11.3 Digital Travel Tools: Mobile, Self-Service, Biometrics & AI in Travel
Key Takeaways
- IATA Resolution 753, effective June 2018, requires members to track baggage at acquisition, loading, custody transfer and delivery, and to exchange those events with other airlines.
- IATA One ID rests on two pillars: digitalization of admissibility before departure so passengers are 'Ready to Fly', and contactless travel using biometric-enabled identification at airport touchpoints.
- The EU Entry/Exit System began on 12 October 2025 and is fully operational from 10 April 2026, registering third-country nationals biometrically instead of stamping passports.
- PCI DSS version 4.0.1 was published in June 2024, and the future-dated version 4.0 requirements became mandatory on 31 March 2025, including multi-factor authentication for cardholder data environments.
- GDPR requires a personal data breach to be notified to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it.
The Traveller-Facing Technology Stack
A consultant is not expected to build any of this, but is expected to explain it calmly to a nervous client.
Mobile and self-service
The mobile boarding pass is a two-dimensional barcode built to the industry BCBP (Bar Coded Boarding Pass) specification and stored in an airline app or a digital wallet (Apple Wallet, Google Wallet), where it can update itself when the gate or time changes. Airline apps add push disruption alerts, self-service rebooking, bag tracking and lounge access.
At the airport, self-service check-in kiosks - often CUSS (Common Use Self-Service) units shared by several carriers - issue boarding passes and bag tags. Self bag drop comes in two flavours: one-step, where the tag is printed and the bag accepted at the same unit, and two-step, where the tag is issued separately (at a kiosk, or as a home-printed bag tag) and the passenger only drops the bag. Permanent electronic bag tags update over Bluetooth from a phone, and RFID (radio-frequency identification) tags allow reading without line of sight.
Behind all of this sits IATA Resolution 753 on baggage tracking, effective June 2018. Members must be able to demonstrate that they tracked the bag at four points - acquisition from the passenger, loading onto the aircraft, custody transfer between carriers, and delivery to the passenger - and must be able to exchange those events with other airlines. The resolution is technology-neutral: barcode, OCR, RFID or manual recording all qualify. Related standards are Resolution 740 for the interline bag tag and Recommended Practice 1740c for RFID.
Identity: IATA One ID and biometrics
IATA One ID aims to make the passenger "Ready to Fly" before arriving at the airport. It rests on two pillars:
- Digitalization of admissibility - passport, visa and authorisation checks done remotely and digitally in advance, so the airline already knows the passenger may travel.
- Contactless travel - biometric-enabled identification at airport touchpoints (check-in, bag drop, security, lounge, boarding), so no physical document is presented at each stop.
The trust anchor is the ICAO e-passport chip in an electronic machine-readable travel document; ICAO's DTC (Digital Travel Credential) derives a digital version of it that can live in a wallet. IATA promotes an open trust framework built on the W3C Verifiable Credentials Data Model, so an airline receives only the minimum attribute it needs rather than a whole document.
Advise clients honestly on the privacy side: biometric data is special-category personal data under the EU GDPR, participation should be consent-based with a non-biometric alternative available, and templates should be held only as long as the purpose requires.
Borders and automated processing
ABC (Automated Border Control) e-gates compare a live facial image with the photograph on the passport chip. The EU Entry/Exit System (EES) began on 12 October 2025 and is fully operational from 10 April 2026: it registers third-country nationals biometrically - facial image and fingerprints - and records entries and exits digitally instead of stamping the passport. Warn clients that the first crossing after registration takes longer. ETIAS is not yet in force and is scheduled for Q4 2026 (EUR 20, three-year validity, free for travellers under 18 or over 70).
Agency-Side Technology
| Tool | What it does | Why the consultant cares |
|---|---|---|
| OBT (online booking tool) | Corporate self-booking front end that enforces travel policy and preferred suppliers | The TMC configures and supports it; exceptions and complex trips still come to a human |
| Mid-office robotics / quality control | Automated checks on records before ticketing: fare, ticketing time limit, SSR, policy, duplicate bookings | Catches errors that would otherwise become an ADM (agency debit memo) |
| CRM and traveller profiles | Stores passport details, preferences, loyalty numbers, cost centres | Speeds service, but concentrates personal data that must be protected |
| Itinerary management apps | Consolidate confirmations into one trip view and push schedule changes | Reduces "where is my confirmation?" calls |
| Duty-of-care traveller tracking | Locates travellers by itinerary during a crisis and issues risk alerts | Core corporate obligation; ISO 31030 gives travel risk management guidance |
AI and Automation in Travel
Useful, genuinely deployed applications include chatbots and virtual agents for routine servicing, dynamic pricing and personalised recommendation, disruption re-accommodation engines that rebook thousands of passengers automatically, itinerary parsing, translation and content drafting.
The limits are equally examinable. Generative models hallucinate - they will produce a fluent, wrong visa rule or fare condition - so entry requirements must always be confirmed against an authoritative source such as TIMATIC or the destination government, never against a chatbot. Models can inherit bias, cannot take responsibility, and are weak on exceptions. Complex, high-value, multi-sector, group and disrupted itineraries still need a human consultant. And never paste passport numbers or card data into a public AI tool.
Data Protection and Payment Security
GDPR builds on six principles plus accountability: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality. Health and biometric data are special category - which means a wheelchair request or a meal code implying religion is sensitive, not routine. Data subjects have rights of access, rectification, erasure, portability and objection, and a personal data breach must be notified to the supervisory authority without undue delay and, where feasible, within 72 hours.
PCI DSS (Payment Card Industry Data Security Standard) has 12 requirements and governs anyone who stores, processes or transmits card data. Version 4.0.1 was published in June 2024, and the future-dated version 4.0 requirements became mandatory on 31 March 2025, including multi-factor authentication for all access to the cardholder data environment. Most agencies are small merchants completing a self-assessment questionnaire.
A six-step routine for a client's sensitive data:
- Collect only what the booking needs - not the whole passport if only the number, name and expiry are required.
- Never accept card details by email, chat or voicemail; use a secure payment link or an authenticated 3-D Secure payment.
- Never store the card verification value (CVV/CVC) at all, and mask the card number in reservation records and profiles by setting agent sign-in display rights correctly.
- Transmit passport scans through an encrypted portal, not as an email attachment, and encrypt them at rest.
- Apply a retention schedule and delete on time - storage limitation is a principle, not a preference.
- Verify any change of bank or payment instructions by telephone on a number you already hold.
Know the fraud patterns: phishing and business email compromise that impersonates a client or supplier and asks to change payment details; compromised cards used for high-value, short-notice, one-way tickets, often booked out of hours to a high-risk destination; compromised agency sign-ins used to issue tickets; and the ADM exposure that follows, because a fraudulent or mis-issued ticket is normally charged back to the agency, not the airline. Speed of booking is never a reason to skip verification.
Under IATA Resolution 753, effective June 2018, what must a member airline be able to demonstrate?
A client emails your agency asking you to hold a hotel room, attaching a photograph of her passport and of her credit card front and back. What is the correct professional response?
IATA's One ID initiative is built on two pillars. Which pair is correct?
You've completed this section
Continue exploring other exams