Brussels airport – €200,000 Fine (Belgium, 2022)

€200,000Autorité de Protection des Données4 April 2022Belgium
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Brussels Airport was fined €200,000 for improperly handling temperature checks during the COVID-19 pandemic. The Belgian Data Protection Authority found that the airport didn't have a clear legal basis for collecting and processing health data. This case highlights the importance of having a valid legal reason for processing sensitive information like health data.

What happened

Brussels Airport used thermal cameras to check passengers' temperatures without a valid legal basis.

Who was affected

Passengers at Brussels Airport who had their temperatures checked and health data processed.

What the authority found

The Belgian Data Protection Authority ruled that Brussels Airport lacked a valid legal basis for processing health data, violating GDPR rules.

Why this matters

This case underscores the need for businesses to ensure they have a clear legal basis when processing sensitive data, especially in public health contexts. It serves as a reminder for companies to conduct thorough data protection impact assessments.

GDPR Articles Cited

AI-verified

Art. 12 GDPR
Art. 5(1)(c) GDPR
Art. 6(1)(e) GDPR
Art. 6(3) GDPR
Art. 9(2)(g) GDPR
Art. 13(1)(c) GDPR
Art. 13(2)(e) GDPR
Art. 35(1) GDPR
Art. 35(3) GDPR
Art. 35(7)(b) GDPR
View original scraped data
Art. 5(1)(c) GDPR
Art. 6(1)(e) GDPR
Art. 9(2)(g) GDPR
Art. 12 GDPR
Art. 13(1)(c) GDPR
Art. 13(2)(e) GDPR
Art. 24 GDPR
Art. 35(1) GDPR
Art. 35(3) GDPR
Art. 35(7)(b) GDPR

Original data from scraper before AI verification against source document.

Entities Involved

Brussels Airport Company SA
€200,000
(controller)
Ambuce Rescue Team SA
€20,000
(joint controller)
Source verified 6 March 2026
articles corrected
entity split needed
Full Legal Summary
Detailed

The inspection service of the Belgian DPA conducted an inspection on the temperature checks carried out by the Brussels Airport, as instructed by the Board of Directors of the DPA. As a first step, the passengers' temperature was measured with thermal cameras. In a second step, all passengers with a temperature above 38°C were invited to be examined by a medical service, to carry out a diagnosis (performed by a doctor and using a form). The information was stored on paper and electronically and potentially shared for contact tracing. The DPA issued a €200,000 fine against the airport for violation of Articles 5(1)(c), 6(1)(e), 9(2)(g), 12, 13(1)(c), 13(2)(e), 35(1), 35(3) and 35(7)(b) GDPR. It also fined the medical service €20,000 for violation of Articles 5(1)(c), 6(1)(e), 9(2)(g), 35(3) and 35(7)(b) GDPR. Finally, it issued a a reprimand against the airport for violation of Articles 5(2), 24 and 35(1) GDPR. = The DPA concluded that the airport was the controller for the processing of data in the context of the first step. The airport and the medical service were considered as joint controllers for the second line of processing. The DPA considered that the qualification under the contractual agreement was not binding upon the DPA (in accordance with the EDPB guidelines on the same). = During the procedure, the airport stated that it relied on Article 6(1)(e) and 9(2)(g) GDPR for the processing. The DPA considered that the decrees and the protocol on which the airport relied as a legal basis were not creating any legal obligation to check the temperatures of the passengers. Moreover, the texts the airport relied upon did not refer, as required by Article 6(3) GDPR, to the purpose of the processing, to the description of the processing operations, nor did the text mention the measures to ensure a lawful and fair processing of the data. The DPA also noted that the airport itself remarked in its data protection impact assessment (DPIA) that no legal text provi

Related Enforcement Actions (0)

No other enforcement actions found for Brussels airport in BE

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

4 April 2022

Authority

Autorité de Protection des Données

Fine Amount

€200,000

GDPRhub ID

gdprhub-4832

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Brussels airport - Belgium (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: