2026 Calendar

Who Controls America's Biometric Data? The TSA Foreign Contractor Controversy

Who Controls America's Biometric Data? The TSA Foreign Contractor Controversy

By Rex M. Lee, Security Advisor | My Smart Privacy

Why Is a Foreign Company Processing Highly Sensitive Information on U.S. Travelers?

A growing controversy involving the Transportation Security Administration raises a fundamental national-security and privacy question: why is the United States allowing a foreign company to process highly confidential identity and biometric information collected from American travelers?

The company at the center of the controversy is IDEMIA, a French identity-security and biometrics company whose technology has been used in systems involving the Transportation Security Administration, Customs and Border Protection, the FBI, the Department of Defense, state motor-vehicle agencies, and other government entities.

The information processed through these systems may include:

  • Driver's-license information
  • Passport information
  • Facial-recognition images
  • Fingerprints and other biometric identifiers
  • Personally identifiable information
  • Travel and identity-verification records

These are not ordinary consumer data points. They are among the most sensitive forms of information a government can collect on its citizens.

Congressional Concerns

Democratic Congressman Josh Gottheimer of New Jersey has called for a government-wide review of federal contracts involving IDEMIA, including its work with the TSA, CBP, FBI, and Department of Defense.

His concern reflects a larger issue: the United States is relying on a foreign-owned contractor to support identity and biometric systems that affect millions of American travelers and citizens.

Previous congressional testimony has also raised concerns about IDEMIA's historical business activities and relationships in China. That testimony alleged that the company maintained relationships with Chinese government and commercial entities and supplied security technology to Chinese airports.

These claims do not prove that IDEMIA is owned or controlled by the Chinese Communist Party. However, they do raise legitimate questions about foreign influence, data security, access controls, supply-chain exposure, and the protection of confidential information belonging to U.S. citizens.

The Proposed Sale to a Spanish Company

The issue has gained additional attention because IDEMIA Public Security is being sold to Amadeus IT Group, a major Spanish travel-technology company.

Amadeus already operates within the global aviation industry, providing technology used for airline reservations, passenger processing, check-in systems, airport operations, and other travel services.

The acquisition would place IDEMIA's public-security and biometric identity operations under the ownership of another foreign corporation with extensive involvement in the international travel-data ecosystem.

This creates an obvious policy question: should highly confidential identity and biometric information collected by the U.S. government be processed by any foreign-owned company, regardless of whether that company is French, Spanish, Chinese, or based in another country?

A National-Security and Privacy Issue

The controversy is not simply about where a company is headquartered. It concerns who develops, controls, maintains, and potentially accesses the systems used to process sensitive government information.

When travelers present a driver's license or passport at an airport, most assume that their information is being handled directly by the U.S. government.

They may not realize that a private foreign contractor could be involved in the technology used to authenticate their identity, process their facial image, or manage related records.

That creates several unresolved questions:

  • Where is the information stored?
  • Who has access to it?
  • Is the information retained after identity verification?
  • Is it shared with subcontractors or foreign affiliates?
  • Can foreign governments legally compel access?
  • What cybersecurity and auditing standards apply?
  • Who is accountable if the information is breached, misused, or transferred?

These questions are especially serious when biometric information is involved. A password can be changed. A credit-card number can be replaced. A face, fingerprint, or iris pattern cannot.

Foreign Contractors and Digital Sovereignty

The IDEMIA controversy exposes a much broader problem involving digital sovereignty.

The United States increasingly depends on multinational technology companies and foreign contractors to operate systems involving national security, identity verification, transportation, communications, cloud computing, artificial intelligence, and biometric surveillance.

This dependence can create security vulnerabilities even when no wrongdoing has been proven.

A foreign company does not have to be directly controlled by an adversarial government to create risk. Exposure can arise through foreign laws, corporate partnerships, overseas operations, subcontractors, acquisitions, software supply chains, or government-access requirements.

For that reason, government contracting decisions involving biometric and identity information should be held to the highest possible standard.

The Need for Accountability

Congress should conduct a transparent, government-wide review of all foreign-owned companies involved in processing sensitive information belonging to U.S. citizens.

That review should determine:

  • What information each contractor collects or processes
  • Whether biometric information is stored or retained
  • Where the information is processed and stored
  • Whether foreign employees, affiliates, or governments can access it
  • Which subcontractors support the systems
  • Whether the systems have been independently audited
  • Whether government agencies can operate the systems without foreign dependency

The government should also explain why a foreign-owned corporation is necessary for functions involving passports, driver's licenses, facial recognition, and other highly confidential identity information.

Conclusion

The central issue is straightforward: the United States should not outsource control over the identity and biometric information of its citizens without full transparency, strict security protections, and clear accountability.

IDEMIA's reported relationships and historical operations in China deserve careful scrutiny, but the larger issue extends beyond China.

Americans have a right to know which companies process their personal and biometric information, where that information goes, how long it is retained, and whether foreign entities can access it.

When the government collects a traveler's passport, driver's-license information, facial image, or biometric identifiers, that information should be protected as a matter of privacy, property rights, civil liberties, and national security.

The question Congress must answer is not simply whether one particular foreign company can be trusted. The larger question is: why is the U.S. government allowing any foreign-owned company to process the most sensitive identity information belonging to American citizens?

About the Author

Rex M. Lee holds Wireless Industry and Application Development Experience (35 years)/Freelance Technology Journalist/Privacy and Data Security Consultant/Blackops Partners Analyst and Researcher/Public Speaker - For More Information Visit My Smart Privacy at: www.MySmartPrivacy.com

Join the Conversation at TechTalk Summits

Want to dive deeper into shaping the future of U.S. innovation? Join us at any TechTalk Summits to engage with experts and explore strategies for digital success.

Register now and stay ahead of the curve! All Events