According to a fresh analysis by ARTICLE 19, the European Union is overseeing an unprecedented growth in border surveillance capacity, with much of the work delegated to private firms. This shift raises serious questions about privacy protections and the ability of people to exercise their fundamental freedoms.
The expansion of digital border surveillance infrastructure
Starting in October 2025, the EU rolled out systematic collection and storage of fingerprints and facial images for all third-country nationals entering its external borders through the Entry/Exit System (EES). The European Travel Information and Authorisation System (ETIAS), set to launch by late 2026, will add another layer by screening visa-exempt visitors before they cross EU borders.
Together, these two systems can handle data on more than 1.4 billion travellers, combining biometric records, migration histories, visa information, and law-enforcement details into profiles that can be searched and cross-referenced.
At the centre of this infrastructure sits EU-LISA (EU Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice), an agency that has received limited public attention despite its critical role in constructing and running the major digital systems that manage EU migration and border control.
ARTICLE 19 examined EUR 1.99 billion in contracts handed out by EU-LISA from 2019 to 2025. The findings demonstrate how firms such as IDEMIA, Sopra Steria, IBM, and Leonardo SpA have gained substantial authority over how these systems function and what they recommend.
The procurement model used by EU-LISA grants private contractors significant control over system capabilities and recommendations through major contracts covering biometrics, technical engineering, and operational management. This arrangement creates a pathway for expanding surveillance functions through technical modifications initiated by companies rather than through transparent political processes.
These same firms operate across a broader ecosystem encompassing global digital identity systems, defence initiatives, and security contracts worldwide. IDEMIA, for example, builds and runs national biometric identification programmes in Morocco, Chile, and Colombia, and also provides election management tools in Kenya.
The movement of these technologies across different countries and contexts warrants closer examination.
Surveillance without accountability puts migrants' rights at risk
The scope of digital systems deployed at borders carries direct implications for those subjected to them.
For migrants and mobile populations, involvement in these systems is mandatory: submitting biometric data and undergoing automated risk assessment are prerequisites for travel or legal status, not optional activities.
This raises urgent concerns because linked systems mean that a single error in one database can spread throughout the entire network, resulting in entry delays, visa denials, or refusals—frequently without clear explanation of how decisions were reached or pathways to challenge them. Many migrants lack the language skills, legal knowledge, and financial means to assert rights they technically possess.
The future trajectory remains unclear: how will these systems categorise individuals, what additional modifications might be introduced, and what options exist for people to contest determinations or retrieve their own information.
What is evident is that mechanisms for holding systems accountable are falling behind the speed at which surveillance tools are being deployed.
The need for rights frameworks and genuine accountability
The rights and freedoms of individuals must not be sacrificed to serve commercial objectives. Strengthening protections and openness for migrant communities demands safeguards tailored to their particular circumstances.
Current legal protections cannot simply be applied as written to EES and ETIAS. Implementation must reject the broad exemptions for migration and law enforcement that currently weaken both the GDPR and the AI Act. EDRi and allied organisations have previously documented how the AI Act leaves migrants and people on the move unprotected.
Mandatory disclosure requirements must govern EU-LISA's contracting decisions and its dealings with commercial partners. Choices to increase surveillance reach should face the same degree of public review and political responsibility as any other major policy shift. These determinations cannot rest solely with industry and technical specialists.
The creation, construction, and rollout of digital border systems must include open community discussion and active involvement of those most impacted. Organisations led by migrants, advocates for refugee protection, and networks defending digital freedoms must participate from the earliest design phases through ongoing assessment, not merely after systems are already in place.
Rendering surveillance infrastructures visible
As the report documents, surveillance systems frequently function beyond public view. These systems must be made transparent and subject to continuous public examination.
Currently, Europe is moving in the opposite direction: toward infrastructure that becomes stronger and less transparent, while those most harmed by it have the least understanding of its workings.
This trajectory can be altered and must be. Ensuring democratic control over border infrastructure is both critical and cannot be treated as optional. ARTICLE 19 intends to track future developments at EU-LISA and in the EES/ETIAS ecosystem, and to advocate for the transparency these systems presently lack.
Systems now hidden from view must be returned to the realm of democratic accountability.



