The selfie arrived before the match did. Weeks before a fan reached a turnstile at Gillette Stadium outside Boston, or Hard Rock Stadium in Miami Gardens, or Mercedes-Benz Stadium in downtown Atlanta, a small ritual of enrolment had already taken place: open the ticketing app, hold the phone at arm's length, look into the lens, submit. The image became a template, a mathematical abstraction of the geometry of a face — the distances between eyes, the contours of cheekbones, the proportions that distinguish one human countenance from another. When that fan finally approached the gate, a camera read their face again, in real time, and the system asked a single question with an answer measured in fractions of a second: does the live face match the stored one? If yes, the gate opened. The face had become the ticket. The body had become the credential. This was the experience organisers described as frictionless, and it is now possible to say precisely how many people passed through it. FIFA's final figures put attendance at 6,810,966 across 104 matches at sixteen stadiums in the United States, Canada, and Mexico — an average of 99.7 per cent of available seats filled, the highest-attended World Cup ever staged, and a total that beat the record set by the 1994 finals in the United States by roughly 90 per cent. WIRED confirmed in June 2026 that biometric readers were already active at multiple US venues, and Mexican authorities announced that World Cup matches in their country would be, in their phrasing, “100 per cent digitised” through biometric turnstile access. Analysts called it the largest deployment of facial recognition technology in the history of professional sport. They were almost certainly right, and the more important point is that almost nobody who walked through those gates between the opening match on 11 June and the final on 19 July meaningfully decided to be part of it.
The Anatomy of Frictionless
It is worth being precise about what the technology actually does, because the marketing language — “frictionless,” “seamless,” “your face is your ticket” — is engineered to obscure the mechanism. The “Go-Ahead Entry” model, a version of which had already spread through American professional sport from Major League Baseball stadiums housing the Phillies, the Astros, and the Nationals into the World Cup venues themselves, depends on a two-stage process. First, enrolment: the fan supplies a reference photograph, the selfie, which the system converts into a biometric template. Second, verification: at the point of entry, a camera captures a live image and a matching algorithm compares it against the enrolled template, or in some configurations against a gallery of templates belonging to everyone expected at the venue that day. The first is a one-to-one comparison, which is the easier and more accurate task. The second, when the system is identifying a face against a crowd rather than confirming a single claimed identity, is one-to-many, and one-to-many is where the trouble historically begins.
The convenience is genuine. Anyone who has stood in a snaking queue outside a stadium understands the appeal of walking through an access corridor while a camera resolves your identity in under a second, the bottleneck dissolved, the bag-check accelerated, the turnstile reduced to a formality. Vendors describe dynamic recognition systems that identify and validate attendees as they walk, cutting entry times to seconds per person. This is not a fantasy; it works, often well, and it is precisely because it works that the deeper questions got waved through alongside the crowds. The promise of speed did an enormous amount of political labour. It converted a profound change in the relationship between a person and the institutions that watch them into a customer-experience upgrade, a line item in the same category as cashless concessions and mobile parking. The frame was consumer convenience. The reality was biometric enrolment at civilisational scale.
Cardiff, and the Mathematics of Large Crowds
To understand why the scale matters, return to the precedent that digital rights advocates kept invoking: the 2017 UEFA Champions League final in Cardiff, where Real Madrid played Juventus before roughly 170,000 people gathered in and around the Principality Stadium and the city's central railway station. South Wales Police deployed automated facial recognition to scan those crowds against a watchlist of custody images. The system generated 2,470 alerts identifying individuals as potential matches against the police database. Of those, according to figures the force later published on its own website, just 173 were genuine matches. The remaining 2,297 — fully 92 per cent of all the people the system flagged as possible criminals — were false positives. Innocent spectators, attending a football match, algorithmically marked as suspects.
South Wales Police defended the deployment, noting reasonably enough that no system is one hundred per cent accurate, that the false alerts led to no wrongful arrests, and that the technology had contributed to hundreds of arrests across its wider use. The force blamed the Cardiff failure rate partly on poor-quality watchlist images supplied by agencies including UEFA and Interpol, and partly on the fact that this was an early, immature deployment. All of that may be true. None of it dissolves the underlying lesson, which is mathematical rather than anecdotal. When you apply a classifier with even a small false-positive rate to an enormous population, the absolute number of false positives becomes large, and because the genuine targets are rare, the false positives can swamp the true ones entirely. This is the base-rate problem, and it does not go away when the engineering improves. It is a property of running probabilistic matching across crowds of tens or hundreds of thousands. A system can perform exactly within its specified error tolerances and still misidentify thousands of people, simply because thousands is what a small percentage of a vast crowd looks like.
The arithmetic deserves to be made concrete, because it is the single most misunderstood feature of crowd-scale biometrics, and the misunderstanding is what allows reassurances about accuracy to land. Imagine a system advertised as 99.9 per cent accurate — a figure that sounds, to a lay ear, like near-perfection, the kind of number that is supposed to end an argument rather than begin one. Now run it against a stadium crowd of one hundred thousand people, of whom, say, a hundred genuinely appear on a watchlist. A false-positive rate of even one in a thousand, the inverse of that gleaming accuracy claim, produces a hundred false alerts from the ninety-nine thousand nine hundred innocent attendees — a hundred ordinary spectators flagged as suspects, roughly matching the number of genuine hits, every one demanding a human decision about whether to intervene. Push the crowd higher, or the watchlist accuracy lower, and the false alerts overwhelm the real ones entirely, which is exactly what Cardiff demonstrated in the field rather than on a whiteboard. The point is not that the technology is broken. The point is that the technology working as specified is itself the problem, because “working as specified” at the scale of a World Cup means thousands of innocent people miscategorised as a matter of routine, and each miscategorisation is a moment in which a human operator, or an automated escalation, decides what to do with a person the machine has wrongly accused. Convenience, again, conceals the stakes: the fan who sails through the gate never sees the fan two corridors over being drawn aside because an algorithm produced a number above a threshold.
The Cardiff case did not end with the published statistics. It became the basis for the first successful legal challenge to police facial recognition anywhere in the world. Edward Bridges, a civil liberties campaigner from Cardiff who had been scanned by the technology, brought a judicial review supported by the human rights organisation Liberty. In August 2020, the Court of Appeal of England and Wales ruled in R (Bridges) v Chief Constable of South Wales Police that the force's use of the technology had been unlawful. The court found that the deployment was not “in accordance with the law” under Article 8 of the European Convention on Human Rights, because existing legislation and the force's own policies left too much unconstrained discretion over who could be placed on a watchlist and where the technology could be deployed. It found the force's data protection impact assessment deficient. And, crucially for what follows, it found that South Wales Police had failed to discharge their public sector equality duty by neglecting to investigate whether the software exhibited bias on grounds of race or sex. The judgment did not ban the technology. It said, in effect, that deploying it without an adequate legal framework, a serious assessment of risk, and a genuine reckoning with demographic bias was not lawful. Hold that tripartite requirement — legal framework, risk assessment, bias reckoning — because it maps almost perfectly onto everything that was missing from the World Cup deployment.
The Bias Built Into the Lens
The Court of Appeal's concern about racial and gender bias was not speculative hand-wringing. It rested on a body of empirical research that has only hardened since. In December 2019, the United States' own National Institute of Standards and Technology — a federal agency, not an advocacy group — published the most comprehensive study of demographic differentials in facial recognition then attempted, evaluating 189 algorithms from 99 developers against more than eighteen million images of more than eight million people. The findings were unambiguous. For one-to-one matching, the algorithms produced false positives for Asian and African American faces at rates ranging from ten to one hundred times higher than for white faces, depending on the algorithm. For one-to-many matching — the crowd-scanning configuration — the highest false-positive rates fell on African American women, a group that sat at the intersection of the two axes along which the systems failed most badly.
NIST was careful to note that the best-performing algorithms showed undetectable demographic differentials, and the security industry has seized on that caveat to argue that bias is an engineering problem already being solved. There is something to this; the technology has improved, and the gap between the best and worst systems is enormous. But it was precisely the wrong lesson to draw in the context of a multi-venue, multi-vendor, multi-national tournament. The reassurance applies only if every venue, in three countries, under no common procurement standard, happened to deploy a top-tier algorithm, tuned correctly, on well-lit and well-positioned cameras, validated against the actual demographic composition of a global football crowd. No public evidence was produced that this condition held. There was, in fact, no public evidence about which algorithms were running at which gates at all, and the tournament has now ended without that evidence appearing. The demographic stakes were not abstract: a World Cup draws one of the most racially and nationally diverse crowds on earth, precisely the population on which the worst systems fail hardest, and the consequence of a false match at a stadium gate in 2026 was not merely an awkward delay. With Department of Homeland Security personnel and US Immigration and Customs Enforcement agents present at venues, a misidentification carried the potential to escalate from inconvenience into detention.
The escalation is not hypothetical, and the people who have documented it most carefully are not technophobes. The ACLU, through senior policy analyst Jay Stanley, has spent years cataloguing what happens when probabilistic facial matches collide with the machinery of law enforcement, and the organisation has tracked multiple cases of Americans wrongfully arrested on the strength of a bad facial recognition match — a disproportionate number of them Black, which is exactly what the NIST differentials predict. Stanley's argument, sharpened across a decade of writing on the subject, is that the danger is not the technology in isolation but its fusion with state power and the human tendency to over-trust a machine's output: an operator presented with a name and a confidence score is psychologically primed to treat the flagged person as guilty until the person proves otherwise, inverting the burden a free society is supposed to place on the accuser. Now transpose that dynamic to a stadium concourse during a World Cup, with armed officers, immigration agents, the adrenaline of a crowd, a foreign visitor who may not speak the local language and may not understand why they have been pulled aside, and an algorithm that the venue cannot or will not name. The false positive that Cardiff produced 2,297 times in a single evening stops being a statistic and becomes a person, frightened and detained, on the wrong side of a threshold they never knew they had crossed.
The enforcement half of that fusion did not remain theoretical either. Human Rights Watch had already set out the danger in December 2025, documenting the case of an asylum seeker detained by ICE near MetLife Stadium during the Club World Cup final that July, after local police questioned him about a small drone he had used to photograph his family and then asked about his immigration status; he spent three months in detention and was deported. In the same report, Human Rights Watch calculated that between January and October 2025, ICE had arrested at least 92,392 people in cities due to host 2026 World Cup matches, 65.1 per cent of whom had no criminal convictions. During the tournament itself, local advocacy groups in Kansas City reported that at least thirty residents were arrested by ICE while the city was hosting matches, with the sharpest concentration between 15 June and 3 July, and comparable patterns were reported across other host cities. Members of Congress had tried to head this off: Representatives Nellie Pou, Eric Swalwell, and LaMonica McIver introduced three bills — the Save the World Cup Act, the Safe Passage to the World Cup Act, and the Protect World Cup Attendees Act — variously prohibiting civil immigration enforcement near match sites and fan festivals, banning it on public transit in host cities during the tournament, and barring homeland security grant funds from being used for enforcement at game sites. None reached the statute book before the opening match. No documented case links any of these arrests to a facial recognition misidentification, and it would be dishonest to claim otherwise. The honest point is narrower and quite bad enough: the enforcement apparatus that critics warned would sit beside the biometric apparatus did in fact operate, at scale, in the host cities, throughout the weeks the cameras were running.
Three Countries, Three Regimes, No Floor
The legal architecture surrounding all of this is best described as a patchwork that failed at exactly the seams where the tournament crossed borders. Consider the three host nations in turn, because the differences are not pedantic — they determined whether a fan had any rights at all over the data extracted from their face.
The United States has no federal biometric privacy law. None. The protection a fan enjoyed depended entirely on which state they happened to be standing in. Illinois, through its 2008 Biometric Information Privacy Act, offers the strongest regime in the country: private entities must obtain written, informed consent before capturing a biometric identifier, must publish a retention-and-destruction schedule, are forbidden from selling biometric data, and — uniquely — individuals harmed by violations can sue directly, recovering statutory damages of one thousand or five thousand dollars per violation. That private right of action is what gave BIPA teeth, and it is why the most consequential biometric privacy litigation in America, including the case that ended with Clearview AI surrendering a 23 per cent equity stake valued at roughly fifty-two million dollars to a class of plaintiffs, was litigated in Illinois. Texas, through its Capture or Use of Biometric Identifier Act, also requires informed consent and limits retention, but enforcement rests solely with the state attorney general; there is no private right of action, only civil penalties of up to twenty-five thousand dollars per violation pursued at official discretion. And the great majority of US states — including most that hosted World Cup matches — have no specific biometric statute at all. A fan at a match in a state without such a law enjoyed essentially no statutory protection over the biometric template generated from their face.
Canada operates under the federal Personal Information Protection and Electronic Documents Act, which governs the commercial handling of personal information but, as the Office of the Privacy Commissioner and outside counsel have both noted, does not explicitly classify biometric data as sensitive nor mandate privacy impact assessments before a facial recognition system is switched on. The Privacy Commissioner issued fresh guidance on biometrics in 2025 attempting to raise the bar within PIPEDA's existing language, but it remains guidance layered atop a statute not designed for the problem. Quebec is the conspicuous exception across the entire continent: under Law 25, the reform also known by its origin as Bill 64, organisations must conduct privacy impact assessments for biometric systems, obtain explicit opt-in consent, and — strikingly — notify the provincial regulator before creating a biometric database at all. It is the closest thing in North America to the European model.
Mexico regulates through the Federal Law on the Protection of Personal Data Held by Private Parties, the LFPDPPP, which requires consent for the collection of personal data and grants individuals rights of access, rectification, cancellation, and objection. Yet Mexico is also the country whose authorities declared World Cup access “100 per cent digitised” through biometric turnstiles, having already normalised stadium biometric registration across its domestic leagues since the 2022-23 season. The gap between a statute that grants cancellation rights on paper and a tournament that made biometric submission a precondition of entry is the gap in which this entire story lives.
The result was a single tournament — a single ticketing system, a single fan experience marketed under a single brand — running across three irreconcilable legal regimes. A fan's rights over their own face changed the instant they crossed a border to follow their team. In Quebec, a regulator had to be told before their biometric data was pooled. In a non-BIPA US state, no one need be told anything. This is not harmonisation with rough edges. It is the absence of a floor.
What a floor looks like was visible the whole time, on another continent. Since 2 February 2025, the EU's AI Act has prohibited real-time remote biometric identification of people in publicly accessible spaces for law enforcement purposes, subject only to narrowly drawn exceptions requiring enabling national legislation, a fundamental rights impact assessment, registration in an EU database, and a bar on any adverse decision taken solely on the system's output. Remote biometric identification is, moreover, the first item in the Act's Annex III catalogue of high-risk systems. Two weeks after the World Cup final, on 2 August 2026, the Act's transparency obligations became applicable across the Union, including a duty on deployers of biometric categorisation and emotion recognition systems to inform the people exposed to them — the bare disclosure no fan at a North American turnstile could obtain. The comparison carries a sobering wrinkle. On 27 July 2026, eight days after the final, the EU's digital omnibus reform entered into force and postponed the full high-risk regime for Annex III systems, remote biometric identification included, to 2 December 2027. The only jurisdiction with a binding, comprehensive floor for this technology spent the summer of the largest facial recognition deployment in sporting history deciding to defer part of it. That is not an argument against the European model but an argument about the pressure a floor comes under even where one exists — and a reminder that in North America there was nothing to defer, because there was nothing there.
What the French Compliance Institute Found, and What It Means
Into this gap arrived the finding that ought to have stopped the deployment in its tracks. Reviewing the deployment at 2026 World Cup venues, the French Compliance Institute concluded that no clear policy governed when biometric data collected during the tournament would be deleted, and that a fan using facial recognition to enter or pay at a venue had no viable means of discovering how long their facial data would be retained, where it would be stored, who would have access to it, or what would become of it once the tournament was over. It set out six core compliance risks running through the deployment: biometric collection without a clear legal basis, failures of transparency, excessive and undefined retention, cross-border data transfers, exposure through third-party vendors, and algorithmic bias producing false positives. Read that plainly: a system extracting biometric templates from the faces of millions of people, and the most basic governance question — how long is my face kept, and when is it destroyed — had no answer a fan could actually reach.
The distinction between an absent policy and an unreachable one matters less than it might appear, because from the position of the person at the turnstile they are the same object. Retention is not a technicality. It is the entire game. A biometric template that exists only for the few seconds required to open a gate, and is then irreversibly deleted, is a fundamentally different object from one that persists in a database for days, months, or indefinitely. The first is a transient convenience. The second is a permanent record of where a person was, when, and in whose company — a record that can be queried, breached, subpoenaed, sold, or repurposed long after the final whistle. The difference between these two architectures was invisible to the fan at the turnstile; the gate opened identically in both cases. The fan could not tell, by looking, whether their face was held for a heartbeat or enrolled forever, and could not find out by asking either. That asymmetry — the user experiencing only the frictionless moment while the consequential decision happens out of sight and without disclosure — is the precise mechanism by which consent is hollowed out. You cannot meaningfully consent to a retention policy you are not permitted to read.
This is also where the EFF's framing becomes essential. Matthew Guariglia, the senior policy analyst at the Electronic Frontier Foundation who studies surveillance and policing and who holds a doctorate in the history of policing in New York, has described stadium surveillance as “infrastructure” that “will outlast the current World Cup.” The cameras, the readers, the matching pipelines, the relationships between venue operators and law enforcement — these are capital investments, and capital investments are not dismantled when the tournament leaves town. They become the new baseline. The World Cup was the justification, the budget line, the public-safety rationale that made the build-out politically possible. The infrastructure is the thing that remains.
The scale of that capital investment is now a matter of public record, and it is the argument made concrete: the United States government allocated more than one billion dollars to World Cup security infrastructure and equipment upgrades, a sum that flowed largely into private hands through government-industry partnerships and bought hardware with a service life measured in decades rather than weeks. The receipts are already visible. Camera-equipped robot dogs patrolled venues in Dallas, East Rutherford in New Jersey, and Monterrey in Mexico. Multiple states, New York conspicuously among them, used federal tournament money to expand the number, capability, and deployment of police drones — aircraft capable of city-wide observation that will still be airworthy long after the trophy has been handed over. And in the single sharpest illustration of the whole phenomenon, the mayor of Seattle reactivated a major closed-circuit television network that the city had previously switched off precisely because of biometric privacy concerns. Read that sequence again, because it is function creep in its purest form: a system a democratic process had switched off for stated privacy reasons was switched back on under a tournament rationale, and no equivalent process is scheduled to switch it off again. Reporting after the final, notably in Foreign Policy on 17 July 2026, framed the tournament exactly this way — as an occasion on which the United States tested new surveillance technology at scale, with ICE's own fiscal year 2026 congressional budget justification drawing the link between the World Cup and federal law enforcement explicitly, and with a Department of Homeland Security definition under which a stadium the public can freely enter counts as a public place, so the surveillance network inside it requires no warrant at all. Function creep is not a risk to be guarded against; it is the predictable, observable life cycle of every surveillance system that has ever been installed for an event and then quietly kept.
The Coercion Hiding Inside “Consent”
Defenders of the deployment reached, inevitably, for consent. The fan downloaded the app. The fan submitted the selfie. The fan agreed to the terms. Nobody held a gun to anyone's head. This argument deserves to be taken seriously and then dismantled, because it is the load-bearing wall of the entire enterprise, and it does not hold weight.
European data protection law, which has thought about this longer and harder than any American regime, sets the bar that exposes the problem. Under the GDPR, biometric data processed to uniquely identify a person is “special category” data, subject to heightened protection, and consent to process it must be — in the regulation's words — freely given, specific, informed, and unambiguous, with a genuine ability to withdraw. The operative phrase is “freely given.” European regulators have repeatedly found that consent extracted under a power imbalance is not free. The most instructive example comes from Sweden, where the data protection authority fined a school that had used facial recognition to track student attendance. The school had obtained parental consent. The regulator ruled that consent invalid anyway, because the imbalance of power between an institution and the families dependent on it meant the agreement was effectively coerced. The principle that follows is that biometric processing may not be a precondition of accessing a service unless it is strictly necessary to that service — and a retail customer, or a football fan, must be offered a genuine alternative that does not involve surrendering their biometrics.
Apply that principle to a World Cup gate. Was facial recognition strictly necessary to admit a ticket-holder to a football match? Plainly not; the turnstile predates the algorithm by a century. Was there a power imbalance between a fan who had spent a small fortune on tickets, travel, and accommodation and the tournament that controlled the only door? Plainly there was. Was a fan, having arrived at the stadium on the day of the match, in any practical position to refuse the biometric pathway and demand a non-biometric one? Only if such an alternative was offered, clearly, without penalty or delay or relegation to a slower queue — and the burden of proving that alternative existed, and worked, and was genuinely equivalent, fell on the organisers, who did not demonstrate it before the tournament and have not demonstrated it since. Consent that you cannot refuse without forfeiting something you have already paid for is not consent. It is a tollbooth wearing the costume of a choice. The selfie submitted weeks in advance, bundled into the act of buying a ticket, was consent in the most degraded sense the word can bear: technically obtained, practically compelled, and informed about everything except the things that mattered — retention, sharing, the identity of the algorithm, the presence of immigration enforcement at the other end of the match. It is worth noting that more than 120 civil society organisations, the ACLU and Amnesty International among them, thought the risks serious enough to issue a joint travel advisory before the tournament, warning prospective visitors of invasive social media screening, searches of electronic devices, racial profiling, arrest, detention, and deportation. That is an extraordinary document to have to publish about a football tournament, and it tells you what informed consent would actually have had to disclose.
The Players, Who Cannot See Their Own Data Either
If the fans are the broad base of this pyramid, the players sit at its sharp and surveilled apex, and their predicament reveals how little the convenience narrative explains. When FIFPRO, the international federation of professional footballers, surveyed players through ten national player unions spanning its four divisions — Africa, the Americas, Asia and Oceania, and Europe — eighty per cent said they wanted access to their own performance data in order to improve how they perform on the pitch. The same players reported that they were concerned about how that data is collected and used, that they were often unsure of their rights and how to protect them, and that clear, practical, enforceable information about those rights was lacking. What mattered to them was not merely access but control over who else reached it. These are not anonymous fans swept up incidentally in a crowd. They are the most scrutinised athletes on the planet, the direct subjects of an entire industrial complex of performance data, and even they struggle to see, retrieve, or comprehend the record being made of their bodies.
That survey is why the union launched its Charter of Player Data Rights in September 2022, ahead of the Qatar World Cup and after two years of development alongside FIFA: it foresaw that new technologies — performance monitoring, in-game tracking, health and biometric measurement, fan-engagement systems — were generating intimate data about players that the players themselves did not control and often could not access. FIFPRO's subsequent published work on volumetric and biometric player data documents the same governance gap from the other end, arguing that the processing of special categories of data, including personal health and biometric information, requires the direct agreement of the player concerned together with collective safeguards, and that the industry still lacks agreed standards governing how such data is collected, protected, and used. The pace of technological development, on the union's own account, continues to outrun the protections meant to constrain it. If the people with the most resources, the most representation, a dedicated global union, and a published charter negotiated with the game's governing body still find themselves arguing for access to and control over the data generated from their own bodies, the proposition that an ordinary fan gave meaningful, informed consent at a turnstile collapses entirely. The players are the canary. Their struggle to reach their own data tells you, with brutal clarity, what the ordinary spectator's rights were actually worth: the system was not built to be legible to the people it measures.
Madison Square Garden, or What the Database Is For
The final piece of the argument is a question of imagination, and the honest answer is that we do not need to imagine. We can look at what venue operators have already done with facial recognition when no World Cup, no terrorism threat, and no security rationale was anywhere in sight.
In late 2022, Madison Square Garden Entertainment used facial recognition to identify and eject lawyers from its venues — not for any crime, not for any threat, but because the lawyers worked at firms engaged in litigation against the company. The most widely reported case involved Kelly Conlon, an attorney who was removed from Radio City Music Hall while attending a Rockettes show with her daughter's Girl Scout troop. Conlon was not personally working on the case against an MSG-owned business; her firm's involvement was enough. The company had built an “attorney exclusion list,” fed it into its facial recognition system, and used the technology to enforce a corporate grudge against members of the public who had bought tickets. Courts subsequently allowed the practice to continue.
This is the demonstration that dissolves every reassurance about purpose limitation. A biometric system installed and justified as a tool for security and convenience was repurposed, by a private entity, to settle scores — to exclude people from public entertainment on the basis of their professional associations. No new law was broken, because in New York no specific law forbade it. The capability, once built, found new uses that its architects never advertised, because that is what capabilities do. Now scale that logic across sixteen World Cup stadiums, three countries, 6.8 million faces, no federal floor in the host nation, no retention policy a fan could locate at any venue, immigration enforcement agents on site and arresting people in the host cities throughout, and a documented history of law enforcement data-sharing that the ACLU warned foreign fans about explicitly. The question was never whether the database could be misused. The question is what plausible mechanism now exists to stop it, and the answer, across most of this tournament's footprint, is none.
What Is Owed, and By Whom
The closing question — what obligations organisers, governments, and technology providers bear to the people whose bodies have been converted into data — does not admit a both-sides shrug, because the asymmetries here are too stark to balance. Nearly seven million people were enrolled into a cross-border biometric system whose retention policy no fan could locate; whose error characteristics fall hardest on the racial and gender groups most heavily represented in a global football crowd; whose architecture sat beside an immigration enforcement operation that arrested people in host cities while the matches were being played; and whose consent mechanism was a selfie bundled into a ticket purchase that could not be refused without forfeiting an expensive, often once-in-a-lifetime journey. Against this, the affirmative case is speed at the turnstile. That is not a balance. It is a category error dressed as a trade-off.
The obligations, then, are specific and heavy, and the tournament's ending makes them more urgent rather than less, because the templates still exist and the cameras are still mounted. Technology providers owe transparency about which algorithms ran where, validated against the actual demographic composition of the crowds they scanned, with published, independently audited false-match rates — the bias reckoning that the Bridges court demanded and that NIST showed is non-negotiable. They owe data minimisation by design: templates that exist for the seconds required to open a gate and are then irreversibly destroyed, with deletion that can be verified rather than merely promised, and they owe an account, now, of whether the templates taken this summer have in fact been destroyed. Organisers — FIFA and the host venues — owed a genuine, frictionless, non-penalised non-biometric pathway at every gate, because consent that cannot be refused is not consent, and they owed a single, published, comprehensible retention-and-deletion policy that a fan could read before arriving, rather than one that a compliance review could not locate afterwards. They owe the players the access and control FIFPRO's members have been asking for and have not been given, because a system that cannot show its most scrutinised subjects their own data has no business scanning the rest. And governments owe the floor that still does not exist: the United States, conspicuously, owes a federal biometric standard, because a constitutional democracy that leaves the protection of its visitors' faces to the accident of which state line they stand behind has abdicated rather than legislated. Where a continental tournament crosses three regimes, the obligation runs to the strictest of them — Quebec's prior notification, the GDPR's freely-given consent, the AI Act's prohibition on scanning publicly accessible spaces without authority — not the weakest, because rights cannot be allowed to evaporate at a border the fan crosses to follow a match.
There is a deeper obligation underneath all of these, and it is the one the convenience narrative was designed to make us forget. A face is not a barcode. It cannot be reissued when it leaks, revoked when it is abused, or changed when it ends up in a database its owner never knew existed. A password compromised in a breach can be reset by lunchtime; a credit card cancelled and reissued within a week; even a stolen passport replaced through a tedious but finite bureaucratic ordeal. A facial template, once extracted and exfiltrated, is the person, permanently, in every future system that learns to read it. When attending a public event becomes a mechanism for enrolment into a permanent, cross-national biometric record — invisible, unconsented in any meaningful sense, and ungoverned at the points that matter most — the people running that event have not sold a ticket. They have taken something that cannot be given back, and offered a faster queue in exchange. The least they owed, before 6,810,966 people walked through those gates, was to say so out loud, in language a fan could understand, before the selfie was taken rather than after the data was gone. They preferred the language of frictionlessness, which is the language of a transaction in which only one party knows what is being traded. The tournament is finished; the trophy has been lifted and the temporary seating taken down. The cameras, the templates, the drones, the reactivated CCTV network in Seattle and the robot dogs in Dallas are still here, and nobody has been asked whether they should be.

