Banco Bilbao Vizcaya Argentaria, S.A. – €70,000 Fine (Spain, 2023)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Banco Bilbao Vizcaya Argentaria was fined €70,000 after a third party withdrew €9,400 from a customer's account using a lost ID card without proper verification. This ruling emphasizes the need for banks to have strong security measures in place to protect customers' money.
What happened
A third party withdrew €9,400 from a customer's account using a lost ID card without proper identity verification.
Who was affected
The customer whose ID card was lost and whose money was withdrawn without authorization was affected.
What the authority found
The Spanish data protection authority found that the bank failed to implement adequate security measures to verify the customer's identity, violating data protection rules.
Why this matters
This case serves as a warning to banks and financial institutions about the importance of verifying customer identities. It shows that negligence in security can lead to significant penalties.
GDPR Articles Cited
In July 2021, the data subject lost his ID card. A third party went to his bank with the ID card and withdrew all the money available in the account, a total of €9,400, without his authorization or consent. The withdrawal was made in person at the local bank branch. The withdrawal also required the signature of the third party. The third party was able to withdraw the money despite their signature not corresponding to the signature on the data subject's ID card. The DPA seemed to infer that identifying a client at a bank for just the sake of providing them with a bank service involves a processing operation which must be carried out in compliance with Article 32 GDPR. The Spanish DPA considered the bank to have failed in adopting appropriate security measures by not verifying the data subject's identity in a reliable manner. As highlighted by AEPD, it was negligence that would have been overcome if available protocols would have been correctly followed. For example, correctly comparing and verifying both the photograph and the signature of the document that was presented in the request. By not using appropriate technical and organisational measures to ensure a level of security appropriate to the risk, the controller violated Article 6 and Article 32 GDPR.
Related Enforcement Actions (2)
Other enforcement actions involving Banco Bilbao Vizcaya Argentaria, S.A. in ES
Fine
€70K
Details
Fine Date
12 September 2023
Authority
Agencia Española de Protección de Datos
Fine Amount
€70,000
Enforcement Tracker ID
ETid-1477
GDPRhub ID
gdprhub-6267About this data
Cite as: Cookie Fines. Banco Bilbao Vizcaya Argentaria, S.A. - Spain (2023). Retrieved from cookiefines.eu
Last updated: