Skip to content

BBVA fined €5.5M by Italy's Garante over in-app marketing

Filip LuchianencoUpdated 4 min read

Last updated: 2026-10-03

On September 3, 2026, Italy's data protection authority, the Garante per la protezione dei dati personali, fined Banco Bilbao Vizcaya Argentaria, S.A., Italian branch (BBVA) €5,508,000 in decision n. 613 (doc. web 10291895). The BBVA fine concerns one customer who switched off commercial notifications in the BBVA app and kept receiving them. The Garante announced it in newsletter n. 551 of September 11, 2026.

What did the BBVA app do after the customer opted out?

The decision (section 3.1) records "almeno dieci notifiche di comunicazioni commerciali non richieste" (at least ten unsolicited commercial notifications) between October 2025 and May 2026. The customer had set the opt-out in the app's settings, which the bank confirmed, and objected again to customer service on October 2 and December 9, 2025. The Garante found that the app setting was the bank's standard procedure for objecting to marketing.

Section 1.2 records the bank's explanation: its internal systems received the switch-off and did not synchronize it with the Customer Relationship Management (CRM) unit that sends commercial communications, "così generando un ritardo implementativo della disattivazione delle notifiche, circostanza per cui queste ultime sono erroneamente proseguite" (thus causing a delay in implementing the deactivation of the notifications, as a result of which the latter continued in error). After the Garante's request for information of April 28, 2026, the bank corrected the customer's profile; the notifications stopped from May 13, 2026.

On December 10, 2025, customer service told the customer "non possiamo rimuovere le notifiche pop-up" (we cannot remove the pop-up notifications) and that the customer "può ignorare le notifiche" (can ignore the notifications), per section 3.2. The Garante found that statement contradicted by the bank's own fix: the bank stated that it blocked the commercial notifications inside the same app.

Which GDPR articles did the Garante find infringed?

Finding GDPR articles
The objection to direct marketing was not acted on correctly or in time, and the customer received no proper reply about it 5(1)(a), 12, 21
Technical and organizational measures inadequate for fair and transparent processing, so customer service gave the customer incorrect information 5(1)(a), 24

Source: Garante decision n. 613, sections 3 and 4.

The bank argued the customer should have written to the data-rights or DPO email addresses in its privacy policy. The Garante rejected this, citing EDPB Guidelines 01/2022: the data subject "non è però tenuto a valersi di questi specifici canali" (is not required to use these specific channels). The bank stated that the sync failure affected this customer alone; the decision records that statement and makes no finding on other customers.

How did one complaint lead to a €5.5 million fine?

Sections 6.1 and 6.2 of the decision rate the seriousness as low ("basso"): one data subject, contact data only, negligence, seven months from October 2025 to May 2026. The decision then weighs turnover: above €500 million, with the cap at 4% of 2025 worldwide annual turnover under Article 83(5). Two aggravating factors count against the bank: a medium degree of responsibility for not training customer service to handle rights requests, and a prior decision against the same branch, n. 413 of July 10, 2025, which found a late reply to an access request unlawful under Articles 12(3), 12(4) and 15. The fix made during the inquiry counts as a mitigating factor.

From newsletter n. 551: "non è sufficiente che il 'no' del cliente venga registrato da un sistema se poi l'organizzazione non è in grado di garantirne l'effettiva applicazione" (it is not enough for the customer's "no" to be recorded by a system if the organization then cannot make sure it is applied).

What must BBVA do, and can it appeal?

The decision orders measures so that rights requests are easy to exercise and are handled without undue delay, with a report to the Garante within 30 days of notification. Payment is due within 30 days or, under art. 166(8) of the Italian Privacy Code, half the fine if paid within the appeal period; an appeal goes to the ordinary court within 30 days of notification (60 if the appellant resides abroad). As of October 3, 2026, the Garante's pages for this case contain no appeal notice. I did not search court records.

What a CITT scan and capture show for an in-app marketing opt-out

The failure in this decision happened inside the bank: its internal systems received the opt-out and did not pass it to the CRM unit. When I scan an Android app, the scan lists the customer-messaging SDKs found in the build, such as Braze, Airship, CleverTap, OneSignal and Salesforce Marketing Cloud, each with its file and line. A capture on a test device records the app's traffic before and after its opt-out control is used. The record includes the request the app sends when the marketing setting is switched off, with the new value and the destination host, and the responses the app receives afterward, in-app message content included. Hosts that pin their certificates are recorded as unobserved. On Android, push notifications arrive through Google Play services' connection to Firebase Cloud Messaging, separate from the app's requests. A promotional message the app downloads after the recorded opt-out is device-side evidence of the pattern the Garante describes; the server-side cause is outside what a capture records. See what a scan checks and the limits of a scan.

Related posts cover the Rodriguez v. Google verdict on data collected while Web & App Activity was off, the Garante's July 2026 Character.AI decision, and California AB 2561, which bars an app or operating system from undoing a privacy setting a user chose without the user's consent.

I run consent and marketing opt-out investigations of apps for lawyers and for researchers working with lawyers. Sign up for a CanITrustThat (CITT) account to run your own research, let us run an investigation for you, or browse the scanned apps.

App privacy law, applied to real apps.

Posts on new laws, fines and studies, and teardowns of the apps those laws apply to.

How we use your address: privacy notice. Prefer a feed reader? Use the RSS feed.