
An analysis by IT security experts at Mint Secure GmbH shows that, since 1 May, the two leading German providers of e-passport photos have been storing biometric passport photos in the AWS cloud and are thus presumably operating in a grey area of the new Identity Card Regulation (PAuswV). It is foreseeable that millions of biometric passport photos will be stored with a US provider in this way. Furthermore, there are critical vulnerabilities in the open-source solutions used, as well as further challenges in the area of data protection.
Important: The information presented in this article was gathered immediately following the changeover on 1 May (the first weekend in May) and is supplemented by updates and feedback from the relevant authorities at the end of the article. Furthermore, the providers mentioned are not yet included in the list of certified providers – yet they are apparently already accepting biometric photographs.
From 1 May 2025, under the new Identity Card Regulation (PAuswV), biometric passport photographs for applications for identity cards, passports or residence permits – paper passport photos will only be accepted in exceptional cases and have thus (at least in this context) become obsolete.
But how secure are the procedures being used? How are issues of data protection, IT security and digital sovereignty being addressed? What are the specific consequences of this changeover? The procedures and providers of such solutions have so far lacked transparency – reason enough to take a closer look at this from both a technical and a data protection perspective.
Legal Basis (GDPR & PAuswV)
Biometric passport photographs fall within the special categories of personal data pursuant to Article 9 of the GDPR, as they constitute biometric data used to uniquely identify a person. This means they require special protection, and correspondingly comprehensive technical and organisational measures (TOMs) must be put in place. Furthermore, a data protection impact assessment should be carried out in accordance with Article 35 of the EU GDPR (as biometric images are presumed to pose a high risk to data subjects).
Section 5a ‘Production and transmission of the photograph using a secure procedure’ of the PAuswV (Chapter 2) describes two permissible methods for transmitting the digital passport photograph:
-
the transmission of the photograph to the identity card authority by a service provider using a cloud provider, or
-
the transmission of the photograph to the identity card authority from a service provider’s certified photographic capture device, which is directly connected to the identity card authority’s network.
The second method is carried out on devices provided by the Bundesdruckerei at the passport or identity card authority’s premises and, according to the present analysis, can be implemented in a way that is more data-protection-friendly and better safeguards fundamental rights. This article examines in depth only the first procedure (i.e. the use of cloud service providers for transmission to authorities).
Providers and technical policies
The two largest cloud providers for e-passport photos are:
- Ringfoto, trading under the brand name ‘alfo-Passbild’ (RINGFOTO GmbH & Co. KG), link
- dm (dm-drogerie markt GmbH + Co. KG), link
Both providers appear to be seeking certification of their cloud components in accordance with BSI’s TR-03170 – although this has not yet been formally noted on their websites.
With the technical policy TR-03170, the BSI has produced a series of documents on the topic, which are linked below:
- BSI TR-03170 Secure digital transmission of biometric photographs from service providers to passport, identity card and immigration authorities – Framework TR, Version 1.2
- BSI TR-03170 Secure digital transmission of biometric photographs by service providers to passport, identity card and immigration authorities – Part 1 – Requirements for the cloud service, Version 1.2
- BSI TR-03170 Secure digital transmission of biometric photographs by service providers to passport, identity card and immigration authorities – Part 2 – Requirements for the software, Version 1.2
- BSI TR-03170 Interface Specification (v1.0.2)
- BSI TR-03170 Test Specification (v1.2)
In the context of this analysis, the document ‘Part 1 – Requirements for the cloud service’ and the ‘Test specification (v1.2)’ are particularly relevant. Furthermore, the documents are extremely helpful in understanding exactly how the processes are intended to work.
‘Intermediate clouds’ & overall procedure
Reports on this topic have often stated that biometric images are transmitted directly to public authorities; however, this is incorrect – as, prior to transmission to a public authority (for example, to issue a new identity document), the images are stored in a kind of ‘intermediate cloud’ operated by the service provider. There, the biometric photos are stored in encrypted form; the idea is that the key is contained exclusively in the Data Matrix code which citizens bring with them to the authorities. Only then are the data retrieved and subjected to decryption, and the biometric passport photo used.
The following diagram from the BSI’s Technical Policy 03170 illustrates how the overall process is intended to work:

Self-test & investigation on the first weekend in May
To gain a deeper technical insight into the IT systems in use, security experts from Mint Secure GmbH took a closer look at the two providers over the first weekend in May – shortly after the systems went live – by simply having passport photos taken of themselves. After visiting a number of photographers (some of whom were unable to provide a photo using the new procedure as they did not yet have the latest software), the relevant dm codes (Data Matrix ECC 200 in accordance with ISO/IEC 16022) were obtained.

The information stored in the Data Matrix is base64-encoded (in accordance with TR-03170, see p. 7). Once decoded, the URL, ID and the associated symmetric key can be extracted.

Analysis of the Data Matrix codes revealed the following URLs for the providers:
- Ringfoto / “alfo-passbild”:
image-download.prod.imagesign.link - dm (Drogerie-Markt):
d.biometric-photos-prod.aws.dmtech.cloud
The strength of the transport encryption on the providers’ systems was tested (using testssl.sh & ssllabs.com).
ssllabs.com test result for image-download.prod.imagesign.link
ssllabs.com test result for d.biometric-photos-prod.aws.dmtech.cloud
Initially, the ‘T’ rating for both solutions was surprising.

However, this can be attributed to the use of a private PKI (belonging to the federal government), which is not trusted by standard browsers. Presumably, when the software is installed by the authorities, the relevant certificates are used to enable secure TLS encryption. Otherwise, the TLS encryption rating on SSL Labs would have been classified as ‘B’ and would have met the level of protection set out in the technical policy mentioned above.
In addition to the result, it is also apparent that the relevant servers (from both providers) are presumably operated within the AWS cloud (presumably the Frankfurt region). This was also confirmed by further investigations. On their websites, the providers refer exclusively to a “secure dm cloud” or “C5 high-security cloud” and do not mention AWS.

Data protection and digital sovereignty: challenges with AWS cloud systems
As the analysis revealed, both solutions rely on Amazon Web Services (AWS) and store the relevant biometric passport photographs there (using symmetric encryption).
Section 5b of the Act, entitled ‘Transmission of the photograph with the involvement of a cloud provider’, states:
‘(4) The processing of personal data may only be carried out by a cloud provider established within the territory of the European Union and exclusively within the territory of the European Union.’
If one examines this sentence closely, it gives pause for thought: are encrypted biometric passport photographs considered personal data? Is AWS a cloud provider established within the European Union? What did the drafters of the Act actually mean by this paragraph?
A few conclusions can be drawn, or considerations made:
“Personal data”: It is legally disputed whether an encrypted biometric image must be classified as “personal data”. It would only cease to be personally identifiable if it were no longer possible to draw any conclusions about the identifiable natural person (see Article 4(1) of the GDPR). Even encrypted data remains personal data as long as it can, in principle, be attributed to a person; for example, if there is a way to decrypt it (in this case, however – according to the idea – this would only be possible via the dm code). It is also conceivable that inferences could be drawn from other information (e.g. the time, the branch, the employees processing the transaction, or an order number, which is available at dm, at least). Only the operators know whether such inferences are possible. However, it does not appear possible to rule them out entirely.
In order to carry out a more detailed data protection assessment of this matter, it is worth first considering whether AWS is established in the EU: AWS Europe (AWS EMEA SARL) is a registered company with its registered office in Luxembourg (EU), thus largely fulfilling the criterion of being established in the EU under Section 5b. However, AWS is a subsidiary of the US parent company (Amazon.com, Inc.), which is relevant under data protection law because group affiliations exist. Even if data is physically stored only within the EU, it is possible that AWS staff from the US (or elsewhere in the world) could access it (for example, for support or maintenance). This would constitute a data transfer to a third country (e.g. the USA); even if the data is not physically moved, this could conflict with the aforementioned law.
Furthermore, the CLOUD Act (Clarifying Lawful Overseas Use of Data Act), which came into force in 2018, a powerful piece of legislation that obliges American internet companies and IT service providers to grant US authorities access to stored data, even if the data is not stored in the US.
Finally, one might argue that the biometric passport photographs are encrypted and therefore pose no risk. However, encryption is always only a temporary safeguard. From an intelligence perspective, it seems plausible and feasible that intelligence agencies might have an interest in storing the encrypted biometric passport photographs in order to decrypt them in a few decades’ time (for example, once powerful quantum computers become available). Ultimately, this would provide biometric information on virtually every person in Germany.
From the perspective of digital sovereignty (a term that is difficult to define in any case), the use of the AWS cloud also gives cause for concern. This is because, in the event of a failure in the AWS region, the relevant authorities would initially be unable to retrieve any photos – which would certainly not be truly sovereign. It remains unclear why both providers opted for AWS as their service provider, and why the TR-03170 does not stipulate even more explicitly that US providers, for example, should not be used.
Other specialist articles by data protection experts reach similar conclusions, even when data in the cloud is subject to encryption: there is no true digital sovereignty with US clouds!
Kuketz Blog
It can be concluded that, even though providers currently refer on their websites and in press releases to a “C5 high-security cloud” or “certified dm-Cloud”, ultimately, vast quantities of encrypted biometric passport images (presumably containing further data that may allow conclusions to be drawn) will be stored in the AWS cloud in future.
For the reasons outlined above, this can and should be regarded as problematic.
Employee data and the treatment of employees
In addition to citizens’ data (primarily the biometric passport photograph), there is another group of data subjects in the context of data protection that is relevant to this analysis: employees in photography studios or dm drugstores.
This is because the regulation stipulates that every single upload must be signed using an identity card. This apparently serves the protective aim of traceability (it makes it possible to trace who took which photo and when). This has met with some resentment amongst dm employees; according to media reports, dm has (or has been) attempting to persuade employees to activate the eID function on their identity cards by offering them a €40 voucher.
This approach is problematic from several perspectives:
- For years, Section 10(1) of the Identity Cards Act (PAuswG) stipulated that the activation of the eID function should be voluntary and that there was no obligation to activate it. This was amended by a change to the law on 18 May 2017. Since then, the eID function has been activated by default on all identity cards issued to people aged 16 and over and can no longer be deactivated. Nevertheless, there may still be people with older identity cards.
- This could also be a sensitive issue under employment law, as it is questionable whether an employer is permitted to suddenly ‘compel’ an employee to use their identity card and its eID function (as well as the processing of the data in systems). Most recently, dm has emphasised the voluntary nature of this requirement.
Ultimately, however, dm and any other service providers find themselves ‘caught between a rock and a hard place’, as the PAuswV clearly stipulates that proof of identity must be provided with every upload.
In addition to the aforementioned encrypted, biometric passport photos, it is likely that employee data is also stored in the AWS cloud. The employees concerned must be fully informed about what happens to their data or be able to make enquiries about it (including the right of access under Article 15 of the GDPR, etc.).
Biometric verification
Another significant ‘black box’ is the verification against biometric rules; under the Regulation and the TR, it is stipulated that images must be checked for biometric characteristics in accordance with TR-03121 before upload (otherwise, uploads are generally not permitted in the first place). It is unclear whether the check takes place on the end devices used to take the photo (locally) or whether another service provider receives the data via upload.
At dm, employees’ smartphones with a special app are usually used for biometric passport photos: the photo is first transferred to a photo terminal in the branch and then uploaded to the cloud.
There is currently little or no information available on the providers’ websites regarding this procedure and data protection within the process. Overall, any potential need for information is not adequately addressed (dm has an FAQ section that describes the topics to some extent, whilst the Ringfoto FAQ contains hardly any details on data protection, even though passport photos involve sensitive information).
According to the procedure, the photos are intended to remain in the AWS cloud for six months or can be deleted upon a visit to the relevant authority. Multiple use is possible.
It can be observed that, as described above, the processing of the photos (e.g. at dm) passes through numerous IT systems before the photo is finally downloaded by the authorities, as shown in the following schematic diagram:

The various devices involved present a potential attack surface and, in some cases, are not even listed in the technical policy (as these ultimately only cover the scope of the upload software and cloud systems; even the authorities’ own software is scarcely described).
Right of access, right to erasure
Under data protection law, data subjects have (among other rights) the right to access (Article 15 of the GDPR) and the right to erasure (Article 17 of the GDPR).
The BSI’s technical policy (see p. 8) also states that the GDPR must be fully complied with:

These rights apply to personal data. As noted above, it is somewhat questionable whether an encrypted biometric passport photograph can still be regarded as personal data. However, in practice it is difficult to ensure that it is absolutely impossible to identify the individual; in this respect, it is assumed that these rights must be fully upheld.
Interestingly, on its website, in the relevant FAQ (archive) regarding the question “Can I retrieve my photo at a later date or have it erased?”, dm states that erasure is only possible through the authorities:

This, however, raises interesting data protection issues, as dm remains the data controller (the cloud belongs to dm and dm has processed the data) and would therefore also have to enforce the rights (in this case, erasure) or pass them on to service providers with a data processing agreement (DPO) in accordance with Article 28 of the GDPR; however, it seems unlikely that dm has concluded a DPO with every authority, and it could be that dm is therefore providing incorrect information in the FAQ.
Employees at Mint Secure GmbH recently contacted the providers and requested a right to access (Article 15 of the GDPR) and a copy of all personal data in accordance with Article 15(3) of the GDPR. The purpose of these enquiries is to determine which service providers may be used and exactly how the process (see above) is carried out.
The enquiries are worded as follows:
Dear Sir or Madam,
I recently had a biometric passport photograph taken at your [branch], which was produced in accordance with the new procedure (PAuswV).
In accordance with Article 15 of the GDPR, I request information regarding the processing of my personal data, in particular with regard to photographs and biometric data (such as images suitable for biometric identification). In my view, this constitutes special categories of personal data under Article 9 of the GDPR, as the image was processed biometrically to uniquely identify a person (checking for biometric features / facial recognition).
I would ask you to inform me:
– Whether any of my personal data (in particular photographs or biometric data) is being processed.
– What personal data (in particular photographs or biometric data) relating to me is being stored or processed.
– For what purposes this data is being processed.
– To which recipients or categories of recipients this data has been or will be disclosed.
– Which sub-processors were involved in the course of data collection or data processing.
– The planned retention period or the criteria for determining the retention period.
– The source of the data, unless it was collected directly from me.
– Whether automated decision-making, including the assessment of suitability for biometric recognition and profiling in accordance with Article 22 of the GDPR, takes place and, if so, meaningful information about the contractual partners involved, the logic, as well as the scope and intended effects of such processing.
In addition, I request a copy of all personal data you hold about me, in accordance with Article 15(3) of the GDPR. I would appreciate a reply within the statutory time limit of one month (Article 12(3) of the GDPR).
Please do not hesitate to contact me if you have any questions.
The service providers now have one month to respond, as this is the statutory time limit (see Article 12(3) of the GDPR). It is possible that, following a response, the right to erasure may also be exercised. Here, too, it remains to be seen with interest whether and how the service providers are able to fulfil this right.
In principle, however, they can only take one of two positions:
- They regard (despite massive objections) the encrypted passport photograph as not being personal data and therefore state that neither the right of access nor the right to erasure can be fulfilled. This could possibly be challenged or refuted, as ruling out any personal reference is almost impossible in practice.
- They regard the encrypted passport photo as personal data and request evidence via an order number. In that case, they could delete the image, but in doing so they would have established a link to an individual, meaning it would clearly be ‘personal data’ and fall entirely within the scope of the GDPR. This would mean that the information provided in the FAQ cited above is incorrect or in need of correction.
It is legally questionable if the right to erasure were only possible through the authorities. Ultimately, the cloud service provider is responsible for the data and must also fully comply with GDPR rights.
Possible solution: photos held by public authorities
For citizens who wish to avoid all these data protection issues and would prefer not to have their (encrypted) biometric photos stored in the AWS cloud, there is some good news to conclude with: As mentioned at the outset, in addition to using cloud service providers, the regulation also allows for the use of certified photo capture devices at the relevant public authorities; these are currently being rolled out in an increasing number of such authorities.
Tip: From the perspective of data protection and IT security, this appears to be the better choice.
Conclusion
In addition to the information provided here, service providers involved in the processing of biometric photos have been made aware of serious security vulnerabilities in the open-source components they use. As there has been no response as yet, no further details will be provided here for the time being. Updates on all the topics described here will be posted regularly in this blog post.
Update (9 May 2025): Netzpolitik.org has published an article on our investigation; as a result, the article has reached more people than we anticipated and we have received some feedback. The article mentioned above states on several occasions that the passport photos are stored in encrypted form; nevertheless, we consider storage in the AWS cloud to be problematic for data protection reasons.
How Mint Secure can help you
Whether you’re a public authority, service provider or business: anyone who processes biometric data or other data requiring special protection should have their data processing practices critically reviewed. We can assist with the following services:
Data Protection Impact Assessment
We assist with the DPIA in accordance with Article 35 of the GDPR for biometric and other high-risk processing operations, including the assessment of cloud and third-country transfers.
Cloud security audit
We analyse the cloud architectures in use from both a technical and organisational perspective for vulnerabilities, transport encryption and third-country risks.
GDPR Access and Erasure Requests
We advise organisations on the legally compliant implementation of requests for access and erasure under Articles 15 and 17 of the GDPR.
Want to get started? We offer a free initial consultation.
Get in touch now.
Conclusion
The switch to e-passport photos on 1 May 2025 raises several unresolved issues from a data protection and security perspective. Both providers examined store encrypted biometric passport photos in the AWS cloud, even though the PAuswV requires processing to be carried out exclusively by a cloud provider based in the EU. Whether this requirement is actually met, given the corporate links to US parent companies and the CLOUD Act, remains questionable.
In our view, there is also room for improvement among the providers regarding the rights to access and erasure, the handling of employee data and the transparency of the procedures used. Those wishing to avoid these risks can opt for certified photo capture devices available directly from public authorities.
Mint Secure supports companies and public authorities in designing such procedures in a way that is both secure and compliant with data protection regulations.
Please get in touch with us.

