Under the assumption that this framework is somewhat sane and only shares biometric data of those people who actually request an ESTA, I don't see the issue.
This data already leaks whenever you travel legally to the US, because they take it from you as a requirement of entry. All this does is let them check the data they take on entry against the provided data. Which seems fair. The fact this data is already in passports is a very different matter, but that is something the EU has done voluntarily.
> those people who actually request an ESTA
I order to know who actually requested it, information needs to be shared that previously was not. (I can think of technical schemes to limit this to less scary recipients and data, but however you do it, some necessary side-effect remains: Citizens of the EU who do not make such request cannot remain entirely unaffected.)