8 Total
2 High severity
6 Medium severity
0 Low severity
Summary

This document establishes American Airlines' data collection, use, and sharing practices across flight bookings, the AAdvantage loyalty program, aa.com, and its mobile app. The policy authorizes collection of biometric identifiers, health information, vaccination status, and geolocation data, with sharing provisions extending to travel partners, loyalty program partners, credit card issuers, and advertising networks. The document permits use of cookies and cross-device tracking to deliver targeted advertising on American Airlines platforms and third-party websites, and establishes data subject request procedures for California residents and certain other state residents.

Technical / Legal Breakdown

This Privacy Policy governs the collection, use, sharing, and protection of personal information by American Airlines, Inc. across its Travel Services, Program Services, and Interactive Services, including the AAdvantage loyalty program, and applies to all interaction channels regardless of device. The agreement states that American collects a broad range of data including biometric identifiers, health information, geolocation, payment data, and communications content; the terms authorize sharing this data with travel partners, loyalty partners, credit card partners, government and law enforcement agencies, advertising networks, and third-party analytics providers, and permit combining online and offline data for targeted advertising purposes. Notably, the policy asserts broad cross-device tracking and data combination practices for behavioral advertising, collects sensitive categories such as biometric, health, and vaccination data, and conditions certain opt-out rights on state residency rather than applying them universally, though applicable law including GDPR, CCPA, and state biometric statutes may constrain how some of these asserted rights operate in practice. The policy engages GDPR for EU/EEA data subjects, the California Consumer Privacy Act and California Privacy Rights Act for California residents, state biometric privacy laws such as Illinois BIPA where biometric data is collected, and federal aviation security and customs regulations that independently compel collection of certain traveler data; the dual role of American as both a commercial data controller and a regulated air carrier creates layered compliance obligations across multiple frameworks and jurisdictions.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial
High — 2 provisions
Medium — 6 provisions

Monitoring

American Airlines has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle Biometric Data Collection and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 06:31 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000633
Version ID CA-V-001287
SHA-256 474ee5633e1a74620002cdd4f9e989cd1f53b4d02591b5c1a46b6d5dab9cbc25
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans