Now Reading
Emirates Fined €180,000 By Italian Privacy Watchdog Over How it Processes the Personal Data of Passengers With Reduced Mobility

Emirates Fined €180,000 By Italian Privacy Watchdog Over How it Processes the Personal Data of Passengers With Reduced Mobility

airplanes on a runway

Dubai-based mega airline Emirates has been fined €180,000 (US $208,000) by Italy’s privacy watchdog over the way it handles sensitive personal data about passengers with reduced mobility or other, sometimes highly personal and sensitive, health conditions.

The watchdog, known in Italy as the Garante, started its probe into how Emirates handles the data of disabled passengers in January 2025 when a woman alleged that the airline had breached Italian privacy and data protection laws.

The woman had requested mobility assistance from the airline ahead of a flight, but in order to do so, she was required to fill out an online form, which is known within the aviation industry as a MEDIF, which stands for ‘Medical Information for Fitness to Travel.’

The MEDIF form is a standardized document used by many airlines around the world, which helps airlines to assess whether a passenger with health conditions is fit to fly.

As Emirates pointed out in correspondence with Garante, “air transport takes place in a physiologically peculiar environment,” which can put enormous pressure even on otherwise healthy adults.

As such, requiring passengers with health conditions to complete a MEDIF form is a good practice effort to reduce the risk of someone suffering a life-threatening medical event at 38,000 feet, where medical support is very limited.

The woman who made the complaint, however, said Emirates was collecting personal and sensitive health information unnecessarily, as it seemed to suggest that every box in the detailed MEDIF form had to be filled in, even for minor assistance requests.

She also complained that Emirates didn’t properly spell out its data privacy policy before she completed the form, or request her consent before the airline processed her data.

Following a review with Italy’s civil aviation regulator, the Garante accepted that Emirates had a right to collect medical information from passengers to ensure they were fit to fly, and had the appropriate level of support, as well as reducing the risk of in-flight medical emergencies.

But the Garante slammed Emirates for failing to properly inform passengers why it was collecting their data using the MEDIF form and how their data would be processed. In fact, the Garante even said it was unclear which categories of passengers were required to supply their personal information via the MEDIF form.

In addition, the Garante also criticized Emirates for retaining the data for up to seven years. Emirates claimed this was necessary due to the risk of lawsuits from passengers, but later admitted that most legal claims against airlines operating international flights have to be filed within two years under the provisions of the Montreal Convention.

Emirates has already started to reduce the retention period to three years, and the Garante has ordered the airline to delete passenger data that has been registered on its database for more than three years.

As well as ordering Emirates to improve the information it provides to passengers about the MEDIF process and how their personal data will be processed, the Garante landed the airline with a fine of €180,000.

View Comments (0)

Leave a Reply

Your email address will not be published.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

© 2024 paddleyourownkanoo.com All Rights Reserved.

Unauthorized use and/or duplication of this material without express and written permission from this site’s author and/or owner is strictly prohibited. Excerpts and links may be used, provided that full and clear credit is given to paddleyourownkanoo.com with appropriate and specific directions to the original content.