Passport stamps inside an open travel passport, the kind of document VFS Global processes for 71 governments across more than 160 countries
Photo via Unsplash

Today in Surveillance:

  • Lighthouse Reports, in collaboration with 14 media outlets, published a year-long investigation on May 28, 2026 into VFS Global, the private equity-owned contractor that processes visa applications for 71 governments and operates in more than 160 countries. The investigation, co-published the same day with Semafor, Le Monde, Politico, The Indian Express, and 10 other outlets, found that VFS Global's handling of applicant personal data amounts to what experts called "manifestly serious violations of the GDPR."[1][2]
  • Semafor's same-day partner piece reported that VFS Global's operating profit rose fourfold between 2017 and 2024 to €172 million ($200 million), on visa-application volume that grew only 15% in the same period. Semafor, citing Lighthouse, also reported that the agency processed about 26 million people in 2024, and that revenue per application rose 41% since pre-pandemic levels.[2]
  • VFS Global's services include biometric collection, identity verification, and online application assistance, and the contractor holds the data of applicants whose passports flag them as 'weak' under the visa regimes of the countries that outsource to it. Wikipedia's company profile lists biometric collection as a core service, and VFS Global's 2023 UK Visas and Immigration contract alone covers 142 countries through 240 Visa and Citizenship Application Service Centres.[3] The 22 Schengen-zone countries that contract VFS Global have documented the firm's data-handling failures in inspection and monitoring reports obtained by Lighthouse Reports via Freedom of Information requests.[1]
  • VFS Global is majority owned by the Blackstone Group, with Singapore state-owned Temasek Holdings as a significant minority stakeholder since October 2024, and the company's owners include what Lighthouse describes as 'a major donor to Donald Trump and Dubai's ruling family.' The investor base tells you who has a financial interest in the visa-frontend market staying private and the data-protection conversation staying quiet.[1][2][3]
  • Watch in the next 7 days: the first named EU member state to publish a Lighthouse-cited inspection report in full, the first published text of the European Commission's leaked diplomatic-service report on VFS Global's deficiencies, the first response from a contracting government to the May 28 data-protection findings, and the first published VFS Global internal training or marketing document showing how add-on service sales are pitched to applicants.

The Investigation: Lighthouse, 14 Outlets, 22 EU Countries, One Vendor

On May 28, 2026, Lighthouse Reports published "The Visa Empire: Borders as a Business," a year-long investigation into VFS Global produced in collaboration with 14 media outlets.[1] The partner list is the canonical evidence that the story is not a single outlet's framing. The 14 outlets include Semafor, Le Monde, Politico, The Indian Express, News24, Le Monde, RFI, The Nation, Kisa Dalga, Twala, Actualite.cd, India Outbound, De Standaard, and Lighthouse Reports itself.[1] A separate Lighthouse methodology page, "How we turned visa receipts into evidence of VFS's add-on business," walks through the receipt-analysis chain that the consortium used to quantify the add-on revenue.[4] The methodology page is the canonical primary record for the consortium's evidence chain.

The investigation drew on hundreds of internal EU documents obtained through Freedom of Information requests, on financial statements filed by VFS Global and its parent entities, on the analysis of customer receipts, and on interviews with dozens of former VFS Global employees.[1] The FOIA documents included inspection and monitoring reports from 22 countries in the EU's Schengen free-travel zone that contract VFS Global, plus "dozens of EU documents evaluating member states' application of the Schengen laws, including the outsourcing of visa processing to companies including VFS."[1] Lighthouse also obtained leaked reports from the European Commission's own diplomatic service that "revealed EU governments are aware of consistent deficiencies in VFS's" operations.[1]

The headline finding was that VFS Global's handling of applicant personal data amounts to "manifestly serious violations of the GDPR," the language used by the experts Lighthouse consulted on the documentary record.[1] The companion finding was on the contractor testimony: former VFS staff in Kenya, Nigeria, Ethiopia, and India told the consortium that they were "trained by VFS Global to include charges for these services" and that "they often ended up doing so without applicants' consent."[2] One former staffer in India, the same Lagos-trained cohort, said customers were "compelled or fooled into buying the services," per Lighthouse's findings shared with Semafor.[2]

VFS Global, in a statement to Lighthouse and reproduced in the methodology page, said that "any suggestion that VFS Global's financial growth has been generated through improper conduct is false."[1] A redacted copy of VFS Global's 22-page response to Lighthouse, dated May 22, 2026, is hosted on Lighthouse's own site as a primary record.[5] The vendor's response is on the public record, and the consortium's findings are on the public record, and the documentary chain is now the canonical data-protection story of 2026.

VFS Global as a Vendor: 71 Governments, 160+ Countries, 100,000 Applications a Day

VFS Global is the world's largest visa-frontend contractor, and the scale is the story.

Zubin Karkaria, then CEO of Kuoni Travel, founded the company in July 2001 in Mumbai, India.[3] In its first year, the company won a US government pilot to process Indian visa applications at the Mumbai embassy, and in 2003 it acquired a UK Government contract to process visa applications from India.[3] By 2007, VFS Global had its first global account from UK Visas and Immigration for operations in 33 countries.[3] The growth is the trajectory of a vendor that figured out how to win government outsourcing contracts at scale, and then how to make the contracts more profitable per applicant than the original business case assumed.

As of January 31, 2026, VFS Global had 17,330 employees and offices in 147 countries, with a secondary registered headquarters in Zurich, Switzerland, in addition to its primary Dubai, United Arab Emirates, base.[3] In 2024 the company processed more than 100,000 applications daily and more than 100 million applications in the preceding five-year period, and the Semafor partner piece put the 2024 single-year figure at about 26 million people processed.[2][3] The Wikipedia profile lists seven "global contracts" with the governments of Austria, Australia, Iceland, Latvia, Norway, Sweden, and the United Kingdom, and the 2023 UK Visas and Immigration contract alone covers 84 new countries on top of 58 existing ones through 240 Visa and Citizenship Application Service Centres across 142 countries.[3]

The visa-frontend contract is the soft layer of the data-collection business. The hard layer is biometric collection. Wikipedia's profile, citing the 2026 global contracts, documents that under those contracts "VFS Global provides services such as biometric collection, identity verification, and online application assistance," and that under the Australia contract specifically the firm's "responsibilities include biometric data gathering, identity verification, and digital assistance for applicants on Australia's ImmiAccount portal."[3] Visa applicants in much of Africa, Asia, and the Middle East are required to provide fingerprints and photographs at VFS Global offices as part of the Schengen, UK, US, Canadian, and Australian application processes that the contractor operates.[1] The data flows from VFS Global offices into the receiving government's visa-decision systems, and the data also sits, for the duration of the application cycle, in VFS Global's own applicant-management systems.

The GDPR Failures: 'Manifestly Serious Violations' Across the Schengen Zone

The data-protection story is the live development, and the documentary chain is the news.

Lighthouse Reports' central finding on data protection is that VFS Global's handling of applicant personal data amounts to "manifestly serious violations of the GDPR," the language used by the experts Lighthouse consulted on the FOIA document set.[1] The Lighthouse methodology page documents the receipt-collection protocol, the financial-statement analysis, the FOIA chain to 22 Schengen-zone countries, and the contractor-interview protocols used by the 14-outlet consortium.[4] The methodology page is the documentary record of how the consortium assembled the evidence, and the documentary record is the reason the GDPR-violation finding is on the public record as something a regulator could act on.

EU member states are required under EU law to closely and regularly monitor outsourced visa service providers, and the Lighthouse FOIA chain produced inspection and monitoring reports from 22 Schengen-zone countries that contract VFS Global.[1] Lighthouse also obtained leaked reports from the European Commission's own diplomatic service, and the diplomatic reports "revealed EU governments are aware of consistent deficiencies in VFS's" operations.[1] The pattern is the one that defines a structural regulatory failure: a contractor is the front door for a Schengen visa, the contractor is breaking GDPR on the data, the 22 contracting governments have inspection reports that document the failures, and the European Commission's own diplomatic service has circulated reports that confirm the governments are aware.

The structural failure has a name in the data-protection literature. "Manifestly serious violations of the GDPR" is the threshold the European Data Protection Board uses to escalate a national supervisory authority's findings into a cross-border enforcement action, and the threshold is the bar at which Article 60 cooperation procedures turn into Article 63 consistency mechanisms.[1] VFS Global is named in inspection and monitoring reports from 22 Schengen-zone governments, the European Commission's diplomatic service has circulated reports documenting the deficiencies, and the contractor's own contractual counter-parties are the governments whose inspection and monitoring failed to act. The data-protection story is not a single national supervisory authority's finding. The data-protection story is a cross-border finding that has been documented internally for years and is now on the public record.

For visa applicants, the practical consequence is concrete. Applicants whose biometrics are collected at a VFS Global office are handing fingerprints, photographs, and travel documents to a vendor that the European Commission's own documents say has been operating with consistent deficiencies. The data flows on to the receiving government's visa-decision system, and the data sits, for the application cycle, in VFS Global's systems. The data-protection question is not whether the receiving government will protect the data. The data-protection question is who is responsible for the data while it sits in the vendor's systems, and what the vendor's GDPR obligations are when its counter-parties are governments that have documented the vendor's deficiencies and have not acted.

The Biometric Angle: The Visa Application as a Data-Collection Event

The biometric collection is the part of the visa-frontend contract that the public conversation has not yet engaged with, and the privacy implications are real.

Under the 2026 global contracts that Wikipedia documents, VFS Global's services "include biometric collection, identity verification, and online application assistance" for Austria, Australia, Iceland, Latvia, Norway, Sweden, and the United Kingdom.[3] Under the Australia contract specifically, VFS Global's "responsibilities include biometric data gathering, identity verification, and digital assistance for applicants on Australia's ImmiAccount portal."[3] The Schengen biometric-data regime, which the EU has rolled out across the Schengen zone since the early 2010s, requires visa applicants in much of Africa, Asia, and the Middle East to provide ten fingerprints and a digital photograph as part of the application process, and VFS Global offices in those regions are the typical collection point for the Schengen biometric data.[1]

The privacy question is structural, not just procedural. A visa applicant who provides fingerprints and a photograph at a VFS Global office in Lagos, Dhaka, Nairobi, or Lima is providing those biometrics to a private contractor whose data-handling practices the European Commission's diplomatic service has documented as deficient, and whose GDPR compliance the experts Lighthouse consulted describe as "manifestly serious violations."[1] The receiving government will use the data to make the visa decision. The contractor will hold the data, and the contractor's GDPR obligations are the question. The contractor's incentive to invest in the data-handling infrastructure is the question. The contractor's record on data-handling is the answer to both questions, and the record is what the May 28 investigation is now on the public record.

The pattern is a familiar one in the 2026 surveillance beat, with a different vendor. Biometric collection is the data layer that turns a process into a surveillance-grade database, and the privacy story is always about who has the data, for how long, under what governance, and with what recourse. For Schengen visa applicants, the answer in 2026 is that the data is held by a private contractor whose ownership has shifted twice in the last five years, whose equity base includes the Blackstone Group and Singapore's Temasek Holdings, and whose handling of the data is the subject of a 14-outlet investigation published on May 28, 2026. The pattern is the structural question. The investigation is the structural answer.

The Profit Engine: A Fourfold Rise, 41% Revenue Per Application, Sales-Driven Bonuses

The financial story is the mechanism, and the mechanism is the policy story.

Semafor's same-day partner piece, citing the Lighthouse investigation's analysis of VFS Global's financial statements, reported that VFS Global's operating profit rose fourfold between 2017 and 2024 to €172 million ($200 million) on account of the sale of add-on services, even though visa applications within the period grew by only 15%.[2] The agency processed about 26 million people in 2024, and revenue per application rose 41% since pre-pandemic levels.[2] The fourfold rise in profit on a 15% rise in application volume is the single most important number in the investigation, and the number is the structural reason the contractor invests in the add-on business at the rate the documentary record documents.

The add-on business is not a side hustle. Lighthouse found that "staff are typically paid low base salaries and awarded bonuses contingent on meeting monthly sales targets for value added services, creating perverse incentives to sell."[1] A visa officer currently working at VFS Global in Nigeria told the consortium that "the bonuses for selling value added services could amount to almost twice the base salaries of contractors."[1] The same officer said contractors make up the majority of the VFS Global workforce and earn base salaries of around €150, with bonuses that can lift total compensation close to the €300 mark.[1] The bonus structure is the operational mechanism for the fourfold profit rise, and the operational mechanism is the documentary record Lighthouse has put on the public record.

The financial story has a precedent in the 2019 Independent investigation, which revealed that VFS Global's shareholders had extracted £567 million through "distribution to owner" payments and inter-company loan write-offs, and attributed the growth to "exploitative" business practices.[3] The 2019 pattern is the 2024 pattern is the 2026 pattern. The mechanism has been the same for at least seven years. The documentary record is now on the public record, in 14 outlets, in three languages, and the structural story is the same: a private equity-owned contractor, a sales-driven compensation model, and a contracting-government regulatory posture that has not produced enforcement.

Ownership and Geopolitics: Blackstone, Temasek, a Trump Donor, Dubai's Ruling Family

The investor base tells you who has a financial interest in the visa-frontend market staying private and the data-protection conversation staying quiet.

Wikipedia's profile documents the equity history. The Swedish private equity group EQT AB acquired VFS Global's then-parent Kuoni in 2016, and the tourism businesses were separated from VFS Global in 2017. EQT declared its intention to sell the company in January 2019, and in October 2021 the Blackstone Group acquired a majority stake.[3] In October 2024, the Singapore state-owned investment firm Temasek Holdings signed a purchase agreement to acquire a minority stake.[3] The current ownership disclosed on Wikipedia is The Blackstone Group at 75% and Temasek Holdings at 18%.[3] Kuoni and the Hugentobler Foundation remain minority stakeholders.[3]

The Lighthouse investigation added that the company's owners include "a major donor to Donald Trump and Dubai's ruling family."[1] The investor disclosure sits alongside the regulatory disclosure: 22 Schengen-zone countries have VFS contracts, the European Commission's diplomatic service has circulated reports on the contractor's deficiencies, and the contractor's owners include the single largest US private equity firm, a sovereign-wealth fund with a Singapore state mandate, and a major US political donor with ties to the current US administration. The political economy of the visa-frontend contract is a story about which governments have outsourced the function, which private equity firms have financed the vendor, and which regulators have the standing to enforce the data-protection rules.

The geopolitical dimension is the second-tier read. The Lighthouse investigation is, on its face, a 14-outlet story about a private vendor's data-protection failures. The geopolitical dimension is that the vendor's equity base, its contracting governments, and the applicants whose data is collected are all in different jurisdictions, and the data-protection question crosses all three. The 22 Schengen-zone governments are the data exporters, in GDPR terms, when the data leaves the vendor's system and enters the receiving government's system. The vendor is the data processor. The applicants are the data subjects. Three jurisdictions, three regulatory regimes, one vendor that all three are relying on, and the documentary record on May 28, 2026 is that the vendor has been operating with consistent deficiencies that the European Commission's own diplomatic service has documented internally for years.

What to Watch in the Next 7 Days

  • First named EU member state to publish a Lighthouse-cited inspection report in full. Lighthouse obtained inspection and monitoring reports from 22 Schengen-zone countries via FOIA, but the public release has been through the consortium's editorial coverage, not through the governments' own publication channels. The first national supervisory authority to publish a full inspection report on VFS Global's data handling, with a named supervisory finding, will be the first data point on whether the May 28 findings translate into a national enforcement action.
  • First published text of the European Commission's leaked diplomatic-service report on VFS Global's deficiencies. The leaked report is the strongest documentary record in the consortium's evidence chain. A formal Commission statement, a Commission response to a parliamentary question, or a published Commission position on the contractor's deficiencies will be the first EU-level data point on whether the diplomatic findings translate into a Commission-level enforcement action.
  • First response from a contracting government to the May 28 data-protection findings. UK Visas and Immigration, the Government of Australia, the Government of Canada, the governments of the Schengen-zone states with VFS contracts, and the governments of the 71 client countries on the Lighthouse list are all in scope. The first contracting government to publish a formal response, a corrective action plan, or a contract-review notice will be the first signal of the political read.
  • First published VFS Global internal training or marketing document showing how add-on service sales are pitched to applicants. The consortium's documentary record is the public record, and VFS Global's pre-publication 22-page response is also on the public record. A leaked internal training document, a leaked internal sales deck, or a leaked internal script showing how the add-on pitch is delivered at the front desk will be the first primary record from inside the contractor's own operations.
  • First published data-protection enforcement action against VFS Global by a national supervisory authority. "Manifestly serious violations of the GDPR" is the threshold the European Data Protection Board uses to escalate a national supervisory authority's findings into a cross-border enforcement action. The first published enforcement action, a fine, a corrective order, or a public statement from a named national Data Protection Authority, will be the first data point on whether the May 28 findings translate into a regulatory consequence.
  • First published disclosure of which VFS Global client governments have already sought to renegotiate or terminate their contracts. The 71 client governments and the 22 Schengen-zone governments are the political base. A leak of internal communications, a parliamentary question, or a published FOIA response showing a contracting government has opened a contract review or a termination process will be the first data point on whether the May 28 findings have moved the procurement conversation.

The Bottom Line

VFS Global is the private contractor that runs the visa-frontend operation for 71 governments and operates in more than 160 countries, and the contractor's services include biometric collection, identity verification, and online application assistance. Lighthouse Reports, in a year-long investigation published May 28, 2026 with 14 partner outlets, found that VFS Global's handling of applicant personal data amounts to "manifestly serious violations of the GDPR," and that 22 Schengen-zone countries had documented the deficiencies in inspection and monitoring reports obtained through Freedom of Information requests. Semafor's same-day partner piece put the financial story on the public record: operating profit up fourfold from 2017 to 2024 to €172 million, on visa-application volume that grew only 15%, with revenue per application up 41% since pre-pandemic levels.

The investor base is the political economy. The Blackstone Group holds 75%, Temasek Holdings holds 18%, and Lighthouse reports that the ownership also includes "a major donor to Donald Trump and Dubai's ruling family." The 22 Schengen-zone governments that contract VFS Global are the regulatory counter-parties whose inspection and monitoring reports document the deficiencies. The visa applicants in Lagos, Dhaka, Nairobi, and Lima are the data subjects whose fingerprints and photographs are collected at VFS Global offices as part of the Schengen, UK, US, Canadian, and Australian application processes.

The data-protection story is the shareable long-form. The contractor has been operating with documented GDPR deficiencies for years, the European Commission's diplomatic service has circulated reports on the deficiencies, the 22 contracting governments have inspection reports documenting the deficiencies, and the contractor's financial model is built on sales-driven compensation for staff on bonuses that can run to twice their base salaries. The 14-outlet consortium has put the documentary record on the public record. The regulatory consequence is the next seven days.

Sources

  1. Lighthouse Reports: The Visa Empire: Borders as a Business (May 28, 2026; the year-long Lighthouse investigation, co-published with 14 media partners including Semafor, Le Monde, Politico, The Indian Express, News24, RFI, The Nation, Kisa Dalga, Twala, Actualite.cd, India Outbound, De Standaard, and Lighthouse Reports itself; the FOIA chain to 22 Schengen-zone countries; the European Commission diplomatic service leak; the "manifestly serious violations of the GDPR" finding; the contractor testimony from Kenya, Nigeria, Ethiopia, and India; and VFS Global's pre-publication denial)
  2. Semafor: Blackstone's VFS banks mega profits on African, Asian visa applicants (Alexander Onukwue, May 28, 2026, 17:23 UTC, updated May 29, 2026 02:09 UTC; the Lighthouse partner piece that put the fourfold operating-profit rise from 2017 to 2024 to €172M ($200M), the 26 million people processed in 2024, the 41% revenue-per-application rise since pre-pandemic levels, and the contractor testimony from Kenya, Nigeria, Ethiopia, and India on the public record)
  3. Wikipedia: VFS Global (accessed June 15, 2026; the company profile documenting the July 2001 founding in Mumbai by Zubin Karkaria, the 17,330 employees as of January 31, 2026, the 147 countries, the 100,000+ applications daily and 100M+ in five years as of 2024, the seven global contracts with Austria, Australia, Iceland, Latvia, Norway, Sweden, and the United Kingdom, the 2023 UK Visas and Immigration contract covering 84 new countries and 58 existing ones through 240 VCAS Centres across 142 countries, the biometric collection, identity verification, and online application assistance services, the data-breach history, the equity history from EQT via Kuoni to Blackstone in October 2021 and Temasek in October 2024, and the current Blackstone 75% / Temasek 18% ownership)
  4. Lighthouse Reports methodology: How we turned visa receipts into evidence of VFS's add-on business (May 28, 2026; the Lighthouse methodology page documenting the receipt collection, the financial-statement analysis, the FOIA chain to 22 Schengen-zone countries, the contractor-interview protocols, and the documentary chain used by the 14-outlet consortium)
  5. Lighthouse Reports: VFS Global's redacted response to Lighthouse Reports (PDF, dated May 22, 2026; the 22-page redacted response VFS Global sent to Lighthouse Reports before publication, hosted by Lighthouse as a primary record of the vendor's pre-publication position and the documentary chain the vendor was asked to address)
  6. Hacker News: Lighthouse Reports VFS Global visa empire thread (news.ycombinator.com, item 48526908, May 28-29, 2026, 4 HN pts; the Hacker News discussion of the Lighthouse / Semafor / 14-outlet investigation, the shareable analysis thread, and the community signal on the data-protection framing)
  7. India Outbound: VFS Global Schengen visa process in spotlight as EU nations flag concerns (May 28, 2026; the Indian travel-trade outlet's coverage of the Lighthouse / 14-outlet investigation, the EU member-state concern thread, and the Schengen-zone regulatory signal)