Italy Fines BBVA Bank EUR 5.5 Million Over Marketing Opt-Out

Independently fact-checkedBy Recording Law Editorial Team7 min read

Independently fact-checked against primary sources (last audited September 17, 2026). · 4 primary sources cited on this page. How we verify our legal content

Italy Fines BBVA Bank EUR 5.5 Million Over Marketing Opt-Out

Frequently Asked Questions

What did the Garante fine BBVA's Italian branch for?

For continuing to send marketing messages through its banking app to a customer who had turned off marketing notifications and separately asked customer service to stop, over a period from October 2025 to May 2026. The Garante found this breached the customer's GDPR right to object to direct marketing and the bank's duty to respond to that objection correctly and promptly.

How much was the fine, in what currency?

EUR 5,508,000 (euro), set out in Provvedimento n. 613 del 3 settembre 2026, doc. web n. 10291895, issued by Italy's Garante per la protezione dei dati personali.

Which company was actually sanctioned?

Banco Bilbao Vizcaya Argentaria, S.A., succursale italiana, the Italian branch of the Spanish bank BBVA, based in Milan.

Why did the bank's explanation not work as a defense?

The bank said a synchronization failure between its internal systems and its CRM (customer relationship management) unit caused the continued messages. The Garante found that a technical explanation for how the failure happened does not excuse the failure itself: once the customer exercised his right to object, the bank was responsible for making sure every system that could message him actually stopped.

Is the decision final, or can BBVA still appeal it?

Under Article 78 of the GDPR and Italian procedural law, a company can bring an opposition before the ordinary Italian courts within 30 days of formal notification of the decision. As of 17 September 2026, recordinglaw.com has not confirmed whether BBVA has filed or intends to file such a challenge, so the decision should not be treated as final and unappealable.

Updates

Independently fact-checked against the cited primary sources

Sources and References

  1. Garante per la protezione dei dati personali, Provvedimento n. 613 del 3 settembre 2026 (doc. web n. 10291895)(garanteprivacy.it).gov
  2. Garante per la protezione dei dati personali, Newsletter N. 551 dell'11 settembre 2026(garanteprivacy.it).gov
  3. Decreto legislativo 30 giugno 2003, n. 196, Codice in materia di protezione dei dati personali, official consolidated text on Normattiva(normattiva.it).gov
  4. Regolamento (UE) 2016/679 (GDPR), official text page of the Garante per la protezione dei dati personali(garanteprivacy.it).gov
Share: