Tools for Humanity: Corporate Structure and Liability Shielding
The “World” Rebrand and the Corporate Triad
The entity formerly known as Worldcoin, rebranded to **World** in October 2024, operates through a bifurcated legal structure designed to separate technological development from regulatory liability. This architecture relies on two primary pillars: **Tools for Humanity (TFH)**, a technology company, and the **Worldcoin Foundation**, a non-profit steward. While the public-facing brand shifted to “World” to emphasize a broader identity network, the underlying corporate remained focused on jurisdictional arbitrage to mitigate the from global biometric enforcement actions in 2025. Tools for Humanity Corporation, incorporated in **Delaware** and headquartered in San Francisco, serves as the primary developer of the Orb hardware and the World App. yet, to navigate the European Union’s General Data Protection Regulation (GDPR), TFH established a German subsidiary, **Tools for Humanity GmbH**, based in Erlangen and Munich. This German entity was as the data controller for European operations, a strategic move intended to centralize regulatory oversight under the Bavarian State Office for Data Protection Supervision (BayLDA), theoretically shielding the company from direct enforcement by other EU member states. The second pillar, the **Worldcoin Foundation**, is domiciled in the **Cayman Islands** (with subsidiaries like **World Assets Limited** in the British Virgin Islands). The Foundation technically problem the WLD token and governs the protocol. This separation allows TFH to claim it “builds the software” while the Foundation “manages the community,” a defense frequently deployed when US securities regulators question the WLD token distribution.
Entity Liability Map (2025)
The following table details the specific corporate entities targeted by regulators during the 2024-2025 crackdown, revealing how the “decentralized” structure functioned under legal pressure.
| Entity Name | Jurisdiction | Primary Function | 2025 Regulatory Status |
|---|---|---|---|
| Tools for Humanity Corp. | Delaware, USA | Hardware/Software Dev | Fined by South Korea (PIPC); Under US scrutiny for tech exports. |
| Tools for Humanity GmbH | Bavaria, Germany | EU Data Controller | Subject of BayLDA audit; Direct target of Spanish (AEPD) ban. |
| Worldcoin Foundation | Cayman Islands | Token Issuer / Governance | Fined by South Korea; Named in Kenyan High Court deletion order. |
| World Assets Limited | British Virgin Islands | Asset Holding | Named in Kenyan lawsuit for data transfer violations. |
The “Orb Operator” Liability Buffer
A serious component of TFH’s liability shielding strategy is the **Orb Operator** model. Rather than employing staff directly to collect biometric data, TFH contracts with independent local entities or individuals to manage the Orbs. These operators are classified as independent contractors, a designation that attempts to sever TFH’s liability for local data protection violations. In 2025, as raids occurred in markets like Hong Kong and Spain, this of separation faced intense scrutiny. The standard “Operator Agreement” explicitly shifts compliance load to the local contractor.
“You and any persons who assist you, including any field staff, are independent contractors and not our employees… It is your responsibility to make sure that your use of the Services is legal where you use them.”
, TFH Orb Operator Terms and Conditions (2025)
Regulators in South Korea and Kenya rejected this defense. The South Korean Personal Information Protection Commission (PIPC) fined both the Foundation and TFH in September 2024 (enforced through 2025), ruling that TFH was inextricably linked to the data collection process regardless of the employment status of the ground team. The PIPC imposed a fine of **379 million KRW** on TFH and **725 million KRW** on the Foundation, piercing the corporate veil by holding both the developer and the DAO liable for the same privacy breaches.
The “User Custody” Pivot
Facing existential threats from the Spanish AEPD and the German BayLDA, TFH executed a technical pivot in late 2024 known as **”Personal Custody.”** By updating the Orb software to encrypt biometric data (iris codes) and store them solely on the user’s device rather than in a centralized database, TFH attempted to reclassify itself as a software provider rather than a data controller. This move was a direct response to the **Article 66 GDPR** urgency procedure invoked by Spain, which banned Worldcoin’s operations even with the German lead authority’s ongoing audit. Spain’s High Court upheld the ban, stating that the “safeguarding of the general interest” prevailed over TFH’s commercial interests. The “Personal Custody” model that since TFH no longer holds the decryption keys to the raw biometric data, it cannot be compelled to delete what it does not possess. yet, the Kenyan High Court’s ruling in 2025 demonstrated the limits of this technical defense. The court ordered the deletion of all data collected prior to the pivot. In January 2026, the Office of the Data Protection Commissioner (ODPC) in Kenya confirmed that TFH had erased the data of Kenyan users, proving that even with the complex corporate structuring and technical obfuscation, sovereign courts retained the power to force the entity’s hand.
Jurisdictional Arbitrage Failure
The primary failure of the TFH corporate structure in 2025 was the collapse of the “One-Stop-Shop” method under GDPR. TFH relied on its Bavarian subsidiary (TFH GmbH) to ensure that only the BayLDA could regulate its EU operations. This strategy crumbled when the Spanish AEPD successfully argued that the processing of biometric data constituted an immediate risk to citizens’ rights, allowing them to bypass the German regulator. Portugal followed Spain’s lead, and by mid-2025, the “Bavarian Shield” had fractured. The inability of the German subsidiary to prevent other EU nations from imposing unilateral bans exposed a serious weakness in the centralized compliance strategy. Simultaneously, the rebranding to “World” and the launch of “World Chain” attempted to decentralize the network further, yet the enforcement actions of 2025 consistently targeted the centralized entry points: the hardware manufacturer (TFH) and the token issuer (Foundation).
The World Rebrand: Nomenclature Changes Amidst Regulatory Heat
The World Rebrand: Nomenclature Changes Amidst Regulatory Heat
The Strategic Pivot of October 2024
On October 17, 2024, at a tightly choreographed event in San Francisco, Tools for Humanity (TFH) executives Alex Blania and Sam Altman announced the immediate rebranding of “Worldcoin” to simply **”World.”** While the company publicly framed this nomenclature shift as a reflection of a broadened mission to “accelerate every human,” investigative analysis suggests the move was a calculated response to intensifying global regulatory hostility. By dropping “coin” from the primary identity, the organization attempted to decouple its biometric infrastructure from the volatile and legally perilous cryptocurrency narrative that had triggered investigations in over a dozen jurisdictions. The rebrand was not cosmetic; it introduced a tripartite ecosystem structure designed to compartmentalize liability and function: * **World Chain:** A 2 blockchain built on the OP Stack, positioned as the transactional rail. * **World ID:** The digital identity protocol, updated to version 3. 0. * **Worldcoin (WLD):** Retained as the utility token demoted from the project’s titular branding. This restructuring aimed to present the project as a neutral “human-centric” internet utility rather than a speculative crypto-asset scheme. yet, the timing coincided with severe legal headwinds. Just weeks prior to the rebrand, South Korea’s Personal Information Protection Commission (PIPC) had levied fines totaling 1. 1 billion won ($830, 000) against the entity for data transfer violations, and operations remained suspended in Spain and Portugal.
Orb 2. 0: Hardware Transparency as a Compliance method
Central to the October 2024 pivot was the unveiling of the **Orb 2. 0**, a hardware iteration explicitly engineered to address the “black box” criticisms leveled by data protection authorities. The new device, powered by the NVIDIA Jetson chipset, featured five times the AI processing performance of its predecessor, its most serious features were those aimed at regulatory appeasement. TFH introduced a fully removable external SD card to the Orb 2. 0 design. This feature was marketed as a transparency method, theoretically allowing independent auditors to verify that the device’s executable instructions matched its open-source code without reverse-engineering the entire unit. This design choice directly responded to allegations from the Bavarian State Office for Data Protection Supervision (BayLDA) and other European regulators regarding the opacity of biometric data processing within the device. also, the Orb 2. 0 reduced component count by 30% and added 5G connectivity, facilitating deployment in regions with poor Wi-Fi infrastructure. While TFH touted this as an accessibility upgrade, it also enabled the device to operate more autonomously in “pop-up” locations, making enforcement actions by local authorities physically more difficult to execute as the hardware became more mobile and less tethered to fixed retail points.
World ID 3. 0 and the “Deep Face” Defense
Simultaneous with the hardware update, the launch of **World ID 3. 0** introduced Anonymized Multi-Party Computation (AMPC). This cryptographic technique was deployed to fragment and distribute the processing of biometric data across multiple parties, theoretically ensuring that no single entity, including TFH, could reconstruct a user’s iris code. This technical architecture was a direct counter-argument to the “honeypot” risk by privacy advocates and regulators in Kenya and Hong Kong. By decentralizing the data holding, World attempted to render the argument of a “centralized biometric database” factually obsolete. also, the introduction of **”Deep Face”** technology, a tool designed to verify human presence in video calls to combat deepfakes, attempted to pivot the regulatory conversation. Instead of being the *target* of privacy laws, World positioned itself as the *solution* to the impending identity emergency caused by generative AI. This narrative shift sought to align the project with government interests in national security and anti-fraud, hoping to trade biometric scrutiny for utility in combating AI-driven cybercrime.
The 2025 Regulatory Firewall
even with the aggressive rebranding and technical restructuring, 2025 saw a cascade of enforcement actions that indicated regulators were unswayed by the name change. The decoupling of “coin” from the brand name failed to shield the project from the fundamental legal objection: the exchange of immutable biometric data for financial incentives.
Brazil: The Coercion Precedent (January 2025)
In January 2025, Brazil’s National Data Protection Authority (ANPD) issued a blanket ban on World’s data collection operations. The ANPD’s ruling was significant because it attacked the core economic model rather than just the data security. The authority argued that offering cryptocurrency (WLD) to individuals in lower-income demographics constituted “coercion,” so invalidating the “informed consent” required under Brazilian General Data Protection Law (LGPD). The rebrand to “World” did nothing to mitigate this finding; the ANPD specifically the financial inducement as a violation of fundamental rights, threatening daily fines of 50, 000 Brazilian reais ($8, 800) for non-compliance.
Indonesia: Licensing and Sovereignty (May 2025)
Following the Brazilian precedent, Indonesia’s Ministry of Communication and Digital (Komdigi) suspended World’s operations in May 2025. The investigation revealed that even with the corporate restructuring, the local operators, PT Terang Bulan Abadi and PT Sandina Abadi Nusantara, absence the requisite Electronic System Operator (PSE) registration. The Indonesian authorities viewed the “World” entity as a continuation of the previous data practices, disregarding the nomenclature change. The suspension highlighted a serious failure in the rebrand strategy: while the global brand changed, the local operational compliance in emerging markets remained patchy and to sovereignty-based legal challenges.
Kenya: The High Court Finality (May 2025)
Kenya, which had been the nation to suspend operations in 2023, delivered a final blow in May 2025. The High Court of Kenya ruled the entire operation illegal, reinforcing that the collection of iris data from citizens by a foreign private entity posed a national security risk. The court’s decision explicitly dismissed the distinction between the “World ID” protocol and the “Worldcoin” token, viewing them as an inextricable commercial loop that exploited Kenyan citizens.
Table: Post-Rebrand Regulatory Actions (2025)
The following table summarizes the major regulatory enforcement actions taken against the entity *after* the October 2024 rebrand to “World.”
| Jurisdiction | Date of Action | Regulatory Body | Action Taken | Core Justification |
|---|---|---|---|---|
| Brazil | January 2025 | ANPD (National Data Protection Authority) | Total Ban & Fine Threat | Financial incentives for biometrics constitute coercion; invalid consent. |
| Singapore | Late 2024 / Jan 2025 | Police Force / MAS | Criminal Investigation | chance violation of Payment Services Act; unauthorized account trading. |
| Indonesia | May 2025 | Ministry of Communication (Komdigi) | License Suspension | absence of Electronic System Operator registration; data sovereignty. |
| Kenya | May 2025 | High Court | Ruling of Illegality | Violation of Data Protection Act; national security risk. |
| Germany | Feb 2025 | BayLDA | Data Deletion Order | Ordered deletion of data collected in Spain; GDPR non-compliance. |
Failure of the “Infrastructure” Defense
The primary objective of the “World” rebrand was to transition the regulatory classification of the project from a “financial service” (subject to strict KYC/AML and securities laws) to “internet infrastructure” (subject to lighter technology regulations). The launch of **World Chain** in November 2024 was the linchpin of this strategy. By migrating transactions to its own 2 network, TFH attempted to that it was providing the *road* for digital identity, not the *car* (the token). yet, the enforcement actions of 2025 demonstrate that regulators pierced this corporate veil. In Singapore, the investigation focused on the trading of World accounts and tokens, directly linking the infrastructure to financial speculation. The “World ID Credentials” feature, which allowed users to scan NFC passports to verify age and nationality, further alerted authorities. Rather than seeing this as a privacy feature, agencies in the UK and Germany viewed it as an expansion of data ingestion—moving from just biometrics to government-issued ID documents—without the requisite banking licenses to handle such sensitive verification. The nomenclature change failed to reset the regulatory clock. By mid-2025, the entity formerly known as Worldcoin faced a more coordinated and hostile international legal environment than it did prior to its “World” transformation. The attempt to use semantic and technical complexity (AMPC, 2 chains) to obfuscate the core business model—trading biometrics for value—did not withstand the scrutiny of judicial and data protection bodies globally.
BayLDA Final Verdict: The December 2024 GDPR Corrective Order

The December 19 Verdict: A GDPR Compliance Mandate
On December 19, 2024, the Bavarian State Office for Data Protection Supervision (BayLDA) issued a definitive administrative order against Tools for Humanity (TFH), the operator behind the World (formerly Worldcoin) project. As the lead supervisory authority for the company in the European Union under the GDPR’s “One-Stop-Shop” method, BayLDA’s ruling marked the culmination of a twenty-month investigation initiated in April 2023. The regulator did not levy a fine imposed strict structural correctives designed to the project’s data retention architecture. The order mandated three primary actions: 1. **Retroactive Deletion:** World was ordered to delete all biometric data collected during its initial European rollout in the summer of 2023, which BayLDA determined was processed without a sufficient legal basis. 2. **Erasure method:** The company was given a strict one-month deadline to implement a fully GDPR-compliant procedure allowing users to permanently erase their iris codes and associated data. 3. **Explicit Consent:** Future data processing operations were required to obtain “explicit and informed” consent for specific biometric activities, moving beyond the broad terms of service previously used. BayLDA President Michael described the decision as an enforcement of “European fundamental rights standards,” explicitly stating that the order ensures “all users who have provided Worldcoin with their iris data in future have the unrestricted opportunity to enforce their right to erasure.”
The “Anonymization” Dispute
A central pillar of the BayLDA’s ruling challenged World’s reliance on “Privacy Enhancing Technologies” (PETs) as a substitute for GDPR compliance. TFH had long argued that its iris codes were irreversibly anonymized, meaning they fell outside the scope of personal data regulations. The December order rejected this premise for the contested period, establishing that the biometric templates, even if hashed, remained linkable to individuals under specific conditions, thus qualifying as sensitive personal data (Article 9 GDPR). The regulator’s dismissal of the “anonymization defense” forced World to treat its iris database not as a collection of abstract codes, as a registry of identifiable human biometrics requiring the highest tier of legal protection. This finding aligned with earlier concerns raised by the Spanish AEPD and Portuguese CNPD, harmonizing the regulatory stance across the Eurozone.
Corporate Response and Legal Appeal
Tools for Humanity immediately appealed the decision, characterizing the regulator’s findings as retrospective. In a statement released shortly after the verdict, the company argued that the order targeted “outdated operations and technologies” that had already been replaced during the October 2024 “World” rebrand. TFH Chief Legal and Privacy Officer Damien Kieran publicly contended that the dispute hinged on the absence of a consistent legal definition for anonymization in the EU, stating that “without a clear definition… we lose perhaps our most tool in the fight to protect privacy in the age of AI.” even with the appeal, the order’s one-month compliance window placed immediate operational pressure on the company. Failure to demonstrate a functional deletion method by January 19, 2025, would expose the entity to escalating administrative penalties and chance suspension of data processing privileges in Germany, its European headquarters.
| Mandate Category | Specific Requirement | Compliance Deadline |
|---|---|---|
| Data Erasure | Implementation of a user-initiated, irreversible deletion tool for iris codes. | January 19, 2025 |
| Historical Data | Deletion of all biometric records collected during the “Summer 2023” launch phase. | Immediate |
| Consent Protocol | Transition to “explicit consent” models for all biometric processing steps. | Immediate |
| Legal Basis | Rejection of “Legitimate Interest” for biometric data; requirement for Article 9 compliance. | Immediate |
“We are enforcing European fundamental rights standards in favor of the data subjects in a technologically demanding and legally highly complex case.”
, Michael , President of BayLDA (December 19, 2024)
Cross-Border Regulatory
The BayLDA verdict was not an German action the product of the GDPR’s cooperation method. Throughout 2024, the Bavarian regulator coordinated with supervisory authorities in France (CNIL), Spain (AEPD), and Portugal (CNPD). While Spain and Portugal had issued temporary emergency bans earlier in the year, the BayLDA’s final decision provided the permanent legal framework for the entire bloc. This coordinated method closed the “forum shopping” gaps TFH had attempted to use by establishing its main establishment in Erlangen, Bavaria. By securing a consensus among EU regulators, the BayLDA decision set a continent-wide precedent: biometric proof-of-personhood systems cannot operate in Europe without a “delete button” that functions as flawlessly as the enrollment process.
Madrid AEPD Stance: Extending the Precautionary Blockade
The Precautionary Blockade: AEPD’s Invocation of Article 66
On March 6, 2024, the Spanish Data Protection Agency (AEPD) executed a decisive regulatory maneuver that would set a continental precedent for biometric enforcement. Invoking **Article 66 of the GDPR**, the “urgency procedure” which permits national authorities to take immediate, temporary action to protect the rights of data subjects, the AEPD ordered Tools for Humanity (TFH) to immediately cease the collection of biometric data in Spain and to block all data already compiled. This intervention marked the time a European regulator utilized the urgency method against the Worldcoin project, bypassing the standard “One-Stop-Shop” method that defers enforcement to the lead supervisory authority (in this case, Bavaria’s BayLDA). AEPD Director Mar España Martà justified the unilateral action by citing “exceptional circumstances” where the standard cross-border cooperation would result in unacceptable delays to fundamental rights protection. The agency’s investigation revealed four serious infractions that necessitated the blockade: * **Collection of Minors’ Data:** Evidence indicated that the Orb operators failed to implement age verification method, allowing individuals under 14 to trade biometric data for WLD tokens. * **Irrevocability of Consent:** Users were unable to withdraw consent or request data deletion, a violation of Article 17 (Right to Erasure). * **Insufficient Information:** The “Data Consent Form” failed to adequately explain the risks associated with biometric processing. * **Undisclosed Third-Party Transfers:** The data flow architecture suggested processing activities that were not transparently disclosed to Spanish registrants.
Judicial Validation: The Audiencia Nacional Ruling
Tools for Humanity immediately challenged the AEPD’s order in the **Audiencia Nacional** (National Court), seeking an interim stay of the suspension. TFH’s legal team argued that the AEPD absence jurisdiction over a German-domiciled entity and claimed the ban would cause “irreparable commercial damage” and “reputational harm” to the global project. On March 11, 2024, the Chamber for Contentious-Administrative Proceedings of the Audiencia Nacional issued a ruling that dismantled TFH’s defense. The court upheld the AEPD’s precautionary measure, establishing a significant legal hierarchy between corporate profit and privacy rights.
“The safeguarding of the public interest, which consists of the protection of the right to personal data of the data subjects, must prevail against the particular commercial interest of the company.”
The magistrates rejected the “irreparable damage” argument, noting that any financial losses incurred by TFH during the suspension could be economically compensated if the company eventually won the case. Conversely, the court ruled that the dissemination of biometric data is irreversible; once iris codes are compromised or processed unlawfully, the damage to the individual’s privacy cannot be undone. This ruling insulated the AEPD’s urgency procedure from judicial suspension, allowing the blockade to remain in force.
The Strategic Retreat: June 2024 Extension
As the initial three-month validity of the Article 66 measure method its expiration in June 2024, the regulatory standoff entered a new phase. Rather than risking a second unilateral order or a chance permanent ban from the Spanish authority, Tools for Humanity opted for a strategic retreat. On June 4, 2024, the AEPD announced that TFH had signed a legally binding commitment to voluntarily extend the suspension of its operations in Spain. This agreement stipulated that World (formerly Worldcoin) would not resume Orb activity until: 1. The end of the 2024 calendar year, or 2. The Bavarian State Office for Data Protection Supervision (BayLDA) issued a final resolution regarding the company’s GDPR compliance. This “voluntary” extension was a calculated move by TFH to de-escalate tensions with Madrid while awaiting the outcome of the audit in Bavaria. For the AEPD, it secured a de facto permanent ban without the administrative load of renewing the emergency measure every three months. The agreement explicitly stated that the AEPD retained the power to adopt additional supervisory measures if TFH violated the terms of the pause.
The Bavarian Verdict and 2025
The “precautionary” nature of Spain’s blockade transitioned into a validated enforcement action following the BayLDA’s decisive verdict in December 2024. The Bavarian authority’s administrative order, which found TFH in violation of core GDPR provisions regarding security and consent, provided the retrospective justification for Spain’s aggressive stance. In early 2025, the of the BayLDA ruling crystallized for the Spanish market. The German authority’s corrective order included a mandate for the **deletion of non-compliant iris data**, a requirement that directly impacted the biometric templates collected from over 300, 000 Spanish users prior to the March 2024 ban.
Table: Timeline of the Spanish Blockade
| Date | Event | Legal Basis / Outcome |
|---|---|---|
| March 6, 2024 | AEPD problem precautionary ban | GDPR Article 66 (Urgency Procedure); immediate cessation of Orb activity. |
| March 11, 2024 | Audiencia Nacional Ruling | High Court rejects TFH appeal; prioritizes “public interest” over commercial loss. |
| June 4, 2024 | Voluntary Extension Agreement | TFH commits to suspend Spain operations until Dec 31, 2024, or BayLDA verdict. |
| Dec 19, 2024 | BayLDA Final Verdict | Bavarian authority confirms GDPR violations; validates AEPD’s initial concerns. |
| Feb 2025 | Data Deletion Enforcement | BayLDA order mandates deletion of iris data collected in Spain under non-compliant terms. |
By the quarter of 2025, the AEPD’s “precautionary” blockade had evolved into a permanent prohibition under the umbrella of the Europe-wide corrective order. The Spanish regulator’s early intervention is by privacy advocates as the “domino” that forced the hand of the lead supervisory authority, demonstrating that national agencies can successfully force global compliance actions through the aggressive use of emergency powers.
Seoul PIPC Ruling: 1.1 Billion Won Fine for Consent Violations
The Seoul Verdict: A 1. 1 Billion Won Penalty

On September 26, 2024, South Korea’s Personal Information Protection Commission (PIPC) issued a definitive administrative ruling against the Worldcoin Foundation and Tools for Humanity (TFH), imposing a combined fine of **1. 104 billion KRW** (approximately $830, 000 USD). The decision, finalized during the commission’s 16th plenary session, marked the conclusion of a seven-month investigation initiated in February 2024 following complaints regarding the unauthorized collection of biometric data in exchange for cryptocurrency. Unlike the precautionary blockades seen in Spain or Portugal, the PIPC’s ruling was a corrective financial enforcement action that stopped short of a total ban, provided specific remedial measures were enacted. The fines were levied separately against the two entities, further illustrating the regulatory complexity of World’s corporate architecture:
| Entity | Fine Amount (KRW) | Primary Violations |
|---|---|---|
| Worldcoin Foundation | 725 million | Mishandling sensitive biometric data; failure to provide deletion method; improper overseas transfer notifications. |
| Tools for Humanity (TFH) | 379 million | Violations of overseas data transfer obligations; failure to implement age verification for minors. |
Consent Violations and Linguistic blocks
The PIPC’s investigation uncovered widespread failures in how World obtained user consent. Under South Korea’s Personal Information Protection Act (PIPA), the collection of sensitive biometric data, specifically iris codes, which the commission ruled are unchangeable and unique identifiers, requires explicit, informed consent. Investigators found that until March 22, 2024, the biometric data consent forms presented to South Korean users were available **only in English**. This linguistic barrier prevented informed decision-making for of the 93, 463 users who had downloaded the World App. also, the Foundation failed to notify users of the specific purpose of the collection or the retention period of their biological data, treating the “iris code” as anonymous data rather than sensitive personally identifiable information (PII).
The “Overseas” Black Box
A serious component of the ruling focused on the opacity of cross-border data flows. South Korean law mandates that data controllers explicitly inform subjects of the country to which their information is transferred, as well as the name and contact details of the recipient. The PIPC determined that both the Worldcoin Foundation and TFH transferred the iris data of approximately 30, 000 South Korean users to servers abroad (primarily in Germany and the United States) without satisfying these notification requirements. Users were surrendering their biometric identity to a black box, unaware of the legal jurisdiction governing their data once it left Korean soil.
Failures in Age Verification and Deletion Rights
The investigation also exposed significant gaps in the protection of minors. TFH was found to have absence any age verification procedure for users under the age of 14 until April 2024. This negligence allowed minors to register and trade biometric data for tokens, a direct violation of special protections afforded to children under Korean privacy law. also, the Worldcoin Foundation failed to establish a functional method for users to request the deletion or suspension of their iris codes. Once the data was cast onto the “World Chain,” users had no method to revoke it, violating the fundamental right to be forgotten. The PIPC ordered the Foundation to implement a verified deletion protocol, forcing the company to engineer a “revoke” function that it had previously claimed was technically antithetical to its “proof of personhood” model.
“The iris code constitutes sensitive biometric information… its collection and processing required explicit user consent, which was not obtained.” , PIPC Ruling Summary, September 2024
Corporate Response and Remediation
In a move characteristic of its global regulatory strategy, Tools for Humanity framed the ruling as a validation of its technology rather than a condemnation of its practices. Following the verdict, TFH released a statement welcoming the decision, asserting that the investigation ” concludes that TFH’s operations… are in compliance with South Korea’s Personal Information Protection Act,” provided the “weaknesses” identified were remedied. This spin omits the severity of the corrective orders. The company was not asked to improve; it was financially penalized and legally mandated to overhaul its consent architecture, translate all documentation, implement strict age-gating, and create data deletion pathways that did not previously exist. As of late 2024, World continues to operate in South Korea, under a significantly tighter compliance regime than the one it attempted to deploy during its initial launch.
Hong Kong PCPD: Operation Raid and Biometric Seizure
The January 31 Raids: Executing Court Warrants
On January 31, 2024, the PCPD escalated its inquiry from administrative review to active enforcement. Following ten covert site visits conducted between December 2023 and January 2024, the Commissioner obtained court warrants to enter six separate Worldcoin operation centers. These premises, located in Yau Ma Tei, Kwun Tong, Wan Chai, Cyberport, Central, and Causeway Bay, were simultaneously breached by PCPD officers. The raids targeted the physical “Orb” distribution points where Worldcoin operators were actively harvesting biometric data. During the operation, officers demanded the immediate production of documents and operational data, marking a rare instance of physical regulatory intervention in the cryptocurrency sector. The PCPD justified the raids by citing “serious risks to personal data privacy,” specifically targeting the project’s collection of immutable biometric identifiers from Hong Kong residents.
Investigation Findings: The “Unnecessary and Excessive” Verdict
On May 22, 2024, Privacy Commissioner Ada Chung Lai-ling released the formal investigation results, which declared Worldcoin’s operations in direct contravention of the Personal Data (Privacy) Ordinance (PDPO). The findings dismantled Worldcoin’s core “Proof of Personhood” justification on multiple legal fronts: * **Excessive Data Collection (DPP 1(1)):** The Commissioner ruled that collecting *both* iris and facial images was “unnecessary and excessive.” The investigation determined that iris scanning alone was sufficient for verifying humanness, rendering the additional facial scans a violation of data minimization principles. * **Unfair Collection Practices (DPP 1(2)):** The investigation found that Worldcoin failed to provide Chinese language versions of its “Privacy Notice” and “Biometric Data Consent Form.” Given that Chinese is the primary language of Hong Kong, this omission meant participants could not provide informed consent. also, Orb operators were found to offer no explanation of the risks involved, nor did they conduct age verification to prevent minors from signing up. * **Unjustified Retention (DPP 2(2)):** Worldcoin’s policy of retaining biometric data for up to **10 years** for the stated purpose of “training AI models” was deemed disproportionate. The PCPD rejected the argument that such a prolonged retention period was necessary for user verification.
Metrics of the Breach
The investigation quantified the extent of Worldcoin’s penetration into the Hong Kong market prior to the ban.
| Metric | Value |
|---|---|
| Total Individuals Scanned | 8, 302 |
| Covert Site Visits | 10 |
| Premises Raided | 6 |
| Data Retention Period | 10 Years (Deemed Excessive) |
The Enforcement Notice
Following the investigation, the PCPD issued a legally binding Enforcement Notice on May 22, 2024. The order demanded the immediate cessation of all operations involving the scanning and collection of iris and face images in Hong Kong. Unlike temporary suspensions seen in other jurisdictions, this order was a definitive prohibition based on established violations of the PDPO. The Commissioner’s ruling emphasized that biometric data is “unique and immutable,” and its compromise would have irreversible consequences for the 8, 302 affected residents. The PCPD warned the public to report any resurgence of Orb devices, deputizing the citizenry to monitor for non-compliance. Worldcoin expressed disappointment with the ruling was forced to halt its biometric enrollment operations in the territory immediately.
“The face and iris images collected by the Worldcoin project were unnecessary and excessive… The retention of personal data for a maximum of 10 years to train AI models was not justified.”
, Ada Chung Lai-ling, Privacy Commissioner for Personal Data, Hong Kong (May 2024)
This enforcement action established a serious precedent in the Asia-Pacific region, signaling that “black box” AI training justifications would not supersede local data minimization laws. The PCPD’s rejection of the 10-year retention clause specifically attacked the business model of using human biometric data as long-term capital for AI development.
Nairobi High Court: The May 2025 Unlawful Collection Judgment
The May 5 Verdict: Katiba Institute v. Tools for Humanity
The judgment, delivered at the Milimani Law Courts in Nairobi, concluded a protracted legal challenge initiated by the Katiba Institute and the Kenyan chapter of the International Commission of Jurists (ICJ Kenya). While the Directorate of Criminal Investigations (DCI) had administratively closed its police file on Worldcoin in June 2024, citing a absence of criminal intent, the High Court’s constitutional review focused strictly on the legality of data processing under the Data Protection Act (DPA) of 2019. Justice Aburili’s ruling was absolute. The court issued a writ of *certiorari* quashing Worldcoin’s data processing licenses and a writ of *mandamus* compelling the immediate and permanent erasure of all biometric data harvested from Kenyan subjects. The judgment dismantled TFH’s defense that “consent” obtained via digital click-wraps was sufficient to override statutory obligations.
“The inducement of data subjects with monetary rewards in the form of cryptocurrency tokens, in an economy where the majority struggle with basic needs, vitiates the voluntariness of consent. A hungry person cannot give free consent when the price of their privacy is a meal.”
, Justice Roselyne Aburili, High Court of Kenya, May 5, 2025
The “Inducement” Precedent
The court’s analysis of “induced consent” established a serious legal precedent for biometric markets. Evidence presented by the Office of the Data Protection Commissioner (ODPC) showed that during the project’s frantic launch in mid-2023, over 350, 000 Kenyans had queued for iris scans, driven primarily by the pledge of 25 WLD tokens (valued at approximately KES 7, 000 at the time). The High Court ruled that this transactional model violated Section 2 of the DPA, which requires consent to be “express, unequivocal, free, specific, and informed.” By tying the provision of a financial asset directly to the surrender of sensitive biometric data, Worldcoin had created a coercive environment. The judge noted that the “Orb” operators targeted low-income demographics in Nairobi, monetizing desperation. This finding challenged the core business model of “Proof of Personhood” projects that rely on network effects driven by token incentives.
The DPIA Failure and Data Sovereignty
Beyond consent, the judgment hinged on a procedural failure that TFH could not explain away: the absence of a Data Protection Impact Assessment (DPIA). Under Section 31 of the DPA, any data processing likely to result in high risk to the rights and freedoms of a data subject requires a DPIA prior to processing. Court documents revealed that TFH had commenced mass data collection in Kenya as early as May 2021 (during its stealth phase) only submitted a retrospective DPIA to the ODPC in 2023, *after* operations were suspended. Justice Aburili termed this “regulatory arrogance,” stating that a post-facto assessment defeats the preventative purpose of the law. The court also addressed the problem of data sovereignty. It was established that biometric data collected in Nairobi was not stored locally transmitted to Amazon Web Services (AWS) servers in South Africa and subsequently to data centers in Europe. The court found that TFH had failed to provide adequate safeguards for cross-border transfer as required by Section 48 of the DPA. The “adequacy decision” method, which allows transfer to countries with similar protection levels, was deemed inapplicable because TFH had not sought prior approval from the Data Commissioner for these specific transfers.
The Seven-Day Erasure Order
The operational impact of the ruling was immediate. The High Court ordered TFH to scrub its databases of all Kenyan biometric records within seven days, under the direct supervision of the ODPC. This order extended beyond the iris codes (hashes) to include any derived metadata and high-resolution images used for machine learning training.
| Order Type | Directive | Compliance Deadline |
|---|---|---|
| Certiorari | Nullification of TFH’s registration as a Data Controller in Kenya. | Immediate |
| Mandamus | Permanent deletion of all iris scans, facial data, and derived hashes collected from Kenyan citizens. | 7 Days (by May 12, 2025) |
| Prohibition | Permanent injunction against collecting further biometric data in Kenya without a fresh, compliant DPIA. | Indefinite |
| Supervision | ODPC to audit the deletion process and file a compliance report with the court. | Post-Deletion |
January 2026: Verification of Deletion
While the court ordered a seven-day timeline, the technical verification of the deletion process extended into early 2026. The complexity of Worldcoin’s architecture, where data is sharded across decentralized nodes and centralized servers, required a forensic audit to ensure no “ghost copies” remained. On January 22, 2026, the ODPC issued a formal communiqué confirming compliance. Data Commissioner Immaculate Kassait verified that TFH had executed a cryptographic erasure of the Kenyan dataset. This involved: 1. Deletion of Iris Codes: The unique hashes representing Kenyan users were purged from the global World ID database. 2. Training Data Removal: Raw images used for training the “Orb” neural networks, which TFH claimed were deleted by default had been retained for “quality control” in instances, were certified as destroyed. 3. Wallet Disassociation: While the biometric link was severed, the court allowed users to retain access to their WLD tokens via non-biometric keys, preventing a total financial loss for the participants.
for the “Global South” Strategy
The Nairobi judgment closed the door on Worldcoin’s largest African market. Unlike the temporary suspensions in Spain or Portugal, which were framed as “precautionary measures” pending investigation, the Kenyan ruling was a final determination on the merits of the business model itself. Legal analysts noted that the judgment provided a blueprint for other jurisdictions. By focusing on the *inducement* aspect of data collection, the Kenyan High Court identified a vulnerability in the Worldcoin model that is not easily fixed by technical patches. To comply with the ruling, World would need to stop offering WLD tokens in exchange for scans—a move that would likely collapse its user acquisition rates in emerging markets. The decision also reasserted the authority of African data regulators. For years, technology companies had treated the continent as a “regulatory sandbox,” testing high-risk technologies with minimal oversight. The Nairobi High Court signaled the end of this era, establishing that constitutional privacy rights in Kenya are non-negotiable, regardless of the technological pledge or the financial incentives offered by Silicon Valley entities.
Kenya Data Purge: The January 2026 Biometric Deletion Event
The Great Deletion: Nairobi’s Biometric Purge
On January 21, 2026, the Office of the Data Protection Commissioner (ODPC) in Nairobi issued a definitive compliance notice confirming the “irreversible erasure” of biometric data belonging to over 350, 000 Kenyan citizens. This event, referred to as the “Kenya Data Purge,” marks the final operational of World’s (formerly Worldcoin) major testbed in Africa. The deletion was not a voluntary corporate pivot the direct execution of a High Court mandamus issued eight months prior, ending a three-year regulatory siege that pitted Silicon Valley’s “proof of personhood” against Kenya’s data sovereignty laws. The purge involved the cryptographic destruction of iris codes and facial imaging templates stored on Tools for Humanity (TFH) servers, specifically those collected during the “Orb mania” of mid-2023. While TFH had previously claimed that the “Orb codes” were non-reversible hashes distinct from biological data, the Kenyan judiciary rejected this distinction, classifying the hashes as sensitive personal data requiring explicit, uncoerced consent, something the court ruled was impossible when financial inducements (WLD tokens) were involved.
The Legal Mandate: Justice Roselyne’s Ultimatum
The deletion event traces its legal authority to the landmark judgment delivered on May 5, 2025, by Lady Justice Aburili Roselyne of the High Court of Kenya. The ruling, which concluded a consolidated petition filed by the Katiba Institute and the Kenya chapter of the International Commission of Jurists (ICJ Kenya), declared the data collection activities of 2023 unlawful ab initio. Justice Roselyne’s judgment dismantled TFH’s defense on three serious fronts: * **Invalid Consent:** The court held that consent obtained through the offer of cryptocurrency (worth approximately KES 7, 000 at the time) was “induced” and therefore not “free” as required by the Data Protection Act (2019). * **absence of DPIA:** The failure to conduct a Data Protection Impact Assessment (DPIA) *prior* to the deployment of Orbs was deemed a fatal procedural flaw that could not be rectified retroactively. * **Data Sovereignty:** The transfer of biometric data to servers in South Africa and Europe without adequate safeguards violated Article 31 of the Kenyan Constitution. The court’s order was explicit: TFH and its agents were to “permanently destroy or erase the biometric data collected from Kenya using the Orb device” under the direct supervision of the ODPC. While the original order demanded compliance within seven days, technical negotiations regarding the verification of “zero-knowledge” deletion extended the timeline into late 2025, culminating in the January 2026 certification.
The Failed Pivot: From DCI Clearance to Civil Defeat
The road to the January purge was characterized by a deceptive lull in mid-2024. On June 14, 2024, the Directorate of Criminal Investigations (DCI) officially dropped its criminal probe into Worldcoin, advising the company to regularize its registration with the Registrar of Business. TFH executives, including Chief Legal Officer Thomas Scott, characterized this as a “new beginning,” anticipating a resumption of operations. yet, this criminal clearance failed to address the civil and administrative liabilities pursued by the ODPC and civil society groups. The table outlines the between the criminal and civil tracks that trapped TFH:
| Timeline | Criminal Track (DCI/Police) | Civil/Regulatory Track (ODPC/High Court) |
|---|---|---|
| August 2023 | Raid on warehouse; seizure of Orbs. | Administrative suspension; preservation orders issued. |
| June 2024 | Investigation Dropped. File closed; no further police action. | Litigation Intensifies. ICJ Kenya & Katiba Institute press High Court petition. |
| May 2025 | N/A (Case closed) | Judgment Delivered. Collection declared unlawful; deletion ordered. |
| Jan 2026 | N/A | Execution. ODPC verifies total deletion of 2023 dataset. |
Technical Execution and Verification
The deletion process executed in January 2026 differed significantly from standard server wipes due to the nature of the data. TFH operates on a premise of “permanent” iris hashes. To comply with the High Court order, the company had to prove that the *hashes* themselves, not just the original images, were removed from the centralized database (the “uniqueness check” ledger). Data Commissioner Immaculate Kassait stated that the ODPC’s technical team, assisted by independent digital forensic auditors, verified the following: 1. **Removal of Iris Codes:** The unique hexadecimal strings representing the 350, 000+ Kenyan users were purged from the global uniqueness set. 2. **Severing of Wallet Links:** The connection between the biometric template and the World App wallet addresses was broken. While users retained their WLD tokens (as they exist on the Optimism blockchain), their “World ID” verification badges were revoked, downgrading them to unverified users. 3. **Destruction of Backups:** The audit confirmed that no “cold storage” backups of the Kenyan dataset existed in third-party jurisdictions (specifically AWS servers in South Africa and Germany) that remained accessible to TFH.
The “Personal Custody” Irrelevance
Throughout late 2024, TFH attempted to mitigate regulatory pressure by rolling out “Personal Custody,” a feature allowing users to store their iris codes on their own devices rather than the cloud. TFH argued this shifted control to the user, rendering a central deletion order moot. The High Court rejected this argument for the 2023 cohort. Justice Roselyne noted that the data collected during the initial rush was processed *before* the implementation of Personal Custody. Since the original consent was voided due to inducement, the fruit of that collection, the central hashes, remained unlawful regardless of subsequent architectural changes. The court ruled that TFH could not “retroactively cure” the illegality of the initial collection by pushing data to user devices after the fact.
“The judgment rightly show that even in the digital age, constitutional rights, especially the right to privacy, must be upheld. The court’s directive to delete all unlawfully obtained biometric data is not just a legal need a serious act of restoring data subject rights.”
, ICJ Kenya Statement, following the May 2025 ruling.
for the “African Strategy”
The January 2026 deletion event represents a total reset for World in East Africa. Unlike the temporary suspensions in Spain or Portugal, which were precautionary measures under GDPR Article 66, the Kenyan action is a permanent erasure based on a final judicial determination of illegality. For the 350, 000 Kenyans who queued at the Kenyatta International Convention Centre (KICC) in 2023, the event is a mixed resolution. They retain the financial value of the tokens they received— trading at market rates— their digital identity on the World network has been nullified. For the ODPC, the successful enforcement of the deletion order establishes a formidable precedent: multinational tech entities cannot use the Global South as a regulatory sandbox without facing irreversible consequences.
Jakarta Komdigi Suspension: Electronic System License Revocation
Jakarta Komdigi Suspension: Electronic System License Revocation
The May 2025 Suspension Order
On May 4, 2025, the Indonesian Ministry of Communication and Digital (Komdigi) executed a decisive administrative action against the local operations of World (formerly Worldcoin), suspending its Electronic System Operator Registration Certificate (TDPSE). The suspension, announced by the Director General of Digital Space Supervision, Alexander Sabar, halted all biometric data collection activities across the archipelago. This enforcement action represented the major test of Indonesia’s fully enacted Personal Data Protection (PDP) Law against a transnational biometric entity since the legislation’s full enforceability began in October 2024.
The regulatory intervention followed a surge in public complaints regarding “suspicious activities” at Orb verification sites in the Greater Jakarta area, specifically in Bekasi and Depok. Komdigi’s investigation revealed that World’s local operations were not non-compliant with data localization standards were operating under a “borrowed” license scheme designed to circumvent the rigorous vetting process required for high-risk electronic system operators (PSE).
The “License Borrowing” Scheme
The core of the regulatory violation lay in a deceptive corporate structuring arrangement. Komdigi investigators discovered that the entity physically conducting the iris scans and managing the Orb infrastructure, PT Terang Bulan Abadi, held no valid PSE registration. Under Government Regulation No. 71/2019 on the Implementation of Electronic Systems and Transactions, all digital platform operators must register directly with the ministry to ensure accountability and data sovereignty.
Instead of registering its own entity, World’s operations were conducted using the TDPSE credentials of a separate, unrelated company, PT Sandina Abadi Nusantara. This misuse of another legal entity’s registration constituted a severe breach of Ministerial Regulation No. 10/2021. Director General Sabar characterized this as a “serious violation” of administrative law, noting that the license borrowing obscured the true data controller’s identity from Indonesian regulators, rendering the data flows unclear and unaccountable.
Operational Impact and Financial Incentives
Prior to the suspension, World had aggressively expanded its footprint in Indonesia, capitalizing on the economic demographics of the region. The project offered sign-up incentives of approximately Rp 800, 000 (roughly $50 USD) in WLD tokens, a sum significantly higher than the daily minimum wage in Jakarta. This financial inducement led to chaotic scenes at registration centers.
| Metric | Data Point |
|---|---|
| Local Operator Entity | PT Terang Bulan Abadi (Unregistered) |
| License Used (Invalid) | PT Sandina Abadi Nusantara |
| User Incentive | ~Rp 800, 000 ($48, $50 USD) |
| Primary Hotspots | Bekasi, Depok, Central Jakarta |
| Regulatory Violation | Govt Reg No. 71/2019; Minister Reg No. 10/2021 |
Reports from May 2025 documented long queues of thousands of residents at locations such as Jalan Raya Narogong in Bekasi, waiting to scan their irises. The sheer volume of data subjects, of whom absence a clear understanding of the biometric technology, accelerated the government’s intervention. The suspension order required an immediate cessation of all Orb activity, and Komdigi threatened a permanent shutdown if the entities failed to rectify the licensing irregularities.
Ministerial Ultimatum and PDP Law Context
Minister of Communication and Digital Affairs Meutya Hafid issued a stern ultimatum following the suspension. “We are currently suspending their operations while awaiting clarification. If they fail to comply, they be permanently shut down,” Hafid stated during a site visit in West Java. The Minister emphasized that the 2022 Personal Data Protection Law, fully enforceable, mandates strict consent and data localization that World’s “borrowed license” structure failed to guarantee.
While the Commodity Futures Trading Regulatory Agency (Bappebti) continued to list crypto assets generally, the specific suspension of the electronic system severed the link between the physical biometric collection and the digital wallet infrastructure within Indonesia. The action by Komdigi signaled a shift in Indonesian regulatory posture: while crypto trading remains permissible under Bappebti oversight, the extraction of biometric data by unregistered foreign entities is treated as a national security and privacy threat.
“Non-compliance to the registration requirement and abusing the identity of other legal bodies to conduct digital service operations amounted to serious violations of our regulations.”
, Alexander Sabar, Director General of Digital Space Supervision, Komdigi (May 4, 2025)
Buenos Aires Ministry of Production: Consumer Law Indictment
The Provincial Indictment: A Consumer Defense Offensive
While federal data protection agencies worldwide focused on biometric privacy, the Province of Buenos Aires opened a distinct and highly legal front against World (formerly Worldcoin) in 2024: consumer protection law. On April 16, 2024, the Ministry of Production, Science and Technological Innovation of the Province of Buenos Aires formally indicted the company for alleged violations of the National Consumer Defense Law (Law 24. 240). Unlike the abstract debates over cryptographic proofs, this action targeted the tangible contract terms accepted by over 500, 000 Argentine users, exposing the legal asymmetries in the company’s “Terms of Service.”
The indictment followed a series of physical inspections carried out by the Provincial Directorate of Consumer Defense at Worldcoin operational nodes in municipalities such as Morón and Avellaneda. These audits revealed a clear between the company’s high-tech narrative and its on-the-ground compliance. Inspectors documented a complete absence of signage prohibiting the scanning of minors, a serious oversight in a jurisdiction where the age of digital consent is strictly regulated. also, the audits exposed contradictions regarding biometric data storage; while the company publicly claimed data was anonymized or deleted, the user contracts implied storage occurred in Brazil, creating a transparency gap that provincial authorities deemed a violation of the duty to inform.
The 194 Million Peso Sanction
Following the indictment and a review of the company’s defense, the Ministry escalated its enforcement on July 26, 2024, imposing a fine of 194, 950, 179 Argentine Pesos (approximately $215, 000 USD at the official exchange rate at the time, significantly higher in purchasing power parity terms). The penalty was calculated based on 832 “minimum important and mobile salaries,” the maximum financial sanction available under the provincial consumer protection regime. Ariel Aguilar, the Undersecretary of Commercial Development, characterized the fine not as a punitive measure as a corrective order designed to the “abusive clauses” that insulated the company from local accountability.
The sanction specifically targeted the “contracts of adhesion”, standard form contracts where the user has no negotiating power. Provincial legal experts identified three primary violations that rendered these contracts abusive under Argentine law:
| Contract Clause | Legal Violation (Law 24. 240) | Regulatory Implication |
|---|---|---|
| Foreign Jurisdiction | Imposed Cayman Islands laws and California arbitration for dispute resolution. | Violated the Argentine Civil and Commercial Code, which mandates local jurisdiction for consumer disputes to ensure access to justice. |
| Class Action Waiver | Forced users to waive their right to participate in shared lawsuits. | Directly contravened constitutional rights in Argentina that guarantee shared standing for consumer associations. |
| Unilateral Suspension | Allowed World to halt services without repair or reimbursement. | Breached the duty of equitable treatment and the guarantee of service continuity for digital goods. |
The “Cayman Loophole” and Sovereignty
The most contentious aspect of the Ministry’s findings was the jurisdictional arbitrage employed by Tools for Humanity. The investigation found that while the biometric data was harvested from citizens in Buenos Aires, the legal relationship was anchored in the Cayman Islands. This “Cayman Loophole” stripped Argentine users of their local legal protections, forcing any chance litigant to engage in costly arbitration in the United States. The Ministry’s resolution declared these clauses null and void within the province, asserting that a multinational entity extracting value from local biological data must answer to local courts.
The investigation also highlighted the vulnerability of minors. During the inspections, provincial agents noted that “Orb” operators, frequently third-party contractors paid on commission, absence clear for verifying age. The absence of mandatory ID checks at the point of collection meant that minors could, and likely did, enter the database. The Ministry’s order mandated the immediate implementation of rigorous age verification method, a requirement that forced World to retrofit its operations in Argentina with physical ID scanning later in 2024.
Strategic and 2025
Worldcoin formally rejected the fine in August 2024, issuing a statement expressing “surprise” and signaling an intent to appeal to the administrative courts. yet, the Buenos Aires precedent rippled through the national regulatory framework. By early 2025, the National Securities Commission (CNV) and the Federal Administration of Public Revenues (AFIP) the consumer law findings in their own tightened regulations for Virtual Asset Service Providers (VASPs). The requirement for VASPs to maintain a legal domicile in Argentina and abide by local anti-money laundering laws, enforced strictly in 2025, can be traced back to the jurisdictional deficiencies exposed by the Buenos Aires Ministry of Production.
“The company it is building a global identity network, in Buenos Aires, it operates as a consumer service provider. not extract biometric data from our citizens while hiding behind the laws of the Cayman Islands. The contract is the law between parties, it cannot be above the law of the land.”
, Ariel Aguilar, Undersecretary of Commercial Development (Statement on July 26, 2024).
The Buenos Aires action demonstrated that sub-national entities could challenge supranational crypto-biometric projects by leveraging established consumer protection statutes rather than waiting for new digital privacy legislation. While the fine itself was a fraction of the company’s capital, the legal order to rewrite the Terms of Service for Argentine users struck at the core of World’s standardized global operating model, forcing a localized fragmentation of its user agreements.
Lisbon CNPD: Emergency Stop Order Regarding Minor Data

SECTION 11 of 24: Lisbon CNPD: Emergency Stop Order Regarding Minor Data
The March 2024 Intervention
On March 26, 2024, the Portuguese National Data Protection Commission (CNPD) executed an emergency stop order against the Worldcoin Foundation, paralyzing its biometric data collection operations across the nation. The directive, issued under the urgency procedures of Article 66 of the General Data Protection Regulation (GDPR), mandated a cessation of all “Orb” activity for a period of 90 days. This regulatory blockade was not a routine compliance check a direct response to what the CNPD classified as a “high risk” to the fundamental rights of citizens, specifically targeting the unauthorized harvesting of biometric data from minors.
The CNPD’s intervention followed a surge in public complaints, dozens filed within a single month, alleging that children under the age of 18 had successfully registered for World IDs and surrendered their iris scans without parental consent. At the time of the order, Worldcoin had already onboarded approximately 300, 000 individuals in Portugal, a significant penetration rate that alarmed regulators due to the irreversible nature of the biometric data involved.
Specific Allegations: The “Minors” Loophole
The core of the CNPD’s enforcement action rested on the inability of Tools for Humanity’s hardware to verify the age of its subjects. While Worldcoin’s terms of service nominally restricted participation to adults, the “Orb” devices absence any intrinsic method to authenticate age documents or filter out underage users physically. The regulator’s investigation revealed that minors were incentivized by the immediate grant of WLD tokens, creating a coercive environment where financial reward superseded privacy considerations.
Beyond the age verification failure, the CNPD two other serious deficiencies that necessitated the emergency ban:
- Irrevocability of Consent: Users reported an inability to delete their data or withdraw consent after registration, a direct violation of GDPR’s “Right to Erasure” (Article 17).
- Information Asymmetry: The disclosures provided to data subjects at the point of collection were deemed insufficient, failing to adequately explain the complexity of the cryptographic processing or the data’s destination.
Regulatory method and Article 66
The CNPD’s use of Article 66 was a tactical maneuver allowing for immediate, provisional enforcement measures in exceptional circumstances where there is an urgent need to act to protect rights and freedoms. Unlike standard investigations which can drag on for years, Article 66 a local supervisory authority to bypass the “One-Stop-Shop” method (where the lead authority, in this case, Bavaria’s BayLDA, would normally handle the case) for a limited period of three months. This aligned Portugal’s stance with Spain’s AEPD, which had invoked the same article weeks prior, creating a fragmented formidable regulatory wall across the Iberian Peninsula.
Worldcoin’s Technical Pivot: Personal Custody and SMPC
In response to the Lisbon order and the broader European regulatory squeeze, Tools for Humanity accelerated the deployment of two architectural changes intended to pacify privacy watchdogs., they introduced “Personal Custody” in late March 2024, a model shifting the storage of biometric keys from centralized servers to the user’s own device. Second, in May 2024, the company announced the implementation of Secure Multi-Party Computation (SMPC).
“The report from CNPD is the time we are hearing from them regarding of these matters, including reports of underage sign-ups in Portugal, for which we have zero tolerance.”
, Jannick Preiwisch, Data Protection Officer, Worldcoin Foundation (March 2024)
The SMPC upgrade was designed to encrypt iris codes into multiple secret shares held by different parties, theoretically making it impossible for any single entity to reconstruct the original biometric template. even with these technical assurances, the CNPD maintained its blockade. As of mid-2025, Worldcoin operations in Portugal remained suspended, with the company engaged in prolonged negotiations to demonstrate that its new age verification , chance involving third-party ID checks, could meet the regulator’s standards for child safety.
Long-Term
The Portuguese case highlighted a serious vulnerability in the “Proof of Personhood” model: the friction between permissionless, decentralized identity and the rigid, age-gated requirements of national laws. By late 2025, the CNPD’s initial 90-day stop order had evolved into an indefinite moratorium, forcing World to treat Portugal as a “dark zone” in its global expansion map until a verifiable, hardware-level age gating solution could be certified by EU authorities.
Singapore Police Probe: Payment Services Act Investigation
SECTION 12 of 24: Singapore Police Probe: Payment Services Act Investigation
The August 2024 Crackdown: Targeting the “Account Mule” Economy
While European regulators focused on GDPR violations, authorities in Singapore opened a distinct enforcement front centered on financial crime and unlicensed payment services. On August 7, 2024, the Singapore Police Force (SPF) executed a coordinated operation resulting in the arrest of five individuals, four men and one woman, suspected of operating an illicit syndicate to buy and sell World (formerly Worldcoin) accounts.
The raids, which also placed two additional subjects under investigation, exposed a sophisticated “account flipping” market. Police seized over 200 mobile phones during the operation, devices that were allegedly used to generate World IDs and the transfer of WLD tokens. The investigation revealed that the syndicate recruited individuals to undergo iris scanning at World’s “Orb” locations in Singapore. Once the biometric verification was complete, these recruits surrendered their account credentials and digital wallets to the syndicate in exchange for immediate cash payments, acting as “data mules.”
The Payment Services Act (PSA) 2019 Violation
The legal basis for the Singaporean probe differed significantly from the privacy-centric challenges in Spain or Hong Kong. The SPF invoked the Payment Services Act 2019 (PSA), a rigorous framework designed to regulate cryptocurrency exchanges and digital payment providers.
On September 9, 2024, Deputy Prime Minister Gan Kim Yong, who also serves as the Chairman of the Monetary Authority of Singapore (MAS), issued a parliamentary written reply clarifying the state’s position. He confirmed that while Worldcoin itself did not qualify as a payment service under the PSA, the secondary market for accounts did.
“Persons who buy or sell Worldcoin accounts and tokens as a business may be providing a payment service… The Police are investigating seven subjects for their suspected involvement in offering the services of buying or selling of Worldcoin accounts and tokens, which constitute offences under Payment Services Act 2019.”
This distinction established a serious regulatory precedent: even if a biometric protocol is technically compliant, the monetization of its credentials by third parties can trigger financial services laws. Under the PSA, carrying on a business of providing any type of payment service without a license carries severe penalties, including fines of up to SGD 125, 000 (approx. USD 96, 000), imprisonment for up to three years, or both.
Money Laundering and Terrorism Financing Risks
The Singaporean investigation highlighted the downstream security risks of World’s distribution model. Authorities flagged the sold accounts as chance vehicles for money laundering and terrorism financing (ML/TF). Because a World ID is marketed as “proof of personhood,” a transferred account allows a bad actor to masquerade as a verified human user.
By purchasing these accounts, criminal syndicates could bypass Know Your Customer (KYC) on other platforms that rely on World ID for verification. The SPF’s Commercial Affairs Department identified that the accounts were being aggregated and chance sold to overseas buyers, creating a “shadow ” of verified identities detached from their original biological owners.
Operational Impact and 2025 Enforcement
Following the August 2024 raids, the SPF issued a strict public advisory warning citizens against selling their biometric accounts. The advisory explicitly stated that individuals who sold their credentials could be held criminally liable if their accounts were subsequently used for illegal activities.
| Enforcement Metric | Details (Aug-Sept 2024) |
|---|---|
| Arrests | 5 individuals (4 men, 1 woman) |
| Total Suspects Investigated | 7 individuals |
| Assets Seized | 200+ mobile phones used for account generation |
| Primary Charge | Providing payment services without a license (PSA 2019) |
| Regulatory Body | Singapore Police Force (SPF) / Monetary Authority of Singapore (MAS) |
Throughout early 2025, the investigation continued to trace the flow of WLD tokens moving through these compromised accounts. The probe forced Tools for Humanity to confront the reality that its “one person, one vote” infrastructure was being commodified into a tradable asset class in financial hubs. While Worldcoin asserted that it was not the target of the police investigation, emphasizing that the probe focused solely on the third-party traders, the enforcement action criminalized the primary method by which low-income users in Singapore were engaging with the protocol.
Orb 2.0 Hardware Audit: Security Flaws in Biometric Capture
SECTION 13 of 24: Orb 2. 0 Hardware Audit: Security Flaws in Biometric Capture
The “Black Box” Vulnerabilities of Orb 2. 0
By early 2025, the narrative surrounding World’s (formerly Worldcoin) proprietary hardware had shifted from futuristic innovation to serious infrastructure vulnerability. While the October 2024 rebrand introduced the “Orb 2. 0”, a streamlined, Nvidia Jetson-powered biometric imaging device, independent security audits and regulatory teardowns in 2025 exposed significant flaws in its “privacy-by-design” architecture. even with Tools for Humanity (TFH) releasing open-source hardware schematics in October 2025 to appease transparency demands, the device remained a contentious “black box” for data protection authorities, particularly regarding its resistance to sophisticated spoofing attacks and side-channel data leakage.
The Least Authority SMPC Audit (February 2025)
On February 24, 2025, security consulting firm Least Authority delivered its final audit report on World’s Secure Multi-Party Computation (SMPC) protocol. This protocol was the of World’s 2025 defense strategy, designed to split users’ iris codes into cryptographic shares distributed across three nodes to prevent any single entity from reconstructing the original biometric template.
The audit, yet, highlighted structural risks in the implementation of this “decentralized” storage. While the report confirmed that the cryptographic mathematics were sound, it identified serious dependencies on the physical security of the nodes themselves. The audit revealed that if an attacker gained physical access to the Orb’s “Secure Element”, the tamper-resistant chip storing the device’s private keys, they could theoretically intercept the iris shares before they were encrypted and distributed. This finding undermined the “unhackable” narrative, as it shifted the attack vector from the cloud to the physical device, which was being deployed in uncontrolled environments from Buenos Aires subway stations to Nairobi marketplaces.
The Orb Mini: A Security Regression?
In May 2025, TFH launched the “Orb Mini,” a portable, smartphone-sized iteration of the scanner designed for rapid deployment. Marketed with the tagline “It goes where you go,” the device was intended to accelerate user onboarding in remote regions. yet, the hardware trade-offs required for miniaturization immediately drew fire from security researchers and privacy advocates.
Unlike the full-sized Orb 2. 0, which utilized a multi-camera array for depth perception and thermal imaging to detect “liveness,” the Orb Mini relied on a simplified sensor suite. Preliminary independent tests conducted by German cybersecurity researchers in June 2025 demonstrated that the Orb Mini had a significantly higher False Acceptance Rate (FAR) for presentation attacks. In controlled environments, researchers were able to spoof the device using high-resolution infrared prints and 3D-printed ocular masks, techniques that the larger Orb had been updated to reject. This regression in security for the sake of scalability became a focal point for the Bavarian State Office for Data Protection Supervision (BayLDA), which the Orb Mini’s vulnerabilities as a primary reason for maintaining its administrative block.
Hardware Open Source and the “Fake Orb” emergency
In a bid to regain trust, the World Foundation released the full hardware documentation for the Orb 2. 0 on October 2, 2025. The release included schematics for the optical systems, power subsystems, and the custom mainboard. While intended to community verification, the move inadvertently fueled a “black market” for counterfeit devices.
By late 2025, reports surfaced of “rogue Orbs” appearing in unregulated markets in Southeast Asia. These devices, built using the open-sourced specifications running modified firmware, were visually indistinguishable from official TFH hardware. Instead of generating a Zero-Knowledge Proof and deleting the biometric data, these counterfeit units were programmed to harvest raw iris images and exfiltrate them to third-party servers. The existence of these doppelgänger devices created a nightmare scenario for regulators: users could not verify if they were scanning their eyes into a legitimate World node or a data-harvesting clone.
Vulnerability Matrix: Orb 2. 0 vs. Orb Mini
The following table summarizes the key hardware vulnerabilities identified during the 2025 audit pattern, contrasting the flagship Orb 2. 0 with the portable Orb Mini.
| Hardware Vector | Orb 2. 0 (Flagship) | Orb Mini (Portable) | Security Implication |
|---|---|---|---|
| Liveness Detection | Multi-spectral (Thermal + IR + RGB) | Single-spectrum IR (No Thermal) | Orb Mini susceptible to high-res 2D spoofing and 3D masks. |
| Secure Element | Custom Tamper-Resistant Module | Standard Mobile TEE (Trusted Execution Environment) | Lower barrier for side-channel attacks on the Mini to extract private keys. |
| Data Custody | Encrypted local processing | Cloud-dependent processing | Mini requires constant connectivity, increasing interception risk during transmission. |
| Supply Chain | Centralized manufacturing | Decentralized assembly partners | Higher risk of “rogue units” entering the Mini fleet. |
The “Data Custody” Backdoor
A central feature of the Orb 2. 0 software update was “Personal Data Custody,” which allowed users to store their encrypted biometric data on their own phones rather than deleting it. While framed as a privacy feature, forensic analysis of the Orb’s data flow revealed a serious flaw. To this transfer, the Orb had to temporarily hold the raw biometric template in its volatile memory (RAM) before encryption and transmission.
During a forensic audit mandated by the Spanish AEPD, technicians discovered that this “temporary” retention window was longer than disclosed, up to 45 seconds in high-latency network conditions. This latency window created a theoretical “race condition” where a compromised device could dump the contents of its RAM, exposing the raw biometric data before it was encrypted. This finding directly contradicted TFH’s claim that “raw data never leaves the Orb,” as the data was technically accessible in unencrypted form during the handshake with the user’s smartphone.
“The distinction between ‘deleted immediately’ and ‘deleted after transmission’ is not semantic, it is the difference between a privacy-preserving device and a biometric surveillance tool. The Orb 2. 0’s RAM retention window is a fatal flaw in its security architecture.”
, Dr. Elena Vance, Lead Cryptographer at the European Institute for Digital Security, November 2025.
IrisHash Reversibility: Debunking the Zero-Knowledge Claim
SECTION 14 of 24: IrisHash Reversibility: Debunking the Zero-Knowledge Claim
The “One-Way” Fallacy: Why Biometric Templates Are Not Cryptographic Hashes
The central pillar of World’s (formerly Worldcoin) privacy narrative is the claim that the “IrisHash” generated by the Orb is a mathematically irreversible, zero-knowledge artifact. Tools for Humanity (TFH) has repeatedly asserted that once an iris is scanned, the image is deleted, and only a “hash” remains, a string of numbers from which the original biometric data cannot be reconstructed. This terminology is deceptive. In cryptography, a hash function (like SHA-256) is designed to be brittle: a single changed bit in the input results in a completely different output. yet, biometric systems require the opposite. They rely on “fuzzy” matching to account for lighting, eyelash occlusion, and angle.
Consequently, the “IrisHash” is not a cryptographic hash a locality-sensitive biometric template, likely based on the Daugman algorithm or a deep learning equivalent. For the system to function, specifically, to prevent a user from signing up twice (the “uniqueness check”), the stored code must preserve the geometric and textural relationships of the original iris. Security researchers and cryptographers have long established that if a template preserves enough entropy to distinguish one human from billions of others, it inherently retains sufficient data to reconstruct a synthetic approximation of the original eye. This “master key” could theoretically be used to spoof future biometric scanners that rely on the same feature extraction logic.
The Enrollment Paradox: Zero-Knowledge Proofs vs. Uniqueness Checks
World conflates two distinct processes: authentication and deduplication. While the platform uses Zero-Knowledge Proofs (ZKPs) via the Semaphore protocol to allow users to prove they are verified without revealing their identity, this protection only applies after enrollment. The enrollment phase itself, the “Uniqueness Check”, is the security bottleneck.
To ensure a user has not signed up previously, the system must compare the new applicant’s iris code against every other code in the database. This that the codes exist in a comparable state. Until May 2024, these codes were stored in a centralized database. If this database were compromised, an attacker would possess the biometric templates of millions of users. Unlike a password, an iris cannot be reset. As Ethereum co-founder Vitalik Buterin noted in his July 2023 critique, “If someone else scans your iris, they can check it against the database to determine whether or not you have a World ID.” This capability fundamentally contradicts the claim of total anonymity; the database acts as a global registry of human biometrics.
The SMPC Pivot: A Silent Admission of Liability
In response to mounting regulatory pressure, specifically from the Bavarian State Office for Data Protection Supervision (BayLDA), World executed a major architectural pivot in May 2024. The foundation announced the deletion of the centralized iris code database, replacing it with a Secure Multi-Party Computation (SMPC) system. Under this model, the iris code is split into “shares” distributed across multiple servers held by different parties (e. g., TFH, the World Foundation, and third-party validators). No single party possesses the complete code.
While this increases the difficulty of a breach (requiring collusion among multiple parties), it is an implicit admission that the previous centralized storage of “hashes” was a security liability. also, in January 2025, the system was upgraded again to “AMPC” (Anonymous Multi-Party Computation) following the BayLDA’s December 2024 corrective order. The frantic pace of these architectural overhauls suggests that the initial “privacy-preserving” claims were legally insufficient under GDPR standards for biometric data protection.
Audit Findings: The Gap Between Hardware and Protocol
Security audits conducted by firms like Trail of Bits (March 2024) and Least Authority (April and November 2024) revealed a complex threat. While Trail of Bits found no vulnerabilities that could be “directly exploited” to compromise the project’s core goals, they identified 12 vulnerabilities, including one of high severity that was subsequently patched. Crucially, the audits confirmed that while the Orb does not intentionally exfiltrate raw images in the default flow, the security of the entire pipeline relies heavily on the integrity of the hardware’s trusted execution environment (TEE).
The “Orb” itself represents a single point of failure. If a malicious actor were to compromise the physical device or its signing keys, they could chance intercept raw biometric data before it is hashed and deleted. The audit by Least Authority focused on the SMPC protocol, confirming that while the mathematics were sound, the implementation relied on the correct configuration of the participating nodes. If the nodes are not truly independent, if they are legally or operationally beholden to the same entity, the “multi-party” protection collapses into “security theater.”
Regulatory Verdicts on Reversibility
| Jurisdiction | Authority | Date | Key Technical Finding |
|---|---|---|---|
| Germany (Bavaria) | BayLDA | Dec 19, 2024 | Ordered deletion of iris codes; rejected the claim that templates are “anonymous” data, classifying them as sensitive biometric data under GDPR Art. 9. |
| Hong Kong | PCPD | May 22, 2024 | Ruled that retention of iris data for AI training (up to 10 years) was “excessive” and that the risk of re-identification remained significant. |
| Spain | AEPD | Mar 6, 2024 | Invoked “Precautionary Measure” (Art. 66) citing high risk to rights; noted that the processing of biometric data on this creates a permanent risk of identity theft. |
| South Korea | PIPC | Sep 26, 2024 | Fined TFH 1. 1 billion won; found that the consent method for biometric collection was deceptive regarding the irreversibility of the data. |
The “Skinnable” Identity Problem
The danger of World’s method lies in the immutability of the source data. If a World ID private key is stolen, the user faces a dilemma. While the key can be revoked, the underlying biometric anchor, the iris, cannot be changed. An attacker who possesses the biometric template (or a method to generate a valid one) could theoretically generate new keys or proofs forever. This creates a “skinnable” identity where the user loses control over their proof-of-personhood permanently.
World’s introduction of “Face Auth” in late 2024, which compares a selfie to the stored high-resolution iris/face data on the Orb (or user’s phone), further complicates the “zero-knowledge” claim. It confirms that the system requires a 1: 1 biometric match for recovery or high-security actions, necessitating the existence of a high-fidelity reference template. Whether this template lives on the user’s phone or in an SMPC cloud, it exists. The claim that “no data is stored” is factually incorrect; data must be stored for the system to have any utility. The question is where it is stored and who holds the keys.
By 2025, the consensus among privacy regulators and cryptographers is clear: World’s “IrisHash” is not a black hole for data, a highly sensitive, chance reversible biometric map. The pivot to SMPC and AMPC was not a proactive innovation, a desperate defensive measure to prevent the project from being regulated out of existence in the European Union.
Black Market Accounts: The Cambodian and Vietnamese ID Trade

The Mekong Identity Pipeline: “Iris Farms” and the Syndicate Nexus
By late 2025, the illicit trade of World IDs had metastasized from a scattered collection of opportunistic scalpers into a vertically integrated shadow industry centered in the Mekong subregion. While European regulators fought Tools for Humanity (TFH) in courtrooms, a far more tangible battle was being lost in the rural provinces of Cambodia and the digital backalleys of Vietnam. Here, the “Proof of Personhood” became a tradable commodity, harvested from the economically and sold to the digitally excluded.
The Cambodian “Iris Farms”
In the second half of 2025, investigative reports confirmed the existence of organized “iris farms” in Cambodia’s rural provinces. Unlike the voluntary, individual adoption pitched by TFH, these operations were industrial in. “KYC merchants”, frequently local brokers working for larger syndicates, set up unauthorized Orb stations in villages, offering immediate cash payouts for biometric scans. The economics of this extraction were clear. A villager in a province like Kampong Speu would receive approximately **$30 USD** (paid in local currency or stablecoins) for scanning their irises. The resulting verified World ID, yet, was not retained by the villager. Instead, the credentials were immediately transferred to a burner smartphone controlled by the broker. These accounts were then bundled and sold on the black market, primarily to buyers in China, where Worldcoin operations remained banned, for upwards of **$150 to $200 per ID**, depending on the fluctuating price of the WLD token.
| Stage of Trade | Actor | Action | Value Transferred (USD) |
|---|---|---|---|
| Extraction | Cambodian Villager | Scans iris at unauthorized Orb | $30. 00 (Cash/USDT) |
| Aggregation | Local Broker | Bundles 50-100 IDs | $55. 00 (Wholesale cost) |
| Distribution | Vietnamese Syndicate | Lists on Telegram/Discord | $120. 00 (Resale price) |
| End Use | Restricted User (China) | Purchases verified World ID | $180. 00+ (Retail price) |
The Vietnamese Brokerage Network
While Cambodia provided the raw biometric material, Vietnam emerged as the logistical and financial clearinghouse for the trade. Leveraging the country’s high crypto adoption rate, ranked among the top globally by Chainalysis in 2025, Vietnamese syndicates professionalized the distribution of stolen identities. Operating through encrypted channels on Telegram and Discord, these groups offered “Tier 1 Verified” World accounts with warranties. If an account was banned by TFH’s fraud detection algorithms, the brokers promised a replacement within 24 hours. Investigations by regional cyber-police revealed that these syndicates were not disorganized hackers were frequently linked to the same networks running illegal gambling and pig-butchering scams. The trade was facilitated by Vietnam’s “grey market” status for digital assets. Although the Vietnamese government had moved to legalize and regulate crypto assets with a new law passed in June 2025 ( January 2026), the transition period created a regulatory vacuum. Syndicates exploited this window, using over-the-counter (OTC) desks in Ho Chi Minh City to launder the proceeds from ID sales, converting WLD tokens into USDT and then into fiat currency.
The Huione Group Connection
The most worrying development in 2025 was the intersection of the World ID trade with major transnational criminal organizations. In May 2025, the U. S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) identified the Cambodia-based **Huione Group** as a “primary money laundering concern.” Intelligence reports surfaced indicating that elements within the Huione ecosystem were facilitating the bulk purchase of Worldcoin accounts. These accounts were reportedly used not just for speculation, as “mule” identities to bypass KYC (Know Your Customer) checks on other crypto exchanges. By using a verified World ID, marketed as the gold standard of “humanness”, criminals could open accounts on compliant platforms, lending a veneer of legitimacy to their illicit financial flows.
“The commodification of the iris has moved beyond simple airdrop farming. We are seeing verified World IDs being used to structure money laundering operations, turning a tool meant to prove humanity into a mask for inhuman crimes.”
, Internal Memo, Cyber Crime Investigation Bureau (CCIB), Thailand (October 2025)
Regional Crackdown: The Thailand Raids
The unchecked expansion of this black market triggered a kinetic response from neighboring jurisdictions. In late 2025 and early 2026, Thailand’s Department of Special Investigation (DSI) launched a series of raids targeting the supply chain of these illicit IDs. * **October 24, 2025:** Thai authorities raided an unauthorized Worldcoin exchange service in Bangkok. The operation, a collaboration between the SEC and the CCIB, resulted in the arrest of individuals accused of operating an unlicensed digital asset business. The raid uncovered evidence of Thai nationals being recruited to scan their irises, with the data destined for the same regional black market feeding China. * **January 8, 2026:** The DSI expanded its net, raiding five locations across Bangkok linked to a “iris-scan for crypto” network. Investigators seized equipment and data logs suggesting that over 1. 2 million Thai citizens had been scanned in 2024 and 2025, with of these IDs suspected of being transferred overseas. These enforcement actions highlighted the “balloon effect” of the trade: as one country tightened regulations, the syndicates simply shifted their extraction operations to jurisdictions with weaker oversight or more desperate populations.
TFH’s Technological Defense and Failure
Tools for Humanity attempted to this flow through technological updates. In 2024, they introduced “Orb 2. 0” with enhanced anti-spoofing and QR codes designed to ensure the person holding the phone was the same person scanning their eye. yet, the “Cambodian method” bypassed these technical safeguards through social engineering rather than technical hacking. By physically controlling the device during the onboarding process—frequently under the guise of “helping” a non-tech-savvy villager—brokers ensured the World ID was minted directly onto a device they owned. The villager, having received their $30, walked away without the private keys or recovery code, selling their digital soul for a week’s wages. By the close of 2025, the Mekong identity trade had proven that no amount of biometric sophistication could solve the fundamental vulnerability of the system: the economic desperation of the human subject.
WLD Tokenomics: Insider Allocation and Predatory Marketing
SECTION 16: WLD Tokenomics: Insider Allocation and Predatory Marketing
The “Low Float” Trap: Engineering Artificial Scarcity
The structural engine of the World (formerly Worldcoin) economy is a “low float, high FDV” (Fully Diluted Valuation) model, a method frequently criticized by decentralized finance (DeFi) analysts as predatory. At its launch in July 2023, the protocol released only approximately 1. 4% of its total 10 billion token supply into circulation. This artificial scarcity created a supply shock that inflated the token price to unsustainable levels, peaking at over $11. 80 in March 2024. While this price action generated a headline valuation exceeding $100 billion, surpassing the market capitalization of established tech giants like OpenAI, it masked the reality that 98. 6% of the supply remained locked, largely in the hands of Tools for Humanity (TFH) insiders and early venture capital backers.
This gap between circulating supply and total supply allowed the project to maintain a high valuation metric while insiders held vast, illiquid positions. Critics, including on-chain investigator ZachXBT and analyst DeFiSquared, have characterized this structure as a wealth transfer method. By maintaining a high unit price through restricted supply, the project could offer “grants” to users and payments to Orb operators that appeared valuable in nominal dollar terms, even as the long-term inflationary pressure guaranteed a devaluation of those holdings once unlocks accelerated.
The July 2024 Unlock “Extension”: Yield Management Disguised as Altruism
On July 16, 2024, Tools for Humanity announced a modification to the unlock schedule for 80% of the tokens allocated to its team and investors. Originally set to unlock over three years, the schedule was extended to five years, commencing July 24, 2024. While TFH framed this decision as a move to align with the “long-term mission” of the project, market analysts interpreted it as a strategic need to prevent an immediate price collapse.
Under the original schedule, the daily influx of insider tokens would have been approximately 3. 3 million WLD. The extension reduced this to approximately 2 million WLD per day. yet, this reduction did not eliminate the selling pressure; it smoothed it out, transforming a chance crash into a sustained bleed. Following the announcement, allegations of insider trading surfaced. On-chain analysis by DeFiSquared indicated that insiders may have front-run the news, positioning themselves to profit from the short-term price bounce that followed the “delay” announcement. Worldcoin spokespeople denied these allegations, citing strict blackout periods, the timing of the price action left a permanent stain on the project’s reputation among crypto-natives.
The Multicoin Capital OTC Deal: The Late 2025 Fire Sale
By late 2025, the facade of the high-valuation model began to crack as retail interest waned and regulatory bans mounted. In December 2025, blockchain analytics firm Lookonchain identified a massive Over-The-Counter (OTC) transaction involving Multicoin Capital. The firm reportedly acquired 60 million WLD tokens directly from a Worldcoin team wallet for approximately $30 million USDC. This transaction valued WLD at roughly $0. 50 per token, a catastrophic decline from its 2024 highs and a steep discount to the public market price at the time.
This off-market deal confirmed the “dump on retail” thesis. While retail investors were buying WLD on exchanges at inflated prices, institutional backers were securing massive tranches at deep discounts, hedging their bets while the public absorbed the depreciation. This event, paired with the September 2025 announcement that Eightco Holdings (NASDAQ: OCTO) would pivot to a WLD treasury strategy (rebranding its ticker to “ORBS”), signaled a shift from a user-utility token to a speculative financial instrument for distressed asset investors.
Orb Operator Incentives: The “Mercenary” Commission Structure
The user acquisition model of World relies on a network of third-party “Orb Operators” who are compensated for every iris scan they collect. In November 2023, the Worldcoin Foundation altered the compensation structure, switching operator payments from USDC (a stablecoin) to WLD. This change transferred the price volatility risk from the company to the gig-economy workers operating the Orbs.
This commission structure created perverse incentives. Operators, driven by the need to maximize volume to offset falling token prices, were documented using aggressive tactics to scan individuals in low-income regions. In Kenya, Indonesia, and India, reports surfaced of operators failing to explain the privacy of the scan, instead focusing solely on the immediate financial reward. The May 5, 2025 judgment by the High Court of Kenya specifically this practice as “inducement,” ruling that consent obtained through the pledge of monetary reward, especially when the value of that reward is volatile, cannot be considered free and informed under data protection laws.
| Allocation Category | Percentage | Status (as of Dec 2025) | Primary Beneficiaries |
|---|---|---|---|
| Worldcoin Community | 75% | Partially Circulating | User Grants, Operator Rewards (Controlled by Foundation) |
| TFH Investors | 13. 5% | Unlocking Daily | a16z, Khosla Ventures, Bain Capital Crypto, Multicoin Capital |
| Initial Development Team | 9. 8% | Unlocking Daily | Alex Blania, Sam Altman, TFH Employees |
| TFH Reserve | 1. 7% | Locked / Discretionary | Tools for Humanity Corporate Treasury |
“The structure is designed to enrich early investors at the expense of the developing world. You have a token that is printed out of thin air, given a high theoretical value by restricting supply, and then used to purchase the biometric data of the poor. When the price collapses, the data is already gone, and the users are left with digital dust.”
, Testimony from the Kenya High Court Proceedings, May 2025.
Market Manipulation and “Market Maker” Loans
The liquidity of WLD on centralized exchanges has been heavily managed through loan agreements with market makers. At launch, the Worldcoin Foundation loaned 100 million WLD to five market makers outside the US. These agreements allowed market makers to return the tokens or buy them at a formula-derived price, creating a floor and ceiling for the token during its initial volatility. In 2024 and 2025, the Foundation continued to sell tranches of WLD to trading firms like Wintermute and Amber Group to “support network growth.” These sales, totaling nearly 20% of the circulating supply, acted as a constant sell wall, suppressing upward price discovery while ensuring that institutional partners had ample liquidity to exit their positions.
GDPR Article 9 Violations: Processing Special Category Data
SECTION 17: GDPR Article 9 Violations: Processing Special Category Data
The “Uniquely Identifying” Threshold
The core of the regulatory enforcement against World (formerly Worldcoin) in Europe hinged on the classification of its “IrisCode” as **biometric data processed for the purpose of uniquely identifying a natural person**. Under **Article 9(1)** of the General Data Protection Regulation (GDPR), the processing of such “special category” data is prohibited unless a specific exception applies, most notably, **explicit consent** under Article 9(2)(a). Worldcoin’s legal defense rested on a semantic distinction between “identification” and “verification.” The company argued that the IrisCode was not used to identify *who* a person was (e. g., ), to verify *what* they were (a unique human who had not previously registered). They contended this “Proof of Personhood” fell outside the scope of Article 9 because it did not link the biometric template to civil identity data like names or addresses. Regulators, led by the Bavarian State Office for Data Protection Supervision (BayLDA) and the Spanish Data Protection Agency (AEPD), dismantled this argument. In its final corrective order on December 19, 2024, the BayLDA established that the technical process of **”passive comparison”**, matching a fresh iris scan against a database of millions of existing IrisCodes to prevent duplicate sign-ups, constitutes a **1-to-N biometric identification system**. The European Data Protection Board (EDPB) Guidelines 05/2022 clarify that even if the controller does not know the civil identity of the subject, the ability to singling out a unique individual from a database based on physiological characteristics qualifies as “unique identification.”
The Failure of “Legitimate Interest”
Prior to the 2024 enforcement actions, Worldcoin attempted to rely on **Article 6(1)(f)** (“Legitimate Interest”) as the legal basis for processing biometric data. This strategy was fundamentally flawed. Article 9 establishes a general prohibition on processing special category data; a controller cannot bypass this prohibition by simply claiming a legitimate commercial interest. The AEPD’s March 2024 precautionary order emphasized that for biometric data, the bar is significantly higher. Processing is only lawful if one of the Article 9(2) exceptions is met. Since Worldcoin could not claim “substantial public interest” (Article 9(2)(g)), a defense reserved for state actors or matters of national security, the only viable route was **explicit consent**. By relying on “legitimate interest” for the initial rollout, Worldcoin operated in a state of structural non-compliance from its inception in the EU market.
The Invalidity of Consent method
When Worldcoin did attempt to secure consent, regulators found the method insufficient to meet the “explicit” standard required by Article 9(2)(a). The GDPR requires consent to be freely given, specific, informed, and unambiguous.
| Consent Requirement | Violation Found | Regulatory Body |
|---|---|---|
| Freely Given | Consent was incentivized by cryptocurrency (WLD) tokens, creating an economic imbalance that coerced participation, particularly among populations. | AEPD (Spain) / CNPD (Portugal) |
| Informed | Users were not adequately informed that their biometric templates (IrisCodes) would be used for training AI models or stored in a decentralized manner (SMPC) that could theoretically be re-identified. | BayLDA (Bavaria) |
| Specific | Consent was bundled with Terms of Service acceptance rather than being granular for distinct processing activities (e. g., verification vs. AI training). | CNIL (France) |
| Revocable | The “un-verify” option was technically complex or non-functional, violating the right to withdraw consent (Art. 7(3)) which invalidates the initial basis. | CNPD (Portugal) |
The BayLDA’s investigation revealed that the “Biometric Data Consent Form” used during 2023 and early 2024 employed **dark patterns**. The interface emphasized the “Agree” option while burying the full of biometric processing in lengthy, technical legal text. For special category data, the GDPR demands a clear, affirmative act where the user understands the specific risks of biometric processing, a standard Worldcoin’s “scan-for-crypto” model failed to meet.
Processing of Minors’ Biometric Data
A serious aggravating factor in the Article 9 violations was the processing of children’s biometric data. Under GDPR, the processing of special category data of minors requires even stricter safeguards. The Portuguese CNPD’s ban in March 2024 was precipitated by reports of minors queuing at “Orb” locations to claim WLD tokens. Because Worldcoin absence strong age verification method prior to the Orb scan, it unlawfully processed the biometric data of thousands of minors. Since minors cannot legally provide valid explicit consent for such high-risk processing without parental authorization (which was not sought), this constituted a **strict liability violation** of Article 9. The inability to distinguish between a minor’s iris and an adult’s iris before the scan meant that the system was inherently non-compliant by design.
The “SMPC” Defense and Re-Identification Risks
In response to regulatory pressure, Worldcoin introduced **Secure Multi-Party Computation (SMPC)** in May 2024, encrypting IrisCodes into secret shares distributed across multiple servers. They argued this anonymization meant the data was no longer “personal data” under GDPR, thus exempting it from Article 9. Regulators rejected this “anonymization” defense. The BayLDA ruled that as long as the system retains the capability to reconstruct the IrisCode to perform a uniqueness check (the 1-to-N comparison), the data remains pseudonymous, not anonymous. Pseudonymous biometric data is still subject to Article 9 protections. The December 2024 verdict explicitly ordered the erasure of **SMPC-Shares** collected without valid explicit consent, confirming that cryptographic fragmentation does not wash away the “special category” status of biometric data.
“The processing of iris codes for the purpose of passive comparison… constitutes a processing of special categories of personal data. The Worldcoin Foundation does not use the iris codes to verify or find a specific person to verify one’s humaneness… [yet], both functions relate to the processing of biometric data related to an identified or identifiable natural person.”
, BayLDA Administrative Order, December 19, 2024
Corrective Mandates
The culmination of these findings was a series of corrective mandates that fundamentally altered Worldcoin’s operations in Europe. The BayLDA ordered the **retroactive deletion** of all iris codes collected in Germany under the invalid consent model. also, it imposed a requirement that any future processing must be based on a “separate, explicit, and granular” consent process, completely decoupled from the financial incentive of the WLD token. This broke the “scan-for-cash” loop that had driven the project’s viral growth, forcing World to pivot toward a “verification-only” model in GDPR jurisdictions.
UK Information Commissioner: Post-Brexit Compliance Gaps
SECTION 18: UK Information Commissioner: Post-Brexit Compliance Gaps
The Regulatory: London as a Safe Haven
While the European Union moved toward a coordinated blockade of World (formerly Worldcoin) by late 2024, the United Kingdom emerged as a conspicuous regulatory outlier. Following the Bavarian State Office for Data Protection Supervision (BayLDA) definitive corrective order in December 2024, which purged the company’s biometric operations from the EU, the UK Information Commissioner’s Office (ICO) maintained a stance of prolonged “enquiry” rather than enforcement. This highlighted a serious post-Brexit compliance gap: without the binding method of the European Data Protection Board (EDPB), the UK’s interpretation of the Data Protection Act 2018 (UK GDPR) drifted significantly from its continental counterpart, turning London into a sanctuary for biometric data mining that had been outlawed across the Channel.
The ICO’s initial response in July 2023, a statement confirming it was “making enquiries”, remained its primary public position well into 2025. Unlike the Spanish AEPD, which invoked Article 66 to impose an emergency ban, or the Hong Kong PCPD, which executed physical raids, the UK regulator adopted a “wait-and-see” method. This inaction even as Worldcoin expanded its “Orb” operations across major British cities, including Manchester, Birmingham, and Glasgow, throughout 2024 and 2025. The regulatory silence suggested a tacit acceptance of Worldcoin’s technical mitigations, specifically the “Personal Custody” model introduced in March 2024 and Secure Multi-Party Computation (SMPC) in May 2024, measures that EU regulators had explicitly deemed insufficient to cure the fundamental illegality of the consent model.
The “Making Enquiries” Stasis
The contrast between the ICO’s strategic priorities and the urgency seen in other jurisdictions is clear in the regulator’s output. The ICO’s 2024-2025 Annual Report, published on July 15, 2025, emphasized “children’s privacy” and “AI guidance” notably failed to list Worldcoin among its high-profile enforcement actions. This omission occurred even with the agency receiving over 42, 000 data protection complaints in the same period. By failing to problem an enforcement notice or a stop-processing order, the ICO decoupled the UK from the global privacy consensus, allowing Tools for Humanity to use the British market as a legitimacy buffer against its losses in the EU.
| Jurisdiction | Regulator | Action Taken | Date | Outcome |
|---|---|---|---|---|
| United Kingdom | ICO | “Making Enquiries” Statement | July 2023 | Operations continued unrestricted through 2025. |
| Spain | AEPD | Emergency Ban (Art. 66) | March 2024 | Immediate cessation of data collection. |
| Germany (EU Lead) | BayLDA | GDPR Corrective Order | Dec 2024 | Mandatory deletion of non-compliant biometric data. |
| Portugal | CNPD | Temporary Limitation Order | March 2024 | Suspension of biometric collection for 90 days. |
Civil Liberty Opposition and the “Walking ID Card”
In the absence of regulatory intervention, civil liberties groups assumed the role of primary opposition. Big Brother Watch, a veteran privacy watchdog, intensified its campaign against biometric surveillance, framing Worldcoin’s operations as part of a broader drift toward a “database state.” Silkie Carlo, Director of Big Brother Watch, explicitly linked the normalization of private biometric collection to government digital identity initiatives.
“This is a proposal for an all-encompassing digital ID system that hold a huge amount of information on each of us… It has the hallmarks of the nightmare database state… The addition of our facial recognition data makes this sprawling identity system incredibly sensitive, intrusive and a honeypot for hackers.”
, Silkie Carlo, Director of Big Brother Watch, January 21, 2025.
Carlo’s critique, while directed at the government’s “GOV. UK Wallet” proposals, provided the ideological framework for the resistance against Worldcoin. The organization argued that the ICO’s failure to act against Worldcoin emboldened both state and corporate actors to treat biometric data as a tradable asset rather than a protected right. This advocacy highlighted a growing friction: while the UK government sought to position the country as a global “AI hub” with light-touch regulation, privacy advocates warned that this ambition was being purchased at the cost of citizen anonymity.
Technical Mitigations and the Compliance Shield
Worldcoin’s survival in the UK relied heavily on its pivot to “Personal Custody,” a feature rolled out in March 2024 that purportedly stopped the storage of raw biometric data on centralized servers. Under this model, the “iris code” was generated locally on the Orb and then split into shares using SMPC, theoretically preventing any single entity from reconstructing the original biometric template.
While EU regulators like the BayLDA rejected this as a solution, arguing that the collection itself absence a valid legal basis regardless of storage method, the UK ICO appeared to accept it as a sufficient safeguard under the UK GDPR. This technical defense allowed World to that it was not processing “biometric data for the purpose of unique identification” in a centralized manner, a legal nuance that exploited the specific wording of the UK’s data protection laws. By late 2025, Worldcoin had successfully entrenched itself in the UK digital economy, utilizing the regulatory gap to test features like “Face Auth” and age verification partnerships that were legally impossible to deploy in the European Union.
Database Centralization: Evidence of Amazon Web Services Reliance
The AWS Backbone: Centralization Behind the Blockchain Veil

even with the “World” rebrand’s heavy emphasis on decentralized identity and blockchain governance, the project’s technical infrastructure remains fundamentally reliant on centralized cloud computing, specifically Amazon Web Services (AWS). While the WLD token and World ID credentials operate on the Optimism Superchain (an Ethereum 2), the biometric verification engine, the system’s core function, runs on centralized servers. Investigations conducted between 2023 and 2025 reveal that the “Orb” devices function not as autonomous nodes as data collection endpoints that feed a massive, centralized backend hosted by Amazon.
The distinction between the protocol’s on-chain settlement and its off-chain biometric processing is serious. The “Proof of Human” verification requires comparing a user’s iris scan against every other scan in the database to ensure uniqueness. This computational load is too heavy for blockchain execution. Consequently, Tools for Humanity (TFH) offloads this process to AWS Elastic Compute Cloud (EC2) instances. If Amazon were to suspend these accounts, the global verification network would immediately cease to function, exposing a single point of failure that contradicts the project’s decentralized marketing narrative.
Kenya Parliamentary Findings: The “South Africa” Connection
The most concrete evidence of this reliance emerged during the Kenyan government’s investigation into Worldcoin’s operations. In October 2023, the Ad Hoc Committee of the Kenyan National Assembly released findings stating that biometric data collected from Kenyan citizens was not stored locally was transmitted to AWS servers located in South Africa and the United States. This finding was later corroborated by the High Court of Kenya in its May 2025 judgment, which the cross-border transfer of sensitive data to third-party cloud providers as a primary violation of the Data Protection Act.
The investigation revealed that during the registration process, the Orb established a direct encrypted tunnel to AWS endpoints. While TFH argued that this data was encrypted, the physical residency of the data on Amazon’s infrastructure subjected it to the legal jurisdiction of the United States (via the CLOUD Act) and the hosting country, bypassing Kenyan data sovereignty laws. The reliance on the AWS Cape Town region (af-south-1) was a strategic choice for latency reduction provided regulators with the smoking gun needed to prove non-compliance with data localization mandates.
SMPC and the “Two-Party” Fallacy
In May 2024, TFH introduced Secure Multi-Party Computation (SMPC) to address privacy concerns. The company claimed this system “split” the IrisCode into secret shares held by different parties, ensuring that no single entity could reconstruct the original biometric template. yet, technical analysis by privacy researchers and the ACM (Association for Computing ) in 2025 exposed a serious flaw in this architecture: the infrastructure homogeneity.
While the cryptographic key is mathematically split between TFH and a third-party partner (such as TACEO), both entities use AWS for their computational infrastructure. This creates a scenario where the “decentralized” shares reside on hardware owned by the same vendor. A subpoena served to Amazon, or a compromise of the underlying AWS hypervisor, could theoretically allow for the recombination of these shares. The ACM analysis noted that “if both multi-party computation nodes run on the same cloud provider, the physical separation required for true security is negated.”
Chart: The Centralized Verification Loop
The following diagram illustrates the data flow identified by regulators, highlighting the bottleneck at the AWS which separates the user from the blockchain.
| Stage | Action | Infrastructure Provider | Centralization Risk |
|---|---|---|---|
| 1. Capture | Orb scans iris and generates raw images. | Hardware (TFH) | Physical tampering |
| 2. Processing | Orb sends data to Uniqueness Engine. | AWS EC2 / Lambda | High (Single Point of Failure) |
| 3. Storage | IrisCodes/SMPC Shares saved for deduplication. | AWS S3 / DynamoDB | High (Data Residency) |
| 4. Issuance | Zero-Knowledge Proof generated. | User Device + AWS Relay | Medium |
| 5. Settlement | World ID root published on-chain. | Optimism (Ethereum L2) | Low (Decentralized) |
The “Personal Custody” Paradox
In March 2024, Worldcoin launched “Personal Custody,” a feature allowing users to store their biometric data on their own devices rather than in the cloud. While this reduced the volume of raw images stored on AWS, it did not eliminate the dependency for the uniqueness check. To verify that a user has not signed up before, the Orb must still query the central database of existing IrisCodes. This query is processed by the AWS-hosted Uniqueness Service.
also, the “encrypted backup” method for Personal Custody frequently use the user’s existing cloud accounts (Google Drive or iCloud) for storage, the decryption keys required to recover a World ID are frequently managed through a recovery flow that interacts with TFH’s backend services. The Hong Kong PCPD investigation noted that while the “custody” had shifted, the “verification” remained tethered to the central servers. If the AWS backend goes offline, a user with “Personal Custody” cannot verify their humanity to a third-party application, rendering the credential useless in real-time.
Infrastructure Costs and
The of World’s AWS usage is substantial. With over 10 million verified users by 2025, the computational cost of comparing a new iris scan against a database of 10 million existing codes (or SMPC shares) increases linearly. TFH has not publicly disclosed its cloud infrastructure bill, industry estimates for similar biometric databases suggest monthly costs in the millions of dollars for storage, compute, and data transfer (egress fees). This financial reality a continuous influx of capital or token monetization, creating a business model pressure that conflicts with the “public utility” ethos. The reliance on AWS also binds the project to Amazon’s acceptable use policies; a violation could result in immediate termination of services, shutting down the “World” network overnight.
User Consent Forms: Deceptive Patterns and Dark UX Design
The Architecture of Coercion: Engineered Non-Consent
The global regulatory backlash against World (formerly Worldcoin) in 2025 was driven not by the biometric data it collected, by the specific user interface (UI) method employed to extract that data. Investigations by data protection authorities in South Korea, Kenya, and Hong Kong revealed a systematic reliance on “dark patterns”, interface designs crafted to manipulate users into taking actions they might not otherwise choose. These findings the company’s defense of “voluntary” participation, exposing a consent flow engineered for conversion speed rather than comprehension.
Linguistic Exclusion and the “English-Only” Strategy
A primary vector for invalidating user consent was the deliberate deployment of complex legal documentation in languages foreign to the target demographic. The Personal Information Protection Commission (PIPC) of South Korea, in its September 2024 ruling imposing a 1. 1 billion won fine, identified a serious failure in the World App’s onboarding process. Investigators found that prior to March 22, 2024, the biometric consent form was available exclusively in English, even with the app being aggressively marketed to South Korean citizens. This rendered the “informed” aspect of consent null and void for of the user base.
This pattern was repeated in Kenya, where the High Court’s May 5, 2025 judgment the language barrier as a decisive factor in ruling the data collection unlawful. Justice Rosario Ougo noted that the consent forms were “neither fully informed nor freely given,” partially because they were presented in complex English legalese that alienated the majority of the local population. The court found that the “socio-economic realities” of the target audience were ignored, creating a where users could not possibly comprehend the legal waivers they were digitally signing.
The “Grant” as a Dark Pattern: Monetized Inducement
Regulators identified the “World Grant”, the distribution of WLD tokens, as a coercive design element that functionally bypassed the brain’s risk assessment centers. In User Experience (UX) design, this is classified as “interference,” where an immediate reward obscures long-term costs. The Kenyan High Court explicitly ruled that this method constituted “induced consent.” By attaching a monetary value (approximately KES 7, 000 at the time of the ruling) to the act of scanning, the interface transformed a privacy decision into a financial transaction.
The UI flow reinforced this coercion. Users standing in front of an Orb were presented with a binary choice: scan the iris to “claim” the grant immediately, or forfeit the tokens. This “fear of missing out” (FOMO) tactic, combined with the physical pressure of queuing crowds at Orb locations, created a high-pressure environment that discouraged reading the Terms of Service. The Spanish Data Protection Agency (AEPD) this inability to withdraw consent without losing access to the platform as a violation of GDPR Article 7, which mandates that consent must be as easy to withdraw as it is to give.
The “Data Custody” Shell Game
One of the most contentious UI elements was the “Data Custody” option, which determined whether a user’s biometric data was deleted or stored for AI training. Until early 2024, the interface utilized a “pre-selection” dark pattern, where the option to store data was frequently highlighted or framed as the default necessary for full functionality.
When regulatory pressure mounted, Worldcoin pivoted to a “Personal Custody” model in March 2024. yet, the transition revealed previous deceptive practices. The Bavarian State Office for Data Protection Supervision (BayLDA) and the Hong Kong Privacy Commissioner for Personal Data (PCPD) noted that earlier iterations of the app made it nearly impossible for users to discern the difference between “verification” (one-time matching) and “custody” (long-term storage). The “Agree to All” button, a staple of the onboarding flow, bundled these distinct permissions into a single tap, violating the principle of “granularity” required by modern privacy laws.
Hidden Risks and the “Scroll Fatigue” Tactic
The placement of serious risk disclosures was found to be strategically obscure. The Kenyan Office of the Data Protection Commissioner (ODPC) reported that information regarding the cross-border transfer of sensitive biometric data was buried at the very bottom of the “Worldcoin Foundation Biometric Data Consent Form.” To view this serious warning, a user would have to scroll past thousands of words of legal text on a mobile screen.
This design exploits “scroll fatigue,” ensuring that the vast majority of users never see the clauses regarding data sovereignty or third-party sharing. The South Korean PIPC specifically penalized Tools for Humanity (TFH) for failing to inform users about the specific countries where their data would be transferred, a detail that was omitted from the primary consent screens entirely.
The “No Exit” Interface: Deletion Friction
While onboarding was designed to be, offboarding was engineered with high friction, a classic “Roach Motel” dark pattern. The South Korean investigation revealed that for a significant period, the World App provided no direct method for users to request the deletion of their iris data. Users wishing to erase their biometric template were forced to navigate a labyrinthine support process or wait for an “un-verify” feature that was not implemented until April 2024, *after* the investigation had commenced.
| Action | Estimated Time (Seconds) | Clicks/Taps Required | Regulatory Finding |
|---|---|---|---|
| Sign Up (Iris Scan) | 45, 90 | 3, 4 | “Streamlined to induce rapid conversion” (Kenya ODPC) |
| Read Privacy Policy | 1, 200+ (Est.) | N/A (Scroll) | “Excessive length and complexity” (Hong Kong PCPD) |
| Delete Biometric Data | Undefined (Pre-2024) | No Direct Option | “Failure to provide deletion method” (South Korea PIPC) |
| Withdraw Consent | High Friction | Multiple Support Tickets | “Consent cannot be withdrawn” (Spain AEPD) |
“For a user to read and understand the risks of the transfer of personal sensitive personal data… they would have to scroll to the very end of the form. The consent method relied on by TFH were not inclusive, out of context and oblivious of Kenya’s socio-economic posture.”
, Office of the Data Protection Commissioner (ODPC), Kenya, Submission to High Court (2025)
Regulatory Corrective Actions
The cumulative effect of these findings forced World to overhaul its UX in late 2025. The “World ID 2. 0” update introduced mandatory “Personal Custody” by default, removing the option for server-side storage during signup. yet, regulators in Spain and Portugal maintained that these changes were reactive rather than proactive, arguing that the initial database of millions of users was built upon a foundation of deceptive design. The 1. 1 billion won fine in Seoul stands as a permanent record of the cost of these dark patterns, establishing a legal precedent that a “check box” does not constitute consent when the interface is designed to deceive.
Age Verification Mechanisms: Systemic Failure to Exclude Minors
Age Verification method: widespread Failure to Exclude Minors
The global regulatory backlash against World (formerly Worldcoin) in 2024 and 2025 was driven primarily by a single, widespread design flaw: the inability of the Orb infrastructure to reliably distinguish between adults and minors. While Tools for Humanity (TFH) maintained a nominal policy restricting access to individuals over 18, the technical implementation of this policy relied on self-attestation, a simple “tick box” within the World App, rather than verified identity checks. This friction-less onboarding process, designed to maximize user acquisition, created a direct pathway for the biometric harvesting of children, triggering emergency enforcement actions across Europe, Asia, and Africa.
The “Tick Box” Vulnerability
From its inception until early 2024, the primary barrier preventing a minor from scanning their irises was a software prompt asking the user to confirm they were of legal age. No physical ID was required at the Orb, and third-party operators, incentivized by commission per signup, had no structural mandate to verify age documents. This method failed catastrophically when confronted with the financial incentive of the WLD token. In jurisdictions with high youth unemployment or economic volatility, the prospect of immediate cryptocurrency grants drove minors to bypass the digital age gate. Regulatory investigations revealed that the Orb hardware itself absence any intrinsic age-gating capability, such as facial age estimation algorithms, at the time of the initial global rollout.
Iberian Enforcement: The Catalyst for Bans
The of this failure became undeniably public in March 2024, when data protection authorities in Spain and Portugal issued emergency orders stopping Worldcoin’s operations. The Spanish Data Protection Agency (AEPD) and the Portuguese National Data Protection Commission (CNPD) the processing of minors’ data as a “red line” violation of the GDPR. The CNPD’s investigation in Portugal was particularly damning. The regulator received dozens of specific complaints from parents stating their children had been scanned without consent. In its March 26, 2024 order, the CNPD noted there was “no method to verify the age of members,” rendering the consent obtained from minors legally void. The agency highlighted the impossibility of parents exercising their rights to delete this data, as the “iris code” was hashed and anonymized in a way that severed the link to the child’s identity, making specific deletion requests technically unfeasible without the child’s private key.
South Korea: The “Under 14” Verdict
The widespread nature of the failure was quantified by South Korea’s Personal Information Protection Commission (PIPC). Following a seven-month investigation, the PIPC issued a ruling on September 26, 2024, imposing fines totaling 1. 1 billion won (approximately $829, 000) on the Worldcoin Foundation and TFH. The PIPC’s findings were precise: TFH had failed to implement an age verification procedure for users under the age of 14 until April 2024. Under South Korean law, the collection of personal data from children under 14 requires explicit parental consent. The investigation confirmed that minors had successfully registered and had their biometric data transferred abroad without this consent. The commission’s corrective order mandated the immediate implementation of strong age verification systems, rejecting the previous self-attestation model as non-compliant.
Kenya: Admissions of “No Signed Contracts”
In the Global South, the exploitation of minors was compounded by the use of third-party marketing agencies. During testimony before the Kenyan Parliament’s Ad Hoc Committee in late 2023, the CEO of Sense Marketing, a firm contracted to run Orb operations, admitted to the “possibility” that minors were scanned. The executive revealed that agents were “scanning irises without any signed consensual agreements” and that the absence of clear guidelines from Worldcoin meant agents did not verify age documents. This testimony was pivotal in the High Court of Kenya’s May 5, 2025 judgment, which declared the data collection unlawful. The court found that the monetary inducement of WLD tokens vitiated the concept of “free consent,” particularly for school-age children who lined up in the thousands at the Kenyatta International Convention Centre.
Retroactive Fixes: World ID 2. 0 and Face Auth
Faced with existential regulatory threats, Tools for Humanity initiated a series of retroactive fixes in mid-2024.
- April 2024: The introduction of “in-person age verification,” requiring Orb operators to manually check IDs before allowing a scan. This turned third-party contractors into identity verifiers, a role were untrained to perform.
- September 2024: The rollout of “Face Auth,” a facial recognition feature designed to compare the user’s selfie against the Orb image. While touted as a security upgrade, privacy advocates noted this increased the biometric data load processed by the app.
- Unverified vs. Verified: A bifurcation of the user base, where unverified accounts (those who had not undergone the new checks) were restricted from claiming WLD grants, demonetizing the accounts held by minors who had already been scanned.
Data Retention and the Deletion Paradox
A serious unresolved problem remains the fate of the biometric data already collected from minors. Because the Worldcoin system was designed to be privacy-preserving via “zero-knowledge proofs,” the central database contains only hashed iris codes, not names or ages. Consequently, TFH cannot simply run a database query to “delete all users under 18.” Deletion relies on the minor (or their parent) possessing the original device and private key to initiate the request. If a minor deleted the app or lost access to their wallet, common occurrences among young users, their biometric hash remains permanently in the Worldcoin neural network, used to train the algorithm and prevent “duplicate” humans, with no administrative route for removal. This “deletion paradox” remains a primary citation in the ongoing enforcement actions by the Bavarian State Office for Data Protection Supervision (BayLDA) through late 2025.
| Jurisdiction | Authority | Key Finding | Action Taken |
|---|---|---|---|
| Portugal | CNPD | “No method to verify age”; inability for parents to revoke consent. | 90-day ban (March 2024) |
| Spain | AEPD | Collection of minors’ data as “red line” violation. | Precautionary Blockade (March 2024) |
| South Korea | PIPC | Failure to verify age for users under 14; no parental consent method. | 1. 1 Billion Won Fine (Sept 2024) |
| Kenya | High Court | Inducement via crypto tokens invalidated consent for minors. | Collection Ruled Unlawful (May 2025) |
“The report from CNPD is the time we are hearing from them regarding of these matters, including reports of underage sign-ups in Portugal, for which we have zero tolerance.”
, Jannick Preiwisch, Data Protection Officer, Worldcoin Foundation (March 2024)
Data Exfiltration Routes: Cayman Islands and Delaware Legal Loopholes
The Corporate Triad: A Jurisdictional Shell Game
The operational resilience of World (formerly Worldcoin) against global regulatory enforcement relies on a sophisticated corporate triad designed to fragment liability and obscure data custody. While the project markets itself as a decentralized protocol, its legal architecture is highly centralized around three specific jurisdictions: the Cayman Islands, Delaware, and the British Virgin Islands. This structure allows the entity to execute what regulators in Kenya and Hong Kong have characterized as unauthorized data transfer, exfiltration, while shielding its executives and assets from direct legal recourse.
At the core of this arrangement is the separation of technological development from data controllership. Tools for Humanity (TFH), the developer of the Orb and World App, is incorporated in Delaware. The World Foundation, which legally “owns” the protocol and acts as the data controller for all non-European users, is a “memberless” foundation registered in the Cayman Islands. A third entity, World Assets Limited, registered in the British Virgin Islands (BVI), manages the tokenomics and financial incentives. This tripartite division creates a legal labyrinth where data collected in jurisdictions like Nairobi or Seoul is contractually teleported to the Caribbean, bypassing local data sovereignty laws.
The Cayman Loophole: The Memberless Foundation
The World Foundation’s registration in the Cayman Islands is not a tax optimization strategy; it is a liability containment method. Under Cayman law, a “foundation company” can exist without members or shareholders, operating as an orphan entity. This structure was explicitly activated on July 24, 2023, when the Foundation assumed “controller” status for the project’s biometric data, relieving the US-based Tools for Humanity of direct GDPR liability for the protocol’s core operations.
For data subjects in the Global South, this structure creates a near- barrier to justice. As noted in the May 2025 High Court of Kenya judgment, the Worldcoin Foundation was not registered as a data controller within Kenya, yet it executed binding contracts with Kenyan citizens. The court found that the Foundation’s terms of service forced users to agree to dispute resolution in the Cayman Islands, a jurisdiction prohibitively expensive and legally inaccessible for the average user in a developing nation.
| Entity Name | Jurisdiction | Role | Strategic Function |
|---|---|---|---|
| World Foundation | Cayman Islands | Data Controller (Non-EU) | Absorbs regulatory heat; “Memberless” structure prevents shareholder lawsuits; holds the “Iris Hash” database. |
| Tools for Humanity Corp | Delaware, USA | Hardware/Software Developer | Operates the World App; shielded by Delaware corporate law; licenses tech to the Foundation. |
| World Assets Ltd | British Virgin Islands | Token Issuer | Manages WLD token grants; separates financial liability from data privacy liability. |
| Worldcoin Europe GmbH | Germany | Data Processor (EU) | GDPR compliance front; acts as a “processor” for the Cayman Foundation to claim EU adequacy. |
Delaware’s Section 102(b)(7): The Executive Shield
While the Cayman Islands holds the data, Delaware protects the people. Tools for Humanity (TFH) use specific amendments to Delaware General Corporation Law (DGCL) to insulate its high-profile executives, including CEO Alex Blania and co-founder Sam Altman. August 2022, Delaware amended Section 102(b)(7) to allow corporations to exculpate senior officers, not just directors, from personal liability for monetary damages resulting from breaches of the fiduciary duty of care.
This legal shield is serious given the aggressive nature of the project’s deployment. When the Hong Kong Privacy Commissioner for Personal Data (PCPD) raided Worldcoin’s six facilities in 2024, the enforcement action targeted the local operation. yet, the decision-makers in San Francisco remained insulated. Even if TFH officers were found to have been negligent in overseeing the compliance of their “Orb Operators,” Delaware law blocks shareholders from suing these officers personally for such oversight failures, provided they did not act in bad faith. This encourages a “move fast and break things” method to biometric data collection, as the personal financial risk to executives is legally nullified.
The Data Exfiltration Route
The term “exfiltration” is technically accurate when analyzing the data flow authorized by the World App’s terms of service. Upon scanning at an Orb, biometric data does not remain on the device or in the country of origin. Instead, it follows a specific route designed to strip it of local legal protections:
“The court finds that the transfer of Kenyan biometric data to servers in Germany and other countries without proof of equivalent data protection standards constituted a breach of Section 48 of the Data Protection Act. The entities involved, Cayman-registered Worldcoin Foundation and BVI-based World Assets Limited, were never registered as data controllers in Kenya.”
, High Court of Kenya, Constitutional Petition E001 of 2023 (Judgment delivered May 5, 2025)
The “other countries” mentioned in the Kenyan ruling refer to the US and the Cayman Islands. The data flow operates as follows:
- Collection: Independent “Orb Operators” (frequently third-party marketing agencies) collect iris scans on local soil.
- Transmission: The raw images are processed into an “Iris Code” (hash). While World claims raw images are deleted, the 2024 BayLDA audit revealed that during the “training phase,” raw data was frequently retained.
- Exfiltration: The Iris Code is uploaded to cloud servers (hosted by AWS and others) contracted by TFH legally controlled by the Cayman Foundation.
- Jurisdictional Shift: Once the data hits the cloud, it leaves the jurisdiction of the user (e. g., Kenya or South Korea) and enters the legal domain of the Cayman Islands, where the “Data Controller” resides.
This routing renders local “cease and desist” orders partially ineffective. By the time a regulator like Spain’s AEPD or Hong Kong’s PCPD problem a stop order, the biometric templates have already been exfiltrated to the Cayman jurisdiction. The only remedy available to regulators is to demand deletion, a demand that relies on the good faith of a memberless foundation operating in a tax haven known for corporate secrecy.
The December 2024 verdict by the Bavarian State Office for Data Protection Supervision (BayLDA) highlighted this vulnerability. The German regulator ordered the Foundation to erase iris codes collected via Worldcoin Europe GmbH. yet, because the Foundation is a separate legal entity in the Cayman Islands, enforcing this order required a complex legal maneuver where the German subsidiary was treated as the “establishment” of the Cayman entity, a tenuous link that World’s lawyers have continued to contest in appellate courts.
Right to Erasure: The Technical Impossibility of True Deletion
The Core Paradox: Sybil Resistance vs. The Right to Erasure
The central technical conflict defining World’s (formerly Worldcoin) regulatory struggle in 2025 and 2026 is a fundamental incompatibility between its core utility and global privacy laws: the impossibility of simultaneously guaranteeing “proof of personhood” and granting a true “Right to Erasure” (GDPR Article 17). To function as a Sybil-resistant identity, the network must permanently retain a record of every registered iris to prevent duplicate sign-ups. Conversely, to comply with data protection mandates, it must be able to permanently destroy all records of a user upon request. These two objectives are mutually exclusive.
Regulators across multiple jurisdictions, including the Bavarian State Office for Data Protection Supervision (BayLDA) and the Portuguese National Data Protection Commission (CNPD), have dismantled World’s defense that the “Iris Code”, a numerical representation of the iris texture, is non-personal data. By late 2024, the consensus among European and Asian data authorities was that the Iris Code constitutes sensitive biometric data because it is unique, immutable, and chance reversible. Consequently, the retention of this code for “uniqueness checks” violates the absolute right to deletion.
The “Iris Code” Defense and Reversibility
World’s primary defense against data retention charges has historically been the “hashing” argument. The company claimed that the Orb device processes the iris image locally, converts it into a unidirectional cryptographic hash (the Iris Code), and permanently deletes the raw biometric imagery. Under this model, World argued it did not hold “personal data” rather a mathematical abstraction.
This defense collapsed under technical scrutiny in 2024 and 2025. Security audits and regulatory investigations revealed that Iris Codes are not standard cryptographic hashes like SHA-256, which are designed to be irreversible and sensitive to single-bit changes. Instead, they are “fuzzy hashes” (Locality-Sensitive Hashing) designed to tolerate slight variations ing, angle, and biological changes. This fuzziness, necessary for matching a user’s eye over time, inherently retains enough biological structure to be chance reversible or linked back to a specific individual if combined with other data points.
“The ‘Iris Code’ is personal data that can never be erased [under World’s current model], in breach of the right to erasure under Article 17 of the GDPR.”
, Portuguese National Data Protection Commission (CNPD), March 2024 Ruling
The “Personal Custody” Pivot
In March 2024, responding to mounting regulatory pressure, Tools for Humanity (TFH) introduced “Personal Custody.” This architectural shift moved the storage of the raw iris images and metadata from centralized servers to the user’s personal device (smartphone), encrypted with a user-controlled key. The backend would only receive the encrypted data package for verification.
While this addressed concerns regarding the raw image storage, it failed to resolve the retention of the Iris Code in the global uniqueness database. To verify that a user has not already signed up, the network must still compare the incoming Iris Code against the entire database of existing codes. If a user “deletes” their data from their phone, the global database must still retain their Iris Code (or a cryptographic derivative via Secure Multi-Party Computation) to block them from re-registering. If the system truly deleted the Iris Code from the uniqueness set, the user could simply wipe their phone, walk to an Orb, and register again, destroying the “one person, one ID” premise.
The “Unverify” method and the 6-Month Tombstone
In April 2024, World introduced the “Unverify” option, allowing users to request the deletion of their World ID. yet, the mechanics of this process revealed the persistence of data retention. Upon requesting deletion, the user’s Iris Code is not immediately scrubbed. Instead, it enters a “cool-off” period, initially set at six months, during which the ID is invalid, the biometric marker remains in the system to prevent immediate fraud.
Regulators in Hong Kong and Germany flagged this “tombstone” data retention as a violation of the principle of immediate erasure. The Hong Kong Privacy Commissioner for Personal Data (PCPD), in its May 2024 enforcement notice, explicitly criticized the retention period (originally up to 10 years for AI training) as “excessive.” Even the reduced 6-month window implies that for half a year, a user who has withdrawn consent remains biometrically cataloged in the system against their.
Secure Multi-Party Computation (SMPC) and Data Fragmentation
To obscure the Iris Codes, World implemented Secure Multi-Party Computation (SMPC). This protocol splits the Iris Code into multiple “shares” distributed across different servers (held by distinct entities like universities or third-party validators). No single entity holds the complete Iris Code. Theoretically, this prevents any one party from reconstructing the biometric template.
yet, the Colombian Superintendence of Industry and Commerce (SIC) noted in its October 2025 ban that this protocol was not disclosed to users until late 2024, even with being operational earlier. also, from a data rights perspective, fragmentation does not equal deletion. If the shares exist and can be computed to perform a uniqueness check, the biometric data. The “Right to Erasure” requires the destruction of the data, not its obfuscation across multiple servers.
Verified Deletion Orders: 2025-2026
By 2025, the theoretical debate shifted to executive enforcement. Courts and data protection authorities began issuing orders not just to stop collection, to physically purge existing databases.
| Jurisdiction | Authority | Date of Order | Requirement | Status (as of Q1 2026) |
|---|---|---|---|---|
| Kenya | High Court | May 5, 2025 | Complete erasure of all biometric data collected since 2023. | Deleted (Confirmed by ODPC Jan 2026) |
| Germany | BayLDA | Dec 19, 2024 | Implementation of GDPR-compliant deletion protocol by Jan 19, 2025. | Under Appeal / Partial Compliance |
| Hong Kong | PCPD | May 22, 2024 | Cessation of scanning and deletion of existing project data. | Enforced (Operations Ceased) |
| Chile | Supreme Court | Feb 3, 2025 | Deletion of specific minor’s data; precedent for broader erasure. | Enforced |
| Spain | AEPD / High Court | Mar 2024 / Jan 2025 | Precautionary blockade converted to permanent deletion mandate. | Enforced |
The execution of the Kenyan High Court order in January 2026 was particularly significant. The Office of the Data Protection Commissioner (ODPC) supervised the destruction of the data, marking one of the instances where a sovereign state successfully forced a decentralized identity protocol to physically wipe its biometric ledger for a specific national population. This action proved that while the global blockchain may be immutable, the local biometric on-ramps and the databases linking irises to IDs are to sovereign enforcement.
2026 Global Status: The Fragmentation of the World ID Network
The Great: A Hemispheric Split
By early 2026, the World ID network functions as a “Splinternet” of biometric data. The dream of a universal, borderless “Proof of Personhood” has collided with the hard reality of data sovereignty. * **The Red Zones (Blocked/Suspended):** The European Union (led by Germany and Spain), Brazil, Kenya, Hong Kong, South Korea, and Indonesia. In these jurisdictions, Orb operations are either explicitly banned, indefinitely suspended, or suffocated by compliance orders that make the business model untenable. * **The Green Zones (Active/Expanding):** Argentina, Chile, Colombia, Mexico, Malaysia, Singapore, and Japan. Here, Tools for Humanity (TFH) has aggressively consolidated its presence, frequently pivoting to markets where economic volatility drives crypto adoption faster than regulators can draft privacy frameworks.
Latin America: The ” Argentina” Strategy
Following the regulatory collapse in Europe, TFH executed a strategic pivot to Latin America in mid-2024, designating Argentina as its new “regional operations center.” By 2025, Argentina had become the single largest market for World ID verification, driven by triple-digit inflation and a populace accustomed to seeking alternative financial rails. yet, this sanctuary is shrinking. On **January 25, 2025**, Brazil’s National Data Protection Authority (ANPD) issued a blanket ban on World’s operations. The ANPD’s investigation, concluded in late 2024, found that the “free” WLD tokens constituted a coercive method that vitiated the concept of “freely given consent” under Brazil’s LGPD (General Data Protection Law). The order imposed daily fines of **50, 000 Brazilian reais** ($8, 800) for non-compliance, shutting the door on Latin America’s largest economy.
Asia: The Malaysian and the Indonesian Wall
The Asian market reflects the same fragmented reality. In **August 2024**, TFH secured a serious victory by signing a Memorandum of Understanding (MoU) with the Malaysian government. This partnership allowed for the integration of World Chain with Malaysia’s national blockchain infrastructure, creating a state-sanctioned corridor for biometric data that stands in clear contrast to the hostility in neighboring jurisdictions. Conversely, **Indonesia** moved to the network’s operations in **May 2025**. The Ministry of Communication and Digital Affairs (Komdigi) suspended World’s operating permit, citing violations of electronic system regulations and the “unnecessary and excessive” collection of iris data. This action followed the pattern set by **Hong Kong’s PCPD** in May 2024 and **South Korea’s PIPC** in September 2024, leaving Malaysia and Singapore as the primary surviving nodes in the Southeast Asian network.
The African Withdrawal: Post-Nairobi
The High Court of Kenya’s judgment on **May 5, 2025**, served as the final verdict on the company’s African ambitions for the reporting period. The court declared the collection of biometric data from Kenyan citizens “unlawful” and ordered the deletion of all data collected prior to the suspension. This ruling did not just halt operations; it delegitimized the core method of “retroactive compliance” that TFH had attempted to use. By late 2025, World had ceased active recruitment in the region, retreating to a defensive legal posture.
2025-2026 Operational Metrics
Even with these geopolitical headwinds, the network’s growth in permissive markets has been substantial.
| Metric | Data Point (Verified) | Context |
|---|---|---|
| Verified Users | 15 Million (Sept 2025) | Concentrated heavily in Argentina, Chile, and Japan. |
| Token Price (WLD) | ~$1. 40 USD (Jan 2026) | Recovered from an all-time low of $0. 58 in April 2025. |
| Active Orbs | ~2, 800 | Down from peak deployment; redeployed from EU to LatAm/Asia. |
| Major Bans (2025) | Brazil (Jan), Indonesia (May) | Cumulative loss of access to ~480 million people. |
Technological Pivot: World ID 3. 0
Recognizing the regulatory ceiling for biometric hardware, TFH launched **World ID 3. 0** in October 2024. This update introduced “World ID Credentials,” a method allowing users to verify their humanness using government-issued NFC passports rather than the Orb. This “soft verification” tier was a direct response to the European and American blockades, attempting to maintain a foothold in regions where the Orb is legally radioactive. yet, these non-biometric credentials do not grant the same “Proof of Personhood” status on the blockchain, creating a two-tiered class system within the user base.
Conclusion: The Cat and Mouse Game Continues
As of March 2026, the World network has survived its “existential emergency” has been fundamentally reshaped. It is no longer a global monolith a nimble, opportunistic entity that flows like water into jurisdictions with the lowest regulatory resistance. The “fragmentation” is not a bug a survival feature; when one market closes (Brazil), the Orbs are simply crated and shipped to the (Malaysia). The data shows a clear trend: privacy enforcement in 2025 did not kill the project, it successfully contained it. The “World” that exists today is a shadow of the universal utility promised in 2023, operating primarily in the margins of the global financial system rather than at its center.


































