Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Building a GDPR-Compliant Data Repurposing ProgramData Privacy
6 min readFor Compliance Officers

Building a GDPR-Compliant Data Repurposing Program

The Spanish Data Protection Agency's EUR 18 million fine against Amadeus IT Group highlights a compliance gap that affects many organizations, not just those in the travel sector. When your team collects personal data through intermediaries and later repurposes it for product development or analytics, your transparency obligations increase significantly.

This guide will help you build a compliant data repurposing program when processing personal data without direct consumer relationships.

The Problem: Indirect Collection and Secondary Use

Your team processes personal data collected through partners, resellers, or integrated platforms. Later, your product team wants to use that data to train algorithms or develop new features. Your privacy policy mentions "product improvement" in paragraph seven, and you assume legitimate interest covers it.

It doesn't.

The Amadeus case demonstrates why: the AEPD found that Amadeus violated both Article 14 (transparency when data isn't collected directly from data subjects) and Article 6 (lawful basis for processing) when it repurposed Passenger Name Record data from 2019-2021 for a hotel chain pilot project in 2021-2022. Amadeus's own internal analysis had flagged legitimate interest as unsuitable for this processing, yet the company proceeded anyway.

If your organization operates in a B2B context where end users don't know you exist, generic privacy policy language won't satisfy Article 14. And legitimate interest requires more than a checkbox.

What You Need Before Starting

Documentation audit:

  • Document all current data processing activities in your Record of Processing Activities under Article 30
  • Tag existing privacy policies and notices by collection point
  • Create data flow diagrams showing where personal data enters your systems and who controls collection
  • Review any previous legitimate interest assessments or Data Protection Impact Assessments

Legal clarity:

  • Confirm your controller/processor status for each processing activity
  • Identify your lead supervisory authority if you operate cross-border in the EU
  • List all data categories you process, with source systems documented

Technical inventory:

  • Identify systems where you store personal data collected indirectly
  • Review retention schedules currently in force
  • Check any existing opt-out or preference management mechanisms
  • Review access logs showing who queries historical data

Stakeholder alignment:

  • Engage product, engineering, and data science teams who might propose secondary uses
  • Secure legal and compliance sign-off authority for new processing activities
  • Coordinate with communications or customer success teams who interface with data subjects or intermediaries

Step-by-Step Implementation

Step 1: Map your indirect collection chains

For every dataset containing personal data, document:

  • The original purpose for collection
  • The intermediary who collected it (airline, agency, partner platform)
  • Whether data subjects received notice at collection mentioning your organization by name
  • How long ago the data was collected

Create a matrix: Data Category | Original Purpose | Collected By | Data Subject Awareness | Age of Data

This exercise reveals your Article 14 exposure. If data subjects don't know you process their data, you can't rely on "reasonable expectations" for secondary use.

Step 2: Draft activity-specific transparency notices

Generic privacy policy updates won't suffice for novel processing activities. When you plan to repurpose data, create a standalone notice that includes:

  • Your identity and contact details as controller
  • The specific new purpose (not "product development" but "analyzing booking patterns to recommend hotel inventory optimization")
  • The categories of personal data involved
  • The legal basis you're relying on and why it applies
  • Retention period for this specific processing
  • Data subject rights, including how to object if you're using legitimate interest
  • Whether data will be shared with third parties for this purpose

Step 3: Conduct a legitimate interest assessment (if applicable)

If you're considering legitimate interest as your legal basis, document:

  • Your specific legitimate interest (be precise: "reducing booking abandonment" not "business operations")
  • Why this interest is genuine and current
  • Whether data subjects would reasonably expect this processing given the original collection context
  • The necessity test: could you achieve the same goal with less intrusive means?
  • The balancing test: does your interest override data subjects' rights and freedoms?
  • Safeguards you'll implement to protect data subjects

The Amadeus decision shows that internal analysis matters. If your own privacy team flags concerns about using legitimate interest, document why you're proceeding or choose a different basis.

For data collected years ago through intermediaries, legitimate interest faces steep hurdles. Data subjects booking a flight in 2021 don't reasonably expect that booking data to train a hotel recommendation engine in 2024.

Step 4: Implement technical controls before processing begins

Before you repurpose any data:

  • Apply Data Minimisation: extract only the fields necessary for the new purpose
  • Implement access controls limiting who can query the repurposed dataset
  • Configure audit logging for all access to the data
  • Build an objection mechanism that actually stops processing for individuals who opt out
  • Set a retention deadline for the repurposed dataset (don't inherit the original retention period automatically)

Step 5: Deliver the transparency notice

This is where indirect collection gets complex. You have three options:

  1. Direct notification: Email data subjects if you have contact information (rarely feasible in B2B contexts)
  2. Intermediary notification: Require your partners/resellers to forward your notice to data subjects (requires contractual leverage)
  3. Public notice with reasonable efforts: Post the notice prominently and take additional steps to make it visible to affected populations (minimum viable approach)

Document which method you used and why. If you chose option three, document the "reasonable efforts": did you notify intermediaries to update their own privacy policies? Did you post notices in user-facing interfaces? Did you issue a press release for large-scale processing?

Step 6: Update your Record of Processing Activities

Add the new processing activity with:

  • Reference to the specific transparency notice
  • The legal basis and justification
  • Retention period
  • Security measures
  • Any third-party recipients

Validation: How to Verify It Works

Test your objection mechanism:

  • Submit a test objection using a dummy data subject record
  • Verify that processing stops for that record within your documented timeframe
  • Confirm the objection is logged and survives system updates

Audit data subject awareness:

  • Survey a sample of data subjects (if you have contact information) or intermediaries
  • Ask: "Are you aware that [your organization] processes your data for [new purpose]?"
  • If awareness is below 50%, your transparency approach needs strengthening

Review access logs:

  • Quarterly, audit who accessed the repurposed dataset
  • Flag any access outside the approved use case
  • Verify that users who objected are excluded from queries

Legal basis stress test:

  • Every six months, revisit your legitimate interest assessment (if applicable)
  • Ask: has the data aged further? Have data subject expectations changed? Have regulators issued new guidance?
  • Document the review even if you conclude the basis remains valid

Maintenance and Ongoing Tasks

Quarterly:

  • Review new product proposals for secondary data use
  • Update your data repurposing register
  • Audit objection logs and processing exclusions

Annually:

  • Refresh your legitimate interest assessments for all active repurposing activities
  • Review transparency notices for accuracy (purposes may evolve)
  • Train product and engineering teams on the approval process for secondary use

When circumstances change:

  • New supervisory authority guidance on legitimate interest → reassess all LI-based processing
  • Partner or intermediary changes → verify transparency chain remains intact
  • Data breach involving repurposed data → notify based on the secondary purpose, not just the original collection purpose

The Amadeus fine demonstrates that regulators will scrutinize how you handle data collected through indirect relationships. Your compliance program must account for the full lifecycle, not just the initial collection. When you build these controls proactively, you avoid the position Amadeus found itself in: defending a processing activity your own team had flagged as problematic.

Promotional banner for the Penetration Report Template Kit

You Might Also Like