GDPR
Amadeus Hit with Record €18 Million Fine for Unauthorized Data Profiling
The Spanish Data Protection Agency (AEPD) has issued a massive fine against Amadeus for reusing traveler data without consent for a profiling pilot project.
Landmark Enforcement Against Data Misuse
In a landmark ruling that sends a clear message to the aviation and IT sectors, Spain's data protection authority, the AEPD, has fined Amadeus IT Group €18 million. The enforcement decision stems from a traveler profiling pilot project where the company was found to have reused customer data without obtaining the necessary legal consent or providing adequate transparency to the individuals involved. This case highlights a critical risk area for many enterprises: the temptation to use existing data repositories for 'innovation' or 'testing' without verifying if such use is legally permissible under the General Data Protection Regulation (GDPR).
Deep Dive into GDPR Violations
The AEPD's investigation identified significant breaches of Article 6 and Article 14 of the GDPR. Article 6 requires a valid legal basis for all processing activities, and the agency found that Amadeus could not rely on 'legitimate interest' for such intrusive profiling. Furthermore, Article 14 was violated because Amadeus failed to inform travelers—whose data was obtained indirectly—about how their profiles were being constructed and used. Even though Amadeus made a voluntary payment of €14.4 million to receive a 20% discount, the severity of the fine underscores that 'repurposing' data for secondary projects without a fresh compliance review is a high-stakes gamble.
Practical Steps to Prevent Privacy Violations
To avoid similar multi-million euro fines, FORTSECURE GLOBAL advises organizations to treat data reuse with extreme caution. Practical steps include: 1. Always perform a Data Protection Impact Assessment (DPIA) before starting any pilot project that involves profiling or large-scale data analysis. 2. Adhere strictly to the 'Purpose Limitation' principle; if you collected data for a flight booking, you cannot automatically use it for behavioral profiling. 3. Maintain an accurate and up-to-date Record of Processing Activities (ROPA) to ensure every data flow has a documented legal justification. 4. Implement 'Privacy by Design' by using anonymized or synthetic data for testing and development whenever possible, rather than real production data.
แหล่งที่มา: Data Protection Report เผยแพร่ครั้งแรก: Mon, 15 Jun 2026 09:26:08 +0000 บทความต้นฉบับ: อ่านต้นฉบับ
Source Attribution
แหล่งที่มา: Data Protection Report
เผยแพร่ครั้งแรก: Mon, 15 Jun 2026 09:26:08 +0000
บทความต้นฉบับ: https://www.dataprotectionreport.com/2026/06/record-e18m-fine-for-amadeus-from-spanish-data-protection-agency-for-gdpr-violations-related-to-use-of-traveller-data-without-consent/
* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์
