Live Archive|Investigative Journalism & Declassified Records
Digital Edition
Unclessify
Unclessify
The Architecture of Biometric Checkpoints: Scrutiny Over Airport Face Recognition Systems
garanteprivacy.it

The Architecture of Biometric Checkpoints: Scrutiny Over Airport Face Recognition Systems

garanteprivacy.itItalia2026public
#protezione-dati#biometria#garante-privacy#gdpr#sicurezza-aeroportuale

Verified Primary Investigative Source: garanteprivacy.itItalia

Share:

Editorial Transparency & Fair Use Notice

Investigative dossier curated and structured by the Unclessify editorial team based on official disclosures, court filings and declassified records published by garanteprivacy.it. Historical context, analytical synthesis, and editorial commentary are provided by Unclessify under Public Interest, Freedom of the Press, and Fair Use principles.

Read Full Editorial Policy & Source Transparency →

Official Records & Declassified Dossier

Public Interest and Systemic Significance

The rapid deployment of automated facial recognition in critical transit hubs represents a structural shift in how physical mobility intersects with fundamental privacy rights. When biometric identification is integrated into passenger flows under the banner of operational efficiency, the technical boundary between voluntary convenience and systemic surveillance becomes fragile. Scrutinizing the architecture of these systems is essential to ensure that fundamental safeguards are not subordinated to throughput optimization.

The regulatory inquiry into the biometric infrastructure operating at Milan Linate Airport highlights an acute legal and architectural confrontation. At stake is whether centralized or hybrid biometric storage models can ever satisfy the strict threshold of European privacy laws when deployed across high-density transit environments. The findings establish a precedent that reaches far beyond a single terminal, influencing the future design of digital border and boarding solutions across the European Union.

Historical and Institutional Trajectory

The integration of automated facial recognition at Milan Linate began moving toward formal execution in the spring of 2024. On May 3, 2024, the airport management operator Società per Azioni Esercizi Aeroportuali (SEA) submitted formal notification indicating its intention to deploy an automated passenger verification system designated as FaceBoarding. This technical initiative aimed to replace manual credential checks across successive control perimeters within the airport infrastructure.

Shortly thereafter, on May 24, 2024, the European Data Protection Board adopted Opinion 11/2024 pursuant to Article 64(3) of Regulation (EU) 2016/679. This provision empowers the board to issue formal positions on matters of general application to ensure consistent enforcement across the European Economic Area under Article 65(1)(c). The opinion established rigorous benchmarks, specifically distinguishing between architectures that maintain passenger-held encryption keys and centralized architectures that compromise passenger autonomy.

In response to the structural criteria formulated in Opinion 11/2024, the Italian supervisory authority initiated an ex officio investigation on December 16, 2024. The inquiry was opened to determine the specific architectural classification of the FaceBoarding system deployed at Milan Linate. Concurrently, the authority served SEA with a formal request for information to reconstruct the exact data processing workflows operating behind the physical verification kiosks.

The airport operating authority submitted its primary response on February 14, 2025, followed by supplementary technical submissions on April 14, 2025. Facing persistent technical ambiguities surrounding data retention and key management, the supervisory authority escalated the procedure. On July 7 and 8, 2025, regulatory inspectors conducted an on-site inspection at the company headquarters to directly verify the physical and logical configuration of the biometric hardware.

Key Institutional and Corporate Entities

The regulatory trajectory involves key public authorities, infrastructural operators, and supranational regulatory bodies:

  • [[Società per Azioni Esercizi Aeroportuali S.E.A.|Q3963725]] (SEA): The managing body of Milan Linate Airport responsible for configuring, deploying, and operating the FaceBoarding infrastructure and processing passenger travel credentials.
  • [[Garante per la protezione dei dati personali|Q3758364]]: The national data protection authority of Italy, acting as the primary supervisory body conducting the administrative investigation, on-site inspections, and enforcement procedures.
  • [[European Data Protection Board|Q54620817]] (EDPB): The independent European body responsible for ensuring the consistent application of data protection rules throughout the European Economic Area through statutory opinions and consistency mechanisms.

Critical Examination of the Technical Evidence

Architectural Classification and the EDPB Benchmark

The core technical dilemma centers on how the FaceBoarding infrastructure aligns with the structural templates defined in EDPB Opinion 11/2024. The European supervisory framework clearly separated compliant systems from non-compliant deployments through defined technical models. Scenario 2 was characterized by the centralized storage of encrypted biometric templates within the airport where the secret decryption key remains exclusively known to the passenger, thereby preserving data subject sovereignty.

Conversely, Scenario 3.1 describes a configuration where cryptographic keys are not exclusively held by the individual data subjects. Under paragraphs 68 through 70 of Opinion 11/2024, such architectures fail to ensure that passengers maintain active control over their personal information. The European Data Protection Board concluded that this systemic deficiency increases vulnerability to data breaches and unauthorized access, resulting in structural incompatibility with Article 5(1)(f), Article 25, and Article 32 of the GDPR.

Pertanto il trattamento proposto nell’ambito dello Scenario 3.1. non può essere compatibile con i requisiti in materia di protezione dei dati fin dalla progettazione e protezione dei dati per impostazione predefinita ai sensi dell’articolo 25 GDPR

Processing Scope Across Airport Perimeters

According to the official filings submitted by SEA on February 14, 2025, FaceBoarding governs passenger transit across two mandatory physical checkpoints: the entry perimeter to the sterile security area and the boarding gate prior to aircraft ingress. The operational rationale advanced by the operator focuses on accelerating queue throughput and elevating user satisfaction metrics through service streamlining.

The system incorporates two operational modalities: a single-transit execution and an optional long-term registration program. Under the long-term track, passenger data is retained in operational databases until December 31 of the calendar year in which enrollment occurred. This extended retention window significantly elevates the compliance stakes, as persistent biometric storage requires enhanced structural guarantees under privacy by design mandates.

The Digital Travel Credentials Defense

In its formal defense, SEA argued that its implementation departs from the impermissible baseline of Scenario 3.1. The operator emphasized that the biometric processing operates through Digital Travel Credentials (DTC) and maintains mechanisms ensuring high passenger agency. In its submission of February 14, 2025, the company stated that it maintains no capability to directly access, alter, or decrypt the underlying credentials stored in transit.

SEA non ha, pertanto, modo di accedere, modificare, né decriptare le Digital Travel Credentials, che sono trasferite ai sistemi S.E.A. per consentire l’identificazione presso l’aeroporto solo a seguito di un’azione da parte del passeggero in tal senso

SEA maintained that while architectural analogies to Scenario 3.1 exist at a superficial level, specific mitigations reduce systemic risks to passenger freedoms. However, technical analysis indicates that the physical interaction required at biometric checkpoints does not automatically resolve underlying cryptographic dependencies. If authentication relies on intermediary validation components not fully controlled by the individual, the structural risks identified in EDPB Opinion 11/2024 remain active.

Unresolved Architectural Questions

The technical documentation leaves fundamental engineering questions open regarding data isolation and cryptographic custody. First, while SEA asserts an inability to decrypt Digital Travel Credentials, the exact boundary between local device authentication and centralized verification servers during gate matching remains sensitive. The technical evidence does not clarify the exact lifecycle of transient matching logs generated during high-load boarding sequences.

Second, the distinction between active user consent and structural architectural compliance must be maintained. High user satisfaction and procedural speed cannot substitute for structural compliance with Article 25. The on-site inspections conducted on July 7 and 8, 2025, reflect the necessity of verifying physical server racks, cryptographic key storage modules, and data deletion scripts rather than relying solely on procedural statements.

Source Provenance and Legal Transparency

This dossier is constructed from the official administrative proceedings and factual determinations formulated by the Italian Data Protection Authority (Garante per la protezione dei dati personali) under decision record Provvedimento del 12 marzo 2026 [10238246]. Public access to these proceedings is governed by the statutory framework of Legge 22 aprile 1941 n. 633, Article 5, which establishes that official texts of state administrations and public authorities are exempt from copyright and reside in the public domain.

The underlying institutional opinions, including EDPB Opinion 11/2024 issued under Article 64(3) of Regulation (EU) 2016/679, constitute public European regulatory instruments. Access to the primary enforcement record and administrative case history is maintained through the official legal repository of the Garante per la protezione dei dati personali (Document Web Record 10238246).

Related content

Click to switch theme:

Comments (0)