ING Bank – Court Ruling (Netherlands, 2026)

Court Ruling
DPA RbAmsterdam16 July 2026Netherlands
final
Court Ruling

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

ING Bank faced a legal challenge over its use of Google Pay for contactless payments, with consumer groups demanding access to data processing agreements. The bank argued that its processing was lawful but refused to share the agreements. This case shows the growing scrutiny on how companies handle personal data, especially when partnering with tech giants.

What happened

Consumer organizations demanded ING Bank disclose its agreements with Google regarding contactless payments.

Who was affected

Consumers who use ING Bank's contactless payment services through Google Pay.

What the authority found

The court was asked to determine whether ING and Google acted as joint controllers of personal data, but the case is still ongoing.

Why this matters

This situation illustrates the increasing demand for transparency in data processing agreements. Small businesses should be aware of their obligations when working with third-party services that handle customer data.

GDPR Articles Cited

AI-verified

View original scraped data
Art. 26(GDPR)

Original data from scraper before AI verification against source document.

Decision AuthorityRbAmsterdam
Source verified 22 July 2026
verified correct
Full Legal Summary
Detailed

ING Bank (the controller) is a bank. One of the services the controller offers is to make contactless payments using an Android phone. This was initially done through its own app, however, the controller later discontinued this and offered the contactless payment through Google Pay. To activate Google Pay, data subjects have to create an account with Google. When making a payment, the controller shares data related to the payment and store to Google. Two Dutch consumer’s organisations (the “Benadeelden in Actie” Foundation, or SBIA and Consumer Union) demanded that the controller discontinue Google Pay, and requested it to share its data. The controller stated that it had reached agreements with Google regarding data processing for contactless payments, but it refused to disclose those agreements. The consumer organisations therefore filed a case with the court, requesting it to order the controller to provide access to the agreements. The organisations also requested access to additional documentation, such as (draft) decisions and research data. They argued that they questioned the lawfulness of the processing of personal data in relation to contactless payments, and needed access in order to verify whether this processing was lawful. The controller, on the other hand, argued that the argument was unsubstantiated because the processing was lawful. The organisations argued that ING and Google acted as joint controllers in accordance with Article 26 GDPR. ING disputed this, and argued that it was only a joint controller with Google for the activation of tokens when making a payment. The court also clarified that ING Bank and Google were joint controllers, in accordance with Article 26 GDPR. The court dismissed the argument that ING and Google were joint controllers only in a specific instance (activating tokens). The court stated that both companies aimed at enabling data subjects to make contact payments with their phones using Google Pay. The court considered t

Outcome

Court Ruling

A ruling by a national court on a data-protection matter.

Details

Ruling Date

16 July 2026

Authority

DPA RbAmsterdam

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. ING Bank - Netherlands (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: