EU-US Traveller Data Deal Heads for Scrutiny

By The European Times | Created at 2026-09-11 09:37:03 | Updated at 2026-09-11 10:58:39 1 hour ago

Draft framework links visa-free travel to new security exchanges while leaving decisive privacy limits to later national agreements The European Commission…

Draft framework links visa-free travel to new security exchanges while leaving decisive privacy limits to later national agreements

The European Commission has proposed a framework for exchanging traveller information with the United States, seeking to preserve visa-free transatlantic travel while establishing common data-protection rules. The proposal could enable automated identity and fingerprint queries, followed by more detailed exchanges when a security match is confirmed. It does not itself authorise access to national databases, but it would shape the bilateral agreements that determine which information is ultimately shared.

The Commission presented the draft on 10 September after negotiating with Washington under a mandate granted by EU governments in December 2025. The initiative responds to a US requirement that countries participating in the Visa Waiver Program establish an Enhanced Border Security Partnership by the end of 2026.

The programme allows citizens of participating countries to travel to the United States without a visa for stays of up to 90 days. That convenience now gives Washington considerable leverage as European institutions consider whether greater information exchange can be reconciled with EU privacy law.

A framework, not immediate database access

The most important limitation is contained in the Commission’s proposed framework agreement: the instrument would not, by itself, provide a legal basis for transferring personal information.

Exchanges could occur only under separate bilateral agreements between the United States and individual EU countries. Those agreements would have to identify the national information systems involved, specify the categories of information available and establish procedures and volume limits.

This distinction matters. Brussels has negotiated the common architecture, but the practical reach of the system would depend on country-by-country decisions that have not yet been made public.

The draft covers EU citizens, US nationals and third-country nationals. Denmark is excluded under its position on the Schengen acquis, while the framework would apply to Ireland only if the EU subsequently notified the United States.

How the screening process would work

The proposal establishes a two-stage process. During a border check or the assessment of a visa or travel-authorisation application, an authority could submit an automated query when there is reason to believe that the person may present a serious and genuine risk to public security or public order.

Possible grounds include suspected identity fraud, doubts about travel documents, apparently false application information or risk assessments based on suspicious activity and criminal intelligence. A connection must also exist between the traveller and the country being queried, such as citizenship, residence or a previous stay.

The initial query could contain biographical details, a national identification number or fingerprints. A positive match could return confirmation of the match, basic identity information and, where domestic law permits, a photograph.

A second request could then seek additional information from databases named in the bilateral agreement. This stage would require a human assessment by the authority holding the records. Special-category information, which the framework defines as potentially including political opinions, religious beliefs, health information and details concerning sexual life, could generally be transferred only when particularly relevant to the security purpose. Biometric data used to identify a person are treated separately.

Safeguards carry significant qualifications

The agreement contains protections concerning accuracy, information security, access, correction and administrative or judicial redress. It requires independent oversight, prohibits arbitrary discrimination and says information should be relevant and no broader than necessary.

Authorities transferring data onward to a third country or international organisation would normally need the prior consent of the authority that originally supplied it. Retention periods would have to be specified in the applicable legal framework and reviewed at least annually.

However, several protections depend on domestic implementation. The provision governing automated decisions does not create an absolute prohibition: a decision causing significant adverse consequences could still rely solely on automated processing when domestic law authorises it and safeguards include the possibility of obtaining human intervention.

Transparency may also take the form of a general published notice rather than direct notification to each affected traveller. Access to records can be restricted for national security, law-enforcement or investigative reasons. For a person wrongly matched at an airport, the practical value of redress will depend on how quickly an authority can identify and correct the error.

These questions echo concerns surrounding Europe’s own expanding biometric border infrastructure. A recent European Times examination of the Entry/Exit System found that formal rights are effective only when travellers receive understandable information and can obtain timely human assistance.

The decisive negotiations come next

The proposal now enters an institutional process. The Council must decide whether to authorise signature and provisional application. The European Parliament’s consent would be required before the agreement could be formally concluded.

The political debate is likely to focus less on the principle of border-security cooperation than on the breadth and enforceability of its limits. Reporting on the negotiations has already identified concern among lawmakers and national governments over sensitive information and the scope of future US access.

The year-end American deadline adds urgency, but it should not reduce parliamentary scrutiny to a choice between unrestricted data exchange and the loss of visa-free travel. The framework expressly relies on reciprocity, necessity and proportionality. Those principles will need measurable expression in every bilateral agreement.

Governments should therefore disclose which databases they intend to connect, the maximum number of queries, the rules governing false matches and the authorities responsible for complaints. Regular statistics should show how often queries are made, how many produce matches and whether those matches lead to adverse travel decisions.

Protecting visa-free travel is a legitimate public objective, as is identifying people who present a demonstrable security risk. The credibility of the agreement will nevertheless depend on whether security cooperation remains targeted, contestable and subject to effective independent supervision. The framework sets the boundaries on paper; the bilateral negotiations will reveal how much protection those boundaries provide in practice.

Read Entire Article