[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhuNlPzPDj7A-aYeP__YptXtMCVkXl-_yKH_IRg1i62g":3},{"article":4,"iocs":42},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"4af93435-7186-442c-867c-e6013f04af8d","Garante per la protezione dei dati personali (Italy) - 613\u002F2026","garante-per-la-protezione-dei-dati-personali-italy-613-2026-7e39e3","← Older revision Revision as of 14:35, 15 September 2026 Line 92: Line 92: }} }} The DPA fined the Italian branch of the Bank of Bilbao Vizcaya Argentina S.A. €5,508,000 for persistently sending in-app communications after a data subject had deactivated the feature and objected to such processing. The DPA fined the Italian branch of the Bank of Bilbao Vizcaya Argentina S.A. €5,508,000 for persistently sending in-app communications after a data subject had deactivated the feature and objected to such processing. Technical error was not found a sufficient justification. == English Summary == == English Summary == === Facts === === Facts === The DPA received a complaint from a data subject after they received in-app communications by the Bank of Bilbao Vizcaya Argentina S.A. Italian branch (the controller) despite having deactivated the setting and objecting to the such processing. The DPA received a complaint from a data subject after they received in-app communications by the Bank of Bilbao Vizcaya Argentina S.A. Italian branch (the controller) despite having deactivated the setting and objected to the such processing. The controller expressed that deactivation of the notifications had not synchronised within its systems due to technical coordination error which caused an implementation delay. They clarified that the error was limited to the complainant, that they corrected the data subject’s profile and implemented stronger technical and organisational measures for data protection. The in-app communication included 10 unsolicited commercial messages. They emphasised that instead of contacting their DPO which was responsible for the exercise of rights, and explicitly stated in the privacy policy, the data subject contacted the customer service. The controller blamed the absence of notification deactivation on a technical error limited to the complainant, which they later fixed. It also claimed that the data subject had contacted the customer service and not the DPO, as explicitly stated in the privacy policy. Throughout the period of delayed implementation, the data subject received 10 unsolicited commercial messages by the controller. === Holding === === Holding === The DPA held that the failure by the controller to act on the request of the data subject, which was done correctly through the in-app settings, in accordance with the advice given by the controller’s customer service, cannot be justified by relying on the technical error between its systems. The DPA held that the failure by the controller to act on the request of the data subject, which was done correctly through the in-app settings, in accordance with the advice given by the controller’s customer service, cannot be justified by a technical error between its systems. The DPA underscored that the controller sent no follow up with the data subject’s request, and in combination with the fact that the controller only acted after the DPA reached out, constitutes a failure to respond to the data subject’s request to object processing. The DPA underscored that the controller sent no follow up with the data subject’s request, and in combination with the fact that the controller only acted after the DPA reached out, constitutes a failure to respond to the data subject’s request to object processing.","The Italian Data Protection Authority (Garante) has fined the Italian branch of BBVA €5,508,000 for continuing to send in-app communications to a user who had deactivated the feature and objected to the processing. The bank cited a technical error as the cause, but the Garante found this insufficient justification, noting the bank only acted after the DPA intervened and that the user received 10 unsolicited commercial messages.","Italian DPA fines BBVA €5.5M for sending unsolicited in-app messages after opt-out.","Help Garante per la protezione dei dati personali (Italy) - 613\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 12:21, 14 September 2026 view sourceSf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators70 editsmTag: Visual edit← Older edit Latest revision as of 14:35, 15 September 2026 view source Ls (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators415 editsTag: Visual edit Line 92: Line 92: }}}} The DPA fined the Italian branch of the Bank of Bilbao Vizcaya Argentina S.A. €5,508,000 for persistently sending in-app communications after a data subject had deactivated the feature and objected to such processing.The DPA fined the Italian branch of the Bank of Bilbao Vizcaya Argentina S.A. €5,508,000 for persistently sending in-app communications after a data subject had deactivated the feature and objected to such processing. Technical error was not found a sufficient justification. == English Summary ==== English Summary == === Facts ====== Facts === The DPA received a complaint from a data subject after they received in-app communications by the Bank of Bilbao Vizcaya Argentina S.A. Italian branch (the controller) despite having deactivated the setting and objecting to the such processing.The DPA received a complaint from a data subject after they received in-app communications by the Bank of Bilbao Vizcaya Argentina S.A. Italian branch (the controller) despite having deactivated the setting and objected to the such processing. The controller expressed that deactivation of the notifications had not synchronised within its systems due to technical coordination error which caused an implementation delay. They clarified that the error was limited to the complainant, that they corrected the data subject’s profile and implemented stronger technical and organisational measures for data protection.The in-app communication included 10 unsolicited commercial messages. They emphasised that instead of contacting their DPO which was responsible for the exercise of rights, and explicitly stated in the privacy policy, the data subject contacted the customer service. The controller blamed the absence of notification deactivation on a technical error limited to the complainant, which they later fixed. It also claimed that the data subject had contacted the customer service and not the DPO, as explicitly stated in the privacy policy. Throughout the period of delayed implementation, the data subject received 10 unsolicited commercial messages by the controller. === Holding ====== Holding === The DPA held that the failure by the controller to act on the request of the data subject, which was done correctly through the in-app settings, in accordance with the advice given by the controller’s customer service, cannot be justified by relying on the technical error between its systems.The DPA held that the failure by the controller to act on the request of the data subject, which was done correctly through the in-app settings, in accordance with the advice given by the controller’s customer service, cannot be justified by a technical error between its systems. The DPA underscored that the controller sent no follow up with the data subject’s request, and in combination with the fact that the controller only acted after the DPA reached out, constitutes a failure to respond to the data subject’s request to object processing.The DPA underscored that the controller sent no follow up with the data subject’s request, and in combination with the fact that the controller only acted after the DPA reached out, constitutes a failure to respond to the data subject’s request to object processing. Latest revision as of 14:35, 15 September 2026 Garante per la protezione dei dati personali - 613\u002F2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 12 GDPR Article 21 GDPR Type: Complaint Outcome: n\u002Fa Started: Decided: Published: Fine: 5508000.0 EUR Parties: Banco Bilbao Vizcaya Argentaria, S.A. National Case Number\u002FName: 613\u002F2026 European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA fined the Italian branch of the Bank of Bilbao Vizcaya Argentina S.A. €5,508,000 for persistently sending in-app communications after a data subject had deactivated the feature and objected to such processing. Technical error was not found a sufficient justification. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA received a complaint from a data subject after they received in-app communications by the Bank of Bilbao Vizcaya Argentina S.A. Italian branch (the controller) despite having deactivated the setting and objected to the such processing. The in-app communication included 10 unsolicited commercial messages. The controller blamed the absence of notification deactivation on a technical error limited to the complainant, which they later fixed. It also claimed that the data subject had contacted the customer service and not the DPO, as explicitly stated in the privacy policy. Holding The DPA held that the failure by the controller to act on the request of the data subject, which was done correctly through the in-app settings, in accordance with the advice given by the controller’s customer service, cannot be justified by a technical error between its systems. The DPA underscored that the controller sent no follow up with the data subject’s request, and in combination with the fact that the controller only acted after the DPA reached out, constitutes a failure to respond to the data subject’s request to object processing. In light of the foregoing the DPA found the controller in violation of Articles 5(1)(a), Article 12 and Article 21 GDPR. In light of the conditions to take into account pursuant to Article 83 and the fact that the controller had already band correspondingly imposed a fine of €5,508,000 on them. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [Web Doc. No. 10291895] Decision of September 3, 2026 Register of Decisions No. 613 of September 3, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016\u002F679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\u002F46\u002FEC (General Data Protection Regulation, hereinafter the “Regulation”); HAVING REGARD TO the Code on the Protection of Personal Data (Legislative Decree No. 196 of June 30, 2003), (hereinafter the “Code”); HAVING REGARD TO Regulation No. 1\u002F2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers entrusted to the Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Gazette No. 106 of May 8, 2019, and at www.gpdp.it, web doc. No. 9107633 (hereinafter “Regulation No. 1\u002F2019 of the Data Protection Authority”); HAVING CONSIDERED the documentation on file; HAVING CONSIDERED the observations submitted by the Secretary General pursuant to Art. 15 of the Data Protection Authority Regulation No. 1\u002F2000 on the organization and operation of the Office of the Data Protection Authority, adopted by resolution of June 28, 2000 (web doc. No. 10","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_613\u002F2026&diff=53037&oldid=53008","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-09-15T14:35:43+00:00","2026-09-15T16:00:45.478174+00:00",7,[18],{"name":19,"type":20},"BBVA","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,32,37],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":38},{"id":39,"icon":23,"name":40,"slug":41},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]