[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f40qUKxGdAVYSIaQMOs8YaeeMgyPo91FCPCvVs5bIlls":3},{"article":4,"iocs":45},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"30ef64ed-69dd-4bb8-8a38-852e035e3b63","Garante per la protezione dei dati personali (Italy) - 613\u002F2026","garante-per-la-protezione-dei-dati-personali-italy-613-2026-c0b22e","Created page with \"{{DPAdecisionBOX |Jurisdiction=Italy |DPA-BG-Color= |DPAlogo=LogoIT.png |DPA_Abbrevation=Garante per la protezione dei dati personali |DPA_With_Country=Garante per la protezione dei dati personali (Italy) |Case_Number_Name=613\u002F2026 |ECLI= |Original_Source_Name_1=Garante per la protezione dei dati personali |Original_Source_Link_1=https:\u002F\u002Fwww.garanteprivacy.it\u002Fweb\u002Fguest\u002Fhome\u002Fdocweb\u002F-\u002Fdocweb-display\u002Fdocweb\u002F10291895 |Original_Source_Language_1=Italian |Original_Source_L...\" Show changes","The Italian Data Protection Authority (Garante per la protezione dei dati personali) has fined the Italian branch of Banco Bilbao Vizcaya Argentaria (BBVA) €5.508.000. The fine was imposed because the bank continued to send in-app communications to a data subject even after they had deactivated the feature and objected to the processing. BBVA cited a technical coordination error for the delay in synchronizing the deactivation, but the DPA found this insufficient justification.","Italy's DPA fines BBVA €5.5M for sending unsolicited messages after opt-out.","Help Garante per la protezione dei dati personali (Italy) - 613\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 10:04, 10 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators61 edits Tag: Decisions [1.0] (No difference) Latest revision as of 10:04, 10 September 2026 Garante per la protezione dei dati personali - 613\u002F2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 12 GDPR Article 21 GDPR Type: Complaint Outcome: n\u002Fa Started: Decided: Published: Fine: 5508000.0 EUR Parties: Banco Bilbao Vizcaya Argentaria, S.A. National Case Number\u002FName: 613\u002F2026 European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA fined the Italian branch of the Bank of Bilbao Vizcaya Argentina S.A. €5.508.000 for persistently sending in-app communications after a data subject had deactivated the feature and objected to such processing. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA received a complaint from a data subject after they received in-app communications by the Bank of Bilbao Vizcaya Argentina S.A. Italian branch (the controller) despite having deactivated the setting and objecting to the such processing. The controller expressed that deactivation of the notifications had not synchronised within its systems due to technical coordination error which caused an implementation delay. They clarified that the error was limited to the complainant, that they corrected the data subject’s profile and implemented stronger technical and organisational measures for data protection. They emphasised that instead of contacting their DPO which was responsible for the exercise of rights, and explicitly stated in the privacy policy, the data subject contacted the customer service. Throughout the period of delayed implementation, the data subject received 10 unsolicited commercial messages by the controller Holding The DPA held that the failure by the controller to act on the request of the data subject, which was done correctly through the in-app settings, in accordance with the advice given by the controller’s customer service, cannot be justified by relying on the technical error between its systems. The DPA underscored that the controller sent no follow up with the data subject’s request, and in combination with the fact that the controller only acted after the DPA reached out, constitutes a failure to respond to the data subject’s request to object processing. In light of the foregoing the DPA found the controller in violation of Articles 5(1)(a), Article 12 and Article 21 GDPR. In light of the conditions to take into account pursuant to Article 83 and the fact that the controller had already band correspondingly imposed a fine of €5.508.000 on them. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [Web Doc. No. 10291895] Decision of September 3, 2026 Register of Decisions No. 613 of September 3, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016\u002F679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\u002F46\u002FEC (General Data Protection Regulation, hereinafter the “Regulation”); HAVING REGARD TO the Code on the Protection of Personal Data (Legislative Decree No. 196 of June 30, 2003), (hereinafter the “Code”); HAVING REGARD TO Regulation No. 1\u002F2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers entrusted to the Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Gazette No. 106 of May 8, 2019, and at www.gpdp.it, web doc. No. 9107633 (hereinafter “Regulation No. 1\u002F2019 of the Data Protection Authority”); HAVING CONSIDERED the documentation on file; HAVING CONSIDERED the observations submitted by the Secretary General pursuant to Art. 15 of the Data Protection Authority Regulation No. 1\u002F2000 on the organization and operation of the Office of the Data Protection Authority, adopted by resolution of June 28, 2000 (web doc. No. 1098801); RAPPORTEUR: Prof. Pasquale Stanzione; 1. FACTS AND COURSE OF THE PRELIMINARY INVESTIGATION 1.1. Origin of the preliminary investigation By letter dated March 11, 2026 (ref. no. 37012), this Authority received a complaint in which the complainant alleged having received in-app commercial communications from Banco Bilbao Vizcaya Argentaria, S.A., Italian branch, with headquarters at Corso Vittorio Emanuele 9, 20122 Milan, Tax ID and VAT No. 06862150155 (hereinafter the “Company”). Specifically, the Company had arranged to send the aforementioned commercial communications—via its App—despite the fact that the User had disabled the relevant setting and had expressed his objection to such processing. By letter dated April 28, 2026 (Ref. No. 64723\u002F26), the Office sent the Company a request for information, pursuant to Article 157 of the Code, aimed at obtaining facts for the assessment of the complaint in question. In its letter dated May 20, 2026 (Ref. No. 77887\u002F26), the Company represented the following: - Although the opt-out from receiving commercial notifications had been processed by the Bank’s internal systems, it had not been synchronized with the Customer Relationship Management (“CRM”) unit responsible for sending commercial communications, “thereby causing a delay in implementing the opt-out, which is why these notifications continued to be sent erroneously”; - Following the Office’s request, the User’s profile was corrected, and as of May 13, the User no longer receives such notifications; at the same time, the systems for aligning opt-out requests with commercial communications were strengthened. In a letter dated May 25, 2026 (Ref. No. 80020\u002F26), the complainant reiterated the allegations, emphasizing that the contested processing did not comply with applicable regulations. 2. INITIATION OF PROCEEDINGS FOR THE ADOPTION OF CORRECTIVE AND SANCTIONING MEASURES AND THE PARTY’S DEFENSES 2.1. Initiation of proceedings (Article 166, paragraph 5, of the Code) Based on the review of the evidence gathered during the activities described above and the determination of the alleged violations, by notice dated June 23, 2026 (Ref. No. 97228), served in accordance with Article 166, paragraph 5, of the Code, the Office initiated proceedings to adopt the measures provided for in Article 58, para 2, of the Regulation against the Company in its capacity as controller, inviting the Company to submit written defenses or documents or to request a hearing before the Authority (Article 166, paragraphs 6 and 7, of the Code, as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981). The alleged violations in question relate to the following provisions: - Articles 5(1)(a), 12, and 21 of the Regulation, in that the Company did not properly address the objection raised by the complainant within the time limits prescribed by applicable law, nor did it provide an adequate response; - Articles 5(1)(a) and 24 of the Regulation, in that the Company failed to implement appropriate technical and organizational measures to ensure the transparency and fairness of ","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_613\u002F2026&diff=52993&oldid=0","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-09-10T10:04:02+00:00","2026-09-10T12:00:28.106969+00:00",8,[18,21],{"name":19,"type":20},"BBVA","vendor",{"name":22,"type":23},"in-app communications","product","d95477d7-eb04-4fad-a2dc-be1428040ce7",{"id":24,"icon":26,"name":27,"slug":28},null,"Privacy Fines","privacy-fines",[30,35,40],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":41},{"id":42,"icon":26,"name":43,"slug":44},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",[]]