W Gregory Voss, ‘Airline Commercial Use of EU Personal Data in the Context of the GDPR, British Airways and Schrems II

ABSTRACT
This study, which focuses on the commercial use of personal data by US airlines, uses actual cases to help analyze the application of the EU General Data Protection Regulation (GDPR) to the airline industry. It is one of the first studies to do so, and as such contributes to the literature. It begins by highlighting the British Airways GDPR penalty case, in which the UK regulator publicized its notice of intention to issue the highest administrative fine to-date under the GDPR.

When the GDPR applies to them, airlines should become fully aware of key provisions of the GDPR, starting with those related to its scope and its underlying data protection principles, discussed in this study. In addition, airlines must have a legal basis to process personal data under the GDPR and, as this study shows, must have adequately prepared for data subject requests to exercise rights and potential data breaches.

Several examples of the first GDPR sanctions in the airline industry are detailed, and lessons drawn. In this context, security of data is a key element. Finally, the recent Schrems II decision invalidating the EU-US Privacy Shield Decision is examined, and its potential impact on the transfer of personal data from the European Union to the United States by airlines is studied, following an analysis of their privacy policies available on the Internet in the European Union.

Voss, W Gregory, Airline Commercial Use of EU Personal Data in the Context of the GDPR, British Airways and Schrems II (September 30, 2020). 19(2) Colorado Technology Law Journal (forthcoming, 2021).

First posted 2020-10-12 19:50:07

Leave a Reply