Introduction: "Do you have the loyalty card?"
Friday, 6:50 a.m., Gare de Lyon. You buy your ticket on the app, you pass through the gate by scanning a QR code, you connect to the free wifi to kill twenty minutes, you pay for a coffee contactlessly, you board, the conductor scans your ticket again, and on arrival you order a ride-hailing car.
In three hours, seven different organisations now know you were in Marseille that Friday: the carrier, its distribution platform, the wifi operator, your bank, the station retailer, your mobile provider via the cell towers, and the booking platform. None of them did anything illegal. Strung together, however, these traces sketch something very precise: where you go, how often, with whom, and for how long.

Movement is a category of data all its own. By inference it reveals what you never declared: a stay in a specialist teaching hospital, monthly trips to a lover's city, a job interview with a competitor, attendance at a rally, a visit to a parent in a care home. Travel history is one of the rare datasets proven to be almost impossible to anonymise: four spatio-temporal points are enough to re-identify 95% of individuals in a mobility database, according to the work published by Yves-Alexandre de Montjoye and his co-authors in Scientific Reports (2013).
This guide is not suggesting you travel clandestinely — that is illegal and pointless. It suggests sorting things out: which traces are imposed by law, and which ones you hand over for free, and how to shrink the second pile.
Who collects what, at each stage of the journey
The honest map
| Stage | Who collects | What is recorded | Your room for manoeuvre |
|---|---|---|---|
| Ticket purchase | Carrier, online distributor | Identity, email, phone, payment method, route, time | Medium |
| Loyalty programme | Carrier | Complete travel history, preferences, complaints | High |
| On-board check / gate | Carrier | Timestamp of passage, seat | Low |
| Free wifi | Network operator | MAC address, email or phone used to log in, duration, sometimes sites visited | High |
| Payment in the station or on board | Bank, retailer | Place, time, amount | High |
| Mobile network | Operator | Cell towers crossed, hence approximate itinerary | Low |
| Commercial flight | Airline + authorities | PNR and API data: identity, passport, baggage, contact details, payment | None |
| CCTV | Station/airport operator | Images, sometimes people counting and silhouette tracking | None |
Note the right-hand column: out of eight sources, four depend entirely on what you do. That is where the real game is played.
The special case of flying
In air travel, the room for manoeuvre on identity is structurally nil. The European regulation known as the "PNR directive" (EU 2016/681), transposed into French law by the act of 3 June 2016, requires airlines to transmit to the French passenger information unit up to 19 categories of data per traveller: name, full itinerary, contact details, payment method, baggage information, travel agency used, history of changes. This data is kept for five years, with partial masking after six months.
To that are added API (Advance Passenger Information) data taken from the identity document. In other words: a commercial flight is never anonymous, and cannot be. Any strategy has to take this into account rather than pretend to ignore it. What remains negotiable in air travel is everything else: the loyalty programme, the airline's app, marketing options, the airport wifi, payment, optional biometrics.
The train ticket: named does not mean talkative
What the law actually requires
In France, SNCF has for several years required named tickets on its trains with compulsory reservation (TGV INOUI, OUIGO, Intercités with reservation). The stated aim is to fight resale and to manage disruption. But named does not mean "verified" in the sense of a systematic identity check: the conductor scans a code, they do not compare your face to a database.
On TER services, regional trains and much of the urban network, the anonymous ticket still exists. The booklet of tickets or the paper ticket bought at the counter, in cash, remains one of the few everyday transactions that leaves no trace linked to your name. This is not a marginal trick: for a sensitive journey, it is the simplest solution.
General rule: the more expensive and long-distance the ticket, the less anonymous it is. The shorter and more local it is, the more latitude you have.
Reducing the trail on a named ticket
A few habits, taken together, change a great deal:
- Create an account with an email address dedicated to travel, separate from your main address and your professional identity. Breaches of carriers' databases are not hypothetical.
- Do not link the account to your social networks. Logging in "with Google" or "with Facebook" opens a channel connecting your social identity to your movements.
- Refuse non-essential cookies on the booking site: the CNIL regularly reiterates that refusing must be as easy as accepting, and penalises sites that make it harder.
- Untick any advertising personalisation in the account settings. It is this setting that feeds the resale of audience segments such as "frequent Paris-Bordeaux business traveller".
- Pay with a single-use virtual card when your bank offers one. The carrier then does not obtain a reusable card identifier that can be used for cross-referencing.
The loyalty programme, that private diary
A discount card or a carrier's loyalty programme is an exhaustive, dated history of all your movements, kept for years. The question to ask is arithmetical: how much do you actually save each year, and are you willing to pay that amount in full visibility over your mobility?
If the answer is yes — and it is often rational for a daily commuter — you can still limit secondary use: switch off sharing with partners, refuse targeted offers, and periodically request erasure of old history under Article 17 of the GDPR. Carriers often invoke a legal retention period for invoicing; it does not cover marketing uses.
Gates, biometrics and checks: where the obligation stops

Biometrics are almost always optional
Automated border control gates (PARAFE in France) rely on reading the biometric passport and comparing facial images. Their use is optional: a lane with a border police officer remains available. It is slower, and that is the only real cost.
The same logic applies to the commercial systems offered by some airlines or airports: facial-recognition boarding, "contactless" bag drop, "streamlined" journeys where you enrol your face at check-in. These services fall under consent within the meaning of the GDPR, biometric data being sensitive data protected by Article 9. The CNIL has stated on several occasions, notably in its positions on biometrics in airports, that such systems must remain optional, that the template should preferably stay under the individual's control (on their own device), and that a non-biometric alternative must exist.
In practice: you can say no, present your boarding pass and ID to a human being, and this delays your journey by only a few minutes.
The new European entry/exit system
The European Union's EES (Entry/Exit System) records, for third-country nationals crossing the external borders, a facial image and fingerprints. It does not apply to EU citizens travelling within the Schengen area, but it changes the general atmosphere of terminals: biometrics become the default option, and refusing requires knowing your rights. Carrying a physical ID document, in an RFID-blocking sleeve, also prevents opportunistic reading of your passport's contactless chip in a crowded queue.
Searches and your phone
At security screening, your bags are inspected, not your files. A demand to unlock a phone falls under a completely different legal framework, essentially customs or judicial, and we have covered it separately. Just remember that an airport security officer has no power to access the contents of your devices.
Station, airport and on-board wifi: the weak link
This is the most avoidable trace, and yet the one most systematically handed over.
A captive portal asks for an email address or a phone number, records your device's MAC address, and links that hardware identifier to a geolocated, timestamped presence. Repeated across several journeys, this dataset is enough to reconstruct a travel calendar — including when you buy no ticket in your own name.
Three simple defences:
- Enable MAC address randomisation on your phone. iOS and Android offer it natively ("private Wi-Fi address" / "randomised MAC"): check that it is active for each network, and not switched off by an older connection.
- Prefer tethering from your mobile plan. You are already paying for data; using it removes an intermediary. For long journeys, a high-capacity power bank makes this habit sustainable.
- Use a trusted VPN when public wifi is unavoidable, bearing in mind that it shifts trust to the VPN operator rather than removing it.
Let us add the most underrated reflex: switch off wifi and Bluetooth when you are not using them. A phone with wifi turned on constantly emits probes that footfall-counting sensors installed in certain public places can record. The CNIL regulates these attendance-measurement systems strictly, but a device that emits nothing remains the best guarantee.
Finally, travel is the moment when you work on sensitive documents in a shared space. A laptop privacy screen filter costs the price of a meal and neutralises the neighbour in the next seat, the passenger in the aisle and the ceiling camera.
Paying, booking, arriving: the side traces

Money tells the itinerary
Your bank statement is a logbook: coffee at Valence TGV, sandwich in Nîmes, hotel in Montpellier. For a trip you want to keep discreet, cash remains the most effective tool — it is legal up to €1,000 for a private individual who is a French tax resident, which is ample for a weekend.
Rechargeable prepaid cards, available in tobacconists, offer a compromise: they are subject to anti-money-laundering obligations, but they separate everyday purchases from your main account.
Ride-hailing, taxis and the last kilometre
The drop-off address is often the most sensitive piece of data in the whole journey: it points to a home, a clinic, a lawyer's office. Getting dropped off at a nearby junction rather than at the exact number is a habit that costs nothing. In the apps, remember to delete saved addresses ("Home", "Work") that stay stored long after the trip.
What you publish yourself
No regulation protects you from a photo of a boarding pass posted on social media. The barcode contains your name, your booking reference and, with some airlines, enough to access your full file: itinerary, contact details, sometimes the ability to change the booking. The same goes for automatic photo geolocation: check that GPS coordinate recording is disabled in your camera app before you leave.
Exercising your rights after the trip
The GDPR provides concrete levers that are rarely used:
| Right | Article | Practical use in transport |
|---|---|---|
| Access | 15 | Request the full travel history held by a carrier |
| Erasure | 17 | Delete an account and the associated marketing history |
| Objection | 21 | Refuse direct marketing and advertising profiling |
| Portability | 20 | Retrieve your data before closing an account |
| Restriction | 18 | Freeze a contested processing operation during a complaint |
The procedure is simple: write to the company's data protection officer (DPO), whose contact details appear in the privacy policy, keep proof of sending, and refer the matter to the CNIL if there is no reply within a month. Requests to access PNR data held by the authorities go through a specific procedure — an indirect right of access exercised via the CNIL for files relating to state security.
To organise all of this without spending your evenings on it, an encrypted notebook or even a simple paper notebook dedicated to administrative matters stops you losing track of the letters sent and the deadlines.
Three profiles, three strategies
The occasional traveller. The essentials come down to four habits: a dedicated email address, refusing advertising cookies, no public wifi, no boarding pass photos. Cost: ten minutes of settings, once.
The daily commuter. Anonymity of journeys is lost by design: the named season ticket is the price of the fare. Concentrate your effort on secondary uses — turning off targeting, an annual purge of history, refusing third-party loyalty apps.
The at-risk situation (acrimonious separation, journalism, legal proceedings, protecting a third party). Here you need to decouple: short-distance tickets paid in cash, no loyalty account, phone in aeroplane mode during the journey or a second device, accommodation booked on a different logic, and above all: tell only the strictly necessary people about your trip — ideally through a channel that does not expose your number.
The essentials in eight lines
- A journey is, by inference, health data, love-life data and opinion data: treat it as such.
- On a plane, identity is compulsory (PNR, API); everything else is negotiable.
- On regional trains and urban transport, the anonymous ticket still exists: use it for sensitive trips.
- Commercial airport biometrics are optional — a staffed lane always exists.
- Free wifi is the most avoidable trace: MAC randomisation, tethering, VPN.
- A transport loyalty card is a life history; weigh up the trade-off.
- Cash and single-use cards break banking cross-referencing.
- The GDPR lets you request erasure of anything not legally required: use it once a year.
Travelling discreetly requires neither special equipment nor technical skill. It requires deciding, at every counter, whether the information being asked of you is necessary for the journey or merely useful to whoever is asking. The difference between the two, repeated thirty times a year, sketches two very different digital lives.



