Israel biometric surveillance public spaces

Shin Bet's David Zini Wants Airport Facial-Recognition Data the Law Already Says He Can't Have

Zini is demanding access to Ben Gurion Airport's biometric database despite an AG ruling — and a history of illegal transfers.

Shin Bet's Airport Database Demand, By the Numbers People of Internet Research · Israel 90 days Photo deletion window Border-crossing photos must be del… 7 years Years of unlawful sharing Population Authority illegally sha… ₪497M Funds diverted to Shin Bet plan Diverted from the '550 Plan' Arab-… peopleofinternet.com
Shin Bet's Airport Database Demand, By… People of Internet Research · Israel 90 days Photo deletion window 7 years Years of unlawful sharing ₪497M Funds diverted to Shin Bet plan peopleofinternet.com

Key Takeaways

Israel's domestic intelligence agency wants into a database the law says is off-limits — and the country has already run this experiment once, with bad results.

A demand the Attorney General has already rejected

According to a July 17, 2026 Haaretz report, Shin Bet director David Zini has sought "unrestricted access" to the facial-image database the Population and Immigration Authority (PIBA) maintains from cameras at Ben Gurion Airport and other border crossings, in order to run facial recognition against suspects in crime scenes (Haaretz; The Times of Israel). Attorney General Gali Baharav-Miara's response was direct: current law confines access to PIBA alone, and giving the Shin Bet a standing line into the database would require new legislation, not an administrative workaround (Türkiye Today). The Shin Bet has called the report "baseless" and said it "does not accord with reality," without disputing the underlying legal point.

The rule itself is not ambiguous. Photographs and biographical data collected from travelers at Israeli border crossings must be deleted within 90 days and may not be transferred to third parties, security agencies included (Türkiye Today; gov.il — National Biometric Database Authority).

This already happened once

What elevates Zini's request above a bureaucratic turf skirmish is that Israel has already run this exact scenario. A 2022 report by the head of the Biometrics Applications Unit found that the Population and Immigration Authority had unlawfully shared millions of Israelis' facial images with an unnamed government agency for roughly seven years — from 2015 until the transfer was flagged in March 2022 (Biometric Update). A related 2021 review found the Authority had separately compiled a lower-resolution facial-image archive that regulators hadn't classified as "biometric" — until face-matching software caught up with the image quality, leaving millions of photos usable for identification without any of the legal safeguards that apply to protected biometric data. A subsequent lawsuit forced a 2024 settlement under which the Authority deleted the unregulated border-crossing database and proposed a legislative fix that, per Haaretz's reporting, still hasn't moved through the Knesset.

In other words: Israel already watched a security-adjacent database migrate outside its legal bounds, got caught, and is still mid-cleanup. Zini's request functionally asks to reopen a door regulators only recently closed.

The security case, stated fairly

Zini's ask is not unreasonable on its face. Israel operates in a genuinely high-stakes threat environment, and facial recognition against a large, high-quality photo archive is a legitimately fast way to identify a suspect fleeing a crime scene or crossing under a false identity. The request also lands days after the government approved a five-year plan — funded by diverting roughly NIS 497 million ($166 million) from the "550 Plan" Arab-community investment program — that gives the Shin Bet a new formal mandate to fight organized crime, including weapons and drug smuggling, inside Arab communities (The Times of Israel). If the Shin Bet is now statutorily tasked with crime-fighting, it has a plausible operational argument for investigative tools comparable to the police's.

Why the Attorney General is right to hold the line anyway

But operational usefulness has never been the legal test for domestic-surveillance access, and it shouldn't become one now by request. The 90-day deletion rule and the bar on third-party transfer exist precisely because a facial-recognition archive populated by nearly every traveler through Ben Gurion Airport — the overwhelming majority with no connection to any investigation — is a categorically different privacy exposure than a targeted police database of known suspects. Handing a domestic intelligence agency standing access to it, without legislation setting retention limits, audit trails, judicial oversight or use restrictions, is exactly the quiet mission creep Israel's own regulators already caught once. Baharav-Miara's answer — take it to the Knesset — is the correct one: weighing that trade-off in public is a legislature's job, not an agency director's to resolve by request or an Attorney General's to grant administratively.

Rights groups' objections to the parallel Shin Bet crime-fighting expansion — that it risks treating an entire community as a security threat rather than a policing problem — deserve to be taken seriously on their own terms.

But the facial-recognition question is narrower, and in some ways more tractable: Israel doesn't need to resolve whether the Shin Bet should have a domestic crime-fighting role at all to conclude that biometric access to millions of travelers' faces needs a statute, not a request.

The fix is legislative, and it's overdue

The Population Authority's own 2025 proposal to formally regulate use of border-crossing photos — specifying who can query the data, under what predicate, for how long, and under what independent oversight — is the right vehicle. Its two-year stall in the Knesset, not the Attorney General's refusal, is the actual failure here. Proportionate regulation of biometric surveillance isn't a brake on Israel's security agencies; it's what lets a facial-recognition capability survive its next legal and public-trust test instead of being quietly rolled back, as the last unauthorized version was.

Sources & Citations

  1. Haaretz — Shin Bet Chief Demands Access to Airport Facial Images Database
  2. The Times of Israel — Shin Bet Reportedly Demands Unauthorized Access
  3. Türkiye Today — Shin Bet Chief Sought Unrestricted Access
  4. Biometric Update — Israeli Agency Unlawfully Shared Biometric Data for 7 Years
  5. The Times of Israel — Government Okays Shin Bet Role in Arab-Sector Crime
  6. Calcalist — Israeli security bodies get direct access to biometric databases
  7. Israel's Biometric Database Law (5770-2009)