A Consultation That Closed Quietly, But Changes a Lot
Between June 12 and August 7, 2026, the European Commission ran a public feedback window on what officials call "Prüm international" — a plan to let EU law enforcement exchange biometric data, including facial-recognition matches, with vetted non-EU partners such as the UK, Ukraine, Moldova, the Western Balkans and Canada (Biometric Update). The Commission plans to table legislative text in Q4 2026. Practically, the whole architecture would run through Europol's infrastructure at its headquarters in The Hague — making the Netherlands the operational hub for whatever gets built.
This is an extension, not a fresh start. Regulation (EU) 2024/982 — "Prüm II" — already lets EU states automatically search each other's facial images, DNA and fingerprints for offences carrying at least a one-year prison sentence, with mandatory human review of matches and a 48-hour window to release confirmed identification data (EUR-Lex; European Parliament). The new proposal would let the Commission grant — and revoke — "trusted partner" status to non-EU states, giving them reciprocal access to that same pipeline.
The Case For It, Stated Fairly
The strongest argument for Prüm international isn't abstract. Cross-border organised crime and fugitive flight don't stop at the EU's edge, and the current patchwork of bilateral data-sharing deals with non-EU states produces exactly what Brussels says it does: "divergent technical architectures, legal conditions and data protection safeguards" that slow down legitimate policing while doing nothing to improve rights protection (Biometric Update). A single, revocable, standardised channel is plausibly better than forty overlapping ad hoc arrangements — for privacy as much as for efficiency — provided the standard it enforces is the EU's own.
Asia Isn't Waiting for a Common Standard
What makes the timing pointed is that Asia is currently running three structurally different experiments in the same technology, none of which resembles Prüm's judicially-gated model.
- Regional police cooperation: ASEANAPOL's 44th conference, held in Manila in late July 2026, endorsed modernising its Electronic ASEANAPOL Database System with wider facial-recognition capability for tracking fugitives across the bloc's members — a body whose dialogue partners already include Europol and Interpol (Philippine Daily Inquirer). This is the closest analogue to Prüm: multilateral, warrant-linked, and framed around named suspects.
- Mandatory telecom biometrics: South Korea will require real-time face-matching against government ID before activating any new mobile number, aimed at the fraud and voice-phishing schemes that cost victims more than 1 trillion won (roughly $760 million) in 2025 alone (Biometric Update). This isn't case-by-case policing — it's a biometric gate on a basic utility, applied to everyone, justified by fraud statistics rather than a warrant.
- Passive infrastructure matching: Indonesia's traffic camera network now cross-references drivers' faces against the national population registry to identify vehicles with obscured or fake plates, flagging over 16,800 plate violations in the first half of 2026 alone (ID Tech). No warrant, no suspect list — just ambient identification against a civil registry.
Three different consent models, three different trigger thresholds, one technology. That divergence is the real argument for why "trusted partner" status can't just mean political trust — it has to mean technical and legal equivalence, checked against a specific model, not a blanket judgment about a country's institutions.
The Netherlands Is Where the Theory Meets the Router
The Dutch context sharpens this. The Autoriteit Persoonsgegevens has already flagged that Dutch police built a live facial-recognition protocol before Parliament passed dedicated legislation governing it — a sequencing problem the regulator called backwards. And per EDRi, the Netherlands has had to delete 218,000 wrongfully-included photos from a police facial database, a concrete illustration of how these systems accumulate bad data even inside a mature EU rule-of-law state with an active regulator watching (EDRi). If that's the failure mode domestically, the question for Prüm international is what happens when a trusted partner's database has the same problem and there's no EDPB or AP equivalent auditing it from outside.
The Proportionate Position
Prüm II's own safeguards — the one-year offence floor, mandatory human review, a ban on automated profiling, minimum facial-data quality standards — exist because Brussels understood that biometric matching without those guardrails is a discrimination and error risk, not just a privacy one. The consultation's flaw isn't the goal of a standardised channel; it's that "trusted partner" status, as scoped, reads as a diplomatic judgment the Commission can revoke after the fact, rather than a technical certification — equivalent retention limits, an equivalent human-review requirement, an equivalent profiling ban — checked before data starts flowing. Given how differently Manila, Seoul and Jakarta are already deploying this technology, exporting the EU's biometric pipeline without exporting its conditions first is the one outcome the Commission should rule out entirely.