EU Forces Sam Altman’s Worldcoin to Delete Biometric Data
In a major blow to Sam Altman’s biometric crypto venture, the Bavarian State Office for Data Protection Supervision issued a corrective order in late December requiring World (formerly Worldcoin) to allow European Union users to comprehensively delete their iris scan data to comply with the General Data Protection Regulation (GDPR).
This landmark ruling under the EU’s strict privacy framework—which carries potential fines of up to 4% of a company’s global annual turnover—demands that the eyeball-scanning digital identity project establish a compliant deletion process. Michael Will, president of the Bavarian State Office for Data Protection Supervision, confirmed in a press statement that all users who submitted their iris data must have an unrestricted right to erasure in the future.
EU Regulators Demand Full Right to Erasure for Iris Scans
World has been given exactly one month from the decision date to launch a GDPR-compliant deletion mechanism, setting the deadline for early 2025. Additionally, the German regulator is forcing Worldcoin to obtain explicit consent for specific future processing steps, signaling that the company must provide EU citizens with more transparent information before scanning their eyes. The order also mandates the purging of specific historical records that were harvested without a valid legal basis.
var playerInstance_jwplayer_6a6936c85b42f = jwplayer( “jwplayer_6a6936c85b42f” );
playerInstance_jwplayer_6a6936c85b42f.setup({
playlist: “https://cdn.jwplayer.com/v2/media/nsQAyeWN”,
});
In response to the corrective order, World announced it will file an appeal. The Bavarian authority has since confirmed that the enforcement timeline is temporarily suspended while the appeal process plays out. However, the regulator clarified that the deletion mandate specifically targets “biometric templates” linked to iris scans, which are stored in standard databases and are fully capable of being erased.
According to Will, the Bavarian DPA views the entire dataset as currently non-anonymous. Consequently, World must prove how it will restructure its data processing to facilitate deletion, which may require removing multiple data fragments. Will emphasized that explicit consent is the only viable legal basis for this type of biometric processing under European law.
The Clash Between Blockchain Immutability and Privacy Rights
The requirement to delete user data strikes at the very heart of World’s technical ambitions. The proof-of-humanness project aims to build an immutable, decentralized ledger of unique digital identities for remote verification. Allowing users to wipe their digital footprint on demand directly undermines the goal of creating a permanent registry of verified humans.
Rebecca Hahn, a spokesperson for Tools for Humanity (TfH)—the development group behind Worldcoin—stated that their appeal will argue that World’s technical setup is inherently privacy-preserving and effectively anonymizes user data. Under GDPR, truly anonymous data is exempt from the law’s strict data access and deletion requirements.
The Battle Against Digital Bots and Bad Actors
Damien Kieran, Chief Privacy Officer at TfH and former X executive, explained why the company resists simple data deletion. Kieran noted that World aims to build a trustworthy digital passport to solve online bot issues. If a suspended user could simply delete their World ID and register a new one, the system’s ability to block malicious actors on platforms like X would be entirely compromised. Therefore, the data must remain anonymized and undeletable to prevent network abuse.
While Kieran noted that World ID holders can delete personal data stored locally on their smartphones, the core regulatory battle focuses on the biometric data used for unique identification. Earlier this year, World unveiled an open-source Secure Multi-Party Computation (SMPC) system, which encrypts iris codes into secret shares distributed across multiple parties, eliminating the need to decrypt codes during identity checks.
As part of these technical shifts, Worldcoin introduced a feature allowing users to request the deletion of their iris codes. However, European regulators have determined that this setup still falls short of GDPR standards, which demand absolute user autonomy over personal information—a design requirement that conflicts with World’s immutable verification mission.
Protecting Fundamental European Data Rights
The Bavarian DPA warned that Worldcoin’s biometric verification process poses significant fundamental data protection risks for a massive number of users. While acknowledging recent technical improvements made by the platform, the regulator insisted that further adjustments are mandatory, particularly regarding comprehensive erasure after consent is withdrawn.
Will emphasized that the decision is a defense of European fundamental rights in a highly complex and technologically demanding scenario. Rather than addressing the core data access issue directly, World’s appeal seeks to redefine how European law classifies anonymous data, launching a blog post asserting that World ID is “anonymous by design.” However, lobbying for reduced individual privacy rights faces a steep uphill battle in Europe.
Worldcoin has already faced severe regulatory hurdles across Europe. Authorities in Spain and Portugal previously utilized emergency powers to halt the project’s eyeball-scanning operations due to concerns over the permanent collection of children’s biometric data. Despite these setbacks, World (recently rebranded from Worldcoin) has pushed forward with its expansion, recently launching operations in Austria.
