Reinier advises national and international companies
reinier.russell@russell.nl +31 20 301 55 55Niek is an expert in corporate and financial law
niek.vandergraaf@russell.nl +31 20 301 55 55This newsletter highlights the key developments in EU law and their practical implications for the aviation sector.
The European regulatory landscape is undergoing a period of intense change, with airlines facing rising compliance pressures across multiple fronts simultaneously. In passenger rights, recent case law on passenger claims not only focuses on extraordinary circumstances but also on the question whether airlines offered passengers the earliest available re-routing. In environmental and climate policy, free carbon allowances are being phased out, and mandatory blending of sustainable aviation fuels has taken effect. Cybersecurity, data protection and competition rules are also being updated in parallel. These developments together impose new requirements on airlines in terms of operating costs, process design and compliance systems.
This newsletter highlights the key developments and their practical implications for the aviation sector. In short,
Recently there has been an interesting development regarding extraordinary circumstances. In T‑134/25 (European Court of Justice, 21 January 2026), the Court ruled that an air traffic management decision may constitute an extraordinary circumstance – irrespective of whether that decision itself caused a delay of three hours or more. The key question is whether the decision was beyond the airline’s actual control and whether the airline contributed to that decision. The defense is not automatic; each case requires individual assessment. Airlines should ensure that ATC slot history and all relevant communications are systematically preserved.
Even where extraordinary circumstances are established, an airline must prove that it took all reasonable measures to mitigate the consequences of the disruption. In practice, this often means offering the earliest available re‑routing to the passenger’s destination, including on flights operated by other airlines. Dutch courts are applying this requirement with increasing strictness. If a passenger suggests that an earlier alternative was available and an airline cannot demonstrate that it indeed offered the first available option, compensation is generally awarded.
The revised EU 261/2004 Regulation was formally approved by the European Parliament and is expected to take effect in mid‑2027. The key elements include the conditions for compensation in cases of delay, complaints procedures, the concept of extraordinary circumstances, price transparency, carry-on luggage, passenger information, the rights of disabled persons and persons with reduced mobility, and the prohibition of certain “no-show” practices for return flights. Airlines should especially take into consideration the following changes:
In July 2026, the European Commission published a proposal to revise the EU ETS Directive (Directive 2003/87/EC), which is currently under negotiation. Among other changes, the proposal would clarify the treatment of CO₂ captured from the atmosphere or from zero-rated sources by assigning such CO₂ an emissions factor of zero when released in an EU ETS-covered activity.
The proposal also addresses the accounting of captured CO₂ across the carbon capture, transport, utilization and storage chain.
For airlines, the continued phase-out of free EU ETS allowances means that carbon costs will become an increasingly important component of operating costs and route economics.
Airlines should therefore factor allowance procurement into pricing and route-planning decisions and monitor the development of the proposed rules on carbon capture and the treatment of atmospheric CO₂.
The ReFuelEU Aviation Regulation has been in force since January 2024, requiring fuel suppliers at EU airports to ensure that minimum Sustainable Aviation Fuel (SAF) blending percentages increase progressively over time. The target is 2% for the period 2025 to 2029, rising to 70% by 2050. In addition, airlines must uplift at least 90% of their annual fuel requirement at EU airports. The 90% uplift requirement is intended to prevent excessive “tankering”, whereby airlines take on additional fuel outside the EU to avoid the cost of the EU SAF requirements. SAF is more expensive than conventional jet fuel, so blending mandates directly increase fuel costs, and the 90% uplift rule restricts refueling flexibility.
Financial penalties for non-compliance may reach approximately €1,500 per tonne of un‑uplifted fuel, with some Member States imposing higher sanctions. In June 2026, the European Commission warned 13 Member States for failing to establish national penalty regimes by the deadline, giving them two months to respond before further steps are considered. Beyond financial penalties, operators also face reputational risk and increased scrutiny in future reporting cycles. Switzerland formally adopted ReFuelEU from January 2026, extending the same requirements to Zurich and Geneva airports.
In May 2026, the European Commission issued guidance in response to fuel supply concerns arising from the situation in the Middle East. The guidance does not amend the ReFuelEU Aviation rules but clarifies that, where fuel shortages or supply disruptions make it necessary for safety or operational reasons, airlines may be unable to meet the 90% fuel uplift requirement. In such circumstances, the usual uplift requirement may be applied with appropriate flexibility.
The NIS2 Directive has applied since October 2024 and imposes clear cybersecurity obligations on critical sectors including air transport. Airlines must implement technical and organizational measures to manage cybersecurity risks. Significant cyber incidents must be reported to national authorities and supply chain security risks must be addressed.
The urgency of these requirements was underscored by the Collins Aerospace cyberattack in September 2025. The attack on this supplier of check-in and boarding systems forced Brussels, Berlin and other airports to revert to manual operations, causing widespread flight delays and cancellations that affected hundreds of thousands of passengers. The incident demonstrated that a security vulnerability at an IT supplier can directly translate into operational disruption for airlines.
The Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements for products with digital elements. The first obligations took effect on 11 September 2026, the remaining obligations on 11 December 2027. Products subject to EU aviation-specific cybersecurity requirements are generally excluded from the CRA’s scope.
Airlines should nevertheless review cybersecurity clauses in contracts with IT suppliers, particularly critical providers such as reservation and departure control system providers. Internal incident-response mechanisms should also be established or strengthened to meet NIS2’s strict reporting deadlines.
Two enforcement cases from 2026 warrant attention. The Spanish Data Protection Authority imposed a fine of €18 million on Amadeus for a pilot project that repurposed PNR data to create passenger profiles and share them with hotels and other travel companies, involving over 12 billion data records. The authority found two violations: failure to proactively inform passengers that their data would be used for secondary processing, and absence of a valid legal basis for such processing. Amadeus relied on broad wording in its privacy policy such as “for analysis or product improvement”, but this was rejected by the regulator.
The Italian Data Protection Authority imposed a fine of €180,000 on Emirates following a complaint concerning a MEDIF form. The investigation found that passengers had not received adequate information about how their personal data would be processed, including who must complete the form and which sections are mandatory, and that a seven-year retention period for health data was excessive.
In addition, in March 2025, the European Data Protection Board confirmed that the general retention period for PNR data for law-enforcement purposes should not exceed six months, with longer retention permitted only where strictly necessary and proportionate for the prevention and prosecution of terrorism or serious crime.
This does not affect the applicable deadlines for EU261 compensation claims, but airlines should ensure that PNR data is not retained or repurposed for claims handling beyond the applicable data-protection limits.
Airlines should review the purposes for which passenger data is processed and ensure that any secondary use, including sharing with third parties, profiling or analytics, is supported by a clear and specific legal basis. Broad privacy policy wording is insufficient. Special assistance data collection processes should be reviewed to ensure passengers receive adequate information, and (health) data retention periods must be strictly limited to what is necessary.
In November 2025, the European Union Aviation Safety Agency (EASA) published its first regulatory proposal on AI trustworthiness in aviation, aimed at implementing the EU AI Act’s requirements within the aviation regulatory framework. The proposal covers AI applications in areas such as flight operations and predictive maintenance. Airlines should monitor further EASA guidance and rulemaking as the framework develops. As of June 2026, EASA has continued developing the framework by publishing its third issue of the AI Concept Paper.
The European Commission has amended the EU aviation security framework to strengthen and harmonize national quality-control programs, including standardized reporting of aviation security incidents and common data-sharing arrangements. Airlines should review internal security reporting, audit and training procedures to ensure alignment with the updated requirements.
National consumer protection authorities continue to scrutinize airline pricing practices, particularly drip pricing, transparency of ancillary fees such as seat selection, and the clarity of fare breakdowns. Fare displays and ancillary fee communications should be reviewed to ensure that they are transparent and not misleading.
As shown above, EU rules are reshaping the operating environment for airlines across multiple dimensions. Passenger rights continue to expand, carbon compliance costs are rising, and enforcement of cybersecurity and data protection rules has intensified significantly. Early identification of risks and corresponding adjustments to internal processes will help airlines maintain operational flexibility within the compliance framework.
Russell Advocaten can assist you in navigating the new legal requirements and responding to regulatory investigations.
Please do not hesitate to contact us:
The regulation of charities and nonprofit organizations is changing rapidly. New rules, stricter audits, and European legislation are making it more important than ever for organizations to stay on top of their compliance obligations. In this newsletter, we outline the most important developments for you.
When a debtor refuses to pay outstanding invoices, despite repeated reminders, demand letters and even settlement proposals, creditors may start looking for stronger measures. One option under Dutch law is filing a bankruptcy petition against the debtor. When can a creditor use this option, and what are the risks involved?
European regulatory developments are introducing major new obligations for companies in the retail, fashion and luxury sectors. Companies must prepare their compliance processes accordingly.
When a foreign creditor is owed money by a Dutch debtor, the debt recovery process involves additional legal considerations, ranging from questions of jurisdiction to the enforceability of foreign judgments and the availability of cross-border enforcement instruments. What options does a creditor have in an international context?
When a debtor refuses to pay despite reminders and demand letters, stronger measures will be necessary to secure a claim. One of the most effective instruments in Dutch debt recovery is attachment. How can a creditor secure such an attachment?
Under the Money Laundering and Terrorist Financing (Prevention) Act (Wwft), banks may be obliged to refuse a customer or terminate their relationship with them. This can also happen to charities. When is a bank permitted to terminate the relationship? And must a customer cooperate with a bank’s investigation?