AEPD (Spain) - EXP202406208

From GDPRhub
AEPD - EXP202406208
Authority: AEPD (Spain)
Jurisdiction: Spain
Relevant Law: Article 5(1)(f) GDPR
Article 5(2) GDPR
Type: Investigation
Outcome: Violation Found
Started: 13.10.2025
Decided:
Published: 08.04.2026
Fine: 240000 EUR
Parties: EVO Banco, S.A. (now Bankinter S.A)
National Case Number/Name: EXP202406208
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): Spanish
Original Source: AEPD (in ES)
Initial Contributor: Ainhoa Salazar Cardero

The DPA fined a bank €240,000 for failing to ensure the integrity and confidentiality of their clients’ and employees’ data in relation to a data breach. It was caused by a vulnerability in an API that allowed unauthorized access to personal data by a third party, affecting approximately 1.27 million individuals.

English Summary

Facts

On 23 March 2024, a personal data breach began at EVO Banco S.A. (now Bankinter S.A.), the controller, due to a vulnerability in an API used for customer onboarding, introduced during a system migration. Between 23 and 26 March 2024, around 5 million anomalous requests were made, of which approximately 1.2 million were successful, allowing unauthorised access to personal data.

On 30 April 2024, a hacker published in the Deep Web that they held a database of 1,3 Million of clients of a Spanish bank. The controller detected this post on 8 April 2024 and notified the DPA 5 days later stating that approximately 1.27 million individuals were affected.

The controller considered the risk to be low and initially decided not to inform data subjects. On 18 April 2024, the DPA ordered the controller to notify affected individuals and launched an investigation. The attacker later published data relating to 958 customers and four employees.

Holding

First, the DPA held that the controller violated Article 5(1)(f) GDPR, as it failed to ensure the integrity and confidentiality of personal data. The breach resulted from a vulnerability in an API that allowed unauthorized access to personal data by a third party, who used the information to threaten the controller with publishing the data on the dark web.

Second, the DPA found that the controller had not implemented appropriate technical and organisational measures, highlighting deficiencies such as the lack of adequate access controls and the absence of data encryption. These shortcomings enabled the breach and demonstrated a failure to prevent unauthorized access also breaching the principle of accountability of Article 5(2) GDPR.

Third, the DPA emphasised the seriousness of the breach due to its scale and the nature of the data involved. The incident affected approximately 1.27 million individuals and included a wide range of personal and financial data, increasing the risk of fraud and identity theft. The DPA stressed that the comprehensive nature of the data -including both the ID of the data subjects as well as financial data such as IBANs or tax declarations could be used to construct profiles which would subsequently be used for fraudulent and identity impersonation purposes.

The fine was initially set at €400,000 but pursuant to Law 39/2015, a Spanish law concerning administrative proceedings, the DPA informed the controller that it may make a voluntary payment of the proposed fine and waive their right to appeal. This action reduces the imposed fine by 20%. The fine can be reduced by a further 20% if the controller acknowledges its liability. The controller opted for both and reduced the fine by 40%, paying the reduced sanction amount of €240,000. The DPA took into account both aggravating and mitigating factors, including the large-scale processing of personal data as an aggravating factor and the subsequent corporate merger as a mitigating factor.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.

1/27

• File No.: EXP202406208

RESOLUTION TERMINATING THE PROCEEDINGS BY ACKNOWLEDGMENT

OF LIABILITY AND VOLUNTARY PAYMENT

From the proceedings initiated by the Spanish Data Protection Agency and based on the following

BACKGROUND

FIRST: On October 13, 2025, the Presidency of the Spanish Data Protection Agency agreed to initiate sanctioning proceedings against BANKINTER, S.A.

(hereinafter, BANKINTER), by means of the agreement transcribed below:

<<

File No.: EXP202406208

AGREEMENT TO INITIATE SANCTIONING PROCEEDINGS

Based on the actions taken by the Spanish Data Protection Agency and the following

FACTS

FIRST: On April 13, 2024, this Agency was notified of a breach of personal data belonging to EVO BANCO, S.A., with Tax Identification Number A70386024 (hereinafter, EVO BANCO).


In the notification, EVO BANCO, through the submission form on its website, states the following:

What may have occurred?: Cyber incident: Unauthorized access to data in an information system (corporate or internet service)

- "Temporal information: The breach began on March 23, 2024, and was detected on April 9, 2024.

- Type of breach: Confidentiality.

- Type of incident: Cyber incident: Unauthorized access to data in an information system (corporate or internet service).

- Responsible party: Not specified.

- Specifically regarding the data affected by the confidentiality breach:

Is the data securely encrypted, anonymized, or protected in such a way that it is unintelligible to anyone who may have had access, or can the individuals be identified? No

- Degree to which it will affect people: very limited inconveniences.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 2/27

- Summary of the incident: On April 8, the security teams
of EVO BANCO were informed by their detection service of a
publication on the Deep Web claiming to have a database of a
Spanish BANK with 1.3 million clients. As a preventive measure,

EVO BANCO performed a check on its systems in order to
identify any possible vulnerabilities and whether said publication referred to its
client database. A weakness was identified (…=, a number of
anomalous queries were detected over a period of 2 days, approximately 5 million, of which
1.2 million were confirmed as successful. As soon as this situation was
confirmed, in addition to proactively correcting the error

(…), reinforcement and corrective measures were established, as well as fraud prevention measures, which are detailed in the attached documentation.

- Data categories: Basic data (e.g., name, surname, date of
birth), National Identity Document (DNI), Foreigner's Identity Number (NIE), Passport and/or any other identification document,

Contact information

- Number of affected parties: 1,275,049

- Categories of affected parties: Customers / Citizens, Subscribers / Potential

- Communication to affected parties: They will not be informed.

- Cross-border implications: No.

- Breach resolved: Yes.

- Method Breach detection: Detection methods implemented
proactively by the data controller or processor.

- The incident has been reported to the police authorities: No.

Along with the notification, the data controller attaches a report, dated April 12, 2024, with
additional information on breach management, entitled “REPORT
SECURITY INCIDENT EVO BANCO, S.A.” (hereinafter, the initial report), which, in summary, reveals the following:

- The data controller detected the breach through a cybercrime prevention and detection service, provided by third parties, upon detecting the sale
on the Deep Web of a database of the entity's clients.

- The data controller considers the detected advertisement credible after verifying

matches with internal encodings used (…).

- The data controller detects a vulnerability generated as a consequence of

(…)

- (…) is used in user registration processes and grants access to a limited data record.

For security reasons, access is limited externally to the

data owner, or internally to a Bank manager.

- (...) an error occurred that apparently affected the established limitation.

- As a result of the internal investigation, the responsible party identified that
between March 23, 2024, and March 26, 2024, there was an anomalous volume of

requests to that query system. Specifically, 5 MILLION
requests, of which 1.2 MILLION were successful. The
responsible party states that: “Following the incident, an
analysis of the affected records was carried out. This confirmed that the
requests allowed for queries to be made to a total of 1.2
million records (...), although it has not been possible to demonstrate that any such queries were successful.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 3/27

any extraction of said information by any third party unrelated to

EVO BANCO.”

- The data controller indicates the criteria used to assess that there is no high risk
for the affected data subjects and its decision not to inform the affected parties

in accordance with Article 34 of the GDPR. This decision is based on the measures
implemented to prevent the exfiltrated data from being used for illicit purposes
within the framework of the entity's procurement processes.

- The data controller also analyzes and assesses as low the risk that a third party
will use them for illicit purposes in procurement processes external to

EVO BANCO. The data controller indicates that such data could only be used
to generate customer confidence that they are communicating with their bank
and encourage them to carry out transactions involving the withdrawal of their
funds through various mechanisms, for which the entity implements anti-fraud and awareness measures.

- The data controller considers that the potential impact on the interested parties would be

low.

In light of the facts, on April 18, 2024, this Agency ordered EVO BANCO to

communicate the breach to the interested parties in accordance with Article 34 of the
GDPR, without undue delay, so that those affected can take the
measures they deem appropriate to avoid any risks that could affect them.

SECOND: As a consequence of the known facts, on April 18, 2024, the
Director of the Spanish Data Protection Agency instructed the Sub-Directorate

General for Data Inspection (SGID) to initiate the preliminary
investigation proceedings referred to in Article 67 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter, LOPDGDD).

THIRD: The Sub-Directorate General for Data Inspection proceeded to the carrying out of preliminary investigative actions to clarify the facts in question, pursuant to the functions assigned to the supervisory authorities in Article 57.1 and the powers granted in Article 58.1 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VIII of the LOPDGDD (Spanish Organic Law on Data Protection and Digital Rights).

Once the preliminary investigative actions had begun, on May 14, 2024, a letter was received from EVO BANCO confirming the dispatch of individualized notifications to the data subjects affected by the personal data breach and including the following information:

- EVO BANCO states that, on April 15, 2024, the Technological Investigation Brigade of the National Police contacted EVO BANCO to inform them that the breach had been detected on the Deep Web. A website published

containing data related to EVO BANCO's databases.

- That, in addition to the post published on 30/03/2024 (this aspect will be
detailed later), the attacker, from 18/04/2024 to 27/04/2024,

made several publications on the Deep Web and contacted several
EVO BANCO employees (including the CISO) in order to extort them and
threaten them with the publication of personal data from EVO BANCO's databases.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 4/27

- That, as a result of these events, EVO BANCO decided to file the
corresponding complaint on 22/04/2024 with the National Police at the
General Information Commissariat in Madrid, with No. Reference 3202/24.

EVO BANCO states that it is submitting the following documents in its submission:

- Document 1: copy of the complaint filed by the responsible party with the National Police.

- Document 2: Screenshots of the publications, threats, and

extortion attempts made by the attacker.

- Documents 3 and 4: Evidence of the content of the breach communications
that EVO BANCO sends to the interested parties.

However, these documents are not attached.

On May 17, 2024, as part of the preliminary investigation, this Agency made a new request for information, which was answered
on May 20, 2024, and in which EVO BANCO provided the missing documents 1, 2, 3, and 4.

On May 28, 2024, EVO BANCO requested an extension from this Agency to respond to the information request. This extension was granted, and on June 18, 2024, EVO BANCO submitted a written response, attaching 10 documents, namely:

- Documents 1, 2, and 3: Report ***COMPANY.1

- Document 4: Company certificate confirming breach notification.

- Document 5: RAT (Report of Access to Information)

- Document 6: Management and notification of security incidents related to personal data (March 2022).

- Document 7: Change management procedure.

- Document No. 8: ***COMPANY.2 – Security Services

- Document No. 9: KBA541 - Alarms from Appdynamics

- Document No. 10: EVO Smart Banking. Technical Refinement and Security Report. API.

- Document No. 11: Complaint filed with the National Police on April 22, 2024

From the analysis of the above documents, as well as those contained in the file, the following conclusions are reached:

1. GAP ANALYSIS

1.1. Detection and Origin of the Breach
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 5/27

The breach was detected on April 8, 2024, by EVO BANCO's Cyber Incident Prevention and Detection systems (service provided by external providers ***COMPANY.2 and ***COMPANY.3), following the publication of a post on the forum

***FORUM.1 of the Deep Web.

The post indicates that the attacker has a database of 1.3 MILLION customers of a Spanish BANK, without specifying which BANK.

This fact is stated by EVO BANCO in its initial report of April 12, 2024:

“On April 8, the EVO BANCO security team was informed by its cybercrime prevention and detection service (provided by ***COMPANY.2 and ***COMPANY.3) of the existence of a post on the Deep Web, which indicated having a “database of 1.3 million customers” of a “Spanish BANK.”

The aforementioned report includes a screenshot of the Deep Web post and states that:

- The post is dated March 30, 2024.

- It is known that the attacker recently joined the forum, in March

2024.

- There are only two posts from the attacker, and their rating indicates
that they are an attacker with a poor reputation.

- The post includes a link with a sample of 10 records.

EVO BANCO also states that:

“The provider who reported the leak also indicated that it was a

hacker with a low reputation, […]

However, the sample was analyzed, revealing identifiers (…) similar to those used by EVO BANCO to register its clients and potential
clients for the implemented services (…).

While news about leaks, attacks, or exploitation of vulnerabilities is
common in these types of environments, and most of these reports turn out to be “false alarms,” this
leak sampled data codes related to 10 user records.

While this data alone does not necessarily imply any affiliation with a specific

company, the data linked to the exposed records included the coding “(…)”, whose numerical correlation matched the internal coding that EVO BANCO uses in the internal management of its
***SYSTEM.1” records.

In light of these findings, EVO BANCO, in its initial report, states that it has

carried out the following analytical actions to determine the source of the breach:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 6/27

- EVO BANCO's security teams are conducting an analysis of their
internal systems.

“Following this revelation, the security teams began an analysis of the internal communication processes used in the entity's
business management, in order to uncover any
anomalous situations.”

“(…)”.

1.2. Actions taken to minimize adverse effects and measures adopted for initial containment

Following the analysis of the source of the breach, EVO BANCO, in its initial report, states that it took the following actions to contain the breach almost immediately after its detection (i.e., on April 8 and 9):

- Once the vulnerability was identified, it was immediately corrected, restoring it to its previous state.

“(…)”.

- After the vulnerability was fixed, EVO BANCO analyzed the affected records, verifying that 1.2 million successful queries allowed access to 1.2 million records in the
***SYSTEM.1 (a system that manages customer relationships and, therefore, is likely to contain customers' personal data).

“(…)”

- On date On April 9, 2024, at 9:30 p.m., EVO BANCO informed its Data Protection Officer of the events that had occurred.

"After verifying that the incident could affect personal data, the Data Protection Officer of
Evo BANCO was informed at 9:30 p.m. on the same day, April 9."

- Among the measures immediately adopted was the

collaboration of forensic experts to investigate the incident. The responsible party requested that a specialized entity in the sector (specifically,

***COMPANY.1) prepare both a forensic report on the breach
that occurred and a penetration test on the affected application.

"An independent audit is being carried out by ***COMPANY.1, a global leader
in consulting and auditing, to provide external verification of the
integrity and security of our communications in the affected application,

certifying its resolution and mitigation as of April 9." April 2024.

1.3. Causes that made the breach possible

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 7/27

EVO BANCO states in its initial report that what made the anomalous volume of calls possible (…) which allowed the personal data breach (…), is a vulnerability generated in the migration process (…). The characteristics of the vulnerability are as follows:

- (…)

This is stated in the initial report: “(…)”.

Based on this information, during the preliminary investigation, the AEPD delved deeper into the vulnerability reported by EVO BANCO. Thus, regarding the vulnerability that led to the breach, based on the information and documentation provided by EVO BANCO on June 18, 2024, the following relevant information is extracted:

- The The affected API is used to onboard current and potential clients of EVO BANCO and is part of its online banking portal and its SYSTEM.1 system of COMPANY.4.

This fact is documented in the forensic report prepared by COMPANY.1,

submitted as document 1 by EVO BANCO on June 18, 2024:

“(…)”

EVO BANCO states this fact in its written response dated June 18, 2024:

“[…] Focusing on the one that generated the vulnerability, (…).

EVO BANCO states these facts in its written response, sent on June 18, 2024: “On February 8, 2024, through the change
planned and approved by the EVO BANCO Change Committee, (…).

1.4. Regarding the type and volume of data affected

1.4.1. Regarding the type of data affected by the breach, in the full breach notification and the initial report, EVO BANCO states:

- That the type of data affected is basic data (e.g., name,
surname, date of birth), National Identity Document (DNI), Foreigner's Identity Number (NIE), Passport, and/or any other
identification document and contact information.

- That there was no access to balances, card numbers, or similar payment methods

nor to passwords or credentials.

- That images of identity documents or
identification methods were not compromised.

- That there was no No personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data, health data, or data concerning the client's sex life or sexual orientation, as defined in Article 9.1 of the GDPR, has been processed or affected.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 8/27

- That the number of affected parties is 1,275,049 MILLION.

- That the categories of affected parties are customers/citizens and
subscribers/potential customers.

- That, among those affected, there are no minors or members of vulnerable groups.

- That, among those affected, there are no interested parties in other EU Member States.

This information contrasts with the findings of the forensic report prepared by
***COMPANY.1, which states the following:

“According to the analysis carried out, in the period between March 23 and March 27, exactly 5,473,299 requests were made, with a total of 1,275,463 of them being successful. (Emphasis added by the Spanish Data Protection Agency)

In other words, of the 5.4 million requests registered during this period, the number of people affected by the security breach is 1,275,463, taking into account, for this purpose, the number of Spanish National Identity Document (DNI) or Foreigner's Identity Number (NIE) recovered through malicious requests. (Emphasis added by the Spanish Data Protection Agency)

Delving deeper into the potentially leaked information, we identified the following data returned by the server in response to the malicious requests, based on the data Registered on the EVO web contracting platform
(See Annex VII. Details of the fields reported in the acquired logs (…) to consult the specific information analyzed):

- ***COMPANY.4 identifier related to each of the affected users.

- Information on promotions used by customers.

- User status in relation to the documentation provided to the entity.

- Socioeconomic data belonging to each of the affected users, such as data on the VAT return for the last fiscal year, years worked, employment status, monthly income, etc.

- Products contracted along with supplementary information, such as the IBAN,

if it was sent to EVO BANK.

- Data on contracted products, if any, including the IBAN number of bank accounts, the product code, the signature identifier, and consent status, among others.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 9/27

- Personal information of users: name and surnames of the affected persons, ID or NIE number, telephone number, and financial status, among others.

As can be seen, although the number of interested parties is similar to that indicated by EVO BANCO in its submission, the forensic report of ***EMPRESA.1 indicates that, among the affected data, economic and financial data are included.

1.4.2. Regarding the total number of data subjects involved in the

processing activities affected by the breach, EVO BANCO provides the Record of Processing Activities (RPA) for said processing (document no. 5), which reveals the following:

According to the data controller, three processing activities were affected by the breach:

• Digital Origination - Acquisition of new clients through digital environments.

• Digital Origination - Monitoring during the contracting process.

• Operations, Organization, and Fraud - Customer registration and deregistration.

The RPA for each of these activities indicates that the number of affected data subjects ranges between 100,001 and 500,000.

In light of this information, it can be inferred that, with respect to the
processing activities affected by the breach, EVO BANCO can handle a maximum
volume of 1.5 MILLION clients and potential clients (maximum volume
indicated at 500,000 per RAT, multiplied by the three affected activities).

Furthermore, it should be noted that this volume is very likely somewhat

lower, as some clients and potential clients will be the same across the
different activities affected by the breach.

Therefore, it can be inferred that the breach, having affected more than 1.2 MILLION
clients, represents a considerable proportion of the total number of data subjects
for whom EVO BANCO processes personal data, estimated at a minimum of

80%.

1.5. Impact of the Personal Data Breach and Exfiltration

According to the full breach notification submitted by EVO BANCO on April 13, 2024, the breach has affected confidentiality, as there has been

access to the personal data of clients and potential clients by unauthorized third parties.

Regarding the exfiltration of personal data, EVO BANCO, in its initial report,
states that:

“[…] this publication sampled data codes related to 10 user records.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 10/27

“[…] although no evidence has been found of any extraction of said information by any third party unrelated to EVO BANCO.”

In the additional information provided by the data controller on May 14, 2024, regarding the

threats perpetrated by the attacker between April 18 and 27, 2024 (subsequent to the
first post dated March 30, 2024), EVO BANCO states the following:

“When EVO BANCO refused to comply with the cybercriminal's demands,
the attacker escalated the threats, indicating that he would publish

some of the data he had accessed as a result of the cyberattack, in batches
of 500 records per day. This threat was only carried out with respect to 958 affected clients
and four employees of the bank.” (Emphasis added by the Spanish Data Protection Agency).

The forensic report prepared by ***COMPANY.1, regarding the exfiltration of personal data, states the following:

“The information leaked on the Deep Web forums belongs to legitimate data of
EVO, which suggests that the responsible threat actor stole data belonging to both clients and non-clients of the entity. (Emphasis added by the
Spanish Data Protection Agency)

The type of data affected matches that collected by
the Procurement Portal and managed (...)”.

“[...] Conversely, it cannot be confirmed that the information returned by the
EVO BANK server was exported by the threat actor.”

Therefore, there is evidence that the attacker accessed this data and that,
some of it was exfiltrated, both in the sample of 10 records published in the
initial post (…) dated March 30, 2024, and in the subsequent threats made by
the attacker, in which he made public the information of 958 affected clients.

This fact is stated by EVO BANCO in its letter dated May 14, 2024:

“Based on the above, it was confirmed that the attacker had the personal data of the individuals indicated in his two posts, and to date, this entity has no further evidence regarding the content of the alleged file he possesses, nor can it confirm that it refers to the number of records

initially indicated by the attacker. Since April 27, there has been no further
posting on the Deep Web, and the same attacker has declared what he now calls an incident closed.” (Emphasis added by the Spanish Data Protection Agency)

2. SECURITY MEASURES

2.1. Security measures implemented prior to the breach

2.1.1. Software change management.

EVO BANCO states that it has a specific procedure for change management. This change management process includes (...).

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 11/27

EVO BANCO confirms this in its response, sent on June 18, 2024:

“The entity's change management procedure is attached as Document 7:

“***URL.1.”

In the case of the change that generated the vulnerability that originated the breach, it can be seen that it was approved and documented (…) with code:
***URL.2.

Thus, EVO BANCO provided, on June 18, 2024, both its change management procedure (document 7) and a detailed explanation of how the migration process in which the vulnerability occurred was carried out (…) due to the incident. Analyzing both documents, it is observed that:

(…)

This fact demonstrates that the functional validation that EVO BANCO performs only verifies that the returned data is the requested data, but does not validate that an unauthorized user (without valid credentials) cannot access the data.

- It is recorded that the date of the next review/expiration of the procedure was June 15, 2024; however, in version control, the last update is dated 22/01/2024. Since this document was received on
18/06/2024, it can be inferred that the document review, which should have

been carried out on June 15, 2024, was not performed.

2.1.2. Security Event Monitoring and Alert Systems.

Regarding this measure, EVO BANCO states the following in its letter dated
18/06/2024:

(…)

3.1.3. Personal Data Breache Management Procedure.

EVO BANCO states that it has a procedure for managing and reporting security incidents related to personal data (document no. 6).

Regarding the penetration tests performed on the development processes in December 2023, EVO BANCO states the following in its letter dated June 18, 2024:

“Attached as Document 8 is the analysis performed on the login processes in December “***URL.3” as well as the customer registration process “(...) - Technical Report.pdf” used by this service.”

In this regard, EVO BANCO provides the report of said penetration tests

(document no.: 8), and thus, analyzing said document, it is concluded that it is a report

prepared by ***COMPANY.2, which reviews the security of the forms for

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 12/27

authentication of various EVO BANCO applications. The report is dated December
2023 and identifies a medium risk level, based on a series of
vulnerabilities for resolution by EVO BANCO.

Regarding the Cybersecurity Master Plan approved by EVO BANCO at the end of 2023, the bank states:

“At the end of 2023, the 2024 strategic technology plan was presented. This plan includes the security-related actions to be carried out in 2024.”

A screenshot is attached to this document, showing various initiatives. According to EVO BANCO, these initiatives would be implemented during 2024. Therefore, these measures are described below.

2.3. Technical and organizational measures adopted to prevent incidents such as the one that occurred

2.3.1. Regarding software change management, EVO BANCO states
in its letter of June 18, 2024, that:

(…)

As already explained, the validation process performed on the API
affected by the incident did not include checking for access denial
to unauthorized users, which prevented the detection of a manual error
in the configuration. This is one of the new measures established by EVO

BANCO:

or (…)

2.3.2. Regarding monitoring and alert systems, EVO BANCO highlights
in its letter of June 18, 2024, the following measures:

- (…)

2.3.3. Regarding specific penetration tests for (…), EVO BANCO
states:

“g. Copy of the pentesting performed by ***COMPANY.1. This party has attached, as
Document 3, the pentest report performed by ***COMPANY.1 immediately
after the incident, which shows that (…) is no longer vulnerable.”

The penetration test report provided by EVO BANCO as

Document No. 3 is reviewed, which states that, after testing, the conclusion is that (…).

2.3.4. Other additional measures. Within the aforementioned EVO BANCO Cybersecurity Master Plan, additional measures are established, the implementation date of which is estimated to be after the incident.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 13/27

Thus, these measures are described in greater detail in Annex I of the initial report dated April 12, 2024, with EVO BANCO stating the following:

“(…)”

3. Other aspects:

As will be noted in the fourth factual background section, during the course of the preliminary investigation, the Spanish Data Protection Agency (AEPD) received several complaints from individuals affected by the personal data breach.

Some of them stated that they had received the notification provided for in Article 34 of the GDPR even though they were not clients of the entity at the time the events occurred, or even though they had exercised their right to erasure in accordance with Article 17 of the GDPR.

In relation to this matter, during the preliminary investigation, it was
verified that the attack affected personal data that was
blocked in compliance with Article 32 of the LOPDGDD (Spanish Data Protection Act).

FOURTH: Between April 27, 2024, and April 1, 2025, this

Agency received ten complaints from individuals affected by the aforementioned personal data breach.

Specifically, one complaint was received on April 27, 2024, two complaints on

May 22, 2024, one complaint on May 23, 2024, another complaint on May 24, 2024, another complaint on June 8, 2024, another complaint on June 17, 2024, another on June 19, 2024, another complaint on August 1, 2024, and
another complaint on April 1, 2025.

In these complaints, the complainants are those affected by the data breach and, along with their
complaints, they include the communication sent by the entity in compliance with
Article 34 of the GDPR.


Some of the complaints also state that they were affected by the personal data breach even though they were not clients of this entity at the time it occurred, and they allege a possible violation of their right to erasure, which they had exercised with the entity. However, the complaints disregard the blocking obligation stipulated in Article 32 of the LOPDGG (Spanish Data Protection Act), and therefore, these facts are not subject to the present sanctioning procedure.

FIFTH: In accordance with Article 65 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights), the ten aforementioned claims were admitted for processing on May 17, 2024, June 28, 2024 (7 of them), October 3, 2024, and May 9, 2025.

SIXTH: According to the report obtained from the AXESOR tool, EVO BANCO was a company incorporated in 2013, whose current status is "inactive due to dissolution."


This is because a merger by absorption by Bankinter S.A. took place after the events in question, as stated in the “Resolution of April 9, 2025, of the Bank of Spain, which publishes the removal of Evo Banco, SA from the Register of Credit Institutions,” and published in the Official State Gazette (BOE) on April 18, 2025:

“Effective April 1, 2025, the removal of Evo Banco, SA, which held the code number 0239, from the Register of Credit Institutions, due to its merger by absorption by Bankinter, SA, has been registered.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 14/27

Since EVO BANCO, SA has ceased operations as a credit institution, it cannot be overlooked that responsibility in these proceedings must be attributed to the banking entity that has absorbed it, BANKINTER SA (hereinafter, BANKINTER).


SEVENTH: According to the information available on Bankinter.com
(https://www.bankinter.com/file_source2/webcorporativa/estaticos/pdf/accionistas-e-inversores/informacion-nanciera/informesrimestrales/2024/t4/FY24_Bankinter_Resultados.pdf),

BANKINTER ESPAÑA's income statement reflects a profit before tax of €1,360,000,000 for the year 2024.

LEGAL BASIS

I
Jurisdiction

In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR) and as established in Articles 47, 48.1, 64.2 and 68.1 of the Organic Law Pursuant to Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter, LOPDGDD), the Presidency of the Spanish Data Protection Agency is competent to initiate and resolve this procedure.

II

Procedure

Likewise, Article 63.2 of the LOPDGDD establishes that: “The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, this Organic Law, the implementing regulations issued thereunder, and, insofar as they do not contradict them, subsidiarily, by the general rules on administrative procedures.”

In accordance with Article 64 of the LOPDGDD, and taking into account the characteristics of the alleged infringements, a sanctioning procedure is initiated.


The procedure will have a maximum duration of twelve months from the date of the initiation agreement. After this period, it will expire and, consequently, the proceedings will be archived, in accordance with the provisions of Article 64 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights).

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 15/27

If no objections are raised to this initiation agreement within the stipulated period, it may be considered a proposed resolution, as established in Article 64.2.f) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP).


III
Preliminary Issues

Article 4.1 of the GDPR defines “personal data” as: “any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.”

Article 4.2 of the GDPR defines “processing” as: “any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.”

Article 4.7 of the GDPR defines “controller” as: “the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of processing are determined by Union or Member State law, the controller or the specific criteria for its appointment may be laid down by Union or Member State law.” Article 4.8 of the GDPR defines the "data processor" as the natural or legal person, public authority, agency, or other body that processes personal data on behalf of the data controller.

In this case, in accordance with Articles 4.1 and 4.2 of the GDPR, the processing of personal data is documented, since EVO BANCO carried out, among other processing activities, the collection and storage of personal data of natural persons, such as: name, surname, date of birth, national identity card number, foreign resident identification number, passport number, IBAN, among others.

EVO BANCO carried out this activity as the data controller, since it determined the purposes and means of the processing in accordance with Article 4.7 of the GDPR.

However, as noted, the publication in the

Official State Gazette Number 94 of Friday, April 18, 2025, in section
III. Other Provisions. BANK OF SPAIN, which states:

(…) 7949 Resolution of April 9, 2025, of the Bank of Spain, which
publishes the removal of Evo Banco, SA from the Register of Credit Institutions.


C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 16/27

In compliance with the provisions of section 3 of Article 15 of Law 10/2014,
of June 26, on the regulation, supervision, and solvency of credit institutions, the following change in the Register of Credit Institutions is hereby published:

Effective April 1, 2025, Evo Banco, SA, formerly registered under code number 0239, has been removed from the Register of Credit Institutions due to its merger by absorption by Bankinter, SA.

Therefore, and as indicated in the aforementioned Resolution of the Bank of Spain, the removal of EVO BANCO from the Register of Credit Institutions was published on April 1, 2025, as it had been absorbed by BANKINTER SA.

Notwithstanding that the date of detection of the personal data breach was

April 9, 2024, and its notification to this Agency on April 13, 2024, that is, all prior to
the process of EVO BANCO's acquisition by BANKINTER SA, the acquisition by
BANKINTER implies the extinction of EVO BANCO's legal personality and that its
new corporate name becomes BANKINTER SA with Tax Identification Number (NIF) A28157360, and it is to this entity that
responsibility for the alleged infringements committed must be attributed.

Given the above, for the purposes of this sanctioning procedure, BANKINTER
SA is considered the data controller.

IV

Obligation breached. Integrity and Confidentiality

Article 5.1(f) of the GDPR stipulates:

"1. Personal data shall be:
(…)
(f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical and organizational measures (‘integrity and confidentiality’)."

The aforementioned principle of confidentiality therefore requires the protection of personal data against unauthorized access, use, and disclosure, as Recital 39 of the GDPR states:

“[…]Personal data should be processed in a manner that ensures appropriate security and confidentiality of the personal data, including to prevent unauthorized access to or use of the personal data and the equipment used for processing.”

In this case, there is evidence of a personal data breach affecting

confidentiality and impacting clients, former clients whose data remained blocked in accordance with Article 32 of the LOPDGDD (Spanish Data Protection Law), potential clients, non-clients, and employees of EVO BANCO.



(This data was not disclosed in the original text.) The personal data breach occurred, as detailed in the initial report
of April 12, 2024, submitted by EVO BANCO, as well as in the report of

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 17/27

***COMPANY.1 provided during the preliminary investigation, as a consequence of (…)

Thus, between March 23 and March 27 (as indicated in the report of
***COMPANY.1, unlike the report by EVO BANCO, which stated March 26), the breach took place, according to the initial report by EVO BANCO, “(…)”. This information is

clarified in the report of ***COMPANY.1, which states: “(…)”.

EVO BANCO was unaware of the breach until April 9, 2024, as a result of the publication dated March 30, 2024.

Thus, the personal data breach affected data confidentiality; that is, an unauthorized third party gained access to the data and made a copy, subsequently threatening EVO BANCO with its publication on the dark web unless a ransom was paid.

In total, 1,275,049 people were affected. Furthermore, of these 1,275,049 affected individuals, the data of 958 clients and 4 employees of the bank was published on the dark web, according to additional information provided by EVO BANCO to this Agency on May 14, 2024.

Regarding the types of personal data affected, as stated in the report from ***COMPANY.1, the following were included: name, surname, national identity card (DNI) or foreign resident's card (NIE), telephone number, economic status, IBAN numbers of bank accounts, signature, code of

contracted products, VAT return for the last fiscal year, years worked, employment status, monthly income, as well as their identifier on the platform, among others.

Regarding the duration of the personal data breach, it should be emphasized that it began on March 23, 2024—notwithstanding that the deficiency in the measures that caused it dates back to March 8, 2024. Regarding its termination, it is noted that on April 9, 2024, upon becoming aware of it, EVO BANCO restored the previous version of the (…). Furthermore, once “(…)”.

At this point, this Agency wishes to indicate that the documentation contained in

the administrative file reveals deficiencies in the technical

and organizational measures in place at the time of the personal data breach that
facilitated the breach as described above. Thus, considering that the origin and cause of the breach
lies in a vulnerability in the API, the following

aspects are highlighted:

- (...)

- Furthermore, it is emphasized that EVO BANCO lacked encryption measures for
personal data, as acknowledged in the personal data breach notification form, which would have limited the impact of access to
its systems.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 18/27

Notwithstanding the foregoing, it should be emphasized that, as demonstrated by the report from ***COMPANY.1 submitted by EVO BANCO, all these issues were subsequently resolved by the entity.

• (…)

In short, based on the evidence available at this time of initiating the sanctioning procedure, and without prejudice to the outcome of the investigation, it is considered that EVO BANCO failed to adopt any technical or organizational measures to guarantee the principle of integrity and confidentiality provided for in Article 5.1 f) of the GDPR.

Therefore, in accordance with the evidence currently available, and in accordance with the initiation of disciplinary proceedings, it is considered that the known facts could constitute an infringement attributable to Bankinter for

violation of Article 5.1 f) of the GDPR, as transcribed above.

V
Classification of the infringement of Article 5.1.f) of the GDPR and qualification for the purposes of

statute of limitations

Article 83.5 of the GDPR classifies as an administrative infringement the violation of the following

articles, which shall be sanctioned, in accordance with paragraph 2, with administrative fines of up to EUR 20,000,000 or, in the case of an undertaking, up to 4% of its total global annual turnover of the preceding financial year, whichever is higher:
"(a) the basic principles for processing, including the conditions for

consent pursuant to Articles 5, 6, 7 and 9;
(b) the rights of data subjects pursuant to Articles 12 to 22;
(c) transfers of personal data to a recipient in a third country or to an
international organisation pursuant to Articles 44 to 49;
(d) any obligation under the law of Member States adopted pursuant to Chapter IX;

(e) failure to comply with a decision or a temporary or permanent limitation on processing or the suspension of data flows by the supervisory authority pursuant to Article 58(2), or failure to provide access in violation of Article 58(1).

For its part, the LOPDGDD, in Article 71, Infringements, states that:

“The acts and conduct referred to in paragraphs 4, 5 and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law, constitute infringements.”

For the sole purpose of determining the statute of limitations, Article 72.1 of the LOPDGDD (Spanish Data Protection Act) establishes the following:

"In accordance with the provisions of Article 83.5 of Regulation (EU) 2016/679, the following infringements are considered very serious and shall be subject to a three-year statute of limitations:

a) The processing of personal data in violation of the principles and safeguards established in Article 5 of Regulation (EU) 2016/679."

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 19/27

"The processing of personal data in violation of the principles and safeguards established in Article 5 of Regulation (EU) 2016/679."

" VI
Proposed Sanction

In order to determine the administrative fine to be imposed, the provisions of Articles 83.1 and 83.2 of the GDPR must be observed. These provisions state:

“1. Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article for infringements of this Regulation, as referred to in paragraphs 4, 9 and 6, is effective, proportionate and dissuasive in each individual case.
2. Administrative fines shall be imposed, depending on the circumstances of each individual case, as an additional measure to, or in lieu of, the measures provided for in Article 58(2)(a) to (h) and (j). When deciding on the imposition of an administrative fine and its amount in each individual case, due consideration shall be given to:

(a) the nature, seriousness and duration of the infringement, taking into account the nature, scope or purpose of the processing operation concerned as well as the number of data subjects affected and the level of damage suffered;

b) the intentionality or negligence of the infringement;

c) any measures taken by the controller or processor to remedy the damage suffered by the data subjects;

d) the degree of responsibility of the controller or processor, taking into account the technical or organizational measures implemented pursuant to Articles 25 and 32;

e) any previous infringements committed by the controller or processor;

f) the degree of cooperation with the supervisory authority in order to remedy the infringement and mitigate its possible adverse effects;

g) the categories of personal data affected by the infringement;

h) how the supervisory authority became aware of the infringement, in particular whether and, if so, to what extent the controller or processor notified the infringement;

i) where the measures referred to in Article 58(2) have been
previously ordered against the controller or processor concerned in relation to the same matter, compliance with those measures;

(j) adherence to codes of conduct pursuant to Article 40 or to approved certification mechanisms pursuant to Article 42; and
(k) any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement.

For its part, Article 76 “Sanctions and Corrective Measures” of the LOPDGDD (Spanish Data Protection Law) provides:

“1. The sanctions provided for in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679 shall be applied taking into account the criteria for determining the severity of the sanction established in paragraph 2 of the aforementioned article.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 20/27

2. In accordance with the provisions of Article 83.2.k) of Regulation (EU) 2016/679, the following may also be taken into account:

a) The continuing nature of the infringement.
b) The connection between the infringer's activity and the processing of personal data.
c) The benefits obtained as a result of committing the infringement.
d) The possibility that the data subject's conduct could have induced the processing of personal data. Commission of the infringement.

e) The existence of a merger by acquisition subsequent to the commission of the infringement, which cannot be attributed to the acquiring entity.

f) The impact on the rights of minors.

g) The appointment of a data protection officer, when not mandatory.

h) The voluntary submission by the controller or processor to alternative dispute resolution mechanisms in cases where disputes arise between them and any interested party.

The above implies, according to Guidelines 04/2022 on the calculation of fines under the GDPR, that the amount of the fine for each infringement must be based on three elements: the turnover, the categorization of the infringements according to their nature (i.e., whether it is an infringement of Article 83.4, 83.5, or 83.6 of the GDPR), and the level of severity of the infringement in each specific case (in accordance with Article 83.2 a), b), and g). In any case, the fine imposed must be, in each individual case, effective, proportionate, and dissuasive, as established in Article 83.1 of the GDPR.

In this regard, the preliminary figure of €1,360,000,000 in pre-tax profits for BANKINTER ESPAÑA in 2024 is considered.

Furthermore, taking into account the categorization of the infringement, in accordance with Article 83.5 of the GDPR, the penalty imposed for each infringement may be a maximum of €20,000,000, or, in the case of a company, an amount equivalent to a maximum of 4% of its annual turnover, whichever is higher.

4% of BANKINTER's turnover (€1,360,000,000 pre-tax in 2024) is €54,400,000.

In accordance with the above, the penalty imposed for each infringement
must necessarily be between €0 and €54,400,000.

Furthermore, regarding the level of severity under the GDPR, without prejudice
to the outcome of the investigation, the following circumstances are considered to exist:

Preliminary considerations include the following circumstances:

• The nature, severity, and duration of the infringement, taking into account the
nature, scope, or purpose of the processing operation in question,

as well as the number of data subjects affected and the level of damage
they have suffered (Article 83.2(a) of the GDPR): the known facts
directly affect the control that the data subjects have over
their personal data. Furthermore, it exceeds the reasonable expectations that the

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 21/27

interested parties can have regarding the processing of their personal data. Thus,
those affected trust the entity for the secure handling of their personal information,
and the trust and reasonable expectations of the

affected parties regarding the processing of their personal data have been eroded.

Regarding the number of affected parties, it should be emphasized that the confidentiality breach has affected 1,275,049 people. In addition, it is established that the data of at least 958 people was

published on the Deep Web.

Furthermore, the high amount of personal data per
affected party that was compromised should be emphasized. It is worth noting that the breach
of the confidentiality principle in this case involves a set of
personal data whose nature amplifies the implications of the personal data breach. This is evident in the fact that a large number of personal data have been affected. Specifically: name, surname, national identity card (DNI) or foreign resident's card (NIE), telephone number, tax status, IBAN number of bank accounts, signature, codes of contracted products, VAT return for the last fiscal year, years worked, employment status, monthly income, and their identifier on the platform, among others, depending on whether they were clients or not. The combination of this type of personal data significantly increases the level of risk to the rights and freedoms of its owners and the implications of the breach of confidentiality. This is due to the fact that this combination not only increases the amount of information available to a malicious actor, but also broadens the spectrum of potential abuses. Since this is not about isolated data or individual pieces of information,

but rather the exposure of an integrated set of
personal data that, when combined, can be used to
build a complete and detailed profile of an individual, which can allow
an attacker to carry out fraud and identity theft with a
higher success rate.


Regarding the duration of the infringement, it lasted at least from
March 23, 2024, to April 9, 2024.

Furthermore, the breach of the principle of integrity and confidentiality
implies a breach of the principle of proactive responsibility provided for in
Article 5.2 GDPR and developed in Article 24, whereby

data controllers must not only comply with the provisions of the
GDPR, but must also be able to demonstrate compliance with a new approach to
adopting and implementing risk-appropriate measures.

- The categories of personal data affected by the infringement

(Article 83.2(g) of the GDPR): Guidelines 04/2022 of the European Data Protection Board
on calculating fines under the GDPR,

adopted on May 24, 2023, in paragraph 57, state the following regarding
the requirement to take into account the categories of personal data:

Affected parties: “(…) the GDPR clearly highlights the types of data that deserve

special protection and, therefore, a stricter response with regard to
fines. This refers, at a minimum, to the types of data referred to
in Articles 9 and 10 of the GDPR and to data outside the scope of

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 22/27

the application of these articles whose disclosure causes immediate
harm to the data subject (for example, location data, data on
private communications, national identification numbers, or
financial data, such as transaction summaries or credit card numbers). In this case, the national identity card numbers of millions of affected individuals have

been affected by the breach. This involves the processing of sensitive data, as this data allows for the direct and unambiguous identification of a
natural person.

In accordance with Royal Decree 255/2025, of April 1, which regulates the National Identity Document (DNI), the DNI number is a

general personal numerical identifier, sufficient to

prove both the identity and nationality of the holder. This characteristic makes it
a particularly sensitive piece of personal data because, to the extent that
its processing is not accompanied by the necessary technical and
organizational measures to guarantee that the person identifying themselves with it is
actually its holder, a third party can easily impersonate a

natural person, or, in other words, can commit identity
fraud, with the risks this entails for the privacy, honor, and
assets of the impersonated individual.

Furthermore, it should be noted that among the compromised data are
financial data: IBAN, tax returns and VAT information, salaries,

among others.

The following factors are also considered as aggravating circumstances:

• The connection of the offender's activity with the processing of

personal data (Article 76.2, letter b), of the LOPDGDD): the
set of operations that a financial institution carries out with the information of
its clients (and/or potential clients), when opening accounts, granting loans,
processing payments, etc., involves the collection of personal identification data

(name, ID/Passport, address, telephone number, etc.), financial data (bank accounts, transactions, cards, etc.), employment and tax data (income, employment status, tax returns, etc.), among others. All of this constitutes a continuous and
massive processing of personal data.

Furthermore, the following is considered a mitigating factor:

• The existence of a merger by absorption subsequent to the commission of the infringement, which cannot be attributed to the absorbing entity (Article 76.2, letter e), of the LOPDGDD): as already indicated in the preliminary

issues of this document, the file contains the publication in the Official State Gazette (BOE) (18/04/2025) of the Bank of Spain Resolution dated 9/04/2025, which
publishes the removal of EVO BANCO from the Register of Credit Institutions, effective 01/04/2025, having been absorbed by BANKINTER SA.


C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 23/27

The assessment of the circumstances contemplated in Article 83.2 of the GDPR and Article 76.2 of the LOPDGDD (Spanish Data Protection Law) regarding the infringement committed by violating the provisions of Article 5.1.f) of the GDPR, allows for the initial imposition of an administrative fine

of 400,000 (FOUR HUNDRED THOUSAND EUROS).

Therefore, in light of the foregoing, the President of the Spanish Data Protection Agency hereby resolves:

FIRST: TO INITIATE SANCTIONING PROCEEDINGS against BANKINTER, S.A., with Tax Identification Number A28157360, for the alleged infringement of Article 5.1.f) of the GDPR, as defined in Article 83.5 of the GDPR.

SECOND: To appoint R.R.R. as instructor and S.S.S. as secretary,
indicating that they may be challenged, if necessary, in accordance with the provisions of
Articles 23 and 24 of Law 40/2015, of October 1, on the Legal Regime of the Public Sector (LRJSP).

THIRD: To incorporate into the file, for evidentiary purposes, the notification of the

personal data security breach, as well as the documents obtained
and generated by the General Sub-Directorate of Data Inspection in the actions
prior to the initiation of these disciplinary proceedings.

FOURTH: That for the purposes set forth in Article 64.2 b) of Law 39/2015, of October 1,

on the Common Administrative Procedure of Public Administrations, the
sanction that may apply, without prejudice to the outcome of the investigation,

would be an administrative fine:

- For the alleged infringement of Article 5.1.f) of the GDPR, classified in Article

83.5 of said regulation, an administrative fine of €400,000.

FIFTH: NOTIFY BANKINTER, S.A., with Tax Identification Number A28157360, of this agreement,

granting it a period of ten business days to submit any
allegations and present any evidence it deems appropriate. In its written
allegations, it must provide its Tax Identification Number and the procedure number that appears in the

heading of this document.

In accordance with Article 85 of the LPACAP (Law on Administrative Procedure and Common Administrative Litigation), you may acknowledge your responsibility within the period granted for submitting allegations to this initiation agreement. This will entail a 20% reduction of the penalty to be imposed in these proceedings. With this reduction, the penalty would be set at €320.00, and the proceedings will be concluded with the imposition of this penalty.

Likewise, you may, at any time prior to the resolution of these proceedings, make voluntary payment of the proposed penalty, which will result in a 20% reduction. With this reduction, the penalty would be set at €320.00, and its payment will terminate the proceedings, without prejudice to the imposition of any other applicable measures.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 24/27

The reduction for voluntary payment of the penalty is cumulative with the reduction applicable for acknowledging responsibility, provided that this acknowledgment is made within the period granted for submitting allegations upon the initiation of the proceedings. Voluntary payment of the amount referred to in the preceding paragraph may be made at any time prior to the resolution. In this case, if both reductions were to be applied, the penalty amount would be set at €240,000.

In any case, the effectiveness of either of the aforementioned reductions will be conditional upon the withdrawal or waiver of any administrative action or appeal against the penalty.



Should you choose to make a voluntary payment of either of the amounts
indicated above (€320,000 or €240,000), you must do so by

depositing the funds into account number IBAN: ES00-0000-0000-0000-0000-0000 (BIC/SWIFT Code: CAIXESBBXXX) held in the name of the Spanish Data Protection Agency at
CAIXABANK, S.A., indicating in the payment details the
reference number of the procedure shown in the heading of this document and the
reason for the reduction in the amount you are applying for.

You must also send proof of payment to the General Sub-Directorate of
Inspection to continue with the procedure in accordance with the amount
deposited.

Finally, please note that, in accordance with Article 112.1 of the LPACAP,
this decision cannot be appealed. No administrative appeal is possible.

1479-010725

Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency

>>

SECOND: On November 6, 2025, BANKINTER paid the fine of €240,000.00, taking advantage of the two reductions provided for in the initial agreement transcribed above. This implies acknowledgment of responsibility in relation to the facts referred to in the initial agreement and their legal classification.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 25/27

LEGAL BASIS

I
Jurisdiction

In accordance with the powers conferred by Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, (hereinafter GDPR), grants each
supervisory authority, and as established in Articles 47, 48.1, 64.2, and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and

guarantee of digital rights (hereinafter, LOPDGDD), the Presidency of the Spanish Data Protection Agency is competent to resolve this procedure.

Likewise, Article 63.2 of the LOPDGDD stipulates that: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of

Regulation (EU) 2016/679, this Organic Law, the implementing regulations issued thereunder, and, insofar as they do not contradict them, subsidiarily, by the general rules on administrative procedures."

II

Termination of the procedure

Article 85 of the Law Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), under the heading "Termination of Sanctioning Procedures," provides the following:

"1. Once sanctioning proceedings have been initiated, if the offender acknowledges their responsibility, the proceedings may be resolved by imposing the corresponding sanction.

2. When the sanction is solely monetary, or when both a monetary and a non-monetary sanction are possible but the impropriety of the latter has been justified, voluntary payment by the alleged offender at any time prior to the resolution will result in the termination of the proceedings, except with regard to restoring the altered situation or determining compensation for damages caused by the commission of the infraction."

3. In both cases, when the sanction is solely monetary, the

competent body to resolve the procedure shall apply reductions of at least
20% to the proposed sanction amount, and these reductions may be combined.

These reductions must be specified in the notification initiating
the procedure, and their effectiveness will be conditional upon the withdrawal or waiver of
any administrative action or appeal against the sanction.

The percentage reduction provided for in this section may be increased
by regulation.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 26/27

III
Voluntary Payment and Acknowledgment of Responsibility

In accordance with the provisions of Article 85 of the LPACAP (Law on Administrative Procedure of Public Administrations), the notified initiation agreement informed the Bankinter of the possibility of acknowledging responsibility and making voluntary payment of the proposed penalty, which would entail two cumulative reductions of 20% each. With the application of these two reductions, the penalty would be set at €240,000.00, and its payment would lead to the termination of the proceedings, without prejudice to the imposition of the corresponding measures.

Following notification of the aforementioned initiation agreement, Bankinter has proceeded to acknowledge responsibility and make voluntary payment of the penalty, taking advantage of the two reductions provided for. In accordance with paragraph 3 of Article 85

LPACAP, the effective date The aforementioned reductions will be conditional upon the withdrawal or waiver of any administrative action or appeal against the sanction.

It should be noted that, in accordance with the provisions of the LPACAP (Law on Administrative Procedure of Public Administrations), as well as the jurisprudence of the Supreme Court on this matter, the exercise of voluntary payment by the alleged offender does not exempt the administration from the obligation to resolve and notify all proceedings, regardless of how they were initiated. Likewise, Article 88 of the aforementioned law establishes that the resolution that concludes the proceedings will decide all issues raised by the interested parties and any other issues arising therefrom.

Therefore, in accordance with the applicable legislation and having assessed the criteria for determining the severity of the sanctions, the Presidency of the Spanish Data Protection Agency resolves:

FIRST: To declare the commission of the infringements and to confirm the sanctions determined in the operative part of the initial agreement transcribed in This resolution.

The sum of the aforementioned amounts totals €400,000.00.

Following BANKINTER, S.A.'s prompt payment and acknowledgment of liability, pursuant to Article 85 of the LPACAP (Law on Administrative Procedure of Public Administrations), a 40% reduction of the aforementioned total is applied, resulting in a final amount of €240,000.00.

The effectiveness of these reductions is conditional upon the withdrawal or waiver of any administrative action or appeal.

SECOND: To declare the termination of procedure EXP202406208, in accordance with the provisions of Article 85 of the LPACAP.

THIRD: To notify BANKINTER, S.A. of this resolution.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 27/27

FOURTH: In accordance with the provisions of Article 85 of the LPACAP, which conditions
the reduction for voluntary payment and acknowledgment of liability on

withdrawal or waiver of any action or appeal through administrative channels, this
resolution will be final through administrative channels and fully enforceable from the date of
its notification.

In accordance with the provisions of Article 50 of the LOPDGDD, this

Resolution will be made public. Publication will take place once the resolution has been
notified to the interested parties.

Against this resolution, which concludes the administrative process as stipulated by
Article 114.1.c) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations,

interested parties may file an appeal with the Administrative Chamber of the National Court, in accordance with the provisions of Article 25 and in section 5 of
the fourth additional provision of Law 29/1998, of July 13, regulating the
Administrative Litigation Jurisdiction, within two months from the

day following notification of this act, as provided for in Article 46.1 of the

said Law.

However, in accordance with the provisions of Article 90.3.a) of the LPACAP, the final administrative decision may be
provisionally suspended if the interested party

expresses their intention to file an administrative litigation appeal. If this is the case,
the interested party must formally communicate this fact in writing
addressed to the Spanish Data Protection Agency, submitting it through the Agency's
Electronic Registry [https://sedeaeps.gob.es/sede-electronica-web/], or
through one of the other registries provided for in Article 90.3.a) of the LPACAP. 16.4 of the aforementioned Law

39/2015, of October 1. You must also forward to the Agency the documentation
that proves the effective filing of the administrative appeal. If the
Agency is not notified of the filing of the administrative appeal within two months from the day following notification of this
resolution, the precautionary suspension will be terminated.

936-101025
Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es