Calls for ICO Probe into Home Office eVisa Data Handling

Civil society and digital rights groups have urged the UK’s data protection regulator to investigate whether the Home Office’s digital-only…
ChatGPT Image - UK Home Office - SecurityBuyer.com

Share this article:

Civil society and digital rights groups have urged the UK’s data protection regulator to investigate whether the Home Office’s digital-only eVisa scheme is breaching GDPR, warning that design flaws and data errors are exposing sensitive personal information and leaving migrants unable to prove their lawful status.

In a joint letter to the Information Commissioner’s Office (ICO), coordinated by the Open Rights Group, the signatories argue that the Home Office has failed to meet its data protection and equality obligations. The eVisa scheme replaces physical proof of immigration status with a live, online record that must be checked in real time. Campaigners say that when the system fails, there is no meaningful fallback, preventing people from accessing work, housing, travel, education and essential services.

The groups cite what they describe as a high volume of data errors linked to the scheme, which they say amount to both operational failures and serious breaches of data protection. One documented case referenced in the letter involved the passport details, contact information and immigration status of a Canadian citizen being wrongly disclosed to a Russian woman.

Other reported issues include migrants being locked out of their eVisa accounts, with little effective support and no clear route to escalate urgent problems. Because the system is digital-only, there is no physical document to rely on when errors occur, leaving individuals unable to demonstrate their right to live and work in the UK at critical moments.

Central to the complaint is the Home Office’s Data Protection Impact Assessment (DPIA), which the groups describe as incomplete and misleading. They argue it fails to address the inherent risks of a digital-only system, particularly for older people, disabled users and those who are digitally excluded. The letter also criticises the removal of all physical proof of immigration status in favour of real-time online checks.

Concerns were also raised about the handling of biometric data. Campaigners say the DPIA downplays the risks associated with the use of facial images for identity verification, automation or sharing with third parties, potentially in combination with other data sets.

The groups further challenge the Home Office’s description of the scheme as “digital by default”. Under the government’s own definition, digital-by-default services should remain accessible to those who cannot use them, yet the eVisa system offers no opt-out. Migrants without smartphones or reliable internet access may be forced to rely on others, creating additional risks around coercion and loss of privacy.

Sara Alsherif, migrants digital justice programme manager at the Open Rights Group, said: “Since the rollout of the digital-only eVisa scheme, we’ve seen widespread data errors, inaccessible design, and persistent technical failures that are leaving migrants unable to prove their right to work, rent, study, travel, or access essential services.

“In its DPIA, the Home Office failed to assess the risks that a digital-only scheme brings, particularly for those who are vulnerable, older, or disabled. It is also misleading in its assessment of the scheme as digital by default. If the Home Office had identified some of these risks, migrants may not have experienced the same levels of distress and hardship that we have seen over the last year. The ICO must investigate.”

The ICO has confirmed it has received the letter and is considering the issues raised. An ICO spokesperson said: “We regularly engage with government departments, including the Home Office, to ensure that data protection obligations are met and potential risks are mitigated. We can confirm that we have received the letter outlining these concerns, and will carefully assess the issues raised before responding.”

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

Jason Bezuidenhout - securitybuyer.com

Zygal Appoints Jason Bezuidenhout

Zygal has appointed Jason Bezuidenhout as Chief Revenue Officer (CRO), strengthening its leadership team as the company continues
Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
OPTEX at Essen - securitybuyer.com

OPTEX to showcase perimeter solutions at Security Essen

OPTEX will present its latest perimeter and asset protection solutions at Security Essen 2026, one of Europe’s leading security trade fairs.
Dallmeier

Building Trust in Modern Video Security

Rebecca Spayne, Managing Editor of Security Buyer, speaks with Josua Braun, Chief Revenue Officer at Dallmeier electronic, about cyber resilience, trusted supply chains, the practical value of artificial intelligence and what security professionals should consider when investing in modern video technology. 
Verkada

Verkada Expands AI Security Platform

Verkada, a provider of AI-powered physical security and operations, has unveiled new capabilities for vehicle fleets, enterprise sound systems, and building operations during its annual customer conference, VerkadaOne.
Assa Abloy

“Mobile-first” access 

David Moser, of ASSA ABLOY Opening Solutions EMEIA explores how mobile digital access unlocks new possibilities for organizations everywhere.
Traka - securitybuyer.com

Integrating Digital and Physical Security

Tom Smith, Vice President and Head of EMEIA for Traka, discusses convergence and the expanding role of integrated key and asset management. 
Traka GSX

GSX Exhibitor Spotlight – Traka

Traka, an ASSA ABLOY company and the global leader in intelligent management solutions for keys and equipment, returns to GSX 2026 at Booth #1233. Traka experts will be available to provide personal demonstrations of how smart asset management systems are streamlining operations in numerous industry verticals. 
Rhombus GSX

GSX Exhibitor Spotlight – Rhombus

When it comes to modernising physical security, Rhombus stands out by making it smarter, simpler, and genuinely easier to manage; no matter the size or complexity of the business. 
Scroll to Top