
What travel e-autorisations keep your details and for how long
Fifteen years in the US, twenty-five in New Zealand, until further notice in South Korea — we’ve reviewed the official privacy policies of leading e-Visa and ETA systems to compare their data-retention rules.
Filling in an electronic travel-authorisation form takes about ten minutes. What stays behind can remain for fifteen years, twenty-five years, or indefinitely. We’ve read the official privacy policies of the main ETA and e-Visa schemes we list, and the variances are striking.
No country holds your data as long as South Korea
The official K-ETA portal, updated 13 March 2025, defines its retention period as “준영구” — a Korean administrative term meaning quasi-permanent. There is no erasure date. The Ministry of Justice cites Article 7-3 of the Immigration Control Act.
The scope is unusually broad: you supply civil status, passport data, occupation, monthly income, and whether you have acquaintances in Korea, plus the option to add a social-media account. Your facial photo and passport scan are likewise retained for the same unlimited term.
The policy is mute about refused applications; the quasi-permanent duration applies to the entire file irrespective of outcome.

In the United States, a refusal can trail you forever
The ESTA regime is documented in the System of Records Notice DHS/CBP-009, published in the Federal Register on 27 June 2019. It sets retention at fifteen years: three years active, twelve years in archive.
Two exceptions expand the reach of this figure. First, any data linked to an active law-enforcement alert — explicitly including refused ESTA requests — stays available for as long as the related enforcement activity persists, i.e., without a time limit. Second, once you actually enter the country, a separate admission record is created and kept for seventy-five years.
The notice also states that Privacy Act access and correction rights are explicitly withheld for sensitive parts of the system; requests can be lodged, but the agency is not compelled to respond.
New Zealand quietly doubled its retention term retroactively
A privacy-impact assessment approved 7 December 2025 reveals that New Zealand’s intelligence service, which enjoys direct access to the NZeTA database, now stores the data for twenty-five years instead of ten.
The document adds that the new term applies to existing holdings: files that had not yet reached the ten-year mark — and so hadn’t yet been destroyed — now fall under the twenty-five-year rule.
A detail worth noting: this term appears in a technical notice for government bodies only and is absent from the privacy declaration that greets travellers at the point of application.

Europe does the opposite — and the difference matters
EU Regulation 2018/1240, which establishes ETIAS, adopts the reverse approach. Article 54 limits retention of an approved traveller’s file to the validity period of the authorisation — at most three years — after which data are erased automatically.
Refused applications are kept for five years, but with a rare safeguard: if the alert that triggered the refusal disappears from the queried databases before the five-year term, the file must be deleted within seven days. The system checks and enforces this condition automatically at regular intervals, without human intervention.
The regulation allows a single three-year extension, conditional on explicit consent that can be revoked at any time; withdrawal triggers automatic erasure. Further, data are barred from transfer to third countries except in narrow Interpol-query cases.
As of today, ETIAS is not yet live; the European Commission forecasts roll-out in Q4 2026. Do not confuse it with the Entry/Exit system, operational across the Schengen area since 10 April 2026.
UK quantifies everything, India publishes nothing
The UK’s ETA privacy notice, last updated 13 November 2025, is the most granular we reviewed. It lists each data category alongside its retention term:
Facial biometrics: three years, unless a longer retention is justified
Biographic and personal data: fifteen years from last file activity
Online verification service: thirty minutes after last activity
Access logs containing IP address: thirty days
Mobile app: no data retained after successful submission

Surprisingly, your face photo expires five times faster than your passport number. The Home Office also notes that grant decisions are automated; complex or negative cases are escalated to a case officer.
At the opposite extreme, India’s official e-Visa portal publishes no privacy policy at all, even though it states that biometric data will be collected again on arrival at immigration. We can only observe the information presented to the traveller at the point of data collection; other government documents may exist elsewhere, but they are not shown to the applicant.
We were unable to establish the retention term for the Canadian eTA or the Turkish e-Visa because both portals block automated consultation; we prefer to state this rather than guess.
Three smart moves before you hit submit on any e-authorisation form Read the portal’s official privacy notice before entering your data — pay special attention to the retention and sharing clauses. Finding it can be tricky; its absence is itself a warning sign. Treat optional fields with care. Requested social-media account details fall into this category and are retained as long as the rest of the file. Be aware that exercising rights is not neutral everywhere. With ETIAS, a rectification request on an open authorisation could restart automated processing and lead to a fresh review of your case. Rules are evolving — and rarely becoming shorter. We also track the technical reliability of the same portals in our availability barometer. |
As CEO of Visamundi, I am dedicated to simplifying international travel by assisting our clients in obtaining visas worldwide. By staying at the forefront of ever-changing regulations, I ensure our agency remains a trusted pillar in the visa services industry.
