ING Bank – Court Ruling (Netherlands, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
ING Bank faced a legal challenge over its use of Google Pay for contactless payments, with consumer groups demanding access to data processing agreements. The bank argued that its processing was lawful but refused to share the agreements. This case shows the growing scrutiny on how companies handle personal data, especially when partnering with tech giants.
What happened
Consumer organizations demanded ING Bank disclose its agreements with Google regarding contactless payments.
Who was affected
Consumers who use ING Bank's contactless payment services through Google Pay.
What the authority found
The court was asked to determine whether ING and Google acted as joint controllers of personal data, but the case is still ongoing.
Why this matters
This situation illustrates the increasing demand for transparency in data processing agreements. Small businesses should be aware of their obligations when working with third-party services that handle customer data.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
ING Bank (the controller) is a bank. One of the services the controller offers is to make contactless payments using an Android phone. This was initially done through its own app, however, the controller later discontinued this and offered the contactless payment through Google Pay. To activate Google Pay, data subjects have to create an account with Google. When making a payment, the controller shares data related to the payment and store to Google. Two Dutch consumer’s organisations (the “Benadeelden in Actie” Foundation, or SBIA and Consumer Union) demanded that the controller discontinue Google Pay, and requested it to share its data. The controller stated that it had reached agreements with Google regarding data processing for contactless payments, but it refused to disclose those agreements. The consumer organisations therefore filed a case with the court, requesting it to order the controller to provide access to the agreements. The organisations also requested access to additional documentation, such as (draft) decisions and research data. They argued that they questioned the lawfulness of the processing of personal data in relation to contactless payments, and needed access in order to verify whether this processing was lawful. The controller, on the other hand, argued that the argument was unsubstantiated because the processing was lawful. The organisations argued that ING and Google acted as joint controllers in accordance with Article 26 GDPR. ING disputed this, and argued that it was only a joint controller with Google for the activation of tokens when making a payment. The court also clarified that ING Bank and Google were joint controllers, in accordance with Article 26 GDPR. The court dismissed the argument that ING and Google were joint controllers only in a specific instance (activating tokens). The court stated that both companies aimed at enabling data subjects to make contact payments with their phones using Google Pay. The court considered t
Outcome
Court Ruling
A ruling by a national court on a data-protection matter.
Related Cases (1)
Other cases involving ING Bank in NL
Details
About this data
Cite as: Cookie Fines. ING Bank - Netherlands (2026). Retrieved from cookiefines.eu
Last updated: