Civil society and digital rights groups have urged the UK’s data protection regulator to investigate whether the Home Office’s digital-only eVisa scheme is breaching GDPR, warning that design flaws and data errors are exposing sensitive personal information and leaving migrants unable to prove their lawful status.
In a joint letter to the Information Commissioner’s Office (ICO), coordinated by the Open Rights Group, the signatories argue that the Home Office has failed to meet its data protection and equality obligations. The eVisa scheme replaces physical proof of immigration status with a live, online record that must be checked in real time. Campaigners say that when the system fails, there is no meaningful fallback, preventing people from accessing work, housing, travel, education and essential services.
The groups cite what they describe as a high volume of data errors linked to the scheme, which they say amount to both operational failures and serious breaches of data protection. One documented case referenced in the letter involved the passport details, contact information and immigration status of a Canadian citizen being wrongly disclosed to a Russian woman.
Other reported issues include migrants being locked out of their eVisa accounts, with little effective support and no clear route to escalate urgent problems. Because the system is digital-only, there is no physical document to rely on when errors occur, leaving individuals unable to demonstrate their right to live and work in the UK at critical moments.
Central to the complaint is the Home Office’s Data Protection Impact Assessment (DPIA), which the groups describe as incomplete and misleading. They argue it fails to address the inherent risks of a digital-only system, particularly for older people, disabled users and those who are digitally excluded. The letter also criticises the removal of all physical proof of immigration status in favour of real-time online checks.
Concerns were also raised about the handling of biometric data. Campaigners say the DPIA downplays the risks associated with the use of facial images for identity verification, automation or sharing with third parties, potentially in combination with other data sets.
The groups further challenge the Home Office’s description of the scheme as “digital by default”. Under the government’s own definition, digital-by-default services should remain accessible to those who cannot use them, yet the eVisa system offers no opt-out. Migrants without smartphones or reliable internet access may be forced to rely on others, creating additional risks around coercion and loss of privacy.
Sara Alsherif, migrants digital justice programme manager at the Open Rights Group, said: “Since the rollout of the digital-only eVisa scheme, we’ve seen widespread data errors, inaccessible design, and persistent technical failures that are leaving migrants unable to prove their right to work, rent, study, travel, or access essential services.
“In its DPIA, the Home Office failed to assess the risks that a digital-only scheme brings, particularly for those who are vulnerable, older, or disabled. It is also misleading in its assessment of the scheme as digital by default. If the Home Office had identified some of these risks, migrants may not have experienced the same levels of distress and hardship that we have seen over the last year. The ICO must investigate.”
The ICO has confirmed it has received the letter and is considering the issues raised. An ICO spokesperson said: “We regularly engage with government departments, including the Home Office, to ensure that data protection obligations are met and potential risks are mitigated. We can confirm that we have received the letter outlining these concerns, and will carefully assess the issues raised before responding.”