How data retention periods, access controls, and oversight mechanisms ensure compliance with European privacy regulations
WASHINGTON, DC, November 29, 2025
The European Union’s new Entry Exit System, widely known as EES, is transforming how millions of non-EU travelers are recorded at Europe’s external borders. Each crossing now generates a digital trace built from biometric identifiers, travel document details, and precise timestamps. For border authorities, this promises better enforcement of stay limits, more reliable identification, and clearer statistics on migration flows.
For privacy regulators and travelers, it raises a different set of questions. How long are biometric records kept? Who can access them? Which bodies ensure that such a powerful system remains within the limits of European data protection law?
This report examines the legal boundaries that frame biometric data in the EES, focusing on retention rules, access controls, and oversight mechanisms that regulators say are designed to keep the system compatible with the European Union’s strict privacy framework. It also considers how these rules are likely to be tested in practice, particularly for travelers and officials in emerging markets that interact closely with Europe.
Legal Foundations Of Biometric Data In The EES
The EES is grounded in a dedicated regulation adopted in 2017 that defines the system’s purposes, data categories, and safeguards. That regulation sits alongside the Schengen Borders Code, which governs checks at external borders, and interoperability rules that link EES to other large-scale systems.
Within this legal framework, EES is described as an automated system that records entries, exits, and refusals of entry for non-EU nationals admitted for short stays. For each traveler covered by the system, EES stores:
- biographical data, such as full name, nationality, and date of birth
• travel document information, including type, number, and issuing country
• biometric identifiers, notably a facial image and, in many cases, fingerprints
• the date, time, and place of each entry, exit, or refusal of entry
The regulation limits EES to clearly defined purposes. Its principal objectives are to improve border management, detect overstays, strengthen the fight against identity fraud, and provide reliable statistics for migration and security policy. It is not intended to be a general population register.
European data protection law, including the General Data Protection Regulation and the specific directive for police and criminal justice processing, applies in parallel. These instruments impose familiar requirements such as lawfulness, fairness, transparency, purpose limitation, data minimisation, and security. The EES regulation translates those principles into system-specific rules intended to serve as rigid boundaries around biometric processing.
Data Retention Periods And Legal Time Limits
One of the most sensitive questions for any biometric database concerns how long the data will be kept. The EES regulation responds with detailed retention rules that draw distinct lines between different categories of records.
For individual entry, exit, or refusal of entry records, the general rule is that they are stored for three years from the date they are created. That period is tied to the system’s core purpose of enforcing short-stay rules. Officials argue that three years allows authorities to assess patterns of travel and detect overstays without creating an indefinite historical archive of movement.
For the underlying personal file that links a traveler’s identity to their biometric and document data, the retention period is three years and one day from the date of the last recorded exit or refusal of entry, provided there has been no new entry. The additional day is a technical measure that allows systems to calculate the start of a new reference period.
Where no exit has been recorded, and an individual appears to have overstayed beyond the permitted 90 days within any 180 days, the rules allow for longer retention. Public guidance from several Member States explains that in such cases, data can be stored for up to five years after the last day of the permitted stay. This extended period is justified to manage the consequences of irregular presence, such as return procedures or entry bans.
The regulation also obliges authorities to delete or anonymise data that has passed its retention limit, except where continued storage is strictly necessary for ongoing proceedings. Automated routines and manual checks are expected to enforce these limits. Still, experience from other databases suggests that data protection authorities will be monitoring closely to ensure that expired records do not linger by default.
Access Controls And Categories Of Users
Retention rules address how long EES data may exist. Access rules determine who can see it and under what conditions.
At the core of the system are border and migration authorities. Border guards at official crossing points use EES to verify identity, calculate authorised stay, and decide whether to allow entry. Visa authorities consult the system when processing applications to check whether an applicant has a history of overstays or refusals of entry.
These authorities are granted direct operational access through national interfaces. Their use of EES must align with the purposes set out in the regulation. They cannot simply browse records out of curiosity; each query must be justified by a concrete task such as processing a crossing, reviewing a visa, or investigating a specific incident.
Law enforcement access is more restricted. Police and judicial authorities may consult EES for the prevention, detection, or investigation of serious crime and terrorism, but only when certain conditions are met. Typically, they must show that:
- access to EES is necessary for the case at hand
• consultation of national databases and existing records has been insufficient
• the request is specific, not a broad fishing expedition
Requests for law enforcement access must be logged, including the identity of the requesting officer, the reason for the search, the date and time, and the data accessed. These logs are available for inspection by data protection authorities and, where relevant, by courts.
The regulation also contemplates information sharing in strictly limited contexts, for example, where EES data is needed to enforce return decisions or carry out border-related risk analysis. In such cases, the system must still be used within the defined purposes, and bulk transfers of identifiable data to external partners are tightly controlled.
Oversight Mechanisms And Coordinated Supervision
EES is subject to multiple layers of oversight. This reflects both its scale and the sensitivity of the biometric and travel data it processes.
At the national level, each Member State’s data protection authority supervises how local border guards, migration offices, and police use EES. These authorities can:
- conduct inspections at border crossing points and central units
• review logs of system access
• issue guidance or corrective orders
• handle complaints from individuals who believe their rights have been violated
At the EU level, the European Data Protection Supervisor oversees the activities of EU LISA, the agency that operates the central system, and other EU institutions involved in managing EES. The Supervisor can audit the agency, review technical and organisational measures, and coordinate with national authorities.
To avoid fragmented oversight, a Coordinated Supervision Committee has been established to bring together national data protection authorities and the European Data Protection Supervisor. That committee now includes EES among the large-scale systems it monitors. It serves as a forum to:
- harmonise interpretations of the rules
• discuss cross-border cases that affect several Member States
• develop joint positions on issues such as retention, access, and transparency
In parallel, the EU Agency for Fundamental Rights has issued dedicated guidance for managers and border guards on implementing EES in line with fundamental rights. These documents highlight practical issues such as explaining procedures to travelers, handling biometric collection with dignity, and providing extra support for people with disabilities or those who do not speak the local language.
Together, these bodies constitute a complex yet comprehensive oversight structure designed to detect and correct misuse, whether arising from technical flaws, inadequate training, or deliberate overreach.
Case Study 1: Correcting An Error In A Biometric Record
A composite scenario illustrates how data protection rights might work in practice.
A non-EU national from an emerging market country has travelled to the Schengen area several times in recent years for short business visits. After EES becomes operational, she completes biometric enrollment at a major airport. Her entries and exits are recorded without incident.
On a subsequent trip, however, she is stopped at the border and informed that EES indicates an overstay on a previous visit. According to the system, her earlier exit was never recorded, and the authorized 90-day stay was exceeded. She is allowed in only after additional questioning and is warned that further overstays could result in sanctions.
Convinced that she left on time, the traveler requests past boarding confirmations from her airline and collects other documents confirming she departed within the permitted period. She then submits a written request to the relevant national authority to access her EES data and to correct any inaccuracies, invoking her rights under EU data protection law.
The authority retrieves her EES file and confirms that an exit record is indeed missing. Further checks reveal that a temporary technical failure at a land crossing prevented the scan from reaching the central system. Based on the evidence she provided, the authority manually adds an exit entry with the correct date and time, thereby resolving the apparent overstay. Logs of the correction and the underlying justification are retained for audit.
If the traveler were not satisfied with the national authority’s response, she could escalate the matter to the national data protection authority, and ultimately to a court. The presence of clear data access and rectification rights, combined with oversight structures, is meant to make such corrections more than theoretical.
Case Study 2: Law Enforcement Access Tested Against Safeguards
A second composite case highlights the boundaries placed on law enforcement.
In a Member State that participates in the Schengen system, police are investigating a suspected organiser of serious cross-border fraud. Investigators believe the suspect travels frequently in and out of the EU under different aliases. They want to consult EES to identify travel patterns, document use, and possible multiple identities.
Under the applicable rules, the investigators must submit a formal request to the competent authority responsible for managing law enforcement access to EES. The request must specify the crime under investigation, the reasons EES data is necessary, and the identity attributes or biometrics to be used in the search.
The authority examines whether national systems and existing records already provide the needed information. It also checks whether the case meets the threshold of serious crime. Only after those conditions are confirmed does it authorise a targeted EES search.
The query returns a set of entries indicating that a biometric profile matching the suspect has been recorded at several borders under different names and with different passports. This gives investigators a stronger factual basis for their case. The entire process, from request to query, has been logged.
If later review by a data protection authority or a court finds that investigators overstated the necessity of the request, or that the case did not in fact qualify as a serious crime, sanctions and remedial orders can follow. The existence of such consequences is a core element of the legal boundary around law enforcement use of EES.
Case Study 3: An Emerging Market Traveler Asserts Data Rights
A third composite scenario focuses on a traveler from a rapidly growing African or Asian economy who frequently uses European hubs to connect to other regions.
The traveler becomes increasingly aware that every crossing generates biometric and movement data stored in the EES. Concerned about privacy, she decides to test how accessible her data really is.
Using information provided on official portals, she submits a request to the national authority of the Schengen state where she often enters, asking whether her data is stored in EES and, if so, requesting a copy. She also asks for information about retention periods and the purposes for which her data may be used.
The authority acknowledges the request and, after verifying her identity, provides a summary of her recorded entries and exits in the system, along with an explanation of the applicable retention rules. For security reasons, the authority does not share raw biometric templates, but confirms that they are stored and gives details about data protection safeguards.
If the traveler believes the response is incomplete or unsatisfactory, she can turn to the national data protection authority, which can investigate and, if necessary, order the controller to provide fuller information. This process is slow and often unfamiliar to travelers, yet it is a key component of European law’s efforts to balance biometric border control with individual rights.
Fundamental Rights, Proportionality, And Risk Of Function Creep
Legal boundaries on biometric data in EES are not solely technical. They are tied to broader fundamental rights debates in Europe.
Biometric data, such as facial images and fingerprints, is considered particularly sensitive because it is unique to each person and challenging to change. Large-scale storage of such data, combined with travel histories, creates a robust infrastructure that, in principle, could support extensive surveillance of movement and association.
European institutions have sought to justify EES as a proportionate interference with rights, arguing that:
- the system pursues legitimate objectives, such as preventing irregular migration and combating identity fraud
• the data collected is limited to what is necessary for those objectives
• retention periods are framed in time and subject to deletion requirements
• access is restricted and overseen by independent authorities
Civil society organisations and legal scholars acknowledge these safeguards but warn of a risk described as function creep. Data collected for one purpose, such as border management, could gradually be repurposed for broader law enforcement or intelligence uses. Interoperability between systems, while technically efficient, may further blur the lines between administrative and criminal justice processing.
The presence of detailed rules, independent oversight, and judicial review is intended to counter that risk. Yet the ultimate test will be how courts respond when concrete cases arise, and whether authorities respect the spirit as well as the letter of the legal boundaries.
Implications For Travelers, Regulators, And Emerging Markets
For travelers, the legal structure around EES translates into a more predictable but less anonymous experience. Short stay limits are calculated automatically. Overstays are more likely to be detected. Biometric enrollment is mandatory for most non-EU visitors, and refusal means no entry.
For regulators, EES marks a shift toward data-rich border management that demands strong institutional capacity. Data protection authorities must understand complex technical architectures. Border agencies must train staff to respect rights while using advanced tools. Courts must grapple with new forms of evidence drawn from movement logs and biometric matches.
For governments and businesses in emerging markets, the European model presents both a challenge and a reference point. Citizens who visit Europe regularly must assume that their movements are recorded in detail, and that those records can interact with other areas of compliance, including tax, banking, and corporate reporting.
Some states are already drawing on the EES framework as they consider their own biometric border systems. Others are watching closely to see how effectively European oversight mechanisms function in practice, and whether the promises of proportionality and transparency are kept.
The Role Of Professional Advisory Services
In this landscape, professional advisory firms have become intermediaries between individuals, companies, and the evolving web of border and data protection rules.
Amicus International Consulting provides professional services to clients who manage complex cross-border lives, including those pursuing alternative residency, second-citizenship, and banking-passport strategies. In the context of EES, advisory work includes:
- explaining how biometric data is collected, stored, and used at European borders
• mapping travel patterns against retention rules and stay limits to reduce compliance risk
• helping clients from emerging markets understand how EES data may intersect with other regulatory regimes, including banking due diligence and tax reporting
• assisting clients in exercising their data protection rights, including access and rectification, when necessary
For high-net-worth individuals, entrepreneurs, and internationally active professionals, EES is no longer a technical abstraction. It is a system that shapes where and how they can travel, how their identity is recorded, and how authorities assess their compliance. Advisory firms that understand both the legal architecture and the operational reality of biometric borders are increasingly seen as part of a broader risk management toolkit.
Looking Ahead: Litigation, Reform, And Global Norms
As EES moves from phased rollout to routine operation in 2026, its legal boundaries will face real-world tests. Cases are likely to arise involving disputed overstays, alleged misuse of data, contested law enforcement access, and technical errors with serious consequences for individuals.
National courts and the Court of Justice of the European Union will play a central role in clarifying the meaning of key concepts such as necessity, proportionality, and purpose limitation in the specific context of biometric border systems. Data protection authorities will continue to publish guidance, conduct inspections, and, where needed, impose corrective measures or sanctions.
Depending on how these processes unfold, the law governing EES may be refined. Retention periods could be adjusted, access rules tightened or clarified, and transparency obligations strengthened. Alternatively, political pressures linked to security and migration concerns could prompt calls for broader use of the system; any such expansion would need to pass the same fundamental rights scrutiny.
Beyond Europe, the way EES is implemented and overseen will influence global norms. States in other regions, from the Gulf and East Asia to Latin America and Africa, are experimenting with their own biometric borders and digital identity platforms. Some will find the European model attractive precisely because it combines sophisticated technology with a robust legal framework. Others may prefer looser regimes.
In all cases, the core questions remain the same. How much biometric data is a state entitled to collect about non-citizens at its borders? How long may it keep that data? Who should watch the watchers?
The EU Entry Exit System is one of the first large-scale attempts to answer those questions within a comprehensive legal architecture. For travelers, regulators, and advisory firms such as Amicus International Consulting, understanding those answers is now essential to navigating an era in which borders are increasingly defined not just by geography, but by the rules that govern data.
Contact Information
Phone: +1 (604) 200-5402
Signal: 604-353-4942
Telegram: 604-353-4942
Email: info@amicusint.ca
Website: www.amicusint.ca