Privacy

Worldcoin hit with another ban order in Europe citing risks to kids

Comment

Worldcoin Project Co-founders Alex Blania (L) and Sam Altman (R)
Image Credits: Worldcoin (opens in a new window)

Controversial crypto biometrics venture Worldcoin has been almost entirely booted out of Europe after being hit with another temporary ban — this time in Portugal. The order from the country’s data protection authority comes hard on the heels of a similar-looking three-month stop-processing order from Spain’s DPA earlier this month.

Portugal was one of just two European countries left where Worldcoin was still operating its proprietary eyeball-scanning orbs after Spain’s ban. This leaves Germany as the only market where it’s currently able to harvest biometrics in Europe as privacy watchdogs take urgent action to respond to local concerns.

Portugal’s data protection authority said it issued the three-month ban on Worldcoin’s local ops Tuesday after receiving complaints Worldcoin had scanned children’s eyeballs.

Other complaints cited in its press release announcing the suspension, which it notes was issued Monday, also mirror Spain’s DPA’s concerns — including insufficient information being provided to users about the processing of their sensitive biometric data; and the inability of users to delete their data or revoke consent to Worldcoin’s processing.

The venture’s use of blockchain technology to store tokens derived from scanned biometrics means the system is designed to retain personal data permanently — without recourse for people to erase their information after the fact.

By contrast, EU data protection law gives people in the region a suite of rights over their personal data, including the ability to have data about them corrected, amended or deleted. So there’s an inherent legal conflict with Worldcoin’s approach — even before you consider other problematic issues like the quasi-financial incentive it offers to encourage people to get scanned; the highly sensitive biometric data involved; and its overarching goal of building and operating an identity layer for “humanness”.

The controversial project is backed by Sam Altman, of OpenAI fame, who is simultaneously supercharging the boom in generative AI tools that are making it harder for people to distinguish between artificial (machine-produced) and human activity online in the first place. Next stop: Rent collection on every online human on Earth?

The Portuguese authority, the CNPD, said it took action after receiving “dozens” of complaints about Worldcoin last month.

It estimates more than 300,000 people in Portugal have submitted to having their irises scanned by its proprietary Orbs in exchange for some Worldcoin, a cryptocurrency also devised by the company, noting that the number of locations where it was offering eyeball-scanning almost doubled in six months. It added that the large influx of people trying to take up the offer of cryptocurrency in exchange for an eye-scan led to Worldcoin instigating a pre-booking system for scanning in the market.

On risks to children’s data, the CNPD notes Worldcoin’s orb operators had no age verification in place — suggesting it was not taking robust steps to prevent children from accessing the technology.

“Biometric data qualifies as special data under GDPR [General Data Protection Regulation] and therefore enjoys increased protection, with the risks of its treatment being high,” it wrote [in Portuguese, this is a machine translation]. “On the other hand, minors are particularly vulnerable and are also subject to special protection under national and European law, as they may be less aware of the risks and consequences of the processing of their personal data, as well as their rights.”

The Portuguese authority gave Worldcoin 24 hours to comply with the local stop processing order.

Given the Worldcoin.org website no longer includes Portugal in the dwindling list of countries where eyeball scans can be booked (as noted above Germany is the only European country left, alongside Argentina, Chile, Japan, Singapore and the U.S.) it appears to have complied with the deadline.

Coincidentally or not, Germany is the EU market where Worldcoin developer, Tools for Humanity, has a regional base. Its co-founder, Alex Blania, is also German. Bavaria’s data protection authority, which leads on data protection oversight of the company in some other cases and has been investigating Worldcoin since last year, has yet to take any public intervention despite peer authorities in Southern Europe making urgent interventions to protect citizens in their own markets.

Worldcoin failed to get an injunction against the Spanish order earlier this month, although its appeal against the DPA’s action continues. It’s not clear whether it intends to try to appeal Portugal’s order.

Tools for Humanity (TFH) was contacted for a response to the latest ban order in the EU. Spokeswoman, Rebecca Hahn, has now sent a statement (below) attributed to Jannick Preiwisch, data protection officer, at the Worldcoin Foundation, in which it claims to be “fully compliant with all laws and regulations governing the collection and transfer of biometric data, including Europe’s General Data Protection Regulation”.

“The Worldcoin Foundation has the utmost respect for the role and responsibilities of data protection authorities, in the CNPD in Portugal,” he adds. “Since offering humanness verification services in Portugal, we have been completely transparent and happy to address CNPD’s questions or concerns. The report from CNPD is the first time we are hearing from them regarding many of these matters, including reports of underage sign-ups in Portugal, for which we have zero tolerance for and are working to address in all instances, even if a matter of a few reports.”

We also reached out to the Bavarian DPA for an update on its investigation. A spokesperson for the authority told us its probe remains ongoing. “Based on our role as lead supervisory authority for World Coin Foundation we are in contact with the controller to establish as quick as possible reliable precautionary measures stopping possible misuse of the services and violations of the terms of services,” they added, saying they are currently examining more than 20 complaints from data subjects in Spain which touch on the question of processing minors’ data.

As TFH’s lead DPA, under the one-stop-shop (OSS) mechanism in bloc’s General Data Protection Regulation (GDPR), it is responsible for investigating a number of privacy and data protection complaints about the company.

This structure means the Bavarian DPA will produce a draft decision on its Worldcoin GDPR investigation for peer authorities to review. Other authorities will then have the chance to object if they do not agree with its findings. The regulation requires majority backing for decisions on cross-border cases, which allows for weaker enforcements to be overruled where there is a consensus that stronger measures are warranted. This in turn allows for forum shopping risks inherent to the GDPR’s OSS mechanism to be mitigated, albeit over a longer time-frame.

The GDPR’s Article 66 powers, which Spain is using for its temporary, local ban on Worldcoin, also provide authorities with tools to respond to urgent risks in cases where a lead authority has yet to act and/or is dragging its feet.

However Portugal’s DPA told us it is not relying Article 66 powers in this case. Rather it said it instigated its own volition enquiry into the Worldcoin project, back in August 2023, when it was not clear to it which of the various involved entities was legally responsible for the data processing.

“Based on the declarations provided by both companies… [Cayman Island-based] Worldcoin Foundation presents itself as data controller of the biometric data and other related data processing with the World ID, and [US-based] Tools for Humanity Corporation is the processor for that data processing and it is the controller for the World App data processing,” a spokesperson for the authority told us. “Therefore, since Worldcoin Foundation is the controller of the biometric data from July 24, 2023, and TFH is only the processor, we did not refer any complaint to Germany as the one-stop-shop does not apply to this specific data processing.”

Neither the Spanish nor Portuguese authority has explicitly called out the Bavarian authority for taking too long to investigate TFH. But the fact of other DPAs making their own urgent interventions speaks volumes.

“Given the current circumstances, in which there is an illegality in the processing of biometric data of minors, associated with potential violations of other GDPR standards, the CNPD understood that the risk to citizens’ fundamental rights is high, justifying urgent intervention to prevent serious or irreparable harm,” the Portuguese authority noted, saying it will continue to investigate Worldcoin’s local activity.

In a statement, the CNPD’s president, Paula Meira Lourenço, added: “This order to temporarily limit the collection of biometric data by the Worldcoin Foundation is, at this moment, an indispensable and justified measure to obtain the useful effect of defending the public interest in safeguarding fundamental rights, especially of minors.”

This report was updated with comment from Worldcoin and the Bavarian DPA. We also made a correction after Portugal’s DPA told us it is not relying on the GDPR’s Article 66 powers for its stop-processing order, as we originally reported. It said this is because it identified US- and Cayman Island-based entities attached to the local Worldcoin operations as the responsible entities in this case — meaning the one-stop-shop does not apply 

Worldcoin fails to get injunction against Spain’s privacy suspension

Worldcoin says it’s paused services in Spain, after filing legal challenge to temporary ban

More TechCrunch

Featured Article

CIOs’ concerns over generative AI echo those of the early days of cloud computing

CIOs trying to govern generative AI have the same concerns they had about cloud computing 15 years ago, but they’ve learned some things along the way.

36 mins ago
CIOs’ concerns over generative AI echo those of the early days of cloud computing

It sounds like the latest dispute between Apple and Fortnite-maker Epic Games isn’t over. Epic has been fighting Apple for years over the company’s revenue-sharing requirements in the App Store.…

Epic Games CEO promises to ‘fight’ Apple over ‘absurd’ changes

As deep-pocketed companies like Amazon, Google and Walmart invest in and experiment with drone delivery, a phenomenon reflective of this modern era has emerged. Drones, carrying snacks and other sundries,…

What happens if you shoot down a delivery drone?

A police officer pulled over a self-driving Waymo vehicle in Phoenix after it ran a red light and pulled into a lane of oncoming traffic, according to dispatch records. The…

Waymo robotaxi pulled over by Phoenix police after driving into the wrong lane

Welcome back to TechCrunch’s Week in Review — TechCrunch’s newsletter recapping the week’s biggest news. Want it in your inbox every Saturday? Sign up here. This week, Figma CEO Dylan…

Figma pauses its new AI feature after Apple controversy

We’ve created this guide to help parents navigate the controls offered by popular social media companies.

How to set up parental controls on Facebook, Snapchat, TikTok and more popular sites

Featured Article

You could learn a lot from a CIO with a $17B IT budget

Lori Beer’s work is a case study for every CIO out there, most of whom will never come close to JP Morgan Chase’s scale, but who can still learn from how it goes about its business.

23 hours ago
You could learn a lot from a CIO with a $17B IT budget

For the first time, Chinese government workers will be able to purchase Tesla’s Model Y for official use. Specifically, officials in eastern China’s Jiangsu province included the Model Y in…

Tesla makes it onto Chinese government purchase list

Generative AI models don’t process text the same way humans do. Understanding their “token”-based internal environments may help explain some of their strange behaviors — and stubborn limitations. Most models,…

Tokens are a big reason today’s generative AI falls short

After multiple rejections, Apple has approved Fortnite maker Epic Games’ third-party app marketplace for launch in the EU. As now permitted by the EU’s Digital Markets Act (DMA), Epic announced…

Apple approves Epic Games’ marketplace app after initial rejections

There’s no need to worry that your secret ChatGPT conversations were obtained in a recently reported breach of OpenAI’s systems. The hack itself, while troubling, appears to have been superficial…

OpenAI breach is a reminder that AI companies are treasure troves for hackers

Welcome to Startups Weekly — TechCrunch’s weekly recap of everything you can’t miss from the world of startups. Sign up here to get it in your inbox every Friday. Most…

Space for newcomers, biotech going mainstream, and more

Elon Musk’s X is exploring more ways to integrate xAI’s Grok into the social networking app. According to a series of recent discoveries, X is developing new features like the…

X plans to more deeply integrate Grok’s AI, app researcher finds

We’re about four months away from TechCrunch Disrupt 2024, taking place October 28 to 30 in San Francisco! We could not bring you this world-class event without our world-class partners…

Meet Brex, Google Cloud, Aerospace and more at Disrupt 2024

In its latest step targeting a major marketplace, the European Commission sent Amazon another request for information (RFI) Friday in relation to its compliance under the bloc’s rulebook for digital…

Amazon faces more EU scrutiny over recommender algorithms and ads transparency

Quantum Rise, a Chicago-based startup that does AI-driven automation for companies like dunnhumby (a retail analytics platform for the grocery industry), has raised a $15 million seed round from Erie…

Quantum Rise grabs $15M seed for its AI-driven ‘Consulting 2.0’ startup

On July 4, YouTube released an updated eraser tool for creators so they can easily remove any copyrighted music from their videos without affecting any other audio such as dialog…

YouTube’s updated eraser tool removes copyrighted music without impacting other audio

Airtel, India’s second-largest telecom operator, on Friday denied any breach of its systems following reports of an alleged security lapse that has caused concern among its customers. The telecom group,…

India’s Airtel dismisses data breach reports amid customer concerns

According to a recent Dealroom report on the Spanish tech ecosystem, the combined enterprise value of Spanish startups surpassed €100 billion in 2023. In the latest confirmation of this upward trend, Madrid-based…

Spain’s exposure to climate change helps Madrid-based VC Seaya close €300M climate tech fund

Forestay, an emerging VC based out of Geneva, Switzerland, has been busy. This week it closed its second fund, Forestay Capital II, at a hard cap of $220 million. The…

Forestay, Europe’s newest $220M growth-stage VC fund, will focus on AI

Threads, Meta’s alternative to Twitter, just celebrated its first birthday. After launching on July 5 last year, the social network has reached 175 million monthly active users — that’s a…

A year later, what Threads could learn from other social networks

J2 Ventures, a firm led mostly by U.S. military veterans, announced on Thursday that it has raised a $150 million second fund. The Boston-based firm invests in startups whose products…

J2 Ventures, focused on military healthcare, grabs $150M for its second fund

HealthEquity said in an 8-K filing with the SEC that it detected “anomalous behavior by a personal use device belonging to a business partner.”

HealthEquity says data breach is an ‘isolated incident’

Roll20 said that on June 29 it had detected that a “bad actor” gained access to an account on the company’s administrative website for one hour.

Roll20, an online tabletop role-playing game platform, discloses data breach

Fisker has a willing buyer for its remaining inventory of all-electric Ocean SUVs, and has asked the Delaware Bankruptcy Court judge overseeing its Chapter 11 case to approve the sale.…

Fisker asks bankruptcy court to sell its EVs at average of $14,000 each

Teddy Solomon just moved to a new house in Palo Alto, so he turned to the Stanford community on Fizz to furnish his room. “Every time I show up to…

Fizz, the anonymous Gen Z social app, adds a marketplace for college students

With increasing competition for what is, essentially, still a small number of hard tech and deep tech deals, Sidney Scott realized it would be a challenge for smaller funds like…

Why deep tech VC Driving Forces is shutting down

A guide to turn off reactions on your iPhone and Mac so you don’t get surprised by effects during work video calls.

How to turn off those silly video call reactions on iPhone and Mac

Amazon has decided to discontinue its Astro for Business device, a security robot for small- and medium-sized businesses, just seven months after launch.  In an email sent to customers and…

Amazon retires its Astro for Business security robot after only 7 months

Hiya, folks, and welcome to TechCrunch’s regular AI newsletter. This week in AI, the U.S. Supreme Court struck down “Chevron deference,” a 40-year-old ruling on federal agencies’ power that required…

This Week in AI: With Chevron’s demise, AI regulation seems dead in the water