Aviation enterprises face complex requirements on customer personal data protection

Insights
Aviation enterprises face complex requirements on customer personal data protection
Posted on: 24/07/2026

    There is a quite special feature of the aviation industry that many businesses in other fields do not encounter. Each flight transports not only passengers, but also "transports" a huge amount of personal data across borders. From the moment a passenger searches for a flight on the website, makes a booking, makes a payment, checks in online, uses facial recognition to board the plane, connects to in-flight Wi-Fi, earns reward points, requests special meals or provides medical assistance, almost the entire journey is recorded as data.

     

    The difference of the aviation industry is not in the volume of data collected, but in the way data is constantly flown between many subjects throughout the passenger's journey.

     

    Therefore, when the Law on Personal Data Protection 2025 and its official guiding documents come into effect, aviation enterprises become one of the groups of businesses under the greatest compliance pressure.

    Aviation: The data ecosystem is more complex than any other industry

    The difference of the aviation industry is not in the volume of data collected, but in the way data is constantly flown between many subjects throughout the passenger's journey.

    A ticket purchase can simultaneously involve ticketing agents, reservation systems, payment gateways, airports, technology service providers, partners in the tourism ecosystem, and multiple state regulatory agencies. For international flights, data continues to be transferred to many different countries to serve transportation activities and state management requirements.

    This creates a trait that very few other industries have: passenger data is almost never solely under the control of a single business. Each entity in the supply chain can participate in the process of collecting, storing, accessing, or processing data according to different legal roles.

    Therefore, the biggest risk of aviation businesses is not the risk of cyber attacks or data leaks from internal systems, but the inability to control their entire data processing chain. As long as a technology service provider, a ground service unit, or a marketing partner fails to meet data protection requirements, businesses may still face disputes, complaints, or liabilities arising.

    A transaction but at the same time subject to the regulation of many legal systems

    The complexity of the aviation industry also comes from the fact that the same data processing activity can be simultaneously governed by many different legal systems.

    From a national perspective, enterprises must comply with regulations on personal data protection, cyber security, cyber information security, consumer rights protection, electronic transactions, civil, commercial and specialized aviation laws. In addition, there are obligations to provide passenger information to management agencies in accordance with regulations on immigration, customs, terrorism prevention or aviation security assurance.

    For international routes, the scope of compliance is significantly wider. Passengers' data may be transferred to or processed in many different countries, requiring businesses to simultaneously consider the requirements of foreign laws, such as the European Union's General Data Protection Regulation (GDPR) when serving passengers in the European market.  or similar regulations of Singapore, Japan, South Korea and many other countries.

    Notably, in the same transaction, the enterprise is both the party to the transportation contract, the digital service provider through the website, mobile application and loyalty program, as well as the subject of managing a large amount of cross-border data. Each of these roles entails its own legal obligations for data collection, use, retention, sharing, and protection.

    It is the intersection of many legal frameworks that makes data management in the aviation industry much more complicated than in traditional business fields. What businesses need to build is not only a personal data protection policy, but a governance system capable of operating uniformly in the context of data constantly moving across multiple subjects and jurisdictions

    One of the important changes to the personal data protection law is to require businesses to clearly define the legal basis for each data processing activity, instead of applying a common mechanism for all information collected.

    For aviation businesses, this requirement is especially important because each type of data is processed to serve a completely different purpose. Passport information used to fulfill obligations under immigration regulations; payment information for the performance of the contract of carriage; health data processed to arrange medical assistance or meet flight safety requirements; while email addresses or ticket purchase history can be used by businesses for marketing or customer care programs.

    The existence of many different processing purposes means that not all data can be based on the same legal basis. Information collected for the performance of a contract of carriage is not automatically allowed to be used to personalize advertising, build customer profiles, or share with commercial partners in the travel ecosystem.

    AI and Sensitive Data: Two New Challenges for the Aviation Industry

    In parallel with digital transformation, artificial intelligence (AI) is being applied to forecast demand and determine ticket prices in real time, optimize flight schedules, customer care chatbots, to facial recognition at airports or behavioral analysis to personalize services, etc  AI is making fundamental changes in the way businesses harness data.

    However, AI models often require large amounts of data to train and operate, and are capable of analyzing, inferencing, and combining various data sources to build a profile of passenger behavior. This raises many legal questions: whether the data used to train the AI is consistent with the purpose for which it was originally collected; whether the personalization of the service leads to automated decisions that significantly affect the interests of customers; how transparent businesses need to be about the use of AI in data processing.

    The peculiarity of the aviation industry also lies in the frequent processing of many groups of sensitive data. Health information for arranging medical assistance, biometric data for touchless boarding, images from security camera systems, information about unaccompanied minors or meal requests that may reflect a health condition or religious beliefs are all types of sensitive data that need to be protected more strictly.

    Therefore, instead of applying a unified policy to the entire database, businesses need to build a mechanism to classify data according to risk level; apply different encryption, decentralization, and retention periods; at the same time, assess the impact of AI systems before putting them into operation. This is also a trend that is being promoted by many countries through the principles of Privacy by Design and AI Governance, whereby data protection requirements must be integrated from the system design stage instead of only being supplemented after the product has been put into operation.

     

    Data incidents that have occurred in the international aviation industry show that the cost of a breach is not just measured in fines.

     

    Data lifecycle management – the heart of modern compliance

    For today's business, it's no longer a matter of how much data it owns, but how to manage it throughout its lifecycle. This requires businesses to answer a series of administrative questions: where is the data collected from; what legal basis for each handling activity; in which country the data is stored; who has access; with which partners the data is shared; how long is the retention period; when to delete or anonymize data; and who is responsible if a violation occurs.

    To do that, many businesses around the world have shifted from the mindset of building individual policies to establishing a comprehensive data governance system. This system usually includes data mapping, data inventory, determination of data flow in the business, development of supplier management processes, data classification mechanisms, incident response processes, data retention and destruction policies, etc  as well as a mechanism to monitor compliance on an enterprise-wide scale.

    This is also an approach that is in line with the principle of accountability of the Law on Personal Data Protection 2025. When an incident occurs, the regulator will not only consider whether the business has been cyberattacked, but also assess whether the business has built a governance system that is appropriate for the scale and level of risk of data processing.

    Lessons from international practice

    Data incidents that have occurred in the international aviation industry show that the cost of a breach is not just measured in fines.

    The British Airways case is a good example[1]. After the cyber attack incident that exposed the data of hundreds of thousands of customers, businesses not only faced the handling measures of the regulator but also had to pay for the cost of investigating, upgrading the system, resolving complaints, responding to lawsuits and overcoming reputational damage. The actual damage lasts for many years and far exceeds the value of the administrative sanction.

    An important lesson to be learned from international cases is that the regulator is increasingly concerned with governance capacity rather than absolute results. No single system can guarantee the complete elimination of cybersecurity risks. However, businesses must demonstrate that they have identified risks, developed appropriate control processes, managed suppliers effectively, and are capable of detecting, responding, and notifying incidents on time.

    For decades, airlines have competed with fleets, route networks, and service quality. In the new context, a new criterion will appear: data governance capacity. When data is both a strategic asset and a source of legal risk, businesses can build a transparent, verifiable governance system and meet multiple legal frameworks simultaneously that will not only minimize compliance risks but also build the trust of customers and partners. That will be the sustainable competitive advantage of the digital aviation industry that should be aimed at.

    Lawyer Nguyen Van Phuc

    HM&P Law Firm