Back to Feed
PolicySep 14, 2026

Garante per la protezione dei dati personali (Italy) - 613/2026

Italy's DPA fines BBVA €5.5M for sending unsolicited in-app messages.

Summary

The Italian Data Protection Authority (Garante) has fined the Italian branch of Banco Bilbao Vizcaya Argentaria (BBVA) €5.5 million for persistently sending in-app communications. This occurred even after a data subject deactivated the feature and objected to the processing of their data. The DPA found that BBVA's failure to act on the data subject's request, and their reliance on a technical error, constituted a violation of GDPR articles related to lawful processing, transparency, and the right to object.

Full text

Help Garante per la protezione dei dati personali (Italy) - 613/2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 10:04, 10 September 2026 view sourceSf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators70 edits Tag: Decisions [1.0] Latest revision as of 12:21, 14 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators70 editsmTag: Visual edit Line 92: Line 92: }}}} The DPA fined the Italian branch of the Bank of Bilbao Vizcaya Argentina S.A. €5.508.000 for persistently sending in-app communications after a data subject had deactivated the feature and objected to such processing.The DPA fined the Italian branch of the Bank of Bilbao Vizcaya Argentina S.A. €5,508,000 for persistently sending in-app communications after a data subject had deactivated the feature and objected to such processing. == English Summary ==== English Summary == Line 103: Line 103: They emphasised that instead of contacting their DPO which was responsible for the exercise of rights, and explicitly stated in the privacy policy, the data subject contacted the customer service. They emphasised that instead of contacting their DPO which was responsible for the exercise of rights, and explicitly stated in the privacy policy, the data subject contacted the customer service. Throughout the period of delayed implementation, the data subject received 10 unsolicited commercial messages by the controllerThroughout the period of delayed implementation, the data subject received 10 unsolicited commercial messages by the controller. === Holding ====== Holding === The DPA held that the failure by the controller to act on the request of the data subject, which was done correctly through the in-app settings, in accordance with the advice given by the controller’s customer service, cannot be justified by relying on the technical error between its systems.The DPA held that the failure by the controller to act on the request of the data subject, which was done correctly through the in-app settings, in accordance with the advice given by the controller’s customer service, cannot be justified by relying on the technical error between its systems. Line 112: Line 109: The DPA underscored that the controller sent no follow up with the data subject’s request, and in combination with the fact that the controller only acted after the DPA reached out, constitutes a failure to respond to the data subject’s request to object processing.The DPA underscored that the controller sent no follow up with the data subject’s request, and in combination with the fact that the controller only acted after the DPA reached out, constitutes a failure to respond to the data subject’s request to object processing. In light of the foregoing the DPA found the controller in violation of Articles 5(1)(a), Article 12 and [[Article 21 GDPR|Article 21 GDPR]]. In light of the conditions to take into account pursuant to Article 83 and the fact that the controller had already band correspondingly imposed a fine of €5.508.000 on them.In light of the foregoing the DPA found the controller in violation of [[Article 5 GDPR|Articles 5(1)(a)]], [[Article 12 GDPR|Article 12]] and [[Article 21 GDPR]]. In light of the conditions to take into account pursuant to [[Article 83 GDPR|Article 83]] and the fact that the controller had already band correspondingly imposed a fine of €5,508,000 on them. == Comment ==== Comment == Latest revision as of 12:21, 14 September 2026 Garante per la protezione dei dati personali - 613/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 12 GDPR Article 21 GDPR Type: Complaint Outcome: n/a Started: Decided: Published: Fine: 5508000.0 EUR Parties: Banco Bilbao Vizcaya Argentaria, S.A. National Case Number/Name: 613/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA fined the Italian branch of the Bank of Bilbao Vizcaya Argentina S.A. €5,508,000 for persistently sending in-app communications after a data subject had deactivated the feature and objected to such processing. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA received a complaint from a data subject after they received in-app communications by the Bank of Bilbao Vizcaya Argentina S.A. Italian branch (the controller) despite having deactivated the setting and objecting to the such processing. The controller expressed that deactivation of the notifications had not synchronised within its systems due to technical coordination error which caused an implementation delay. They clarified that the error was limited to the complainant, that they corrected the data subject’s profile and implemented stronger technical and organisational measures for data protection. They emphasised that instead of contacting their DPO which was responsible for the exercise of rights, and explicitly stated in the privacy policy, the data subject contacted the customer service. Throughout the period of delayed implementation, the data subject received 10 unsolicited commercial messages by the controller. Holding The DPA held that the failure by the controller to act on the request of the data subject, which was done correctly through the in-app settings, in accordance with the advice given by the controller’s customer service, cannot be justified by relying on the technical error between its systems. The DPA underscored that the controller sent no follow up with the data subject’s request, and in combination with the fact that the controller only acted after the DPA reached out, constitutes a failure to respond to the data subject’s request to object processing. In light of the foregoing the DPA found the controller in violation of Articles 5(1)(a), Article 12 and Article 21 GDPR. In light of the conditions to take into account pursuant to Article 83 and the fact that the controller had already band correspondingly imposed a fine of €5,508,000 on them. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [Web Doc. No. 10291895] Decision of September 3, 2026 Register of Decisions No. 613 of September 3, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter the “Regulation”); HAVING REGARD TO the Code on the Protection of Personal Data (Legislative Decree No. 196 of June 30, 2003), (hereinafter the “Code”); HAVING REGARD TO Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers entrusted to the Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Gazette No. 106 of May 8, 2019, and at www.gpdp.it, web doc. No. 9107633 (hereinafter “Regulation No. 1/2019 of the Data Protection Authority”); HAVING CONSIDERED the documentation on file; HAVING CONSIDERED the observations submitted by the Secretary General pursuant to Art. 15 of the Data Protection Authority Regulation No. 1/2000 on the organization and operation of the Office o

Entities

BBVA (vendor)in-app communications (product)