Regulatory Watch  /  Spain  /  Data protection authority action
High impactData protection authority actionFiled

noyb files complaint with Spanish DPA over Ryanair’s facial‑recognition verification for travel‑agent bookings

noyb lodged a complaint with Spain's Data Protection Authority (AEPD) alleging that Ryanair forces customers who book via online travel agents to undergo a facial‑recognition verification process. The complaint argues that Ryanair lacks a valid legal basis, that consent is not informed, and that the practice may breach GDPR provisions on biometric data. The AEPD could impose a fine of up to €192 million based on Ryanair’s 2022 turnover.

Why it matters: The case highlights potential GDPR violations from Ryanair’s use of biometric facial‑recognition for customers booking through third‑party agents.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Booking a Ryanair flight through an online travel agent might hold a nasty surprise
noyb · primary source · Jul 27, 2023
Booking a Ryanair flight through an online travel agent might hold a nasty surprise
noyb · Jul 27, 2023
Details
JurisdictionSpain
RegulatorSpanish Data Protection Authority (AEPD)
LawGeneral Data Protection Regulation
StatusFiled
PublishedJuly 27, 2023
Effectivenot stated
PenaltyBased on Ryanair’s turnover of € 4.8 billion in 2022 , the Data Protection Authority could issue a fine of up to € 192 million.
OrganisationsRyanair, eDreams, GetID, noyb
Topicsbiometrics, consent, data minimization, privacy
Databiometric, personal