Italy Fines BBVA Bank EUR 5.5 Million Over Marketing Opt-Out
Independently fact-checked against primary sources (last audited September 17, 2026). · 4 primary sources cited on this page. How we verify our legal content

Italy's data protection authority, the Garante per la protezione dei dati personali (the national regulator that enforces the GDPR and Italy's own privacy code inside Italy), has fined the Italian branch of Banco Bilbao Vizcaya Argentaria EUR 5,508,000 after finding the bank kept sending marketing messages to a customer for seven months after he opted out, and after he repeatedly asked customer service to stop.
Verified on 17 September 2026 against the Garante's own provvedimento (decision) and its Newsletter N. 551, both fetched directly from garanteprivacy.it.
Jurisdiction scope: This article covers a decision of Italy's Garante per la protezione dei dati personali applying the EU General Data Protection Regulation (GDPR) and Italy's d.lgs. 196/2003. It describes Italian and EU law only and does not describe or compare United States law.
What the Garante Found
According to the provvedimento, a customer of BBVA's Italian branch turned off marketing notifications inside the bank's app and, on top of that, contacted customer service more than once asking that promotional messages stop. Despite that, the bank kept sending promotional communications through the app from October 2025 to May 2026, a span of roughly seven months.
The bank told the Garante that a technical synchronization failure between its internal systems and its CRM unit (the platform that manages customer communications and marketing preferences) was to blame, and that the mismatch, not a decision to keep marketing to the customer, caused the continued messages.
The Garante was not persuaded. In its own words: "Tale affermazione, però, equivale a confermare che la Società non ha dato seguito alla richiesta, seppure per un asserito difetto tecnico, nonostante l'interessato avesse correttamente esercitato la propria opposizione al trattamento." In English: this statement, the authority found, amounts to confirming that the company did not act on the request, even if due to an alleged technical defect, despite the data subject having correctly exercised the right to object to the processing.
The Right to Object and the Duty to Respond
The decision turns on two GDPR duties that sit on top of each other. Article 21 gives a person an unconditional right to object to direct marketing at any time; once they do, a controller must stop processing their data for that purpose, no exceptions and no balancing test. Article 12 separately requires a controller to facilitate that objection and to respond to it correctly and without undue delay. The Garante treated these as one continuous failure rather than two separate technical glitches: the customer exercised his right, and the bank's own systems did not carry that instruction through to the channel that kept messaging him.
The Garante also found the bank fell short of its Article 24 accountability duty, which requires a controller to put in place technical and organizational measures capable of actually delivering GDPR compliance, not just policies that assume compliance will happen. A marketing preference that is recorded in one internal system but never reaches the system that sends the messages is, in the authority's assessment, exactly the kind of gap Article 24 exists to prevent.
Why the "System Synchronization" Defense Failed
BBVA's core argument was that the continued messages were an unintended side effect of a technical break between internal platforms, not a deliberate choice to keep marketing to an opted-out customer. The Garante's provvedimento addressed that argument directly and rejected it, finding that "la Società, dunque, risulta non aver dato seguito, né riscontro, all'opposizione del reclamante in modo corretto (almeno in un primo tempo) e tempestivamente, come riconosciuto anche nella nota fornita a questo Ufficio." In English: the company is found not to have followed up on, or responded to, the customer's objection correctly (at least at first) and promptly, as the bank's own note to the authority acknowledged.
The reasoning is straightforward: under the GDPR, a controller cannot point to an internal engineering problem to explain away a data subject's exercised right. The obligation runs to the outcome, that the marketing stops, not to whichever internal system happened to receive the opt-out first. A synchronization gap between an app's preference center and a CRM platform is an internal architecture choice, and the bank, not the customer, bears the risk that the architecture fails to carry an objection through.
The Sanction and What Comes Next
The EUR 5,508,000 fine was set under the Garante's power to impose administrative fines pursuant to Articles 58(2)(i) and 83 of the GDPR and Article 166 of Italy's Codice. Separately, Article 157 of the Codice is the basis for the Garante's order that the bank report back within 30 days of notification describing the corrective measures it has actually implemented, alongside the general order to adopt adequate technical and organizational measures and to ensure rights requests are satisfied promptly and correctly going forward. The decision itself is also published on the Garante's website, which is standard practice for its sanctioning decisions and adds a public transparency element beyond the fine.
Under Article 78 of the GDPR and Articles 152 of the Codice and 10 of d.lgs. 150/2011, a sanctioned company can bring an opposition before the ordinary Italian courts, filed with the competent tribunale (court), within 30 days of formal notification of the decision. As of 17 September 2026, recordinglaw.com has not been able to confirm whether BBVA has filed, or intends to file, such an opposition, so the decision should be treated as recent and potentially still within its challenge window rather than as final and unappealable.
Analysis: Why This Matters
This is analysis from the Recording Law Editorial Team. The decision is a clean illustration of a principle that applies well beyond banking marketing: once a person exercises the GDPR's right to object to direct marketing, the burden shifts entirely to the company to make sure every system that touches that person's data actually stops, and an internal technical failure is not a defense to that burden, only a fact about how the failure happened. Companies operating in Italy and the broader EU that route marketing decisions through multiple internal systems, an app, a call center log, a CRM platform, should read this decision as confirmation that a broken handoff between those systems is treated as the company's own compliance failure, not as an excusable accident.
The fine also sits inside a broader enforcement pattern the Garante has pursued against financial institutions and other large controllers over how they handle individual rights requests, an area the authority tracks separately from data breach enforcement. For the wider framework this decision sits inside, see the Italy data privacy laws overview and, for readers weighing whether recording a customer service call for compliance purposes carries its own separate rules in Italy, the Italy recording laws page.
This article is general information about a decision by Italy's Garante per la protezione dei dati personali under the GDPR and Italy's d.lgs. 196/2003. It covers Italian and EU law only, is not legal advice, and does not create an attorney-client relationship. Anyone with a specific claim or concern involving Italian or EU data protection law should consult a qualified lawyer licensed in that jurisdiction.
Related articles
Last updated: 2026-09-17. This is a developing story; we update it as the record changes.
Frequently Asked Questions
What did the Garante fine BBVA's Italian branch for?
For continuing to send marketing messages through its banking app to a customer who had turned off marketing notifications and separately asked customer service to stop, over a period from October 2025 to May 2026. The Garante found this breached the customer's GDPR right to object to direct marketing and the bank's duty to respond to that objection correctly and promptly.
How much was the fine, in what currency?
EUR 5,508,000 (euro), set out in Provvedimento n. 613 del 3 settembre 2026, doc. web n. 10291895, issued by Italy's Garante per la protezione dei dati personali.
Which company was actually sanctioned?
Banco Bilbao Vizcaya Argentaria, S.A., succursale italiana, the Italian branch of the Spanish bank BBVA, based in Milan.
Why did the bank's explanation not work as a defense?
The bank said a synchronization failure between its internal systems and its CRM (customer relationship management) unit caused the continued messages. The Garante found that a technical explanation for how the failure happened does not excuse the failure itself: once the customer exercised his right to object, the bank was responsible for making sure every system that could message him actually stopped.
Is the decision final, or can BBVA still appeal it?
Under Article 78 of the GDPR and Italian procedural law, a company can bring an opposition before the ordinary Italian courts within 30 days of formal notification of the decision. As of 17 September 2026, recordinglaw.com has not confirmed whether BBVA has filed or intends to file such a challenge, so the decision should not be treated as final and unappealable.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- Garante per la protezione dei dati personali, Provvedimento n. 613 del 3 settembre 2026 (doc. web n. 10291895)(garanteprivacy.it).gov
- Garante per la protezione dei dati personali, Newsletter N. 551 dell'11 settembre 2026(garanteprivacy.it).gov
- Decreto legislativo 30 giugno 2003, n. 196, Codice in materia di protezione dei dati personali, official consolidated text on Normattiva(normattiva.it).gov
- Regolamento (UE) 2016/679 (GDPR), official text page of the Garante per la protezione dei dati personali(garanteprivacy.it).gov