Privacy

Worldcoin faces pivotal EU privacy decision within weeks

Comment

Worldcoin plans to resume iris scans in Kenya soon
Image Credits: JUAN MABROMATA/AFP via Getty Images / Getty Images under a license.

The next few weeks could be pivotal for Worldcoin, the controversial eyeball-scanning crypto venture co-founded by OpenAI’s Sam Altman, whose operations remain almost entirely shuttered in the European Union following a series of privacy complaints — including in France, Germany, Portugal and Spain.

The only EU market where Worldcoin is still scanning eyeballs according to the Worldcoin.org website is Germany, where its developer Tools for Humanity (TfH) has a local office. But that could change imminently depending on the outcome of an investigation instigated by Bavaria’s data protection authority.

The authority told TechCrunch it expects to reach a decision on the probe soon — a spokesman suggested it will be ready to publish its conclusions in mid July. The watchdog began looking into Worldcoin last year following its global launch in July 2023.

“Taking into account further steps to align with other SA’s [supervisory authorities] I currently expect results that we are able to use in public in mid July 2024,” he told us.

In the EU, complaints have been raised that Worldcoin is breaching the bloc’s General Data Protection Regulation (GDPR), which sets rules for how personal data may be processed. The regime not only gives supervisory authorities, aka data protection authorities (DPAs), powers to issue fines of up to 4% of global annual turnover for confirmed breaches. They can also order non-compliant processing to stop.

That’s important because in the case of a crypto-biometrics project like Worldcoin — which turns a person’s eyeball scan into an immutable identity token stored on a decentralized blockchain — it may mean setting conditions that essentially bar it from the EU for good. Unless Worldcoin is able to revise its system to allow for personal data to be deleted on request. But, er, blockchains don’t typically work like that.

Other GDPR concerns attached to Worldcoin include the legal basis it claims for processing people’s sensitive biometric data for its identification purpose; and whether it’s meeting the regulation’s transparency and fairness requirements.

A key criticism of its approach is that it incentivizes people to hand over their sensitive biometric data in exchange for the eponymous cryptocurrency baked into the proof of “humanness” identity system it’s devised — whereas the GDPR requires consent to data processing to be freely given.

Fears that Worldcoin is posing risks to children have also driven some EU regulators to slap temporary bans on its operations in their own markets this year, after complaints Worldcoin operators had scanned minors’ eyeballs.

Back in March Spain’s DPA took such emergency action — ordering Worldcoin to stop collecting and processing locals’ data for up to three months. It said it was acting on a number of privacy complaints, including about risks to children’s information. The move was quickly followed by a similar order by Portugal’s DPA also acting on complaints Worldcoin had scanned minors’ eyeballs.

Despite these urgent interventions, German privacy regulators have allowed Worldcoin to continue scanning eyeballs in the market while the Bavarian DPA investigates. Although the below image of a Worldcoin scanning location in Berlin — embedded in a post on X — is notable for including a prominent poster in the window displaying an 18+ age limit for submitting irises to the orb.

On Tuesday the Spanish DPA announced that Worldcoin has agreed not to relaunch its operations in the market once its three-month ban order expires shortly. In a press release, it said Worldcoin’s developer has committed — in what it described as “a legally binding manner” — not to resume its activity in Spain until the Bavarian authority has adopted a final resolution on the investigation (or else not before the end of the year).

TfH had initially sought to challenge Spain’s temporary ban in the courts, including by seeking an injunction (which it was not granted). It’s not clear why the company has agreed to wait for the outcome of the Bavarian investigation but it may have decided it’s the best course of action to reduce its regulatory risk. It may also feel confident it won’t have too long to wait for a decision.

The Spanish authority’s press release contains another interesting tidbit — suggesting that following its emergency order TfH announced changes to Worldcoin’s operation which it said included the introduction of controls to verify the age of users; and “the possibility of eliminating the iris code”.

TfH was contacted with questions about its agreement with Spain’s DPA and changes it’s committed to. Company spokeswoman, Rebecca Hahn, pointed us to a statement on Worldcoin’s website — in which the company writes that it has “committed not to perform orb operations in Spain through the end of calendar year 2024, or if sooner, until the BayLDA [Bavarian DPA] consultation process with other EU data protection authorities is concluded”.

Worldcoin’s statement also flags what TfH refers to as a series of privacy and security measures” which it says have been implemented in recent months aimed at addressing DPAs’ concerns. It said this includes “advanced controls for age verification, the deletion of old iris codes by transforming them into SMPC [Secure Multi-Party Computation] shares, optional World ID unverification (including the ability to delete iris codes) and more”.

It is not clear whether transforming iris codes into SMPC shares would constitute deletion of the data under the GDPR.

In its statement, Spain’s DPA said it expects the Bavarian data protection authority’s investigation to be concluded “soon” — adding that it anticipates the final decision to reflect the positions of all concerned European supervisory authorities.

Should there be disputes between DPAs over what to do about Worldcoin, it’s worth noting the GDPR contains a mechanism for handling cross-border complaints that allows concerned authorities to raise objections. If a majority way forward still cannot be found the European Data Protection Board may be asked to step in and make the final call.

This report was updated to include Worldcoin’s statement

More TechCrunch

Ola Electric, India’s largest electric two-wheeler maker, saw its shares rise as much as 20% on its public debut on Friday, making it the biggest listing among Indian firms in…

Ola Electric surges in India’s biggest listing in two years

Rocket Lab surpassed $100 million in quarterly revenue for the first time, a 71% increase from the same quarter of last year. This is just one of several shiny accomplishments…

Rocket Lab’s sunny outlook bodes well for future constellation plans 

In 1996, two companies, Patersons HR and Payroll Solutions, formed a venture called CloudPay to provide payroll and payments services to enterprise clients. CloudPay grew quietly over the next several…

CloudPay, a payroll services provider, lands $120M in new funding

The vulnerabilities allowed one security researcher to peek inside the leak sites without having to log in.

Security bugs in ransomware leak sites helped save six companies from paying hefty ransoms

Featured Article

A comprehensive list of 2024 tech layoffs

The tech layoff wave is still going strong in 2024. Following significant workforce reductions in 2022 and 2023, this year has already seen 60,000 job cuts across 254 companies, according to independent layoffs tracker Layoffs.fyi. Companies like Tesla, Amazon, Google, TikTok, Snap and Microsoft have conducted sizable layoffs in the…

A comprehensive list of 2024 tech layoffs

A new “beta rabbit” mode adds some conversational AI chops to the Rabbit r1, particularly in more complex or multi-step instructions.

Rabbit’s r1 refines chats and timers, but its app-using ‘action model’ is still MIA

Los Angeles is notorious for its back-to-back traffic. Three events that promise to bring in millions of spectators from around the world — the 2026 World Cup, the Super Bowl…

Archer to set up air taxi network in LA by 2026 ahead of World Cup

Featured Article

Amazon is fumbling in India

Amazon’s decision to overlook quick-commerce in India is now looking like a significant misstep.

Amazon is fumbling in India

OpenAI’s GPT-4o, the generative AI model that powers the recently launched alpha of Advanced Voice Mode in ChatGPT, is the company’s first trained on voice as well as text and…

OpenAI finds that GPT-4o does some truly bizarre stuff sometimes

On Thursday, Box filled in a missing piece on its AI platform when it bought automated metadata extracting startup, Alphamoon.

Box adds crucial piece to its AI platform with Alphamoon acquisition

OpenAI has announced a new appointment to its board of directors: Zico Kolter. Kolter, a professor and director of the machine learning department at Carnegie Mellon, predominantly focuses his research…

OpenAI adds a Carnegie Mellon professor to its board of directors

Count Spotify and Epic Games among the Apple critics who are not happy with the iPhone maker’s newly revised compliance plan for the European Union’s Digital Markets Act (DMA). Shortly…

Spotify and Epic Games call Apple’s revised DMA compliance plan ‘confusing,’ ‘illegal’ and ‘unacceptable’

Thursday seeks to shake up conventional online dating in a crowded market. The app, which recently expanded to San Francisco, fosters intentional dating by restricting user access to Thursdays. At…

Thursday, the dating app that you can use only on Thursdays, expands to San Francisco

AI companies are gobbling up investor money and securing sky-high valuations early in their life cycle. This dynamic has many calling the AI industry a bubble. Nick Frosst, a co-founder…

Cohere co-founder Nick Frosst thinks everyone needs to be more realistic about what AI can and cannot do

Instagram is rolling out the ability for users to add up to 20 photos or videos to their feed carousels, as the platform embraces the trend of “photo dumps.” Back…

Instagram is embracing the ‘photo dump’

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Anyone paying…

Lyft ‘opens a can of whoop ass’ on surge pricing, Tesla’s Dojo explained and Saudi Arabia pumps $1.5B into Lucid

Flint Capital just closed its third fund at $160 million. Its has a unique strategy for finding its limited partner investors. 

Flint Capital raises a $160M through an unusual fund-raising strategy

Earlier this week it emerged that the DPC had instigated court proceedings seeking an injunction against X over the data processing without consent.

Elon Musk’s X agrees to pause EU data processing for training Grok

During testing, Google DeepMind’s table tennis bot was able to beat all of the beginner-level players it faced.

Google DeepMind develops a ‘solidly amateur’ table tennis robot

The X account announced that its Premium+ subscription would now be “fully” ad-free, leading some to question how this change would affect creator earnings.

As X sues advertisers over boycott, the app ditches all ads from its top subscription tier

Apple has further revised its compliance plan for the European Union’s Digital Markets Act (DMA) rulebook, which, since March, has forced it to give iOS developers more freedom over how…

Apple revises DMA compliance for App Store link-outs, applying fewer restrictions and a new fee structure

The rise of neobanks has been fascinating to witness, as a number of companies in recent years have grown from merely challenging traditional banks to being massive players in and…

Chime and Dave execs are coming to TechCrunch Disrupt 2024

If you visited the Wikipedia website on mobile this week, you might have seen a pop-up indicating that dark mode is ready for prime time.

How to enable Wikipedia’s dark mode

The home security company says attackers accessed databases containing customer home addresses, email addresses, and phone numbers.

Home security giant ADT says it was hacked

The Looking Glass Pro has a 6-inch display and a foldable base. It shows spatial images like those created with the Apple Vision Pro and iPhone 15 Pro.

Looking Glass’ new lineup includes a $300 phone-sized holographic display

TikTok’s latest offering is capitalizing on the app’s ability to serve as a discovery engine for other media — something its users already take advantage of by sharing short clips…

TikTok partners with Warner Bros. to become a discovery engine for TV and movies

Cocoon is a new startup built on the belief that greener steel production and the creation of concrete slag doesn’t have to be an either/or proposition.

Cocoon is transforming steel production runoff into a greener cement alternative

SoundHound, an AI company that makes voice interface tech used by car companies, restaurants and tech firms, is doubling down on enterprise services by playing consolidator in a crowded market.…

SoundHound acquires Amelia AI for $80M after it raised $189M+

Seeking mental health support is a complex process, but some founders believe that using AI to formalize techniques like cognitive behavioral therapy (CBT) can help folks who might not have…

Feeling Great’s new therapy app translates its psychiatrist co-founder’s experience into AI

The U.K.’s antitrust regulator has confirmed that it’s carrying out a formal antitrust investigation into Amazon’s ties with Anthropic, after Amazon recently completed a $4 billion investment into the AI startup.…

UK launches formal probe into Amazon’s ties with AI startup Anthropic