Private application assistance - not affiliated with UK Government Ref: GB-ETA-PORTAL-2026
Help

Find more info about how to answer each question below:

Select your nationality from the dropdown list. This information is used to determine the visa requirements and applicable fees.

Select the type of visa you're applying for. The various types include different durations and entry types. Make sure to choose the one that matches your travel plans.

Please select the date you will be arriving at your destination. This date will help us determine the validity period of your visa.

Enter your first name and middle name exactly as they appear in your passport, using letters A-Z.

Enter your last name exactly as it appears in your passport, using letters A-Z. If you don't have a last name, enter "N/A."

Select your date of birth from the dropdown menus. Make sure this matches the date of birth listed in your passport.

Enter your email address. We'll use this to send you updates about your application. You won't be enrolled in any promotional messages unless you click the checkbox below.

Select the nationality as it appears on your passport. This must match the nationality on the passport you're using for this application.

Check this box if you want to skip entering your passport information at this moment. You'll need to provide this information later to complete your application.

Stay up to date on new UK ETA services, exclusive offers, and helpful travel information.You'll have full control to unsubscribe anytime.

Privacy Policy

The present statutory instrument administers the collection, retention, processing, and onward transmission of personal data submitted by The Declarant to Fast ETA Portal.

Ref: GB-ETA-PRIV-21-2026 · Effective Date: 01 September 2025

Identity of the Data Controller & Applicable Frameworks

Fast ETA Portal, a private third-party administrative facilitator, acts in the capacity of data controller for the purposes of the present instrument and administers the collection, processing, safeguarding, and disclosure of personal particulars submitted by The Declarant when accessing this website or utilising the Electronic Travel Authorisation document review and application assistance services.

Administrative facilitation is extended to Declarants resident in the European Union (EU), the United Kingdom (UK), and the United States (US). Accordingly, the present instrument is aligned with the following statutory frameworks:

  • EU General Data Protection Regulation (EU GDPR – Regulation 2016/679).
  • UK GDPR & Data Protection Act 2018.
  • California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA).
  • Applicable United States state privacy legislation and international data privacy instruments.

All inquiries pertaining to the present instrument, requests concerning data rights, or communications addressed to a supervisory authority are to be transmitted via the electronic correspondence address set forth in the Notice below.

Categories of Personal Data Collected

(a) Particulars Furnished Directly by The Declarant. For the discharge of the present application, the following particulars are collected:

  • Identification Particulars: Full name, date of birth, gender, and nationality.
  • Travel Document Particulars: Passport number, issuance and expiration dates, issuing authority, and digital passport scans/images.
  • Verification Media: Facial photographs or selfies submitted for the verification of identity against the travel document.
  • Contact Particulars: Electronic correspondence address, telecommunication number, and home address.
  • Itinerary Particulars: Intended arrival dates, point of entry, and purpose of travel.
  • Statutory Declarations: Criminal background or offense declarations, strictly where mandated by official immigration entry questionnaires.
  • Billing Reference Particulars: Payment confirmation identifiers. (Complete credit/debit card particulars are transmitted directly to certified third-party payment processors and are never retained upon the portal's servers.)
  • Support Inquiries: Transcripts and correspondence transmitted through the designated contact channels.

(b) Technical & Usage Telemetry Collected Automatically. Upon navigation of the portal, the following is automatically collected:

  • Network identifiers (IP address and approximate geographic location).
  • Device characteristics, browser specifications, and operating system particulars.
  • Navigation paths, duration upon pages, referral links, and cookie interactions (see the Cookie Policy article below).

(c) Third-Party Data Sources. Where permitted by statute, verification signals may be received from accredited identity checks, anti-fraud systems, or payment processors for the validation of transactions.

Lawful Bases for Processing

Personal data is processed under the following defined lawful bases, in accordance with UK/EU GDPR:

Processing Purpose Categories of Data Lawful Ground
Processing of the Application Identification, passport particulars, travel data Performance of Contract
Identity Verification Passport scans, selfie images Performance of Contract / Explicit Consent
Immigration Safety Declarations Criminal history disclosures (where required) Legal Obligation / Public Interest (Art. 10 GDPR)
Payment Handling Payment references, order particulars Performance of Contract
Customer Support & Updates Contact particulars, interaction logs Performance of Contract / Legitimate Interest
Legal Compliance & Security Transaction history, IP logs Legal Obligation / Legitimate Interest
Site Optimisation & Analytics Cookie identifiers, interaction metrics Legitimate Interest / Consent
Marketing Communications Electronic correspondence address Explicit Consent (Opt-in)

Special Category Data, Biometrics & Automated Checks

Biometric Safeguards. Facial imagery and passport photograph uploads submitted for the confirmation of the Declarant's identity may be categorised as biometric data under applicable statute. Such sensitive particulars are handled under the Declarant's explicit consent and strict necessity:

  • Encryption: Biometric media is encrypted during transmission and storage using industry-standard protocols.
  • Access Control: Access is restricted strictly to technical personnel directly processing the Declarant's filing.
  • Zero Commercial Use: Biometric assets are at no time analysed for marketing, user profiling, or commercial resale.
  • Accelerated Erasure: Media files are purged under the accelerated erasure schedule set forth in the Retention Period article below.

Automated Checks & Human Oversight. Automated matching software is utilised to compare selfie images against travel document particulars for the detection of fraud. Such instruments assist — but do not supplant — human review. No final determination leading to rejection of the application or legal consequence is taken solely by way of automated processing. A manual human review of automated checks may be requested via the contact particulars set forth in the Notice below.

Cookie Policy & Tracking Management

This website utilises cookie files and analogous technical tracking instruments for the maintenance of portal stability, evaluation of site traffic, and support of Declarant preferences. Upon initiation of the portal, the presented banner permits selection of:

  • Accept All: Enables necessary, analytical, and functional optimisation cookies.
  • Necessary Only: Restricts tracking exclusively to essential operational cookies.

The categories of cookies deployed are as follows:

  • Strictly Necessary Cookies: Essential for session management, retention of application steps, portal security, and secure checkout. These cannot be disabled.
  • Analytics & Preference Cookies: Permit evaluation of visitor engagement, detection of software errors, and storage of language settings. Enabled solely with consent.

Preferences may be updated at any time by clearing browser cookies or by contacting the portal.

Onward Transmission & Third-Party Vendors

Personal data is not sold, let, or traded to third parties for marketing purposes. Data is transmitted solely to:

  • Immigration Authorities: The competent sovereign issuing authority and other relevant government departments (such as HM Government / Home Office) as necessary for the processing of the Declarant's travel authorisation.
  • Service Infrastructure Partners: Vetted third-party suppliers, including secure cloud hosting providers, encrypted payment processors, and customer support ticket systems, operating under binding Data Processing Agreements (DPAs).
  • Legal Authorities: Regulatory agencies, law enforcement, or judicial bodies where legally mandated.
  • Fraud Prevention Partners: Third-party anti-fraud engines for the evaluation of platform security risks.
  • Notice: The portal may contain links to external websites, software, or integrations. No control is exercised over, and no responsibility is accepted for, the content, security practices, terms, or privacy policies of any third-party site or service, and access to and use of such instruments is undertaken entirely at the Declarant's own risk. In order to discharge the present services effectively, trusted third-party service providers — for example, secure payment processors and customer support platforms — may be engaged, each of whom processes user data solely under binding data protection agreements.

Retention Period & Accelerated Erasure Schedule

Personal data is retained solely for such duration as is required for the discharge of the present service and the fulfilment of statutory obligations.

General Schedule

  • Application Text Records (name, travel dates, contact particulars): retained for 12 months from submission for the resolution of service inquiries, and thereafter securely archived or erased.
  • Criminal History Declarations: conclusively destroyed within 2 to 4 days following submission of the application to the competent authorities.
  • Financial & Order Records: retained for 7 years for the satisfaction of accounting and taxation audit requirements.
  • Support Inquiries: retained for up to 3 years from the last interaction.

Accelerated Biometric Erasure Schedule

Raw passport images and facial verification photographs are erased under accelerated timelines, as follows:

Triggering Event Erasure Timeline
Application Approved & Delivered Erased within 24 hours
Application Rejected by the Government Erased within 24 hours
Application Cancelled by the Declarant Erased Immediately
Full or Partial Refund Processed Erased within 24 hours
Incomplete/Abandoned Application Erased automatically (14 days)

Data Security Measures

Rigorous technical and organisational controls are enforced for the safeguarding of personal data against unauthorised access, loss, or alteration. Such measures include AES-256 encryption at rest, TLS encryption in transit, strict role-based access limits, and regular security audits. In the unlikely event of a security incident affecting the Declarant's rights, the relevant supervisory authorities and affected Declarants shall be notified as required by statute.

Protection of Minors

The present services are not intended for the independent use of individuals under 18 years of age. A minor may apply solely through a parent, legal guardian, or authorised representative who submits particulars on the minor's behalf. Children's particulars furnished for family travel filings are administered with security and retention protections identical to adult filings. Where it is suspected that a minor has submitted particulars directly without parental authorisation, the portal is to be contacted via the Notice below for immediate erasure.

Direct Marketing

Where the Declarant opts in to receive promotional updates or service announcements, periodic electronic correspondence may be transmitted. Consent may be withdrawn at any time via the "Unsubscribe" link appearing within any communication, or by contacting support.

Instrument Modifications

The present instrument may be updated to reflect changing regulatory requirements or service enhancements. Revisions shall be published upon this page with an updated effective date.

Rights of the Data Subject & Region-Specific Provisions

The Declarant is entitled to the following rights, subject to the region-specific provisions set forth below:

  • Right of access to personal data.
  • Right of rectification of inaccurate particulars.
  • Right of erasure, subject to statutory retention obligations.
  • Right of restriction of processing.
  • Right of data portability.
  • Right of objection to processing on grounds of legitimate interests.

European Union (EU) Residents. Fast ETA Portal acts as the data controller for personal data processed via this website. Transfers of EU personal data outside the European Economic Area (EEA) rely upon European Commission-approved Standard Contractual Clauses (SCCs) to guarantee equivalent protection. Under the EU GDPR, the Declarant maintains the right to lodge a complaint with the competent local EU Data Protection Authority.

United Kingdom (UK) Residents. Processing of UK data subjects is conducted under UK GDPR and the Data Protection Act 2018. Transfers outside the UK utilise the UK International Data Transfer Agreement (IDTA) or Addendum. The Declarant may contact the Information Commissioner's Office (ICO) at www.ico.org.uk or 0303 123 1113 for supervisory concerns.

United States Residents (including California CCPA/CPRA). Categories collected in respect of United States Declarants comprise identifiers, commercial records, passport/biometric particulars (for verification), geolocation data, and device activity. Personal data is not sold or shared for third-party targeted advertising. California residents possess the following additional rights:

  • Right to Know & Access: Request particulars regarding personal data collected over the past 12 months.
  • Right to Delete: Request removal of personal information, subject to statutory retention exemptions.
  • Right to Correct: Request correction of inaccurate personal records.
  • Limit Sensitive Data Use: Request limits upon the processing of sensitive identifiers (passport numbers, biometric verification files).
  • Non-Discrimination: Services shall not be denied, nor pricing altered, for the exercise of privacy rights.

United States requests are to be submitted via the contact form with the subject line "US Privacy Rights Request". Verified requests are acknowledged and processed within state-mandated timelines (e.g., 45 days for the CCPA).

Notice · Submission of Requests
Requests pertaining to the rights enumerated above, or any other privacy inquiry, are to be transmitted using the contact form.