Amadeus pays €14.4 million to settle a fine by Spain’s DPA
Spain’s DPA has found that Amadeus, a reservation system used by airlines, hotels, railway/cruise operators and travel agencies breached the GDPR in its use of travel booking data to test a new product.
The DPA says that the violations were against GDPR Articles 14 (information to be provided where personal data have not been obtained from the data subject) and 6 (lawfulness of processing). Amadeus had processed personal data of millions of passengers without a proper legal basis, it says. The company said it relied on legitimate interest as the data was from its own Global Distribution System and used for a pilot project that was never commercialised. The DPA view was that the data was collected for reservations but then used three years later for a new purpose without informing the individuals or obtaining their consent.
Spain’s DPA imposed a fine of €9 million for the infringement of Article 14 GDPR. For the infringement of Article 6 GDPR, it imposed another €9 million fine. Making use of the 20% discount available, Amadeus made a voluntary payment of €14.4 million without admitting liability. This payment was made on 29 May and resulted in the termination of the administrative procedure.
See: