
The European Data Protection Board (EDPB) announced on 12 June that its Coordinated Supervision Committee (CSC) is now the sole supervisory authority for Eurodac, the fingerprint database that underpins the EU’s asylum system. Until now, oversight was split between each national data-protection authority and the European Data Protection Supervisor. From a French perspective the change means the CNIL will sit on the CSC and help set common audit priorities, rather than conducting France-only inspections. The CSC can issue guidance that is directly applicable in Paris, Marseille or at the new Bardonnex border-procedure hub near Geneva. Why does this matter to corporate mobility? First, Eurodac is increasingly queried when authorities check whether a foreign worker previously applied for asylum elsewhere in Europe. A more harmonised supervisory framework should reduce the risk of inconsistent matches that can delay work-permit approvals. Second, the move signals how the EU intends to govern its growing stack of large-scale IT systems (EES, ETIAS, ECRIS-TCN). Companies that handle traveller biometrics must prepare for pan-European audit protocols rather than 27 different ones. Data-protection officers in multinationals that contract with French migration agencies should expect the CNIL to align its positions with CSC guidance, particularly on retention periods and access-log monitoring. The EDPB says the first coordinated inspection plan will be agreed in October. While private firms do not feed data into Eurodac, carriers and visa outsourcers increasingly interface with systems that cross-link to it. Forward-looking compliance teams should track CSC minutes—now published in English and French—to anticipate future technical and contractual requirements.