
€18 million. Spain’s largest-ever privacy fine. For using data passengers already gave you — just not for this.
Spain’s AEPD fined Amadeus IT Group for building a traveller-profiling system from historical booking data. The data was real. The consent wasn’t.
Here’s the compliance failure: Amadeus collected passenger data in the normal course of ticket processing.
Then it used that same data — retrospectively — to build personalized marketing profiles and commercial analytics.
The problem wasn’t the data. It was the purpose.
Under GDPR, data collected for one purpose cannot simply be repurposed for another. Legitimate interests, consent, and compatible purpose all have to be re-evaluated for each new processing activity. Retrospective profiling using transactional data — without re-establishing legal basis — is a clean violation of Article 6.
What this means for your compliance team:
→ Legal basis is processing-specific, not data-specific. Holding data lawfully does not authorise every use of that data.
→ Historical data is not free data. Every new analytical or commercial use of existing records requires a fresh legal basis assessment.
→ Settlement at €14.4M signals cooperation was recognised — but €18M was the starting point.
→ Travel, hospitality, retail, and financial services all hold vast historical transaction datasets. The question regulators are now asking: “What did you do with that data — and did you have a legal basis to do it?”
At S8fe.ai, we help organisations map their data against multiple regulations, and flag risks. this map can be leveraged in a processing register to anticipate compliance exposure before it becomes an enforcement event.
Source: https://www.travelmole.com/news/spain-hits-amadeus-record-fine
