TL;DR for the DPO
Italy's DPA fined Emirates EUR 180,000 over the handling of reduced-mobility passengers' health data. The processing was lawful (needed to ensure safe transport and assistance), but the authority found two breaches: a notice that was not sufficiently clear and complete, and retention of health data for 7 years, deemed excessive and disproportionate. The case arose from a complaint by a passenger asked to complete a medical form despite not being required to.
The three points that matter
- Lawful basis OK, but not enough: collecting health data for assistance is lawful, but the rest of the obligations must hold up.
- Poor transparency: the notice did not clearly and fully explain what was collected and why, neither on the website nor through staff.
- Disproportionate retention: 7 years for health data collected for a single trip was deemed excessive. The principle is minimisation (Art. 5(1)(c)-(e) GDPR).
What to do now
For every client handling special-category data (healthcare, but also gyms, care homes, insurers, transport): 1) make sure the notice separates data-subject categories and clearly states the purpose and legal basis of the health data; 2) set a PROPORTIONATE retention period and document why; 3) collect the special-category data ONLY from those actually required to provide it. Blanket 'just in case' collection is exactly what the regulator challenges.
Why it matters for your clients
This case proves that lawful collection is not a safe harbour: the fine landed on transparency and retention, two aspects many underestimate. For a DPO it is a concrete talking point for clients handling health data, and a good reason to review notices and retention periods before an authority does.
Official source:Italian DPA / Reuters - Emirates EUR 180,000 fine (June 2026)Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free