SECURITY — GDPR
Passports, visas, payments, health data and Saudi transfers: practical questions every European Umrah agency should address.
Umrah agencies process identities, passport copies, photographs, visas, payments and sometimes health or mobility information. Data protection is therefore an operational responsibility, not a legal checkbox.
A file may move between sales, visa, finance, hotels, carriers and Saudi partners. Agencies need to know who accesses each data category, for what purpose, how long it is retained and where it is sent.
The CNIL processing register guidance provides a practical framework for documenting these decisions.
Passport → WhatsApp · Photo → email · Payment → spreadsheet · Visa → external portal
Every copy expands exposure and makes correction, deletion and incident response harder. Centralisation can reduce duplication and associate each document with the correct traveller and trip.
Sales, visa and finance teams do not need the same information. Apply role-based access, remove permissions when staff leave and use authentication proportionate to risk. Personal data must not be retained indefinitely; the CNIL explains that periods follow purpose and applicable obligations.
Saudi visa and operational processes may require data to leave the EEA. Identify what leaves, who receives it, why, and the applicable Chapter V mechanism. Cloud, OCR, messaging and AI providers also form part of the processing chain and require appropriate assessment and contracts.
Unauthorised access to passports may constitute a personal-data breach. All breaches must be documented. Risk-bearing breaches may require supervisory notification without undue delay and, where feasible, within 72 hours; high-risk cases may also require informing affected people.
Software can support compliance but cannot make an agency automatically compliant. OmraDesk provides structure; each agency remains responsible for its real-world processing decisions.
See how OmraDesk brings agency operations together while each organisation remains responsible for its own compliance.