info@josefelgueroso.com
2021-04-07
In January, the Spanish Data Protection Agency imposed on CaixaBank a fine of 6,000,000 euros and corrective measures in connection with the processing of its clients' personal data. In particular, it found that CaixaBank:
On the other hand, the Data Protection Agency found no evidence that CaixaBank took solely automated decisions. It did not impose penalties on CaixaBank based on this ground of the complaint.
In this article I use the terms "controller" and "data subject," following the terminology of the European Data Protection Regulation. The controller is the person or entity that determines the purposes and means of the processing of personal data; in this case, the controller is CaixaBank. The data subject is the natural person whose personal data the controller processes; in this case, the data subjects are CaixaBank's clients.
An individual petitioner complained to the Data Protection Agency, stating that CaixaBank imposed on him the obligation to accept new conditions for the processing of personal data. In particular, the petitioner objected to CaixaBank's transfer of his personal data to all the companies of the Grupo CaixaBank group of companies and stated that the process to cancel this transfer was more complicated than the process to give his consent.
On the other hand, a consumer organization complained to the Data Protection Agency, stating that CaixaBank imposed consent for the processing of its clients' personal data and their transfer to third parties.
CaixaBank had several documents related to the processing of its clients' personal data, among them a Framework Agreement and a Consent Agreement. The Framework Agreement asked the clients' consent for several purposes:
The Consent Agreement asked the clients' consent for marketing purposes and the transfer of data to third parties. The content of the Consent Agreement was similar to one of the clauses of the Framework Agreement.
Initially, CaixaBank obtained verbally its clients' consent for each of those three purposes, and one of them was broken down into four categories. After an inspection by the Data Protection Agency, CaixaBank began using a tablet with a shared screen to obtain its clients' consent. CaixaBank also used its website and its digital app in a similar manner for that purpose.
The Data Protection Agency had to decide whether CaixaBank had complied with its duty to provide certain categories of information to its clients in connection with the processing of their data, as the European Data Protection Regulation indicates.
When a controller obtains data directly from the data subject, it must provide the following categories of information, among others:
In addition, if the controller obtains the data from a third party it must inform the data subject about the categories of personal data obtained and their origin.
The Data Protection Agency determined that CaixaBank used inconsistent terminology, mentioned similar data processing activities for different purposes, and offered several contractual documents to communicate the information: the Framework Agreement, the Consent Agreement, a Privacy Policy, and an Aggregation Service Agreement. These contractual documents were not always offered to all of the bank's clients. As a result, the information that CaixaBank offered to its clients was not uniform. This reduced the transparency of the processing, one of the principles of the European Data Protection Regulation.
Also, CaixaBank's contractual documents included imprecise and ambiguous terminology. For example, CaixaBank included in its contractual documents expressions such as "give you a better service," "know you better," and "communicate your data to third parties with whom we have an agreement." According to the Data Protection Agency, the terminology that CaixaBank used was indefinite and difficult for the clients to understand, which violated the transparency principle.
The Data Protection Agency also determined that CaixaBank's contractual documents contained defects in the information related to its use of legitimate interest as a basis for the processing of personal data. For example, CaixaBank mentioned legitimate interest as a basis for certain data processing, but did not indicate the specific interest it pursued. Thus, the information was not sufficient to evaluate whether CaixaBank's interests prevailed over those of its clients.
The information related to the creation of profiles was also inadequate. In some cases the contractual documents did not specify the type of profiles, their uses, or their consequences. On the other hand, CaixaBank did mention the use of profiles for marketing purposes, but did not inform its clients about their right to object to it.
Regarding the information provided to the clients about the exercise of their rights, the Data Protection Agency determined that the Consent Agreement mentioned the possibility of exercising rights, but did not mention specific rights. The Privacy Policy did not mention the client's right to object to the processing of the data. Finally, the Aggregation Service Agreement did not mention the right to withdraw consent or the right to object.
In short, the Data Protection Agency concluded that the information that CaixaBank provided to its clients was inadequate, which violated the transparency principle and CaixaBank's duty to provide certain information to its clients for the processing of their personal data.
The Data Protection Agency had to determine whether CaixaBank lawfully processed its clients' personal data using consent as a legal basis.
The processing of personal data is lawful if data subjects give their consent, which must be specific, informed, freely given, and unambiguous:
CaixaBank's Framework Agreement indicated several purposes for the data processing:
The Data Protection Agency determined that the Framework Agreement combined purposes and data processing, and thus the clients' consent was not specific. On the other hand, the information that CaixaBank provided about the data processing was indefinite, because the information about the processing purposes was unclear and did not specify the categories of data involved in the processing. Finally, the clients' consent was not freely given, because the signing of the agreement imposed essential aspects of data processing, such as the communication of personal data to companies of Grupo CaixaBank.
As a result, the Data Protection Agency concluded that the data processing by CaixaBank was not lawful, because the consent given by the clients was not adequate, as it was not specific, informed, or freely given.
The Data Protection Agency had to determine whether CaixaBank lawfully processed personal data based on its legitimate interest.
Data processing by a controller may be lawful if it is based on the legitimate interest of the controller or a third party. But if the interests, rights, or freedoms of the data subject prevail over that legitimate interest, the data processing is unlawful. The interests involved must be assessed:
The data subjects' expectations must also be taken into account: if they do not expect further processing of the data, the data subjects' interests may prevail. On the other hand, one must take into account the impact of the processing on the data subject: the more negative or uncertain that impact is, the less legitimate the processing becomes. Finally, direct marketing may constitute a legitimate interest of the controller.
The Data Protection Agency concluded that CaixaBank's legitimate interest was unclear, because the bank did not even mention a legitimate interest for the data processing. CaixaBank did indicate the purposes of the processing, but they were indefinite, such as for example knowing the client, improving services, and developing the business model. In addition, it was unclear whether the transfer of information to offer products or services similar to those contracted by the client referred to CaixaBank's products or services or those of Grupo CaixaBank or third parties.
CaixaBank's contractual documents confused bases and processing, because they indicated different legal bases for similar data processing activities. For example, they indicated legitimate interest for the communication of personalized offers, the application of promotions, or the preapproval of loans, but these processing activities were similar to those indicated under the consent basis. This could lead to CaixaBank's processing data based on legitimate interest in situations in which the data subject refused consent. According to the Data Protection Agency, this was inadmissible.
Other factors that the Data Protection Agency took into account to assess the lawfulness of legitimate interest as a basis was the lack of transparency in the logic involved for the creation of profiles, the large numbers of persons affected, the large volume of data involved, and the relative position of CaixaBank and its clients. It also took into account that CaixaBank did not provide its clients an assessment of the impact of the processing on the data subjects and that it did not offer a mechanism for the data subjects to exclude themselves from the processing.
In short, the Data Protection Agency concluded that legitimate interest as it appears in CaixaBank's contractual documents was not an adequate basis for the processing of its clients' data, because they did not indicate the interest pursued, confused processing and bases, and could have a significant impact on the data subjects.
The Data Protection Agency identified in CaixaBank's contractual documents frequent references to the communication of personal data to Grupo CaixaBank. It examined several possible bases for these communications, and it had to determine whether they were sufficient to make them lawful.
Group of Undertakings
A possible basis for these data communications is the transfer of personal data between companies of the same group of undertakings for internal administrative purposes; these communications may constitute a legitimate interest of the controller. The European Data Protection Regulation defines a "group of undertakings" as "a controlling undertaking and its controlled undertakings."
The Data Protection Agency found that these communications to Grupo CaixaBank had no internal administrative purposes, but rather business purposes, such as the design of new products. Thus, the concept of group of undertakings was not an adequate basis for the communication of personal data between companies of Grupo CaixaBank.
Consent
Another possible basis for these communications was the data subject's consent given in CaixaBank's contractual documents. That consent must be specific and informed, among other things.
The data subjects' consent was not an adequate basis for these communications to Grupo CaixaBank. CaixaBank's clients did not give separate consent for specific companies of Grupo CaixaBank. Thus, the Data Protection Agency found that client consent for the processing of their personal data by CaixaBank did not constitute consent for the processing of those data by other companies of Grupo CaixaBank. On the other hand, CaixaBank did not provide to its clients information about the obligations of the companies of Grupo CaixaBank toward the data subject, and it did not provide an agreement that indicated the obligations between CaixaBank and the companies of Grupo CaixaBank.
In short, the Data Protection Agency concluded that the communications of personal data to companies of Grupo CaixaBank were unlawful, because they were not covered by the concept of group of undertakings and because the consent given by the bank's clients was not specific or informed.
The European Data Protection Regulation prohibits solely automated decision-making (including profiling) that has legal effects or a significant similar impact on the data subject. The following are exceptions:
In any event, the controller must inform the data subject about the existence of the automated decision-making, the logic involved, and the consequences of the processing for the data subject.
CaixaBank's contractual documents informed the data subject about the existence of automated decision-making; recognized the clients' right to demand human intervention, obtain an explanation, and challenge the decision; and indicated that the basis for these decisions was the clients' consent.
The Data Protection Agency found no evidence that CaixaBank took solely automated decisions, and it did not impose penalties on the bank based on this ground of complaint.
The Data Agency imposed on CaixaBank a fine of 6,000,000 euros and corrective measures.
In determining the amount of the fine, the Data Protection Agency took into account the following aggravating factors, among others: the violation affected 's entire activity, the violation was permanent, the persons impacted by the violation were all of CaixaBank's clients, and the violation constituted an intrusion into the privacy of CaixaBank's clients.
Regarding the corrective measures, the Data Protection Agency prohibited CaixaBank from processing personal data in the absence of the information it must provide to its clients or their valid consent. It also prohibited data processing based on the legitimate interest as it appears in CaixaBank's contractual documents and processing activities without a legal basis indicated in the decision. On the other hand, CaixaBank should instruct the companies of Grupo CaixaBank to erase the client data that had been unlawfully transferred. Finally, CaixaBank should stop the processing of data that had their origin in companies of Grupo CaixaBank.