Emirates Airline Hit With €180,000 Fine by Italy Over Reduced-Mobility Passengers Health Records

Italy’s data protection authority, the Garante per la protezione dei dati personali, fined Emirates (EK) €180,000 (approximately US$208,000) on 17 June 2026 over how the airline processes sensitive health data submitted by passengers with reduced mobility. The Garante — which is widely considered one of the most active and influential data protection regulators in the European Union — opened its investigation in January 2025 following a formal complaint by a passenger who alleged that Emirates had breached Italian privacy and data protection laws. The case centred on the airline’s use of a MEDIF form, a standardised Medical Information for Fitness to Travel document that Emirates, which introduced a new livery to show solidarity with UAE during the war in Iran, requires passengers with health conditions to complete when requesting mobility assistance.

The Garante accepted that Emirates had a lawful basis for collecting medical data from passengers to assess fitness to fly and determine the appropriate level of on-board support, Paddle Your Own Kanoo reported. However, it found two separate violations: the airline failed to inform passengers clearly how their health data would be used, and it retained that data for up to seven years — a retention period the authority ruled was excessive and disproportionate. The Garante ordered Emirates to delete all passenger health data held for more than three years and to improve the information it provides to passengers at the point of data collection. A fine of €180,000 accompanied those remedial orders.

Photo: Emirates

A Passenger’s Complaint About the MEDIF Form Triggered the Investigation

The complaint that prompted the Garante’s probe was filed in January 2025 by a woman who had requested mobility assistance from Emirates ahead of a flight. In order to receive that assistance, the airline required her to complete an online MEDIF form. She objected on two grounds. First, she argued that Emirates appeared to require every field in the detailed form to be completed, even for minor assistance requests that did not clinically justify such comprehensive disclosure. Second, she said Emirates did not clearly explain its data privacy policy before she submitted the form, and did not obtain her explicit consent before processing her health data.

The MEDIF is a standardised document used by many airlines worldwide to assess whether a passenger with a health condition is physically fit to fly. Emirates, in its correspondence with the Garante, noted that “air transport takes place in a physiologically peculiar environment” and argued that the form helps prevent in-flight medical emergencies at altitude, where clinical support is very limited.

The Garante, after consulting Italy’s civil aviation regulator, accepted that position in principle. The collection of medical data was found to be lawful. The violations identified were procedural, not substantive: it was the absence of transparency around the data collection process, and the length of time the data was retained, that the authority penalised.

Photo: Emirates

How Italy’s Garante Enforces GDPR

The fine against Emirates was issued under the General Data Protection Regulation (GDPR), which applies directly across all EU member states, including Italy. Italy layers its own national Privacy Code (Legislative Decree 196/2003) on top of the GDPR, and also enacted a dedicated AI law — Law No. 132/2025 — in September 2025. The Garante is the supervisory authority responsible for monitoring compliance with both frameworks and has the power to issue fines of up to €20 million or 4% of a company’s global annual turnover under GDPR Article 83.

The Garante is among Europe’s most prolific enforcement authorities. In 2026 alone, it has taken action against several entities, including ITA Airways and Alitalia, which were jointly fined €1.25 million in March 2026 for the unlawful transfer of employee personal data during the transition between the two carriers. The authority’s inspection programme for January to July 2026 explicitly focused on data breaches involving public databases, electronic health records, and biometric recognition systems — signalling continued attention to the processing of sensitive personal data in regulated sectors, including transport and aviation.

The Garante has also previously found the FaceBoarding facial recognition system at Milan Linate Airport unlawful due to GDPR non-compliance, demonstrating that aviation data practices in Italy fall squarely within its enforcement perimeter.

Photo: Emirates

Garante Found Two Specific Violations

The Garante’s ruling against Emirates identified two distinct breaches, both relating to the processing framework around the MEDIF form rather than the collection of health data itself:

  • Lack of transparency: Emirates failed to provide sufficiently clear and complete privacy information to passengers, either on its website or through the staff assisting them. The Garante also found it was unclear which categories of passengers were required to complete the MEDIF form, meaning passengers had no reliable way to determine whether their specific assistance request actually required full medical disclosure.
  • Excessive data retention: The seven-year retention period for health data was found to be disproportionate, particularly after Emirates acknowledged that most legal claims on international routes fall under the Montreal Convention’s two-year limitation period.

The authority did not find that the data collection itself was unlawful. It accepted that Emirates needed medical information to ensure passenger safety and manage in-flight medical risk.

Photo: Emirates

What Airlines Must Do Under GDPR When Collecting Health Data

The Emirates case illustrates a compliance gap that is not unique to one airline. Many carriers use the MEDIF form or equivalent documents as part of standard procedures for passengers with reduced mobility, health conditions, or special assistance needs. Those forms collect data that falls under GDPR Article 9 — special category personal data — which requires not just a legal basis for processing but also an explicit legal basis drawn from a narrower list of permitted grounds, such as vital interests or explicit consent.

Under the GDPR, controllers processing special category data must:

  • Provide clear, complete privacy information at or before the point of data collection, including the purpose, legal basis, retention period, and the rights of the data subject.
  • Apply data minimisation principles: only data that is strictly necessary for the stated purpose may be collected. Requiring passengers to complete every field of a detailed medical form for minor assistance requests risks violating this principle.
  • Limit retention: data must not be held for longer than necessary. Retention periods must be tied to the actual purpose, not to a theoretical maximum legal exposure.
  • Obtain explicit consent where that is the chosen legal basis — or document a clearly applicable alternative legal ground under Article 9(2) GDPR.

The European Data Protection Board’s 2026 coordinated enforcement initiative focuses specifically on transparency obligations across all member states. The Garante is participating in that initiative, meaning aviation operators should expect heightened scrutiny of privacy notices and MEDIF-related data processing documentation across Europe in the months ahead.

Scroll to Top