Back to Feed
Privacy FinesSep 15, 2026

AEPD (Spain) - ps-00028-2025

Spain's AEPD fines CaixaBank €408,000 for GDPR violations in inheritance procedures.

Summary

Spain's data protection authority (AEPD) has fined CaixaBank €408,000 for failing to adhere to GDPR principles in its inheritance procedures. The bank was found to have collected more personal and financial data than necessary, violating data minimisation by design requirements under Article 25 GDPR. Additionally, CaixaBank failed to adequately inform data subjects about their rights and the data processing involved, breaching Article 13 GDPR transparency obligations.

Full text

Help AEPD (Spain) - ps-00028-2025: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 13:46, 15 September 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators309 edits Tag: Decisions [1.0] (No difference) Latest revision as of 13:46, 15 September 2026 AEPD - ps-00028-2025 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 13 GDPR Article 25 GDPR Article 30 GDPR Article 71 LOPDGDDArticle 73 LOPDGDDArticle 76 LOPDGDD Type: Complaint Outcome: Upheld Started: Decided: 10.09.2026 Published: 10.09.2026 Fine: 408000.0 EUR Parties: CAIXABANK, S.A. National Case Number/Name: ps-00028-2025 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Spanish Original Source: AEPD (in ES) Initial Contributor: bms The DPA fined CaixaBank €408,000 for failing to implement data minimisation by design in inheritance procedures and for not providing data subjects with the information required under Article 13 GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A data subject and other heirs were handling the inheritance of a deceased customer through CaixaBank, S.A., the controller. In the course of the inheritance procedure, the controller obtained a complete notarised deed of acceptance, partition and allocation of the inheritance. The data subject considered that the controller had obtained substantially more personal and financial information than necessary to distribute the funds held with the controller. In particular, the deed contained information concerning the deceased's entire estate and personal and financial information relating to the heirs, including assets unrelated to the controller. The data subject subsequently complained to the controller and asked for the legal basis for requesting the complete deed. The controller replied that it had not required the submission of a complete public deed and claimed that the heirs could have provided only the relevant parts or used a private document. It also stated that its inheritance guidance informed customers of the available alternatives. The data subject lodged a complaint with the DPA. During its investigation, the DPA established that the controller's internal inheritance guide generally instructed heirs to submit a public deed of acceptance of the inheritance. The guide did not adequately inform heirs that the inheritance could instead be partitioned through a private document containing only the information necessary for the distribution of the relevant bank assets. The investigation also concerned whether the controller had complied with its transparency obligations. The controller argued that its general privacy policy and a specific inheritance form provided the information required under Article 13 GDPR. However, it could not demonstrate that the relevant form or equivalent privacy information had actually been provided to the data subject when the personal data were collected. The DPA initially investigated a possible infringement of Article 5(1)(c) GDPR concerning data minimisation. Following the investigation, it considered that the systemic design of the controller's inheritance procedure was more appropriately assessed under Article 25 GDPR. The DPA also investigated a possible infringement of Article 30 GDPR. During the proceedings, the controller provided the complete version of its record of processing activities and demonstrated that inheritance-related processing was included in it. Holding The DPA found that the controller infringed Article 25 GDPR because its inheritance procedure was not designed in accordance with the principle of data minimisation. The controller's internal process generally contemplated the collection of a complete notarised inheritance deed, although this could contain extensive personal and financial information unrelated to the specific banking assets concerned. The DPA considered that the controller could have relied on documentation limited to the information necessary to establish the heirs' rights over the relevant assets. Since this resulted from the design of the controller's general procedure, the DPA assessed the conduct under Article 25 GDPR rather than Article 5(1)(c) GDPR. The DPA also found an infringement of Article 13 GDPR. The controller could not demonstrate that the data subject had been provided with the required information when the personal data were collected. Its general privacy policy did not clearly cover inheritance-related processing and the specific information form submitted during the investigation was unsigned. The DPA imposed fines of €500,000 for the infringement of Article 25 GDPR and €10,000 for the infringement of Article 13 GDPR. The alleged infringement of Article 30 GDPR was archived after the controller demonstrated that inheritance-related processing was included in its record of processing activities. Following voluntary payment, the total fine of €510,000 was reduced by 20% to €408,000 according to Spanish Administrative Law (39/2015). The DPA also ordered the controller, within six months, to adopt measures ensuring compliance with Article 25 GDPR, provide the information required under Article 13 GDPR to affected data subjects and include inheritance-related processing in its privacy policy. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details. Case No.: EXP202403125 DECISION TO TERMINATE THE PROCEEDINGS DUE TO VOLUNTARY PAYMENT Regarding the proceedings conducted by the Spanish Data Protection Agency and based on the following BACKGROUND FIRST: On July 9, 2025, the Presidency of the Spanish Data Protection Agency agreed to initiate disciplinary proceedings against CAIXABANK, S.A. (hereinafter, CAIXABANK). Once the decision to initiate proceedings was notified and after analyzing the arguments submitted, on May 8, 2026, the proposed resolution was issued, as transcribed below: << Case No.: EXP202403125 PROPOSED RESOLUTION ON DISCIPLINARY PROCEEDINGS Regarding the proceedings conducted by the Spanish Data Protection Agency and based on the following: BACKGROUND FIRST: On June 19, 2024, a complaint was filed with the regarding a possible violation attributable to CAIXABANK, S.A., Tax ID No. A08663619 (hereinafter, CAIXABANK or the respondent). The facts brought to the attention of the Data Protection Authority are as follows: (…) the complainant had a joint account with the respondent. The complainant (acting on their own behalf and also in representation of (…)) states that, following the death of (...) and during the settlement of his estate at a branch of the respondent, the account manager assigned to them by said institution required, as a necessary step to proceed with the processing and disbursement of funds, the submission, among other documents, of the notarized deed of partition, allocation, and acceptance of the inheritance, dated June 6, 2022, signed by the three interested parties (…). The requested documentation was delivered to the branch by the interested parties (the claimant), without their being provided with a document certifying the delivery or receipt. However, the claimant states that they subsequently became aware that current regulations stipulate that it is sufficient to provide a private document signed by all interested parties agreeing to the distribution of the 28001 - Madrid 6 sedeagpd.gob.es 2/46 funds at the banks; therefore, they consider the requirement to submit the aforementioned deed to be disproportionate, given that the respondent has unjustifiably accessed a large amount of private information about the deceased and also of his wife (informatio

Entities

CaixaBank (vendor)