[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fD-MD2wwPq8XKQGaEFD6wj66yfA7NvIyF06xPcJUVKHU":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"755b4f51-177c-4d99-9cf5-37e08f3f67e4","AEPD (Spain) - ps-00028-2025","aepd-spain-ps-00028-2025-c598a2","← Older revision Revision as of 13:07, 22 September 2026 Line 104: Line 104: }} }} The DPA fined CaixaBank €408,000 for failing to implement data minimisation by design in inheritance procedures and for not providing data subjects with the information required under [[Article 13 GDPR|Article 13 GDPR]]. The DPA fined CaixaBank €408,000 for failing to implement data minimisation by design in inheritance procedures and for not providing data subjects with the information required under [[Article 13 GDPR]]. == English Summary == == English Summary == Line 117: Line 117: During its investigation, the DPA established that the controller's internal inheritance guide generally instructed heirs to submit a public deed of acceptance of the inheritance. The guide did not adequately inform heirs that the inheritance could instead be partitioned through a private document containing only the information necessary for the distribution of the relevant bank assets. During its investigation, the DPA established that the controller's internal inheritance guide generally instructed heirs to submit a public deed of acceptance of the inheritance. The guide did not adequately inform heirs that the inheritance could instead be partitioned through a private document containing only the information necessary for the distribution of the relevant bank assets. The investigation also concerned whether the controller had complied with its transparency obligations. The controller argued that its general privacy policy and a specific inheritance form provided the information required under [[Article 13 GDPR|Article 13 GDPR]]. However, it could not demonstrate that the relevant form or equivalent privacy information had actually been provided to the data subject when the personal data were collected. The investigation also concerned whether the controller had complied with its transparency obligations. The controller argued that its general privacy policy and a specific inheritance form provided the information required under [[Article 13 GDPR]]. However, it could not demonstrate that the relevant form or equivalent privacy information had actually been provided to the data subject when the personal data were collected. The DPA initially investigated a possible infringement of [[Article 5 GDPR|Article 5(1)(c) GDPR]] concerning data minimisation. Following the investigation, it considered that the systemic design of the controller's inheritance procedure was more appropriately assessed under [[Article 25 GDPR|Article 25 GDPR]]. The DPA also investigated a possible infringement of [[Article 30 GDPR|Article 30 GDPR]]. During the proceedings, the controller provided the complete version of its record of processing activities and demonstrated that inheritance-related processing was included in it. The DPA initially investigated a possible infringement of [[Article 5 GDPR|Article 5(1)(c) GDPR]] concerning data minimisation. Following the investigation, it considered that the systemic design of the controller's inheritance procedure was more appropriately assessed under [[Article 25 GDPR]]. The DPA also investigated a possible infringement of [[Article 30 GDPR]]. During the proceedings, the controller provided the complete version of its record of processing activities and demonstrated that inheritance-related processing was included in it. === Holding === === Holding === The DPA found that the controller infringed [[Article 25 GDPR|Article 25 GDPR]] because its inheritance procedure was not designed in accordance with the principle of data minimisation. The controller's internal process generally contemplated the collection of a complete notarised inheritance deed, although this could contain extensive personal and financial information unrelated to the specific banking assets concerned. The DPA considered that the controller could have relied on documentation limited to the information necessary to establish the heirs' rights over the relevant assets. Since this resulted from the design of the controller's general procedure, the DPA assessed the conduct under [[Article 25 GDPR|Article 25 GDPR]] rather than [[Article 5 GDPR|Article 5(1)(c) GDPR]]. The DPA found that the controller infringed [[Article 25 GDPR]] because its inheritance procedure was not designed in accordance with the principle of data minimisation. The controller's internal process generally contemplated the collection of a complete notarised inheritance deed, although this could contain extensive personal and financial information unrelated to the specific banking assets concerned. The DPA considered that the controller could have relied on documentation limited to the information necessary to establish the heirs' rights over the relevant assets. Since this resulted from the design of the controller's general procedure, the DPA assessed the conduct under [[Article 25 GDPR]] rather than [[Article 5 GDPR|Article 5(1)(c) GDPR]]. The DPA also found an infringement of [[Article 13 GDPR|Article 13 GDPR]]. The controller could not demonstrate that the data subject had been provided with the required information when the personal data were collected. Its general privacy policy did not clearly cover inheritance-related processing and the specific information form submitted during the investigation was unsigned. The DPA also found an infringement of [[Article 13 GDPR]]. The controller could not demonstrate that the data subject had been provided with the required information when the personal data were collected. Its general privacy policy did not clearly cover inheritance-related processing and the specific information form submitted during the investigation was unsigned. The DPA imposed fines of €500,000 for the infringement of [[Article 25 GDPR|Article 25 GDPR]] and €10,000 for the infringement of [[Article 13 GDPR|Article 13 GDPR]]. The alleged infringement of [[Article 30 GDPR|Article 30 GDPR]] was archived after the controller demonstrated that inheritance-related processing was included in its record of processing activities. The DPA imposed fines of €500,000 for the infringement of [[Article 25 GDPR]] and €10,000 for the infringement of [[Article 13 GDPR]]. The alleged infringement of [[Article 30 GDPR]] was archived after the controller demonstrated that inheritance-related processing was included in its record of processing activities. Following voluntary payment, the total fine of €510,000 was reduced by 20% to €408,000 according to Spanish Administrative Law (39\u002F2015). The DPA also ordered the controller, within six months, to adopt measures ensuring compliance with [[Article 25 GDPR|Article 25 GDPR]], provide the information required under [[Article 13 GDPR|Article 13 GDPR]] to affected data subjects and include inheritance-related processing in its privacy policy. Following voluntary payment, the total fine of €510,000 was reduced by 20% to €408,000 according to Spanish Administrative Law (39\u002F2015). The DPA also ordered the controller, within six months, to adopt measures ensuring compliance with [[Article 25 GDPR]], provide the information required under [[Article 13 GDPR]] to affected data subjects and include inheritance-related processing in its privacy policy. == Comment == == Comment ==","Spain's data protection authority (AEPD) has fined CaixaBank €408,000 for violating GDPR. The bank failed to implement data minimization by design in its inheritance procedures and did not adequately inform heirs about their data rights. The fine was reduced from an initial €510,000 due to voluntary payment.","Spain's AEPD fines CaixaBank €408,000 for GDPR violations related to inheritance procedures.","Help AEPD (Spain) - ps-00028-2025: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 13:46, 15 September 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators322 edits Tag: Decisions [1.0] Latest revision as of 13:07, 22 September 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators322 editsTag: Visual edit Line 104: Line 104: }}}} The DPA fined CaixaBank €408,000 for failing to implement data minimisation by design in inheritance procedures and for not providing data subjects with the information required under [[Article 13 GDPR|Article 13 GDPR]].The DPA fined CaixaBank €408,000 for failing to implement data minimisation by design in inheritance procedures and for not providing data subjects with the information required under [[Article 13 GDPR]]. == English Summary ==== English Summary == Line 117: Line 117: During its investigation, the DPA established that the controller's internal inheritance guide generally instructed heirs to submit a public deed of acceptance of the inheritance. The guide did not adequately inform heirs that the inheritance could instead be partitioned through a private document containing only the information necessary for the distribution of the relevant bank assets.During its investigation, the DPA established that the controller's internal inheritance guide generally instructed heirs to submit a public deed of acceptance of the inheritance. The guide did not adequately inform heirs that the inheritance could instead be partitioned through a private document containing only the information necessary for the distribution of the relevant bank assets. The investigation also concerned whether the controller had complied with its transparency obligations. The controller argued that its general privacy policy and a specific inheritance form provided the information required under [[Article 13 GDPR|Article 13 GDPR]]. However, it could not demonstrate that the relevant form or equivalent privacy information had actually been provided to the data subject when the personal data were collected.The investigation also concerned whether the controller had complied with its transparency obligations. The controller argued that its general privacy policy and a specific inheritance form provided the information required under [[Article 13 GDPR]]. However, it could not demonstrate that the relevant form or equivalent privacy information had actually been provided to the data subject when the personal data were collected. The DPA initially investigated a possible infringement of [[Article 5 GDPR|Article 5(1)(c) GDPR]] concerning data minimisation. Following the investigation, it considered that the systemic design of the controller's inheritance procedure was more appropriately assessed under [[Article 25 GDPR|Article 25 GDPR]]. The DPA also investigated a possible infringement of [[Article 30 GDPR|Article 30 GDPR]]. During the proceedings, the controller provided the complete version of its record of processing activities and demonstrated that inheritance-related processing was included in it. The DPA initially investigated a possible infringement of [[Article 5 GDPR|Article 5(1)(c) GDPR]] concerning data minimisation. Following the investigation, it considered that the systemic design of the controller's inheritance procedure was more appropriately assessed under [[Article 25 GDPR]]. The DPA also investigated a possible infringement of [[Article 30 GDPR]]. During the proceedings, the controller provided the complete version of its record of processing activities and demonstrated that inheritance-related processing was included in it. === Holding ====== Holding === The DPA found that the controller infringed [[Article 25 GDPR|Article 25 GDPR]] because its inheritance procedure was not designed in accordance with the principle of data minimisation. The controller's internal process generally contemplated the collection of a complete notarised inheritance deed, although this could contain extensive personal and financial information unrelated to the specific banking assets concerned. The DPA considered that the controller could have relied on documentation limited to the information necessary to establish the heirs' rights over the relevant assets. Since this resulted from the design of the controller's general procedure, the DPA assessed the conduct under [[Article 25 GDPR|Article 25 GDPR]] rather than [[Article 5 GDPR|Article 5(1)(c) GDPR]].The DPA found that the controller infringed [[Article 25 GDPR]] because its inheritance procedure was not designed in accordance with the principle of data minimisation. The controller's internal process generally contemplated the collection of a complete notarised inheritance deed, although this could contain extensive personal and financial information unrelated to the specific banking assets concerned. The DPA considered that the controller could have relied on documentation limited to the information necessary to establish the heirs' rights over the relevant assets. Since this resulted from the design of the controller's general procedure, the DPA assessed the conduct under [[Article 25 GDPR]] rather than [[Article 5 GDPR|Article 5(1)(c) GDPR]]. The DPA also found an infringement of [[Article 13 GDPR|Article 13 GDPR]]. The controller could not demonstrate that the data subject had been provided with the required information when the personal data were collected. Its general privacy policy did not clearly cover inheritance-related processing and the specific information form submitted during the investigation was unsigned.The DPA also found an infringement of [[Article 13 GDPR]]. The controller could not demonstrate that the data subject had been provided with the required information when the personal data were collected. Its general privacy policy did not clearly cover inheritance-related processing and the specific information form submitted during the investigation was unsigned. The DPA imposed fines of €500,000 for the infringement of [[Article 25 GDPR|Article 25 GDPR]] and €10,000 for the infringement of [[Article 13 GDPR|Article 13 GDPR]]. The alleged infringement of [[Article 30 GDPR|Article 30 GDPR]] was archived after the controller demonstrated that inheritance-related processing was included in its record of processing activities.The DPA imposed fines of €500,000 for the infringement of [[Article 25 GDPR]] and €10,000 for the infringement of [[Article 13 GDPR]]. The alleged infringement of [[Article 30 GDPR]] was archived after the controller demonstrated that inheritance-related processing was included in its record of processing activities. Following voluntary payment, the total fine of €510,000 was reduced by 20% to €408,000 according to Spanish Administrative Law (39\u002F2015). The DPA also ordered the controller, within six months, to adopt measures ensuring compliance with [[Article 25 GDPR|Article 25 GDPR]], provide the information required under [[Article 13 GDPR|Article 13 GDPR]] to affected data subjects and include inheritance-related processing in its privacy policy.Following voluntary payment, the total fine of €510,000 was reduced by 20% to €408,000 according to Spanish Administrative Law (39\u002F2015). The DPA also ordered the controller, within six months, to adopt measures ensuring compliance with [[Article 25 GDPR]], provide the information required under [[Article 13 GDPR]] to affected data subjects and include inheritance-related processing in its privacy policy. == Comment ==== Comment == Latest revision as of 13:07, 22 September 2026 AEPD - ps-00028-2025 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 13 GDPR Article 25 GDPR Article 30 GDPR Article 71 LOPDGDDArticle 73 LOPDGDDArticle 76 LOPDGDD Type: Complaint Outcome: Upheld Started: Decided: 10.09.2026 Published: 10.09.2026 Fine: 408000.0 ","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_ps-00028-2025&diff=53149&oldid=53032","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F5\u002F59\u002FLogoES.jpg","2026-09-22T13:07:34+00:00","2026-09-22T14:00:13.875319+00:00",7,[18],{"name":19,"type":20},"CaixaBank","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,32,37,39],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":38},{"id":21,"icon":23,"name":24,"slug":25},{"category":40},{"id":41,"icon":23,"name":42,"slug":43},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]