Italy's privacy watchdog fines Emirates over handling of passenger health data - Finance news and analysis from Global Banking & Finance Review
Finance

Italy's privacy watchdog fines Emirates over handling of passenger health data

Published by Global Banking & Finance Review

Posted on June 17, 2026

2 min read

· Last updated: June 17, 2026

Add as preferred source on Google

Italy Fines Emirates €180,000 for Mishandling Passenger Health Data and Privacy

Emirates Penalized Over Passenger Health Data Handling

Background of the Case

ROME, June 17 (Reuters) - Italy's data protection authority said on Wednesday it had fined the Emirates airline €180,000 ($208,890) for the allegedly unfair handling of health data of passengers with reduced mobility.

Complaint Details

• The case stemmed from a complaint by a passenger who said Emirates had made her fill in a medical form even though she was not among the categories required to submit such documentation.

Regulator's Findings

Lawfulness of Data Processing

• The Italian regulator found that the processing of health data itself was lawful as necessary to guarantee safe transport and assistance, but identified breaches on transparency and data storage limits.

Transparency and Privacy Issues

• The authority said Emirates failed to provide sufficiently clear and complete privacy information, either on its website or through staff assisting passengers.

Data Retention Concerns

• It also found that the airline retained health data collected via medical forms for seven years, which it considered excessive and disproportionate.

Emirates' Response

• Emirates was not immediately available for comment.

Exchange Rate Information

($1 = 0.8617 euros)

Reporting Credits

(Reporting by Giulia Segreti, editing by Alvise Armellini)

Key Takeaways

  • The Garante ruled health data collection by Emirates was permissible to ensure safe transport but found shortcomings in transparency and data retention policies.
  • Emirates failed to clearly inform passengers through its website or staff, and stored medical data for seven years—considered disproportionate by the regulator.
  • Compared with other recent GDPR fines in Italy—ranging from €12.5 million against Poste Italiane to €31.8 million against Intesa Sanpaolo—this represents a relatively modest penalty, reflecting the scale and nature of the breach.

Frequently Asked Questions

Why was Emirates fined by Italy's privacy watchdog?
Emirates was fined for allegedly unfair handling of passenger health data, with issues in transparency and excessive data retention.
How much was Emirates fined for data privacy violations?
Emirates was fined €180,000 ($208,890) by Italy's data protection authority.
What specific breaches did the Italian regulator identify?
The regulator found a lack of clear privacy information and that Emirates retained health data for seven years, which was deemed excessive.
What triggered the investigation into Emirates' data handling practices?
A complaint from a passenger who was asked to fill in a medical form led to the investigation.
Was the collection of health data by Emirates considered lawful?
Yes, the processing was lawful for transport and assistance, but the breaches involved transparency and data storage limits.

Tags

Related Articles

More from Finance

Explore more articles in the Finance category