Is Etapermits GDPR compliant? What this means for you.
- Philip Talbot
- May 8
- 3 min read
When you apply for a travel authorisation through any online service, you are sharing some of your most sensitive personal information — your full name, date of birth, passport number, and sometimes financial details. So before you hand over that information, it's entirely reasonable to ask: is this website safe, and what do they do with my data?
At ETA Permits, we take that question seriously. Here's everything you need to know.
What is GDPR?
GDPR stands for General Data Protection Regulation. It is a law introduced by the European Union in 2018 and retained in UK law following Brexit as the UK GDPR. It is one of the strictest data protection frameworks in the world.
In simple terms, GDPR gives you — the individual — control over your personal data. It sets out strict rules about how organisations collect, store, use, and protect your information.
Under GDPR, any organisation that handles your personal data must:
Tell you clearly what data they collect and why
Only collect data they actually need
Store your data securely
Never sell your data to third parties without your consent.
Delete your data when it is no longer needed
Allow you to request access to your data or ask for it to be deleted at any time
If an organisation fails to comply, they can face fines of up to £17.5 million or 4% of their annual turnover — whichever is higher.
Why Does This Matter When Applying for an ETA or ETIAS?
Travel authorisation applications involve highly sensitive personal data. Your passport number, nationality, date of birth, and travel history are exactly the kind of information that identity thieves and fraudsters target.
When you use an online application service, you are trusting that service with information that could cause serious harm if it fell into the wrong hands. GDPR compliance is not just a legal requirement — it is a signal that a business takes your privacy seriously.
Before using any travel authorisation service, you should always check:
Do they have a clear Privacy Policy explaining how your data is used?
Do they use a secure, encrypted connection (look for the padlock in your browser)?
Do they have a cookie consent mechanism in place?
Are they transparent about who your data is shared with?
Is ETA Permits GDPR Compliant?
Yes. ETA Permits is fully GDPR compliant. Here is what that means in practice for you:
We only collect the personal information necessary to process your application
Your data is stored securely and never sold to third parties
We use cookie consent technology to give you full control over tracking preferences
Our Privacy Policy clearly sets out your rights and how we handle your information
We process your data for one purpose only — to assist with your travel authorisation application. Nothing else.
Your Rights Under GDPR
As a user of our service, you have the following rights:
The right to know what data we hold about you - after processing - we delete everything.
The right to correct inaccurate data
The right to request deletion of your data
The right to object to how your data is used
The right to make a complaint to the ICO (Information Commissioner's Office) if you believe your data has been mishandled
Peace of Mind When You Apply
Choosing ETA Permits means choosing a service that is transparent, secure, and fully compliant with UK and EU data protection law. When you apply through us, you can do so with complete confidence that your personal information is in safe hands.
If you have any questions about how we handle your data, please don't hesitate to get in touch.


Comments