
Electronic travel authorisations: how long authorities keep your data
Fifteen years in the United States, twenty-five in New Zealand, no end date in South Korea, three years in the European Union. We read the official privacy policies of the main ETA and e-Visa schemes.
Filling in an electronic travel authorisation takes about ten minutes. The data you leave behind sometimes stays for fifteen years, twenty-five years, or with no end date at all. We read the official privacy policies of the main ETA and e-Visa schemes we cover, and the gaps between them are considerable.
Nobody keeps your data as long as South Korea
The privacy policy of the official K-ETA portal, in force since 13 March 2025, states a retention period described as « 준영구 », a term of Korean administrative law meaning quasi-permanent. No deletion date is set. The Korean Ministry of Justice relies on article 7-3 of the Immigration Control Act.
This deserves closer attention because the Korean form goes further than most. Beyond civil status and passport details, it asks for your occupation, your monthly income, whether you have acquaintances in Korea, and offers a field for a social media account. The facial photograph and passport copy follow the same retention rule.
The policy says nothing about refused applications. The quasi-permanent period applies to the file as a whole, without distinguishing authorisations granted from those that were not.
In the United States, a refusal can follow you indefinitely
The ESTA regime is set out in a public document, System of Records Notice DHS/CBP-009, published in the Federal Register on 27 June 2019. It sets retention at fifteen years: three years in an active database, then twelve years in archive.
Two qualifications change what that figure means. First, data linked to an active law enforcement matter, which expressly includes refused ESTA applications, remains accessible for as long as that law enforcement activity lasts. In other words, with no fixed end. Second, if you actually enter the country, a separate admission record is created, and that one is kept for seventy-five years.
The same document states that the access and correction rights available under the Privacy Act are expressly exempted for the sensitive parts of the system. You can file a request, but the administration is not required to answer on those elements.
New Zealand doubled its retention period, retroactively
A privacy impact assessment approved on 7 December 2025 documents a change that went largely unnoticed. The New Zealand intelligence service, which has direct access to the NZeTA database, now keeps that data for twenty-five years instead of ten.
The document specifies that the new period also applies to existing records: data that had not yet reached ten years, and had therefore not been destroyed, moves to the twenty-five year regime.
One detail is worth noting. That period appears in a technical document written for government agencies. It does not appear in the privacy statement travellers read when they apply.
Europe does the opposite, and that matters
Regulation (EU) 2018/1240, which establishes ETIAS, takes the opposite approach. Its article 54 provides that the file of an authorised traveller is kept for the validity period of the authorisation, three years at most, then automatically erased.
The file of a refused traveller is kept for five years. But the text adds an unusual mechanism: if the alert that triggered the refusal disappears from the queried databases before that term, the file must be deleted within seven days. The system checks this condition on its own, at regular intervals, and erases the record without human intervention.
The regulation allows a three-year extension, but it rests on the applicant's explicit consent, which can be withdrawn at any time. Withdrawal triggers automatic erasure of the file. The text also prohibits, as a matter of principle, any transfer of this data to a third country, with a narrow exception for Interpol queries.
One point of timing: ETIAS is not yet running. The European Commission announces a start in the last quarter of 2026. It should not be confused with the Entry/Exit System, fully operational across the Schengen area since 10 April 2026.
The United Kingdom quantifies everything, India publishes nothing
The UK ETA privacy notice, updated on 13 November 2025, is the most detailed we read. It separates each category of data and attaches a period to it.
- Facial biometrics: three years, unless there are grounds to keep them longer
- Biographic and personal data: fifteen years after the last case action
- Online checking service: thirty minutes after your last activity
- Access logs containing your IP address: thirty days
- Mobile app: no data kept after successful submission
The result runs against common intuition: the photograph of your face is erased five times faster than your name and passport number. The Home Office also states that the decision to issue an ETA is automated, with complex or adverse cases handled by a trained officer.
At the other end, the official Indian e-Visa portal publishes no privacy policy at all, while announcing that the applicant's biometric details will be mandatorily captured at immigration on arrival. This observation concerns the information available to travellers at the point of collection. Other documents may exist elsewhere in the Indian administration, but they are not shown to travellers when they hand over their data.
We could not establish the period applying to the Canadian eTA or the Turkish e-Visa, as both portals block automated access. We would rather say so than put forward a figure.
What you can actually do
Three useful habits before filling in an electronic authorisation form.
Read the privacy policy of the official portal before entering your data, in particular the retention and sharing sections. It is sometimes hard to find, and its absence is information in itself.
Treat optional fields with judgement. The social media account requested by some schemes falls into that category, and it will be kept for as long as the rest of the file.
Be aware that exercising a right is not neutral everywhere. Under ETIAS, a correction request concerning a valid authorisation restarts the automated processing, which can lead to the file being reassessed.
These rules change, and rarely towards shorter periods. We also track how reliable these same portals are technically, and published an availability barometer on the subject.
As CEO of Visamundi, I am dedicated to simplifying international travel by assisting our clients in obtaining visas worldwide. By staying at the forefront of ever-changing regulations, I ensure our agency remains a trusted pillar in the visa services industry.
