Data Protection & GDPR

Immigration casework involves personal and often sensitive information. This page sets out how we handle it under UK data protection law.

Our Legal Framework

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Personal data is used fairly, lawfully and transparently, for specified and explicit purposes, and is not used in any way incompatible with those purposes.

How We Handle Sensitive Immigration Information

  • Data minimisation: we collect only the information a case genuinely requires
  • Accuracy: information is kept accurate and, where necessary, up to date
  • Retention: data is kept for no longer than necessary, then securely deleted or anonymised
  • Security: access controls and secure systems protect against unauthorised access, loss or damage
  • Confidentiality: client information is treated as confidential and shared only where necessary to progress a case or as required by law

Third-Party Processors

Where we use third-party systems or processors (for example secure case-management or document-storage systems), we work with providers who can demonstrate appropriate data protection standards.

Your Rights

Individuals have rights under UK GDPR, including the right to access, correct or, in some circumstances, request deletion of their personal data. Our full Privacy Policy sets out how to exercise these rights.

Staff Responsibilities

All staff handling client information are trained on their data protection responsibilities as part of our induction and ongoing compliance processes, consistent with our Information Security policy.

Related Information

Contact Us About Data Protection

For a data protection query, or to exercise a data-subject right, contact our team directly.

Reviewed by the Morgan Smith Immigration team — IAA-regulated UK immigration specialists. Last reviewed 2026-09-23.

Scroll to Top