On May 26, 2026, the Spanish Data Protection Agency (“AEPD”) published details of its decision to fine Amadeus IT Group, S.A. (“Amadeus”), a Madrid-headquartered technology provider for the global travel and tourism industry, EUR 18 million in connection with GDPR violations involving Amadeus’s Global Distribution System (“GDS”). Amadeus voluntarily paid the fine, less a 20% reduction, on May 29, 2025, thereby terminating the proceedings without admitting liability. The fine, one of the largest the AEPD has imposed, highlights the enforcement risks associated with repurposing personal data such as passenger data without appropriate transparency or a valid legal basis under the GDPR.
Latest Post
More Posts
Quantum Computing: Quantum Applications in Finance
Quantum-as-a-Service: Practical Considerations for Drafting and Negotiating Agreements
Quantum Computing: Overview of Drafting Considerations for Quantum-as-a-Service Agreements
Quantum Computing: Developments in the UK and US
The “Agile” Path to Market: An Alternative Approach to Food Industry R&D
EHR Interoperability: Public Health Benefits & Privacy Considerations
State Medical Licensing Changes to Combat COVID-19
The Potential Benefits of Digital Health Technology in Managing COVID-19
AI/IoT Update: The Potential Benefits of Digital Health Technology in Managing COVID-19
Connect: http://www.cov.com/nhoward
Subscribe: Subscribe via RSS