CAIXABANK, S.A. – €408,000 Fine (Spain, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
CaixaBank, S.A. was fined for collecting more personal information than necessary during an inheritance process. This matters because it shows that companies must only ask for information that is relevant to their services. The ruling serves as a reminder for financial institutions to respect privacy and limit data collection.
What happened
CaixaBank, S.A. collected excessive personal and financial information during an inheritance procedure.
Who was affected
Heirs of a deceased customer whose personal information was collected beyond what was necessary for the inheritance process.
What the authority found
The DPA ruled that CaixaBank violated GDPR by requesting more information than needed for the inheritance distribution.
Why this matters
This case highlights the importance of data minimization and may lead to stricter practices in how companies collect personal information.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
A data subject and other heirs were handling the inheritance of a deceased customer through CaixaBank, S.A., the controller. In the course of the inheritance procedure, the controller obtained a complete notarised deed of acceptance, partition and allocation of the inheritance. The data subject considered that the controller had obtained substantially more personal and financial information than necessary to distribute the funds held with the controller. In particular, the deed contained information concerning the deceased's entire estate and personal and financial information relating to the heirs, including assets unrelated to the controller. The data subject subsequently complained to the controller and asked for the legal basis for requesting the complete deed. The controller replied that it had not required the submission of a complete public deed and claimed that the heirs could have provided only the relevant parts or used a private document. It also stated that its inheritance guidance informed customers of the available alternatives. The data subject lodged a complaint with the DPA. During its investigation, the DPA established that the controller's internal inheritance guide generally instructed heirs to submit a public deed of acceptance of the inheritance. The guide did not adequately inform heirs that the inheritance could instead be partitioned through a private document containing only the information necessary for the distribution of the relevant bank assets. The investigation also concerned whether the controller had complied with its transparency obligations. The controller argued that its general privacy policy and a specific inheritance form provided the information required under Article 13 GDPR. However, it could not demonstrate that the relevant form or equivalent privacy information had actually been provided to the data subject when the personal data were collected. The DPA initially investigated a possible infringement of Article 5(1)(c) GD
Related Enforcement Actions (3)
Other enforcement actions involving CAIXABANK, S.A. in ES
Fine
€408K
Details
Fine Date
10 September 2026
Authority
Agencia Española de Protección de Datos
Fine Amount
€408,000
GDPRhub ID
gdprhub-10275About this data
Cite as: Cookie Fines. CAIXABANK, S.A. - Spain (2026). Retrieved from cookiefines.eu
Last updated: