Awareness Lessons
4 months ago
Amadeus IT Fined €14.4M for Unlawful Secondary Use of Passenger Data
Amadeus IT Group violated GDPR by repurposing passenger name record (PNR) data collected for travel reservations to test a new product without obtaining proper consent or providing adequate notification to data subjects. The company relied on a generic privacy policy that was insufficient for their B2B Global Distribution System service, failing to meet the transparency requirements of GDPR Article 14. This case demonstrates that organizations cannot assume broad consent covers secondary data uses, especially when the original data collection context differs significantly from new purposes.
Tactical Insight
Immediate actions
- Conduct data mapping audit to identify all secondary uses of personal data beyond original collection purposes
- Review and update privacy notices to explicitly cover all actual data processing activities
- Implement consent management systems that capture specific consent for each data use purpose
Long-term improvements
- Establish data governance committees to review and approve any new uses of existing personal data
- Implement privacy-by-design principles requiring GDPR impact assessments for new product development
- Create role-based training programs on data protection requirements for product and engineering teams
Compliance monitoring
- Deploy automated monitoring tools to detect when personal data is accessed for purposes not covered by existing consent
- Establish regular audits of data processing activities against documented lawful bases