CAIXABANK, S.A. – €3,500,000 Fine (Spain, 2024)

€3,500,000Agencia Española de Protección de Datos12 December 2024Spain
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Spanish DPA has imposed a fine of EUR 3.5 million on CAIXABANK, S.A. Following a complaint from customers, it was found that the mother of an account holder had access to a joint account via the bank's online platform, even though she was neither the account holder nor an authorized user. The DPA found that CaixaBank had not taken adequate technical and organizational measures to protect personal data. In addition, the principle of data protection by design and by default had been violated.

GDPR Articles Cited

AI-verified

Art. 25 GDPR
Art. 5(1)(f) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 25 GDPR

Original data from scraper before AI verification against source document.

Source verified 5 March 2026
date discrepancy
Full Legal Summary

The Spanish DPA has imposed a fine of EUR 3.5 million on CAIXABANK, S.A. Following a complaint from customers, it was found that the mother of an account holder had access to a joint account via the bank's online platform, even though she was neither the account holder nor an authorized user. The DPA found that CaixaBank had not taken adequate technical and organizational measures to protect personal data. In addition, the principle of data protection by design and by default had been violated.

Details

Fine Date

12 December 2024

Authority

Agencia Española de Protección de Datos

Fine Amount

€3,500,000

Enforcement Tracker ID

ETid-2562

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. CAIXABANK, S.A. - Spain (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: