AMADEUS IT GROUP, S.A.
GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2025-04-07.
Case details
- Authority
- Spanish Data Protection Authority (aepd)
- Date
- 2025-04-07
- Controller / Processor
- AMADEUS IT GROUP, S.A.
- Sector
- Transportation and Energy
- Quoted Articles
- Art. 6 GDPR, Art. 14 GDPR
- Type of violation
- Insufficient legal basis for data processing
Summary
The Spanish DPA has imposed a fine of EUR 14,400,000 on AMADEUS IT GROUP, S.A. The controller is a company that provides travel companies with technology, including a Global Distribution System, which gives the controller access to its customers' customer data. The controller reused personal data obtained from the Global Distribution System for another product. The controller did not adequately inform the data subjects regarding the secondary use of their data, nor did they base the processing on a sufficient legal basis. The original fine of EUR 18,000,000 was reduced to EUR 14,400,000 due to immediate payment by the controller.