The Spanish authority closes the case against OPENBANK without sanction for fraudulent account opening
The Spanish data protection authority has published a decision to close the procedure against the bank OPEN BANK, S.A., concerning data processing without a legal basis following identity theft, considering that the organization's culpability could not be established with certainty.
Facts and context
The case originates from a complaint filed by an individual on March 19, 2024, following the fraudulent opening of a bank account in their name on July 8, 2022, by a third party who had stolen their identity.
Reasons for the decision
The authority analyzed the identity verification measures implemented by the bank during the online account opening. Although the procedure resulted in the creation of an account for an impostor, the authority ultimately closed the case applying the principle of reasonable doubt regarding the bank's culpability.
- Lawfulness obligation of processing (Article 6(1) of the GDPR): The authority found that a bank account had been opened based on a fraudulent request, involving processing of the complainant's personal data without a valid legal basis. However, the analysis focused on the bank's subjective responsibility. The bank demonstrated that it followed its remote identification procedure, compliant with anti-money laundering regulations, by verifying the copy of the provided identity document, confirming ownership of another bank account in the complainant's name via an interbank service, and using a one-time code sent by text message for electronic signature. Although the phone number used belonged to a third party, the authority considered that the measures taken by the bank created reasonable doubt about the existence of negligent fault. Applying the principle *in dubio pro reo* (the benefit of the doubt to the accused), derived from Spanish criminal administrative law, the authority concluded that there was no basis for sanction due to the inability to establish the element of culpability with certainty.
Authority's decision
Consequently, the authority decided to close the procedure initiated against OPEN BANK, S.A.
Lessons learned
This decision reminds that:
- Demonstrating an objective violation of the GDPR alone is not sufficient to trigger a sanction; the supervisory authority must also establish the subjective element of culpability (intention or negligence) of the data controller.
- Compliance with identification procedures provided by other sectoral regulations, such as anti-money laundering, can be a decisive factor to exclude the culpability of an organization in cases of identity theft, even if these measures prove ineffective.
- In case of reasonable doubt about the diligence of a data controller facing sophisticated fraud, the authority may apply the principle *in dubio pro reo* and refrain from imposing a sanction.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire