World (formerly Worldcoin) is a project that proposes to prove you are a real and unique human being by scanning your iris with a spherical device called the "Orb," in order to issue you a digital identifier named World ID. The stated goal is to distinguish humans from bots and artificial intelligences in an age where the fake becomes indistinguishable from the real. Should we be worried? The honest answer is nuanced: the project responds to a real need, but the collection of biometric data as sensitive as the iris has triggered suspensions and investigations by several data protection authorities. The debate is not a conspiracy; it is documented and, in part, settled by regulators.
Definition. "Proof of personhood" is a mechanism aimed at attesting that an online entity is a real and unique human, without necessarily revealing their civil identity. World obtains it through iris biometrics: a pattern considered highly distinctive from one person to another, captured by the Orb to generate a non-duplicable identifier.
The project was launched under the name Worldcoin, associated with a cryptocurrency (the WLD token), before being renamed World to emphasise its identity component rather than its monetary dimension. Three elements, often confused, must be distinguished:
The project's operator highlights technical safeguards: the iris image is, according to its statements, transformed into a code and then deleted, and the system is said to rely on cryptographic (zero-knowledge) proofs designed to avoid linking the identifier to civil identity. These claims reflect the design announced by the operator; their independent verification is precisely one of the issues raised by regulators.
It would be dishonest to present this project as a whim. As artificial intelligence makes fake accounts, fake faces, and fake text indistinguishable from real ones, "proving you are a real and unique human" becomes a coveted resource. It is a structural demand, not an isolated invention: it is found, in other forms, in public identity wallets such as the European Digital Identity Wallet established by the eIDAS 2.0 regulation (EU 2024/1183).
What World specifically — and controversially — adds is the method: anchoring this proof of personhood to one of the most sensitive biometric data points, the iris, collected by a private actor on a global scale. It is this choice — not the objective — that concentrates the concerns.
Iris biometrics are not data like any other. In the European Union, the General Data Protection Regulation (GDPR, EU 2016/679) classifies biometric data used to identify a person among "sensitive" data, subject to reinforced protection. One characteristic aggravates the risk: you can change a compromised password, but not your iris. Leaked biometric data is leaked permanently.
Beyond the legal framework, an MIT Technology Review investigation published in 2022 documented, during the project's test phase across several countries, gaps between the public discourse on privacy protection and the lived experience of those enrolled: information sometimes provided in a language not understood, data collected beyond the iris alone, and consent judged insufficiently informed. This journalistic work helped establish the vigilance that preceded the regulators' action.
The concerns raised by authorities and rights advocates focus mainly on:
These concerns did not remain theoretical: several data protection authorities have acted, and these actions are attributed to the regulators themselves, through their own published decisions. In Spain, the Spanish Data Protection Agency (AEPD) ordered, on 6 March 2024, the suspension of the collection and processing of personal data by the project, through an urgent precautionary measure based on Article 66 of the GDPR, following complaints concerning notably insufficient information, the collection of minors' data, and the impossibility of withdrawing consent.
In Germany, the Bavarian data protection authority (BayLDA), competent for this case, concluded its investigation on 19 December 2024: it found "fundamental" data protection risks and ordered the Worldcoin Foundation to put in place a GDPR-compliant erasure procedure as well as the deletion of certain iris codes collected without a sufficient legal basis. The published decision details these obligations. The operator announced it would appeal.
In Hong Kong, the Office of the Privacy Commissioner for Personal Data (PCPD) published its investigation findings on 22 May 2024: it considered that the operation of the project contravened several principles of the local privacy ordinance (excessive collection of iris and face images, insufficiently informed consent, unjustified retention period) and served the operator with an order to cease its scanning operations in the territory.
Elsewhere, other authorities have acted within their respective frameworks. In Kenya, the government suspended the project's operations in August 2023, the Office of the Data Protection Commissioner (ODPC) having identified shortcomings; in 2025, the High Court ordered, under the regulator's supervision, the erasure of the biometric data collected — an erasure the ODPC subsequently confirmed. In Argentina, the Agency for Access to Public Information (AAIP) opened an investigation and fined the Worldcoin Foundation for shortcomings relating to information and registration.
The lesson is important and runs counter to the fatalistic narrative: a global biometric project does not advance without checks and balances. Data protection law is precisely the terrain where these collections are contested, suspended, sometimes bounded — by regulators' decisions, not by mere suspicion.
An honest clarification is needed: these measures are, in part, precautionary, under investigation, or under appeal, and situations vary from one country to another. To claim the project is "banned everywhere" would be inaccurate; to claim it operates without oversight would be just as much so. The documented reality is that of an active project, but under active regulatory scrutiny.
Neither panic nor denial. The World project is not a conspiracy: it is a private, ambitious, and contested response to a real problem — distinguishing the human from the machine online. The risk lies not in the existence of a proof of personhood, but in the choice to anchor it to irreversible biometrics collected globally by a private actor, and in the genuine quality of consent and safeguards.
The useful question is therefore not "is this evil?" but "does this infrastructure offer verifiable guarantees?": data minimisation, the impossibility of linking the identifier to civil identity, effective deletion of images, independent audit, and the possibility of revoking without being excluded. These properties, not the promises, distinguish a tool of inclusion from a point of control. And it is these that regulators are now demanding.
Does World really scan the iris? Yes. Enrolment goes through a spherical device, the Orb, which captures the iris image to generate the World ID. The operator claims the image is transformed into a code and then deleted; this claim reflects the announced design and is subject to regulatory verification.
Is World ID banned? Not universally. But several authorities have acted: the Spanish AEPD ordered a suspension of collection in March 2024, the German BayLDA ordered erasures in December 2024, and Hong Kong's PCPD ordered operations to cease in May 2024. Other countries (Kenya, Argentina) have investigated and sanctioned. Situations differ by jurisdiction and evolve.
Why does the iris pose a particular problem? Because it is sensitive and irreversible biometric data: unlike a password, you cannot change it if it is compromised. The GDPR grants it reinforced protection, which explains regulators' vigilance over mass collection.
To place this question within the whole file — how money, identity, and the biometric gaze converge, and why to distinguish capability from intent — read the pillar article: Digital identity: panopticon or simplification? And if you want the full investigation, marked out level of certainty by level of certainty, with its institutional sources, Tome 2 — The Architecture of Control takes up each piece of the file.
Yes. Enrolment goes through a spherical device, the Orb, which captures the iris image to generate the World ID. The operator claims the image is transformed into a code and then deleted; this claim reflects the announced design and is subject to regulatory verification.
Not universally. But several authorities have acted: the Spanish AEPD ordered a suspension of collection in March 2024, the German BayLDA ordered erasures in December 2024, and Hong Kong's PCPD ordered operations to cease in May 2024. Other countries (Kenya, Argentina) have investigated and sanctioned. Situations differ by jurisdiction and evolve.
Because it is sensitive and irreversible biometric data: unlike a password, you cannot change it if it is compromised. The GDPR grants it reinforced protection, which explains regulators' vigilance over mass collection.
In July 2023, the CNIL declared that the legality of Worldcoin's iris collection seemed questionable to it, as did the conditions for storing biometric data. Its checks established that the Bavarian authority (BayLDA) is the European lead authority on the case, with the CNIL assisting it. This investigation resulted in December 2024 in corrective measures, including the erasure of iris codes.
No, not via an Orb on French territory: the operator stopped offering verification in France on 20 December 2023, presenting that rollout as access "for a limited time". No formal French ban has however been published: the applicable framework remains the GDPR, under the supervision of the BayLDA as lead authority, with the participation of the CNIL.
Dossier : Monnaie & identité numérique : l'architecture du contrôle
TOME 2: L'Architecture du Contrôle
Accueil · Collection · Journal · Dossiers · Sources