Emirates – €180,000 Fine (Italy, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Emirates was fined for not properly handling personal data of passengers with disabilities. This is important because it shows that companies must respect privacy rights when collecting sensitive information. Airlines and businesses should ensure they have clear consent processes in place.
What happened
Emirates required passengers with reduced mobility to fill out a form without proper consent or privacy notice.
Who was affected
Passengers with disabilities or reduced mobility who traveled with Emirates were affected.
What the authority found
The Garante ruled that Emirates did not have a valid legal basis for processing sensitive personal data, violating GDPR requirements.
Why this matters
This case highlights the need for companies to obtain clear consent when processing sensitive information. Businesses should review their data collection practices to ensure compliance and protect user privacy.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
Emirates (the controller) is an airline company. In 2025, a data subject brought a complaint to the DPA regarding the controller’s processing activities of data subjects with disabilities or reduced mobility. The controller required persons with reduced mobility to complete a form to provide them with the transport services. This form processed names, contact details, health information, and medical certificates when needed. The controller presented the form without referring to the privacy notice and without obtaining data subjects’ consent. According to the data subject, the controller requested them to fill in the form despite them not needing the assistance. The controller required the data subject to provide their health data without explaining how it would be processed or obtaining consent for it. The controller argued that it requested this information as a preventative measure to ensure it can provide assistance to all data subjects that need it, in accordance with its obligations under EU law.The controller referred to Regulation 1107/2006 concerning the rights of disabled persons and persons with reduced mobility when travelling by air (https://eur-lex.europa.eu/eli/reg/2006/1107/oj/eng) The form was a standardised tool to collect the data necessary to determine whether a data subject needed assistance. In terms of data protection, the controller claimed it provided clear and accessible information. In addition, the processing was lawful under performance of a contract and to comply with legal obligations related to safety. The controller processed health data lawfully under substantial public interest. Finally, the controller made the form accessible to a limited number of parties, and retained the data for a period of 7 years to meet legal and defence requirements. The DPA first found that the controller did not violate Articles 5(1)(a), (b), (c), 6(1) and 9 GDPR. The DPA consulted the national authority responsible for monitoring compliance with the
Related Enforcement Actions (0)
No other enforcement actions found for Emirates in IT
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
14 May 2026
Authority
Garante per la protezione dei dati personali
Fine Amount
€180,000
Enforcement Tracker ID
3220
GDPRhub ID
gdprhub-10071About this data
Cite as: Cookie Fines. Emirates - Italy (2026). Retrieved from cookiefines.eu
Last updated: