180 incidents on record · 2026 Headlights Incident reports by Ellie Harris · Melbourne
10 new this week Library last updated 30 August 2026
← The incident library
HD-INC-172
Aviation · Ireland · 2024 · Biometric verification of customers, subject to an open regulatory inquiry

Ireland's data protection regulator opened an inquiry into an airline's use of facial recognition to verify passengers who had booked through third party websites or online travel agents

By Ellie Harris · Filed Inquiry commenced and announced 4 October 2024

Alleged: Ryanair developed or deployed the AI system implicated in this incident. Details are drawn from public reports; parties are presumed innocent of any wrongdoing not established by an official finding.

Ireland's data protection regulator opened an inquiry into an airline's use of facial recognition to verify passengers who had booked through third party websites or online travel agents

What happened

It was reported that the Data Protection Commission in Ireland announced on 4 October 2024 that it had opened an inquiry into an airline’s customer verification process under section 110 of the Data Protection Act 2018. The regulator said the verification methods included facial recognition technology using customers’ biometric data. The inquiry would examine whether the airline’s use of those verification methods complies with the General Data Protection Regulation.

It was reported that passengers who booked through third party websites or online travel agents were asked to complete extra verification, while those who booked directly were not. The reported options were facial recognition at booking for a 59 cent fee, which the airline says it does not benefit commercially from, a form taking up to seven days, or arriving at the airport two hours early. The airline said it welcomed the inquiry, that the process protects customers from non approved online travel agents, and that its methods comply with the regulation.

What an auditable version would have shown

The sources reviewed do not establish whether the processing was lawful. That is what the regulator is investigating. A privacy advocacy group complained about the same verification process to the Spanish data protection authority in July 2023. Its case record shows that the complaint was sent to the Irish regulator, as lead supervisory authority, on 29 September 2023, more than a year before the inquiry was announced. The sources reviewed did not identify how many passengers were asked to verify, how many chose facial recognition instead of another option, or how long their biometric data was kept.

For each verification, the airline could keep a record of the lawful basis it relied on, the alternatives offered and which option the passenger chose. It could also record what data was collected, where it went and when it was deleted. Those records would allow the airline to say how many passengers used facial recognition and how many completed the same booking without it.

Where the gap was

The regulator said the verification process included facial recognition using customers’ biometric data. It also noted the European Data Protection Board’s position that biometric data and facial recognition entail heightened risks to the rights and freedoms of data subjects.

A ConstraintGate is designed to check the standing rule for this type of data before it is collected, and require an explicit recorded approval when the rule is not satisfied. A ConductRecord keeps the basis relied on, the alternatives offered, what data was collected and how long it was kept. This gives the organisation a record of what happened if the regulator asks. Neither decides whether the processing was lawful. That remains with the regulator.

What governance should have looked like

The airline’s position is that its verification process protects customers from non approved online travel agents and fully complies with the regulation. The regulator has not published a decision, and the sources reviewed do not establish that any part of the process was unlawful.

Where an organisation asks people for biometric data as part of a transaction, best practice would be to record why it is legally entitled to collect that data before collecting it. It should also record what other options the person was offered, which one they chose, how long the biometric data was kept and when it was deleted.

Failure Pattern: it was reported that customers booking through third parties faced an extra verification process that could involve handing over biometric data. Whether that processing was lawful later became the subject of a regulatory inquiry.

Governance Principle: an organisation collecting biometric data should be able to show why it was entitled to collect it, what other option the person was given, what data was collected, where it went and how long it was kept.

The reference implementation of ConstraintGate and ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed and free to install. The repository is public now.

Sources

The mailing list

Fresh incident reports every week. One email to match.

We add new incidents to the library regularly, and send a single short email each week with what's new. The library stays free and open; this is just how you keep up with it.

No tracking. Unsubscribe in one click.

The record

An auditable system would have produced a signed, tamper-evident record the moment this happened: what the system did, the version that did it, the basis it acted on, and the action taken, and Ryanair could have produced it on demand.

This is the record the system as deployed did not produce in a signed, auditable form.

What this teaches
Capture what happened when it happens
What the system did, the version that did it, the basis it acted on, and the action taken, recorded at the moment, not reconstructed after.
Sign it, so no one has to trust the record-keeper
A tamper-evident entry. Edit it later and the signature breaks. The record does not ask for the benefit of the doubt.
Make it verifiable by anyone
A court, a regulator, a customer's lawyer can check the record themselves, without taking the company, or us, at our word.

Headlights summarises publicly reported AI incidents. All summaries are independently written, attributed to their original sources, and intended for research and educational purposes. Allegations are identified as such until established through official findings.

Last reviewed August 2026. This report is based on the sources listed above and reflects information available at the time of review; later developments may not be captured. Where a person is described as charged with or alleged to have done something, that allegation is unproven unless a conviction or a court or regulatory finding is stated. Headlights publishes journalism and commentary, not legal advice.

Want to write back?

Direct to my inbox.

ellie@useheadlights.com →