PrivacySignal
Enforcement

Amadeus IT Group Receives GDPR Fine

Inside Privacy (Covington) · · International · Enforcement

Spain's data protection authority fined Amadeus IT Group €18 million for GDPR violations tied to its Global Distribution System, which powers booking and travel data infrastructure used across the global travel industry. Amadeus voluntarily paid the fine, receiving a 20% reduction for doing so.

Why this matters: Amadeus is not a brand most travelers recognize, but its systems sit behind an enormous share of the world's flight, hotel, and travel bookings. That means the data at issue is not abstract — it is itineraries, passport details, payment records, and travel histories for millions of people. A fine this size signals that regulators are willing to go after the infrastructure layer, not just the consumer-facing companies. If the pipes that carry your data are not compliant, the fact that you never heard of the company running them does not protect you.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

The Attacker Did Not Need to Sleep

Spain received its first reported personal-data breach carried out by an AI agent. The techniques were familiar. The speed and autonomy were not.

· 4 min read Read →

Related stories

Enforcement
BleepingComputer · · International

IQVIA fined $7.8 million for failing to properly anonymize health data

Italy's data protection authority fined IQVIA €7 million after finding that the company's anonymization practices were inadequate, leaving roughly one million patients at risk of being re-identified from their health data.

Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals · AI governance · General readers · Policy

#enforcement#healthcare#gdpr#privacy Read original →
Enforcement
DataBreaches.net · · International

South Korea’s President Lee Jae Myung orders thorough probe into data breaches at local banks

South Korean President Lee Jae Myung has ordered a formal investigation into a recent series of data breaches at financial and public institutions, amid growing concern about AI-powered cyberattacks targeting the sector.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Administrators · General readers · Policy

#enforcement#ai-governance#ai Read original →
Enforcement
C CT Mirror · · International

Data privacy lawsuit, subsidies for childcare staff: CT politics news

A data privacy lawsuit is among the political stories making news in Connecticut, alongside a separate measure involving subsidies for childcare workers. Details on the parties, claims, and current status of the lawsuit were not provided.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
T Top Class Actions · · International

$3.5M MDLive data privacy class action settlement

MDLive, a telehealth company, has agreed to a $3.5 million settlement to resolve a class action lawsuit over alleged data privacy violations.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →