CAIXABANK, S.A. – €408,000 Fine (Spain, 2026)

€408,000Agencia Española de Protección de Datos10 September 2026Spain
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

CaixaBank, S.A. was fined for collecting more personal information than necessary during an inheritance process. This matters because it shows that companies must only ask for information that is relevant to their services. The ruling serves as a reminder for financial institutions to respect privacy and limit data collection.

What happened

CaixaBank, S.A. collected excessive personal and financial information during an inheritance procedure.

Who was affected

Heirs of a deceased customer whose personal information was collected beyond what was necessary for the inheritance process.

What the authority found

The DPA ruled that CaixaBank violated GDPR by requesting more information than needed for the inheritance distribution.

Why this matters

This case highlights the importance of data minimization and may lead to stricter practices in how companies collect personal information.

GDPR Articles Cited

AI-verified

Art. 13(GDPR)
Art. 25(GDPR)
View original scraped data
Art. 13(GDPR)
Art. 25(GDPR)
Art. 30(GDPR)

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Art. 39/2015 Spanish Administrative Law
Source verified 16 September 2026
articles corrected
national law identified
Full Legal Summary
Detailed

A data subject and other heirs were handling the inheritance of a deceased customer through CaixaBank, S.A., the controller. In the course of the inheritance procedure, the controller obtained a complete notarised deed of acceptance, partition and allocation of the inheritance. The data subject considered that the controller had obtained substantially more personal and financial information than necessary to distribute the funds held with the controller. In particular, the deed contained information concerning the deceased's entire estate and personal and financial information relating to the heirs, including assets unrelated to the controller. The data subject subsequently complained to the controller and asked for the legal basis for requesting the complete deed. The controller replied that it had not required the submission of a complete public deed and claimed that the heirs could have provided only the relevant parts or used a private document. It also stated that its inheritance guidance informed customers of the available alternatives. The data subject lodged a complaint with the DPA. During its investigation, the DPA established that the controller's internal inheritance guide generally instructed heirs to submit a public deed of acceptance of the inheritance. The guide did not adequately inform heirs that the inheritance could instead be partitioned through a private document containing only the information necessary for the distribution of the relevant bank assets. The investigation also concerned whether the controller had complied with its transparency obligations. The controller argued that its general privacy policy and a specific inheritance form provided the information required under Article 13 GDPR. However, it could not demonstrate that the relevant form or equivalent privacy information had actually been provided to the data subject when the personal data were collected. The DPA initially investigated a possible infringement of Article 5(1)(c) GD

Details

Fine Date

10 September 2026

Authority

Agencia Española de Protección de Datos

Fine Amount

€408,000

GDPRhub ID

gdprhub-10275

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. CAIXABANK, S.A. - Spain (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: