The Spanish authority closes a complaint against CAIXABANK for an alleged GDPR violation related to the disclosure of bank certificates

The Spanish data protection authority closed a sanction procedure for confidentiality violation, considering that proof of unauthorized disclosure of documents by the data controller was not established. In the absence of certainty about the source of the leak, the authority applied the principle that doubt benefits the accused.

Facts and context

The Spanish data protection authority (AEPD) published a decision to close the procedure against CAIXABANK, S.A. for an alleged violation of the confidentiality principle.

The case originated from a complaint by a person who accused the bank of having communicated to a third party bank certificates she had signed, containing her signature and identity document number, in the context of an inheritance.

Reasons for the decision

  • Obligation of integrity and confidentiality (Article 5(1)(f) of the GDPR): The complainant argued that the bank disclosed to a third party copies of bank position certificates she had signed and which remained in the custody of the institution. Although the complainant did receive by email, from the lawyer of another heir, photographs of these signed documents, the authority considered that there was no evidence to attribute this leak with certainty to the bank. The authority noted that the documents could have been obtained by other means and that reasonable doubts remained about the bank's responsibility. Applying the principle that doubt benefits the accused, the authority concluded that the violation could not be established.

Authority's decision

Consequently, the authority ordered the closure of the sanction procedure initiated against CAIXABANK, S.A.

Lessons learned

This decision reminds that:

  • The burden of proof of a confidentiality violation lies with the authority, and in the absence of factual certainty about the origin of a disclosure, the principle of doubt benefiting the data controller can lead to closure of the procedure.
  • A mere allegation of unauthorized disclosure, even supported by circumstantial elements, may be deemed insufficient if reasonable doubts remain about the direct responsibility of the data controller.
  • For a sanction to be imposed, it is necessary to establish a direct and proven causal link between an action or omission of the data controller and the data breach observed.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire