How data collected at border control is shared is crucial to ensure travellers’ protection in a time where data breaches, hacking, and cyberattacks are common. Collaboration has been initiated between the European Union (EU) and the United States (US), but the EU-US data privacy framework lacks effectiveness in terms of data sharing. This Brief recommends collaboration on stricter standards to enable safer data sharing, specifically concerning governments.
Introduction
AI has revolutionised travelling. It reduces time spent at border control with the creation of automatic passport checks and enhances security by implementing real-time luggage screening for example. The question of data sharing at borders is becoming increasingly important as globalisation and transnational traveling intensifies, and biometric data is collected each day. Sharing of data needs to be regulated to protect human rights, ethics, and privacy of individuals.
Sharing data would have a plethora of benefits, including higher travel liberties by smoothing out the border control processes for passengers (something already done within the EU, which could be extended by sharing data with other countries), and the development of innovations, especially within the field of cybersecurity, leading to better protection against cyber-attacks. However, due to low trust in data sharing, conflicting economic incentives on data sharing at the moment, data is not being reused as much.
While the EU-US Data Privacy Framework aims to facilitate data sharing between both sides of the Atlantic, gaps still remain. Especially, there has been a lack of clarity and trust, mostly due to a variation in ethical standards. The EU has always placed a higher emphasis on individual privacy rights, while the US often prioritises economic benefits and national security considerations. Thus, while this framework works well for data transfers between individual companies, it fails to address data sharing potentials between government bodies, meaning each European country has to collaborate with the US separately. The goal is thus to strengthen the transatlantic relationship by extending the current framework to encompass governments, allowing data sharing at a larger scale.
The Challenge of Biometric Data Sharing
The key issue created by the utilisation of AI-based biometric systems in harvesting personal data at border crossings pertains to the legal, social, and technological problems created by biometric border data sharing between the US and the EU.
- Legally, the right to privacy and protection of personal data is referenced in multiple human rights instruments, rendering violations of data privacy a breach of international law and human rights. In particular, Article 8 of the European Convention on Human Rights stipulates that data privacy is a key right. Further, the EU General Data Protection Regulation (GDPR) imposes harsh penalties on parties violating the biometric data standards of EU citizens and residents. In the US, the Privacy Act of 1974 prohibits federal agencies from disclosing personal information without consent. Due to a lack of coordinated US-EU legal instruments, issues arising during transatlantic data sharing such as privacy violations, security risks, and accountability may remain legally ambiguous and fail to provide the necessary protection to citizens.
- Socially, data breaches may inadvertently harm or create new risks for already-vulnerable populations such as unlawful profiling, bias, and discrimination. In the US, for example, the Immigration and Customs Enforcement has been accused of using AI facial recognition to violate data privacy by tracking down asylum seekers at the US-Mexico border for the purpose of deportation.
- Technologically, problems have emerged surrounding the dependability of these biometric technologies, with a 2015 report from the Automatic Fingerprint Identification System showing that accuracy of biometric information was dependent on physical characteristics such as age, which may impact the reliability of the data shared between the EU and US. Further, there are issues stemming from the lack of a harmonious international approach to data collection at border crossings, such as cross-border incompatibility between systems, and lack of transparency in the event of a data security breach.
To address these concerns, the EU and the US have negotiated the Data Privacy Framework. However, according to a report by the Brookings Institution, this frameworks’ scope does not regulate AI technologies used for border security and thus its applications remain unstandardised between states. In order to effectively facilitate secure and ethical biometric data sharing between the US and EU, further measures are necessary.
Policy Options
In order to develop a well-founded recommendation addressing data-sharing challenges, a comprehensive analysis of various policy alternatives later outlined was conducted. This permitted the evaluation of what would effectively tackle the challenges expressed earlier. Each of these options, although addressing AI challenges in data-sharing, did not fully capture the extent of the issue but they served as a foundation for our recommendation.
The initial policy option involved the creation of a dedicated body responsible for overseeing data-sharing practices and ensuring compliance with privacy regulations. The standardisation of data anonymisation procedures is a crucial element in safeguarding citizen data security. Standardised methods ensure consistency and trust which is especially important in border control considering the overall scepticism over AI. Through homogeneity of privacy regulation, consistent data anonymisation levels across datasets can be reached. This builds trust in the process, as citizens can be more confident their data is truly anonymised. Moreover, different anonymisation methods have varying strengths and weaknesses. Standardisation helps confidence in the outcome and adopt the most robust techniques, making it harder for someone to re-identify individuals from the anonymised data. This mitigates the risk of data breaches or actors piecing together information to reveal identities. To ensure the implementation of such a framework, a body auditing regulation is essential. This can ensure that if sensitive biometric data is shared between the US and EU, such as fingerprint scans collected at borders, it can be done so safely as it cannot be traced back to the citizen it was collected from. However, the issue with this recommendation of anonymisation is that if facial recognition scanning, rather than fingerprints, are collected, there is no way to truly anonymise that data. Additionally, the establishment of a new body is not efficient and only adds bureaucracy and paperwork, compromising the performance we aim to achieve. Efforts might be more productively directed towards strengthening and optimising the functionalities of the existing infrastructure. Not only would it not be time optimal, but significant costs would need to be incurred.
The second policy option evaluated the implementation of a framework of stricter legal regulations and enhanced accountability measures within AI data-sharing legislation in border control. This approach is essential to protect citizens against potential AI misuse. Similarly to the options listed before, such a framework ensures that this data is collected, stored, and used responsibly, minimising privacy risks as well as deterring negative consequences of AI misuse. Clear legal frameworks can establish procedures for handling errors and ensuring individuals have recourse if they are wrongly interpreted by AI. Nonetheless, this option also exhibits limitations in scope. It primarily addresses the negative implications of AI, failing to provide a constructive framework for promoting responsible and efficient data-sharing practices.
Recommendation
As outlined in the problem definition, the key issue is the potential for data protection and privacy breaches if sensitive biometric data were to be shared. This is especially important to address at a time when cyberattacks, hacking, and data breaches are increasingly common.
Taking the existing EU-US Data Protection Framework as a model, the proposal is to initiate a new, government-targeted addition to the existing framework encouraging increased discussion, collaboration, and implementation of stronger data-sharing laws between the US and EU concerning AI biometric data collected at border control. The target organisation for this recommendation is the European Commission due to its existing strong stance towards data protection, as seen in the GDPR. We recommend its collaboration with the US Customs and Border Protection Agency, particularly the Privacy Office, as they already aim to safeguard border-related records that contain personally identifiable information. Each of the steps in the framework will rely on US and EU bodies and their respective representatives coming together in joint discussions to clarify the various elements of this framework.
Therefore, the recommended sequential implementation framework is as follows:
- Provide a collective clarification of the relationship between AI-related biometric data, its usage in border control, and the future of this relationship. Important is also an emphasis on the consideration of ethics and human rights underlining the principle of “do no harm”, particularly when determining whether data sharing is even feasible in a safe and protective manner. This joint discussion will help ensure the US and EU are on the same page when addressing present and future border-related biometric data-sharing considerations.
- Developshared definitions and terminology agreed upon between the EU and the US to create a common understanding of basic concepts related to AI, biometrics, border control, and data protection. This will also ensure shared understanding and set the foundation for the next step in the framework, the creation of joint regulations.
- Negotiate joint regulations addressing the potential of biometric data sharing between the US and the EU. These discussions will need to consider the differing approaches to data protection between the US and EU, especially in light of very strong EU regulatory approaches regarding data protection.
Outline the types of biometric data these regulations should be applied to and to what extent. Similar to the EU’s AI Act that applies different obligations based on the risk level of the particular AI system, this brief suggests different standards based on the level of threat to security posed by each form of biometric data.
This publication was produced by the participants of the year-long Transatlantic Leaders Fellowship Programme by European Horizons. Their policy pitch on ‘EU-US Border Control: Collaboration for AI Biometric Data Sharing’ was selected as a winner of the Public Policy Consultation in Democratic Technology category. Their ideas were subsequently revised by TEPSA and are presented in this brief.
