Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Italian Privacy Regulator Fines BBVA €5.5 Million Over Unwanted Marketing Messages

Italian Privacy Regulator Fines BBVA €5.5 Million Over Unwanted Marketing Messages

By
Key Takeaways
  • €5.5 Million Fine: Italy’s Data Protection Authority fined BBVA more than €5.5 million after a customer continued receiving promotional messages despite objecting to them.
  • Seven Months of Messages: The customer received unsolicited commercial communications from October 2025 through May 2026 after refusing them through the bank’s app and Customer Service.
  • Systems Failed to Align: BBVA attributed the issue to a technical error that prevented its systems from properly aligning with the platform managing commercial communications.
  • Technical Errors Do Not Remove Responsibility: The Garante found that the malfunction was not sufficient to relieve BBVA of responsibility and identified broader problems in its data-management processes.
Deep Dive

Italy’s Data Protection Authority has fined Banco Bilbao Vizcaya Argentaria Italia (BBVA) more than €5.5 million after finding that the bank continued sending promotional messages to a customer who had objected to receiving them, an enforcement action that exposed wider problems in how the bank managed privacy requests across its systems.

The case began with a customer who expressed his opposition to commercial communications through the BBVA app and later reiterated that refusal to Customer Service. The request was clear. What happened afterward was not: promotional messages continued arriving for seven months, from October 2025 through May 2026.

BBVA attributed the problem to a technical error that prevented the correct alignment of its company systems with the platform responsible for managing commercial communications to customers. The preference existed, in other words, but it did not reliably reach the system that needed to act on it.

For the Garante, that explanation identified the problem without excusing it. A technical malfunction was not enough to relieve the bank of responsibility, and the regulator characterized the episode as evidence of a flaw in BBVA’s data-management processes.

There is a practical distinction buried in that finding, and it is the one that gives the case significance beyond a single customer receiving unwanted promotions. An organization can provide a mechanism for exercising a privacy right, record the resulting choice and still fail to respect that right. The request is not the end of the process. It has to survive whatever happens next.

The Garante’s investigation found problems there as well. The authority said BBVA failed to provide the customer with accurate feedback concerning the exercise of his rights and provided incorrect information about how its internal processing worked.

The regulator formalized its findings in Decision No. 613 of September 3, 2026. Its reasoning reaches into a problem familiar to any large organization whose customer data passes through multiple applications, databases and platforms: a person’s preference cannot be treated as effective simply because one system knows about it.

Privacy compliance, as the Garante framed it, cannot stop at the boundary of an individual application or database. The systems involved in processing personal data must communicate effectively enough to ensure that a customer’s choice is respected throughout the processing operation. Otherwise, the organization has collected a preference without actually honoring it.

That is what makes seven months of promotional messages more consequential than seven months of promotional messages might initially appear. The failure was visible in the customer’s inbox, but the regulator found its cause further upstream, in the machinery responsible for turning an expressed privacy choice into an operational fact.

Alongside the fine of more than €5.5 million, the Garante ordered BBVA to adopt adequate technical and organizational measures to facilitate the exercise of individuals’ rights and ensure that their requests are handled correctly and promptly.

The order leaves BBVA with work that is less simple than finding the system that sent the messages and switching it off. The regulator’s concern is with the connections between systems and the procedures surrounding them: whether a decision made by a customer in one place remains the same decision everywhere else his data travels. A privacy preference that disappears somewhere between those points is not much of a preference at all.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong