BBVA Italy Fined €5.5M for Ignoring User Opt-Out Preferences
The root cause of this violation was a failure to honour a user's explicit opt-out request due to a technical error in the bank's communication preference management system. Critically, BBVA did not detect or remediate the issue independently — action was only taken after the Garante intervened, indicating a lack of adequate monitoring and internal controls. This matters because GDPR grants individuals the right to object to marketing processing, and organisations are legally obligated to enforce those preferences immediately and reliably. A 'technical error' is not an acceptable defence when the underlying systems lack the controls to validate that consent and preference changes are correctly applied end-to-end.
Tactical Insight
Immediate actions
- Audit all active communication channels to verify that opt-out and consent withdrawal signals are being correctly applied in real time.
- Implement automated blocking of outbound marketing communications to users with active objection or opt-out flags before any message is dispatched.
Long-term improvements
- Build a centralised, auditable Consent & Preference Management Platform (CMP) that serves as the single source of truth for all marketing communication permissions.
- Establish a formal change-management process requiring regression testing of preference enforcement logic whenever communication systems are updated.
- Conduct periodic end-to-end testing (including synthetic opt-out scenarios) to confirm that withdrawal of consent is correctly propagated across all downstream systems.
Detection & monitoring measures
- Deploy automated monitoring alerts that flag any instance where a communication is sent to a user whose preference record shows an objection or opt-out status.
- Implement a complaints and anomaly dashboard reviewed weekly by the Data Protection Officer to catch consent enforcement failures before regulatory escalation.