
Privacy Notice Template and DPA Guide for Visa Agencies
A visa agency needs two data protection documents before anything else: a privacy notice for applicants and a data processing agreement with every supplier that handles their files. Here is what each must contain.

Key takeaways
- A visa agency needs a privacy notice for applicants and a data processing agreement with every supplier that processes applicant data on its behalf.
- Under the UK GDPR and EU GDPR, the privacy notice must cover identity, purposes, lawful basis, recipients, international transfers, retention and individual rights.
- Health data from medical checks and biometric data used for identification are special category data, which need an Article 9 condition on top of a lawful basis.
- A processor contract must oblige the supplier to act only on your documented instructions, keep data confidential and secure, control sub-processors and delete or return data at the end.
- Embassies, consulates and visa application centres are recipients you must name in the notice, not suppliers you can bind with your own processing agreement.
Which data protection documents does a visa agency need?
A visa agency needs two core documents: a privacy notice that tells applicants what personal data you collect, why, on what lawful basis, who receives it, where it goes and how long you keep it; and a data processing agreement with every supplier that handles that data for you, such as your CRM, email and cloud storage providers.
This article is general information, not legal advice. Data protection law differs by country, and the right wording for your agency depends on what you actually do. Use this as a working brief, then have a qualified privacy lawyer or data protection adviser review your final documents.
The two documents solve different problems. The privacy notice is about transparency toward the people whose passports, bank statements and family details sit in your files. The processing agreement is about control: it binds each supplier to use that data only the way you tell it to. A generic notice copied from a website builder does neither job well, and a supplier signed up with a card and a click usually comes with a processing agreement that nobody at the agency has read or filed.
The examples below use the UK GDPR and EU GDPR because the UK regulator, the ICO, publishes clear guidance on both documents. If you work under another regime, the structure still helps, but check your own law. We cover the wider compliance picture in data privacy compliance for visa agencies.
What must a privacy notice to visa applicants include?
The ICO lists the privacy information you must give when you collect data directly from the individual. For a visa agency, that is almost always the case: the applicant fills in your intake form, sends documents and answers questions.
The notice must cover:
- your agency's name and contact details, and your representative's details if you have one
- the contact details of your data protection officer, if you have appointed one
- the purposes of processing and the lawful basis for each purpose
- the legitimate interests you rely on, where that is your basis
- the recipients or categories of recipients of the data
- details of transfers to other countries and the safeguards used
- how long you keep the data, or the criteria you use to decide
- the individual's rights, including access, rectification, erasure, restriction, objection and portability
- the right to withdraw consent, where consent is your basis
- the right to complain to the supervisory authority
- whether providing the data is a legal or contractual requirement and what happens if it is not provided
- whether you use automated decision-making, including profiling
If you receive data about someone from another source, for example a sponsor's details supplied by the applicant, the ICO says you must also tell that person what categories of data you hold and where it came from.
Here is how those headings translate into visa agency reality:
| Notice item | What it means in a visa agency |
|---|---|
| Purposes | Assessing eligibility, preparing the application, booking appointments, taking payment, sending status updates |
| Recipients | The consulate or embassy, its visa application centre, translators, courier, payment provider, partner agencies |
| Transfers | Destination governments outside your country, suppliers hosting data abroad |
| Retention | How long case files, passports copies and payment records are kept after the case closes |
| Consequences of not providing | Without the required documents the application cannot be prepared or submitted |
| Automated decisions | Whether any eligibility scoring runs without a human reviewing it |
Write the notice for the applicant, not for a regulator. Plain sentences, short sections and a layered version on your intake form, with a link to the full notice, work better than a single legal page. The retention section is where most agencies get vague; our guide on how long a visa agency should keep client data will help you fill it in with real periods.
See VisaCRM in action
Book a quick demo and see how it works for your visa types.
Which lawful basis applies to visa applicant data?
Every purpose in your notice needs a lawful basis, and a visa agency normally uses more than one. Match each purpose to a basis before you write the notice, not after.
Common pairings to discuss with your adviser:
- Preparing and submitting the application you were hired for: usually performance of a contract with the applicant.
- Keeping invoices and payment records: often a legal obligation under tax and accounting rules.
- Following up on enquiries or improving your service: sometimes legitimate interests, which then must be named in the notice.
- Marketing emails and newsletters: often consent, which must be as easy to withdraw as to give.
Special category data: health and biometrics
Visa files regularly contain information the law treats as more sensitive. The ICO lists nine types of special category data, including health data and biometric data used to identify a person. For an agency this typically means medical examination results, vaccination records, disability information supporting a request, and fingerprints or facial images if you ever handle them. See our glossary entry on biometrics for how biometric collection works in visa processes.
To process special category data you need both an Article 6 lawful basis and a separate Article 9 condition, and the ICO points out that high-risk processing can require a data protection impact assessment. Criminal record information, such as police certificates, is not special category data, but the ICO notes that similar protective rules apply to it under separate provisions.
The practical rule for agencies is data minimisation: collect a medical report only when the destination requires it, restrict it to the staff handling that case, and delete it on the schedule you promised.
Who is the controller and who is the processor?
Whether you need a processing agreement with someone depends on their role. The European Data Protection Board's Guidelines 07/2020 set out the distinction: a controller decides why and how personal data is processed; a processor processes it on the controller's behalf and on its instructions. The same organisation can be a controller for one activity and a processor for another, so decide role by role, not company by company.
For an agency that sells visa services directly to applicants, the agency is the controller for the applicant's data. The table below shows how common relationships usually fall. Treat it as a starting point for a conversation with your adviser, because the actual contract and facts decide the role.
| Relationship | Usual role | What you need |
|---|---|---|
| CRM or case management platform | Processor | Data processing agreement |
| Email, cloud storage, e-signature tools | Processor | Data processing agreement, usually the vendor's standard terms |
| Freelance translator you instruct | Processor | Data processing agreement or clause in the engagement letter |
| Consulate, embassy, visa application centre | Separate organisation acting for a government | Name as recipient in your notice |
| Payment provider | Depends on the provider's terms | Read how the provider describes its own role |
| Partner or sub-agent that sends you clients | Depends on who decides the purposes | Written agreement setting out each party's role |
Partner relationships deserve particular care. If a travel agency collects applicant documents and passes them to you, and both of you use the data for your own purposes, neither is simply working on the other's instructions. Write down who does what before data starts moving. Our guide to building a B2B partner network covers the commercial side of those agreements.
A visa application centre does not take instructions from your agency, so you cannot bind it with your own processing agreement. What you can do is tell the applicant, clearly, that their data will be sent to the consulate and to the centre it uses, and point them to those organisations' own privacy information.
What goes into a data processing agreement?
Article 28 of the UK GDPR and EU GDPR requires a written contract whenever a controller uses a processor. According to the ICO, the contract must describe the processing itself: its subject matter and duration, its nature and purpose, the types of personal data and categories of data subject, and the controller's obligations and rights.
It must also contain these minimum terms:
- The processor acts only on the controller's documented instructions.
- Everyone processing the data is under a duty of confidence.
- The processor takes appropriate security measures.
- The processor uses sub-processors only with the controller's authorisation and on equivalent terms.
- The processor helps the controller respond to individuals exercising their rights.
- The processor assists the controller with its own obligations, such as security and breach notification.
- At the end of the contract, the data is deleted or returned.
- The processor makes information available and allows audits and inspections.
Most software suppliers publish a standard processing agreement, often linked from their terms. You rarely negotiate it, but you still need to read it and file it. When you review a supplier's agreement, check:
- where the data is hosted and whether it leaves your jurisdiction
- the current list of sub-processors and how you are notified of changes
- the security measures described, not just promised
- how quickly the supplier will tell you about a breach
- what happens to your data when you cancel, and in what format you get it back
That last point matters more than it looks. An agency that cannot export its case files cleanly is locked in, and an agency that does not know whether data was deleted cannot answer an erasure request. If you are evaluating platforms, the questions in where visa applicant data is stored and who can see your clients' data in a visa CRM are a good checklist.

How should you describe embassies and international transfers?
Visa work is international by definition. The applicant's data goes to a foreign government, and often to suppliers hosting data in other countries. Your privacy notice has to say so, and the ICO lists details of transfers and their safeguards among the required information.
Split transfers into two groups when you write this section:
- Transfers the applicant asked for. Sending an application to the destination's consulate is the reason the applicant hired you. Name the destination countries you work with, or describe them as the country whose visa is being applied for.
- Transfers that come from your own tooling. If your CRM, email or backup provider stores data in another country, that is your choice, and it needs its own safeguard under the law that applies to you.
The second group is the one agencies forget. Ask every supplier where data is hosted and which transfer mechanism they rely on, and record the answer in your register of suppliers. If the answer changes, your notice may need to change too.
A few wording habits keep this section honest:
- say where the data goes, not just that it may be transferred abroad
- avoid promising that data never leaves the country if a supplier stores it elsewhere
- explain that the destination government applies its own rules once it receives the application
For country-specific visa workflows, our Germany country page and other country pages show how agencies structure submissions per destination.
Ready to streamline your visa business?
Tell us what you need and we'll come back with a plan. Nothing to pay until it's delivered.
Get started →How do you keep the notice and agreements up to date?
Both documents go stale the moment your operations change, and visa agencies change often: a new destination, a new messaging channel, a new partner. Build the review into operations instead of treating it as a one-off legal task.
Keep a simple register with one row per supplier:
| Supplier | Data it touches | Role | Agreement on file | Hosting location | Last reviewed |
|---|---|---|---|---|---|
| CRM platform | All case data and documents | Processor | Yes | Check with supplier | Record the date |
| Email provider | Client correspondence | Processor | Yes | Check with supplier | Record the date |
| Freelance translator | Documents sent for translation | Processor | Clause in engagement letter | Translator's own device | Record the date |
Review the privacy notice and the register when any of these happen:
- you add a new supplier, channel or partner
- you start serving a new destination country
- you begin collecting a new type of data, such as medical results
- you change how long you keep files
- a supplier notifies you of a new sub-processor
Software can take some of the load. A platform that holds documents in one place, controls who can open each file and logs access makes it far easier to answer the questions your notice promises to answer. That is part of what VisaCRM builds and runs for agencies, as a processor under a written agreement; see whether VisaCRM is GDPR compliant and our document management features. Anyvisa, for example, tripled its application capacity without adding headcount, which only works when the data handling is structured rather than scattered across inboxes. Read the Anyvisa case study for the operational side.
Whatever tools you use, the documents remain your responsibility as controller. Date them, version them and have them reviewed by a qualified adviser before you publish, and again whenever the facts behind them change.
Frequently asked questions
Does a small visa agency really need a privacy notice?
Yes. If the agency collects personal data from applicants and is subject to the UK GDPR or EU GDPR, the right to be informed applies regardless of size. The notice must be given at the time the data is collected and explain who you are, why you use the data, your lawful basis, who receives it, how long you keep it and what rights the applicant has.
What is the difference between a privacy notice and a data processing agreement?
A privacy notice is written for the applicant and explains how the agency uses their personal data. A data processing agreement is a contract between the agency, as controller, and a supplier that processes the data on its behalf, such as a CRM, email or cloud storage provider. The first is about transparency, the second about binding the supplier to your instructions.
Is a visa application centre a processor for my agency?
Usually not. A visa application centre works for the government whose visa is being applied for, not for your agency, so you cannot instruct it the way you instruct a supplier. Treat the consulate and the centre it appoints as recipients of the applicant's data and name them, or their categories, in your privacy notice. Check their own privacy information for how they handle the data.
Can I use a free privacy notice template?
A template is a reasonable starting point for structure, but it cannot know what your agency actually does. Replace every generic line with your real purposes, lawful bases, suppliers, destinations and retention periods. A notice that describes processing you do not do, or omits processing you do, fails the transparency requirement even if it looks complete. Have a qualified adviser review the final version.
Do I need a separate lawful basis for medical and biometric data?
Yes. Health data and biometric data used to identify a person are special category data under the UK GDPR and EU GDPR. Processing them requires both an Article 6 lawful basis and a separate Article 9 condition, and the ICO notes that high-risk processing may also need a data protection impact assessment. Collect only what the destination actually requires and restrict who can view it.
Sources
Rules, fees and processes change. We checked this article against the official sources below on 16 September 2026 — confirm anything time-sensitive with the source before you rely on it.
- What privacy information should we provide? — Information Commissioner's Office (UK)
- What needs to be included in the contract? — Information Commissioner's Office (UK)
- What is special category data? — Information Commissioner's Office (UK)
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR — European Data Protection Board
Related questions
See it running in a real agency
The patterns in this article are already deployed across these platforms. Different brands, different visa types — one engine underneath.
Further reading
Practical guides that go deeper on running a modern visa business.










