The EU aims to ensure that all its citizens can travel to the U.S. without a visa, according to a briefing note from the European Parliamentary Research Service (EPRS), published on Monday. As the Service notes, at this stage, Cyprus, along with Bulgaria and Romania, remains outside the U.S. Visa Waiver Program, in which the other EU member states participate.
In this context, on July 23, 2026, the European Commission concluded negotiations with the U.S. on aframework agreement on enhanced cooperation in border security, which provides for the exchange of personal data, including biometric data. The agreement aims to maintain visa-free travel for citizens of member states that already participate in the U.S. program. It should be noted that the agreement requires the consent of the European Parliament and the approval of the Council of the EU.
The framework agreement will set out the conditions under which Member States may negotiate bilateral agreements with the U.S. for the exchange of information from their national databases. Each member state will decide which databases and which categories of information to include in the exchange. The framework will apply to EU member states, with the exception of Ireland and Denmark.
Exchange of Biometric Data
The U.S. has set a deadline of December 31, 2026, for the conclusion of the relevant agreements, requesting access to information held in national databases, including biometric data such as fingerprints.
According to the EPRS, U.S. authorities seek to use the information to screen and verify the identity of travelers, those seeking immigration or humanitarian protection, as well as other individuals screened as part of border procedures and the enforcement of immigration laws.
The agreed framework provides that the initial search for information may be conducted automatically, provided that the principles of necessity and proportionality are respected. In the event of a match between databases, it will be possible to submit a request for additional information, which must be reviewed by a competent person and not exclusively through an automated process.
Restrictions are also provided for on the transfer of sensitive personal data, which may be exchanged only if they are linked to a serious and genuine threat to public security or public order. The information received should be retained only for as long as necessary, with the retention period reviewed at least once a year.
Source: KYPE