Garante per la protezione dei dati personali (Italy) - 613/2026
Italy's Garante fines BBVA €5.5M for GDPR violations related to data subject objections.
Summary
Italy's Garante per la protezione dei dati personali has fined the Italian branch of Banco Bilbao Vizcaya Argentaria (BBVA) €5,508,000 for violating GDPR. The bank failed to properly respond to a data subject's request to object to processing and continued sending unsolicited in-app communications even after the setting was deactivated and an objection was raised. The Garante found that a technical error was not a sufficient justification for the non-compliance.
Full text
Help Garante per la protezione dei dati personali (Italy) - 613/2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 14:35, 15 September 2026 view sourceLs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators421 editsTag: Visual edit← Older edit Latest revision as of 08:23, 16 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators74 editsmTag: Visual edit Line 107: Line 107: The DPA underscored that the controller sent no follow up with the data subject’s request, and in combination with the fact that the controller only acted after the DPA reached out, constitutes a failure to respond to the data subject’s request to object processing.The DPA underscored that the controller sent no follow up with the data subject’s request, and in combination with the fact that the controller only acted after the DPA reached out, constitutes a failure to respond to the data subject’s request to object processing. In light of the foregoing the DPA found the controller in violation of [[Article 5 GDPR|Articles 5(1)(a)]], [[Article 12 GDPR|Article 12]] and [[Article 21 GDPR]]. In light of the conditions to take into account pursuant to [[Article 83 GDPR|Article 83]] and the fact that the controller had already band correspondingly imposed a fine of €5,508,000 on them.In light of the foregoing the DPA found the controller in violation of [[Article 5 GDPR|Article 5(1)(a)]], [[Article 12 GDPR|Article 12]] and [[Article 21 GDPR]]. In light of the conditions to take into account pursuant to [[Article 83 GDPR]], and the fact that the controller had already been found in violation of the GDPR, the DPA correspondingly imposed a fine of €5,508,000 on them. == Comment ==== Comment == Latest revision as of 08:23, 16 September 2026 Garante per la protezione dei dati personali - 613/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 12 GDPR Article 21 GDPR Type: Complaint Outcome: n/a Started: Decided: Published: Fine: 5508000.0 EUR Parties: Banco Bilbao Vizcaya Argentaria, S.A. National Case Number/Name: 613/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA fined the Italian branch of the Bank of Bilbao Vizcaya Argentina S.A. €5,508,000 for persistently sending in-app communications after a data subject had deactivated the feature and objected to such processing. Technical error was not found a sufficient justification. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA received a complaint from a data subject after they received in-app communications by the Bank of Bilbao Vizcaya Argentina S.A. Italian branch (the controller) despite having deactivated the setting and objected to the such processing. The in-app communication included 10 unsolicited commercial messages. The controller blamed the absence of notification deactivation on a technical error limited to the complainant, which they later fixed. It also claimed that the data subject had contacted the customer service and not the DPO, as explicitly stated in the privacy policy. Holding The DPA held that the failure by the controller to act on the request of the data subject, which was done correctly through the in-app settings, in accordance with the advice given by the controller’s customer service, cannot be justified by a technical error between its systems. The DPA underscored that the controller sent no follow up with the data subject’s request, and in combination with the fact that the controller only acted after the DPA reached out, constitutes a failure to respond to the data subject’s request to object processing. In light of the foregoing the DPA found the controller in violation of Article 5(1)(a), Article 12 and Article 21 GDPR. In light of the conditions to take into account pursuant to Article 83 GDPR, and the fact that the controller had already been found in violation of the GDPR, the DPA correspondingly imposed a fine of €5,508,000 on them. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [Web Doc. No. 10291895] Decision of September 3, 2026 Register of Decisions No. 613 of September 3, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter the “Regulation”); HAVING REGARD TO the Code on the Protection of Personal Data (Legislative Decree No. 196 of June 30, 2003), (hereinafter the “Code”); HAVING REGARD TO Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers entrusted to the Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Gazette No. 106 of May 8, 2019, and at www.gpdp.it, web doc. No. 9107633 (hereinafter “Regulation No. 1/2019 of the Data Protection Authority”); HAVING CONSIDERED the documentation on file; HAVING CONSIDERED the observations submitted by the Secretary General pursuant to Art. 15 of the Data Protection Authority Regulation No. 1/2000 on the organization and operation of the Office of the Data Protection Authority, adopted by resolution of June 28, 2000 (web doc. No. 1098801); RAPPORTEUR: Prof. Pasquale Stanzione; 1. FACTS AND COURSE OF THE PRELIMINARY INVESTIGATION 1.1. Origin of the preliminary investigation By letter dated March 11, 2026 (ref. no. 37012), this Authority received a complaint in which the complainant alleged having received in-app commercial communications from Banco Bilbao Vizcaya Argentaria, S.A., Italian branch, with headquarters at Corso Vittorio Emanuele 9, 20122 Milan, Tax ID and VAT No. 06862150155 (hereinafter the “Company”). Specifically, the Company had arranged to send the aforementioned commercial communications—via its App—despite the fact that the User had disabled the relevant setting and had expressed his objection to such processing. By letter dated April 28, 2026 (Ref. No. 64723/26), the Office sent the Company a request for information, pursuant to Article 157 of the Code, aimed at obtaining facts for the assessment of the complaint in question. In its letter dated May 20, 2026 (Ref. No. 77887/26), the Company represented the following: - Although the opt-out from receiving commercial notifications had been processed by the Bank’s internal systems, it had not been synchronized with the Customer Relationship Management (“CRM”) unit responsible for sending commercial communications, “thereby causing a delay in implementing the opt-out, which is why these notifications continued to be sent erroneously”; - Following the Office’s request, the User’s profile was corrected, and as of May 13, the User no longer receives such notifications; at the same time, the systems for aligning opt-out requests with commercial communications were strengthened. In a letter dated May 25, 2026 (Ref. No. 80020/26), the complainant reiterated the allegations, emphasizing that the contested processing did not comply with applicable regulations. 2. INITIATION OF PROCEEDINGS FOR THE ADOPTION OF CORRECT