Emirates Fined €180K for Unlawful Health Data Collection and Excessive Retention
Emirates collected sensitive health data from passengers with disabilities or reduced mobility without obtaining valid consent or providing clear privacy notices, violating foundational GDPR principles. The airline further failed to justify the retention period for this data, citing speculative future disputes as a basis — a rationale the Garante rejected as insufficient under the storage limitation principle. This case highlights that special category data (such as health information) demands a higher standard of lawful basis and transparency, not simply convenience or operational habit. Organizations that collect sensitive data without robust consent mechanisms and defined retention schedules face significant regulatory and reputational risk across the EU.
Tactical Insight
Immediate actions
- Audit all data collection forms and processes that capture special category data (health, disability) to verify a valid GDPR lawful basis exists for each.
- Review and update privacy notices to ensure they clearly explain what health data is collected, why, and for how long, in plain language accessible to passengers.
Long-term improvements
- Implement a formal data retention policy with documented, legally justified timeframes for each category of personal data, reviewed annually.
- Establish a Data Protection Impact Assessment (DPIA) process mandated for any new service collecting special category data before launch.
- Appoint or empower a Data Protection Officer (DPO) to conduct periodic compliance reviews of customer-facing data collection practices.
Detection & governance measures
- Introduce automated alerts or workflow gates that flag collection of special category data and require documented lawful basis approval before storage.
- Schedule regular third-party GDPR compliance audits covering consent management, retention schedules, and privacy notice adequacy.