All news
Enforcement June 17, 2026 4 min

Italy's DPA fines Emirates EUR 180,000: passenger health data kept for 7 years and an unclear notice

Processing the health data was lawful (assisting reduced-mobility passengers), but the regulator challenged transparency and retention. A lesson in how NOT to handle special-category data

TL;DR for the DPO

Italy's DPA fined Emirates EUR 180,000 over the handling of reduced-mobility passengers' health data. The processing was lawful (needed to ensure safe transport and assistance), but the authority found two breaches: a notice that was not sufficiently clear and complete, and retention of health data for 7 years, deemed excessive and disproportionate. The case arose from a complaint by a passenger asked to complete a medical form despite not being required to.

The three points that matter

  • Lawful basis OK, but not enough: collecting health data for assistance is lawful, but the rest of the obligations must hold up.
  • Poor transparency: the notice did not clearly and fully explain what was collected and why, neither on the website nor through staff.
  • Disproportionate retention: 7 years for health data collected for a single trip was deemed excessive. The principle is minimisation (Art. 5(1)(c)-(e) GDPR).

What to do now

For every client handling special-category data (healthcare, but also gyms, care homes, insurers, transport): 1) make sure the notice separates data-subject categories and clearly states the purpose and legal basis of the health data; 2) set a PROPORTIONATE retention period and document why; 3) collect the special-category data ONLY from those actually required to provide it. Blanket 'just in case' collection is exactly what the regulator challenges.

Why it matters for your clients

This case proves that lawful collection is not a safe harbour: the fine landed on transparency and retention, two aspects many underestimate. For a DPO it is a concrete talking point for clients handling health data, and a good reason to review notices and retention periods before an authority does.

Official source:Italian DPA / Reuters - Emirates EUR 180,000 fine (June 2026)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement
26complaints, and no fine

You declare contract, then you reject the objections: Norway shows how the two mistakes travel together

SATS asked members for a photo kept in the membership system and used at the desk to check the identity of people coming in. Datatilsynet found the notice stated the wrong legal basis, failed to explain the right to object, and that objections were rejected without demonstrating compelling legitimate grounds. The deadline to fix it is 11 September 2026.

Aug 26, 2026New 6 min
Enforcement
825 mln €the second-largest fine ever

Eight hundred and twenty-five million for an algorithm that deactivated accounts with nobody looking

It is the second-largest fine ever imposed under the GDPR, behind only Meta's 1.2 billion. It is not about a data transfer or a security breach: it is about Article 22, the rule on automated decisions that almost nobody documents because it looks like a big-platform problem. It is in fact about anyone who lets software decide something that weighs on a person's life.

Aug 24, 2026New 5 min
Enforcement
64 mln złagainst 14 the year before

Poland quadrupled its fines in a year, and the three highest ever all date from 2025

For years Poland was treated as a low-enforcement market. That assumption no longer holds: in twelve months the total went from fourteen to over sixty-four million zloty, and the three largest fines in the country's history all carry the same year. If you look after a client with a branch, a supplier or a service centre in Poland, the risk calculation has changed.

Aug 24, 2026New 4 min