Banco Bilbao Vizcaya Argentaria, S.A. – €70,000 Fine (Spain, 2023)

€70,000Agencia Española de Protección de Datos12 September 2023Spain
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Banco Bilbao Vizcaya Argentaria, S.A. was fined €70,000 for not properly verifying a customer's identity. A thief used a lost ID card to withdraw €9,400 from the customer's account without permission. This case highlights the importance of strong security measures in protecting customer information.

What happened

A third party withdrew €9,400 from a customer's account using a lost ID card without proper verification.

Who was affected

The affected person was a customer of Banco Bilbao Vizcaya Argentaria, S.A. whose account was accessed without authorization.

What the authority found

The Spanish data protection authority ruled that the bank failed to implement adequate security measures to verify the customer's identity, violating GDPR's requirements.

Why this matters

This ruling emphasizes that banks must have strict security protocols to protect customer data. Other companies should review their identity verification processes to avoid similar issues.

GDPR Articles Cited

AI-verified

Art. 6(1) GDPR
Art. 32(1) GDPR
Art. 83(4)(a) GDPR
Art. 83(5)(a) GDPR
View original scraped data
Art. 6(1) GDPR
Art. 32(1) GDPR
Art. 83(4)(a) GDPR
Art. 83(5)(a) GDPR

Original data from scraper before AI verification against source document.

Source verified 12 March 2026
articles corrected
national law identified
Full Legal Summary
Detailed

In July 2021, the data subject lost his ID card. A third party went to his bank with the ID card and withdrew all the money available in the account, a total of €9,400, without his authorization or consent. The withdrawal was made in person at the local bank branch. The withdrawal also required the signature of the third party. The third party was able to withdraw the money despite their signature not corresponding to the signature on the data subject's ID card. The DPA seemed to infer that identifying a client at a bank for just the sake of providing them with a bank service involves a processing operation which must be carried out in compliance with Article 32 GDPR. The Spanish DPA considered the bank to have failed in adopting appropriate security measures by not verifying the data subject's identity in a reliable manner. As highlighted by AEPD, it was negligence that would have been overcome if available protocols would have been correctly followed. For example, correctly comparing and verifying both the photograph and the signature of the document that was presented in the request. By not using appropriate technical and organisational measures to ensure a level of security appropriate to the risk, the controller violated Article 6 and Article 32 GDPR.

Details

Fine Date

12 September 2023

Authority

Agencia Española de Protección de Datos

Fine Amount

€70,000

GDPRhub ID

gdprhub-6267

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Banco Bilbao Vizcaya Argentaria, S.A. - Spain (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: