On 5 September 2026 the Syrian Ministry of Interior announced that INTERPOL had cancelled an alert covering 24,511 Syrian passports. The announcement came from Colonel Abdul Rahim Jabara, the Ministry’s director of international cooperation, and was reported by Enab Baladi and The New Arab among others. The story he told is short. In November 2024, just after Aleppo fell, the Assad government reported the passports stolen from an immigration and passports office in the city. They had not been stolen. They had been issued in the normal way and handed to their holders, who then spent close to two years travelling on documents that every border post in the world was told to treat as stolen. Some of them were detained. Some had the passport taken off them. Getting the alert lifted took what the Ministry calls sustained efforts by the INTERPOL bureau in Damascus, in continuous contact with the General Secretariat, and it ended, in Jabara’s words as reported by Enab Baladi, in “verification that the alert was incorrect and based on inaccurate facts.”
The tool behind all this is INTERPOL’s Stolen and Lost Travel Documents database, SLTD for short. Turkey used it against its opponents abroad a few years ago. Syria’s former government has now used it, in effect, against a population it had just lost. In between, nothing about the database’s safeguards has visibly changed, and the two proposals put to the U.S. Helsinki Commission in October 2024, at its briefing on countering authoritarian abuse of INTERPOL, are still sitting where they were left.
What the SLTD database is
The SLTD database holds records of travel and identity documents reported as stolen, lost, revoked, invalid or stolen blank. We described it, and the ways it gets misused, in a 2024 article. The numbers have grown since. INTERPOL now puts the database at around 138 million records, against about 99 million then. It was searched 3.6 billion times in 2023 and returned 232,423 hits. Few INTERPOL tools are consulted so often, for the simple reason that border officers run it at the moment a passport is handed over.
Two things about how it works matter here. Only the issuing country can record a document, through its National Central Bureau or another authorised agency. And there is no pre-publication check of the kind notices get. Every notice request has to be examined by the General Secretariat for compliance before it goes out (Article 77 of the Rules on the Processing of Data); the Notices and Diffusions Task Force, created in 2016, does that job. Nothing comparable exists in the Rules for an SLTD record. INTERPOL’s own page on the database describes how records are entered and how they are searched, and stops there. The public references to any review of SLTD data amount to one sentence in an interview and one paragraph in a letter, which we come to below.
The categories matter too. The database was built for stolen and lost documents. It now also takes documents reported as revoked or invalid, which turned a tool for catching fraudulent passports into a place where a government can record its decision to cancel a passport that is sitting in its owner’s pocket. The Commission for the Control of INTERPOL’s Files saw the problem when it was consulted on the “invalid” category, meant for expired, damaged or destroyed documents. Its 2018 activity report says the Commission “was concerned that this category could be misused or may not include an explanation as to why a document had been invalidated.” The General Secretariat’s response was to update the SLTD standard operating procedures, an internal document that has never been published.
The Turkish precedent
Turkey showed what the database could do for a government going after its opponents. According to Disclose, after the 2016 coup attempt the Turkish authorities cancelled hundreds of thousands of passports on political grounds and put some of them into SLTD. Leaked intelligence documents published by Nordic Monitor in February 2019 described the practice. People who had left the country learned about it at a foreign border. Two lawyers, Ali Yildiz and Ben Keith, set out the mechanics in Just Security in July 2023, and they note that Turkey’s own Constitutional Court has ruled three times that passport revocations and travel bans need a court order. The entries went in anyway.
Yildiz and Keith were writing after an open letter from 25 human rights lawyers and defenders, dated 5 June 2023, had asked the Secretary General to suspend Turkey’s access to the database until further checks were in place. The letter also asked for something more durable: a review mechanism for SLTD entries modelled on the one the Notices and Diffusions Task Force runs for notices. Their argument was about incentives. Turkey’s use of Red Notices had been restricted in 2018. A state that still wanted to reach a dissident abroad would look for the channel with the least scrutiny, and SLTD was it. The Secretary General answered on 23 June 2023. He rejected the allegations, said SLTD data must meet the conditions of INTERPOL’s Constitution and rules like any other data, wrote that the General Secretariat “remains vigilant” and that corrective measures had been applied to National Central Bureaus before, “including in relation to data uploaded to the SLTD database,” and pointed applicants to the right of access before the CCF. He did not take up the proposal for a review mechanism. Corrective measures are INTERPOL’s standard answer to misuse, and they have a problem of their own: INTERPOL almost never says which countries are under them, why, or for how long, a point developed in a Harvard International Law Journal piece co-authored by Charlie Magri earlier this year.
How big the problem was only came out later. In November 2024 the New York Times reported that Turkey and Belarus had turned the database “into a weapon to harass dissidents or strand them abroad,” that INTERPOL had at one point blocked Turkey from using it, and that Belarus was under special monitoring. The head of INTERPOL’s notices review team told the paper that INTERPOL was also looking at ways to expand oversight of the passport database. Nothing has been published on that since. Then in January 2026 Disclose cited an internal INTERPOL document it had seen. Close to 74,000 Turkish passports and travel documents had been deleted from the database between 2016 and 2021. According to the same document, Turkey recorded another 560 in 2023, all of which INTERPOL itself deemed problematic. In 2021 INTERPOL placed Turkey under corrective measures, which Disclose describes as enhanced supervision of its Red Notices and messaging. Those measures were lifted in under three years. A January 2025 memo from the corrective measures team, quoted by Disclose, says that “requests from Ankara continue to pose challenges” and that “despite improvement in terms of statistics, the non-compliance percentage remains higher than for most countries.” The memo speaks of Turkish requests generally, not of SLTD in particular.
So Turkey was dealt with by deleting entries after the fact, blocking access for a while, and a spell of corrective measures that has ended. No public rule came out of it.
Syria, 2024 to 2026
Syria fits the same pattern, with one twist: the government that made the entries is gone. Its bureau had itself been under INTERPOL corrective measures from December 2012 until October 2021, when the General Secretariat lifted them with a promise to “continue to carefully monitor the NCB’s activities.” Three years later, the bureau filed the batch. The Assad administration reported 24,511 passports stolen just after it lost Aleppo. Whatever it meant by that, the effect was to flag the documents of more than 24,000 people who had just come under opposition control. The entries stayed live through the fall of Damascus in December 2024 and for twenty-one months after it. They came out in September 2026, at the request of the successor government, after what that government describes as sustained follow-up with the General Secretariat.
Notice what was, and was not, wrong with those entries from INTERPOL’s side. They were made by the issuing country, as the rules require, so on paper they were in order. They arrived in bulk. And nobody affected could have known. There is no notification when a passport goes into SLTD, no summary, nothing the traveller can see. The first anyone hears of it is a border officer looking at a screen. The Ministry says people were detained and had passports confiscated in several countries because of the alert; it does not say how many, or where, or whether every passport has since been given back.
Which raises the question this case turns on. Between a National Central Bureau entering a record and a border officer seeing the flag, is anything checked, by whom, and against what? INTERPOL has said a little on the subject, in general terms. Its rules say less. Both are set out below.
Review without rules
INTERPOL does say SLTD data is reviewed. Carla Delle Donne, Counsel Coordinator of the Notices and Diffusions Task Force, told INTERPOL Spotlight that the team’s main focus is notices and diffusions, “but we also review for compliance data recorded in other tools, such as our Stolen and Lost Travel Documents database.”
Add the Secretary General’s 2023 letter, with its vigilance and its past corrective measures, and that is the entire public record on the subject. Neither text says when a record is looked at, on what trigger, against what criteria, or by whom. With 138 million records and entries arriving tens of thousands at a time, the Task Force plainly cannot examine each one, and INTERPOL does not claim it does. There are no figures for SLTD entries reviewed, blocked or deleted, although INTERPOL now publishes exactly that for notices and diffusions.
The rules underneath are thinner still. When the Secretary General answered the 2023 open letter, he wrote that SLTD information, like all data in INTERPOL’s databases, “must meet the conditions defined in INTERPOL’s Constitution and rules.” Fair enough, but which conditions? For SLTD they can only be the general principles of the Rules on the Processing of Data that apply to every piece of data in the system: Article 10 on purpose, Article 11 on lawfulness, Article 12 on quality. Under Articles 11 and 12 the recording country answers for the lawfulness and accuracy of what it enters, and the General Secretariat has to “put in place the mechanisms and tools to guarantee compliance.” That is the whole of it. Notices have their own set of articles (73 to 96). Diffusions have theirs (97 to 101). Travel documents have no article at all: nothing on what a country must show before it records a passport as stolen, revoked or invalid, nothing on what INTERPOL does when 24,511 of them land in one batch. What exists instead are standard operating procedures, revised after the CCF raised its concern in 2018 and never published.
Syria is the test of that arrangement, and the result is on the record. A collapsing government reported 24,511 passports stolen in one go, in the days after it lost its second city, and the entries sat there for twenty-two months. If some compliance review of SLTD entries is running, it did not catch this. The new government had to raise it, and even then it took what the Ministry calls sustained efforts to get the entries out.
The individual route is not much better. Anyone flagged in the database can ask the CCF for access to the data and for deletion. Having no SLTD-specific conditions to apply, the Commission falls back on Articles 11 and 12 and asks the recording country for the legal framework and the reasons behind the entry. Two published decisions show how that plays out. In CCF-2019-04, a passport recorded as revoked and seized at an airport was deleted because the provisions the country cited dealt with issuing passports, not cancelling them, and the country never produced the revocation decision or the arrest warrant the Commission asked for, despite several requests. In CCF-2024-03, the entry was kept: the country produced a court decision banning the applicant from travel and cancelling his passport, and the applicant’s evidence of misuse was a newspaper article and a report on his country’s SLTD practice in general, which the Commission held said nothing about his case. The remedy exists, then, but the whole exercise is one passport at a time, for the person who files, and slow. The CCF Statute gives the Commission four months to decide an access request and nine months to decide a deletion request (Article 40). It no longer holds those deadlines. Its 2024 report shows 30 percent of deletion requests running past nine months, double the year before, and the Chairperson has said the position will get worse before it improves. For someone whose passport is flagged, that is the better part of a year, often more, of not travelling while the file works its way through.
None of this is new. Charlie Magri, founder of Otherside, made the same two points to the U.S. Helsinki Commission on 29 October 2024, when asked whether abuse of the database can be prevented (the exchange is in the official transcript). One: INTERPOL should adopt clear rules for entering data into SLTD and put them in the Rules on the Processing of Data, including a requirement for a court decision before a passport is recorded as revoked, so that the entry rests on a legal ground and not a political one. Two: checking every entry before it goes in is unrealistic at this volume, so INTERPOL should at least set up a review mechanism that runs basic checks on the data. Neither has happened. A batch of 24,511 records from a state in the middle of losing a war is about as obvious a candidate for a basic check as one could invent. It got none that anyone can point to.
Where this leaves INTERPOL
Red Notices are now reviewed before publication, and the rejection statistics INTERPOL publishes show the review is real. Blue and Green Notices came under pre-issuance review in 2024. Each time one channel is tightened, the pressure moves to the next. SLTD is the biggest of INTERPOL’s tools and among the most consulted, it has the least written rule around it, and a traveller cannot see an entry until a border officer does. Turkey exposed the weakness. Syria has exposed it again from the opposite direction: a collapsing regime flagged the documents of a population it had just lost, and the flags outlived the regime by nearly two years.
INTERPOL has the text it needs, and the two Helsinki proposals map onto two different gaps.
The first gap is the rule. The Rules on the Processing of Data set conditions for notices, diffusions and analysis files; travel documents need an article of their own. It would say what a country has to show before a passport is recorded as revoked, invalid or stolen, and it would require a court decision where the passport has been revoked or invalidated, so that the entry rests on a legal ground and not a political one. A rule of that kind is written once, adopted by the General Assembly, and binds every National Central Bureau the day it enters into force.
The second gap is the compliance mechanism, and a rule does not fill it on its own. Notices have one: the Task Force, its criteria, its published refusal figures. SLTD has a sentence in an interview and a paragraph in a letter. What is needed is a mechanism that is set up, documented and published, so that everyone knows what is checked and how. It does not have to check everything. At 138 million records nobody could, and nobody is asking for that. It could work on triggers, and the obvious trigger is volume. When a country submits a large number of documents at once, say more than a few hundred in a single batch, the records would be held before going live. The General Secretariat would draw a random sample of documents from the batch and ask the recording country for the evidence behind each one sampled: the police report of the theft, or the decision cancelling the passport. If the evidence holds, the batch goes live. If it does not, the batch does not. That is the check the CCF already performs, one file at a time, when an applicant complains; the difference is doing it before the flag reaches the border, not years after. Twenty-four thousand passports reported stolen from one office, in a city that had just changed hands, would not have survived it.
The court-decision rule would not have touched the Syrian case, which was dressed as theft. A published mechanism with a volume trigger would have. Until INTERPOL has both, a written rule for travel documents and a compliance mechanism it has documented and made public, the next 24,511 passports are a question of when.
Charlie Magri is the founder of Otherside, a specialist law firm dedicated exclusively to INTERPOL and CCF matters. He is a former Legal Officer at the Secretariat to the Commission for the Control of INTERPOL’s Files.
Stopped at a border over a passport flagged in INTERPOL’s systems?
Otherside files access and deletion requests before the Commission for the Control of INTERPOL’s Files, including for entries in the Stolen and Lost Travel Documents database. If a passport has been reported stolen, revoked or invalid without a lawful basis, contact us for a confidential review.




