Last updated: September 2026
The protection of your personal data is an important concern for us at Swiss International Air Lines Ltd. In the following, we explain how we process your personal data in connection with your use of the services and products we offer through our website, app, and other means, and outline your rights in this context.
We have based this Data Protection Notice on both the Swiss Federal Act on Data Protection (“FDPA”) and the European Union’s General Data Protection Regulation (“GDPR”). Whether these and/or other data protection laws apply depends on the individual case. Unlike the FDPA, the GDPR generally requires processing to be based on a specific legal basis. Where relevant, we therefore refer to the legal bases under the GDPR to explain the grounds on which we process personal data.
Please note that additional information may apply to specific data-processing activities, such as those carried out in connection with our air-freight division, Swiss WorldCargo. We also often provide you with the relevant information at the place where we collect your personal data. Please also note the contractual conditions applicable to individual passenger services, in particular our General Conditions of Carriage.
1. Who is the data controller?
The controller within the meaning of the FDPA and GDPR for the processing described in this Notice is:
Swiss International Air Lines Ltd.
Obstgartenstrasse 25
8302 Kloten
Switzerland
(referred to in this Notice as “SWISS”, “we” or “us”)
2. Who can I contact?
If you have any further questions about data protection in connection with our website or the services and products offered by us, please contact our data protection officer and team at dataprotection@swiss.com.
Inquiries not related to data protection, such as requests or feedback on individual bookings or services, will not be answered or forwarded by our data protection team. Please contact our Customer Support, use the appropriate contact form, or contact your SWISS contact if you are representing a business partner.
Representative in the European Union
Unsere Vertretung in der EU gemäß Art. 27 DSGVO ist die Swiss International Air Lines AG Niederlassung Frankfurt, Cargo City Süd 558 c, 60549 Frankfurt am Main.
3. What personal data do we collect?
Personal data is any information about an identified or identifiable natural person that you provide to us or that we collect. These are in particular:
Booking data: If you book a flight or flight-related service with us, the content data entered by you and the content data collected about you (in particular name, contact details, date of birth and payment data) as well as the information provided to you by us will be processed. In addition, we collect information about time, scope and, if applicable, place of your booking. In individual cases, your nationality and voluntary information on frequent flyer programs will also be collected. If you book transportation services, we may process information about transportation arrangements that could indirectly reveal sensitive data, for example the information about a required wheelchair. If bookings are made for minors, the contact details of the legal guardians will also be collected.
Check-in data: As part of the check-in and boarding process, we process your booking data, information about your baggage, security data (e.g. your boarding time, security check status, timestamps regarding your check-in process), data about your entry documents (passport, visa, etc.) if applicable, as well as any other contact details, such as your emergency contact.
API data: API (Advanced Passenger Information) data contains the information from your travel document (e.g. passport), such as name, date of birth, nationality, passport number, gender.
PNR data: PNR (Passenger Name Record) data is collected and processed by us when we operate certain flights. This includes, but is not limited to, your name, contact details, baggage information, API data, payment details, travel itinerary information and the history of booking changes. A detailed list of possible data elements can be found in Annex 1 Swiss PNR Act and Annex I PNR Directive (EU) 2016/681.
SSR data: Special service request information such as health data in the context of mobility aids or information about religion when providing meals on board.
Medical data: Information on the processing of personal data relating to passengers requiring medical clearance.
Content data: When you use services on our website or in our app, such as the use of contact forms, customer service, newsletters or participation in competitions or surveys, the content data entered by you and the content data collected about you as well as the information provided to you by us will be processed.
Cookie data: Data collected by cookies we use during your visit to the website or app.
Login data: Some services on our website or in our app require registration (e.g. TravelID, e-mail newsletter). For this purpose, some information is mandatory (e.g. e-mail address), other information can be added voluntarily (e.g. gender, name). As part of the registration process, we also collect your IP address and time of registration.
Server log data: When you use our websites, data (such as the date and time of your visit, pages accessed and files requested, type and version of the web browser you use, type and operating system of the device you use and your IP address) are temporarily stored in a log file on our servers. If you access our offer via our app, the type and operating system of your mobile device and your IP address will be stored in addition to the information about your visit to the app.
We generally receive this personal data directly from you, for example when you make a booking, use our website or app, contact us, or use our services. We may also collect personal data automatically from your device or from your use of our websites, apps and other services. In addition, where necessary and permitted by applicable law, we may receive personal data from:
- other companies in the Lufthansa Group and companies (e.g. travel-service providers, or payment providers) involved in providing your booked services;
- persons acting on your behalf, such as family members, legal representatives or travel agencies;
- public authorities, courts and other parties in connection with official or legal proceedings.
If you provide us with personal data relating to another person, such as a family member or fellow traveler, please ensure that you are authorized to do so and that the person concerned has been informed about this Data Protection Notice.
4. What personal data is processed, for what purposes and for how long?
4.1 Booking flights and flight-related additional services
If you book a flight and/or flight-related additional services (such as seat reservations, luggage or animal transport, etc.) with us, we process your booking data for the purpose of issuing a flight ticket or booking confirmation of the flight-related service booked. If you rebook or cancel your flight or flight-related additional service, we will process your booking data accordingly.
The legal basis for the processing is the conclusion and performance of a contract with you for the operation of a flight or flight-related services, Art. 6 para. 1 lit. b GDPR.
In the event that special personal data has to be processed when booking flight-related additional services (e.g. health data when booking transport aids or information about religion when booking meals on board), the processing is based on your explicit consent (Art. 6 para. 1 lit. a GDPR). The processing of the relevant special categories of personal data is additionally permitted under the exception in Art. 9 para. 2 lit. a GDPR.
In individual cases, we are also legally and contractually obliged to process the necessary data of passengers with disabilities or reduced mobility in order to ensure carriage (Regulation (EC) No. 1107/2006, Art. 6 para. 1 lit. b, c, Art. 9 para. 2 lit. g GDPR).
If you choose to pay on account or in instalments, we transmit the personal data necessary to arrange this payment option to the relevant payment service provider. The payment service provider is an independent controller and processes your personal data under its own responsibility, including for identification, creditworthiness assessments, payment-risk management and fraud prevention. By selecting this payment option, you accept the payment service provider’s terms and data protection notice. Where the GDPR applies, our transmission of the data is based on the performance of the contract with you (Article 6 para. 1 lit. b GDPR). The payment service provider determines the purposes and means of its processing and is responsible for complying with the relevant data-protection requirements.
4.2 Registration of a Travel ID
4.3 Miles & More frequent flyer programme
If you would like to collect miles with our frequent flyer programme Miles & More when booking a flight, we will pass on your booking data including your Miles & More card number to Miles & More GmbH (see also Section 5.2). The legal basis for data processing is the performance of the contract (Art. 6 para. 1 lit. b GDPR).
4.4 Operate flights and flight-related services (including Check-in data and Boarding data)
4.4.1 Notifications
In order to carry out the flights you have booked and other flight related services, we process your booking data already received as well as your check-in data. You may also receive flight-related notifications, such as gate changes or entry/baggage instructions. In the event of a delay, cancellation or other flight irregularity, we may use your personal data to inform you about the situation and to provide or assess any assistance and remedies available under applicable passenger-rights laws, including the Air Passenger Rights Regulation (EU 261/2004) where applicable.
4.4.2 Disclosure of API and PNR to Swiss and foreign authorities
Where necessary, in connection with the operation of your flight and in accordance with national and international legislation and agreements, we will transfer your API data or PNR data to the relevant authorities in Switzerland and abroad for the purposes of preventing, detecting, investigating and prosecuting terrorist offences and serious crime, and combating illegal immigration.
The legal basis for the processing is the conclusion and performance of a contract with you for the operation of a flight or the provision of flight-related services, Art. 6 para 1 lit. b GDPR. With regard to the transfer of your API and PNR data, the legal basis in individual cases is a legal obligation (Art. 6 para. 1 lit. c GDPR in conjunction with the applicable national or international legislation or agreements from which legal obligations arise for us). For example, in specific cases we are obliged to transfer your API data to the competent Swiss authorities in accordance with Art. 104 to 104b of the Swiss Federal Act on Foreign Nationals and Integration (FNAI; SR 154.20), and, once it enters into force, your PNR data in accordance with the Swiss Federal Act on the Processing of Air Passenger Data to Combat Terrorist and Other Serious Offences (Swiss PNR Act, see the following paragraph).
For flights to or from Switzerland, your PNR data will be disclosed to the Swiss Federal Office of Police (fedpol), including its Passenger Information Unit in accordance with the Swiss PNR Act. You have the right to request access to personal data relating to you that is processed under the Swiss PNR Act. The designated contact details for exercising this right will be made available by fedpol when the Swiss PNR Act enters into force. Where your PNR data is disclosed to a foreign authority in connection with such a flight, information on the relevant state and its passenger information unit will, where applicable, be provided by reference to the list of states to be maintained by fedpol.
SWISS has been disclosing PNR data to the passenger information units in the EU Member States, the United Kingdom, Norway, Türkiye, the United Arab Emirates (UAE), South Korea, the United States of America (USA) and Canada on the basis of applicable international agreements, national laws and directives issued by Swiss authorities. Examples of foreign legal bases are the PNR Directive (EU) 2016/681 and the corresponding national implementation laws in the EU Member States. France, in particular, requires air carriers to inform passengers as follows: “In accordance with Article L 232-7 of French Internal Security Code, please be informed that air carriers have to transmit reservation/checking and boarding data collected from their passengers (PNR/API) to the French national public services and competent authorities for the purposes and under conditions as defined in the Decree N° 2014-1095 dated 26/09/2014 and the modifying Decree N° 2018-714 dated 03/08/2018.”
4.4.3 Travel Document Verification
Where required or permitted by applicable law, we may also disclose relevant passenger data to competent public-health authorities for the prevention, detection and management of public-health threats, including communicable-disease outbreaks and related contact-tracing measures. This may include identifying passengers who may have been exposed to an infectious disease, for example through proximity to an infected passenger during a flight. Any such disclosure will be limited to the data necessary for the relevant public-health purpose. The legal basis for such disclosure is, as applicable, a legal obligation (Art. 6 para. 1 lit. c GDPR) or the performance of a task carried out in the public interest or in the exercise of official authority (Art. 6 para. 1 lit. e GDPR), in conjunction with the applicable public-health legislation. Where the data processed constitutes data concerning health, the disclosure will additionally be permitted only where an exception under Art. 9 para. 2 GDPR applies, in particular Art. 9 para. 2 lit. i GDPR or another applicable provision of Art. 9 para. 2 GDPR.
4.4.4 Emergency contact
You also have the option of storing the contact details of a person who would be contacted in an emergency (emergency contact). The processing of these contact details is carried out on the basis of the consent of the data subject (Art. 6 para. 1 lit. a GDPR). In this regard, when providing the contact details, you confirm that the consent of the data subject has been obtained.
4.4.5 Special Service Requests
In the event that special personal data has to be processed during the performance of flight-related services (e.g. SSR data), the legal basis for the processing of this data is your consent in accordance with Art. 9 para. 2 lit. a GDPR.
We are required under the applicable laws and regulations to ensure that our passengers possess the necessary travel documents, as well as any health and other documents required under the laws and regulations applicable in the countries of departure, destination and transit. These requirements are consistent with ICAO Annex 9, Chapter 3, Section H, paragraph 3.33.
In line with this obligation, the agents of our service providers may check the presence and apparent validity of passengers’ travel documents at the airport. For destinations with an increased risk profile or where there is doubt regarding the authenticity of a document presented, the agents may scan and retain copies of the documents for further verification and/or as evidence that the inspection was carried out.
If copies are retained, the retention period is generally one week. If we receive notification that a passenger has been refused admission, the relevant copies are retained for the duration of the investigation and any related legal proceedings.
The legal basis for checking your travel documents is that processing is necessary for the performance of the contract of carriage with you (Art. 6 para. 1 lit. b GDPR). The retention of copies of travel documents for verification purposes, to document the inspection carried out and to establish, exercise or defend legal claims is based on our legitimate interests (Art. 6 para. 1 lit. f GDPR). Where applicable law imposes a specific obligation on us to carry out or document such checks, the processing will additionally be based on compliance with a legal obligation (Art. 6 para. 1 lit. c GDPR). If the documents contain data concerning health, the processing will also be subject to an applicable exception under Art. 9 para. 2 GDPR, in particular Art. 9 para. 2 lit. i GDPR where the processing is necessary for reasons of public interest in the area of public health.
4.4.6 Connecting passengers at Zurich Airport
If you pass through border control (including the information systems of the Schengen Area) for your connecting flight at Zurich Airport, we may scan your boarding pass immediately after border control. We process the following information from the scan: the date of the flight, the origin and destination of the flight, the flight number, the check-in sequence number, and the date and time of the scan. We use this information to facilitate the transfer process and manage our ground operations, including baggage loading, and to help avoid delays.
The legal basis for this processing is our legitimate interest in facilitating connecting journeys, managing our ground operations and avoiding delays (Art. 6 para. 1 lit. f GDPR).
4.4.7 AI-supported counting during aircraft boarding
To increase aviation safety and optimize the boarding process, SWISS uses AI-supported counting technology. The technology helps to determine whether the number of passengers boarding the aircraft corresponds to the number of passengers who have checked in and supports safe and accurate baggage reconciliation.
The AI model is trained to distinguish passengers boarding the aircraft from flight and ground staff without identifying individuals. In this way, passengers and hand baggage can be counted reliably and automatically. The video recordings of boarding passengers are anonymized after successful counting and verification. The AI model is trained exclusively on anonymized data.
The automated counting of passengers and hand baggage items serves, in particular, to ensure that baggage belonging to passengers who do not board the aircraft, or who leave the aircraft again before departure, can be identified. SWISS uses passenger counting to fulfil this aviation-security requirement under the National Civil Aviation Security Programme of Switzerland and Commission Implementing Regulation (EU) 2015/1998 laying down detailed measures for the implementation of the common basic standards on aviation security.
To the extent that the automated counting is not required by applicable law, the legal basis for the processing is our legitimate interest in increasing aviation safety and optimizing the boarding process, including through passenger counting and the automation of related operational procedures (Art. 6 para. 1 lit. f GDPR).
4.5 Safety, Security and Unruly Passengers
We process personal data for safety and security purposes.
For example, we use video surveillance at specific premises for the detection and prosecution of criminal acts. In keeping with applicable aviation security requirements, we also monitor the area immediately in front of the cockpit door.
“Unruly Passengers” are passengers whose improper, aggressive or violent behavior, non-compliance with instructions, threats or other misconduct endangers or disrupts the safety or security of the flight, the crew, other passengers or third parties.
We record relevant incidents in a Passenger Disturbance Report (“PDR”). Depending on the nature and severity of the disturbance or misconduct, the PDR may include details of the incident and, where necessary, information from the passenger’s travel documents to identify the passenger. We may use this information to document, assess and prevent incidents, protect the safety and security of our flights, crew and passengers, and protect our rights.
We may disclose relevant information to the police and other authorities, and, in serious cases, refuse carriage, prohibit the passenger from traveling on SWISS flights (flight ban) or inform the crew of previous incidents. Where necessary and permitted by applicable law, we may also exchange relevant information within the Lufthansa Group and with other airlines to document, analyse and prevent fraud and incidents involving Unruly Passengers, and disclose information relating to harm, injury or criminal acts to authorities and insurance companies.
This processing is based on our legitimate interest in ensuring safety and security (Art. 6 para. 1 lit. f GDPR).
4.6 Your inquiries/feedback
If you send us inquiries via contact form, e-mail, chat or service calls, we process your content data to answer your request and, if applicable, the IP address, date and time of the request to avoid misuse of the contact form. With your explicit consent, we may record the call with you for quality assurance and training purposes. In the event that you inform us of possible errors in the website or app, we will use the data you enter and, if applicable, the data of your device to analyze and rectify the error you have reported.
The legal basis for the processing is Art. 6 para. 1 lit. f GDPR. Our and your (legitimate) interest in this data processing arises from the aim of answering your inquiries, solving any problems that may exist and thus maintaining and promoting your satisfaction as a customer or user of our website or app. If your request is aimed at initiating or executing a contract, the additional legal basis for the processing is Art. 6 para. 1 lit. b GDPR. The legal basis for the processing of data protection requests is Art. 6 para. 1 lit. c GDPR, as this is necessary to comply with legal obligations. Regarding the recording of phone calls the legal basis is your consent, Art. 6 para. 1 lit. a GDPR.
If the processing is based on the legal basis of the overriding legitimate interest (Art. 6 para. 1 lit. f GDPR), you may object to the processing of your data on grounds relating to your particular situation (see Section 7 below). We may continue processing your personal data if we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or if the processing is necessary to establish, exercise or defend legal claims..
This data will be deleted when our communication with you has ended, i.e. when the affected matter has been conclusively clarified and there is no further legitimate interest in storing it or there are no further legal obligations to store it. Your communication with our chat bot we will retain for 30 days. If you communicate with our staff, we will retain the data for 90 days.
4.7 Marketing Notifications
We process your data to send you marketing notifications.
For example, on our website, you can receive information about our products and services even without a Travel ID. In addition to our newsletter, you can also subscribe to the Best Price Alert to be informed about the best price for your individual flight route. In addition, you can receive other marketing notifications if you wish, such as notifications about flight bookings that you have not yet completed.
Your subscription to email advertising will be effective upon your confirmation. To do this, you must click on a link that we will send you in our confirmation email when you register for the newsletter.
The legal basis for the processing of your contact data is your consent (Art. 6 para. 1 lit. a GDPR). You may withdraw your consent to receive our promotional notifications at any time.
Without separate consent to receive marketing notifications, we contact customers who have already made bookings with us individually by e-mail with information about similar offers and services from us. However, you will only receive this information if and to the extent that (a) we have received your e-mail address from you in connection with the sale of a good or service, (b) we use this e-mail address for direct marketing of our own similar goods or services, and (c) you have not objected to receiving it.
The legal basis for the processing is our legitimate interest (Art. 6 para. 1 lit. f GDPR).
You can object at any time to the processing of your personal data for the purposes of marketing and product development, in whole or in part, or revoke any consent you have given.
You can object as follows:
- In case of e-mail notifications, you can use the unsubscribe link provided for you in each of them.
- Alternatively, you can send a message (keyword: data protection) via the contact form on our website and app or in writing or by e-mail to the email address in Section 2 above.
Your data will be deleted after your objection or the revocation of any consents you may have given, or otherwise at the latest after we have ceased to use it, or will only be stored in aggregated, anonymised form. Where necessary, we will store the fact of your objection and your respective contact details to prevent you from being contacted further. In the case of objection or revocation of consent regarding marketing, we will update your marketing preferences. Please note that an objection to marketing does not automatically result in the deletion of your booking data or Travel ID (Art. 6 para. 1 lit. b GDPR).
4.8 Further development and optimization of our services and offers
We process your data to optimize our services and products.
For example, we process your Booking data (excluding any sensitive data they may contain) as well as content data that we collect when communicating with you (see section 4.5), for the further development and optimization of our services, offers and AI tools used (such as our Chat Assistant) as well as for internal statistics. This processing is used in particular to optimize our customer service, to process your enquiries efficiently and to improve the customer experience with us and our range of services.
The legal basis for the processing is our legitimate interests in further developing and optimizing our services and offers as well as compiling internal statistics (Art. 6 para. 1 lit. f GDPR). You can object to the processing for the purposes of further development and optimization at any time (see Section 7 below).
We generally process your data for these purposes in anonymised form and delete it after two years. If, for example due to irregularities in the provision of services, it is necessary to store your data in order to comply with statutory retention obligations (e.g. in accordance with applicable bookkeeping and tax regulations)we will retain the relevant data for the statutory retention period.
Personal data collected during your interactions with our Chat Assistant or customer service channels may be used, in anonymised and aggregated form only, for the purpose of further developing and improving the AI tools we deploy. No personal data that directly identifies you, and no special category data within the meaning of Article 9 GDPR (including any health or mobility information provided as part of a special service request), is used for AI model training or fine-tuning.
We may invite you to participate in customer panels, market-research activities or customer-satisfaction surveys to obtain feedback on and improve our services, products and customer experience. Participation is voluntary. We process the personal data you provide in this context, including your responses and any related contact or participation data. Processing is based on your consent (Art. 6 para. 1 lit. a GDPR), which you may withdraw at any time with effect for the future.
4.9 Cookies and similar technologies
We use cookies and similar technologies on our websites and apps, including the SWISS Magazine websites, for technical, analytical and marketing purposes. This may include displaying and measuring the performance of advertising, including advertising provided by third parties, as well as ensuring security, preventing fraud and correcting errors. Personalized advertising and other processing requiring consent are carried out only with your consent, where required by applicable law.
4.10 Securing the booking process and preventing fraud
In order to secure and optimise the booking process as well as to prevent fraud and to limit the risk of payment defaults, we process especially your payment data, name and address during the booking process and, if applicable, in any compensation or repayment transactions, in order to check whether there are any risks or anomalies. In addition, in the event of order cancellation, the data accrued up to the time of the order is cancelled is stored for the (technical) optimisation of the ordering process, for the detection of fraud patterns and in order to be able to answer customer inquiries about the order processes.
The legal basis for the data processing described in this section is Art. 6 para. 1 lit. b and lit. f GDPR. The legitimate interest results from the protection of your identity, the minimization of non-payment risks and the avoidance of fraud attempts.
This data is only stored for as long as necessary for the purposes stated. Where suspicious booking transactions are detected and data is processed in the fraud management system, the retention period is three years from the date on which the relevant data was recorded. Data will only be stored for a longer period where and for as long as statutory retention obligations apply or where further storage is necessary for the assertion, exercise or defence of legal claims.
4.11 Enforcement of legal claims
For the purpose of enforcing our own legal claims and defending our legal position, we process the personal data required for enforcement or defense in individual cases. This can be booking data, among other things.
The legal basis for the processing is our legitimate interest in enforcing legal claims and defending our own legal position (Art. 6 para. 1 lit. f GDPR).
The data required for this will be deleted after the conclusion of the legal dispute or after the statutory retention period has expired.
4.12 Ensuring the technical infrastructure and provision of the website and app
The processing of the server log data serves the technical provision of the website or our app and then to ensure system security and protection of the technical infrastructure in order to detect malicious access to our website or app.
The legal basis for the processing is our legitimate interest in providing the website / app with our services and protecting our technical infrastructure (Art. 6 para. 1 lit. f GDPR). The processing is absolutely necessary for the use of our website and app.
This data will be deleted after 180 days after the end of your session at the latest.
4.13 General retention principles
We retain personal data for the periods stated in this Data Protection Notice or, where no specific period is stated, for as long as necessary for the purposes for which it was collected. We may retain personal data for longer where this is required by law or necessary to establish, exercise or defend legal claims. Once the applicable retention period has expired, we delete or anonymize the data, unless further retention is required or permitted by law.
In particular, Swiss statutory retention obligations may require us to retain certain personal data for extended periods. For example, Swiss law requires certain accounting records to be retained for ten years. Specific retention periods may also apply to records required for tax purposes, including VAT records. SWISS may generally retain relevant contractual data for up to ten years after the end of the contractual relationship where this is necessary to comply with statutory retention obligations or to establish, exercise or defend legal claims. Depending on the type of data and the circumstances of the individual case, shorter or longer retention periods may apply.
5. To whom do we transfer your data?
Within the framework of the above-mentioned data processing and the respective legal bases, your data may be transferred to the following categories of recipients.
5.1 Transfer of data to processors
In some cases, we use service providers in compliance with the legal requirements by way of order processing, i.e. on the basis of a contract on our behalf, according to our instructions and under our control.
Processors are in particular
- vicarious agents, e.g. service providers for ground handling services, claim handling companies and other additional services in this context,
- customer service centers (call center, mail servicing, chat provider),
- other service providers, e.g. for the provision of the website, the sending of newsletters, the processing of feedback, the compilation of international aviation statistics,
- Cloud service providers and hosting providers (for data storage and infrastructure),
- Service providers for the operation and maintenance of IT systems,
- technical service providers that we use to provide our website and app and the respective functionalities, e.g. technically necessary cookies,
- service providers for the practical implementation of advertising and marketing, e.g. service providers for e-mail sending and analysis cookies.
In these cases, we remain responsible for data processing; the transfer and processing of personal data to or by our processors is based on the legal basis that allows us to process the data in each case. A separate legal basis is not required.
5.2 Transfer of data to Lufthansa Group Companies
Certain of your data will also be transferred to other companies of the Lufthansa Group. In this case, we can be joint controllers together with the airlines concerned for the processing of this specific data in accordance with Art. 26 GDPR.
In individual cases, the recipients are Air Dolomiti S.p.A Linee Aeree Regionali Europee (Dossobuono di Villafranca (VR), Via Paolo Bembo 70, Italy), Austrian Airlines AG (Office Park 2, Postbox 100, 1300 Vienna Airport, Austria), Brussels Airlines NV/SA (Kompaslaan 26, 1831 Machelen, Belgium), Deutsche Lufthansa AG (Venloer Straße 151-153, 50672 Cologne, Germany, Germany), Edelweiss Air AG (The Circle 32, 8058 Zurich Airport, Switzerland), Eurowings GmbH (Waldstraße 249, 51147 Cologne, Germany), EW Discover GmbH (Hugo-Eckener-Ring 1, FAC Building, 60549 Frankfurt a.M., Germany), Italia Trasporto Aereo S.p.A. (Via Venti Settembre 97, Rome, 00187, Italy), Lufthansa CityLine GmbH (Munich Airport, FOC, Südallee 15, 85356 Munich, Germany) and Lufthansa City Airlines GmbH (Munich Airport, FOC, Südallee 15, 85356 Munich, Germany, Germany) – together "Lufthansa Group Airlines".
Furthermore, we may transfer your data to other group companies, such as Miles & More GmbH (see Section 4.3 above) as well as other group companies involved in the provision of services to you.
For example, your data will be passed on to the Lufthansa Group Airlines if this is necessary for the operation of the booked flight. If you book a flight with us that is operated by another airline of the Lufthansa Group, we transmit your data to this airline in order to fulfill the contract with you (Art. 6 para. 1 lit. b GDPR). In addition, based on our legitimate interest, we share information about individuals who are subject to flight bans (Art. 6 para. 1 lit. f GDPR).
For the purpose of further developing and optimizing our services and offers (see also section 4.7 above), we may pass on your data to the Lufthansa Group Airlines. The legal basis for the disclosure is the legitimate interest of the airlines involved (Art. 6 para. 1 lit. f GDPR) to improve their own services for you and other customers for the future and to adapt their own offer to your needs.
The joint controllers have entered into an arrangement pursuant to Article 26 GDPR determining their respective responsibilities for compliance with the obligations under this Regulation. The essence of that arrangement is as follows: Deutsche Lufthansa AG acts as the primary point of contact for the exercise of data subject rights arising from jointly processed data; requests submitted to any other Lufthansa Group Airline will be forwarded to the competent entity without undue delay. The full text of the arrangement is available on request by contacting the data protection officer set out in Section 2 above. However, your rights under Section 7 of this data protection notice can be asserted against any group company involved.
5.3 Transfer of data to third parties
In addition, we also transfer your data to third parties, i.e. partners that provide services as independent controllers.
These partners are in particular:
- Other airlines, rail partners and providers of ground transport services that carry out part of the transport (the legal basis for the data transfer is Art. 6 para. 1 lit. b GDPR);
- payment service providers with whom we cooperate and with the help of which you can make the flight booking with us (the legal basis for the data transfer is Art. 6 para. 1 lit. b GDPR);
- communications provider that operates the in-flight entertainment portal on board and provides you with access to the Internet and entertainment content, e.g. FlyNet (the legal basis for the data transfer is Art. 6 para. 1 lit. b GDPR); banks and payment service providers with whom we cooperate to process relevant booking, payment, contact and technical data as necessary to secure and optimize the booking process, prevent fraud, detect suspicious activity, and limit the risk of payment defaults (the legal basis for the data transfer is Art. 6 para. 1 lit. f GDPR);
- state authorities and institutions, e.g. on the basis of entry requirements or police activities and investigations (the legal basis for the data transfer is Art. 6 para. 1 lit. b or c GDPR)
- service providers engaged in the event of service disruptions, e.g. hotels (the legal basis for the data transfer is Art. 6 para. 1 lit. f GDPR).
5.4 Transfer of data to third countries
In some cases, we transfer personal data to recipients who are not in the immediate scope of the FADP or GDPR, but located in third countries worldwide (see for passenger data in particular Section 4.4 above). Unless the Swiss Federal Council and the EU Commission have decided that these countries provide an adequate level of legal protection for your personal data, we must either ensure that we implement sufficient safeguards for your personal data or that one of the legal exceptions applies.
In accordance with Art. 16 para. 2 lit. d FADP and Art. 46 para. 2 lit. c GDPR, we regularly use EU standard contractual clauses adopted by the EU Commission and recognized by the Swiss Federal Data Protection and Information Commissioner with recipients in third countries without an adequacy decision. Nevertheless, in some third countries, there is a risk that your data may be demanded by national authorities from the recipients for control and monitoring purposes without the requirements being clearly regulated or appropriate legal remedies available. To the extent that such risks exist that are considered unreasonable by the jurisdiction of the European courts (for example, as in some constellations in the case of the USA), we will take additional safeguards and agreements to the extent possible. For more information on these third-country transfers, and in particular for a copy of the Standard Contractual Clauses, please refer to the contact details set out in Section 2.
In some cases, we also transfer your data on the basis of Art. 17 para. 1 FADP and Art. 49 para. 1 GDPR. This can be, for example, your explicit consent in accordance with Art. 17 para. 1 (a) FADP and Art. 49 para. 1 s. 1 (a) GDPR to the transfer of data to recipients in unsafe third countries, for example if our partners use cookies or comparable technologies on our website. Before giving consent, we explicitly inform you that the transfer carries possible risks for you because an adequate level of data protection and suitable safeguards are not available in the third country. If you give your consent, you accept that the risks described above, in particular access to your data by foreign authorities, will occur without further guarantees being agreed or additional protective measures being taken. In other cases, we may transfer your personal data to authorities in third countries on the basis of Art. 17 para. 1 (b) FADP and Art. 49 para. 1 s. 1 (b) GDPR in order to fulfill the flight booking you have made with us.
6. What kind of automated decision-making is used?
Automated decision-making (including profiling) is a data processing operation in which a decision is made automatically without any human intervention or assessment of the content.
We do not use solely automated decision-making that produces legal effects concerning you or similarly significantly affects you, pursuant to Art. 21 para. 1 FADP and Art. 22 para. 1 GDPR. In the event that we use such a system in the future, we will inform you in accordance with the legal obligations.
7. What rights do you have?
In relation to the processing of your personal data by us, you have the following rights, provided that the applicable conditions are met and no statutory exceptions apply:
Right of access: You have the right to obtain confirmation from us as to whether or not we are processing your personal data. If personal data is processed by us, you have the right to obtain information about this data as well as about the purposes of processing, data categories, data recipients, storage period, data origin, information about your rights and the existence of automated decision-making, including profiling.
Right to rectification: If your personal data is incorrect or incomplete, you have a right to rectification.
Right to erasure: You have the right to request the erasure of your personal data. This is also known as the right to be forgotten. There is no blanket right to erasure of all personal data. For example, we may be legally obliged to continue to process individual personal data or the processing may be necessary to defend our interests in case of legal claims.
Right to restriction of processing: You have the right to request the restriction of the processing of your personal data. If processing is restricted, the data will be blocked.
Right to data portability: If the processing is based on your consent or if the personal data must be processed by automated means for the performance of a contract, you have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format or to transmit this data to another controller.
Right of revocation: If you have consented to the processing on the basis of a corresponding declaration, you can revoke your consent at any time for the future. The lawfulness of the data processing carried out on the basis of the consent before the revocation is not affected by this.
Right to object: Insofar as we process your data to safeguard legitimate interests, you can object to this processing at any time using our data protection contact form if there are reasons arising from your particular situation that oppose data processing by us. You have the right to object at any time to the processing of your personal data for the purpose of direct marketing, without providing any reasons. The data processing will then be terminated unless SWISS can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or if the processing serves to establish, exercise or defend legal claims.
8. Right to lodge a complaint with a supervisory authority
If you have any questions, concerns or complaints regarding the processing of your personal data, we encourage you to contact our data protection officer and team first at dataprotection@swiss.com.
This does not affect your right to lodge a complaint with a competent data protection supervisory authority. The competent supervisory authority for SWISS in Switzerland is:
Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1
3003 Berne Switzerland
https://www.edoeb.admin.ch/en
This data protection notice may be amended to reflect changes in our data processing practices or legal requirements. The current version is available on our website at any time.