top of page

Is Etapermits GDPR compliant? What this means for you.

When you apply for a travel authorisation through any online service, you are sharing some of your most sensitive personal information — your full name, date of birth, passport number, and sometimes financial details. So before you hand over that information, it's entirely reasonable to ask: is this website safe, and what do they do with my data?

At ETA Permits, we take that question seriously. Here's everything you need to know.

What is GDPR?

GDPR stands for General Data Protection Regulation. It is a law introduced by the European Union in 2018 and retained in UK law following Brexit as the UK GDPR. It is one of the strictest data protection frameworks in the world.

In simple terms, GDPR gives you — the individual — control over your personal data. It sets out strict rules about how organisations collect, store, use, and protect your information.

Under GDPR, any organisation that handles your personal data must:

  • Tell you clearly what data they collect and why

  • Only collect data they actually need

  • Store your data securely

  • Never sell your data to third parties without your consent.

  • Delete your data when it is no longer needed

  • Allow you to request access to your data or ask for it to be deleted at any time

If an organisation fails to comply, they can face fines of up to £17.5 million or 4% of their annual turnover — whichever is higher.

Why Does This Matter When Applying for an ETA or ETIAS?

Travel authorisation applications involve highly sensitive personal data. Your passport number, nationality, date of birth, and travel history are exactly the kind of information that identity thieves and fraudsters target.

When you use an online application service, you are trusting that service with information that could cause serious harm if it fell into the wrong hands. GDPR compliance is not just a legal requirement — it is a signal that a business takes your privacy seriously.

Before using any travel authorisation service, you should always check:

  • Do they have a clear Privacy Policy explaining how your data is used?

  • Do they use a secure, encrypted connection (look for the padlock in your browser)?

  • Do they have a cookie consent mechanism in place?

  • Are they transparent about who your data is shared with?

Is ETA Permits GDPR Compliant?

Yes. ETA Permits is fully GDPR compliant. Here is what that means in practice for you:

  • We only collect the personal information necessary to process your application

  • Your data is stored securely and never sold to third parties

  • We use cookie consent technology to give you full control over tracking preferences

  • Our Privacy Policy clearly sets out your rights and how we handle your information


We process your data for one purpose only — to assist with your travel authorisation application. Nothing else.

Your Rights Under GDPR

As a user of our service, you have the following rights:

  • The right to know what data we hold about you - after processing - we delete everything.

  • The right to correct inaccurate data

  • The right to request deletion of your data

  • The right to object to how your data is used

  • The right to make a complaint to the ICO (Information Commissioner's Office) if you believe your data has been mishandled

Peace of Mind When You Apply

Choosing ETA Permits means choosing a service that is transparent, secure, and fully compliant with UK and EU data protection law. When you apply through us, you can do so with complete confidence that your personal information is in safe hands.

If you have any questions about how we handle your data, please don't hesitate to get in touch.

Comments


bottom of page