This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Data Sovereignty
Italian DPA fines Emirates EUR 180 000 for infringements concerning passengers’ health data
The Italian Data Protection Authority (DPA) initiated an investigation following a complaint lodged by a passenger concerning the processing of health data by Emirates in connection with assistance for passengers with disabilities or reduced mobility. The complainant stated that Emirates had required her to complete a MEDIF (Medical Information for Fitness to Travel or Special Assistance) form, although she claimed not to fall within the categories of passengers required to do so. After consulting the Italian Civil Aviation Authority, the Italian DPA found that the processing of health data through the MEDIF form could be lawful where necessary to ensure safe air transport and provide appropriate assistance to passengers with disabilities or reduced mobility. Therefore, it found no infringement of Articles 5(1)(a)-(c), 6(1) and 9 GDPR concerning the lawfulness of collecting such data. The Italian DPA also found that the seven-year retention period applied to MEDIF data was excessive in relation to the purposes of assessing fitness to fly and providing assistance during the journey. In determining the fine, the Italian DPA took into account, among other factors, the limited number of passengers concerned compared with Emirates’ overall customer base, the absence of an intention to discriminate against the complainant, the corrective measures imposed and the absence of previous data protection infringements by the company.