Avanza Bank – €1,320,000 Fine (Sweden, 2024)

€1,320,000Integritetsskyddsmyndigheten24 June 2024Sweden
final
ePrivacy
Fine

Avanza Bank was fined 1.32 million euros for using Meta's analytics tool without proper consent from users. This is important because it shows that companies must get clear permission before tracking user behavior online. Small businesses should ensure they have proper consent mechanisms in place when using tracking tools.

What happened

Avanza Bank used Meta's analytics tool to track user behavior without obtaining proper consent.

Who was affected

Website visitors of Avanza Bank who had their data tracked by Meta's analytics tool were affected.

What the authority found

The Swedish authority ruled that Avanza Bank violated GDPR by not securing user consent for tracking cookies.

Why this matters

This ruling reinforces the importance of user consent in data tracking and sets a precedent for other companies to follow strict consent guidelines.

GDPR Articles Cited

AI-verified

Art. 5(1)(f) GDPR
Art. 32(1) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 32(1) GDPR

Original data from scraper before AI verification against source document.

Source verified 2 April 2026
verified correct
Full Legal Summary
Detailed

The controller, Avanza Bank AB, used Meta’s analytics tool Meta Pixel to measure the effectiveness of the bank’s Facebook advertising. By collecting information about which pages on the controller’s website a person visited, the controller wanted to optimise its marketing measures. This tool would only collect information about a data subject’s website visits, IP addresses and information about certain unique events such as searches on the websites. Two new functions of the analytics tool, the Automatic Advanced Matching (AAM) and the Automatic Events (AE), were activated by the controller by mistake. The AAM looked for recognisable form fields and other sources on the controller’s website that contain information such as first name, last name and email address. It transferred data to Meta in hashed form (an irreversible one-way process that converts data into a unique string of characters) if a data subject filled in any of the five different forms of the controller’s website or mobile app. When users logged in and accepted marketing cookies, the AAM collected the personal data, including personal identification number, contact details, loan amounts on existing loans, employers, type of employment and account numbers. With this, Meta-Pixel could match the hashed data with the behaviour of data subjects to the website to obtain a more detailed profile of the data subjects. It is unknown whether this resulted in targeted advertising. The AE analysed which buttons on the controller’s website and mobile app the user pressed and transmitted this data in plain text to Meta to then make suggestions about marketing on Facebook. However, the controller categorised visual fields as buttons on their website and mobile app. Via AE, personal data of data subjects were collected, including securities holdings and value, loan amounts, account number and email address and social security number. The controller found out by an external source that the personal data of 500,001 to

Violations (2)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Third-Party Cookies Without Consent
critical

Third-party tracking cookies or scripts are loaded without obtaining prior user consent.

Art. 13, 14 GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Avanza Bank in SE

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

24 June 2024

Authority

Integritetsskyddsmyndigheten

Fine Amount

€1,320,000

15,000,000 SEK

GDPRhub ID

gdprhub-8041

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified
Cookie relevance: 80%

Cite as: Cookie Fines. Avanza Bank - Sweden (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: