Amadeus Fined 14.4M for Reuse, Not a Breach
If you collect data for one purpose and later repurpose it for profiling, that is now a 14.4 million euro problem. Three GDPR fines landed in one week, two from Spain’s AEPD and one from Italy’s Garante, and Amadeus is the one that should change how you scope your next project. The mechanism is the point. Amadeus was not punished for a breach or for losing data, which is where most attention goes and where NIS2 keeps pushing budgets. It was punished for taking booking data and later using it to profile passengers without a legal basis and without telling anyone. In our assessment that is the part to sit with. Purpose creep under GDPR is as serious a risk as a classic security incident, and there are no shortcuts around it.
The Week’s Fines Hit Reuse, Security and Retention
Spain published its 14.4 million euro Amadeus fine on 27 June, for reusing PNR booking data without a legal basis. If you handle compliance for a travel, hospitality or GDS-adjacent business, the company that processes your bookings just became a worked example of purpose-limitation enforcement. The AEPD found Amadeus reused passenger name record data for profiling under Articles 6 and 14 GDPR, with the original 18 million figure cut to 14.4 million after voluntary payment. Data you are entitled to hold is not data you are entitled to reuse, and that gap is the whole case.
The same week, Spain fined Vodafone España 1.05 million euro and Italy fined Emirates 180,000 euro. Three different sectors, one root cause, which is why this reads as a pattern and not three coincidences. Vodafone’s penalty stacked two Article 6 breaches on top of an Article 32 security failure. Emirates was caught keeping reduced-mobility passengers’ medical forms for seven years under Article 5(1)(e). If your retention schedule still says keep everything just in case, Emirates paid 180,000 euro to show that storage limitation is enforceable.
The EDPB also put out something smaller teams can actually use, a standard breach notification template. If you have ever drafted an Article 33 notification at 2am working out what the supervisory authority actually wants, this is for you, and it is open for consultation until 5 August. A regulator producing a form that makes the job easier rather than harder is a rare event.
Our read is that this lands hardest at larger companies, or at least gives them pause. The message from regulators across Europe is clear enough now. Collecting data lawfully is no longer enough. For every new use, you have to re-check the legal basis and the purpose. Expect more vendor reviews and more purpose-limitation arguments before any new project reaches production. The harder part is usually technical, which is how to run those checks transparently and efficiently rather than as an afterthought.
New on RegDossier
If you are working out where your AI systems actually land, our full list of high-risk categories under Annex III walks through all eight, plus the Article 6(3) exemptions that decide whether you are caught. And if you want every date in one place rather than scattered across press releases, the EU Compliance Deadline Tracker covers twelve regulations, each date checked against EUR-Lex.
Coming Up in July
MiCAR’s transition window closes on 1 July. If your business touches crypto-asset services, the grandfathering ends and it either holds a national authorisation under Article 63 or it stops operating, with some member states running even earlier cut-offs.
The AML Package reaches full application on 10 July, and the AI transparency Code of Practice closes for founding signatories on 22 July. The AML date bites because the new authority is due to deliver its first batch of binding technical standards that day, so “we are waiting for guidance” stops being an answer. Then there is 2 August, which despite the Omnibus headlines remains the live deadline for most AI Act obligations until the new text is published in the Official Journal. The Union is racing to pass a law to move a deadline, and if it misses, the old deadline stands.
If you are not in crypto or finance, the AI Act is the one worth your time in July. MiCAR and AML are sectoral. AI is already in nearly every company, so it is worth pinning down which obligations actually apply on 2 August and which have genuinely moved. In our assessment more teams will get this wrong because they heard only that the deadline moved.
RegDossier
Making EU compliance almost enjoyable. Almost.
EU regulatory updates in your inbox every two weeks. Free.
Get the next briefing