Back to Feed
Privacy FinesOct 9, 2026

Italian DPA fines Emirates EUR 180 000 for infringements concerning passengers’ health data

Italian DPA fines Emirates EUR 180,000 for GDPR infringements regarding passenger health data.

Summary

The Italian Data Protection Authority (DPA) has fined Emirates EUR 180,000 for violating GDPR principles related to the processing of passenger health data. The investigation, triggered by a passenger complaint, found that while collecting health data via a MEDIF form could be lawful for assistance, Emirates failed to provide clear and transparent information. Additionally, a seven-year data retention period was deemed excessive.

Full text

Italian DPA fines Emirates EUR 180 000 for infringements concerning passengers’ health data National News 09 October 2026 it Background informationDate of final decision: 14 May 2026National caseController: EmiratesLegal Reference(s): Article 5 (Principles relating to processing of personal data), Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject) and Article 13 (Information to be provided where personal data are collected from the data subject)Decision: Administrative fine, Compliance orderWebsite topics: Health and research, Basic principlesSummary of the DecisionOrigin of the case The Italian Data Protection Authority (DPA) initiated an investigation following a complaint lodged by a passenger concerning the processing of health data by Emirates in connection with assistance for passengers with disabilities or reduced mobility.The complainant stated that Emirates had required her to complete a MEDIF (Medical Information for Fitness to Travel or Special Assistance) form, although she claimed not to fall within the categories of passengers required to do so. The form collected information concerning passengers’ health, as well as data relating to their doctor and any accompanying person. The complainant also raised concerns about the information provided regarding the processing of such data.Key FindingsAfter consulting the Italian Civil Aviation Authority, the Italian DPA found that the processing of health data through the MEDIF form could be lawful where necessary to ensure safe air transport and provide appropriate assistance to passengers with disabilities or reduced mobility. Therefore, it found no infringement of Articles 5(1)(a)-(c), 6(1) and 9 GDPR concerning the lawfulness of collecting such data.However, Emirates failed to provide sufficiently clear, complete and transparent information about the processing. Passengers could not easily determine in advance whether their condition required completion of the MEDIF form, or clearly identify relevant information such as the purposes, legal bases and retention periods.The Italian DPA also found that the seven-year retention period applied to MEDIF data was excessive in relation to the purposes of assessing fitness to fly and providing assistance during the journey.DecisionThe Italian DPA imposed an administrative fine of EUR 180 000 on Emirates for infringements of Articles 5(1)(a), 5(1)(e), 12 and 13 GDPR.The Italian DPA also ordered Emirates, within 30 days, to bring the processing into compliance. In particular, the company must clearly identify the categories of passengers required to complete the MEDIF form and specify which sections and fields are necessary. It must also establish appropriate retention periods for MEDIF data and delete data retained beyond the newly defined period.In determining the fine, the Italian DPA took into account, among other factors, the limited number of passengers concerned compared with Emirates’ overall customer base, the absence of an intention to discriminate against the complainant, the corrective measures imposed and the absence of previous data protection infringements by the company.For further information: Decision concerning Emirates (IT) Relevant topics Health and research Basic principles Latest news RSS Feed National News it Italian DPA fines BBVA EUR 5 508 000 for failing to respect a customer’s objection to direct marketing09 October 2026 National News se Swedish DPA fines Miljödata i Karlskrona approximately EUR 160 000 for insufficient technical and organisational measures to ensure information security08 October 2026 National News nl Dutch DPA fines Uber EUR 824 990 000 for unlawful automated decision-making and insufficient information on profiling08 October 2026All news

Entities

Emirates (vendor)