Back to all lessons
Awareness Lessons
4 months ago

Amadeus IT Fined €14.4M for Unlawful Secondary Use of Passenger Data

Amadeus IT Group violated GDPR by repurposing passenger name record (PNR) data collected for travel reservations to test a new product without obtaining proper consent or providing adequate notification to data subjects. The company relied on a generic privacy policy that was insufficient for their B2B Global Distribution System service, failing to meet the transparency requirements of GDPR Article 14. This case demonstrates that organizations cannot assume broad consent covers secondary data uses, especially when the original data collection context differs significantly from new purposes.

Tactical Insight

Immediate actions

  • Conduct data mapping audit to identify all secondary uses of personal data beyond original collection purposes
  • Review and update privacy notices to explicitly cover all actual data processing activities
  • Implement consent management systems that capture specific consent for each data use purpose

Long-term improvements

  • Establish data governance committees to review and approve any new uses of existing personal data
  • Implement privacy-by-design principles requiring GDPR impact assessments for new product development
  • Create role-based training programs on data protection requirements for product and engineering teams

Compliance monitoring

  • Deploy automated monitoring tools to detect when personal data is accessed for purposes not covered by existing consent
  • Establish regular audits of data processing activities against documented lawful bases