Airbnb Violated GDPR by Demanding ID for Erasure Requests
Airbnb Ireland UC violated GDPR by requiring a data subject to provide government-issued ID before processing a legitimate data erasure request, breaching the data minimization principle under Article 5(1)(c). Organizations are only permitted to collect personal data that is adequate, relevant, and limited to what is strictly necessary for the stated purpose. Demanding excessive identity verification for routine data rights requests creates unnecessary friction and constitutes an unlawful processing activity. This case underscores that compliance with data subject rights must be operationally embedded — not just policy-deep — to avoid regulatory enforcement. Even when the underlying request is ultimately fulfilled, the improper initial handling can still constitute a GDPR violation.
Tactical Insight
Immediate actions
- Audit all existing data subject request (DSR) workflows to ensure verification steps collect only the minimum data necessary to confirm identity.
- Remove or revise any policies that require government-issued ID or disproportionate proof of identity for standard erasure, access, or rectification requests.
Process & Policy improvements
- Establish a documented legal basis review for every data point collected during DSR handling, aligning with GDPR Articles 5, 6, and 17.
- Train customer-facing and privacy operations teams on lawful identity verification standards for data subject rights requests.
- Create clear internal guidelines distinguishing low-risk DSRs (requiring minimal verification) from higher-risk scenarios that may justify additional checks.
Governance & Monitoring
- Implement periodic internal audits of DSR handling procedures with DPO sign-off to catch disproportionate data collection before regulators do.
- Establish a feedback loop between legal, privacy, and operations teams to flag and resolve ambiguous verification requirements in near-real time.