In two lines
Italian DPA, decision no. 613 of 3 September 2026 (doc. web no. 10291895): EUR 5,508,000 against Banco Bilbao Vizcaya Argentaria S.A., Italian branch, for breach of Arts. 5(1)(a), 12, 21 and 24 GDPR. One complainant, at least ten in-app commercial notifications between October 2025 and May 2026.
The facts fit in a few lines. Between 2 October and 9 December 2025 the customer tells Customer Service he no longer wants commercial messages, and in parallel switches the notifications off in the app settings. In its defence the bank admits the opt-out had been taken up by its internal systems but «had not been synchronised» with the CRM unit that sends the messages. The notifications continue until May 2026, when the bank acts — after the authority's request for information.
The defence that did not hold, and why it concerns you too
The bank argued that the complainant had not used the right channels: the privacy notice listed a dedicated rights address and the DPO's, and had he used them the request would have been handled as a rights request under Arts. 15-22. The authority rejects this by pointing to Art. 12, which places on the controller the duty to FACILITATE the exercise of rights, and to EDPB Guidelines 1/2022 on the right of access (version 2.1, adopted 28 March 2023): there are no format requirements, the data subject is not obliged to use the indicated channels and may write to an official contact point of the controller. The only limit is addresses that are «entirely random or apparently incorrect».
The Customer Service sentence that became an Art. 24 breach
On 10 December 2025 Customer Service replies that only email communications can be adjusted, that the app «is the same for all customers» and that pop-up notifications cannot be removed: if he does not want them, he can ignore them. The authority notes that this statement is contradicted by the technical work the bank itself later carried out to block those very notifications. The gap between what the company does and what it tells the outside world is qualified as the result of inadequate organisational measures — and it is the second breach, of Arts. 5(1)(a) and 24. Customer Service, the authority writes, is the first point of contact between data subjects and controller.
How you get to EUR 5.5 million starting from one data subject:
- Intrinsic seriousness LOW: one person involved, contact data, negligent breach, marketing purpose (EDPB Guidelines 4/2022 of 24 May 2023, point 60)
- Duration: seven months, from October 2025 to May 2026
- Controller's turnover above EUR 500 million: Art. 83(5) applies, capped at 4% of 2025 worldwide turnover
- Mitigating: measures taken during the proceeding to stop the breach
- Aggravating: medium degree of responsibility for failing to train Customer Service adequately
- Aggravating: earlier decision no. 413 of 10 July 2025 (doc. web no. 10168555) for relevant breaches
What to check on Monday morning, for every client
1) Ask for the list of systems that send commercial messages and of those that record objections: if they are not the same system, ask how and how often they are synchronised, and ask for evidence of the last sync. 2) Check that an objection raised through a non-dedicated channel — switchboard, counter, chat, social — still reaches whoever processes: that path belongs in a written procedure, not in the operator's good sense. 3) Make sure every rights request gets a reply within one month under Art. 12(3): here the bank fixed the record but never answered, and the missing reply was charged separately. 4) Put the front line in the training plan: Customer Service is a processing activity, not a switchboard.
A caveat on how to read the figure
The decision was adopted on 3 September and published on 11 September 2026. The company may still settle by paying half the fine (Art. 166(8) of the Italian Privacy Code) and may oppose it before the ordinary courts within thirty days of notification, under Art. 152 of the Code and Art. 10 of Legislative Decree 150/2011. As at the date of this article it is not publicly known which route was taken: EUR 5,508,000 should therefore be read as the amount ordered, not as the amount finally collected.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free