Booking engines, traveler portals, and trip-planning chatbots built with AI hold passports, full itineraries, and payment data - often for international travelers, which puts a US agency in GDPR scope regardless of location. 90% of travel executives use gen AI, and AI-generated code introduces vulnerabilities in roughly 45% of tasks (Veracode).
Get a Free Security Scan See Our AI App AuditTravel businesses hold a rare combination - passports, full itineraries, and payment data - and the last 24 months of breaches show attackers targeting exactly that.
Hand-rolled payment flows put the whole app in PCI scope, and AI-generated code fails security checks in roughly 45% of tasks (Veracode). Acquirer fines run –nth, scaling up to nth plus possible loss of processing.
AI builders ship databases with row-level security off by default - Lovable's CVE-2025-48757 left 170 of 1,645 showcased apps (roughly 1 in 10) leaking data. Passport scans resell for – on dark-web markets, with verified EU passports fetching +. Eurail (308,777 passport numbers), WestJet, and BCD Travel were all breached with passport/ID data among the losses.
Guessable booking IDs and unauthenticated lookups expose full itineraries - exactly the data weaponized in the April 2026 Booking.com incident, where stolen reservation details fueled WhatsApp/SMS scams quoting real hotel names, dates, and reference numbers. A breached itinerary tells criminals exactly where a traveler will be, and that home is empty.
Feeding traveler PII into LLM prompts, or reusing booking data for personalization without notice or a lawful basis, is what earned GDS giant Amadeus a record €18M GDPR fine (published May 2026) for repurposing booking data into traveler profiles without Article 14 notice. Chatbots also add a prompt-injection and data-exfiltration surface.
Travel is a top fraud target - the average travel/ticketing/hospitality company loses M a year to fraud (Ravelin, 2025). AI-written deposit and refund logic rarely includes velocity checks or chargeback defenses, and SMS payment reminders add TCPA exposure at – per text.
API keys embedded client-side and OAuth misconfigurations are a real attack path: Salt Labs found an account-takeover flaw in a travel service integrated into dozens of airline sites, letting attackers spend victims' loyalty points. Qantas's 5.7 million-record breach came through a third-party call-center platform - every AI-generated integration with a hardcoded key is the same failure mode.
| Regulation | When it applies | Penalty |
|---|---|---|
| PCI DSS 4.0.1 | Any card acceptance/storage/transmission (deposits, checkout); 51 future-dated reqs mandatory since 2025-03-31 | – → up to ; loss of processing |
| GDPR | Selling to or tracking EU/UK travelers - typical for any travel site; passport data = high-risk | Up to €20M or 4% turnover; Amadeus €18M, Uber €290M |
| CCPA/CPRA (+ states) | CA residents' data over revenue/consumer thresholds | Up to intentional/minors (2025 figures) |
| State breach-notification | Passport and government-ID numbers are notification-triggering | Per-state penalties + class actions |
| ADA Title III | Public booking sites - nexus via booking calendars, reservation flows, maps | ~– all-in per single-plaintiff case |
| TCPA | SMS/voice trip reminders or deal alerts without prior express written consent | / willful per text |
| CA Seller of Travel (+ FL, WA, HI) | Selling/advertising air/sea transport to anyone in California - even one ticket | /violation; felony tier where funds mishandled |
Not by default. Roughly 1 in 10 showcased Lovable apps leaked data via missing row-level security (CVE-2025-48757), and AI-generated code introduces vulnerabilities in roughly 45% of tasks (Veracode). A travel app holding passport scans and payment data needs both checked before launch.
Yes, if you sell to or track EU or UK travelers - GDPR follows the traveler, not your business address. Amadeus was fined €18M for reusing booking data for personalization without proper notice, showing regulators actively scrutinize travel-data practices.
Qantas was breached in June 2025 through a third-party call-center platform, exposing 5.7 million customers' data. WestJet was breached the same month, with passports and government IDs among the roughly 1.2 million customers' data stolen - both attacks were attributed to the Scattered Spider threat group.
Spain's data protection authority fined GDS giant Amadeus €18M (published May 2026) for repurposing booking data into traveler profiles for hyper-personalized targeting without proper Article 14 notice or an Article 6 lawful basis.
Yes, if you sell or advertise air or sea transportation to anyone in California - even a single ticket. Violations carry per-violation penalties, with a felony tier where customer funds are mishandled.
Rotate every API key and credential, enable row-level security if it wasn't already on, and determine whether passport or government-ID data was involved - that triggers notification obligations in all 50 states. Move quickly, since stolen itinerary and reservation data is now being weaponized in phishing scams within days of a breach.
We audit AI-built travel and booking apps for exposed passport data, missing RLS, and PCI/GDPR gaps - then fix what we find.
Get a Free Security Scan