Regulatory Watch  /  Italy  /  Fine
High impactFineDecided

Italian DPA fines Emirates €180,000 for health data infringements

The Italian Data Protection Authority imposed an administrative fine of EUR 180,000 on Emirates for violations of GDPR transparency and retention requirements concerning passengers' health data. Emirates was ordered to clarify which passengers must complete the MEDIF form, specify necessary fields, and reduce the seven‑year data retention period. The decision was issued on 14 May 2026.

Why it matters: The enforcement highlights GDPR obligations for clear information and proportionate retention of health data in the aviation sector.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Italian DPA fines Emirates EUR 180 000 for infringements concerning passengers’ health data
European Data Protection Board news · primary source · Oct 9, 2026
Details
JurisdictionItaly
RegulatorItalian Data Protection Authority
LawGeneral Data Protection Regulation
StatusDecided
PublishedOctober 9, 2026
Effectivenot stated
DecisionMay 14, 2026
Penaltyadministrative fine of EUR 180 000
OrganisationsEmirates
Topicshealth, transparency, retention, data minimization
Datahealth, personal