ING Bank N.V. – Court Ruling (Netherlands, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
A Dutch court ruled that ING Bank did not properly investigate complaints about contactless payment features on debit cards. This decision matters because it emphasizes the importance of addressing user complaints thoroughly. Small businesses should ensure they have clear processes for handling customer concerns about personal data.
What happened
The court found that ING Bank failed to adequately address complaints regarding contactless payment chips on debit cards.
Who was affected
Customers of ING Bank who were concerned about the contactless payment feature on their debit cards.
What the authority found
The court determined that ING Bank did not properly investigate user complaints about the processing of personal data through debit card chips.
Why this matters
This ruling underscores the need for companies to take customer complaints seriously and investigate them thoroughly. Small businesses should ensure they have effective complaint resolution processes to avoid similar issues.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
ING Bank N.V. (the controller) is a bank. In 2022, several data subjects brought a complaint to the DPA regarding the controller’s contactless payments. The data subjects requested the controller to issue debit cards without a chip that would enable contactless payments. The controller stated that this was not possible, however, the contactless payment feature could be disabled on the data subjects’ cards. The data subjects later filed a complaint because the debit cards contained the chips even if the contactless feature was disabled. The DPA dismissed the complaint in 2024, on the grounds that further investigation would be needed to determine whether the controller violated the GDPR or not. The DPA stated that it had limited capacity and such an investigation would place a heavy burden on it. The data subjects appealed this decision to the court, who determined that the DPA had wrongfully failed to hear the data subjects during the objection phase. The DPA issued a new decision in 2025 and concluded that the controller had not violated the GDPR. The data subjects appealed this decision, arguing that the DPA had again not investigated the case sufficiently. In addition, the data subjects argued that the controller processed personal data through the debit card chip without a valid legal basis. This is because the chip allowed payments made with blocked or expired cards, meaning Article 6(1)(b) GDPR did not apply. The controller could also not rely on consent (Article 6(1)(a) GDPR) to process the data. The DPA argued that the GDPR does not require controllers to completely eliminate a risk. In addition, disabling contactless payments or blocking cards were related to the contract between the data subject and the controller; the DPA argued that this did not remove the basis to process personal data. The court found that the DPA investigated the complaint to an appropriate extent and was not required to conduct a further investigation. According to the court, the d
Outcome
Court Ruling
A ruling by a national court on a data-protection matter.
Related Cases (7)
Other cases involving ING Bank N.V. in NL
Court Ruling
Details
About this data
Cite as: Cookie Fines. ING Bank N.V. - Netherlands (2026). Retrieved from cookiefines.eu
Last updated: