
AIRLINE DATA PROTECTION & GDPR
Legal support for airlines on GDPR compliance, passenger data and privacy governance.
Since 2018, I have worked directly with data protection in the airline sector. I help airlines address privacy requirements in the context of their operational systems, commercial relationships and regulatory obligations.
01 - GDPR Compliance for Airline Operations
I advise airlines on the collection, use, sharing and retention of personal data across booking, check-in, customer service and employment processes. Each review starts with the relevant data flows, the purposes of processing and the responsibilities of the organisations involved.
My support includes legal-basis assessments, privacy notices, retention rules, records of processing activities and internal procedures. Where information reveals a passenger's health condition or other sensitive details, I assess the additional requirements rather than treating it as ordinary booking data.
The objective is to identify specific compliance gaps and translate them into practical changes, with clear responsibilities for implementation.
02 - DPIAs & Privacy by Design
I help airlines assess the privacy implications of new systems, suppliers and changes to existing processes. This can include booking platforms, customer analytics, employee monitoring and technology involving sensitive personal data.
I determine whether a Data Protection Impact Assessment, or DPIA, is required and assist with its preparation or review. The assessment addresses the proposed processing, necessity and proportionality, risks to individuals and appropriate safeguards.
Working with your operational and technical teams, I advise on data minimisation, access arrangements, retention and default settings. Where the assessment identifies unresolved high risks, I advise on the need for prior consultation with the competent supervisory authority.
03 - Data Processing Agreements & International Transfers
I review how personal data is shared with technology providers, ground handlers, distribution partners and other recipients. The contractual approach depends on each party's actual role and the circumstances of the processing.
Roles & Responsibilities
I assess whether the parties act as controllers, joint controllers or processors. I help align the contractual arrangements with their actual decision-making responsibilities, rather than applying the same processing agreement to every relationship.
Data Processing Agreements
I draft and review provisions on processing instructions, confidentiality, security, subprocessors, assistance with individual rights, breach notifications, audit rights and the return or deletion of data.
International Transfers
I assess transfers outside the European Economic Area, including relevant overseas access arrangements. My advice covers applicable transfer mechanisms, standard contractual clauses, transfer impact assessments and supplementary safeguards where required.
04 - Data Subject Requests & Privacy Complaints
I help airlines handle requests for access, erasure, rectification and other GDPR rights from passengers, customers and employees. My support includes assessing the request, verifying identity where appropriate, identifying relevant records and preparing a legally reasoned response.
The review considers applicable deadlines, retention obligations and the rights of other individuals. Requests are assessed individually, including where they arise alongside an employment dispute, passenger complaint or legal claim.
I also help establish internal workflows so that requests reaching customer service, HR or other departments are recognised, escalated and handled consistently.
05 - Personal Data Breaches & Supervisory Proceedings
I support airlines with the legal assessment of suspected personal data breaches and the response to related regulatory enquiries. I work alongside the DPO, information security team and relevant operational departments.
Breach Assessment
I assess whether an event constitutes a personal data breach and evaluate the risks to affected individuals. The review covers confidentiality, integrity and availability, not only the disclosure of passenger information.
Notifications & Documentation
I advise on notification to the competent supervisory authority and communication to affected individuals. I help prepare the required reports and document the assessment, including the reasons where notification is not required.
Regulatory Representation
I assist with authority enquiries, inspections and proceedings before the Czech Office for Personal Data Protection. My work includes submissions, evidence review, responses to findings and advice on corrective measures and available remedies.
06 - Airline Experience & External Privacy Counsel
My airline-sector work includes data protection and cybersecurity governance at Smartwings and Czech Airlines. This experience informs my approach to internal responsibilities, operational evidence and the implementation of privacy requirements.
I can work alongside your in-house legal team, DPO and compliance function. For airlines that prefer outsourced legal support, I can assemble and lead an external legal team tailored to the agreed scope, while remaining your primary point of contact.
Support can cover a specific project, a complaint or ongoing privacy advice. Any separate DPO appointment is assessed and structured to preserve the independence of that role and avoid conflicts of interest.
