EU-made facial recognition ended up scanning schoolchildren in Brazil
In August 2019, the Swedish Data Protection Authority fined a school board that had piloted a facial-recognition attendance system for 22 students over three weeks. (Source: Investigate Europe)

Investigations

EU-made facial recognition ended up scanning schoolchildren in Brazil

By Nico Schmidt⁩ and Leonardo Coelho,
Berlin/Rio de Janeiro
,

When the European Union agreed its landmark AI Act in December 2023, Commission president Ursula von der Leyen declared it a “historic moment”, saying the legislation “transposes European values to a new era.” Since then, the EU has positioned itself as the global standard-setter for trustworthy AI.

At the AI Action Summit in Paris in February 2025, von der Leyen pledged that Europe would “spare no effort to make Europe an AI continent,” insisting that safety and innovation must go hand in hand. 

But European AI regulations have a blind spot. While they strictly regulate certain AI uses within Europe, including biometric surveillance, they contain no provisions to monitor or restrict the export of the same technologies beyond the EU’s borders.

That gap is not hypothetical. It is already being exploited.

In the southern Brazilian state of Paraná, close to one million schoolchildren are identified each day by a facial-recognition system developed by a European company.

Since 2023, the technology has been deployed in more than 1,700 public schools. A teacher opens an app, photographs the classroom, and within seconds, a cloud-based algorithm detects each student’s face and compares it against a biometric database. Students identified are marked present; those that the system does not find are marked absent.

The recognition algorithm was developed by Innovatrics, a Slovak company headquartered in Bratislava, with an annual turnover of more than €23m.

According to the company, its technologies have processed biometric data from more than one billion people in over 80 countries. Innovatrics has also received close to €200,000 in EU public funding for a research project focused on the automated analysis and classification of photographs using facial biometrics.

Blocked in Europe

Comparable uses of facial recognition in European schools have been blocked by courts and regulators in multiple instances. In August 2019, the Swedish Data Protection Authority fined a school board that had piloted a facial-recognition attendance system for 22 students over three weeks.

The regulator ruled that the experiment violated the GDPR, finding it disproportionate and excessively intrusive. Schoolchildren, the authority emphasised, cannot freely consent to surveillance technologies in the classroom.

In February 2020, an administrative court in Marseille reached a similar conclusion, halting pilot projects at high schools in Nice and Marseille.

The judges found the consent obtained from students invalid given the power imbalance between schools and minors, and ruled that the biometric system was disproportionate given that alternatives like badge-based entry were available.

The EU’s AI Act, adopted in 2024, has since moved to regulate such technologies. While not outright prohibited, the deployment of biometric surveillance in schools is strictly regulated.

But the legislation does not extend to monitoring the export of these technologies beyond Europe’s borders.

(Source: Investigate Europe)

The export gap

During the AI Act negotiations, the European Parliament argued for a ban on certain exports.

Its official position stated that “it is appropriate to prohibit the export” of systems classified as “unacceptable” under the AI Act. But the proposal found little support among the other EU institutions and was dropped from the final law.

“The absence of such measures means that technologies banned here might still be sold and deployed elsewhere, undermining our values,” said Brendo Benifei, an Italian socialist MEP who supported the ban. “We should not allow the export and use abroad of systems we would not permit at home.”

Caitlin Bishop, who coordinates work on surveillance technologies at Privacy International, called the situation “noxious.”

The absence of any export controls has created “not a good situation,” she said, which allows “deeply invasive technology” to be sold internationally by European companies.

Errors, welfare risks, and a legal challenge

In Brazil, the system’s deployment has raised serious concerns. Teachers told Investigate Europe that the algorithm often takes longer than manual attendance and that identification errors are common.

An independent study published in 2025 by researchers at São Paulo State University found the system achieved an average accuracy of 91.1 per cent – below the 95 per cent threshold specified in the procurement contract.

A survey by APP-Sindicato, a union representing more than 65,000 teachers, found that eight out of ten educators considered the system less effective than traditional roll call.

The errors take on particular weight because eligibility for Bolsa Família, Brazil’s main welfare programme, depends partly on school attendance. In Paraná, those records are now largely generated by the facial-recognition system. Investigate Europe found no confirmed case in which a false absence led directly to suspended payments. But teachers have warned that the risk is real.

Paraná’s secretary of education said that use of the facial-recognition system is optional for teachers, who would manually verify the list of students present and could make corrections in cases where the system fails to identify them. Students can also opt-out using the system “without any prejudice” if requested. Technical failures, the secretariat said, do not automatically result in a student being marked absent, and do not directly affect eligibility for social welfare programs.

In April 2025, public prosecutor Marcos José Porto Soares filed the first legal challenge, arguing the system violates Brazilian data protection law.

Among the issues was consent: Investigate Europe confirmed with Paraná’s education secretariat that an earlier version of the enrolment form did not allow parents to refuse the use of their children’s images. A judge initially denied a request to suspend the system; the case remains pending.

(Source: Investigate Europe)

Spreading beyond Paraná

Despite the legal proceedings, Paraná extended its contract through September 2026. According to the research organisation InternetLab, seven of Brazil’s 27 states are now using facial-recognition technology in schools.

The technology has also begun to travel back toward Europe. In 2024, the government of Paraná announced that its system had been exported to Portugal, where it was tested at United Lisbon International School. When contacted, the school’s owner stated: “The school does not use this tool.”

Following questions from Investigate Europe, the Portuguese data protection authority announced it would launch an official investigation.

Paraná’s secretary of education said the system complies with Brazil’s data protection law. It also informed that “prior to the implementation of the solution, Data Protection Impact Assessment was prepared.” Regarding the on-going trial, the Secretary stated “the case is still under judicial review and, so far, there has been no court decision.”

This story was produced in partnership with the Pulitzer Center’s AI Accountability Network.

Additional reporting: Paulo Pena

This investigative project was led by Investigate Europe. It is being published globally with media partners Tech Policy Press (USA), Núcleo (Brazil), Público (Portugal), EUobserver (Belgium) and Denník N (Slovakia).

In August 2019, the Swedish Data Protection Authority fined a school board that had piloted a facial-recognition attendance system for 22 students over three weeks. (Source: Investigate Europe)