BBVA Italia fined €5.5M for ignoring marketing opt-out
Italy's privacy authority says the bank kept sending in-app marketing after a customer switched it off, blaming a technical error.
By Sam Reyes · Published · Updated · 11 min read

Italy's data protection authority has fined BBVA Italia €5,508,000 for ignoring a customer's objection to marketing, overview.legal reports.
What happened
- On 2 October 2025, a customer contacted BBVA's customer service and asked to stop receiving commercial communications; the representative directed him to switch off marketing in the bank's app settings, which he did.
- The bank still sent 10 unsolicited commercial messages in the app, continuing for seven months, from October 2025 to May 2026, because the opt-out was never synced to the CRM system that sends in-app marketing, according to DataGuidance.
- The customer complained a second time on 9 December 2025. Customer service told him only email communications could be adjusted, that the app "is the same for all customers," and that the pop-up notifications "cannot be removed," according to The DPO's summary of the ruling.
- BBVA blamed a technical error affecting only that customer and said the person should have contacted its data protection officer instead.
What the regulator decided
The Garante issued its order (provvedimento n. 613) on 3 September 2026. It rejected both of BBVA's arguments. It said:
- A technical problem between the bank's systems is no excuse.
- The customer objected correctly, through the app and then through customer service.
- BBVA only acted after the regulator got involved.
It found breaches of Articles 5(1)(a), 12, 21 and 24 of the GDPR. The bank had broken the GDPR before — a previous Garante order (n. 413 of 10 July 2025) against the bank was cited as a relevant precedent, according to provvedimentigaranteprivacy.it.
The regulator's own summary states the core principle plainly: "Il titolare non può negare il diritto di opposizione al marketing limitando i canali di comunicazione" — the data controller cannot deny the right to object to marketing by limiting the channels of communication — meaning a company must honor a valid objection made through any official contact point, without requiring additional formalities, according to provvedimentigaranteprivacy.it.
Why it matters
The size of the fine for one complaint shows regulators take the right to object to marketing seriously — and that "it was a glitch" will not work as a defence. Notably, the Garante itself rated the severity of the infringement as low, since it involved only a single data subject, yet still imposed a multi-million-euro fine — reflecting how heavily Italian regulators weigh aggravating factors like a company's size, its prior violations, and inadequate staff training, according to The DPO.
Your rights
You can object to direct marketing at any time, and companies must stop. If they do not, you can complain to your data protection authority.
Why a single complaint led to a big fine
GDPR fines are not calculated per affected person. Regulators look at how serious the breach is, whether it was intentional or negligent, what steps the company took to fix it, and its history of past violations. A large bank that ignores a basic right, blames the customer and has broken the rules before is likely to be treated harshly — even if only one person complained.
The case also sends a message to the wider sector: if one customer's opt-out failed, others may have too. Regulators expect companies to check their systems properly, not treat each complaint as a one-off. The Garante's ruling specifically cited BBVA's failure to adopt adequate organizational measures — including properly training its customer service staff to recognise and process opt-out requests — as a medium-level aggravating factor, according to provvedimentigaranteprivacy.it.
How the right to object works
Article 21 of the GDPR gives everyone an absolute right to object to direct marketing. Unlike some other rights, the company cannot weigh this against its own interests — once you object, it must stop using your data for marketing.
Article 12 also requires companies to make it easy to exercise your rights. That is why the regulator rejected BBVA's argument that the customer should have written to its data protection officer: using the setting in the app was enough. The Garante also found that telling a customer a pop-up "cannot be removed" when in fact a technical fix was always possible breached the bank's duty of fairness and transparency under Article 5(1)(a), according to The DPO.
How to object effectively
- Use the opt-out setting in the app or account, and take a screenshot as proof.
- If messages continue, send a written objection by email and keep a copy.
- If the company still ignores you, complain to your national data protection authority. In Italy that is the Garante.
- Keep a timeline of every contact you make with a company's customer service about an opt-out request, including dates and the name of any representative you spoke with — this proved decisive in the BBVA case.
What readers should do
- Check your own marketing preferences on banking and retail apps you use, and confirm settings have actually taken effect by watching for further messages over the following days.
- If you have objected to marketing and still receive messages, document every instance before complaining, since regulators weigh evidence of repeated, documented objections heavily.
- Know your national data protection authority's complaint process — in the EU, complaints are free and can be filed online.
- If a company tells you an opt-out request cannot be processed through the channel you used, insist on escalation in writing rather than accepting the explanation at face value.
Sources
Article 21 in full: an absolute right, with few exceptions
The GDPR text itself is unusually blunt on this point. Article 21(2) states that where personal data is processed for direct marketing, the data subject "shall have the right to object at any time," and Article 21(3) is unconditional: "Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes" (overview.legal, GDPR Article 21 text). Unlike objections to processing based on legitimate interest, there is no balancing test a company can invoke to keep marketing someone who has objected — the obligation to stop is immediate and absolute.
Article 21(4) adds a procedural requirement relevant to the BBVA case: companies must flag the right to object "explicitly" and present it "clearly and separately from any other information" at the first point of contact (overview.legal).
This is not an isolated case
Right-to-object marketing complaints have reached European regulators before. In a 2019 case handled under GDPR's one-stop-shop cooperation mechanism, Malta's data protection authority found a controller in breach of Article 21 after a complainant's repeated objections to marketing emails were not properly recorded, partly because the company's internal process only recognized objections sent from the specific email address a customer used to register — a rigidity regulators have repeatedly criticized for making it unnecessarily hard for people to exercise their rights (Privacy Design summary of the decision).
GDPR fines for marketing and consent violations have also hit major advertising and adtech firms. France's data protection authority (CNIL) fined Criteo, a personalized-advertising company, €40 million in 2023 over failures tied to consent and user rights in its tracking practices (European Data Protection Board). As of this reporting, the independent GDPR Enforcement Tracker database lists over 3,228 publicly known GDPR fines and penalties across the EU/EEA, totalling more than €6.31 billion since the regulation took effect (GDPR Enforcement Tracker) — a scale that illustrates how routine fines for marketing, consent and rights-related breaches have become, even as individual cases like BBVA's still generate headlines because of the size of the penalty relative to the number of people affected.
How the fine compares
At €5,508,000 for a single customer's complaint, the BBVA fine stands out even within that wider pool of enforcement actions. The Garante's own assessment rated the severity of the underlying infringement as low — it affected one identified data subject over roughly seven months — yet the final penalty still ran into the millions. That outcome reflects how heavily Italian authorities weigh aggravating circumstances distinct from the scale of harm itself: the bank's size and financial capacity, a prior GDPR violation finding against it from July 2025, and what the regulator considered inadequate staff training around marketing opt-outs.
What this means for other financial institutions
Banks and other large financial services firms generally operate multiple interconnected systems — app settings, CRM platforms, email marketing tools, call-center software — that are not always synchronized in real time. The BBVA case shows that from a regulatory standpoint, that technical complexity is not a valid excuse. If a customer uses any officially sanctioned channel to object to marketing, including an in-app toggle, the burden falls on the company to make sure that objection takes effect everywhere, not on the customer to chase down every system where it might not have applied.


