The Italian authority imposes a €180,000 fine on Emirates for breaches of transparency and data retention limitations regarding passengers with reduced mobility

The Italian data protection authority sanctioned the airline Emirates for breaches related to transparency and the retention period of health data collected through its medical form, while recognizing the legitimacy of this collection in the name of aviation security.

Facts and context

The Italian data protection authority (GPDP) today published a sanction decision against Emirates, including the imposition of a €180,000 fine, for breaches related to the processing of health data of passengers with reduced mobility.

The case originated from a complaint filed on January 29, 2025, by a passenger who was required to complete a medical questionnaire, the Medical Information Form for Fitness to Travel or Special Assistance (MEDIF), without having received adequate prior information about the processing of her data.

Reasons for the decision

The authority first examined the lawfulness of the health data collection. After consulting the National Civil Aviation Authority (ENAC), it concluded that the processing was justified by reasons of substantial public interest related to air transport safety and the need to verify passengers' fitness to fly. Therefore, breaches of Articles 5(1)(a), (b), and (c), 6(1), and 9 of the GDPR were not upheld. However, violations were confirmed on other aspects.

  • Transparency obligation (Article 5(1)(a), 12 and 13 of the GDPR): The authority found that the information provided to passengers was insufficient. Neither the website page dedicated to the MEDIF form nor the general privacy policy contained specific, clear, and accessible information on the purposes, legal bases, and retention periods of this particular processing of health data. The subsequent addition of a link to the general policy was considered insufficient to ensure complete and intelligible information at the time of collection.
  • Retention limitation obligation (Article 5(1)(e) of the GDPR): The company retained the MEDIF forms for seven years after the trip. The authority deemed this duration excessive and not compliant with the storage limitation principle, as specified by Recital 39 of the GDPR. The main purpose, namely verifying fitness to fly, is achieved once the trip is completed. The justification for prolonged retention for potential litigation was considered too abstract and disproportionate, noting that the Montreal Convention provides a two-year limitation period for compensation claims.

Authority's decision

Consequently, the authority imposed a €180,000 fine on Emirates.

Furthermore, the authority ordered the company, within 30 days, to bring its processing into compliance. It must notably precisely define the categories of passengers and the information strictly necessary for collection, provide specific and clear information on the form page, and establish a retention period proportionate to the purpose, deleting data retained beyond this new duration.

Lessons learned

This decision reminds that:

  • Recognition of a substantial public interest as a legal basis for processing health data does not exempt the controller from respecting other GDPR principles, notably transparency and storage limitation.
  • Information provided to data subjects must be specific to the processing concerned and easily accessible at the time of data collection; a reference to a general privacy policy is insufficient, especially for sensitive data.
  • The retention period must be strictly aligned with the pursued purpose. Retention for legal defense must be based on a concrete and probable risk, not on a purely abstract possibility.
  • The data minimization principle requires collecting only strictly necessary information, which can be reflected by clearly identifying mandatory and optional fields in a form.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire