Full-body security scanners are designed to detect concealed objects without requiring every traveler or visitor to undergo a physical search, but the term “full body X-ray scanner” can be misleading because not all modern people-screening systems use X-rays. Current airport screening in the United States primarily relies on advanced imaging technology that uses millimeter-wave energy rather than ionizing X-radiation. X-ray people-screening systems also exist in security applications, and those systems raise a different radiation-safety question because X-rays are ionizing radiation. The distinction matters for both safety and privacy. A person should know what technology is being used, what type of energy it emits, what the system displays to the operator, whether images are stored, and what alternatives are available when screening is optional or an accommodation is required. Discussions of full body X-ray scanners therefore need to separate equipment types rather than treating every portal scanner as the same technology.
Millimeter-Wave Scanners and X-Ray Scanners Are Different
Millimeter-wave security systems use non-ionizing radiofrequency energy. According to the FDA’s security-screening information, systems that comply with the applicable national safety limits have no known adverse health effects from the screening exposure. General-use X-ray people-screening systems, by contrast, intentionally expose the person to a very low dose of ionizing radiation, so they are subject to radiation-safety standards and dose limits. This is why a traveler should not assume that the large airport scanner is taking an X-ray image. The Transportation Security Administration — Passenger Screening information describes current passenger screening procedures and advanced imaging technology separately from baggage X-ray systems.
Ionizing Radiation Requires a Different Safety Framework. X-rays have enough energy to ionize atoms, which is why medical and security X-ray exposures are managed using dose limits and risk-benefit principles. The FDA’s FDA — X-Ray Security Screening Systems resources explain that general-use people-screening systems must operate at extremely low doses. The FDA has historically compared one compliant security scan with a small fraction of the natural cosmic-radiation exposure received during ordinary air travel. The practical safety principle is that equipment should be properly designed, maintained, regulated, and used for a justified security purpose. “Low dose” does not mean radiation is conceptually irrelevant; it means the dose is controlled to a level judged acceptable for general screening under the applicable standards.
Millimeter Waves Are Non-Ionizing
Millimeter-wave systems use electromagnetic energy at frequencies that do not have enough energy to ionize atoms. They detect how energy reflects from the body and concealed objects. Modern airport systems generally use automated threat detection rather than presenting a detailed anatomical image to a remote operator in the way early full-body imaging systems were often described. This technology still deserves safety standards, testing, and regulatory oversight, but concerns about ionizing radiation from X-rays should not be applied directly to millimeter-wave screening. Privacy Concerns Have Changed as the Technology Evolved. Early body scanners generated images that led to substantial privacy criticism because the outline could reveal anatomical detail beneath clothing. Modern screening systems are designed to use automated target recognition and show a generic body figure or location indicator when the system identifies an area requiring additional screening. This reduces the amount of body detail visible to personnel. Privacy analysis should therefore focus on the current system rather than only on early-generation scanner images. It should ask what the machine produces today, who can access it, and what data is retained.
Data Retention Is as Important as Image Appearance
Even when a screen displays only a generic avatar, travelers may reasonably ask whether raw sensor data or images are saved. A responsible screening program should define whether data can be retained, under what circumstances, who has access, and how long records remain available. Operational testing modes can sometimes differ from normal passenger-screening mode, so agencies should publish clear policies. Privacy protection is strongest when the system collects only what is necessary for the security decision and deletes unnecessary data promptly. False Alarms Can Lead to Additional Screening. Advanced imaging systems are not perfect. Clothing folds, medical devices, sweat, bandages, prosthetics, body contours, or objects in pockets can trigger an alarm. When the system identifies an area of concern, security officers may need to conduct targeted pat-down screening or another inspection. False positives are an important operational consideration because a technology can be physically safe yet still create inconvenience, embarrassment, or unequal screening burdens if alarm rates are high for certain groups or conditions.
Medical Devices Need Clear Screening Procedures
Travelers with insulin pumps, ostomy supplies, prosthetics, surgical implants, braces, or other medical devices may have questions about how screening affects the device or how much personal information they need to disclose. Security agencies typically provide procedures for requesting assistance and explaining medical conditions privately. A traveler should not remove or disconnect a medically necessary device simply because a security line is busy. Follow the device manufacturer’s advice and use the agency’s accommodation process when needed. Pregnancy Questions Depend on the Technology. For non-ionizing millimeter-wave systems, the radiation mechanism is different from medical X-rays. For systems that intentionally use X-rays, the relevant issue is the very low controlled dose and whether the facility follows general-use standards. Pregnant travelers who remain concerned can ask what screening method is being used and what alternative procedures are available. Individual medical advice should come from a qualified healthcare professional rather than from security-equipment marketing material.
Children and Frequent Travelers Raise Exposure Questions
With general-use X-ray people scanners, regulators consider both the per-scan dose and annual exposure. FDA guidance is designed around extremely low dose limits for general public use, including populations that may be more sensitive. A frequent traveler would still need an unusually large number of compliant screenings to approach established annual security-screening dose limits. With millimeter-wave systems, ionizing-radiation accumulation is not the issue because the technology is non-ionizing. Again, identifying the technology is the first step toward discussing the correct risk. Operators Need Training and Quality Assurance. Safe equipment can be used poorly. Personnel need training in system operation, alarm resolution, privacy procedures, accommodations, and respectful communication. X-ray systems also require radiation-safety quality controls, while all systems need maintenance and checks to ensure sensors and software are functioning correctly. Organizations should document inspections, maintenance, calibration where relevant, incident handling, and procedures for taking malfunctioning equipment out of service.
Cybersecurity Is Part of Scanner Privacy
Modern security scanners are computer systems. They may include network connections, operating systems, image-processing software, administrative accounts, update mechanisms, and logs. Weak cybersecurity could expose sensitive operational data or create risks that did not exist in older stand-alone equipment. Access control, software updates, network segmentation, logging, and vendor security practices should therefore be included in procurement and privacy assessments. Security Effectiveness Must Justify the Intrusion. Any screening technology creates a tradeoff between security, cost, throughput, privacy, and inconvenience. A system that detects a meaningful category of concealed threat with lower physical contact may provide a strong benefit, but the organization should still evaluate false-alarm rates, accessibility, staffing, and privacy impact. Technology should not be deployed simply because it is available. The security need should be defined first, followed by an assessment of whether the scanner materially improves detection compared with less intrusive alternatives.
Transparency Builds Public Trust
People are more likely to accept security technology when agencies explain what it does and does not do. Clear signage can identify the technology, explain whether it uses ionizing radiation, describe what the operator sees, and provide information about alternative screening. This reduces rumors and prevents outdated images of early scanners from defining public understanding of modern systems. Transparency is particularly important when screening occurs in airports, courthouses, prisons, borders, and other environments where individuals may feel they have limited ability to refuse.
What Organizations Should Ask Before Buying a Scanner
AreaQuestions to verify
TechnologyMillimeter wave, X-ray, or another imaging method?
SafetyWhich exposure standards and regulatory requirements apply?
PrivacyWhat does the operator see, and is raw data stored?
AccuracyWhat are detection and false-alarm rates in the intended environment?
AccessibilityHow are medical devices, disabilities, children, and accommodations handled?
CybersecurityHow are software, accounts, logs, and network access protected?
Organizations Should Conduct Privacy Impact Assessments Before Deployment. A privacy impact assessment can force an agency or facility to document exactly what information the scanner creates, whether that information can identify an individual, which personnel can access it, whether data leaves the device, and how long any records are retained. The assessment should also cover maintenance access, vendor diagnostics, software updates, test modes, and incident response. Privacy controls are strongest when they are built into procurement and system configuration rather than added after public concern develops. The same assessment should consider proportionality. A technology may be technically capable of collecting more detailed information than is necessary for a routine security decision. Data minimization means configuring the system to use the least intrusive information needed to detect the relevant threat and restricting access to diagnostic or raw data that ordinary screeners do not require.
Independent Testing and Procurement Standards Matter
Security organizations should not rely entirely on manufacturer claims about detection performance, radiation output, privacy, or cybersecurity. Procurement can require evidence of conformity with applicable safety standards, independent laboratory testing, software-security documentation, maintenance schedules, and measurable acceptance criteria. For X-ray people-screening systems, radiation-safety programs should include dose verification and procedures for unexpected radiation events. For millimeter-wave systems, radiofrequency exposure limits and electrical/product safety remain relevant even though the technology is non-ionizing. Performance testing should use realistic populations and objects rather than only ideal laboratory scenarios. Clothing, body types, mobility aids, religious garments, medical devices, and ordinary passenger behavior can affect alarm rates. A scanner that performs well statistically but creates excessive secondary screening for particular groups can generate operational and civil-liberty concerns that need to be addressed.
People Need a Clear Way to Raise Concerns. A responsible screening program should provide a process for travelers or employees to ask what technology is being used, request an accommodation where available, report inappropriate screening, or raise a privacy concern. Complaint data can reveal recurring problems with officer behavior, false alarms, communication, or equipment configuration that technical maintenance logs will never show. This feedback is particularly important because screening occurs in settings with an inherent power imbalance. Clear procedures and respectful communication can reduce anxiety without weakening security objectives.
Workplace Screening Raises Different Consent Questions Than Airport Screening
Full-body security screening can also appear in prisons, high-security industrial sites, border facilities, or other workplaces. In those settings, the legal and employment framework can differ significantly from passenger screening. Organizations should define why the technology is necessary, what happens when an employee or visitor refuses, whether alternatives exist, and how medical or religious accommodations are handled. A security objective does not automatically eliminate privacy, disability, labor, or data-protection obligations. Policies should be written before deployment and applied consistently. Employees and contractors should know whether screening is random or routine, what the machine detects, whether information is retained, and who can review exceptions. Clear governance reduces the risk that a technically capable scanner becomes an opaque surveillance tool. Procurement teams should also review how long the manufacturer will support software, replacement parts, calibration, and security updates. A scanner that cannot be maintained securely for its intended service life can create operational and privacy risk even if its original performance was acceptable.
For organizations adopting body-scanning technology, privacy controls should be documented before deployment rather than added after complaints arise. Procurement teams should define what data the scanner creates, whether images or raw signals can identify a person, who can access diagnostic information, whether data leaves the device, and how long any records are retained. Clear retention limits, role-based access, audit logs, staff training, and a complaint process reduce the risk that a security system becomes a broader surveillance tool than the operational purpose requires.
Conclusion
Safety and privacy questions around full-body security scanners cannot be answered responsibly without identifying the technology. Millimeter-wave systems use non-ionizing energy and are the main advanced imaging technology encountered in current U.S. airport passenger screening, while general-use X-ray people scanners use very low levels of ionizing radiation governed by specific safety standards. Privacy has also evolved from early detailed body images toward automated threat recognition and generic displays, but data retention, access, false alarms, accommodations, and cybersecurity still matter. A well-run screening program should combine justified security benefits with transparent technology information, regulated exposure limits where applicable, trained operators, minimal data collection, and respectful alternatives for people who need them.