Regulatory Watch  /  Italy  /  Enforcement
Moderate impactEnforcementFiled

noyb files GDPR complaint against Ryanair over mandatory biometric face scans

Sources disagree
noyb gives penalty 431,000,000 EUR; event has 431 EUR.

noyb has filed a complaint with the Italian Data Protection Authority alleging that Ryanair forces new customers to create permanent accounts and undergo a biometric facial‑recognition verification to book flights. The complaint says this breaches GDPR articles on data‑minimisation, purpose limitation and consent. The authority could impose a fine of up to €431 million.

Why it matters: The complaint challenges Ryanair’s use of mandatory biometric data, potentially leading to a large GDPR fine and changes to its booking process.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Want to book a Ryanair flight? Prepare for a face scan!
noyb · primary source · Dec 19, 2024
Want to book a Ryanair flight? Prepare for a face scan!
noyb · Dec 19, 2024
Details
JurisdictionItaly
RegulatorItalian Data Protection Authority (Garante)
LawGeneral Data Protection Regulation
StatusFiled
PublishedDecember 19, 2024
Effectivenot stated
PenaltyBased on Ryanair’s turnover of € 10 billion in 2023 , the data protection authority could issue a fine of up to € 431 million.
OrganisationsRyanair
Topicsbiometrics, consent, data minimization, purpose limitation, privacy
Datapersonal, sensitive, biometric