
How long do consular authorities keep your personal data?
Fifteen years in the US, 25 in New Zealand, no set limit in South Korea, only three in the EU. We analyzed the official privacy policies of major ETA and e-Visa schemes worldwide.
Completing an electronic travel-authorization request takes about ten minutes. The personal data you submit may remain on file for fifteen years, twenty-five years—or sometimes indefinitely. We reviewed the official privacy policies of the main ETA and e-Visa systems listed on our site, and the differences are stark.
No jurisdiction keeps records longer than South Korea
South Korea’s official K-ETA privacy policy—in force since 13 March 2025—states a retention period described as “준영구,” a Korean administrative term meaning quasi-permanent, with no erasure date envisaged. The Ministry of Justice cites Article 7-3 of the Immigration Control Act.
The Korean form collects more than the usual civil-status and passport data. Applicants must disclose occupation, monthly income, whether they know anyone in Korea, and may optionally provide a social-media account. Face photos and passport copies are subject to the same indefinite retention.
The policy is silent on refused applications; the quasi-permanent rule applies to the entire database regardless of approval status.

In the US, an ESTA refusal can haunt you forever
The ESTA regime is contained in a public document, System of Records Notice DHS/CBP-009, published in the Federal Register on 27 June 2019. It sets a fifteen-year retention schedule: three years in active use and twelve years in archives.
Two nuances extend the effective window. Records linked to an active law-enforcement alert—explicitly including refused ESTA applications—remain accessible for as long as the related enforcement action continues (i.e., indefinitely). And once you actually enter US territory, a separate admission record is created and kept for seventy-five years.
The same document notes that the Privacy Act rights of access and correction are explicitly waived for sensitive parts of the system; authorities are not required to respond to such requests.
New Zealand doubled its retention period—and made it retroactive
A privacy-impact assessment approved on 7 December 2025 reveals an overlooked policy shift: New Zealand’s intelligence service, which has direct access to the NZeTA database, now retains entries for twenty-five years instead of ten.
The document clarifies that the new rule applies to all existing records that had not yet reached the ten-year mark and therefore had not yet been deleted; they now fall under the twenty-five-year regime.
Notably, this duration appears only in an internal technical memo aimed at agencies; it does not appear in the passenger-facing privacy notice displayed during application.

Europe bucks the trend—and that matters
The EU Regulation 2018/1240 that creates ETIAS adopts the opposite logic. Article 54 specifies that the file of an approved traveller is kept for the validity period of the authorization—three years at most—then erased automatically.
A refused traveller’s data is kept for five years, but with an automatic purge trigger: if the alert that led to the refusal disappears from queried databases before that term, the record must be deleted within seven days. The system performs the check periodically and executes erasure without human intervention.
The regulation allows a three-year extension, but only with the explicit, revocable consent of the applicant; any withdrawal triggers immediate erasure. Transfer of data to third countries is prohibited in principle, the narrow exception being Interpol queries.
As of today, ETIAS is not yet operational; the European Commission pencils in a launch in Q4 2026. Do not confuse it with the Entry/Exit system, which has been fully in service throughout the Schengen area since 10 April 2026.
One publishes details, another publishes nothing at all
The UK’s ETA privacy notice, updated 13 November 2025, is the most granular we found. It breaks down each data category and assigns a retention term:
Facial biometrics: three years unless a longer retention basis applies
Biographical and personal data: fifteen years after the last dossier activity
Online verification service: thirty minutes after the last session activity
Access logs containing IP address: thirty days
Mobile-app data: no storage after successful submission

Oddly, your facial image is erased five times faster than your name and passport number. The Home Office also notes that most decisions are automated; complex or negative cases are escalated to a case officer.
At the opposite end, India’s official e-Visa portal conspicuously lacks any published privacy policy, even though it states that biometric data must be collected at the border on arrival. Whether retention durations exist elsewhere in Indian administration is immaterial to a traveller who is never shown them. We were also unable to retrieve any retention figure for Canada’s eTA or Turkey’s e-Visa because their respective portals blocked automated review; we prefer to state the unknown rather than guess.
What you can actually do
Three practical habits before filling in an electronic authorization form:
Check the privacy notice of the official site first—look specifically for retention and sharing clauses. It can be hard to find, and its absence is itself a red flag.
Only supply optional fields when necessary. A social-media account asked for by some systems is optional and will be stored as long as the rest of your file.
Exercise rights with caution. In ETIAS, asking for a correction on an open authorization reactivates the automated process, which may trigger a full re-examination of your dossier.
These rules evolve—rarely in a traveller-friendly direction. We also monitor the technical reliability of the same portals; earlier this year we published an availability barometer on that topic.
As CEO of Visamundi, I am dedicated to simplifying international travel by assisting our clients in obtaining visas worldwide. By staying at the forefront of ever-changing regulations, I ensure our agency remains a trusted pillar in the visa services industry.
