The only substantial contracts the Foreign and Commonwealth Office (FCO) has for the processing of personal data are with two commercial partners responsible for the collection and administration of visa applications from foreign nationals wishing to travel to the UK. Both contracts contain clauses committing the partner to conformity with ISO27001, the international standard relating to the security of data systems, requiring auditable processes, and to compliance with the provisions of the Data Protection Act. The contracts also provide for surprise audits of partner premises by UKvisas. More generally, FCO model contracts contain specific clauses obliging the contractor to abide by the provisions of the Data Protection Act and empowering the FCO to ensure compliance.