Traveler data: avoiding GDPR fines in 2026

Map your data flows, audit your service providers, and secure your traveler data before 2026. A 12-point checklist for decision-makers to avoid GDPR fines.

15.9.2026

Corporate travel programs handle tens of thousands of pieces of personal data every year: bank details, passport information, medical preferences, and travel habits. In 2026, the CNIL is stepping up inspections of companies managing cross-border data flows. A single leak is enough to trigger a fine of up to 4% of global annual turnover. Yet, most Travel Managers still don't know who actually has access to what within their processing chain. GDPR for traveler data requires full traceability, from booking to archiving. Here is how to map your risks and secure your flows before the next audit.

How GDPR is transforming travel program management in 2026

The European regulation isn't changing in 2026, but its enforcement is tightening. Regulatory authorities now have three years of case law to target recurring flaws: lack of a designated DPO, supplier contracts without GDPR clauses, and excessive data retention after trips. Companies that outsource their travel management without verifying their providers' compliance face joint liability in the event of a breach.

The new development: cross-audits between the CNIL and tax authorities. A tax audit can trigger a GDPR inspection if expense receipts reveal poorly protected personal data. Travel Managers must therefore synchronize their accounting obligations with their data protection policy. This requires a complete review of the chain: who collects, who processes, who stores, and who deletes.

The main risk is no longer a spectacular data breach, but the accumulation of micro-violations: an Excel file shared without encryption, a provider keeping passports beyond the legal limit, or an API exposing data without explicit consent. Each of these situations constitutes a sanctionable offense.

Analyste de données cartographiant les flux d'informations sur un tableau blanc avec son équipe

Mapping traveler data flows: who has access to what

The first step is to physically trace the path of traveler data within your organization. Take an international flight booking, for example: the employee enters their information into your booking tool (TMC or internal platform), which then transmits it to the airline, the GDS, your expense management system, your travel insurer, and potentially your Duty of Care provider. Each entity becomes a data controller or processor under GDPR.

For each flow, you must identify: the legal basis for processing (employment contract, legal obligation, legitimate interest), the retention period, the security measures applied, and any transfers outside the EU. A spreadsheet is no longer enough: you need an up-to-date processing register, including the contact details for each provider's DPO and the signature dates for GDPR contractual clauses.

The most common gray areas: data collected "just in case" (passport numbers for domestic flights), backup files that are never purged, and administrator access that is never revoked after changing providers. Every piece of data collected must have a specific, documented purpose. If you cannot justify why you are keeping information, you are in violation.

The 5 high-risk areas in a corporate travel program

Area 1: Online booking tools. Many platforms store payment methods and traveler preferences indefinitely. Verify that your TMC or self-booking tool applies an automatic purge after the trip ends, and that bank data is tokenized rather than stored in plain text.

Area 2: International transfers. As soon as an employee travels outside the EU, their personal data may be transferred to servers located in countries without an adequacy agreement (such as the United States, China, or India). You must have signed Standard Contractual Clauses (SCCs) with each relevant provider and documented security guarantees equivalent to GDPR standards.

Area 3: Duty of Care providers. These solutions collect real-time location data, medical information, and emergency contacts. They must be configured to collect only what is strictly necessary, with explicit traveler consent and automatic deletion 30 days after the return date.

Area 4: Expense management systems. Scanned receipts often contain sensitive data: hotel invoices with room numbers, taxi receipts with personal addresses, and restaurant receipts revealing dietary habits. These documents should be anonymized or deleted once accounting validation is complete, unless there is a legal obligation to retain them.

Area 5: Old files and backups. Companies sometimes keep travel history for 10 years for tax purposes, even though the GDPR requires a proportionate retention period. You must define a retention policy for each data type and automate the purging of obsolete archives.

Travel Manager vérifiant les paramètres de sécurité sur un tableau de bord numérique

GDPR compliance for travelers: a 12-point checklist for decision-makers

  1. Up-to-date processing register: document every traveler data flow, including its purpose, legal basis, and retention period.
  2. Identified and reachable DPO: your employees must know who to contact to exercise their rights (access, rectification, erasure).
  3. GDPR clauses in all supplier contracts: TMCs, airlines, hotels, rental agencies, insurers, and booking platforms.
  4. Standard Contractual Clauses (SCCs) for transfers outside the EU: mandatory whenever a service provider stores data on non-European servers.
  5. Explicit consent for sensitive data: health, real-time location, religious or dietary preferences.
  6. Defined and enforced retention periods: automatic purging after the trip ends, unless there is a documented legal obligation.
  7. Data encryption in transit and at rest: secure APIs, encrypted files, and access restricted by strong authentication.
  8. Breach management procedure: response plan in the event of a leak, notification to the supervisory authority within 72 hours, and communication to the affected individuals.
  9. Documented and enforceable traveler rights: process for handling requests for access, rectification, and erasure.
  10. Regular provider audits: annual verification of their GDPR compliance and updates to contractual clauses.
  11. Training for Travel and Finance teams: raising awareness of GDPR risks and best practices for data handling.
  12. Documentation of international transfers: register of recipient countries, security guarantees, and the legal basis for each transfer.
Auditeur d'entreprise interrogeant un prestataire de services lors d'une réunion de conformité

Auditing your travel providers: the right questions to ask

A GDPR audit of your suppliers is not just about asking for a certificate of compliance. You need to verify their practices in concrete terms. Start by requesting their processing register: what data do they collect, for what purposes, and for how long is it stored? If the provider cannot provide this document, it is an immediate red flag.

Next, ask about server locations and any potential subcontractors. Many TMCs use GDS systems hosted in the United States or call centers located in India. Every subcontractor must be identified in the contract, with the same GDPR guarantees as the primary provider. Ask for the standard contractual clauses signed with these subcontractors.

Check technical security measures: data encryption, access management, backup policies, and breach notification procedures. Ask for the latest security audit report and the date of the last penetration test. A serious provider should be able to supply these items within 48 hours.

Finally, test the responsiveness of the provider's DPO. Send a dummy data subject access request (accessing data for a test traveler) and measure the response time. GDPR mandates a maximum of one month. If the provider takes longer or does not understand the request, you have a compliance issue.

A compliant provider must also provide you with a clear responsibility matrix: who does what in the event of a breach, who notifies the supervisory authority, and who informs the affected travelers. This division of labor must be formalized in a contract, with precise deadlines and penalties for non-compliance.

Strategic Conclusion

GDPR compliance for traveler data is not just an IT project; it is a complete overhaul of your processing chain. Companies that wait until 2026 to act risk immediate sanctions and a loss of employee trust. The priority: map your actual data flows, audit your existing providers, and document every process with a solid legal basis. The tools exist (automated registers, standardized contractual clauses, encryption solutions), but they require clear governance between Travel Management, IT, Legal, and Finance. GDPR imposes joint liability: if a breach occurs at a provider, you are liable if you have not verified their compliance. It is better to invest in a full audit now than to pay a fine of 4% of your turnover in 2026.