Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Privacy

Spain fines Amadeus €14.4M for passenger profiling

Spain's AEPD says Amadeus combined travel bookings with hotel records to profile millions of passengers without a valid legal basis.

By · Published · Updated · 4 min read

Spain fines Amadeus €14.4M for passenger profiling

Spain's data protection authority, the AEPD, has fined travel technology company Amadeus IT Group €14.4 million, PPC Land reports.

What Amadeus did

The AEPD found Amadeus used tens of millions of passenger booking records to build passenger profiles, combining data from its own reservation system with customer records from major hotel chains — without a valid legal basis or proper transparency. That broke Articles 6 and 14 of the GDPR.

How the case started

  • An anonymous complaint in September 2023 alleged Amadeus had pooled the travel histories of millions of people, involving more than 12 billion records.
  • The AEPD opened an investigation in October 2023, and further complaints followed in 2024.

Amadeus is one of the world's largest Global Distribution System operators, used by airlines and travel agents to handle bookings.

Why it matters

Most travellers have never heard of Amadeus, yet their trips pass through its systems. Profiling people who have no direct relationship with a company — and no idea it holds their data — is exactly what the GDPR's transparency rules are meant to prevent.

Sources

Read next