ING Bank N.V. – Court Ruling (Netherlands, 2026)

Court Ruling
DPA RbRotterdam24 June 2026Netherlands
final
Court Ruling

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A Dutch court ruled that ING Bank did not properly investigate complaints about contactless payment features on debit cards. This decision matters because it emphasizes the importance of addressing user complaints thoroughly. Small businesses should ensure they have clear processes for handling customer concerns about personal data.

What happened

The court found that ING Bank failed to adequately address complaints regarding contactless payment chips on debit cards.

Who was affected

Customers of ING Bank who were concerned about the contactless payment feature on their debit cards.

What the authority found

The court determined that ING Bank did not properly investigate user complaints about the processing of personal data through debit card chips.

Why this matters

This ruling underscores the need for companies to take customer complaints seriously and investigate them thoroughly. Small businesses should ensure they have effective complaint resolution processes to avoid similar issues.

GDPR Articles Cited

AI-verified

Art. 32(GDPR)
Art. 6(1)(a) GDPR
Art. 6(1)(b) GDPR
View original scraped data
Art. 6(1)(a) GDPR
Art. 6(1)(b) GDPR
Art. 32(GDPR)

Original data from scraper before AI verification against source document.

Decision AuthorityRbRotterdam
Reviewed AuthorityDPA
Source verified 15 July 2026
verified correct
Full Legal Summary
Detailed

ING Bank N.V. (the controller) is a bank. In 2022, several data subjects brought a complaint to the DPA regarding the controller’s contactless payments. The data subjects requested the controller to issue debit cards without a chip that would enable contactless payments. The controller stated that this was not possible, however, the contactless payment feature could be disabled on the data subjects’ cards. The data subjects later filed a complaint because the debit cards contained the chips even if the contactless feature was disabled. The DPA dismissed the complaint in 2024, on the grounds that further investigation would be needed to determine whether the controller violated the GDPR or not. The DPA stated that it had limited capacity and such an investigation would place a heavy burden on it. The data subjects appealed this decision to the court, who determined that the DPA had wrongfully failed to hear the data subjects during the objection phase. The DPA issued a new decision in 2025 and concluded that the controller had not violated the GDPR. The data subjects appealed this decision, arguing that the DPA had again not investigated the case sufficiently. In addition, the data subjects argued that the controller processed personal data through the debit card chip without a valid legal basis. This is because the chip allowed payments made with blocked or expired cards, meaning Article 6(1)(b) GDPR did not apply. The controller could also not rely on consent (Article 6(1)(a) GDPR) to process the data. The DPA argued that the GDPR does not require controllers to completely eliminate a risk. In addition, disabling contactless payments or blocking cards were related to the contract between the data subject and the controller; the DPA argued that this did not remove the basis to process personal data. The court found that the DPA investigated the complaint to an appropriate extent and was not required to conduct a further investigation. According to the court, the d

Outcome

Court Ruling

A ruling by a national court on a data-protection matter.

Details

Ruling Date

24 June 2026

Authority

DPA RbRotterdam

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. ING Bank N.V. - Netherlands (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: