On 13 January 2021, the Spanish data protection authority issued the largest penalty under the GDPR because valid consent is not obtained before processing personal data.
GDPR: CaixaBank in Spain is fined €6M for consent failure - UniConsent
The Spanish data protection authority ('AEPD') fines CaixaBank S.A. €6 million for violating Articles 6, 13, and 14 of the General Data Protection Regulation (Regulation (EU) 2016/679) ('GDPR') on 13 January 2021.
The resolution highlights that CaixaBank did not provide sufficient justification for the legal basis for the processing of personal data, especially in relation to the data processed on the basis of legitimate interest.
CaixaBank did not comply with the requirements for obtaining valid consent, namely, to be specific, unequivocal, and informed.
The resolution further outlines that deficiencies were identified in the processes to obtain the consent of the clients for the processing of their personal data.
The resolution rules the transfer of personal data to companies within the CaixaBank Group was unlawful.
The fine is the largest financial penalty issued under the GDPR by the AEPD to date.
Reference (Spanish): https://www.aepd.es/es/documento/ps-00477-2019.pdf
Compliant with GDPR, CCPA, COPPA, LGPD, PECR, PDPA, PIPEDA, and more.
Activate Google Consent Mode UniConsent to enhance the accuracy of your Google Analytics and Google Ads conversion data.
Set up Google Consent Mode →Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc
Sign upNFL.com CIPA Lawsuit: When Opting Out Doesn't Stop Tracking — How to Make Opt-Outs Actually Work

First-Party CMP Domain: Serve Your Consent Banner from Your Own Domain
UniConsent Is a Certified Microsoft UET CMP and Microsoft Clarity CMP

UK GDPR Right to Complain: Changes on June 19, 2026 and What Organisations Must Do

Prebid.js CMP Setup: Passing TCF, GPP, and CCPA Consent to Your Header Bidding Stack

The Best Consent Management Platform 2026: UniConsent vs Usercentrics vs Cookiebot vs Didomi vs OneTrust
Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc
Sign up