Privacy

Worldcoin faces pivotal EU privacy decision within weeks

Comment

Worldcoin plans to resume iris scans in Kenya soon
Image Credits: JUAN MABROMATA/AFP via Getty Images / Getty Images under a license.

The next few weeks could be pivotal for Worldcoin, the controversial eyeball-scanning crypto venture co-founded by OpenAI’s Sam Altman, whose operations remain almost entirely shuttered in the European Union following a series of privacy complaints — including in France, Germany, Portugal and Spain.

The only EU market where Worldcoin is still scanning eyeballs according to the Worldcoin.org website is Germany, where its developer Tools for Humanity (TfH) has a local office. But that could change imminently depending on the outcome of an investigation instigated by Bavaria’s data protection authority.

The authority told TechCrunch it expects to reach a decision on the probe soon — a spokesman suggested it will be ready to publish its conclusions in mid July. The watchdog began looking into Worldcoin last year following its global launch in July 2023.

“Taking into account further steps to align with other SA’s [supervisory authorities] I currently expect results that we are able to use in public in mid July 2024,” he told us.

In the EU, complaints have been raised that Worldcoin is breaching the bloc’s General Data Protection Regulation (GDPR), which sets rules for how personal data may be processed. The regime not only gives supervisory authorities, aka data protection authorities (DPAs), powers to issue fines of up to 4% of global annual turnover for confirmed breaches. They can also order non-compliant processing to stop.

That’s important because in the case of a crypto-biometrics project like Worldcoin — which turns a person’s eyeball scan into an immutable identity token stored on a decentralized blockchain — it may mean setting conditions that essentially bar it from the EU for good. Unless Worldcoin is able to revise its system to allow for personal data to be deleted on request. But, er, blockchains don’t typically work like that.

Other GDPR concerns attached to Worldcoin include the legal basis it claims for processing people’s sensitive biometric data for its identification purpose; and whether it’s meeting the regulation’s transparency and fairness requirements.

A key criticism of its approach is that it incentivizes people to hand over their sensitive biometric data in exchange for the eponymous cryptocurrency baked into the proof of “humanness” identity system it’s devised — whereas the GDPR requires consent to data processing to be freely given.

Fears that Worldcoin is posing risks to children have also driven some EU regulators to slap temporary bans on its operations in their own markets this year, after complaints Worldcoin operators had scanned minors’ eyeballs.

Back in March Spain’s DPA took such emergency action — ordering Worldcoin to stop collecting and processing locals’ data for up to three months. It said it was acting on a number of privacy complaints, including about risks to children’s information. The move was quickly followed by a similar order by Portugal’s DPA also acting on complaints Worldcoin had scanned minors’ eyeballs.

Despite these urgent interventions, German privacy regulators have allowed Worldcoin to continue scanning eyeballs in the market while the Bavarian DPA investigates. Although the below image of a Worldcoin scanning location in Berlin — embedded in a post on X — is notable for including a prominent poster in the window displaying an 18+ age limit for submitting irises to the orb.

On Tuesday the Spanish DPA announced that Worldcoin has agreed not to relaunch its operations in the market once its three-month ban order expires shortly. In a press release, it said Worldcoin’s developer has committed — in what it described as “a legally binding manner” — not to resume its activity in Spain until the Bavarian authority has adopted a final resolution on the investigation (or else not before the end of the year).

TfH had initially sought to challenge Spain’s temporary ban in the courts, including by seeking an injunction (which it was not granted). It’s not clear why the company has agreed to wait for the outcome of the Bavarian investigation but it may have decided it’s the best course of action to reduce its regulatory risk. It may also feel confident it won’t have too long to wait for a decision.

The Spanish authority’s press release contains another interesting tidbit — suggesting that following its emergency order TfH announced changes to Worldcoin’s operation which it said included the introduction of controls to verify the age of users; and “the possibility of eliminating the iris code”.

TfH was contacted with questions about its agreement with Spain’s DPA and changes it’s committed to. Company spokeswoman, Rebecca Hahn, pointed us to a statement on Worldcoin’s website — in which the company writes that it has “committed not to perform orb operations in Spain through the end of calendar year 2024, or if sooner, until the BayLDA [Bavarian DPA] consultation process with other EU data protection authorities is concluded”.

Worldcoin’s statement also flags what TfH refers to as a series of privacy and security measures” which it says have been implemented in recent months aimed at addressing DPAs’ concerns. It said this includes “advanced controls for age verification, the deletion of old iris codes by transforming them into SMPC [Secure Multi-Party Computation] shares, optional World ID unverification (including the ability to delete iris codes) and more”.

It is not clear whether transforming iris codes into SMPC shares would constitute deletion of the data under the GDPR.

In its statement, Spain’s DPA said it expects the Bavarian data protection authority’s investigation to be concluded “soon” — adding that it anticipates the final decision to reflect the positions of all concerned European supervisory authorities.

Should there be disputes between DPAs over what to do about Worldcoin, it’s worth noting the GDPR contains a mechanism for handling cross-border complaints that allows concerned authorities to raise objections. If a majority way forward still cannot be found the European Data Protection Board may be asked to step in and make the final call.

This report was updated to include Worldcoin’s statement

More TechCrunch

Amazon has released an all-new version of its Echo Spot ahead of Prime Day, the company announced on Monday. The 2024 version of the Alexa-enabled smart alarm clock costs $79.99,…

Amazon revives its Echo Spot with an upgraded look and improved audio

One of the vendors to benefit from the database boom is Tembo, a startup creating a platform that lets developers deploy different flavors of Postgres.

Tembo capitalizes on the database boom and lands new cash to expand

TechCrunch Disrupt 2024 is set to welcome an impressive lineup of judges for the Startup Battlefield 200 competition, presented this year by Google Cloud. These judges will decide which company…

Mayfield’s Navin Chaddha is coming to TechCrunch Disrupt 2024

Numerous concerns are weighing on the minds of many, whether it’s current global conflicts, climate change or the precarious state of the economy, it is no surprise that the world…

Art therapy app Scribble Journey lets you express emotions through doodles

Pestle addresses the common problem of finding recipes on the web.

Pestle’s app can now save recipes from Reels using on-device AI

These efforts have come as Lucid is looking to start building its Gravity SUV by the end of this year.

Lucid Motors sets new record for EV deliveries as it seeks ‘escape velocity’

Berlin-based food delivery giant Delivery Hero has warned investors it may “ultimately” face an antitrust fine of up to €400 million. The development, reported earlier by Reuters, follows unannounced raids…

Delivery Hero warns it could face €400M antitrust fine

Featured Article

Investors chase wealth tech startups in India as affluent class grows

The high-net-worth and ultra-high-net-worth segments are booming in India, prompting some wealth management firms to aggressively expand their relationship manager networks to capture this market.

16 hours ago
Investors chase wealth tech startups in India as affluent class grows

Featured Article

Seed VCs are turning to new ‘pro rata’ funds that help them compete with the big firms

Three companies with new funds deploy capital to support seed and Series A VCs looking to exercise their pro rata rights.

20 hours ago
Seed VCs are turning to new ‘pro rata’ funds that help them compete with the big firms

Here are the latest companies venturing into the gaming scene and details about each offering, including pricing, examples of titles and supported devices. 

YouTube and LinkedIn have games now, and here’s how you can play them

Featured Article

CIOs’ concerns over generative AI echo those of the early days of cloud computing

CIOs trying to govern generative AI have the same concerns they had about cloud computing 15 years ago, but they’ve learned some things along the way.

1 day ago
CIOs’ concerns over generative AI echo those of the early days of cloud computing

It sounds like the latest dispute between Apple and Fortnite-maker Epic Games isn’t over. Epic has been fighting Apple for years over the company’s revenue-sharing requirements in the App Store.…

Epic Games CEO promises to ‘fight’ Apple over ‘absurd’ changes

As deep-pocketed companies like Amazon, Google and Walmart invest in and experiment with drone delivery, a phenomenon reflective of this modern era has emerged. Drones, carrying snacks and other sundries,…

What happens if you shoot down a delivery drone?

A police officer pulled over a self-driving Waymo vehicle in Phoenix after it ran a red light and pulled into a lane of oncoming traffic, according to dispatch records. The…

Waymo robotaxi pulled over by Phoenix police after driving into the wrong lane

Welcome back to TechCrunch’s Week in Review — TechCrunch’s newsletter recapping the week’s biggest news. Want it in your inbox every Saturday? Sign up here. This week, Figma CEO Dylan…

Figma pauses its new AI feature after Apple controversy

We’ve created this guide to help parents navigate the controls offered by popular social media companies.

How to set up parental controls on Facebook, Snapchat, TikTok and more popular sites

Featured Article

You could learn a lot from a CIO with a $17B IT budget

Lori Beer’s work is a case study for every CIO out there, most of whom will never come close to JP Morgan Chase’s scale, but who can still learn from how it goes about its business.

2 days ago
You could learn a lot from a CIO with a $17B IT budget

For the first time, Chinese government workers will be able to purchase Tesla’s Model Y for official use. Specifically, officials in eastern China’s Jiangsu province included the Model Y in…

Tesla makes it onto Chinese government purchase list

Generative AI models don’t process text the same way humans do. Understanding their “token”-based internal environments may help explain some of their strange behaviors — and stubborn limitations. Most models,…

Tokens are a big reason today’s generative AI falls short

After multiple rejections, Apple has approved Fortnite maker Epic Games’ third-party app marketplace for launch in the EU. As now permitted by the EU’s Digital Markets Act (DMA), Epic announced…

Apple approves Epic Games’ marketplace app after initial rejections

There’s no need to worry that your secret ChatGPT conversations were obtained in a recently reported breach of OpenAI’s systems. The hack itself, while troubling, appears to have been superficial…

OpenAI breach is a reminder that AI companies are treasure troves for hackers

Welcome to Startups Weekly — TechCrunch’s weekly recap of everything you can’t miss from the world of startups. Sign up here to get it in your inbox every Friday. Most…

Space for newcomers, biotech going mainstream, and more

Elon Musk’s X is exploring more ways to integrate xAI’s Grok into the social networking app. According to a series of recent discoveries, X is developing new features like the…

X plans to more deeply integrate Grok’s AI, app researcher finds

We’re about four months away from TechCrunch Disrupt 2024, taking place October 28 to 30 in San Francisco! We could not bring you this world-class event without our world-class partners…

Meet Brex, Google Cloud, Aerospace and more at Disrupt 2024

In its latest step targeting a major marketplace, the European Commission sent Amazon another request for information (RFI) Friday in relation to its compliance under the bloc’s rulebook for digital…

Amazon faces more EU scrutiny over recommender algorithms and ads transparency

Quantum Rise, a Chicago-based startup that does AI-driven automation for companies like dunnhumby (a retail analytics platform for the grocery industry), has raised a $15 million seed round from Erie…

Quantum Rise grabs $15M seed for its AI-driven ‘Consulting 2.0’ startup

On July 4, YouTube released an updated eraser tool for creators so they can easily remove any copyrighted music from their videos without affecting any other audio such as dialog…

YouTube’s updated eraser tool removes copyrighted music without impacting other audio

Airtel, India’s second-largest telecom operator, on Friday denied any breach of its systems following reports of an alleged security lapse that has caused concern among its customers. The telecom group,…

India’s Airtel dismisses data breach reports amid customer concerns

According to a recent Dealroom report on the Spanish tech ecosystem, the combined enterprise value of Spanish startups surpassed €100 billion in 2023. In the latest confirmation of this upward trend, Madrid-based…

Spain’s exposure to climate change helps Madrid-based VC Seaya close €300M climate tech fund

Forestay, an emerging VC based out of Geneva, Switzerland, has been busy. This week it closed its second fund, Forestay Capital II, at a hard cap of $220 million. The…

Forestay, Europe’s newest $220M growth-stage VC fund, will focus on AI