SANTANDER CONSUMER FINANCE, S.A. – €500,000 Fine (Spain, 2025)

€500,000Agencia Española de Protección de Datos14 February 2025Spain
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

SANTANDER CONSUMER FINANCE, S.A. (the controller) is a bank. In October and November 2022, two companies acting as a processor for the controller reported a data breach to the DPA. The DPA began investigating following two complaints by data subjects against the processors, however, the controller was also investigated. The DPA found that the data breach affected over 100,000 data subjects, with data such as names, contact information, IBAN and ID information being available on the dark web. Some of the DPA’s findings were also based on previous data breach reports from processors contracted by the controller. The controller informed affected data subjects of the data breach in December 2022. The controller argued that it was not the controller in this case, as the data breach was targeted towards the processors. The DPA first dismissed the arguments by the controller. The DPA emphasised that the controller was responsible for the processing of personal data of its customers, and the negligence of third parties does not completely exempt it from responsibility. The DPA noted that, for example, the controller gave the processors insufficient instructions regarding security measures when processing personal data. The DPA found a violation of Article 5(1)(f) GDPR. During its investigations, the DPA found that until 2021 the controller stored data subjects’ IBAN without pseudonymising it. This meant there was a high risk of the data being accessed and misused by third parties. According to the DPA, the unauthorised access would have not occurred if the controller had pseudonymised or anonymised the data. The DPA fined the controller €500,000. The DPA considered this a serious violation, taking into account the high number of data subjects affected. In addition, the DPA ordered the controller to implement appropriate security measures.

GDPR Articles Cited

AI-verified

Art. 5(1)(f) GDPR
View original scraped data
Art. 5(1)(f) GDPR

Original data from scraper before AI verification against source document.

Source verified 6 March 2026
verified correct
Full Legal Summary

SANTANDER CONSUMER FINANCE, S.A. (the controller) is a bank. In October and November 2022, two companies acting as a processor for the controller reported a data breach to the DPA. The DPA began investigating following two complaints by data subjects against the processors, however, the controller was also investigated. The DPA found that the data breach affected over 100,000 data subjects, with data such as names, contact information, IBAN and ID information being available on the dark web. Some of the DPA’s findings were also based on previous data breach reports from processors contracted by the controller. The controller informed affected data subjects of the data breach in December 2022. The controller argued that it was not the controller in this case, as the data breach was targeted towards the processors. The DPA first dismissed the arguments by the controller. The DPA emphasised that the controller was responsible for the processing of personal data of its customers, and the negligence of third parties does not completely exempt it from responsibility. The DPA noted that, for example, the controller gave the processors insufficient instructions regarding security measures when processing personal data. The DPA found a violation of Article 5(1)(f) GDPR. During its investigations, the DPA found that until 2021 the controller stored data subjects’ IBAN without pseudonymising it. This meant there was a high risk of the data being accessed and misused by third parties. According to the DPA, the unauthorised access would have not occurred if the controller had pseudonymised or anonymised the data. The DPA fined the controller €500,000. The DPA considered this a serious violation, taking into account the high number of data subjects affected. In addition, the DPA ordered the controller to implement appropriate security measures.

Details

Fine Date

14 February 2025

Authority

Agencia Española de Protección de Datos

Fine Amount

€500,000

GDPRhub ID

gdprhub-9508

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. SANTANDER CONSUMER FINANCE, S.A. - Spain (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: