[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjV5i3qtmQY76W8AGpBXCO2rsW39VeYDou9TyNGnFrrM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":46},"57ade3dc-a76e-4951-bddd-7cf89cab1b9a","emirates-fined-180k-for-failing-to-inform-customers-about-health-data-processing","03ccea22-4734-434d-949b-31408599de74","Emirates Fined €180K for Failing to Inform Customers About Health Data Processing","Emirates violated GDPR transparency requirements by failing to adequately inform customers with limited mobility about how their health data was being collected and processed via an online form. Consent for sensitive health data — a special category under GDPR Article 9 — must be explicit, informed, and purpose-specific, none of which were satisfied here. This case highlights that lawful processing alone is insufficient; organizations must also meet strict notice and consent obligations independently. The fine serves as a reminder that privacy compliance is not a checkbox exercise but requires deliberate, user-facing communication design. Airlines and other service providers collecting health data for accessibility purposes are particularly exposed if their data collection forms lack clear, plain-language disclosures.","**Immediate actions:**\n- Audit all customer-facing forms that collect special category data (health, disability, etc.) to verify they include clear, plain-language privacy notices.\n- Ensure explicit consent mechanisms are implemented separately from general terms for any health-related data collection.\n\n**Long-term improvements:**\n- Embed Privacy by Design principles into the development lifecycle so that data transparency requirements are addressed before forms or features go live.\n- Establish a Data Protection Impact Assessment (DPIA) process for any processing involving special category data under GDPR Article 9.\n- Train product, marketing, and UX teams on GDPR transparency obligations (Articles 13 & 14) to prevent gaps at the design stage.\n\n**Governance & monitoring:**\n- Schedule periodic DPO-led reviews of all active data collection touchpoints to ensure ongoing compliance with notice and consent requirements.\n- Maintain a Record of Processing Activities (RoPA) that is regularly reconciled against live data collection forms to detect undisclosed processing.",[12,13,14,15,16,17,18,19],"GDPR Article 5(1)(a) – Lawfulness, fairness, and transparency","GDPR Article 9 – Processing of special categories of personal data","GDPR Article 13 – Information to be provided where personal data are collected from the data subject","GDPR Article 7 – Conditions for consent","NIST Privacy Framework PR.PO-P1 – Policies, processes, and procedures for privacy","CIS Control 3 – Data Protection","ISO\u002FIEC 27701 – Privacy Information Management System (PIMS)","ITIL Service Design – Privacy and data protection considerations in service design","published","2026-06-24T16:20:20.538961+00:00","2026-06-24T16:20:20.21+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_347\u002F2026&diff=52000&oldid=51977","garante-per-la-protezione-dei-dati-personali-italy-347-2026-c01d62","Garante per la protezione dei dati personali (Italy) - 347\u002F2026",[28,34,40],{"id":29,"name":30,"slug":31,"description":32,"color":33},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":35,"name":36,"slug":37,"description":38,"color":39},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":41,"name":42,"slug":43,"description":44,"color":45},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]