Back to all lessons
Awareness Lessons
4 months ago

Amadeus Fined €14.4M for Unlawful Secondary Use of Passenger Data

Amadeus IT Group violated GDPR by repurposing passenger name record (PNR) data collected for travel reservations to test a new product without proper consent or legal basis. The company failed to inform data subjects about this secondary processing purpose and could not justify the use under legitimate interest provisions. This case highlights that organizations cannot freely repurpose personal data for new uses without explicit consent or valid legal justification, even for internal testing purposes. Generic privacy notices are insufficient when processing involves indirect data subjects in B2B scenarios.

Tactical Insight

Immediate actions

  • Conduct data processing impact assessments before any secondary use of personal data
  • Review all current data processing activities to ensure proper legal basis and consent
  • Update privacy notices to specifically address all processing purposes including testing activities

Long-term improvements

  • Implement data governance frameworks requiring approval for any new data processing purposes
  • Establish clear procedures for obtaining valid consent when repurposing personal data
  • Train development and product teams on GDPR requirements for data reuse

Monitoring measures

  • Deploy data lineage tracking to monitor how personal data flows through different systems
  • Regular audits of data processing activities to ensure compliance with stated purposes
  • Implement automated alerts when data is accessed for purposes not covered by original consent