Worldcoin Ordered to Delete Biometric Data Following GDPR Ruling
The Bavarian State Office for Data Protection Supervision (BayLDA) has issued significant corrective measures targeting World, formerly known as Worldcoin, concerning the handling of biometric data collected through its digital identity project. The ruling, announced on December 19th, stems from an investigation initiated in 2023 due to concerns over the collection and processing of user iris data. World, a project spearheaded by Tools for Humanity (TFH) and co-founded by OpenAI CEO Sam Altman, employs iris biometrics for digital identity verification. In response to the BayLDA’s concerns, World temporarily halted its activities across several EU countries.
BayLDA’s focus centers on ensuring compliance with the European Union’s General Data Protection Regulation (GDPR). The authority’s decision prioritizes strengthening the rights of World ID users, granting them the unrestricted capability to exercise their right to erasure – essentially, the ability to have their data completely deleted. BayLDA president Michael Will emphasized this commitment, stating, “With today’s decision, we are enforcing European fundamental rights standards in favor of the data subjects in a technologically demanding and legally highly complex case.”
The core of the ruling involves a mandated data deletion procedure. World must establish a compliant process for removing data, a requirement that encompasses iris code records gathered from July 2023 through the present. Furthermore, BayLDA necessitates explicit consent for specific data processing steps going forward. The order also mandates the deletion of “previously collected without a sufficient legal basis” data records. As Michael Will explained, “The order aims at all those sets of iris codes from its customers which were gathered in the starting phase in summer 2023 until a certain point in this year, where Worldcoin changed its activities to a more lawful basis.”
Adding another layer to the regulatory scrutiny, BayLDA has requested World to actively seek clarity on the legal definition of anonymization within the EU. The organization contends that the current GDPR lacks a precise definition, a situation the World Foundation and TFH believe is critical to address, particularly in the context of advancements in artificial intelligence. Damien Kieran, TFH’s chief legal and privacy officer, highlighted this point, asserting, “Data anonymization, not just data deletion, is essential for enabling people to verify themselves as human online while remaining completely private.” He underscored the importance of a clear legal framework to protect privacy amid the growing influence of AI.
The World Foundation and TFH are appealing BayLDA’s decision, requesting judicial clarity on whether World’s technology meets the legal standards for anonymization. They assert a commitment to collaborating closely with regulators across the EU and globally, aiming for a resolution that supports privacy and innovation. This ongoing pursuit of legal definition reflects a wider concern regarding the intersection of biometric data, digital identity, and the evolving landscape of data protection regulations. The challenges underscore the need for adaptation in a rapidly changing technological environment.