Today in Surveillance:
- Lighthouse Reports published 'The Visa Empire: Borders as a Business' on May 28, 2026, the product of a year-long investigation with 14 media partners across four continents. The piece is the first major structural look at VFS Global, the world's largest visa-outsourcing vendor, and is the shareable long-form on the visa-industrial complex for the week of May 28.[1]
- VFS Global runs visa application centres for 71 governments, including the US, UK, the entire Schengen zone, Canada, and Australia. Most applicants outside Europe will have queued at a VFS centre to apply for a visa. The vendor was founded in 2001 and is now a multi-billion-dollar company. Its current ownership includes Blackstone (a major Trump donor) and Dubai's ruling family. The vendor handles the biometric intake for the majority of the world's 'weak-passport' visa applicants.[1][2]
- The investigation found a 'manifestly serious' pattern of GDPR violations: bribery of visa applicants by VFS staff, repeated mishandling of personal data, and aggressive (and at times dishonest) upselling of optional services to applicants who often cannot tell VFS apart from the embassy itself. VFS's profits increased fourfold between 2017 and 2024. The growth came from selling add-on services (SMS updates, courier returns, premium lounges) on top of the mandatory service fee, with staff paid on sales-target bonuses.[1][3]
- Lighthouse obtained inspection and monitoring reports from 22 EU member states under freedom-of-information law, plus leaked European Commission documents showing that EU governments know about the violations and rarely act. EU diplomatic sources confirmed to Lighthouse that they were aware of the problems. The internal 'monitoring' system that EU law requires for outsourced visa service providers is, in practice, a paper exercise.[1][4]
- The investigation's structural argument: VFS Global is a private surveillance contractor that governments have offloaded a core state function to, with no independent audit of where the biometric data ends up, no public procurement accountability, and a sales-pressure model that puts the most vulnerable applicants in front of the most aggressive upsellers. The biometric intake is the surveillance core. The upselling is the profit engine. The two are structurally linked. The vendors that handle biometric intake should not be the same vendors that profit from making the application process miserable.[1][5]
- Watch in the next 7 days: the first EU member-state government to suspend a VFS contract in response to the investigation, the first European Parliament committee hearing notice citing the Lighthouse investigation, the first named VFS applicant to file a class action under GDPR Article 82, the first public procurement record of a government actually auditing VFS biometric data flows, and the first response from Blackstone (the Trump-donor owner) to the profit-fourfold / GDPR-violation framing.
What Landed on May 28, 2026
Lighthouse Reports published 'The Visa Empire: Borders as a Business' on May 28, 2026, the product of a year-long investigation with 14 media partners across Africa, Asia, Europe, and the Middle East.[1] The piece is the first major structural look at VFS Global, the world's largest visa-outsourcing vendor, and is the shareable long-form on the visa-industrial complex for the week of May 28.
The investigation has three structural pieces, and the three pieces are the data points that matter for the privacy and border-immigration beats in 2026.
First, the vendor. VFS Global was founded in 2001 and now runs visa application centres for 71 governments, including the US, UK, the entire Schengen zone, Canada, and Australia. Most applicants outside Europe have queued at a VFS centre to apply for a visa. The vendor is now a multi-billion-dollar company. Its current ownership, per the investigation, includes Blackstone (a major Trump donor) and Dubai's ruling family. The vendor handles the biometric intake for the majority of the world's 'weak-passport' visa applicants. The vendor is not a small contractor. The vendor is the infrastructure.[1][2]
Second, the profit engine. VFS's profits increased fourfold between 2017 and 2024. The growth came from selling add-on services (SMS updates, courier returns, premium lounges) on top of the mandatory service fee, with staff paid on sales-target bonuses. Lighthouse analysed financial statements of VFS and its subsidiaries in Luxembourg and India, and found that value-added services accounted for 30% of VFS's revenue in a 2,000-receipt sample drawn from Swedish-embassy visa applications in 16 Asian and African countries. A VFS India subsidiary reported pre-tax margins of up to 70% on its value-added services business. The profit engine is the upselling. The profit engine is also the corruption risk. Current and former VFS staff told Lighthouse that bonuses for selling value-added services could amount to almost twice the base salary. Contractors in Nigeria are paid about 126 euros a month, with the bonus contingent on hitting monthly sales targets. The pressure to upsell is structural.[1][3]
Third, the EU oversight failure. Lighthouse obtained inspection and monitoring reports from 22 EU member states under freedom-of-information law, plus leaked European Commission documents showing that EU governments know about the violations and rarely act. The internal 'monitoring' system that EU law requires for outsourced visa service providers is, in practice, a paper exercise. EU diplomatic sources confirmed to Lighthouse that they were aware of the problems. The governments that contract VFS to run their visa application centres are also the governments that are supposed to monitor VFS. The conflict of interest is structural. The 'manifestly serious' GDPR-violation framing in the investigation comes from the experts Lighthouse consulted on the leaked documents. The framing is not a Lighthouse editorial position. The framing is a legal assessment of the document set.[1][4]
Three structural pieces, one vendor. The vendor is the visa-industrial complex. The vendor is also the surveillance-industrial complex. The biometric intake that VFS runs for 71 governments is the same biometric intake that, in any other context, would be subject to a data-protection impact assessment under GDPR or its non-EU equivalents. The biometric intake at a VFS centre is subject to no equivalent assessment. The biometric intake is the contract, not the audit.
The Vendor Profile: 71 Governments, 60+ Countries, One Vendor
VFS Global was founded in 2001 as a joint venture between the Kuwaiti MEA (Middle East Affairs) Group and the Swiss Kuoni travel group. The vendor is now headquartered in Dubai and Zurich, and operates visa application centres in 60-plus countries. The 71 government clients include the US Department of State, the UK Home Office, the entire Schengen zone (operating through individual member-state consulates), the Government of Canada, the Australian Department of Home Affairs, and dozens of others. The vendor also runs passport-renewal services and biometric-enrollment services in countries that do not have the domestic capacity to handle the volume.[1]
Blackstone acquired a majority stake in VFS Global in 2023, via the EQT VIII fund. The deal valued VFS at a reported 2.5 billion euros. Blackstone's co-founder and senior chairman, Stephen Schwarzman, is one of Donald Trump's largest individual donors and was the chair of Trump's Strategic and Policy Forum during the first Trump administration. EQT is a Stockholm-based private equity firm with close ties to the Wallenberg family. Dubai's ruling Al Maktoum family holds a stake via the MEA Group. The ownership concentration is the structural explanation for why VFS has been able to grow profits fourfold in seven years while remaining unaccountable to the governments that contract it. The owners are not the governments. The owners are private equity. The owners have a different return-on-capital horizon than the governments.[1][2]
The vendor profile matters because it changes the conversation. VFS is not a niche outsourcing firm. VFS is the dominant infrastructure for the visa application layer of the global border. The vendor is the place where the 'weak-passport' applicant (the applicant from a country whose passport requires a visa to enter Europe, the US, the UK, Canada, or Australia) has their first and often only direct interaction with the border. The vendor is also the place where the biometric data is collected, stored, and transmitted to the requesting government. The vendor sits between the applicant and the state. The vendor is a private intermediary that the state has chosen to outsource a core state function to.
That choice has consequences. The state is no longer the first responder to the applicant. The vendor is. The vendor is not a neutral pass-through. The vendor is a profit-maximizing intermediary with sales targets and bonus structures. The state has, in effect, hired a private surveillance contractor to be the first face the applicant sees. The first face is the upsell face. The first face is the upsell face because the vendor's profit model requires it to be.
The Data Flow: Faces, Fingerprints, and No Audit Trail
The biometric intake at a VFS centre is, in structural terms, the most sensitive data-flow in the global visa system. The applicant walks in, presents their passport, and submits to fingerprint capture, facial-image capture, and sometimes iris-scan capture. The data is encrypted in transit. The data is supposed to be transmitted only to the requesting government's visa-processing system. The data is supposed to be retained for the duration of the application, then deleted. The data is supposed to be subject to the data-protection law of the country where the centre operates.
None of those 'supposed-to' statements is independently audited. The Lighthouse investigation found that VFS has 'manifestly serious' GDPR violations, per the experts quoted, and that contracting governments know about the violations but rarely take meaningful action. The investigation did not surface a single public audit of VFS's biometric data flow. The investigation did not surface a single government record of an independent data-protection impact assessment under GDPR Article 35. The investigation surfaced internal EU documents showing that governments are aware of 'consistent deficiencies' in VFS's service, and that the EU's own diplomatic service has documented the gaps. The EU's own monitoring is a paper exercise.[1][5]
The structural problem is not the encryption. The structural problem is the absence of a public audit trail. The applicant has no way to verify that the biometric data was transmitted only to the requesting government. The applicant has no way to verify that the biometric data was deleted after the application was processed. The applicant has no way to verify that the biometric data was not shared with the VFS parent, the VFS subsidiary, the VFS subcontractor, or any third party. The applicant has no way to verify because no one has been required to publish a verification. The vendor's contracts with the governments that hire it are not public. The vendor's data-flow architecture is not public. The vendor's audit reports are not public.
The data-flow opacity is the surveillance core. The same faces that go through a visa application in Lagos, Dhaka, or Lima end up in a database whose governance no one has ever audited. The governance gap is not an accident. The governance gap is the business model. A vendor that allows its data flows to be audited would have to disclose that the data flows are wider than the contract. A vendor that does not allow its data flows to be audited can keep the data flows as wide as the engineering allows. The Lighthouse investigation is the first major structural disclosure of how wide the data flows are. The 'manifestly serious' framing is the first major legal assessment of how wide the data flows are.
The comparison that matters is the EU AI Act biometric-identification regime. Under the EU AI Act, the use of real-time remote biometric identification in publicly accessible spaces by law enforcement is a high-risk AI use case, with a tiered set of obligations including fundamental-rights impact assessments, judicial pre-authorization, and prior independent testing. VFS's biometric intake does not fall under that regime, because the intake happens in a 'private' space (a visa application centre), not a 'publicly accessible' one. The legal classification is a loophole. The functional equivalence is not. The functional equivalence is: a private vendor running a biometric-collection infrastructure at scale, with no public audit, no fundamental-rights assessment, and no judicial pre-authorization. The structural argument of the investigation is that the legal classification is wrong, and that the functional equivalence should pull the activity into the EU AI Act regime or its non-EU equivalent.
The Geopolitical Dimension: Whose Data, Whose Governments, Whose Audit
The geopolitical dimension of the Lighthouse investigation is the most-underreported piece. The 71 governments that contract VFS are a mix of Western visa-issuing states (the US, UK, Schengen, Canada, Australia) and a much larger set of non-Western governments whose citizens are the primary applicants (Nigeria, India, Bangladesh, Pakistan, DRC, Angola, Turkey, Saudi Arabia, the UAE, and dozens of others). The data flow is asymmetric. The Western visa-issuing states collect the data. The non-Western applicants submit the data. The private vendor in the middle handles both. The audit gap is the gap no one is structurally motivated to close.[1]
The Trump-donor angle is the second geopolitical piece. Blackstone's Stephen Schwarzman is one of Trump's largest individual donors. The 2023 VFS acquisition happened under the Biden administration, but the ongoing contract relationships with the US Department of State are happening now. The 2025-2026 expansion of US visa social-media screening (covered on this site) is being implemented at VFS centres in dozens of countries. The State Department is contracting the vendor that handles the biometric intake to also handle the social-media disclosure intake. The vendor is the integration point. The vendor is the place where the biometric and the social-media data converge. The vendor is also the place where the audit-gap meets the Trump-donor ownership.[1][2]
The Dubai ruling-family angle is the third geopolitical piece. Dubai's MEA Group is the original Kuwaiti-Dubai partnership that founded VFS in 2001. The Maktoum family retains a stake. The headquarters is in Dubai. The data centres are, per the vendor's own disclosures, distributed across the UAE, India, and a small number of other jurisdictions. The audit question that follows: which governments can request access to the biometric data on file at VFS data centres, and on what legal terms? The UAE does not have a public data-protection regime equivalent to the GDPR. The UAE does have bilateral law-enforcement cooperation treaties with dozens of countries. The combination is the structural data-flow concern. The combination is not a hypothetical. The combination is the operating environment.[1]
Three geopolitical pieces, one vendor. The vendor is a private equity-owned, Dubai-headquartered, multi-government-contracted biometric data-handling infrastructure with no independent audit and a sales-pressure profit model. The privacy and border-immigration beats have a single shared structural problem. The structural problem is the vendor. The structural problem is the lack of an audit. The structural problem is the absence of public accountability for the private equity owner, the Dubai co-owner, the 71 contracting governments, and the EU oversight regime that was supposed to be monitoring all of it.
Where Things Stand on June 15, 2026 (18 Days After Publication)
- First EU member-state government to suspend a VFS contract in response to the investigation. The EU's own diplomatic service has documented the gaps. A member-state government that has the political will to actually act could use the Lighthouse document set as the public justification. Watch for the first announcement from a Schengen member state. The likeliest candidates are the governments that have been most critical of outsourcing in public procurement: Germany, France, the Netherlands, the Nordics.
- First European Parliament committee hearing notice citing the Lighthouse investigation. The European Parliament's LIBE committee (Civil Liberties, Justice and Home Affairs) has jurisdiction over EU visa policy and the Schengen visa code. The LIBE committee is the natural venue. Watch for the first hearing notice, the first letter from a LIBE member to the European Commission, or the first parliamentary question tabled in plenary.
- First named VFS applicant to file a class action under GDPR Article 82. GDPR Article 82 gives any data subject the right to compensation for material or non-material damage suffered as a result of an infringement of the GDPR. The Lighthouse document set is the public evidence base. A consumer-rights NGO or a privacy-litigation firm could use the article to file a representative action. Watch for the first filing, the first law-firm press release, or the first noyb (Max Schrems' organization) statement.
- First public procurement record of a government actually auditing VFS biometric data flows. The Lighthouse investigation found that no government has published an independent audit of VFS's biometric data flows. A government that audits and publishes the audit would be the first structural accountability data point. Watch for the first FOIA response, the first parliamentary question answer, the first European Ombudsman decision, or the first EDPB (European Data Protection Board) opinion.
- First response from Blackstone (the Trump-donor owner) to the profit-fourfold / GDPR-violation framing. Blackstone's communications team has not yet issued a public statement. The 2023 acquisition was the largest single piece of VFS ownership. The owner has a fiduciary duty to defend the investment. Watch for the first Blackstone press release, the first Stephen Schwarzman interview, the first VFS Global CEO statement, or the first EQT fund investor letter.
- First non-EU government to suspend a VFS contract. The US Department of State, the UK Home Office, and the Australian Department of Home Affairs are the three largest non-EU VFS customers. A suspension from any one of them would be a major structural data point. Watch for the first State Department cable, the first UK Home Office procurement notice, or the first Australian immigration minister statement.
- First African or Asian visa applicant government to file a data-protection complaint against VFS. The non-EU side of the VFS data flow is the least-regulated side. A data-protection authority in Nigeria, India, Bangladesh, Pakistan, or the Philippines could use the Lighthouse document set as the basis for a complaint. Watch for the first Nigeria Data Protection Commission action, the first Indian Ministry of Electronics and Information Technology statement, or the first Philippines National Privacy Commission filing.
- First major data-breach disclosure involving VFS-held biometric data. The Lighthouse document set establishes that VFS's data-protection practices are not at GDPR standard. A breach disclosure would be the first concrete data-loss event. Watch for the first CERT-EU advisory, the first CISA advisory, the first national CERT notification, or the first ransomware group claiming to have exfiltrated VFS biometric data.
The Bottom Line
Lighthouse Reports published 'The Visa Empire: Borders as a Business' on May 28, 2026, the product of a year-long investigation with 14 media partners. The investigation found that VFS Global, the world's largest visa-outsourcing vendor with 71 government clients, has built a multi-billion-dollar business on top of a 'manifestly serious' pattern of GDPR violations, aggressive upselling of optional services to visa applicants with weak passports, and biometric data flows that no government has audited. Owners include Blackstone (a major Trump donor) and Dubai's ruling family. EU diplomatic sources told Lighthouse that governments know about the violations and rarely act. Semafor confirmed the Blackstone ownership. Politico framed the 'big business' angle. Le Monde anchored the EU-side policy debate. The Indian Express published the EU on-site inspection report.
The structural argument is that VFS Global is a private surveillance contractor that governments have offloaded a core state function to, with no independent audit of where the biometric data ends up, no public procurement accountability, and a sales-pressure model that puts the most vulnerable applicants in front of the most aggressive upsellers. The biometric intake is the surveillance core. The upselling is the profit engine. The two are structurally linked. The vendors that handle biometric intake should not be the same vendors that profit from making the application process miserable. The privacy and border-immigration beats have a single shared structural problem. The structural problem is the vendor. The structural problem is the lack of an audit. The structural problem is the absence of public accountability.
The first 18 days since publication are the first-cycle data point: the first EU member-state to suspend a VFS contract, the first European Parliament LIBE hearing notice, the first GDPR Article 82 class action, the first public audit of VFS biometric data flows, the first Blackstone response to the profit-fourfold framing, the first non-EU government suspension, the first non-EU data-protection complaint, and the first major data-breach disclosure involving VFS-held biometric data. The investigation is the disclosure. The structural problem is the vendor. The first 18 days have produced no contract suspensions, no class-action filings, no public audit, and no Blackstone statement. The disclosure has not yet changed the vendor's operating environment. The disclosure is being absorbed. The cycle-2 question, ahead of the EU GDPR 8-year anniversary on June 16, is whether the next round of follow-up reporting surfaces the first structural accountability data point, or whether the vendor continues to absorb the disclosure.
Sources
- Lighthouse Reports: The Visa Empire: Borders as a Business (May 28, 2026; the primary investigative piece, the year-long investigation with 14 media partners, the 71-government scope, the GDPR-violation framing, the EU monitoring report data set, the leaked European Commission documents, and the on-the-record interviews with dozens of former VFS staff across Africa, Asia, and the Middle East)
- Semafor: Blackstone's VFS banks mega profits on African visa applicants (the Semafor co-publication, the Blackstone ownership confirmation via the EQT VIII fund, the 'mega profits on African applicants' framing published May 28 as part of the package, and the structural financial-statement analysis of the value-added services business)
- Politico: How a company turned visas to Europe into big business (the Politico co-publication, the 'turned visas to Europe into big business' framing, the EU-side policy context, and the Brussels insider framing of the outsourcing trend)
- The Indian Express: VFS Global visa operations: 20-member EU team came to India with focus on gaps, problems and remedies (the Indian Express co-publication, the EU on-site inspection of VFS centres in India, the 20-member EU team, and the India-specific operational concerns about gaps, problems, and remedies)
- Le Monde (Les Décodeurs): Comment la privatisation de la gestion des visas a profité à la société VFS Global, entre 'services optionnels facturés' et soupçons de corruption (the Le Monde Les Décodeurs co-publication, the 'privatization of visa processing' framing, the 'optional services charged' vs 'suspicions of corruption' tension, and the structural-argument anchor for the EU policy debate; French original, no English translation)
Published: June 15, 2026