The Spanish authority sanctions CAIXABANK for non-compliance with Articles 13 and 25 of the GDPR in inheritance management

The Spanish data protection authority has issued a sanction decision against CAIXABANK, S.A. including the imposition of a fine of €510,000 for breaches related to data protection by design and the information obligation in the context of inheritance management.

Facts and context

The case originated from a complaint filed on June 19, 2024, by an heir, who accused the bank of requiring the submission of a complete notarized deed of division, allocation, and acceptance of inheritance, deemed disproportionate.

Grounds for the decision

  • Obligation of data protection by design and by default (Article 25 of the GDPR): The authority found that CAIXABANK's internal procedure for inheritance management, as described in its own guide, systematically required heirs to present the complete public notarized deed. The authority considered this requirement disproportionate as it led to the collection of asset data not necessary for managing only the assets held by the bank. Relying on the 2022 Report of the Complaints Service of the Bank of Spain, the authority recalled that the requirement of a public deed instead of a private document is considered a practice contrary to good banking practices and, in this case, to the data minimization principle. By not designing a process that limits collection to only necessary data, the bank failed its obligation to integrate data protection by design, violating Article 25 of the GDPR, an analysis reinforced by the European Data Protection Board (EDPB) Guidelines 4/2019.
  • Information obligation at the time of data collection from the data subject (Article 13 of the GDPR): The authority established that CAIXABANK did not provide the complainant with the information required by Article 13 at the time of data collection. The bank could not prove having delivered any information document, merely producing an unsigned standard form. Furthermore, the authority verified that the bank's privacy policy, although available online, did not specifically mention the processing of data related to "post-mortem contractual management," making the information neither clear nor easily accessible to data subjects in this situation.

Authority's decision

Consequently, the authority imposed a fine of €510,000 on CAIXABANK, S.A., broken down into €500,000 for the violation of Article 25 and €10,000 for that of Article 13 of the GDPR.

Moreover, the authority ordered the bank to bring its procedures into compliance with Article 25 of the GDPR and to provide data subjects with the information required by Article 13, integrating this specific processing into its privacy policy, within six months.

Lessons learned

This decision reminds that:

  • The design of an internal process that systematically requires the submission of a document (such as a complete notarized deed) without providing a less intrusive alternative (such as a private document or an excerpt) constitutes a breach of the obligation of data protection by design.
  • In the context of inheritance management, a financial institution cannot require the production of a notarized deed for the distribution of assets and must accept a private document; the contrary practice is not only a bad banking practice but also a violation of the data minimization principle.
  • The mere existence of a privacy policy on a website is not sufficient to prove compliance with the information obligation; the data controller must be able to demonstrate that the information was actively provided or made accessible to the data subject at the time of data collection.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire