Italian DPA fines Emirates EUR 180 000 for infringements concerning passengers’ health data

  • National News

Background information

  • Date of final decision: 14 May 2026
  • National case
  • Controller: Emirates
  • Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject) and Article 13 (Information to be provided where personal data are collected from the data subject)
  • Decision: Administrative fine, Compliance order
  • Website topics: Health and research, Basic principles

Summary of the Decision

Origin of the case  

The Italian Data Protection Authority (DPA) initiated an investigation following a complaint lodged by a passenger concerning the processing of health data by Emirates in connection with assistance for passengers with disabilities or reduced mobility.

The complainant stated that Emirates had required her to complete a MEDIF (Medical Information for Fitness to Travel or Special Assistance) form, although she claimed not to fall within the categories of passengers required to do so. The form collected information concerning passengers’ health, as well as data relating to their doctor and any accompanying person. The complainant also raised concerns about the information provided regarding the processing of such data.

Key Findings

After consulting the Italian Civil Aviation Authority, the Italian DPA found that the processing of health data through the MEDIF form could be lawful where necessary to ensure safe air transport and provide appropriate assistance to passengers with disabilities or reduced mobility. Therefore, it found no infringement of Articles 5(1)(a)-(c), 6(1) and 9 GDPR concerning the lawfulness of collecting such data.

However, Emirates failed to provide sufficiently clear, complete and transparent information about the processing. Passengers could not easily determine in advance whether their condition required completion of the MEDIF form, or clearly identify relevant information such as the purposes, legal bases and retention periods.

The Italian DPA also found that the seven-year retention period applied to MEDIF data was excessive in relation to the purposes of assessing fitness to fly and providing assistance during the journey.

Decision

The Italian DPA imposed an administrative fine of EUR 180 000 on Emirates for infringements of Articles 5(1)(a), 5(1)(e), 12 and 13 GDPR.

The Italian DPA also ordered Emirates, within 30 days, to bring the processing into compliance. In particular, the company must clearly identify the categories of passengers required to complete the MEDIF form and specify which sections and fields are necessary. It must also establish appropriate retention periods for MEDIF data and delete data retained beyond the newly defined period.

In determining the fine, the Italian DPA took into account, among other factors, the limited number of passengers concerned compared with Emirates’ overall customer base, the absence of an intention to discriminate against the complainant, the corrective measures imposed and the absence of previous data protection infringements by the company.

For further information: 

Relevant topics
Health and research
Basic principles

Latest news

  • National News

Italian DPA fines BBVA EUR 5 508 000 for failing to respect a customer’s objection to direct marketing

  • National News

Italian DPA fines IQVIA EUR 7 000 000 for unlawful processing of patients’ health data

  • National News

Italian DPA fines security company EUR 39 000 for violations concerning employees’ data