[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhc6Iei2VdBe7ZmK4uE9lQyvzhQHBgj5TRnhgdhkMUVI":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"9d8a95bb-45ef-479c-b2f6-786c2aaed044","emirates-fined-180k-for-mishandling-passenger-health-data-under-gdpr","c5ce0139-508f-4601-b7c6-8b32635dedc3","Emirates Fined €180K for Mishandling Passenger Health Data Under GDPR","Emirates violated GDPR by failing to provide clear and transparent information to passengers when collecting sensitive health data through MEDIF forms, and by retaining that data for an excessive seven-year period. Transparency and data minimisation are foundational GDPR principles — individuals must know how their data is used, and organisations must not hold it longer than necessary. This case demonstrates that even when data collection may be lawful in purpose, the manner of collection and retention practices can independently constitute violations. A single passenger complaint was enough to trigger a regulatory investigation, illustrating how exposed organisations are when their data governance processes are inadequate.","**Immediate actions:**\n- Audit all health-related data collection forms (e.g., MEDIF) to ensure privacy notices are clear, complete, and compliant with GDPR Articles 13 and 14.\n- Review existing data retention schedules for sensitive personal data and reduce retention periods to the minimum necessary for the stated purpose.\n\n**Policy & governance improvements:**\n- Establish a formal Data Retention Policy with defined, legally justified retention periods for each data category, subject to regular review.\n- Appoint or engage a qualified Data Protection Officer (DPO) to oversee ongoing compliance with GDPR obligations for special category data.\n- Conduct Data Protection Impact Assessments (DPIAs) for all processing activities involving health or other special category data under GDPR Article 9.\n\n**Monitoring & accountability measures:**\n- Implement periodic internal audits of data collection workflows to verify that transparency obligations and retention limits are being met.\n- Establish a complaint-response protocol that triggers an internal compliance review whenever a data-related complaint is received from a passenger or customer.",[12,13,14,15,16,17,18,19,20],"GDPR Article 5(1)(a) – Lawfulness, fairness, and transparency","GDPR Article 5(1)(e) – Storage limitation","GDPR Article 9 – Processing of special categories of personal data","GDPR Article 13 & 14 – Information to be provided to data subjects","GDPR Article 35 – Data Protection Impact Assessment (DPIA)","NIST Privacy Framework PR.PO-P1 – Policies for data processing","NIST SP 800-53 IP-1 – Consent and Privacy Notice","CIS Control 3 – Data Protection","ISO\u002FIEC 27701 – Privacy Information Management System (PIMS)","published","2026-10-09T08:20:42.849931+00:00","2026-10-09T08:20:42.529+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.edpb.europa.eu\u002Fnews\u002Fitalian-dpa-fines-emirates-eur-180-000-for-infringements-concerning-passengers-health-data_en","italian-dpa-fines-emirates-eur-180-000-for-infringements-concerning-passengers-h-79e18b","Italian DPA fines Emirates EUR 180 000 for infringements concerning passengers’ health data",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]