AEPD (Spain) - PS-00437-2024
| AEPD - PS-00437-2024 | |
|---|---|
| Authority: | AEPD (Spain) |
| Jurisdiction: | Spain |
| Relevant Law: | Article 5(1)(f) GDPR Article 32 GDPR Article 34 GDPR |
| Type: | Other |
| Outcome: | n/a |
| Started: | 23.02.2023 |
| Decided: | |
| Published: | |
| Fine: | 650.000 EUR |
| Parties: | Iberia Líneas Aéreas de España, S.A. |
| National Case Number/Name: | PS-00437-2024 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Spanish |
| Original Source: | AEPD (in ES) |
| Initial Contributor: | bms |
The DPA fined an airline €650,000 for failing to implement appropriate security measures after a data breach at one of its processors exposed personal data across several Member States. The DPA also noted that the airline failed to notify the affected data subjects.
English Summary
Facts
Iberia Líneas Aéreas de España, S.A. Operadora, the controller, notified the DPA of a personal data breach on 23 February 2023. The controller stated that, on 20 February 2023, one of its service providers, acting as processor, informed it of a cybersecurity incident involving unauthorised access to systems containing personal data.
The breach affected the confidentiality of personal data. The controller initially stated that the incident involved an external and intentional cyberattack, that the data were not encrypted or otherwise rendered unintelligible, and that the possible consequences included identity theft and phishing or spam campaigns. The affected data included basic personal data, professional contact details, credentials, flight-related information, ticket information, company membership information and travel agency names. The affected data subjects included employees of the controller and representatives of corporate clients.
The controller later updated the DPA and confirmed that the incident had involved access to and exfiltration of personal data under its responsibility. The breach affected data subjects in several Member States, including Germany, Austria, Belgium, Denmark, France, Italy, the Netherlands, Portugal and Sweden.
The controller did not communicate the breach to the affected data subjects. It argued that, although the DPA’s own breach communication tool indicated that the breach should be communicated to the data subjects, it had adopted sufficient mitigation measures after the incident so that a high risk to the rights and freedoms of the data subjects was no longer likely to materialise.
The DPA initiated sanctioning proceedings against the controller for alleged infringements of Articles 5(1)(f), 32 and 34 GDPR. During the proceedings, the controller argued that it had implemented adequate security measures, that the breach resulted from an external attack against the processor, and that no sanction should be imposed.
Holding
The DPA held that the controller infringed Article 5(1)(f) GDPR, which requires personal data to be processed in a manner ensuring appropriate security, including protection against unauthorised or unlawful processing.
The DPA found that the controller had not demonstrated that it had carried out an adequate risk assessment for the processing operation affected by the breach. In particular, the documentation provided by the controller did not identify concrete risks linked to the processing, nor did it set out adequate technical and organisational measures to mitigate such risks. According to the DPA, since the GDPR requires security measures to be appropriate to the risks of the processing, the absence of an adequate risk analysis necessarily undermined the controller’s ability to select and implement effective safeguards.
The DPA also considered that the security measures in place were not appropriate in light of the risks. The DPA noted that the incident led to unauthorised access to and downloading of personal data and that the relevant infrastructure remained accessible for more than a month and a half. This showed, in the DPA’s view, insufficient monitoring and detection capabilities. The DPA further referred to weaknesses concerning the protection of credentials and passwords and considered that the controller had not adequately ensured the confidentiality of the affected data.
The DPA therefore concluded that the controller had breached the integrity and confidentiality principle under Article 5(1)(f) GDPR. It imposed an administrative fine of €650,000.
The DPA did not impose separate sanctions for Articles 32 and 34 GDPR. As regards Article 32 GDPR, the alleged lack of appropriate technical and organisational measures was assessed as part of the Article 5(1)(f) GDPR infringement, since both provisions were based on the same security shortcomings. As regards Article 34 GDPR, the DPA considered that the controller should have communicated the breach to the data subjects, but archived this infringement because it was time-barred under national law.
In addition to the fine, the DPA ordered the controller, under Article 58(2)(d) GDPR, to prove within six months that it had adopted technical and organisational security measures appropriate to the risk of the personal data processing carried out.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.
1/59
• File No.: EXP202312854
RESOLUTION OF TERMINATION OF PROCEEDINGS DUE TO VOLUNTARY PAYMENT
From the proceedings initiated by the Spanish Data Protection Agency and based on the following
BACKGROUND
FIRST: On April 16, 2025, the Presidency of the Spanish Data Protection Agency agreed to initiate sanctioning proceedings against CAIXABANK, S.A.
(hereinafter, CAIXABANK). Having been notified of the initiation agreement and after analyzing the allegations presented, on March 4, 2026, the following proposed resolution was issued:
<<
File No.: EXP202312854
PROPOSED RESOLUTION OF SANCTIONING PROCEEDINGS
From the proceedings initiated by the Spanish Data Protection Agency and based on the following:
BACKGROUND
Contents
FIRST: Complaint 1.........................................................................................3
SECOND: Complaint 2........................................................................................3
THIRD: Preliminary investigative actions......................................................4
FOURTH: Agreement to initiate sanctioning proceedings:......................................4
FIFTH: Allegations against the initiation agreement:................................................................5
1. Context in which the processing of personal data affected by the Personal data breaches......................................................5
2. Article 5.1 f) of the GDPR......................................................................................5
3. Article 25 of the GDPR..........................................................................................6
4. Lack of proportionality...................................................................................6
5. Existence of a medial concurrence.......................................................................6
SIXTH: Trial period:.....................................................................7
SEVENTH: List of documents included in the proceedings:........................7
PROVEN FACTS..................................................................................................7
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 2/59
INDEX OF PROVEN FACTS:...........................................................................7
FIRST:.................................................................................................................8
SECOND:................................................................................................................9
THIRD:...............................................................................................................10
FOURTH:.................................................................................................................11
FIFTH:..................................................................................................................12
SIXTH:....................................................................................................................13
SEVENTH:................................................................................................................14
EIGHTH:..................................................................................................................15
NINTH:.................................................................................................................16
TENTH:..................................................................................................................18
ELEVENTH:.............................................................................................................20
TWELFTH:..........................................................................................................21
THIRTEENTH:................................................................................................23
FOURTEENTH:...................................................................................................23
FIFTEENTH:....................................................................................................25
SIXTEENTH:......................................................................................................26
SEVENTEENTH:..................................................................................................27
EIGHTEENTH:......................................................................................................27
NINETEENTH:..................................................................................................28
TWENTIETH:..............................................................................................................28
TWENTY-FIRST:.............................................................................................29
TWENTY-SECOND:............................................................................................31
TWENTY-THIRD:............................................................................................33
TWENTY-FOURTH:...............................................................................................34
TWENTY-FIFTH:................................................................................................36
TWENTY-SIXTH:..................................................................................................37
TWENTY-SEVENTH:..............................................................................................39
TWENTY-EIGHTH:...............................................................................................40
TWENTIETH NINTH:..............................................................................................40
THIRTIETH:............................................................................................................42
THIRTY-FIRST:...........................................................................................43
THIRTY-SECOND:.........................................................................................45
THIRTY-THIRD:..........................................................................................45
THIRTY-FOURTH:............................................................................................47
THIRTY-FIFTH:.............................................................................................49
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 3/59
THIRTY-SIXTH:...............................................................................................50
THIRTY-SEVENTH:...........................................................................................52
LEGAL BASIS.................................................................................53
I. Jurisdiction..........................................................................................................53
II. Preliminary Issues................................................................................................53
III Response to the Objections Made to the Initiation Agreement..........................54
1. OBJECTIONS RELATING TO THE CONTEXT IN WHICH THE PROCESSING OF PERSONAL DATA AFFECTED BY THE
PERSONAL DATA BROKENNESSES TAKES PLACE................................................................54
2. ARTICLES 25 and 5.1 f) of the GDPR....................................................................56
3. PROPORTIONALITY:...................................................................................78
IV Breach of Obligation. Data Protection by Design and by Default.........79
V. Classification of the infringement under Article 25 of the GDPR and its classification for the purposes of the statute of limitations..............................................................................................................80
VI. Proposed Sanction..........................................................................................81
Breached obligation under Article 25 of the GDPR:..................................................82
VII. Corrective Measures............................................................................................86
FIRST: Complaint 1
On July 19, 2023, a complaint was filed with the Spanish Data Protection Agency (hereinafter, AEPD) by A.A.A. (complainant 1) regarding a possible infringement attributable to CAIXABANK, S.A., with Tax Identification Number A08663619 (hereinafter, CAIXABANK, the bank, or the respondent).
The facts brought to the attention of this authority are as follows:
The claimant states that on ***DATE.1, they received an email from
CAIXABANK Customer Service (hereinafter,
independently referred to as Customer Service, CAIXABANK Customer Service, or ***COMPANY.1 Customer Service) in response to
a complaint they had not filed, addressed to a third party, B.B.B.,
whom they do not know.
The content of said claim, the accompanying documentation, the
processing thereof, and the references to said claim contained in the
preliminary investigation report, are reflected in the facts established
first through eighth.
In summary, claimant 1 received a response to a claim he had not
submitted, which revealed data addressed to a third party
(a representative of another CAIXABANK client, neither of whom were known to him).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 4/59
During the preliminary investigation, it was discovered that the document in question
was also sent to the representative of another CAIXABANK client, revealing personal data
of Complainant 1.
SECOND: Complaint 2
On October 16, 2023, a complaint was filed with the Spanish Data Protection Agency
by C.C.C. (Complainant 2) regarding a possible
infringement attributable to CAIXABANK, S.A., in which he states that CAIXABANK sent him
documentation relating to two people he does not know.
The content of said claim, the accompanying documentation, the
processing of said claim, and the references to said claim contained in the
preliminary investigation report, are reflected in the
proven facts nine through thirteen.
In summary, claimant 2, who had submitted a request to CAIXABANK,
filed two complaints regarding the manner in which said request was being processed.
In response to one of these complaints, CAIXABANK sent a reply
erroneously attaching a letter addressed to another CAIXABANK customer, revealing
that customer's personal data.
During the trial phase, it was discovered that the response was also
sent to a third party (a CAIXABANK customer, unknown to claimant 2), to whom
claimant 2's personal data was disclosed.
Subsequently, as the processing of the application submitted by claimant 2 to CAIXABANK continued, the branch manager mistakenly sent him a document prepared
for signature that contained the personal data of a third party (a CAIXABANK customer
different from those mentioned above), thus disclosing the claimant's personal data.
THIRD: Preliminary Investigative Actions
The Deputy Directorate General for Data Inspection carried out preliminary investigative actions to clarify the facts in question, pursuant to the functions assigned to supervisory authorities in Article 57.1 and the powers granted in Article 58.1 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VIII of the LOPDGDD (Spanish Organic Law on the Protection of Personal Data and Guarantee of Digital Rights).
As a result of the actions taken, the following have been made known:
The points reflected in the preliminary investigation report of February 28, 2025.
FOURTH: Agreement to initiate sanctioning proceedings:
On April 16, 2025, the Presidency of the Spanish Data Protection Agency (AEPD) agreed to initiate sanctioning proceedings against the respondent, in accordance with the provisions of Articles 63 and 64 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), for the alleged infringement:
- Of Article 5.1.f) of the GDPR, as defined in Article 83.5 of the GDPR.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 5/59
LPACAP - From Article 25 of the GDPR and classified in Article 83.4 of the GDPR.
FIFTH: Allegations against the initiation agreement:
Having been notified of the aforementioned initiation agreement in accordance with the rules established in Law
39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), the respondent submitted a statement of allegations in which, in summary, it stated the following:
1. Context in which the processing of personal data affected by the personal data breaches takes place
The activity of the CAIXABANK Customer Service Department is subject to a series of legal requirements arising from the banking sector in which it operates. These requirements, on the one hand,
condition its operation, since the service cannot function
exclusively according to CAIXABANK's criteria, and, on the other hand, imply
direct supervision of its operation by the Bank of Spain, with the ultimate goal of
improving its performance.
The operation of CAIXABANK's Customer Service Center (SAC) is based on documented procedures,
of a preventative nature and with a focus on the risks inherent in the activity
carried out by Customer Service Centers in the banking sector. For this reason, the defendant does not
consider the perception that it could be an environment where errors or non-compliance are systematically
going to occur. According to CAIXABANK, the
isolated instances in which such errors occur are due to the very nature of the Customer Service Center's activity, which is clearly exposed to potential human error.
According to CAIXABANK, the Customer Service Department (SAC) operates according to pre-established, highly preventative procedures that take into account the risks inherent in all the activities it carries out.
In addition to the above, CAIXABANK states that:
1. The SAC must prepare an annual report of its activities, which is presented to the Board of Directors. This report, or a summary thereof, is included in CAIXABANK's annual report.
2. The SAC is subject to an independent internal review, conducted by CAIXABANK's internal audit function, which evaluates the proper functioning and organization of the service.
CAIXABANK concludes that the direct cause of the two personal data breaches examined in this case file is not the way in which the Customer Service Department (SAC) was configured and managed, but rather isolated human errors committed by SAC staff who did not follow the procedures and instructions provided by CAIXABANK for carrying out the SAC's activities.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 6/59
2. Article 5.1 f) of the GDPR
1. CAIXABANK believes that the Spanish Data Protection Agency (AEPD) does not adequately assess the potential consequences of the personal data breaches for those affected, nor does it provide evidence of damages suffered.
In their opinion, the sanction is disproportionate, considering the facts, the circumstances, and the fact that no damages were caused to the interested parties.
2. The respondent asserts that adequate measures were in place to mitigate the risk of personal data breaches in the operation of the customer service department of COMPANY 1. They indicate that if personal data breaches occurred, it was due to human error, as the individuals responsible for handling complaints failed to follow the instructions provided by CAIXABANK.
In their opinion, a declaration of infringement for a violation of the principle of integrity and confidentiality (Article 5.1 f) of the GDPR) is not warranted, based on the lack of technical and organizational measures to guarantee the security of personal data, given that the personal data breaches were due to human error.
3. Article 25 of the GDPR
1. CAIXABANK points out that measures must be adopted at the design stage of the processing operations and also during the processing itself. It emphasizes that the processing must be adapted to changing risks within the framework of a continuous improvement process.
In the opinion of the respondent, its actions, which they consider diligent, both before and after the two personal data breaches that prompted the decision to initiate the sanctioning procedure, are not being adequately assessed.
2. It indicates that the information provided by CAIXABANK in response to the various requests from the Spanish Data Protection Agency (AEPD) reflects, according to the bank, that the measures adopted prior to the two personal data breaches were already effective in mitigating the risk of personal data breaches occurring, without prejudice to possible human error.
3. The respondent argues that in this second infringement, the Spanish Data Protection Agency (AEPD) does not precisely identify which infringement has been committed, given that Article 25 of the GDPR includes two different obligations or principles. It understands that the AEPD is referring to Article 25.1 of the GDPR.
4. Furthermore, it asserts that the principle of data protection by design, regulated in Article 25.1 of the GDPR, has not been violated, as it has been taken into account throughout the entire lifecycle of the data processing carried out by the CAIXABANK Customer Service Department.
4. Lack of Proportionality
In the respondent's opinion, there is a clear lack of proportionality in the proposed sanctions.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 7/59
5. Existence of a medial concurrence
CAIXABANK asserts that there is a medial concurrence between the two proposed infringements.
The respondent argues that some of the principles and safeguards that must be present in sanctioning procedures have been disregarded and requests that the proceedings be dismissed, as no infringement has been committed on its part.
If the proceedings are not dismissed, the respondent requests that a single sanction be imposed for non-compliance with Article 5.1 f) of the GDPR, which would absorb the alleged infringement of Article 25.1 of the GDPR, given the existence of a concurrent infringement, thus reducing the amount of the fine.
Finally, if a single sanction is not imposed, the respondent requests that the amounts of the fines be significantly reduced.
SIXTH: Evidence Period:
On November 26, 2025, the case officer agreed to open an evidence period, during which the following actions were taken:
Evidence I:
The opening of an evidence period was communicated, and CAIXABANK was required to submit information and documentation, as reflected in the document dated November 26, 2025, which is included in the file. On December 12, 2025, CAIXABANK submitted a written response to the evidence request, accompanied by various documents.
Among the submitted documents is a document entitled (Document 5 - DETAILS OF BREACHES), which contains information on the personal data breach that is the subject of claim 2, as well as similar data breaches that occurred in 2023, and which is attached to the proposed resolution.
Evidence Request II:
Having reviewed the documentation submitted by the respondent, the Spanish Data Protection Agency (AEPD) issued a new evidence request on December 17, 2025, which is included in the file.
On December 23, 2025, CaixaBank submitted a document, prepared as a response to Evidence Request II, accompanied by various documents.
SEVENTH: List of documents included in the proceedings:
A list of documents included in the proceedings is attached as an annex.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 8/59
ESTIMATED FACTS
INDEX OF ESTABLISHED FACTS:
To facilitate the reading of the established facts set forth in the proposed resolution, we indicate that:
• Established facts one through eight refer to the processing of personal data and circumstances related to claim 1.
• Established facts nine through thirteen refer to the processing of personal data and circumstances related to claim 2.
• Established facts fourteen and fifteen refer to the possible recurrence of personal data breaches similar to those related to claims 1 and 2, and to the analysis of the table with information regarding personal data breaches in 2023, provided by CAIXABANK.
• Proven fact sixteen, with information relating to the personal data breach
(…) (***REFERENCE.1).
• Proven fact seventeen, with information relating to the personal data breach
(…) (***REFERENCE.2).
• Proven fact eighteen, with information relating to the personal data breach
(…) (***REFERENCE.3).
• Proven fact nineteen, regarding the training provided in 2024 to the CAIXABANK Customer Service Department staff on personal data protection.
• Proven facts twentieth through twenty-second contain information
relating to the organization of the Customer Service Department of ***COMPANY.1, including references to
(…).
• From the twenty-third to the twenty-ninth proven fact, with information
relating to the characteristics of the operation of the Customer Service Department of ***COMPANY.1,
(…).
• The thirtieth and thirty-first proven facts contain information
relating to audits of the Customer Service Department of ***COMPANY.1.
• The thirty-second and thirty-third proven facts, documents with
information on the operation of the Customer Service Department.
• From the thirty-fourth to the thirty-sixth proven fact, regarding instructions for
the handling of complaints in the Customer Service Department.
• The thirty-seventh proven fact relating to the exercise of the right of access at
CAIXABANK, if the request to exercise rights is made through the
Customer Service Department.
FIRST:
On ***DATE.1 (…) the CAIXABANK Customer Service Department sent A.A.A. (Complainant 1) from the email address (***EMAIL.1) an email with the subject
“***TITLE.1” attached to the response to the complaint with reference number
***REFERENCE.4.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 9/59
The email included two attachments named ***ATTACHMENT.1 and
***ATTACHMENT.2.
The attached document ***ATTACHMENT.1 is a letter on CAIXABANK letterhead
dated ***DATE.2 addressed to B.B.B. (…) and contains the reference number ***REFERENCE.5, which does not correspond to the number shown in the title of the PDF document, ***REFERENCE.4.
(…) responds to the complaint regarding the interest rate applied in the deferred payment credit card contract.
The document includes the full name and surname of Complainant 1, as well as their National Identity Document (DNI) number.
The attached document ***ATTACHMENT.2 is a letter on CAIXABANK letterhead, dated ***DATE.1, addressed to Complainant 1.
It responds to a claim with reference number ***REFERENCE.4. In this instance, there is a match between the reference number of the claim and the title number of the PDF document.
The letter rejects the claim, as the
claims presented were addressed on ***DATE.2. Both documents conclude by stating that, in case of disagreement with the decision, a complaint may be filed with the Bank of Spain's Complaints Service.
SECOND:
On ***DATE.1 at (…) the claimant sent a reply email to the CAIXABANK Customer Service Department (***EMAIL.1) with the following text:
“Good morning,
I have no idea who this B.B.B. is, nor am I aware of having
filed any complaint regarding the interest rate on my credit card.
(…)
I'm afraid you owe me an explanation.
YYYY.”
That same day, claimant 1 sent another email to the CAIXABANK Customer Service Department (***EMAIL.1) at (…) with the following text:
“Good morning,
I demand that you immediately send me a copy of the complaint with number
REFERENCE.4, which, according to you, I filed with that department, and
I want to know who this B.B.B. is that you are referring to. I am sending my
contact information to you.
YYYY.”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 10/59
On July 6, 2023, at (…) claimant 1 sent a new email to the CAIXABANK Customer Service Department (***EMAIL.1) with the following text:
“Good morning,
Extension of your request for information.
From this moment on, I have placed this matter in the hands of my lawyer and I reserve the right to take any legal action that may be
appropriate to me.
A.A.A.”
The file contains a letter dated July 6, 2023, sent by
Claimant 1 to the CaixaBank Customer Service Department, stating the following:
“I am referring to the email I received yesterday, ***DATE.1, regarding a complaint
filed with that department, which includes my name, surname, and
ID number, as well as the name B.B.B.
I wish to state that I did not file the complaint you are referring to, either personally or through
a third party.
Therefore, I demand an explanation from your institution as to why
my personal data appears in the complaint and how
my personal data has been processed.
Documents attached via email:
Copy of ID
Form for exercising the right of access (Spanish Data Protection Agency)
Copies of the two letters sent by CaixaBank Customer Service.
A.A.A..”
Likewise, there is a record of an exercise of the right of access addressed to CAIXABANK on that
same date (July 6, 2023), a form for exercising the right prepared by the
Spanish Data Protection Agency (AEPD), as well as a copy of the front and back of the ID card of claimant 1.
THIRD:
On July 7, 2023 (…) the CAIXABANK Customer Service Department (***EMAIL.1) sent a new email to claimant 1 entitled ***TITLE.2, attaching a response to the
claim with reference number ***REFERENCE.6. The email
includes an attachment named “***REFERENCE.6.pdf”
This attachment is a letter on CAIXABANK letterhead dated July 7, 2023, addressed to Complainant 1 (the text includes Complainant 1's full name and both surnames). The document is signed by the Head of Customer Service.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 11/59
• It refers to the complaint regarding the response letters received
about a credit card contract with deferred payment.
• CAIXABANK apologizes and regrets that the service did not meet expectations, as well as any inconvenience caused.
• It concludes by indicating the possibility of filing a complaint with the Bank of Spain's Complaints Service.
FOURTH:
Claimant 1 receives a new letter from CAIXABANK's Customer Service Department dated July 11, 2023, which has been assigned complaint number ***REFERENCE.7, in which
CAIXABANK (…).
The following handwritten notes made by Claimant 1 appear on said letter:
“NEW RESPONSE, THEY STILL HAVEN'T CLARIFIED ANYTHING.”
“THEY SAY NOTHING ABOUT THE USE OF MY PERSONAL DATA.”
FIFTH:
On July 19, 2023, A.A.A. (Complainant 1) filed a complaint with the Spanish Data Protection Agency (AEPD) regarding
a possible infringement attributable to CaixaBank.
In the section describing the events, it states:
“On ***DATE.1, I received via email from Caixabank's Customer Service Department a copy of a complaint I filed on ***DATE.2 and its
corresponding resolution, dated ***DATE.1. According to the email, it was
addressed to B.B.B.
I wish to state that I neither filed the complaint they refer to
nor do I know B.B.B., who, as I have been able to verify online, appears to be
a lawyer based in ***CITY.1 with a firm specializing
in banking complaints.
On July 6th, I requested that Caixabank send me a copy of the alleged
complaint filed by me, and more importantly, information regarding the use of my personal data by
third parties.
On July 7th, I received a written response via email, which did not address
any of my requests, especially the second one, which is the one that concerns me most.
This is a matter of concern and, in my opinion, falls squarely within their remit.”
Along with the complaint, Complainant 1 submits the documents referenced in the first four findings of fact.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 12/59
In response to the complaint and request for information sent to CAIXABANK by the Spanish Data Protection Agency (AEPD), the respondent submitted a document dated November 10, 2023, in which:
CAIXABANK refers to the response contained in the document dated July 11, 2023, which they attached, and whose content is reflected in the fourth finding of fact.
They further stated:
“We wish to inform this Agency that, given the situation that has occurred, the Customer Service Department has initiated a review of the system for sending responses to customer complaints, in order to prevent and avoid the incident that is the subject of this complaint.” (emphasis added by CAIXABANK)
Regarding the exercise of the right of access by complainant 1, they indicate that they have verified that the right of access was not included in the response dated July 11, 2023, from the Customer Service Department. Attached is a response to the exercise of the right of access, dated November 9, 2023, addressed to claimant 1.
SIXTH:
Regarding claim 1, the preliminary investigation report dated February 28, 2025, based on information provided by CAIXABANK in response to various information requests, indicates the following:
• On ***DATE.2, two claims were registered in CAIXABANK's Customer Service Department (SAC)
(REFERENCE.8, (…) by claimant 1 and REFERENCE.5,
filed by a third party). Both claims were mistakenly associated with claimant 1.
• The manager responsible for registering the second claim in CAIXABANK's systems (…)
• The error was not detected, and the manager completed the registration (…)
On ***DATE.1, CAIXABANK's Customer Service Department sent the Claimant 1's response to claim ***REFERENCE 5.
The preliminary investigation report states:
“The respondent states regarding the origin of this incident that on [DATE 2], claims [REFERENCE 8], associated with the claimant, and claim [REFERENCE 5], to which their contact information was mistakenly assigned, were registered. The reason for this is that in this second claim, the case manager entered the contact information incorrectly, associating the claim with the respondent. According to statements: “The manager responsible for registering the claim in the Entity's systems mistakenly linked this new claim to the immediately preceding claim.”
The processing of claim [REFERENCE 5] continued, thus mixing data from one claim with another: “The manager who registered the claim did not notice this error and completed the registration process.”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 13/59
adding (…) the following data pertaining to the complaint:
***REFERENCE.5: Data of the representative appearing in the complaint
***REFERENCE.5: B.B.B.”
The Customer Service Department (SAC) sends the response to complaint ***REFERENCE.5 on ***DATE.1,
addressing it to the complainant, as their contact information is included, and
other data specific to the complaint is also included, such as the name of the
representative.”
SEVENTH:
CAIXABANK indicates that the personal data breach was caused by human error
on the part of the manager who processed the registration of the complaint.
• Regarding the assessment of the impact of said personal data breach, the
respondent states that “The only person affected by the incident is a person
named B.B.B.”
• CAIXABANK considers that the personal data breach did not have any
impact on claimant 1.
In this regard, the preliminary investigation report is partially reproduced below:
“The respondent’s assessment of the incident is as follows:
The origin of the incident, according to them, is: “Human error by the manager who processes
the registration and filing of the claim.” The respondent’s assessment of the impact is:
“The only person affected by the incident is a person named
B.B.B.” Additionally, the respondent states that this incident did not
have any impact on the claimant: “A response was sent from the Customer Service Department
regarding a claim (claim number
REFERENCE.9) which, although not filed by A.A.A., was answered in based on a
card contract in their name, a fact that does not affect
A.A.A.'s data in any way.”
Likewise, the letter from CAIXABANK dated August 2, 2024, prepared
in response to a request for information from the SGID, is reproduced, indicating that in the
personal data breach linked to claim 1 there was only one affected party
(B.B.B.):
“1.4. Total number of affected parties for each incident. Information regarding
communication made to the other affected parties, if any (provide
a copy of the communication sent and the submission procedure).
(…)
During the preliminary investigation, in response to a
information request issued by the Sub-Directorate General for
Data Inspection (SGID), CAIXABANK, in its letter of February 3, 2024,
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 14/59
pages 13 and 14, provided a copy of the letter it sent to B.B.B. (representative
of another CAIXABANK client), revealing the complainant's name and surname
and ID number to said person. The content of said letter coincides with the letter dated
***DATE.2, to which the first proven fact refers.
The file does not show that CAIXABANK notified complainant 1 of this
circumstance.
EIGHTH:
The personal data breach was detected by CAIXABANK as a result of
a new complaint filed with the bank by Complainant 1 on
***DATE.1.
Regarding the measures taken by the defendant to resolve the case,
the Customer Service Department responded to Complainant 1 on July 7 (proven fact
third) and July 11 (proven fact four).
This is reflected in the preliminary investigation report:
“The error was detected, as indicated by the respondent, following the filing of a new complaint on ***DATE.1 by the claimant.
(Detection: 05/07/2023 (…) A.A.A. submitted a complaint to the Customer Service Department indicating that they had received a response to a complaint they did not file and that was addressed to a third party (B.B.B.).). No proactive action to detect the error is noted.
The measures taken to resolve the case, as stated by the respondent, were: “The Customer Service Department responded to A.A.A. on July 7 and July 11, apologizing for the error made in the complaint registration process.” However, as detailed in section 4.2 of this report, the respondent has implemented general measures regarding this type of communication with customers.
(…)
(…)
For its part, CAIXABANK, in its letter of August 2, 2024, prepared in response to a request for information from the SGID; Regarding the actions taken to minimize adverse effects, it is noted: “since the response letter included the name and surname of a third party (B.B.B.), (…).
Having assessed the impact on the rights and freedoms of the third party (the improbability of it entailing a high risk to their rights and freedoms), the interested party was not notified.
NINTH:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 15/59
Complainant 2 receives a letter on CAIXABANK letterhead dated October 6, 2023, addressed to them, with the claim reference number ***REFERENCE.10.
At the top of the letter are the name and surname of Complainant 2 (C.C.C.)
as well as their email address: ***EMAIL.2).
The letter CAIXABANK responds to a complaint regarding the delay and alleged negligence of the person responsible for processing a ***APPLICATION.1.
The respondent apologizes for any inconvenience and indicates that the account manager for claimant 2 has informed them that they contacted the claimant to apologize for the delay and request the final documentation required to process their application.
CAIXABANK states that it has verified that on October 5, 2023, claimant 2 submitted the documents requested by the account manager in the last communication sent by the manager, and adds that they have instructed the manager to review them as soon as possible.
They inform that, once confirmation is received that the submitted documentation is complete, the application will be formalized, and the legally stipulated timeframe for issuing a decision will begin.
The letter concludes by indicating that, in case of disagreement with The decision,
can be appealed to the Bank of Spain's Complaints Service.
Along with this document, the complainant is sent two documents:
The first is a letter on CAIXABANK letterhead dated October 3, 2023, related to the complaint with reference number ***REFERENCE.11 (which does not match the reference number assigned to the previous document ***REFERENCE.10, which it accompanies).
In the upper left corner of the letter is the full name of a third party, Mr./Ms. D.D., and their email address (***EMAIL.3).
The letter contains the response to a complaint received by CAIXABANK's Customer Service Department on October 2, 2023, regarding disagreement with the fees charged for opening an overdraft and overdraft interest.
The section entitled "Resolution of the Complaint" is reproduced below:
"(...)"
Therefore, the text The document reflects an overdraft situation related to another client.
(D.D.D.) It indicates the amount for opening the overdraft and the overdraft interest applied by CAIXABANK to said client, as well as the first eight digits and the last four digits of said client's bank account (CAIXABANK code and the last four digits of the client's bank account).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 16/59
The second attached document is ***DOCUMENT.1 from CAIXABANK, prepared for the signature of another CAIXABANK client (E.E.E.).
In this case, there is no claim reference number, as it is a form that must be signed by the client to whom it is sent.
The document indicates, in duplicate, the name and surname of the CAIXABANK client (E.E.E.), their tax identification number (NIF), the town/city (***LOCATION.2), and the date. signature (***DATE.3) and the
office ((...)).
The document reflects that ***DOCUMENT.1 consists of a set of measures
for the protection of mortgage debtors without resources.
Below are three sections that appear in said Code:
“(…)”
TENTH:
On October 16, 2023, C.C.C. (claimant 2) filed a complaint with the Spanish Data Protection Agency (AEPD)
for a possible infringement attributable to CAIXABANK.
In the section describing the facts, it states:
“I handed over my own documents, which they lost, and they sent me
private documents from another client, whose name I don't know, with a name, surname,
(…) and email address, explaining that this gentleman owed money and that they were waiving the
fees. They also sent me the completed document (…) in the name of
another person. Regarding my documentation, they've lost it, they've requested it
several times, they've caused it to expire, and I have to pay again to
obtain it. There's no security whatsoever for the information and no privacy... I shouldn't
have to know other clients' information and have mine lost.
Absolute chaos.”
That same day at (…) CAIXABANK notified several employees, including F.F.F. (…), of the personal data breach via email.
(…)
ELEVENTH:
In CAIXABANK's letter dated February 13, 2024, prepared in response to the complaint and request for information from the Spanish Data Protection Agency (AEPD), the respondent states, among other things, the following:
1. No documentation belonging to the complainant has been lost. 2. Their request has been processed and accepted.
2. Complainant 2 initiated the procedures for the request (…) ***DOCUMENT.1.
For its processing, Complainant 2 had to provide a series of documents.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 17/59
Complainant 2 filed two complaints with the Customer Service Department of CAIXABANK:
1. Due to their dissatisfaction and displeasure with the timelines and procedures
followed in processing their request by the account manager.
2. Requesting a response to the previous complaint, as well as a request
for a refund of the service fees applied for
outstanding balances and overdrafts.
The CAIXABANK Customer Service Department responded to the first complaint, but due to a
specific human error within the CAIXABANK Customer Service Department, the response sent to claimant 2 was intended for another customer.
Furthermore, the account manager requested claimant 2 to sign an information document
regarding CAIXABANK's adherence to
***DOCUMENT.1. Due to an error, the completed information document was sent to the claimant
in the name of a third party. Upon discovering the error, the account manager
contacted the claimant, apologized, and provided the
document completed with their information.
The following documentation is attached: The following documents:
• Document from (…) in the name of Claimant 2, dated ***DATE.4, unsigned.
• Response letter to Claimant 2's claim, dated October 6, 2023, the content of which coincides with that reflected in the ninth finding of fact.
• Letter on CAIXABANK letterhead, dated October 6, 2023, drafted (…) in response to a claim filed by Claimant 2, requesting a response to a previous claim and the refund of the service charges applied for outstanding balances and overdrafts.
The preliminary investigation report indicates the origin of the personal data breach:
“The respondent states the following regarding the origin of this incident: on October 2, claim ***REFERENCE.10 was registered by the claimant.” On October 4th, a response was sent to that claim,
attaching the response to another claim,
***REFERENCE.11. According to statements: “the response to claim ***REFERENCE.11 (made by D.D.D.) was sent to the email address
***EMAIL.2, attaching, due to an error by the specialized manager in charge of
resolving the claim and sending the appropriate response.”
This response was made by D.D.D. Furthermore, another document was also sent to the third party,
E.E.E., the respondent states: “Within the framework of the processing of the application
(…) ***DOCUMENT.1) and in order to continue with its processing, the
office manager (from the CaixaBank branch) assigned to the matter requested the complainant to
sign an information document regarding CaixaBank's adherence to ***DOCUMENT.1. Due to a mistake on the part of the
office manager, she sent the complainant (C.C.C.) said information document
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 18/59
completed in the name of a third party (E.E.E.) instead of providing the
completed document in their name.”
CAIXABANK identifies the cause of the personal data breach as human error on the part of the
specialized manager responsible for resolving the complaint and sending the corresponding
response, as reflected in the preliminary investigation report:
TWELFTH:
In response to a request for information from the SGID, CAIXABANK indicated
that the only person affected by the personal data breach related to complaint 2
was D.D.D.
The preliminary investigation report reproduces the response provided
by CAIXABANK, in response to the request for information from the
SGID regarding the existence of a single individual affected by the personal data breach, and
reflects the contradiction between this information and the fact that
claimant 2 also received DOCUMENT 1 in the name of a third party (EEA).
First, the letter from CAIXABANK dated August 2, 2024, is partially reproduced below:
“1.4. Total number of people affected by each incident. Information regarding any communication made to the other affected parties, if applicable (provide a copy of the communication sent and the submission procedure).
(…)”
Likewise, the report on preliminary investigative actions is partially reproduced below:
“(…) The assessment of the impact by the respondent is: “The only person affected by the incident is a CaixaBank customer, Mr./Ms. D.D.” These statements would contradict the receipt of the best practices document in the name of a third party.” (emphasis added).
In a subsequent request dated September 2, 2024, the SGID issued a new request for information to clarify the facts:
“5. Information regarding claims ***REFERENCE.10 and
***REFERENCE.12 addressed to C.C.C. and the relationship between the different
claims related to this incident. Their relationship to document
“***DOCUMENT.1”, addressed to E.E.E. and erroneously sent to the claimant.
Any communications that have been maintained with this person regarding this event.
Please indicate dates.”
The letter from CAIXABANK dated October 7, 2024, prepared in response to said
request for information, states:
“(…)”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 19/59
Therefore, despite CAIXABANK's response in its letter of August 2, 2024, in the case of the personal data breach that gave rise to claim 2,
there was not a single person affected by the personal data breach (D.D.D.). This breach
of personal data also affected (E.E.E.), whose personal data
was included in the ***DOCUMENT.1 prepared for signature, which was mistakenly sent to
claimant 2.
THIRTEENTH:
Regarding the detection of the personal data breach, the preliminary investigation report indicates that CAIXABANK detected the breach as a result of the claimant's notification on October 4, 2023:
“The detection occurred, as indicated by the respondent, following the notification
by the claimant itself (Detection: 10/04/2023 (…) C.C.C., sends an email
from their email address ***EMAIL.2 indicating that they have received
a response that was not theirs). No proactive action
to detect the error is noted.”
Regarding the measures taken to resolve the case, the preliminary investigation report states that (...):
“The measures taken to resolve the case, as stated by the defendant, were aimed at eliminating the documentation of other clients sent in error: (...)”.
FOURTEENTH:
In response to a request for information from the SGID, CAIXABANK has indicated that it has no record of any case analogous to the one that gave rise to claim 1.
The existence of personal data breaches analogous to that of claim 2 has been verified in 2022, 2023, and 2024: sending a response to a claim
filed with the Customer Service Department to the wrong recipient.
The following table reflects the data provided in CAIXABANK's submissions regarding this matter during the preliminary investigation.
Data Breaches
Claims
Year
Similar personal data breaches handled by The Customer Service Center (SAC)
2022 (…) (…)
2023 (…) (…)
2024 (…) (…)
The preliminary investigation report highlights the growing volume of
personal data breaches, proportionally greater than the growing volume of
complaints processed:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 20/59
- Year 2022: 1 case for every (…) complaints.
- Year 2023: 1 case for every (…) complaints.
- Year 2024: 1 case for every (…) complaints
The relevant section of the preliminary investigation report that refers to this recurrence is reproduced below:
“(…)”
CAIXABANK indicated that personal data breaches similar to the one that gave rise to
complaint 2 (sending a response to a Complaints filed with the Customer Service Department (SAC) to the wrong recipient were detected through one of these three channels:
(…)
This is reflected in CAIXABANK's letter of October 7, prepared in response to a request for information from the SGID:
“(…).
FIFTEENTH:
Incorporate into the established facts the content of the table relating to the personal data breach that gave rise to complaint 2 (sending a response to a complaint filed with the SAC to the wrong recipient) and other similar data breaches that occurred in 2023, which is attached to the proposed resolution.
This table includes information on the following aspects:
• Date on which the personal data breach occurred.
• Personal data disclosed.
• Identification of the affected party.
• Cause of the personal data breach.
• How the breach was detected
• Date of notification to the affected party (if applicable)
• Date of notification to the DPO.
The examination of the data contained in this table reflects the following:
In (…) cases, the personal data breaches were detected by personnel who
provided services to CAIXABANK:
• (…) detections by the Customer Service Manager.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 21/59
• (…) detections by internal audits
In the remaining (…) cases, the personal data breaches were detected by
individuals outside of CAIXABANK:
• (…) detection by the Bank of Spain upon receiving the documentation.
• (…) detection by the Catalan Consumer Agency upon receiving the documentation.
• (…) individuals who receive documentation containing personal data of third parties.
Detection of personal data breaches by individuals outside of CAIXABANK represents
(...)% of the total.
CAIXABANK detected personal data breaches on its own in
(...)% of cases.
(…)
SIXTEENTH:
The personal data breach (…) (***REFERENCE 1) occurred because the Customer Service representative who prepared the response made a mistake when attaching (…) the documents to the letter.
Instead of sending the mortgage loan agreement, requested by a CAIXABANK client, they attached a mortgage payment and cancellation letter, which encumbered the property of two other individuals.
CAIXABANK detected the personal data breach on November 17, 2023, upon
receiving an email at (***EMAIL.1) from H.H.H., the lawyer for J.J.J. (a CAIXABANK client who received documentation containing third-party personal data).
Personal data disclosed:
The following personal data appears in the deed of payment and loan cancellation:
The names and surnames of L.L.L. and M.M.M., their national identity document numbers (DNI), nationality, marital status, professions, address, and IBAN (a photocopy of a bank check made out to the name of the bank, used to pay the mortgage loan, is attached).
Regarding the bank representative, N.N.N., their name and surnames and their national identity document number (DNI) are included.
The names and surnames of four notaries are also listed, as well as the address,
telephone number, and fax number of one of them:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 22/59
Furthermore, it should be noted that the notarial deed indicates both the total amount and the breakdown of the debt (principal, ordinary interest, and late payment interest on the mortgage loan), as well as extensive information about the mortgaged property.
SEVENTEENTH:
The personal data breach (…) (***REFERENCE 2) occurred because the Customer Service Representative, when responding to a customer complaint (O.O.O.), mistakenly attached a
loan agreement belonging to another CAIXABANK customer (P.P.P.).
The document sent in error is a loan application and contains the following personal information of P.P.P.:
Name and surname, ID number, nationality, address, marital status, date of birth,
telephone number, occupation, employer, and handwritten signature.
The document also includes details of a vehicle owned by P.P.P., her length of service at her company, the year her home was built, and that the home is mortgaged, as well as all the terms and conditions of the loan that has been granted.
EIGHTEENTH:
The personal data breach (…) (***REFERENCE.3) occurred because, when
responding to a complaint from a CAIXABANK customer (Q.Q.Q.), the Customer Service Manager
of ***COMPANY.1 mistakenly attached a document with a response intended
for another customer (R.R.R.).
CAIXABANK detected the personal data breach upon receiving an email from Q.Q.Q. on
April 28, 2023, stating:
“It seems to me that you are cross-referencing and changing email addresses; this is not
mine.
Regards, Q.Q.Q.”
The document mistakenly sent to Q.Q.Q. on April 11, 2023, contains the following personal data of R.R.R. Name and surname, address, email address, reference number of the claim filed with CAIXABANK, and the mortgage loan number without the asterisk.
NINETEENTH:
On February 26, 2024, CAIXABANK provided training to staff (…) at the Customer Service Department (SAC) on personal data breaches and the rights that data subjects can exercise regarding the protection of personal data.
This training covers the following topics:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 23/59
(…)
TWENTIETH:
(…)
This is reflected in the report of (…).
(…)
TWENTY-FIRST:
(…)
TWENTY-SECOND:
(…)
TWENTY-THIRD:
(…)
TWENTY-FOURTH:
(…)
The preliminary investigation report also highlights that the processes for
registering, recording, and responding to complaints submitted to CAIXABANK's Customer Service Department
were (…),
2. When registering a complaint and assigning it to a customer in the Customer Service Department of
***COMPANY.1:
(…)
Information available in CAIXABANK's document dated August 2, 2024.
TWENTY-FIFTH:
(…)
Information available in CAIXABANK's document dated August 2, 2024.
TWENTY-SIXTH:
Subsequent to the processing of personal data related to the
complaints 1 and 2. CAIXABANK introduced the following changes to its claims management system:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 24/59
The reference to these measures, as they appear in the
preliminary investigation report, is shown below:
“(…)
This information also appears in documents from CAIXABANK dated August 2 and October 7, 2024, prepared in response to information requests from the
SGID.
(…)
TWENTY-SEVENTH:
(…)
TWENTY-EIGHTH:
(…)
TWENTY-NINTH:
(…)
THIRTIETH:
1. CAIXABANK carried out two audits of the Customer Service Center on ***DATE.5 and ***DATE.6 from
***COMPANY.1, which has submitted its statement of objections to the initial agreement.
Having examined the content of the audit report dated ***DATE.5, it is verified that the conclusions state:
“(…)”
The conclusions section of the audit report dated ***DATE.6 states:
“(…)”
The perspective from which these audits were conducted is primarily banking-related.
The audit reports frequently refer to the Bank of Spain (BdE), the BdE Guide, Order ECO/734/2004, and Order ECO. Other supervisory bodies (CNMV and the Directorate General of Insurance and Pension Funds) are also mentioned.
The terms “data protection,” “data subject,” and “personal data breach” do not appear in these reports. Neither of the distribution lists for these audit reports includes the CAIXABANK DPO.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 25/59
(…)
Letter from CAIXABANK dated December 12, 2025, prepared as evidence:
“(…)”
The respondent has submitted a certificate dated December 11, 2025, from
***POST.1, which states:
(…)
THIRTY-FIRST:
(…)
THIRTY-SECOND:
In response to a request for information from the SGID, on August 2, 2024,
CAIXABANK submitted to the AEPD the rules, policies, and procedures that govern the
operation of CAIXABANK's Customer Service Department.
This is reflected in the statement of objections to the initial agreement:
(…)
The aforementioned documents are:
(…)
THIRTY-THIRD:
(…)
THIRTY-FOURTH:
(…)
THIRTY-FIFTH:
(…)
THIRTY-SIXTH:
(…)
THIRTY-SEVENTH:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 26/59
(…)
LEGAL BASIS
I. Jurisdiction
In accordance with the powers conferred upon each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR) and as established in Articles 47, 48.1, 64.2 and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (GDPR), Personal Data Protection and
Guarantee of Digital Rights (hereinafter, LOPDGDD), the Presidency of the Spanish Data Protection Agency is competent to resolve this procedure.
Likewise, Article 63.2 of the LOPDGDD establishes that: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of
Regulation (EU) 2016/679, this Organic Law, the implementing regulations issued thereunder, and, insofar as they do not contradict them, subsidiarily, by the general rules on administrative procedures."
II. Preliminary Issues
Article 4.1 of the GDPR defines "personal data" as: "any information relating to an identified or identifiable natural person ("data subject"); A natural person is considered to be:
An identifiable natural person is any person whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
Article 4.2 of the GDPR defines "processing" as: "any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction."
Article 4.7 of the GDPR defines the “controller” as: “the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of processing are determined by Union or Member State law, the controller or the specific criteria for its appointment may be laid down by Union or Member State law.”
Article 4.12 of the GDPR defines a “personal data breach” as: “any breach of security leading to the accidental or unlawful destruction, loss or alteration of personal data transmitted, stored or otherwise processed; or to the unauthorized disclosure of, or access to, personal data.”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 27/59
In this case, in accordance with Articles 4.1 and 4.2 of the GDPR,
the processing of personal data is established, since
CAIXABANK carries out, among other processing activities: the collection, recording, organization,
structuring, storage, modification, retrieval, consultation, use, and
communication by transmission of personal data of natural persons, for example:
name and surname, national identity document (DNI), date of birth,
email address, mobile phone number, IBAN, etc.
CAIXABANK carries out this activity in its capacity as data controller,
since it is the one that determines the purposes and means of such activity, pursuant to Article
4.7 of the GDPR.
III Response to the allegations made regarding the initiation agreement
1. ALLEGATIONS RELATING TO THE CONTEXT IN WHICH THE THEY CARRY OUT THE
PROCESSING OF PERSONAL DATA AFFECTED BY THE PERSONAL DATA BREACHES
PERSONAL DATA
CAIXABANK is a banking entity, and as such, it must comply with the obligations
stipulated in banking regulations, and its activity is subject to the supervision of the
Bank of Spain. Therefore, it must take into account the criteria established by said
supervisor and the content of the “Guide on the criteria for the organization and
operation of customer service departments of entities supervised
by the Bank of Spain” of July 19, 2021.
However, the daily activity carried out by CAIXABANK is not simply a
banking activity. The defendant, as the data controller, carries out a significant volume of personal data processing of
data subjects (customers or other natural persons whose personal data is processed by
the same) on a daily basis. With regard to said personal data processing,
CAIXABANK must comply with current data protection regulations. of personal data.
It is important to remember that personal data protection regulations are cross-cutting in nature and must be respected by all data controllers, regardless of whether they are banks, insurance companies, hospitals, courier companies, etc.
These companies must comply with the obligations arising from their sector-specific regulations, bearing in mind that if they process personal data and act as data controllers, they must also guarantee full compliance with the provisions of the GDPR and the LOPDGDD (Spanish Data Protection Law).
Personal data protection regulations focus on the processing of personal data carried out with the ultimate goal of guaranteeing full respect for the rights and freedoms of data subjects.
Therefore, in accordance with personal data protection regulations, the
data subject is at the center of the process, making it necessary to analyze the potential
impact that the processing, whether planned or ongoing, has
on the rights and freedoms of said data subject.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 28/59
Banking regulations address their own purposes, specific to the banking sector, which do not coincide with the purposes of personal data protection regulations. Therefore, the fact that a
banking entity, such as CAIXABANK, complies with and respects banking regulations does not
necessarily or automatically imply compliance with the GDPR or the LOPDGDD.
The Bank of Spain's supervisory role is aimed at verifying CAIXABANK's compliance with banking regulations, not with regulations concerning the protection of personal data, which falls under the jurisdiction of the Spanish Data Protection Agency (AEPD).
Based on the regulations set forth in the GDPR and the Spanish Data Protection Act (LOPDGDD), if an activity involving the daily processing of a significant volume of personal data, such as the Customer Service Department (SAC) of ***COMPANY.1 when handling complaints, is "clearly exposed to human error," as CAIXABANK states in its arguments, errors with clear implications for data protection that affect the rights and freedoms of data subjects, this circumstance is not inevitable or acceptable as a starting point.
Rather, it is necessary to take action. These human errors,
if they occur, will have a negative impact, affecting the rights
and freedoms of the data subjects, which is what current regulations on
personal data protection seek to prevent.
Furthermore, the fact that CAIXABANK's Customer Service Department (SAC) prepares an annual
report on its activities for the Board of Directors of
CAIXABANK is a way of informing the Board about the SAC's operation
although, in principle, it does not demonstrate compliance with regulations on
personal data protection.
Regarding internal audits, along with its statement of objections to the agreement to initiate
the audit, CAIXABANK has submitted two audit reports related to the SAC (…).
During the evidentiary phase, the audit report related to the SAC for the year 2025 was requested. (…).
Before addressing the remaining allegations made by
CAIXABANK, it should be noted that, in this case, having reviewed the allegations against the
initiation agreement made by CAIXABANK, and having examined the documentation contained
in the file following the evidentiary phase, it is clear that, in this particular case,
the absence of a series of data protection measures by design
and, occasionally, by default, has meant that the
principle of confidentiality has not been effectively applied.
The lack of measures under Article 25 of the GDPR has also affected the application
of other principles set out in Article 5 of the GDPR, such as the principle of
data minimization (Article 5.1 c) and the principle of accuracy (Article 5.1 d).
... Therefore, in the specific case examined, it is the provision contemplated in Article 25 of the GDPR that fully fits the typical conduct due to its specific nature,
and therefore, the dismissal of the case under Article 5.1(f) of the GDPR is proposed.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 29/59
Therefore, the allegations regarding Article 25 and 5.1 f) are addressed jointly.
2. ARTICLES 25 and 5.1 f) of the GDPR
1. Response to the allegations regarding the alleged lack of specificity in the
initiation agreement when imputing a violation of Article 25 of the GDPR:
Regarding CAIXABANK's allegation that, in the initiation agreement, the
alleged infringement of Article 25 of the GDPR is not sufficiently specific to
be considered to meet the minimum requirements set forth in Article 64.2
of the LAPCAP, it should be noted that paragraph 2(b) of said article states:
“(b) The facts that give rise to the initiation of the proceedings, their possible
classification and the corresponding sanctions, without prejudice to what
results from the investigation.” (emphasis added).
That is, when the initial agreement is issued, the classification and the determination of the
possible sanctions that may apply will be made according to the information
available at that time.
In this case, a period for gathering evidence has been opened, during which
two requests for information have been made to the respondent. The versions of
some documents sent by CAIXBANK to the Spanish Data Protection Agency (AEPD) during the preliminary
investigation proceedings corresponded to versions submitted after
the events occurred, making it necessary to request a new version of
the same.
Furthermore, CAIXABANK, in its statement of objections, points out:
“(57) The lack of clarity mentioned in the previous point is evident
when the Spanish Data Protection Agency (AEPD) identifies the “data protection by design and by default” obligation as the one that has not been fulfilled, referring in its entirety to an alleged
infringement of Article 25 of the GDPR. We are dealing with two obligations clearly
distinguished by the legislator, even though they are regulated in the same article.
Despite this, considering the grounds on which the
initiation agreement is based, it can be deduced that the AEPD is referring
exclusively to data protection by design, that is, to paragraph 1
of the aforementioned Article 25.”
Firstly, as indicated in the statement of objections to the initiation agreement,
the GDPR has regulated data protection by design and
data protection by default in the same article.
Guidelines 4/2019 of the European Data Protection Board (hereinafter,
EDPB) on Article 25, Data Protection by Design and by Default,
version 2.0, adopted on October 20, 2020, analyze in a single set of guidelines
data protection by design and data protection by default, using
the abbreviation “DPD” to refer to the obligation to protect data
by design and by default.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 30/59
These Guidelines state that “Data protection by design and data protection
by default are two complementary concepts that reinforce each other. Data subjects will benefit more from data protection by default if it is applied together with data protection by design, and vice versa.” (emphasis added).
The relationship between data protection by design and data protection by default (DPO) is also reflected in the content of the Spanish Data Protection Agency (AEPD) Guidelines (Privacy by Design Guide, October 2019 version, and AEPD Guide to Data Protection by Default, October 2020 version).
Data protection by default (DPO) implies the need to determine the minimum data required for each processing operation, regardless of the personal data that is available.
In this regard, EDPB Guidelines 4/2019 state:
“2.2.2.2 ‘the scope of processing’
51. Processing operations applied to personal data shall be limited to what is strictly necessary. Many processing operations can contribute to a processing purpose. However, the fact that certain personal data are necessary for a particular purpose does not imply that all types of processing operations can be applied to such data, nor with any frequency.” (emphasis added).
(…) is a data minimization measure, which can be framed within Article 25.1, as a measure intended to guarantee one of the principles of Article 5 of the GDPR, and which clearly falls within Article 25.2 of the GDPR, which is why the expression “data protection by design and by default” was used in the initial agreement.
In its statement of allegations, CAIXABANK states:
“(59) We understand that the alleged infringement of Article 25.1 refers to the fact
of not having adopted measures to apply the principle set out in Article
5.1.f of the GDPR (“integrity and confidentiality”), the potential infringement of which has already
been attributed to CaixaBank, since it is the only breach of principles
addressed in the initial agreement. Therefore, the Agency would be imposing
two different sanctions for the same act, as we will argue later.”
The EDPB Guidelines 4/2019 state:
“61. To give effective GDPR [data protection by design and by default], controllers must apply the principles of transparency, lawfulness, fairness, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability.”
Having examined the facts related to this case, based on the information
available after the evidence-gathering phase, it cannot be understood that the infringement of
Article 25 of the GDPR only affected the principle of confidentiality
(Article 5.1 f of the GDPR).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 31/59
The principle of data minimization, regulated in Article 5.1(c) of the GDPR, has also been affected, as previously indicated.
Likewise, the principle of accuracy (Article 5.1(d) of the GDPR) has been affected. The facts examined show that in the CAIXABANK system, a legal representative was listed as the representative of Complainant 1, but this representative was actually the representative of a different client. Furthermore, Complainant 1's ID number was linked in the CAIXABANK system to a complaint that had not actually been filed.
In conclusion, it cannot be asserted that Article 25 of the GDPR has been violated solely due to the failure to adequately guarantee the provisions of Article 5.1(f) of the GDPR, given that other principles set forth in Article 5 of the GDPR have also been affected.
Regarding the statement "the mere addition by a data controller of new documents relating to the measures to be implemented with respect to processing, in relation to those initially drawn up, is not privacy by design," which is referenced in the statement of objections to the initial agreement, it is considered that this statement has been misinterpreted by the respondent. However, the content of this legal basis has been summarized by removing the relevant paragraph.
To clarify the potential misinterpretation reflected in the statement of objections to the initial agreement, it is important to note that:
The EDPB Guidelines 4/2019 state:
“(…) Data controllers shall apply data protection by design (DPD) before processing and also continuously during processing, regularly reviewing the effectiveness of the chosen measures and safeguards. DPD also applies to existing systems that process personal data.”
In other words, data protection by design must be applied before processing and continuously throughout the processing, with regular reviews of the effectiveness of the chosen measures and safeguards.
This statement, which the respondent has considered contradictory, reflects one of the fundamental principles of privacy by design, which stipulates that privacy must be incorporated into the design phase.
The Spanish Data Protection Agency's (AEPD) Privacy by Design Guide highlights:
“3. Privacy incorporated in the design phase
Privacy must be an integral and inseparable part of systems,
applications, products, and services, as well as the organization's business practices and
processes. It is not an additional layer or module added to
something pre-existing, but rather must be integrated into the set of non-functional requirements
from the very moment it is conceived and designed” (emphasis added).
This is the idea to which the paragraph mentioned by CAIXABANK refers in its
statement of objections to the initial agreement.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 32/59
2. Relevant aspects relating to the operation of the Customer Service Department of ***COMPANY.1 at the
time the personal data breaches
examined in this case occurred.
The facts examined are related to the processing of personal data
carried out in the Customer Service Department (hereinafter referred to interchangeably as the Customer Service Department, the CAIXABANK Customer Service Department, or the ***COMPANY.1 Customer Service Department). The information available in the file
reflects the following characteristics of the operation of the ***COMPANY.1 Customer Service Department:
(…)
In order to illustrate some design problems related to the processing of
personal data carried out by the ***COMPANY.1 Customer Service Department, two
examples will be examined (the personal data breaches that gave rise to claims 1 and 2).
3. Example 1: Analysis of the processing of personal data related to claim 1 (information from the CAIXABANK letter of August 2, 2024, prepared in response to a request for information from the SGID):
On June 8, 2023, at (…), claim ***REFERENCE.8, submitted by A.A.A., was registered and entered into the Customer Service Department.
On June 8, 2023, at (…) (20 minutes later), claim ***REFERENCE.5, the subject of the personal data breach, was registered and entered into the Customer Service Department.
The Customer Service Department manager responsible for the registration mistakenly (…).
On July 5, 2024, at (…), the Customer Service Department sent the response to complaint ***REFERENCE 13 to the email address of A.A.A.
The response contained explanations regarding the product contracted by
complainant 1 (credit card contract). The name of the
representative (…) appeared in the document: B.B.B.
(…)
Regarding complaint 1, it should also be noted that the exercise of the right of access by complainant 1 in their letter of July 6, 2023, went completely unnoticed (proven facts two and five). This occurred despite the fact that another letter of
the same date indicated that the right of access was being exercised, that it was exercised using a form
prepared by the Spanish Data Protection Agency (AEPD), and that the interested party provided a photocopy of the front and back of
their national identity document (DNI).
The request to exercise the right was detected during the transfer of the complaint by the Spanish Data Protection Agency (AEPD) and was processed on November 9, 2023.
The request to exercise the right was made with several simultaneous petitions. It was a document
with several claims, one of which was the exercise of a right.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 33/59
This situation reflects another deficiency related to the scope of Article 25 of the GDPR.
Measures should be adopted to ensure that requests to exercise
rights do not go unnoticed, as has happened in this case, and that they can be
processed within the established timeframe, which will contribute to ensuring adequate
compliance with regulations by the data controller.
(…)
4. Example 2: Analysis of the processing of personal data related to
Claim 2 (information from CAIXABANK's correspondence of August 2 and February 3, 2025, prepared in response to a
information request from the SGID and the breach notification to
CAIXABANK's DPO dated October 16, 2023):
On October 2, 2023, at (…) the claim
***REFERENCE.10, (…) was registered by C.C.C. (Claimant 2) from their email address ***EMAIL.2).
This claim concerns various issues related to the request made
by Claimant 2 to CAIXABANK (…) ***DOCUMENT.1 (…) (***DOCUMENT.1).
On October 2, 2023, the CAIXABANK Customer Service Department received a letter from D.D.D., which was assigned the number ***REFERENCE.14. Due to an error, the case was identified under the name of claimant 2.
On October 4, 2023, at (…), the response to claim ***REFERENCE.10 was sent to the email address ***EMAIL.2. Due to an error (…)
This letter was also sent to D.D.D.
On October 4, 2023, at (…), claimant 2 sent a message to CAIXABANK from their email address indicating that they had received a response that was not addressed to them (this new letter was registered in the system with the number
***REFERENCE.15).
(…)
(…), the CAIXABANK branch manager asked claimant 2 to sign the
***DOCUMENT.1. Due to a misunderstanding, the claimant was sent the document
prepared for a third party's signature (E.E.E.).
Complete information regarding the facts related to this claim was
obtained after the evidentiary phase. As can be seen, there were three
errors on the part of different individuals providing services to CAIXABANK.
As indicated above, (...).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 34/59
In this case, two different individuals submitted erroneous documentation containing
personal data of two CAIXABANK clients. and EEA.
(…)
(…) the following measures were introduced in the CAIXABANK Customer Service Department:
• (…)
5. Non-compliance with Article 25 of the GDPR:
CAIXABANK, in its statement of objections to the initial agreement, asserts that “the handling of complaints is inextricably linked to the processing of personal data.”
It also points out that “the activities of the Customer Service Center (SAC), which largely depend on the fact that
the people providing the aforementioned service do not make mistakes,” with numerous
references in said document to the risk associated with possible human
errors on the part of the staff working in the SAC.
(…)
6. This case is not limited to the examination of two personal data breaches:
This disciplinary case is not limited to examining two personal data breaches
in which the following information was communicated and unauthorized access was granted
by third parties:
- 4 names and surnames
- 1 national identity card number
- 1 email address
- Some figures related to an overdraft situation.
The situation analyzed is considerably more complex.
As a result of the processing of personal data related to claims 1 and 2,
the SIGD (Data Protection Authority) has carried out preliminary investigative actions,
in which several requests for information were made to the party against whom the complaint was filed.
Furthermore, during the processing of this sanctioning procedure, a period for gathering evidence was opened, during which two letters were sent to CAIXABANK.
In addition to the two personal data breaches related to claims 1 and 2 (proven facts one through thirteen), it has been established that
several personal data breaches similar to claim 2 occurred (proven facts fourteen through eighteen): consisting of sending the response to a complaint
filed with the Customer Service Department to the wrong recipient, revealing personal data of third parties.
According to data provided by CAIXABANK in response to information requests from the SGID (General Directorate of Data Protection), the recurrence of this type of breach would be as follows:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 35/59
Year Data Breaches Similar Personal Complaints
handled by the Customer Service Department
2022 (…) (…)
2023 (…) (…)
2024 (…) (…)
As highlighted in the preliminary investigation report, the volume of personal data breaches is increasing, proportionally greater than the increasing volume of complaints processed in 2023 and 2024:
- Year 2022: 1 case for every (…) complaints.
- Year 2023: 1 case for every (…) complaints.
- Year 2024: 1 case for every (…) claims
7. Problems on the part of CAIXABANK in detecting personal data breaches, with the consequences that such lack of detection implies:
Likewise, as indicated in the preliminary investigation report (proven fact fourteen):
“Furthermore, as the respondent points out, one of the mechanisms for
detecting these events was the communication of the affected individuals themselves, so a larger volume could not be ruled out in that context.”
During the evidentiary phase, CAIXABANK was asked for information on the (…) personal data breaches, similar to the personal data breach that gave rise to claim 2, that occurred in 2023.
Among the information requested were:
• The date on which the personal data breach occurred.
• The date the personal data breach was reported to the CAIXABANK Data Protection Officer (DPO).
Having examined the data corresponding to this sample of personal data breaches (fifteenth proven fact), which includes the personal data breach
that gave rise to complaint 2, as well as other cases in which CAIXABANK also sent the response to a complaint filed with the Customer Service Department to the wrong recipient, disclosing personal data of data subjects, the following is observed:
In these cases, the personal data breaches were detected by staff providing services to CAIXABANK:
• Detections by the Customer Service Department manager.
• (…) detections by internal audits
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 36/59
In the remaining (…) cases, personal data breaches were detected by
individuals outside of CAIXABANK:
• (…) detection by the Bank of Spain upon receiving the documentation.
• (…) detection by the Catalan Consumer Agency upon receiving the documentation.
• (…) individuals receiving documentation containing personal data of third parties.
Detection of personal data breaches by individuals outside of CAIXABANK represents
(…)% of the total.
CAIXABANK detected personal data breaches on its own in
(…)% of the cases. Note that the detection of such personal data breaches by CAIXABANK personnel does not reach (…)% of cases.
As can be seen, the detection of this type of personal data breach by CAIXABANK depends largely on the third party receiving the incorrect documentation, which includes personal data of other interested parties, contacting CAIXABANK and informing them that they have received erroneous documentation that does not belong to them. It is not possible to determine the precise number of personal data breaches that have actually occurred in the Customer Service Department of ***COMPANY.1.
In addition to the above, the examination of the data provided by CAIXABANK reveals another circumstance (fifteenth proven fact). The problem in detecting personal data breaches
translates into delays,
sometimes even months, in reporting the existence of these breaches to the CAIXABANK DPO (…).
Having analyzed the information provided by the complainant, (…)
During this extended period, the affected personal data breaches have gone
unnoticed by the complainant, with the resulting consequences: neither the
DPO (…) is aware of the existence of these personal data breaches,
no one has assessed whether these personal data breaches pose a high risk
to the rights and freedoms of the individuals whose data has been
affected, nor have any measures been taken by the bank, given that
it is unaware of their existence.
There has been a loss of control by the data subjects over their personal data, which has gone unnoticed by the bank where it occurred.
8. Sometimes problems arise in identifying the personal data
affected by personal data breaches:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 37/59
Regarding the affected data, Document 5, BREAK DETAILS (fifteenth proven fact), submitted during the evidence-gathering phase by CAIBANK, in response to the letter of November 26, 2025, includes a column relating to the
personal data disclosed in these (…) personal data breaches.
This column includes, among others: first and last names, national identity document number, gender, marital status,
date of birth, address, email address, telephone number, and
occupation. Financial data is sometimes revealed, for example: loan agreement number, insurance contract number, credit card contract number, guarantee number, loan terms, credit card updates, etc., or the individual's annual income.
Furthermore, when examining some of these personal data breaches, comparing the information provided by CAIXABANK with the documentation submitted by the bank, it has been observed that, on occasion, not all personal data affected by the breach is reflected.
For example, regarding the personal data breach (…) identified by CAIXABANK with reference (***REFERENCE.1), Document 5, BREAKDOWN DETAILS, provided by CAIXABANK, indicates that the following personal data was affected:
“(…).”
In this personal data breach, a deed of payment and loan cancellation was disclosed to a third party, containing the following personal data:
The names and surnames of L.L.L. and M.M.M., their national identity document numbers (DNI), nationality, marital status, professions, address, and IBAN (a photocopy of a nominative bank check used to pay the mortgage is attached).
Regarding the bank representative, N.N.N., their name and surnames and national identity document number (DNI) are included.
The names and surnames of four notaries are also included, as well as the address, telephone number, and fax number of one of them.
Therefore, Document 5 does not contain all the personal data affected by the personal data breach; the following are not mentioned (nationality, marital status, professions, IBAN, address, and contact information of one notary).
Among the omitted personal data, the bank account number (IBAN) is particularly relevant. It appears on a photocopy of a nominative bank check and is not marked with an asterisk.
The same applies to the personal data breach (…), identified by
CAIXABANK with reference (***REFERENCE.1), proven fact seventeen.
Document 5, BREAK DETAILS, provided by CAIBANK, indicates that the following personal data was affected:
“(…).”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 38/59
In this case, the document sent in error was a loan application.
The document contains the following personal information of P.P.P.:
Name and surname, ID number, nationality, address, marital status, date of birth, telephone number, occupation, company where employed, and handwritten signature.
Likewise, the document includes details of a vehicle owned by
P.P.P., her length of service with her company, the year her home was built, and that
the home is mortgaged, as well as all the terms and conditions of the
loan granted to her.
Once again, not all the affected personal data is indicated, with significant omissions such as the interested party's handwritten signature.
The situation described also occurred in relation to claim 2.
The statement of objections to the initial agreement prepared by CAIXABANK analyzes the
personal data affected by the data breach:
(...)
If we examine ***DOCUMENT.1 (...), prepared for signature (proven fact
ninth), it shows, in duplicate, the name and surnames of the
CAIXABANK client (E.E.E.), their tax identification number (NIF), the town (***TOWN.2), and the branch ((...)).
It is of utmost importance to identify all personal data affected by the data breach, both so that CAIXABANK can properly assess whether the breach poses a high risk to the rights and freedoms of the individuals whose personal data was affected, and to prevent subsequent risks (fraud, identity theft, etc.).
9. Sometimes problems arise in identifying the natural persons (data subjects) affected by personal data breaches:
This situation is analyzed below in relation to claims 1 and 2:
Claim 1:
In the SGID's request for information dated June 20, 2024, among the information requested from CAIXABANK regarding the personal data breach that gave rise to claim 1, the following was requested:
“1.4. Total number of data subjects affected by each incident. Information regarding the communication made to the other data subjects, if any (provide a copy of the communication sent and the notification procedure).”
As reflected in the seventh finding of fact, CAIXABANK considered that the only person affected by the personal data breach was B.B.B.
However, following a new request for information from the SGID, CAIXABANK sent a copy of the letter sent to B.B.B., in which personal data of claimant 1 was disclosed to B.B.B., a representative of another CAIXABANK client.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 39/59
Therefore, claimant 1 (A.A.A.) was also affected by the personal data breach, despite not being listed as such in the CAIXABANK letter of August 2, 2024, referenced above.
Claim 2:
In the SGID's information request of June 20, 2024, among the information requested from CAIXABANK regarding the personal data breach,
which gave rise to Claim 2, was the following:
“1.4. Total number of people affected by each incident. Information regarding the communication made to the other affected parties, if any (provide a copy of the communication sent and the transmittal procedure).”
As reflected in the twelfth finding of fact, CAIXABANK responded to said request indicating that the only person affected by the personal data breach was D.D.D.
The aforementioned finding of fact reflects that the preliminary investigation report reveals a contradiction between this statement and the receipt by Claimant 2 of a ***DOCUMENT.1 containing personal data of a
third party (EEA).
Despite what was stated by CAIXABANK in its letter of August 2, 2024, both D.D.D. and E.E.E. were third parties affected by the personal data breach.
During the evidentiary phase, CAIXABANK was asked, in relation to the personal data breach that gave rise to claim 2, to provide documentation that proved the breach had been reported to CAIXABANK's Data Protection Officer (DPO).
The tenth finding of fact reproduces the email of October 16, 2023, provided by CAIXABANK, which shows that claimant 2 was also a data subject affected by the personal data breach.
The previous section highlighted the importance of identifying the personal data affected by personal data breaches. However, it is even more important that the data controller correctly identify each and every data subject affected by such breaches.
The correct identification of those affected by a personal data breach is critical for the data controller to effectively guarantee adequate protection of their personal data.
If the data controller fails to identify a natural person as affected by the personal data breach when they are:
• They will not assess whether the breach poses a high risk to the rights and freedoms of the data subject, nor whether it is appropriate to notify the data subject in accordance with Article 34 of the GDPR.
• They will not take measures to prevent this situation from recurring.
• They will not mitigate any damage that may have occurred as a result of the breach materializing.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 40/59
10. Application of personal data protection measures
by design or by default in order to correct the situations described
in sections 7, 8, and 9:
The situation described in the previous sections reflects other areas where
deficiencies are evident regarding the application of measures contemplated in Article
25 of the GDPR.
It is advisable that CAIXABANK review its system and adopt measures designed
to effectively apply the principle of confidentiality, in order to improve
its ability to detect personal data breaches, identify all
data subjects affected by them, and identify all personal data
disclosed.
11. Training on Personal Data Breaches:
CAIXABANK has provided documentation relating to two training sessions held
on February 26 and June 4, 2024, for staff (…) at the Customer Service Department (SAC), both of which took place
after the personal data processing events that gave rise to
claims 1 and 2.
These training sessions, the content of which is summarized in the nineteenth finding of fact, took place after several of the personal data breaches
examined in this case file.
(…)
12. Response regarding the absence of damages to the data subjects:
The statement of objections to the initial agreement contains numerous references
to the fact that damages have not been proven on the part of those affected by the personal data breaches. The defendant even goes so far as to claim that the data subjects affected by the personal data breaches have not suffered any damages.
First, the fact that CAIXABANK claims to have no record of the
existence of damages does not mean that such damages do not exist or
have not occurred. Furthermore, since the defendant does not have an effective system
for detecting breaches, it cannot know if there are damages if it is unaware
that such breaches are occurring (in most cases, it has
become aware of the breaches through individuals who received
letters addressed to third parties).
Please note that, following the assessment of the personal data breach by the
defendant, it was determined that the breaches associated with claims 1 and 2, as well as
the other (...) breaches, analogous to that of claim 2, detected by
CAIXABANK in 2023, (...).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 41/59
Secondly, it is necessary to clarify that civil damages are not entirely the same as those contemplated in the GDPR:
According to recitals 75 and 85 of the GDPR:
(75) Risks to the rights and freedoms of natural persons, of varying severity and likelihood, may arise from the processing of data that could cause physical, material or non-material damage, in particular where the processing may lead to problems of discrimination, identity theft or fraud, financial losses, damage to reputation, loss of confidentiality of data subject to professional secrecy, unauthorized reversal of pseudonymization or any other significant economic or social harm; where data subjects are deprived of their rights and freedoms or prevented from exercising control over their personal data; in cases where the personal data
processed reveals ethnic or racial origin, political opinions, religion or
philosophical beliefs, trade union membership and the processing of
genetic data, data concerning health or data concerning sex life, or
criminal convictions and offenses or related security measures; in cases where personal aspects are evaluated, in particular the analysis or
prediction of aspects relating to work performance, economic
situation, health, personal preferences or interests, reliability or
behavior, situation or movements, for the purpose of creating or using personal
profiles; in cases where personal data of vulnerable persons, in particular children, are processed; or in cases where the processing
involves a large amount of personal data and affects a large number of
data subjects.
“(85) If appropriate measures are not taken in a timely manner, breaches of personal data security can result in physical, material, or non-material damage to natural persons, including loss of control over their personal data or restriction of their rights, discrimination, identity theft, financial losses, unauthorized reversal of pseudonymization, damage to reputation, loss of confidentiality of data subject to professional secrecy, or any other significant economic or social harm to the natural person concerned. Therefore, as soon as the controller becomes aware of a personal data breach, the controller must, without undue delay and, where feasible, no later than 72 hours after becoming aware of it, notify the competent supervisory authority of the personal data breach, unless the controller can demonstrate, in accordance with the principle of accountability, that the personal data breach is unlikely to result in a risk to the data subjects.” rights and freedoms of natural persons. If
such notification is not possible within 72 hours, it must be accompanied by
an indication of the reasons for the delay, and information may be provided in
stages without undue delay.” (emphasis added).
The Court of Justice of the European Union (CJEU), in its judgment of 4 September 2025 in Case C-655/23, highlights a broad concept of damages for data subjects and has determined that the mere loss of control over their own personal data by data subjects as a consequence of a GDPR infringement, even if there has not been a specific misuse of the data in question, may be sufficient to cause non-material damages.
59 Second, as the European Commission has pointed out in its written observations, situations such as those invoked in the main proceedings, relating to "damage to reputation" as a consequence of a personal data breach or to a "loss of control"
over such data, are expressly included among the examples of possible damages and
losses listed in recitals 75 and 85 of the GDPR.
"60 In particular, the Court of Justice has stressed that it is clear from the illustrative list
of the 'damages' or 'losses' that data subjects may suffer, set out in
recital 85, first sentence, of the GDPR, that the legislator of
the Union intended to include in these two concepts, in particular, the mere 'loss of
control' over the personal data of those data subjects as a
consequence of an infringement of that Regulation, even if there has not
been any actual misuse of the data in question." Such a loss
of control may be sufficient to cause “non-material damages” within the
meaning of Article 82(1) of that Regulation, provided that the
data subject demonstrates that they have actually suffered such damages, however
minimal, without this concept of “non-material damages”
requiring proof of the existence of additional tangible negative consequences
(see, to that effect, the judgment of 4 October 2024,
Agentsia po vpisvaniyata, C-200/23, EU:C:2024:827, paragraphs 145, 150 and 156 and
the case law cited therein). (emphasis added)
In any event, we also do not agree with CAIXABANK’s assertion that
no damage or harm has been caused to the data subjects affected by the
personal data breaches.
As indicated in the preceding paragraphs, there is a problem regarding The detection of personal data breaches similar to the one that led to complaint 2 at CAIXABANK (which sent the response to a complaint filed with the Customer Service Department to the wrong recipient, revealing the personal data of the data subjects).
Since CAIXABANK relies heavily on the customer, who received the documentation sent in error containing the personal data of a third party, contacting the complainant and alerting them to the error, a prolonged period of time can occur between the date the personal data breach occurs and when it is reported to CAIXABANK's Data Protection Officer (DPO).
During this period, sometimes lasting months, the data subject has lost control of their personal data, and this circumstance has gone completely unnoticed by the data controller.
Furthermore, the personal data breach has not been detected during this period, and the data subject awaits a response from CAIXABANK regarding a A banking product that will not arrive (since it was mistakenly sent to a third party) may be generating interest, a statute of limitations may have expired, etc., causing harm to the interested party.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 43/59
Furthermore, if we analyze the personal data disclosed to third parties affected by the personal data breaches (Document 5 BREACH DETAILS), we observe cases in which the disclosed data includes banking information and details of the interested party (for example: breach (…) with reference (***REFERENCE.1), which includes an IBAN without an asterisk, or breach (…) (***REFERENCE.2) in which a significant volume of personal data of all kinds relating to the interested party is disclosed (name and surname, ID number, nationality, address, marital status, date of birth, telephone number,
profession, company where they work, handwritten signature, details of a vehicle they own, their length of service at their company, the year their home was built, and
that said home is mortgaged, as well as all the conditions related to
the loan that was granted to them).
In other cases, in addition to personal data, it has been revealed that the financial situation of the person affected by the data breach was dire,
a circumstance that can be considered reputational damage.
For example, claim 2 states:
“I handed over my own documents, which they lost, and they sent me
private documents from another client whose name I don't know, with their surname,
(…) and email address, explaining that this gentleman owed money and that they were waiving the fees. They also sent me the completed banking best practices document in someone else's name.” (emphasis added).
The client who owed money and whose fees were waived by CAIXABANK is D.D.D.
(…)
Regarding the potential damages, the case of claimant 1 deserves special attention.
A.A.A., from the moment he received a letter addressed to
B.B.B., requested explanations from CAIXABANK, expressing his concern about the processing
of his personal data by CAIXABANK and that his personal data had been
disclosed to B.B.B., unknown to him (proven facts four and five).
When submitting to the Spanish Data Protection Agency (AEPD), along with his complaint, the subsequent letters sent by
CAIXABANK dated July 7 and 11, 2023, claimant 1 included the following handwritten notes (proven fact four):
“NEW RESPONSE, THEY STILL HAVEN'T CLARIFIED ANYTHING.”
“THEY SAY NOTHING ABOUT THE USE OF MY PERSONAL DATA.”
Despite the fact that the interested party had requested CAIXABANK repeatedly
explanations about what happened and had expressly inquired about the processing
of his personal data by CAIXABANK, there is no record
that CAIXABANK informed him that the document containing his personal data that
it received, addressed to B.B.B., was also sent to that person (proven fact seven).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 44/59
This circumstance represents a clear loss of control by the data subject over his
personal data.
When a personal data breach occurs, CAIXABANK, as the data controller, assesses whether or not the breach poses a high risk to the rights and freedoms of the data subjects affected, in order to determine whether or not to inform them that a personal data breach has occurred, in compliance with Article 34 of the GDPR.
However, if the data subject himself The complainant directly contacts CAIXABANK and requests information on how the bank has processed their personal data. The complainant must provide the requested information. In this second scenario, the situation is different, as the data subject requests information from the data controller regarding the processing of their personal data.
CAIXABANK's system listed a person as the representative of Complainant 1 who was not actually the representative. CAIXABANK had sent this person a letter containing Complainant 1's personal data.
The letter addressed to B.B.B. is dated ***DATE.2, and the detection
of the personal data breach occurred on ***DATE.1 (when
complainant 1 contacted CAIXABANK's Customer Service Department and reported that they had
received a response to a complaint they had not filed, addressed to
a third party).
It is important to be aware of the enormous power that CAIXABANK had granted to
B.B.B. over the complainant. This person was considered by the data controller to be the legal representative of complainant 1, despite not actually being so.
For all the reasons stated above, it cannot be considered that the data subjects affected
by the personal data breaches referred to in this file have not suffered any harm or damage.
13. Reference to Supreme Court Judgment 543/2022 of the Administrative Chamber
of February 15, 2022, regarding the obligation of means and not of results
On the one hand, the manner in which the data processing examined was carried out by SAC staff produced a result, since personal data of numerous data subjects was disclosed to third parties.
Furthermore, the deficiencies from a design perspective have also been evidenced, both in the preceding sections and in the proven facts. That is to say, at the time the personal data processing was carried out, a series of appropriate technical and organizational measures, designed to effectively apply the principles of data protection, had not been implemented.
These measures were implemented gradually thereafter.
3. PROPORTIONALITY:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 45/59
Having examined the arguments presented by CAIXABANK, it has been considered that certain mitigating circumstances may apply in this case, reducing the amount of the administrative fine corresponding to the infringement of Article 25 of the GDPR.
Article 83.4 of the GDPR provides:
“4. Infringements of the following provisions shall be subject to administrative fines, in accordance with paragraph 2, of no more than EUR 10,000,000
or, in the case of an undertaking, no more than 2% of its total worldwide annual turnover of the preceding financial year, whichever is higher.”
The business volume of the party being sued amounts to €1,310,563,000 in 2023, and 2% of this is €26,211,260.
Therefore, the penalty to be imposed must necessarily be between €0 and €26,211,260.
This proposed resolution accuses CAIXABANK of an infringement of Article 25 of the GDPR. Given the seriousness of the facts reflected in the background, established facts, and legal grounds, an administrative fine of €500,000 cannot be considered disproportionate.
In response to the remaining allegations questioning the severity of the fines
pursuant to Article 83.2 of the GDPR, the following should be noted:
Regarding Article 83.2(a) of the GDPR, as has been repeatedly stated,
the facts examined in this case are serious and demonstrate a
infringement of Article 25 of the GDPR.
In the initial agreement of April 16, 2025, the content of Article 83.2(a) of the
GDPR was taken into account as a circumstance for determining the level of
seriousness of the infringement, but not as an aggravating factor.
With regard to Article 83.2(b) of the GDPR (intent or negligence in the
infringement), no intent on the part of CAIXABANK is found, although
gross negligence can be established, as explained in Legal Basis VI.
Regarding Article 83.2 c) of the GDPR (any measure taken by the controller or processor to mitigate the damage suffered by data subjects),
this mitigating circumstance is considered applicable, and the amount of the fine is reduced.
With respect to Article 83.2 d) of the GDPR (degree of responsibility of the controller, taking into account the technical or organizational measures implemented pursuant to Articles 25 and 32), this mitigating circumstance has been applied.
With respect to the aggravating circumstance of Article 76.2 b) of the LOPDGDD (connection of the infringer's activity with the processing of personal data), Legal Basis VI sets out the reasons why it is considered applicable in this case. C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 46/59
IV. Unfulfilled Obligation. Data Protection by Design and by Default
Article 25 of the GDPR states the following:
"1. Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of the processing, as well as the risks of varying likelihood and severity of processing for the rights and freedoms of natural persons, the controller shall implement, both at the time of determining the means of processing and at the time of processing, appropriate technical and organizational measures, such as pseudonymization, designed to effectively implement the principles of data protection, such as data minimization, and to integrate the necessary safeguards into the processing, in order to comply with the requirements of this Regulation and to safeguard the rights of data subjects.
2. The controller shall implement appropriate technical and organizational measures to ensure that, by default, only personal data that are necessary for each specific purpose of the processing are processed. This obligation shall apply to the amount of personal data." collected, to the extent of their processing, to their retention period, and to their accessibility. Such measures shall, in particular, ensure that, by default, personal data are not accessible, without the intervention of the data subject, to an indeterminate number of natural persons.
3. An approved certification mechanism pursuant to Article 42 may be used as evidence of compliance with the obligations set out in paragraphs 1 and 2 of this Article.
Data protection by design, regulated in Article 25 of the GDPR, stems from the obligations imposed on all data controllers in Articles 5.2 and 24 of the GDPR and is intended to ensure compliance with the GDPR.
It must be considered by the data controller from the earliest stages of planning any personal data processing.
It implies a comprehensive design of the personal data processing and its risks to the rights and freedoms of data subjects. It is not an additional layer or
module that is added to something pre-existing, but rather it must be integrated into the set
of non-functional requirements from the very moment it is conceived and designed.
This does not mean that the activity and interests of the
data controller are not taken into consideration, although when doing so, an approach must be taken
to prevent risks to the rights and freedoms of the data subjects. Therefore,
starting from an approach centered on the natural persons whose personal data is
being processed.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 47/59
Regarding the infringement of Article 25.1 of the GDPR, in addition to what has already been stated
in this legal basis, reference should be made to the established facts and
legal basis III, paragraph 2.
Furthermore, an infringement of Article 25 of the GDPR is also found, specifically with regard to its
second paragraph, given that CAIXABANK processed more personal data than
necessary ((...)).
Therefore, the known facts are considered to constitute a procedural infringement
attributable to CAIXABANK, for violation of Article 25 of the GDPR.
V. Classification of the infringement of Article 25 of the GDPR and its classification for the purposes of the statute of limitations
Article 83.4 of the GDPR classifies as an administrative infringement the violation of the following articles, which shall be sanctioned, in accordance with paragraph 2, with administrative fines of up to EUR 10,000,000 or, in the case of an undertaking, up to 2% of its total global annual turnover of the preceding financial year, whichever is higher:
"(a) the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39, 42 and 43;"
"" For its part, the LOPDGDD, in its Article 71, Infringements, states that:
“The acts and conduct referred to in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law, constitute infringements.”
For the sole purpose of the limitation period, Article 73 of the LOPDGDD establishes the following:
"In accordance with the provisions of Article 83.4 of Regulation (EU) 2016/679,
infringements that constitute a substantial breach of the articles mentioned therein are considered serious and shall be subject to a two-year limitation period, and
in particular, the following:
(…)
d) The failure to adopt the appropriate technical and organizational measures
to effectively implement the principles of data protection by design, as well as the failure to integrate the necessary safeguards into
the processing, as required by Article 25 of Regulation (EU) 2016/679."
e) The failure to adopt appropriate technical and organizational measures to
ensure that, by default, only the personal data necessary
for each of the specific processing purposes will be processed, as required by
Article 25.2 of Regulation (EU) 2016/679.
VI. Proposed Sanction
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 48/59
In order to determine the administrative fine to be imposed, the provisions of
Articles 83.1 and 83.2 of the GDPR must be observed, which state:
“1. Each supervisory authority shall ensure that the imposition of administrative fines
pursuant to this Article for infringements of this
Regulation referred to in paragraphs 4, 9 and 6 are, in each individual case,
effective, proportionate and dissuasive.
2. Administrative fines shall be imposed, depending on the circumstances of
each individual case, in addition to or as an alternative to the measures provided for
in Article 58(2)(a) to (h) and (j). When deciding on the imposition of an
administrative fine and its amount in each individual case, due consideration shall be given to
the following:
(a) the nature, seriousness, and duration of the infringement, taking into account the
nature, scope, or purpose of the processing operation concerned,
as well as the number of data subjects affected and the level of damage
they have suffered;
(b) the intent or negligence in the infringement;
(c) any measures taken by the controller or processor to
remedy the damage suffered by the data subjects;
(d) the degree of responsibility of the controller or processor,
taking into account the technical or organizational measures they have implemented
pursuant to Articles 25 and 32;
(e) any previous infringements committed by the controller or processor;
f) the degree of cooperation with the supervisory authority in order to remedy the infringement and mitigate its possible adverse effects;
g) the categories of personal data affected by the infringement;
h) how the supervisory authority became aware of the infringement, in particular whether and, if so, to what extent the controller or processor notified the infringement;
i) where the measures referred to in Article 58(2) have been previously ordered against the controller or processor concerned in relation to the same matter, compliance with those measures; (j) adherence to codes of conduct pursuant to Article 40 or to certification mechanisms approved pursuant to Article 42, and (k) any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement.”
For its part, Article 76 “Sanctions and corrective measures” of the LOPDGDD provides:
“1. The sanctions provided for in paragraphs 4, 5 and 6 of Article 83 of Regulation (EU) 2016/679 shall be applied taking into account the criteria for
graduation established in paragraph 2 of the aforementioned Article.
2. In accordance with Article 83.2.k) of Regulation (EU) 2016/679, the following may also be taken into account:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 49/59
a) The ongoing nature of the infringement.
b) The connection between the infringer's activity and the processing of personal data.
c) The benefits obtained as a result of committing the infringement.
d) The possibility that the data subject's conduct may have induced the commission of the infringement.
e) The existence of a merger by acquisition subsequent to the commission of the infringement, which cannot be attributed to the acquiring entity.
f) The impact on the rights of minors.
g) The appointment of a data protection officer, where not mandatory.
h) The voluntary submission by the controller or processor to alternative dispute resolution mechanisms in cases where disputes arise between them and any interested party.
In this case, considering the seriousness of the potential infringement, and especially the consequences for those affected, the imposition of the corresponding fine would be appropriate, in addition to the adoption of measures, if applicable.
The fine imposed must be, in each individual case, effective, proportionate, and dissuasive, in accordance with Article 83.1 of the GDPR.
To guarantee these principles, the turnover of CAIXABANK, €1,310,563,000 in 2023, as reflected in the eleventh fact of the initial agreement, is taken into account.
For the purposes of deciding on the imposition of an administrative fine and its amount, it is considered appropriate to determine the appropriate sanction in accordance with The following
circumstances, contemplated in the aforementioned provisions.
For the purposes of deciding on the imposition of an administrative fine and its amount, it is
considered appropriate to determine the sanction to be imposed in accordance with the following
circumstances, contemplated in the aforementioned provisions.
Breach of obligation under Article 25 of the GDPR:
Preliminary considerations indicate that the following circumstances exist:
• The nature, seriousness, and duration of the infringement, taking into account the
nature, scope, or purpose of the processing operation in question, as well as
the number of data subjects affected and the level of damage they have suffered (Article 83.2(a) of the GDPR):
CAIXABANK, as the data controller, must guarantee the principles
set forth in Article 5 of the GDPR. The facts examined reflect that a series of principles (confidentiality,
accuracy, minimization) were not
duly guaranteed.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 50/59
(…)
Complaints
Year handled by the Customer Service Department
2022 (…)
2023 (…)
2024 (…)
Furthermore, it must be considered that the framework in which the
examined personal data processing took place (Customer Service Department of ***COMPANY.1) has a
significant potential impact on the rights and freedoms of numerous
data subjects.
The following refers to how several principles
of Article 5 of the GDPR were affected:
With regard to the principle of confidentiality, we are not dealing with two
isolated cases, but rather with at least:
(…) personal data breaches in 2022.
(…) personal data breaches in 2023
(…) personal data breaches in 2024.
These affected numerous interested parties, disclosing personal data.
Regarding the principle of data minimization, (...).
With respect to the principle of accuracy, the lack of design measures under Article 25 of the GDPR resulted in problems of inaccuracy of the personal data processed.
The data controller has subsequently adopted measures to address some issues related to Article 25 of the GDPR,
although some matters remain unresolved.
• Intentionality/Negligence in the infringement (Article 83.2(b) of the GDPR):
While intentionality cannot be established with regard to the infringement of Article 25 of the GDPR, gross negligence can be established.
At the time the personal data processing examined took place, a set of circumstances existed related to the way the Customer Service Department (SAC) was organized and the processing of personal data within it, which facilitated errors by the staff. processed these claims.
(...)
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 51/59
Furthermore, serious negligence on the part of CAIXABANK can be observed for not
having adequately addressed, from the perspective of Article 25 of the
GDPR, the problems related to the detection of personal data breaches such as
those examined. The following is particularly noteworthy:
• The high degree of dependence, when detecting breaches,
on the intervention of third parties (who have received incorrect documentation
containing personal data of data subjects and
report it to CAIXABANK).
• The lengthy periods of time that elapse between the occurrence of personal data breaches and their notification to the CAIXABANK Data Protection Officer (DPO) (periods that sometimes last several months).
• The categories of personal data affected by the infringement (Article 83.2, letter g) of the GDPR):
The documentation provided by CAIXABANK during the preliminary investigation and the evidentiary phase shows that numerous personal data were affected.
One of the data most frequently affected is the National Identity Document (DNI).
It should be noted that the processing of the DNI/NIF/NIE number constitutes the processing of particularly sensitive personal data, as it allows for the direct and unambiguous identification of a natural person. As established by
Royal Decree 255/2025, of April 1, which regulates the National Identity Document (DNI),
the DNI is a personal numerical identifier of a general nature,
with sufficient value to prove both the identity and nationality of the
holder, making it a particularly sensitive element within the
ecosystem of personal data. Furthermore, its misuse entails a
high risk of identity theft, financial losses, or infringement of the
right to honor, risks expressly contemplated in recital 75 of the
GDPR. Therefore, a systematic and purposive interpretation of the GDPR—in accordance
with recitals 51 and 75—allows the DNI number to be considered a
particularly sensitive piece of data, given its potential to cause significant
harm in the event of unauthorized use. In this regard, when assessing
this circumstance, reference should be made not only to the types of data covered
by Articles 9 and 10 of the GDPR, but also to data outside the scope of
these articles whose disclosure causes immediate harm or hardship
to the data subject, as permitted by the provision.
As noted, both personal data and financial data have sometimes been affected, with the data subject's creditworthiness or financial circumstances being disclosed to
third parties.
Occasionally, banking details such as IBAN, card contract number, guarantee number, and loan contract number have been affected,
disclosed to third parties along with the name and surname and other
identifying personal data (name and surname) or contact information (email address), with the potential risks to the data subject arising from the simultaneous disclosure of such personal data.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 52/59
The following factors are also considered aggravating circumstances:
• The connection between the offender's activity and the processing of personal data (Article 76.2, letter b), of the LOPDGDD):
The performance of financial activities, which is the main activity of
CAIXABANK, necessarily involves the processing of personal data
of the bank's clients (or potential clients), not only with respect to the documentation submitted by them through the channels established by the data controller, but also for all types of activities.
CAIXABANK emphasizes that "the handling of complaints is inextricably linked to the
processing of personal data." Indeed, the receipt, registration,
processing, and response to complaints submitted to the Customer Service Department (SAC) of
CAIXABANK involves the routine and continuous
processing of personal data of a large number of data subjects.
Therefore, the infringement occurs within the framework of personal data processing that the data controller routinely carries out in its business and that is
closely linked to it.
It should also be noted that CAIXABANK has a Data Protection Officer (DPO) and a team who
can advise you on compliance with regulations regarding
the protection of personal data. Furthermore, it has ample
human and material resources and full knowledge of the obligations
stipulated in both the GDPR and the LOPDGDD.
Furthermore, the following mitigating factors are considered in accordance with Article 83.2 of the GDPR:
• Any measures taken by the controller or processor to mitigate the damage suffered by data subjects (Article 83.2(c) of the GDPR):
(…)
• Degree of responsibility of the controller, taking into account the technical and organizational measures implemented pursuant to Articles 25 and 32 of the GDPR (Article 83.2(d) of the GDPR):
As reflected in the nineteenth finding of fact, prior to receiving the first request for information from the SGID, the defendant had conducted training sessions in 2024 for the staff of the Customer Service Department (SAC), providing training on various issues related to the protection of personal data and, in particular, on personal data breaches.
• Any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement” (Article 83.2.k) of the GDPR:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 53/59
The assessment of CAIXABANK's conduct in this case requires considering the actions taken by said entity aimed at complying with the provisions of the GDPR and the Spanish Data Protection Act (LOPDGDD), in consideration of the principle of continuous improvement.
Without overlooking the fact that this continuous improvement is an obligation for data controllers, it is deemed appropriate to consider the attitude shown by CAIXABANK, which, throughout the proceedings, has reported the implementation of various measures throughout 2024 aimed at complying with data protection regulations.
For the purposes of deciding on the imposition of An administrative fine and its amount:
It is considered that the balance of the circumstances contemplated in Article 83.2 of the
GDPR and 76.2 of the LOPDGDD, with respect to the infringement committed by violating the provisions of
Article 25 of the GDPR, allows for the imposition of an administrative fine of €500,000.00.
VII. Corrective Measures
If the infringement is confirmed in the resolution, it could be agreed to impose on the controller the adoption of appropriate measures to bring its actions into compliance with the regulations mentioned
in this act, in accordance with the provisions of Article 58.2(d) of the GDPR,
according to which each supervisory authority may “require the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specific manner and within a specified period…”. The imposition of this measure is compatible with the sanction of an administrative fine, as provided in Article 83.2 of the GDPR.
Thus, the responsible entity may be required to adapt its actions to the
personal data protection regulations, to the extent expressed in the
previous Legal Grounds.
The infringement committed and the facts giving rise to the
breach of data protection regulations are established, from which it is clear
what measures must be adopted, without prejudice to the fact that the specific type of procedures,
mechanisms, or instruments for implementing them corresponds to the
sanctioned party, since it is the data controller who fully knows their
organization and must decide, based on proactive responsibility and a risk-based approach,
how to comply with the GDPR and the LOPDGDD.
However, in this case, regardless of the above, the resolution adopted may require CAIXABANK to adopt the following measures:
Within a maximum period of 6 months, counting from the date of Enforceability of the
final resolution of this procedure:
- Demonstrate the adoption of measures by CAIXABANK specifically aimed at
improving the detection of personal data breaches that occur
within the entity, as well as its capacity to identify
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 54/59
all persons affected by such breaches and the personal data
disclosed therein.
Within a maximum period of 9 months from the date of enforceability of the
final resolution of this procedure:
- Demonstrate having conducted a review of the operation of the Customer Service Department, preparing
a report that includes other measures aimed at ensuring full
compliance with the provisions of Article 25, paragraphs 1 and 2 of the GDPR,
submitting its content to the competent body for the approval of said
measures.
Please note that failure to comply with any order to adopt measures imposed by this agency in the sanctioning resolution may be considered an
administrative infringement under the GDPR, specifically classified as an
infringement in Articles 83.5 and 83.6, and may lead to the initiation of
further administrative sanctioning proceedings.
Furthermore, please remember that neither acknowledgment of the infringements committed nor, where applicable, voluntary payment of the proposed amounts, exempts you from the obligation to
adopt the necessary measures to cease the conduct or correct the effects of
the infringement committed, and from demonstrating compliance with this
obligation to the Spanish Data Protection Agency (AEPD).
In view of the foregoing, the following
PROPOSED RESOLUTION is issued:
That the President of the Spanish Data Protection Agency sanction
CAIXABANK, S.A., with Tax Identification Number A08663619, for an infringement of Article 25 of the GDPR,
classified in Article 83.4 of the GDPR, with a fine of €500,000.00 (five hundred thousand euros).
That the President of the Spanish Data Protection Agency close the
sanctioning procedure initiated against CAIXABANK, S.A., with Tax Identification Number A08663619, for the
alleged infringement of Article 5.1 f) of the GDPR, classified in Article 83.5 of the GDPR.
That the Presidency of the Spanish Data Protection Agency order
CAIXABANK, S.A., with Tax Identification Number A08663619, pursuant to Article 58.2.d) of the GDPR,
to demonstrate compliance with the following measures:
1. Within a maximum period of 6 months from the date of enforcement of the
final resolution of this procedure, adopt the following measures:
- Demonstrate the adoption by CAIXABANK
specifically aimed at improving the detection of personal data breaches
occurring within the entity, as well as its
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 55/59
capacity to identify all persons affected by such breaches
and the personal data disclosed therein.
2. Within a maximum period of 9 months from the date of enforcement of the final resolution of this procedure, adopt the following measures:
- Demonstrate that you have conducted a review of the Customer Service Department's operation,
preparing a report that includes other measures aimed at
ensuring full compliance with the provisions of Article 25 of the GDPR,
paragraphs 1 and 2, and submitting its contents to the competent body for
approval of said measures.
Furthermore, in accordance with the provisions of Article 85.2 of the LPACAP, you are hereby informed that you may, at any time prior to the resolution of this
procedure, make voluntary payment of the proposed penalty, which
will result in a 20% reduction of the penalty amount. With the application of this
reduction, the penalty would be set at €400,000.00 and its payment will result in the
termination of the procedure, without prejudice to the imposition of the
corresponding measures. The effectiveness of this reduction will be conditional upon the withdrawal or waiver of any administrative action or appeal against the sanction.
To this end, if you choose to take advantage of this reduction, you must send the General Sub-Directorate for Data Inspection express notification of your withdrawal or waiver of any administrative action or appeal against the sanction.
Should you choose to make voluntary payment of the amount specified above, in accordance with the provisions of Article 85.2, you must make the payment by depositing it into the restricted account no. IBAN: ES00-0000-0000-0000-0000 (BIC/SWIFT Code: CAIXESBBXXX) held in the name of the Spanish Data Protection Agency at CAIXABANK, S.A., indicating in the payment details the reference number of the procedure shown in the heading of this document and the reason for the reduction of the penalty amount due to voluntary payment. You must also send proof of payment to the General Sub-Directorate of Inspection in order to close the file.
Therefore, you are hereby notified of the foregoing, and the proceedings are made available to you
so that, within TEN DAYS, you may submit any arguments you deem relevant in your defense and
present any documents and information you consider pertinent, in accordance with
Article 89.2 of the LPACAP (Law on Administrative Procedure of Public Administrations).
926-250625
(…)
INSTRUCTOR
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 56/59
ANNEX
File Index EXP202312854
(…)
>>
SECOND: On March 19, 2026, CAIXABANK paid the
fine in the amount of €400,000.00, taking advantage of the reduction provided for in the
proposed resolution transcribed above.
THIRD: The proposed resolution transcribed above established the
facts constituting an infringement of Article 25 of the GDPR, and proposed that the
Presidency require the controller to adopt appropriate measures to
bring its actions into compliance with the regulations, in accordance with the provisions of Article
58.2(d) of the GDPR, which states that each supervisory authority may “require the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a
specified manner and within a specified period…”.
Specifically, with regard only to the measures specifically designed to improve the detection of personal data breaches occurring within the entity, as well as its capacity to identify all individuals affected by such breaches and the personal data disclosed therein, it is noted that having received a letter from CAIXABANK informing that it has adopted the necessary measures in this regard, this Agency acknowledges receipt thereof, without this statement implying any pronouncement on the legality or legitimacy of the measures adopted.
Note is drawn from the provisions of Article 5.2 of the GDPR, which establishes the principle of proactive responsibility when it states that “The controller shall be responsible for compliance with paragraph 1 and be able to demonstrate such compliance.” This principle refers to the obligation of the
data controller not only to design, implement, and observe the appropriate
legal, technical, and organizational measures to ensure that data processing complies with regulations, but also to remain actively vigilant throughout the entire
processing lifecycle to ensure proper compliance, and to be
able to demonstrate it.
LEGAL BASIS
I
Jurisdiction
In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR)
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 57/59
City Hall, and as established in Articles 47, 48.1, 64.2 and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter LOPDGDD), the Presidency of the Spanish Data Protection Agency is competent to resolve this procedure.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 57/59 Likewise, Article 63.2 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) stipulates that: "The procedures
processed by the Spanish Data Protection Agency shall be governed by the provisions
of Regulation (EU) 2016/679, by this Organic Law, by the implementing regulations issued thereunder, and, insofar as they do not contradict them,
subsidiarily, by the general rules on administrative procedures."
II
Termination of the Procedure
Article 85 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP), under the heading
“Termination of Sanctioning Procedures,” provides the following:
“1. Once a sanctioning procedure has been initiated, if the offender acknowledges their responsibility,
the procedure may be resolved by imposing the corresponding sanction.
2. When the sanction is solely monetary, or when a
monetary sanction and a non-monetary sanction may be imposed but the
inappropriateness of the latter has been justified, voluntary payment by the alleged offender, at
any time prior to the resolution, will imply the termination of the procedure,
except with regard to restoring the altered situation or determining
compensation for the damages caused by the commission of the infraction.
3. In both In cases where the sanction is solely monetary, the competent body to resolve the procedure will apply reductions of at least 20% on the amount of the proposed sanction, and these reductions can be combined.
The aforementioned reductions must be specified in the notification initiating the proceedings, and their effectiveness will be conditional upon the withdrawal or waiver of any administrative action or appeal against the sanction.
The percentage reduction provided for in this section may be increased by regulation.
III
Voluntary Payment
In accordance with the provisions of Article 85 of the LPACAP (Law on the Common Administrative Procedure of Public Administrations), the notified resolution allowed for voluntary payment of the proposed penalty, which would entail a 20% reduction. With this reduction, the penalty would be set at €400,000.00, and its payment would terminate the proceedings, without prejudice to the imposition of any corresponding measures.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 58/59
Following the aforementioned resolution, and before a decision was issued by this authority, CAIXABANK made the voluntary payment on March 19, 2026, taking advantage of the 20% reduction. In accordance with paragraph 3 of Article 85 of the LPACAP, the effectiveness of the The aforementioned reduction will be conditional upon the
withdrawal or waiver of any administrative action or appeal against the
sanction.
It should be noted that, in accordance with the provisions of the LPACAP (Law on Administrative Procedure of Public Administrations), as well as
the jurisprudence of the Supreme Court on this matter, the exercise of voluntary payment by the alleged offender does not exempt the administration from the obligation to resolve and notify all proceedings, regardless of how they
began. Likewise, Article 88 of the aforementioned law establishes that the resolution
that concludes the proceedings will decide all issues raised by the interested parties and any others arising therefrom.
Therefore, in accordance with the applicable legislation and having assessed the criteria for
graduating sanctions, the Presidency of the Spanish Data Protection Agency RESOLVES:
FIRST: TO DECLARE the commission of the infringement and TO CONFIRM the sanction
determined in the operative part of the proposed resolution transcribed in the
present resolution.
The amount of the administrative fine stated in the operative part
of the proposed resolution is €500,000.00.
Following CAIXABANK, S.A.'s voluntary payment, although without
acknowledgment of liability, pursuant to Article 85 of the LPCAP (Law on Administrative Procedure),
a 20% reduction of the aforementioned total is applied, resulting in a final amount of
€400,000.00.
The effectiveness of this reduction is conditional, in any case, on the withdrawal
or waiver of any action or appeal through administrative channels.
SECOND: TO DECLARE the dismissal of the infringement of Article 5.1 f) of the GDPR,
classified in Article 83.5 of the GDPR.
THIRD: TO DECLARE the termination of procedure EXP202312854,
in accordance with the provisions of Article 85 of LPACAP.
FOURTH: ORDER CAIXABANK, S.A. to notify the Agency, within 9 months of this resolution becoming final and enforceable, of the adoption of the following measures:
- Demonstrate that it has conducted a review of the Customer Service Department's operation, preparing a report that includes other measures aimed at ensuring full compliance with the provisions of Article 25, paragraphs 1 and 2 of the GDPR, and submitting its content to the competent body for the approval of said measures.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 59/59
FIFTH: NOTIFY CAIXABANK, S.A. of this resolution.
SIXTH: In accordance with the provisions of Article 85 of the LPACAP, which conditions the reduction for voluntary payment on the withdrawal or waiver of any action or appeal through administrative channels, this resolution will be final. through administrative channels and fully enforceable upon notification.
In accordance with Article 50 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights), this Resolution will be made public. Publication will take place once the resolution has been notified to the interested parties.
Against this resolution, which concludes the administrative process as stipulated by Article 114.1.c) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations, interested parties may file an appeal with the Administrative Chamber of the National Court, pursuant to Article 25 and paragraph 5 of the fourth additional provision of Law 29/1998, of July 13, regulating the Administrative Jurisdiction, within two months from the day following notification of this act. provided for in Article 46.1 of the aforementioned Law.
However, in accordance with the provisions of Article 90.3 a) of the LPACAP, the final administrative decision may be
provisionally suspended if the interested party
expresses their intention to file an appeal with the Administrative Court. If this is the case, the interested party must formally communicate this fact in writing
addressed to the Spanish Data Protection Agency, submitting it through the Agency's Electronic Registry [https://sedeaepd.gob.es/sede-electronica-web/], or
through one of the other registries provided for in Article 16.4 of the aforementioned Law
39/2015, of October 1. They must also provide the Agency with the documentation
that proves the effective filing of the appeal with the Administrative Court. If the
Agency is unaware of the filing of the appeal with the Administrative Court, A period of two months from the day following notification of this resolution would terminate the precautionary suspension.
1331-101025
Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es




