[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fu5oTi3MADQZrx679_ApMiSkPfaDFGeLYlc5JYZasY-w":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"c683377c-2a1f-47a2-b869-4850d59d17c9","caixabank-fined-408k-for-gdpr-violations-in-inheritance-data-handling","fa8b0252-b2b9-437b-bee7-2583da09dce6","CaixaBank Fined €408K for GDPR Violations in Inheritance Data Handling","CaixaBank collected more personal and financial data than was necessary during inheritance procedures, violating the GDPR principle of data minimisation by design under Article 25. The bank also failed to properly inform data subjects of their rights and how their data was being processed, breaching Article 13 transparency obligations. This case highlights that data protection must be embedded into business processes by design, not treated as an afterthought. Regulatory fines and reputational damage are the direct consequence of failing to align operational workflows with GDPR requirements.","**Immediate Actions:**\n- Conduct a data audit of all inheritance and similar procedural workflows to identify and remove excessive data collection.\n- Update all customer-facing privacy notices to clearly explain data processing purposes, legal bases, retention periods, and data subject rights.\n\n**Long-term Improvements:**\n- Implement a Privacy by Design framework that mandates data minimisation reviews for every new or updated business process involving personal data.\n- Establish a recurring GDPR compliance review cycle led by the Data Protection Officer (DPO) to assess all high-risk processing activities.\n- Embed data minimisation and transparency requirements into change management procedures so regulatory obligations are validated before process deployment.\n\n**Detection & Monitoring Measures:**\n- Deploy ongoing monitoring of data collection fields across operational systems to flag any collection beyond what is documented in the Records of Processing Activities (RoPA).\n- Schedule regular internal audits and third-party assessments specifically targeting Article 13 and Article 25 compliance gaps.",[12,13,14,15,16,17,18,19,20],"GDPR Article 5(1)(c) – Data Minimisation","GDPR Article 13 – Transparency and Information Obligations","GDPR Article 25 – Data Protection by Design and by Default","GDPR Article 83(4) – Administrative Fines","NIST Privacy Framework PR.DS-P1 – Data Processing","NIST SP 800-53 IP-1 – Consent and Privacy Notice","CIS Control 3 – Data Protection","ISO\u002FIEC 27701 – Privacy Information Management System (PIMS)","ITIL Service Design – Privacy and Data Governance","published","2026-09-15T14:20:21.854416+00:00","2026-09-15T14:20:21.724+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_ps-00028-2025&diff=53032&oldid=0","aepd-spain-ps-00028-2025-6ef529","AEPD (Spain) - ps-00028-2025",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]