Compliance

Data Protection for Immigration Advisers: Handling Client Passports and Personal Data

Immigration advisers are custodians of some of the most sensitive data a person holds. Collect only what a case needs, secure it, keep it no longer than necessary, honour access and deletion requests, and be ready to report a serious breach to your regulator.

Whether you advise under UK GDPR, EU GDPR, or Canada's PIPEDA, the core duty is the same. You are the custodian of some of the most sensitive personal data a person holds, so collect only what the case needs, protect it, keep it no longer than necessary, honour clients' access and deletion requests, and be ready to report a serious breach to your regulator. The specifics, who you register with, the exact breach deadline, whether a fee applies, differ by country. The discipline does not.

The duty that holds everywhere

Across the markets most advisers work in, the same principles recur: collect the minimum a case requires, keep it only as long as you need it, protect it with appropriate security (encryption is the safeguard regulators expect for data this sensitive), and give clients the right to see and delete what you hold. Get those right and most of the rest is detail.

The details that differ by country

MarketRegulatorRegister / feeBreach deadlineNotable quirk
UKImmigration Advice Authority (IAA, formerly OISC)Register with the ICO; fee from £5272 hours to the ICOThe "immigration exemption" is for the Home Office, not you
EUYour national data protection authorityNo ICO-style fee72 hours to the authorityMember-state specifics vary
CanadaCollege of Immigration and Citizenship Consultants (CICC)No registration feeReport on "real risk of significant harm"Keep a record of every breach for two years

A practical checklist

  1. Know your regulator (UK: the IAA; Canada: the CICC; EU: your national authority).
  2. Register and pay where required (UK: the ICO fee, around £52 for small firms; Canada: no fee).
  3. Write a privacy notice covering what you collect, why, the lawful basis, and how long you keep it.
  4. Collect only what the case needs. A per-case checklist beats "send me everything."
  5. Secure the data with encryption in transit and at rest, and don't leave passports in a personal inbox or a shared folder.
  6. Set a retention period and delete when the case and any legal-hold period end.
  7. Be ready for access and deletion requests, which means knowing where each client's data lives.
  8. Have a breach plan before you need it, and know your regulator's deadline.
  9. Don't assume an exemption covers you. The UK immigration exemption doesn't.

Where doconvoy fits

Several of these duties are operational, and a secure intake tool makes them routine rather than manual. doconvoy collects the document packet through an encrypted request, with files encrypted in the client's browser, keeps each client's documents isolated, timestamps every submission for your records, and lets you delete at the individual submission level when a client exercises their right to erasure. It doesn't make you compliant on its own. Registration, lawful basis, retention, and the breach plan are yours. What it removes is the riskiest manual part: passports collected and stored ad hoc.

Encrypted, isolated, auditable document intake for immigration casework.

Collect applicant documents securely

Related: Immigration document collection · GDPR-compliant data collection · How to collect documents from clients without email attachments · Audit Trail

Common questions

Do immigration advisers need to register with a data protection regulator?

In the UK, most advisers are data controllers and must register with the ICO and pay the data protection fee, which is £52 for a micro business. Rules differ by country: Canada's PIPEDA has no equivalent registration fee. Check your own jurisdiction's regulator.

Does the UK 'immigration exemption' apply to immigration advisers?

No. The UK GDPR immigration exemption can be applied only by the Home Office for immigration-control purposes. It is not available to private advisers who liaise with the Home Office.

How long do we have to report a data breach?

In the UK and EU, a notifiable breach must be reported to the regulator within 72 hours, and affected individuals told where the risk is high. Under Canada's PIPEDA, report to the Privacy Commissioner and affected individuals where there is a real risk of significant harm, and keep a record of every breach for two years.

Is a client's passport 'special category' data?

In the EU and UK, a passport photo is not automatically special-category data. It only becomes biometric special-category data when it's processed by technical means for unique identification, such as facial recognition.