Netherlands facial recognition law enforcement Asia

The EU's Plan to Export Facial-Recognition Sharing to 'Trusted' Non-EU Police Forces Tests Whether Its Own Safeguards Travel With the Data

Brussels' Prüm II consultation would let vetted non-EU police forces tap EU facial-recognition matches — even as Asia's own biometric policing models diverge sharply.

One Technology, Four Diverging Models People of Internet Research · Netherlands 57 days EU consultation window Public feedback on Prüm internatio… 1-year offence floor Prüm II match threshold Facial searches under Prüm II appl… 218,000 deleted NL wrongful database photos Dutch police removed wrongly-inclu… ~$760M S. Korea fraud losses, 2025 Cited to justify South Korea's new… peopleofinternet.com
One Technology, Four Diverging Models People of Internet Research · Netherlands 57 days EU consultation window 1-year offence floor Prüm II match threshold 218,000 deleted NL wrongful database photos ~$760M S. Korea fraud losses, 2025 peopleofinternet.com

Key Takeaways

A Consultation That Closed Quietly, But Changes a Lot

Between June 12 and August 7, 2026, the European Commission ran a public feedback window on what officials call "Prüm international" — a plan to let EU law enforcement exchange biometric data, including facial-recognition matches, with vetted non-EU partners such as the UK, Ukraine, Moldova, the Western Balkans and Canada (Biometric Update). The Commission plans to table legislative text in Q4 2026. Practically, the whole architecture would run through Europol's infrastructure at its headquarters in The Hague — making the Netherlands the operational hub for whatever gets built.

This is an extension, not a fresh start. Regulation (EU) 2024/982 — "Prüm II" — already lets EU states automatically search each other's facial images, DNA and fingerprints for offences carrying at least a one-year prison sentence, with mandatory human review of matches and a 48-hour window to release confirmed identification data (EUR-Lex; European Parliament). The new proposal would let the Commission grant — and revoke — "trusted partner" status to non-EU states, giving them reciprocal access to that same pipeline.

The Case For It, Stated Fairly

The strongest argument for Prüm international isn't abstract. Cross-border organised crime and fugitive flight don't stop at the EU's edge, and the current patchwork of bilateral data-sharing deals with non-EU states produces exactly what Brussels says it does: "divergent technical architectures, legal conditions and data protection safeguards" that slow down legitimate policing while doing nothing to improve rights protection (Biometric Update). A single, revocable, standardised channel is plausibly better than forty overlapping ad hoc arrangements — for privacy as much as for efficiency — provided the standard it enforces is the EU's own.

Asia Isn't Waiting for a Common Standard

What makes the timing pointed is that Asia is currently running three structurally different experiments in the same technology, none of which resembles Prüm's judicially-gated model.

Three different consent models, three different trigger thresholds, one technology. That divergence is the real argument for why "trusted partner" status can't just mean political trust — it has to mean technical and legal equivalence, checked against a specific model, not a blanket judgment about a country's institutions.

The Netherlands Is Where the Theory Meets the Router

The Dutch context sharpens this. The Autoriteit Persoonsgegevens has already flagged that Dutch police built a live facial-recognition protocol before Parliament passed dedicated legislation governing it — a sequencing problem the regulator called backwards. And per EDRi, the Netherlands has had to delete 218,000 wrongfully-included photos from a police facial database, a concrete illustration of how these systems accumulate bad data even inside a mature EU rule-of-law state with an active regulator watching (EDRi). If that's the failure mode domestically, the question for Prüm international is what happens when a trusted partner's database has the same problem and there's no EDPB or AP equivalent auditing it from outside.

The Proportionate Position

Prüm II's own safeguards — the one-year offence floor, mandatory human review, a ban on automated profiling, minimum facial-data quality standards — exist because Brussels understood that biometric matching without those guardrails is a discrimination and error risk, not just a privacy one. The consultation's flaw isn't the goal of a standardised channel; it's that "trusted partner" status, as scoped, reads as a diplomatic judgment the Commission can revoke after the fact, rather than a technical certification — equivalent retention limits, an equivalent human-review requirement, an equivalent profiling ban — checked before data starts flowing. Given how differently Manila, Seoul and Jakarta are already deploying this technology, exporting the EU's biometric pipeline without exporting its conditions first is the one outcome the Commission should rule out entirely.

Sources & Citations

  1. EUR-Lex: Prüm II regulation summary
  2. European Parliament Legislative Train: Prüm II
  3. Biometric Update: EU seeks feedback on non-EU biometric sharing
  4. EDRi: EC jumps the gun on Prüm
  5. Philippine Daily Inquirer: PNP, ASEANAPOL facial recognition
  6. Biometric Update: South Korea mobile facial-recognition mandate
  7. ID Tech: Indonesia adds facial recognition to traffic enforcement