
The European Data Protection Board (EDPB) has announced that supervision of Eurodac, the EU’s fingerprint database for asylum-seekers, is now handled by its new Coordinated Supervision Committee (CSC). The shift, effective 12 June, means France’s data-protection authority CNIL will join other national regulators and the European Data Protection Supervisor in a single audit framework. Eurodac stores the fingerprints of everyone aged six or older who applies for asylum or is caught crossing an external border irregularly. Under the Migration Pact, France must now collect full ten-print sets during initial registration – a practice that has already been codified in the updated Ceseda. The CSC will inspect both the central unit managed by eu-LISA and the national units operated by the French Interior Ministry’s Directorate for Foreigners. For corporate mobility teams the development is indirect but relevant: contractors handling reception-centre logistics or biometric equipment will face stricter tender clauses on data security, and any breach could trigger parallel investigations in Paris and Brussels. Public-sector DPOs are advised to align their records-of-processing with the EDPB’s forthcoming templates, as divergent national practices will no longer be tolerated. The move also foreshadows how future large-scale EU IT systems (EES, ETIAS, ECRIS-TCN) will be policed. Organisations that still treat compliance as a purely French matter risk missing continent-wide requirements that now come with real enforcement teeth.
Source: Leto Legal Watch