Worldcoin Foundation – Order (Italy, 2024)

Order
Garante per la protezione dei dati personali21 March 2024Italy
final
Order

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Worldcoin Foundation was investigated for using biometric data in its cryptocurrency project without clear consent. This matters because it highlights the importance of transparency when handling sensitive information. Companies should ensure they clearly communicate how they use personal data.

What happened

Worldcoin Foundation processed biometric data for a cryptocurrency project without clear consent mechanisms.

Who was affected

Individuals whose biometric data was collected by the Worldcoin project were affected.

What the authority found

The Garante ruled that the Worldcoin Foundation lacked a valid legal basis for processing biometric data, violating GDPR requirements.

Why this matters

This case emphasizes the need for companies to be transparent about how they collect and use sensitive data. It serves as a reminder for businesses to review their data practices to ensure compliance.

GDPR Articles Cited

AI-verified

Art. 7(GDPR)
Art. 9(1) GDPR
Art. 9(2) GDPR
Art. 4(14) GDPR
Art. 58(2)(a) GDPR
View original scraped data
Art. 4(14) GDPR
Art. 7(GDPR)
Art. 9(1) GDPR
Art. 9(2) GDPR
Art. 58(2)(a) GDPR

Original data from scraper before AI verification against source document.

Source verified 12 April 2026
scope corrected
Full Legal Summary
Detailed

The Italian DPA (Garante) initiated an investigation concerning the Worldcoin Foundation’s (the controller) cryptocurrency project. The controller offers a phone application (World App) where data subjects create a digital identity profile (World ID). An in-person device called the ‘Orb,’ which scans data subjects’ irises and faces, can be used to establish a ‘verified’ World ID. In exchange for the biometric data, data subjects are offered ‘free’ Worldcoin tokens via the phone application. During the investigation, the Garante observed that Italian citizens could download the World App, wherein they could provide personal data and claim ‘free’ tokens. The Garante noted that Orbs were not present in Italy at the time of the investigation. However, it considered that the World App’s availability anticipated the future installation of Orbs in Italy. The Garante also considered that the controller lacked age verification mechanisms for installation of World App or processing of biometric data via the Orb. The Garante made a request for information, which the controller responded to with documentation as well as a data protection impact assessment. It asserted that its legal basis for processing biometric data was consent. The Garante issued a warning against the controller pursuant to Article 58(2)(a) GDPR, finding that the processing of biometric data that may be carried out in Italy would likely lack legal justification under Article 9(2) GDPR and violates Article 7 GDPR consent obligations. The Garante categorised the imaging of data subjects’ irises and faces as ‘biometric data’ pursuant to Article 4(14) GDPR. Processing of such data is generally prohibited under Article 9(1) GDPR, and the Garante cautioned that in this case consent was unlikely to suffice as a justifying legal basis pursuant to Article 9(2) GDPR. It noted that the controller provided insufficient information about risks related to processing for data subjects to form adequate consent pursuant

Outcome

Order

A binding order requiring the controller to take specific action.

Violations (1)

Unclear Cookie Information
high

The cookie banner or cookie policy provides vague, incomplete, or unclear information about what cookies are used and why.

Art. 12, 13 GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Worldcoin Foundation in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Order Date

21 March 2024

Authority

Garante per la protezione dei dati personali

GDPRhub ID

gdprhub-7786

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Worldcoin Foundation - Italy (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: