The Italian Data Protection Authority imposed an administrative fine of EUR 180,000 on Emirates for violations of GDPR transparency and retention requirements concerning passengers' health data. Emirates was ordered to clarify which passengers must complete the MEDIF form, specify necessary fields, and reduce the seven‑year data retention period. The decision was issued on 14 May 2026.
Why it matters: The enforcement highlights GDPR obligations for clear information and proportionate retention of health data in the aviation sector.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.