ING Bank Spain – €1,600,000 Fine (Spain, 2025)

€1,600,000Agencia Española de Protección de Datos27 March 2025Spain
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The data subject opened a “non-payroll” bank account, one which does not require proof of income, with ING Bank Spain (controller). In 2022, the controller informed her that her account would be reclassified as a “non-account account” if her balance exceeds €30,000 and recommended she open a “non-account account”, different account offering from the bank, and split her balance between the two. In order to open this other account, however, the controller required she provided consent for the controller to contact the General Treasury of the Social Security to verify the origin of funds to be deposited. The controller claimed this was necessary to comply with Spanish money laundering and anti-terrorist financing laws. A clause giving consent for this processing was included in a document containing pre-contractual information, to which the data subject had to click “confirm”. The anti-money laundering law in question, Law 10/2010, requires the verification of origin of funds where prospective clients either present higher than average risks arising from a provision or the bank’s own risk analysis, or, where prospective client’s banking records do not correspond to their declared activity or operating history. On 3 November 2022 the data subject filed a complaint with the AEPD (Spanish DPA). She argued that she falls into neither of the categories envisaged by Law 10/2010 and the controller is using it as an excuse to make the data subject give her consent. The controller argued that consent being sought in this context does not equate to the concept of consent under the GDPR. They noted that they rely on their legal obligation under Article 6(1)(c) GDPR for this processing, and the collection of the consent is to satisfy the envisaged requirement of getting “authorisation” from the prospective account holder, as envisaged in the money laundering law. The controller further argued that the verification of origin of funds by the Treasury is the only meaningful way, gi

GDPR Articles Cited

AI-verified

Art. 6(1) GDPR
Art. 6(1)(a) GDPR
Art. 6(1)(c) GDPR
Art. 6(1)(f) GDPR
View original scraped data
Art. 6(1) GDPR
Art. 6(1)(a) GDPR
Art. 6(1)(c) GDPR
Art. 6(1)(f) GDPR

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Regulation of Law 10/2010 of 28 April, on the prevention of money laundering and terrorist financing
Source verified 5 March 2026
articles corrected
national law identified
date discrepancy
Full Legal Summary

The data subject opened a “non-payroll” bank account, one which does not require proof of income, with ING Bank Spain (controller). In 2022, the controller informed her that her account would be reclassified as a “non-account account” if her balance exceeds €30,000 and recommended she open a “non-account account”, different account offering from the bank, and split her balance between the two. In order to open this other account, however, the controller required she provided consent for the controller to contact the General Treasury of the Social Security to verify the origin of funds to be deposited. The controller claimed this was necessary to comply with Spanish money laundering and anti-terrorist financing laws. A clause giving consent for this processing was included in a document containing pre-contractual information, to which the data subject had to click “confirm”. The anti-money laundering law in question, Law 10/2010, requires the verification of origin of funds where prospective clients either present higher than average risks arising from a provision or the bank’s own risk analysis, or, where prospective client’s banking records do not correspond to their declared activity or operating history. On 3 November 2022 the data subject filed a complaint with the AEPD (Spanish DPA). She argued that she falls into neither of the categories envisaged by Law 10/2010 and the controller is using it as an excuse to make the data subject give her consent. The controller argued that consent being sought in this context does not equate to the concept of consent under the GDPR. They noted that they rely on their legal obligation under Article 6(1)(c) GDPR for this processing, and the collection of the consent is to satisfy the envisaged requirement of getting “authorisation” from the prospective account holder, as envisaged in the money laundering law. The controller further argued that the verification of origin of funds by the Treasury is the only meaningful way, gi

Related Enforcement Actions (0)

No other enforcement actions found for ING Bank Spain in ES

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

27 March 2025

Authority

Agencia Española de Protección de Datos

Fine Amount

€1,600,000

GDPRhub ID

gdprhub-9205

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. ING Bank Spain - Spain (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: