Enforcement · Spanish Data Protection Authority (aepd) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
CAIXABANK, S.A.: Non-compliance with general data processing principles
How it connects
Related across sources
Guidance Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 News What Happened to the Risk-Based Approach to Data Transfers? News Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures Guidance EDPB Annual Report 2021 News DeFine is a calculator for GDPR fines based on method of the EDPB Case Law HvJ EU: Privacy Shield ongeldig verklaard (Schrems II)
Full text
The Spanish DPA has imposed a fine of EUR 5 million on CAIXABANK, S.A.. A customer had filed a complaint about having access to a document containing information on a transfer from a third party. The document contained personal data of the third party, such as the name and bank details of the data subject. During its investigation, the DPA found that the controller had failed to implement appropriate technical and organizational measures to protect personal data and prevent such incidents. The DPA also found that the controller had failed to comply with the principle of data protection by design and by default, as it acted reactively rather than proactively in handling the complaint.
Industry: Finance, Insurance and Consulting
Original document at the source www.aepd.es