Privacy Trust Center

At Amadeus, we are deeply committed to protecting the personal data of our customers, partners, and employees.

Privacy Trust Center
Our approach

Privacy compliance at Amadeus

Given our central role in the travel ecosystem, Amadeus processes millions of personal data records daily. From booking and ticketing to loyalty programs and biometric boarding, our open platforms enable the secure exchange of personal data between authorized travel stakeholders. This includes traveler profiles, preferences, payment details, and more. We apply privacy‑by‑design principles and maintain a comprehensive data governance framework to ensure this data is handled lawfully and transparently.

  • Privacy

  • Regulation

  • Privacy rights

  • Training and awareness

  • Monitoring practices

  • Progress and recognition

  • Privacy Trust Center

    Privacy by design, embedded from the start

    At Amadeus, privacy is not an afterthought—it’s embedded into every product and service from the earliest design stages. Our teams apply privacy-by-design principles to ensure that personal data is handled responsibly, securely, and in compliance with global regulations.

  • Privacy Trust Center

    Regulatory alignment

    We regularly review our practices to align with evolving legal standards, including GDPR, CCPA, and other global frameworks.

  • Privacy Trust Center

    Empowering privacy rights

    This is a fundamental aspect of our commitment to protecting user data. By leveraging advanced technology platforms, we facilitate the management of data subject rights (DSRs), cookie consent, and regulatory requests. These tools enable us to respond efficiently to privacy inquiries, ensuring transparency and fostering trust among users and partners alike.

  • Privacy Trust Center

    Continuous training and awareness

    All Amadeus employees receive privacy training tailored to their roles. Specialized training is provided to those in privacy-related functions, ensuring that everyone—from developers to executives—understands their responsibilities in protecting personal data.

  • Privacy Trust Center

    Monitoring practices

    We conduct systematic internal reviews and external audits to ensure compliance. Privacy controls are continuously evaluated as part of our ISO 27001 and SOC certification processes.

  • Privacy Trust Center

    Measurable progress and external recognition

    Amadeus has achieved measurable improvements in privacy maturity over the past five years, outperforming industry peers in assessments conducted by independent firms. This reflects our commitment to continuous improvement and excellence in data protection.

Privacy Trust Center

A robust global governance framework

Our privacy program is supported by a robust governance structure that includes a dedicated Group Data and AI Office, supported by Privacy compliance specialists embedded within each of the Amadeus corporate functions and business units, as well as within some of our key locations. These roles ensure that privacy responsibilities are clearly defined and consistently implemented across all regions and business units. The Group Data and AI Office is responsible for defining the data privacy vision and strategy, organizing the resources dedicated to privacy compliance and managing the Amadeus privacy program. It reports to top management and the Board of Directors regularly on the privacy program maturity and effectiveness, investigations and compliance risks.

 

Independent oversight

Amadeus appoints Data Protection Officers (DPOs) where required and maintains direct lines of accountability to senior leadership, including the Amadeus Risk and Compliance Board.


Amadeus Privacy principles

The Amadeus Privacy Policy outlines the core principles that guide how we collect, use, and protect personal data. It reflects our commitment to transparency, accountability, and respecting the privacy rights of individuals across all our operations.

Lawfulness

Personal data must be collected and processed lawfully and only after ensuring a legal basis in place for doing so.

Transparency

Information about how personal data is processed must be provided to the customer, to the individuals whose personal data are undergoing processing or to both in some cases.

Proportionality

The processing of personal data must be minimized and restricted to what is necessary. This involves limiting the time for which personal data is kept and limiting the communication of personal data within Amadeus and/or with third parties.

Privacy by design

Every single initiative that involves the processing of personal data is mandatorily subject to the Privacy by Design Process for the assessment and handling of privacy compliance risks.

Respect for individuals' rights

Individuals' rights with regards to their personal data must be respected and services must be designed in a way that so allows.

Security

Personal data must be duly protected from breaches of confidentiality, integrity, availability and resilience. Security policies must be followed.
Best Privacy Programme Award

Amadeus has been shortlisted for the PICCASO Awards Europe 2025

Being shortlisted is a remarkable accomplishment—especially in a year with a record‑breaking number of entries. It reflects the exceptional work and unwavering dedication of our teams.

Contact us for any questions about Amadeus' Privacy practices