Your data, their decision: the hidden surveillance infrastructure behind Europe’s digital borders

A new report by ARTICLE 19 examines how the European Union is presiding over the most significant expansion of border surveillance in its history. Much of this development is being outsourced to private companies – with profound consequences for privacy and freedom of expression.

By ARTICLE 19 (guest author) · October 8, 2026

The expansion of digital border surveillance infrastructure

In October 2025, the EU began systematically collecting and storing fingerprints and facial images of every third-country national crossing its external border, under the Entry/Exit System (EES). By late 2026, the European Travel Information and Authorisation System (ETIAS) will expand this approach by pre-screening visa-exempt travellers before they arrive at EU borders.

Together, the two systems are capable of processing more than 1.4 billion travellers, integrating biometric, migration, visa, and law-enforcement data into searchable profiles.

The new report by ARTICLE 19, examining how the EU is significantly expanding border surveillance, focuses on the agency at the heart of the system: EU-LISA (EU Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice). This little-scrutinised entity plays a key role in building and maintaining the large-scale digital infrastructure projects that underpin EU migration and border management.

ARTICLE 19 analysed EUR 1.99 billion in contracts awarded by EU-LISA between 2019-2025. The analysis shows how private companies, including IDEMIA, Sopra Steria, IBM, and Leonardo SpA, have gained unprecedented power to shape how the systems operate.

Because of the way EU-LISA procurement works, private companies are gaining real influence over what the systems can do and recommend, through large building blocks of biometrics, engineering, and operations. In practice, this means that surveillance capacities within EES and ETIAS could be expanded through ‘technical adjustments’ decided by companies rather than accountable political decisions.

Those same companies are part of a growing industry that spans global digital IDs, defence and security projects worldwide. IDEMIA, for instance, develops and implements national biometric identification systems in countries including Morocco, Chile, and Colombia, as well as election management technologies in Kenya.

How these technologies travel across contexts deserves further scrutiny.

Surveillance without accountability puts migrants’ rights at risk

This scale of digitalisation at the border has real-life consequences for the people subjected to it.

For migrants and people on the move, participation in these systems is not optional: biometric registration and automated risk-scoring are conditions for mobility or legal status, not choices people can opt out of.

This is deeply concerning because interconnected systems mean a single database error can cascade across the entire network, leading to delayed or denied entry or visa refusals – often with little transparency about how a decision was made or how to challenge it. Many migrants lack the linguistic, legal, and financial resources needed to exercise rights they formally have.

The long-term picture remains uncertain: how exactly will these systems classify people, what further changes might be introduced, and what mechanisms can people use to question decisions or access their own data.

One thing is clear: accountability mechanisms are lagging further behind the pace of deployment of these surveillance tools.

The need for rights frameworks and genuine accountability

Individuals’ rights and freedoms should not be subordinated to commercial interests. Strengthening rights mechanisms and transparency for migrant populations requires protective frameworks designed for the conditions they face.

Existing legal frameworks cannot simply apply to EES and ETIAS on paper. They need to be enforced without the broad exceptions for migration and law enforcement that currently undermine both the GDPR and the AI Act. EDRi and its members have already documented how the AI Act fails migrants and people on the move.

We need binding transparency obligations around EU-LISA’s procurement processes and its relationships with private contractors. Decisions that expand surveillance capacities should require the same level of public scrutiny and political accountability as any other major policy change. They cannot be left to commercial and engineering considerations alone.

More broadly, the design, development, and deployment of digital border infrastructure must not be allowed to proceed without open public debate and meaningful participation of those most affected. Migrant-led organisations, refugee rights groups, and digital rights networks should be included at every stage of design and evaluation, not just after systems are already operational.

Rendering surveillance infrastructures visible

As the report shows, surveillance infrastructures too often operate in the dark. We need to make them visible and open to sustained public scrutiny.

Right now, Europe seems to be running in the opposite direction: toward systems that grow more powerful and more opaque, while the people most affected by them have the least insight into how they operate.

This can and must be reversed. Democratic oversight of border infrastructure is urgent and cannot be optional. ARTICLE 19 will keep monitoring developments at EU-LISA and within the EES/ETIAS framework, and continue pushing for the transparency these systems currently lack.

Infrastructure currently operating in the dark, must be brought back into the scope of democratic accountability.

Contribution by: EDRi member, ARTICLE 19