Document policy
Handle every record with purpose.
The rules that apply when a client stores or asks MSA to prepare, review, organise, or transmit a maritime record.
Version document-processing-2026-08-22 · Effective 22 August 2026An MSA status confirms only the internal administrative review described. It does not replace authentication by the issuer, recognition by a flag State, or acceptance by an employer, school, embassy, or competent authority.
1. Client ownership and authority
The client retains rights in their document content and instructs MSA how it may be used. The client must be the document subject or have lawful authority from that person. Uploading another person's passport, certificate, medical record, or employment record without authority is prohibited.
2. Permitted purpose
Files may be uploaded only for an identified MSA service, secure career record, expiry reminder, readiness review, or client-directed application. MSA will not reuse a document for advertising, train a public artificial-intelligence model with it, or share it for an unrelated purpose.
3. Document-processing authorisation
Before the first upload, the client must authorise MSA to store, scan for malware, classify, display back to the account holder, and allow authorised MSA reviewers to inspect the file for the client's case. The authorisation can be withdrawn for future uploads. Withdrawal does not undo processing already required to complete an instructed submission, resolve a complaint, meet law, or preserve a legal claim.
4. No automatic external sharing
Portal upload authorisation is not permission to send a file outside MSA. External sharing requires a separate instruction that identifies the service, purpose, and intended recipient or recipient category. MSA should record that instruction and disclose the minimum necessary file or fields.
5. Authenticity obligations
The client must submit a complete, legible, unaltered copy and disclose any correction, name variation, loss, expiry, restriction, or known authenticity concern. Cropping for legibility is permitted only if security features and relevant content remain visible. Fabricated, stolen, purchased, materially edited, or unlawfully obtained records are forbidden.
6. Review levels
- Stored: uploaded and associated with the client account.
- System checked: file type, signature, size, and malware screening passed.
- Agency reviewed: an MSA reviewer checked apparent readability, consistency, dates, and suitability for the stated checklist.
- Issuer verified: authenticity was confirmed through a competent issuer or official register and the evidence/source is recorded.
- Recipient accepted: the intended third party confirmed acceptance for its own purpose.
MSA must not use “issuer verified” or “recipient accepted” unless the corresponding evidence exists.
7. Medical and highly sensitive records
Upload only the minimum medical-fitness evidence requested. Do not upload full clinical notes, genetic data, biometric templates, criminal records, financial passwords, payment-card data, or unrelated family documents. MSA may quarantine or delete material that creates disproportionate risk or is not required.
8. Physical originals
MSA normally works with secure copies. A physical original may be accepted only under a separately signed custody receipt recording the document, condition, purpose, responsible person, storage, handover history, and return deadline. MSA will never retain a passport as security for payment or employment.
9. Security, versions, and access
Files are stored outside the public website, access is checked against the signed-in account, and replacements create versioned records. Authorised staff access is role-controlled and auditable. Clients should remove a file when it is no longer needed and immediately report mistaken upload or suspected account access.
10. Retention, deletion, and legal holds
The Privacy Notice retention schedule applies. Client deletion removes the live document record through the platform workflow; encrypted backup remnants age out through the rolling backup cycle. MSA may temporarily preserve a copy where law, a fraud investigation, an active complaint, a competent order, or defence of a legal claim requires it and will document the reason.
11. Refusal and reporting
MSA may refuse, quarantine, or suspend a file where malware, forgery, theft, impersonation, unlawful processing, sanctions risk, or material inconsistency is reasonably suspected. MSA may report conduct only where required or permitted by applicable law and should preserve confidentiality and procedural fairness.
Questions or rights requests
Contact MSA through the protected enquiry route.
Use the contact form for legal, privacy, cancellation, or complaint matters. Do not include passport numbers, medical information, or document copies in the public form.
Contact the agency