Privacy for Profit: Why Biometric Incentives Deserve Scrutiny (World App Controversy)
Privacy for Profit: Why Biometric Incentives Deserve Scrutiny (World App Controversy)
Cybersecurity Insights

By Patricia A. Pramono • Studio 1080, Published on May 21, 2025

SHARE THIS ARTICLE

In recent weeks, the World App, part of the broader Worldcoin ecosystem, has gone viral. The reason? Its offer of IDR 800,000 in crypto for anyone willing to undergo a biometric eye scan using a device called the Orb.

While the offer may appear harmless (just a few seconds of scanning in exchange for digital currency) it raises a critical question: are we underestimating the value of our biometric data?

Understanding World App, World ID, and Worldcoin

World App is the official digital wallet developed by Tools for Humanity (TFH), the same company behind Worldcoin. Co-founded by Sam Altman, CEO of OpenAI, TFH promotes World App as a solution to verify that users are real humans and not bots in the age of generative AI and deepfakes.

To create a World ID, users must undergo iris scanning via the Orb, a metallic sphere equipped with high-resolution cameras and sensors. Upon successful verification, users receive Worldcoin (WLD), a cryptocurrency that can be stored and managed within the World App.

According to the project’s official communications, this digital identity system is designed to be secure, private, and anonymized using cryptographic methods such as zero-knowledge proofs. The company claims that biometric data is not stored permanently and remains local to the Orb device, which will eventually be wiped.

However, the volume and sensitivity of the data collected (from eye scans to facial and body images, even to vital signs such as heartbeat) have sparked growing concerns across multiple countries.

Data Privacy Concerns and Global Backlash

Biometric data is permanent, unique, and cannot be changed, unlike passwords or PIN codes. A breach of such information could lead to identity theft, surveillance misuse, or long-term privacy violations.

Despite assurances from Worldcoin, according to Channel News Asia, several countries have taken regulatory action:

  • Kenya suspended the project and ordered the deletion of iris scan data collected from its citizens, citing legal and ethical concerns.
  • Spain and Portugal also halted Worldcoin’s operations, highlighting gaps in data protection especially involving minors.
  • Hong Kong issued a cease order after determining the collection of facial and iris data violated privacy laws.

In Indonesia, the Ministry of Communication and Digital (Kominfo) has responded by freezing World App’s operations as a preventive measure, citing concerns over unregistered local operators and potential legal violations. According to official statements, PT Terang Bulan Abadi (believed to be the local facilitator) was not registered under the country’s Electronic System Provider (PSE) database, raising further red flags regarding compliance and oversight .

The Risks of Biometric Trade-Offs

Cybersecurity and artificial intelligence experts warn that biometric data (especially iris and retina scans) represents one of the most sensitive forms of personal information.

As noted by Adila Alfa Krisnadhi, an AI expert from Universitas Indonesia, the long-term consequences of biometric leaks can be far-reaching:

“Unlike passwords, biometric identifiers cannot be changed. If compromised, they pose a lifetime security risk,” she stated in an interview with Investor.id.

Beyond the technical risks, there is also a wider ethical implication: who owns this data, and how will it be used in the future?

Worldcoin claims to use a secure system called Secure Multi-Party Computation (SMPC) that encrypts iris codes and splits them across various storage locations to prevent single-point access. However, these processes remain unclear to most users and lack independent verification or third-party audits.

Our Public Awareness Is At A Critical Weakness

What this controversy truly highlights is a broader issue: the low level of public awareness around digital privacy and data protection.

In the face of financial incentives many individuals are willing to trade away sensitive data without understanding the risks. This phenomenon underscores the urgent need for public education on data privacy, particularly in regions where regulatory frameworks are still maturing.

While innovation in digital identity and decentralized finance continues to accelerate, ethical implementation and informed consent must not be sidelined. Any system that collects, stores, or utilizes biometric data must uphold the highest standards of transparency, security, and user protection.

Conclusion

Worldcoin’s vision of a human-centric blockchain economy may hold merit in theory. But its implementation reveals glaring concerns about governance, consent, and control of one’s own identity.

As cybersecurity professionals, policymakers, and users, we must ask:

  • Who owns our data once it’s scanned?
  • How do we verify that deletion claims are followed?
  • What protections exist if misuse occurs years later?


In today’s digital economy, our data is our identity and our currency. We must treat it with the seriousness it deserves.

For more insights on online safety, cybersecurity tips, and scam awareness, follow Cisometric on social media and stay updated on the latest threats. Together, we can build a safer digital environment in Indonesia.

Follow us on:

LinkedIn: Cisometric

Instagram: @cisometric

Youtube: Cisometric



Reference: 

Mengenal Aplikasi World App yang Bayar Rp800.000 untuk Scan Retina, Amankah Data Anda?

Indonesia suspends eye-scanning Worldcoin crypto project

Apa itu Worldcoin dari World App, serta apa risikonya?

Waspada, Ada Potensi Bahaya di Balik Scan Retina Aplikasi World App

You may like this...

Cybersecurity Insights
Inside Trump’s Cyber Blunder: How a Wrong Chat Turned Into a National Security Mess

Inside Trump’s Cyber Blunder: How a Wrong Chat Turned Into a National Security Mess

The incident now referred to as SignalGate began with what appeared to be a routine coordination effort among top-ranking U.S. government officials. A Signal group chat, titled “Houthi PC small group,” was created by a staff member

Read More
Cybersecurity Insights
 Indonesia Ranks 2nd with the Most Spam Calls in Asia Pacific

Indonesia Ranks 2nd with the Most Spam Calls in Asia Pacific

The data in GoodStats’ report is based on insights from the Hiya Global Call Threat Report Q1 2025, which recorded a shocking 12.5 billion suspected spam calls globally in just the first quarter of the year, which is equivalent to 137 million unwanted calls per day.

Read More
Industry Updates
16 Billion Passwords Just Leaked: Here’s What You Need to Know and Do

16 Billion Passwords Just Leaked: Here’s What You Need to Know and Do

In June 2025, Bob Diachenko, a Cybernews contributor, cybersecurity researcher, and owner of SecurityDiscovery.com, confirmed the existence of 30 exposed datasets, each containing tens of millions to billions of login records. Combined, these datasets account for 16 billion credentials, making it potentially the largest aggregated leak ever observed.

Read More
Cybersecurity Insights
Juice Jacking: How Public Chargers Can Steal Your Data

Juice Jacking: How Public Chargers Can Steal Your Data

Our devices have become more than communication tools. They now hold access to our finances, personal records, work documents, photos, and even health information. This level of connectivity makes our lives easier, but it also makes our devices attractive targets.

Read More
Industry Updates
Tariff Trade: Our Personal Information as a Trade Offer?

Tariff Trade: Our Personal Information as a Trade Offer?

Because in this era of AI, algorithmic profiling, and platform-driven everything, personal data is no longer just metadata, it’s also behavioral insight, political targeting, digital identity, and economic leverage.

Read More

Search Article by Category