an overarching piece of legislation, there is a patchwork of federal legislation covering specific sectors, such as education, healthcare and finance, as well as privacy laws at state level. Often action is triggered only when harm occurs, such as discriminatory treatment or financial loss.
By contrast, EU citizens have more control over their data, and they need to give consent before their data can be used. They can also access their data and ask for them to be restricted or deleted. In the US, data can generally be collected unless the person involved explicitly rejects this (although California does offer its residents some rights that are similar to those in the EU).
The GDPR sets strict fines for violations, which can total 4 % of a company's global annual revenue, and every EU country has established an independent data protection authority responsible for its enforcement. In the US, fines tend to be lower and enforcement more fragmented, as responsibility lies with either a federal agency or state attorneys-general.
What EU data rules say about biometric data
The EBSP agreement must comply with EU fundamental rights requirements, as well as Article 16 of the Treaty on the Functioning of the European Union on the right to the protection of personal data.
EU secondary law and European Court of Justice case law on data protection and artificial intelligence (AI) can provide meaningful insights into how the EU views the processing of biometric data.
The EU's GDPR legislation defines biometric data as 'personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data'.
Article 9 of the GDPR specifies that the processing of 'biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited'. The article then describes the strict conditions under which this ban may be lifted. However, it also mentions that EU countries can maintain or introduce further conditions, including limitations, with regard to the processing of genetic, biometric or health data.
The sensitivity of processing biometric data and the need for increased protection are further reflected in the EU's Artificial Intelligence Act, which prohibits, and stipulates specific requirements for, AI systems that process biometric data in specific contexts.
Case law
European Court of Justice
The framework agreement would have to be in line with the Charter of Fundamental Rights, including Articles 7, 8, 11 (freedom of expression and information), 47 (right to an effective remedy and to a fair trial), and 52 (scope and interpretation).
In its case-law on personal data protection, the Court of Justice of the European Union (CJEU) has consistently stated that interference with the rights to the protection of personal data and respect for private life must be justified by objectives of general interest recognised by the EU or the need to protect the rights and freedoms of others. Any such interference must be provided for by law, respect the essence of data protection and privacy, and comply with the principles of necessity and proportionality, For example, in its ruling on joined cases C‑511/18, C‑512/18 and C‑520/18, the Court said that:
The rights enshrined in Articles 7, 8 and 11 of the Charter are not absolute rights, but must be considered in relation to their function in society.
In Case C‑817/19 regarding the Passenger Name Directive, the CJEU said that the transfer, processing and retention of passenger name record data provided for by the directive may be regarded as being limited to what is strictly necessary for the purposes of combating terrorist offences and serious crime, provided that the powers provided for by that directive are interpreted restrictively.
In its opinion 1/15 regarding an agreement to exchange passenger name records with Canada, the Court found that the agreement was not acceptable in its current form, and stated that the data collection for this should be limited to what is strictly necessary to achieve the goal of safeguarding public security.
The CJEU has elaborated on the requirements for the automated analysis of passenger information.
European Court of Human Rights
The European Court of Human Rights (ECHR) has also issued important rulings on the use of personal data, including biometric data, especially under Article 8 (right to respect for private and family life) and Article 10 (freedom of expression) of the European Convention of Human Rights.
In S and Marper v the United Kingdom, the Court made a distinction between the retention of fingerprints and the retention of cellular samples and DNA profiles, as the latter has a greater impact on private life due to the information they contain. Retaining fingerprints is also considered an infringement of the right to respect for private life and should only be undertaken if it is justified.
In Glukhin v Russia , involving the use of facial recognition technology, the ECHR noted the fundamental importance of the right to privacy and the need for safeguards in domestic law to protect it:
The need for such safeguards is all the greater where the protection of personal data undergoing automatic processing is concerned, not least when such data are used for police purposes, and especially where the technology available is continually becoming more sophisticated. The protection afforded by Article 8 of the Convention would be unacceptably weakened if the use of modern scientific techniques in the criminal-justice system were allowed at any cost and without carefully balancing the potential benefits of the extensive use of such techniques against important private-life interests.
One of the issues in the case Willems v the Netherlands was whether the biometric data collected to produce a passport, as set out in Regulation 2252/2004, could be collected, processed or used for other purposes. The ECHR said the regulation did not apply in this case and ruled against the applicant.
Concerns over the protection of personal data
European Data Protection Supervisor
In September 2025, the European Data Protection Supervisor (EDPS) issued an opinion on the recommendation for a Council decision to start negotiations on the framework agreement for the EBSP. The EDPS noted that this would be the first agreement by the EU with a third country to involve the large-scale sharing of personal data, including biometric data such as fingerprints, for the purpose of border and immigration controls. As such, it stressed the need to ensure that the processing of personal data involved did not exceed the limits of what was strictly needed and proportionate. It therefore recommends defining the personal and material scope of envisaged data-sharing as narrowly as possible. There is also a need for accountability mechanisms and the availability of judicial redress in the US regardless of citizenship.
The EDPS regretted that the Commission had not commissioned an impact assessment, which it felt would have been 'fully justified' due to the 'subject matter and the expected significant impact on the fundamental rights of a large number of individuals'.
Statewatch
Statewatch has been following discussions on the EBSP since 2022. It voiced its concerns on the website of European Digital Rights (EDRi), a European network defending rights and freedoms online. Statewatch Director Chris Jones pointed out that the European Court of Justice had on various occasions1 ruled that the US does not offer adequate privacy protections for non-citizens, and so questioned whether EU countries should open up their biometric databases. He also called for more transparency on the discussions taking place.
On 23 July 2026, in an open letter signed by Statewatch and coordinated by European Digital Rights, organisations and academics called on the Council to reject the US' 'excessive demands' regarding the proposed data exchange:
We call on the Council to push back against the excessive demands of the US Government, which can be seen as nothing less than pressure tactics, and uphold vital EU legal protections. People's personal data, especially their biometric data, should not be up for sale, especially to a country responsible for increasing human rights violations and with a fast democratic backsliding.
The letter was based on a leaked draft of the agreement and preceded the Commission's publication of the final text of the draft agreement on 10 September 2026.
0n 24 August 2026, Statewatch published another statement about the proposed agreement on its website, voicing concerns that the agreement could enable the US to target activists or engage in racial profiling . The organisation called the draft agreement a 'bad deal' and said there were 'serious conflicts' with EU law:
In its rush to get a deal done, [the European Commission] seems to want to allow any data the US wants to be exchanged freely, with no further protection. Aside from the obvious privacy implications, this places the Commission’s stance in direct contradiction with EU law, which generally prohibits the use of citizens' data in the way the US wants.
European Center for Digital Rights
The European Center for Digital Rights, an NGO known under the abbreviation noyb ('none of your business'), has previously raised concerns over the transfer of EU data to the US. For example, in a criticism of the Trans-Atlantic Data Privacy Framework, it pointed out that US legislation does not offer non-US citizens reasonable privacy protections. In another article it highlighted that the independence of the Federal Trade Commission, an independent US agency responsible for safeguarding consumer privacy, could no longer be guaranteed under the current president. Its critical stance has also been echoed by other digital rights advocacy organisations.
The role of the European Parliament
As it is an international agreement, the framework agreement will have to be approved by the European Parliament as well as the Council before it can enter into force.
Parliament has always been keen to highlight the importance of protecting personal data. For example, in 2010, MEPs rejected an EU‑US agreement on banking data transfers via the SWIFT network, citing concerns about privacy, reciprocity and proportionality. This led to safeguards being added to the agreement, which was approved by Parliament later that year.
Examples of existing EU‑US agreements for the exchange of data
The EU and the US already have agreements in place for exchanging data in various circumstances, for example the EU‑US umbrella agreement, which is a comprehensive, high-level data protection framework for EU‑US law enforcement cooperation.
Other examples are the PNR Agreement (regarding data on air passengers) and the TFTP Agreement (terrorist finance tracking programme).
Examples of US agreements with non‑EU countries for sharing biometric data
Information on US biometric data-sharing agreements is not widely available, especially in relation to the EBSP, as many countries prefer to keep the discussions confidential due to their sensitive nature.
The US already has an agreement for sharing biometric data with the members of the Five Country Conference (now known as Migration 5), an international forum for cooperation on immigration matters. In addition to the US, its members are Australia, Canada, New Zealand and the United Kingdom. Biographical data, such as names and other personal details, are only shared in case of a fingerprint match. Moreover, the countries involved do not share their own citizens' data.
The EBSP would go beyond that to allow the US Department of Homeland Security to routinely screen against the biometric databases of partner countries.
New Zealand has already confirmed that it is in talks with the US about the EBSP. During a debate in the Australian Senate on 4 March 2026, it was confirmed that Australia does not currently share the biometric data of Australian citizens applying for a US visa with US authorities, and that the government had not made any commitments regarding the EBSP with the US.
A 2024 freedom of information request confirmed that the UK was in discussions with the US about allowing US authorities to check the fingerprints of UK citizens applying for a US visa. However, in February 2026, the Information Commissioner's Office, the UK’s independent regulatory body responsible for upholding information rights, data privacy and freedom of information, was unable to confirm whether the UK was negotiating an EBSP agreement with the US. The Canadian government has not stated whether it is in talks with the US regarding the EBSP.
The US has an agreement with Israel that includes the sharing of biometric data, in addition to one with Chile, and reportedly also with Ecuador.
Main references
- Mildebrath, H., Understanding EU data protection policy, EPRS, European Parliament, January 2026.
- Monteleone, S., GDPR goes live: A modern data protection law, EPRS, European Parliament, 2018.
Endnotes
Classification
Policy areas: Area of Freedom, Security and Justice
Committees: Civil Liberties, Justice and Home Affairs (LIBE)
Statement on the use of AI
Any AI-generated content in this text has been reviewed by the author.
Disclaimer
This document is prepared for, and addressed to, the Members and staff of the European Parliament as background material to assist them in their parliamentary work. The content of the document is the sole responsibility of its author(s) and any opinions expressed herein should not be taken to represent an official position of the Parliament.
Copyright
© European Union.
The reuse of this document is authorised under a Creative Commons Attribution 4.0 International (CC-BY 4.0) licence.
https://creativecommons.org/licenses/by/4.0/deed.en
To use or reproduce elements that are not owned by the European Union, permission may need to be sought directly from the respective rightsholders.