Italian DPA fines Emirates EUR 180 000 for infringements concerning passengers’ health data
Italy's data protection authority fined Emirates €180,000 following an investigation into how the airline handled passengers' health data. The ruling cited violations of GDPR principles on lawful processing, transparent communication, and disclosure obligations at the point of data collection.
Why this matters: Airlines collect sensitive health data and most passengers have no practical way to opt out or even know what is happening to that information. Italy's finding covers the basics: Emirates did not process the data on sound legal footing and did not tell people clearly what their data was being used for. These are not technical violations. They are the foundation of what privacy law is supposed to guarantee. A €180,000 fine is not large for a global carrier, so the compliance order attached to it matters more than the penalty itself.
Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals · AI governance · General readers · Policy
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.