One thing comes to mind is the personally identifiable information (PII) that is in the passport/ID. Usually it will have ID numbers but also name, address, etc.
Look at what the EU is requiring for this - it used to be called Safe Harbor.
A few things I remember about those requirements:
- data encryption at rest and in transit
- no onward transfer to third parties
- opt-out methods for users to not allow you to capture the data
You may want to look into any restrictions on using a cloud provider or specific configurations you may need (i.e. no failover to a non-AU AWS farm).