Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Enforcement September 20, 2026 6 min

One complainant, ten notifications, EUR 5.5 million: the opt-out that was recorded and never applied

The Italian DPA fines Banco Bilbao Vizcaya Argentaria Italia EUR 5,508,000. The customer had switched the notifications off in the app and repeated it to Customer Service: the record was there, but the CRM never heard about it

In two lines

Italian DPA, decision no. 613 of 3 September 2026 (doc. web no. 10291895): EUR 5,508,000 against Banco Bilbao Vizcaya Argentaria S.A., Italian branch, for breach of Arts. 5(1)(a), 12, 21 and 24 GDPR. One complainant, at least ten in-app commercial notifications between October 2025 and May 2026.

The facts fit in a few lines. Between 2 October and 9 December 2025 the customer tells Customer Service he no longer wants commercial messages, and in parallel switches the notifications off in the app settings. In its defence the bank admits the opt-out had been taken up by its internal systems but «had not been synchronised» with the CRM unit that sends the messages. The notifications continue until May 2026, when the bank acts — after the authority's request for information.

The defence that did not hold, and why it concerns you too

The bank argued that the complainant had not used the right channels: the privacy notice listed a dedicated rights address and the DPO's, and had he used them the request would have been handled as a rights request under Arts. 15-22. The authority rejects this by pointing to Art. 12, which places on the controller the duty to FACILITATE the exercise of rights, and to EDPB Guidelines 1/2022 on the right of access (version 2.1, adopted 28 March 2023): there are no format requirements, the data subject is not obliged to use the indicated channels and may write to an official contact point of the controller. The only limit is addresses that are «entirely random or apparently incorrect».

The Customer Service sentence that became an Art. 24 breach

On 10 December 2025 Customer Service replies that only email communications can be adjusted, that the app «is the same for all customers» and that pop-up notifications cannot be removed: if he does not want them, he can ignore them. The authority notes that this statement is contradicted by the technical work the bank itself later carried out to block those very notifications. The gap between what the company does and what it tells the outside world is qualified as the result of inadequate organisational measures — and it is the second breach, of Arts. 5(1)(a) and 24. Customer Service, the authority writes, is the first point of contact between data subjects and controller.

How you get to EUR 5.5 million starting from one data subject:

  • Intrinsic seriousness LOW: one person involved, contact data, negligent breach, marketing purpose (EDPB Guidelines 4/2022 of 24 May 2023, point 60)
  • Duration: seven months, from October 2025 to May 2026
  • Controller's turnover above EUR 500 million: Art. 83(5) applies, capped at 4% of 2025 worldwide turnover
  • Mitigating: measures taken during the proceeding to stop the breach
  • Aggravating: medium degree of responsibility for failing to train Customer Service adequately
  • Aggravating: earlier decision no. 413 of 10 July 2025 (doc. web no. 10168555) for relevant breaches

What to check on Monday morning, for every client

1) Ask for the list of systems that send commercial messages and of those that record objections: if they are not the same system, ask how and how often they are synchronised, and ask for evidence of the last sync. 2) Check that an objection raised through a non-dedicated channel — switchboard, counter, chat, social — still reaches whoever processes: that path belongs in a written procedure, not in the operator's good sense. 3) Make sure every rights request gets a reply within one month under Art. 12(3): here the bank fixed the record but never answered, and the missing reply was charged separately. 4) Put the front line in the training plan: Customer Service is a processing activity, not a switchboard.

A caveat on how to read the figure

The decision was adopted on 3 September and published on 11 September 2026. The company may still settle by paying half the fine (Art. 166(8) of the Italian Privacy Code) and may oppose it before the ordinary courts within thirty days of notification, under Art. 152 of the Code and Art. 10 of Legislative Decree 150/2011. As at the date of this article it is not publicly known which route was taken: EUR 5,508,000 should therefore be read as the amount ordered, not as the amount finally collected.

Official source:Italian Data Protection Authority, decision of 3 September 2026, register of decisions no. 613, doc. web no. 10291895. Newsletter no. 551 of 11 September 2026.

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement

The vendor's bug turned into a criminal conviction

On 7 September 2026, before the Dublin Metropolitan District Court, Brown Thomas Arnotts Limited pleaded guilty to five sample charges out of twenty-one for breaches of the Irish ePrivacy Regulations. Three concerned the absence of a valid opt-out address, two the sending of marketing without valid consent. The sum paid is two thousand euro. The sum is not the point: this was a criminal prosecution.

Sep 07, 2026New 5 min
Enforcement
403million euro, and six months to comply

Google, €403 million: half the findings live in your register

On 21 September 2026 the Irish Data Protection Commission closed the inquiry it opened into Google Ireland in February 2020. Its subject: location data in three features — Web & App Activity, Location History, Location Accuracy — between 25 May 2018 and 4 February 2020. Fines totalling €403 million and six months to come into compliance. The number makes the headlines; for practitioners, the interesting part is elsewhere.

Sep 23, 2026New 6 min
Enforcement
24.000euros for an access authorised by the medical management

«Not unlawful, the medical management authorised it»: the Italian DPA says no, EUR 24,000

The case is small and the lesson is not. A hospital is at once a place of care and the employer of the same person, and when the two capacities touch, the health record becomes the handiest and most wrong tool. The employer had put it in writing to the prosecutor: that access was not unlawful, it was «carried out on the instructions of the medical management» «for the performance of the work». That is precisely the sentence the authority takes apart.

Sep 22, 2026New 6 min