BBVA fined 5.5 million euros after an app opt-out never reached its marketing tool

Ulf Aslak Lai photo Ulf Aslak Lai Published 10 Oct 2026 AI drafted 8 min read
BBVA fined 5.5 million euros after an app opt-out never reached its marketing tool

In October 2025 a BBVA customer in Italy objected to the bank's marketing, both to customer service and through the notification setting in its mobile app. The app saved the setting, but the system that sends BBVA's promotions never received it, so at least ten promotional pop-ups reached him over the next seven months. On 3 September 2026, Italy's data protection authority, the Garante, fined BBVA 5,508,000 euros for it 1. The same gap exists in many software products, B2B ones included: the marketing preference is saved in the product's own database, while promotions such as upgrade prompts go out from a separate tool that keeps its own list. Under the GDPR, an objection to marketing has to stop the marketing in every system that sends it, and a choice saved in one system and ignored by another does not meet that rule.

What did the Italian regulator fine BBVA for?

It fined the bank for failing to act on one customer's objection to marketing, and for giving him wrong information about it. The decision 1 sets out what happened. The EDPB, the board where the EU's data protection regulators agree common positions, published an English summary on 9 October 3.

  • October 2025. The customer objects to marketing to customer service (on 2 October) and switches off commercial notifications in the app's settings.
  • 10 December 2025. After a second objection, customer service tells him the pop-ups cannot be removed, the app "is the same for everyone", and he can ignore them.
  • 13 May 2026. Only after the Garante asks BBVA for an explanation does the bank fix his profile, and the notifications stop.

The Garante found three breaches, each also a breach of Article 5(1)(a), the GDPR principle that data is handled fairly and transparently 1:

  • The objection was ignored. Article 21 of the GDPR gives everyone the right to object to the use of their data for marketing, and BBVA did not act on it.
  • The customer got no proper answer. Article 12 requires a company to tell the person what it did about their request. While the objection was being ignored, BBVA's replies only explained how to use the app setting. It apologised once it understood the problem.
  • Customer service gave false information. Telling him the pop-ups could not be switched off was, for the Garante, a failure of the processes and training a company must have under Article 24 to make sure it follows the GDPR.

Does your legal documentation match what you ship?

Lawcel watches your product changes and flags the moment your terms or privacy policy fall out of sync, then proposes the edits for your team to approve and publish.

Get started

Why do promotions keep coming after someone opts out?

Usually because the setting and the sender live in different systems. A product stores the user's choice in its own database, and promotional messages go out from a separate messaging tool that keeps its own record of who may be contacted. Unless something passes the choice across, the messaging tool keeps sending. At BBVA the sender was its CRM, and the bank told the Garante the customer's choice "was duly registered in the bank's systems" but never synchronised to it (my translation from Italian) 1. The Garante's answer was that BBVA's own explanation admitted the marketing had continued: a technical fault can explain why an objection was ignored, but the company is still responsible for the result. Article 21(3) says that once someone objects, "the personal data shall no longer be processed for such purposes" 2.

Common messaging tools keep each channel's opt-out separate:

Each tool controls its own channel, so the product has to tell each one what the user chose. Two kinds of opt-out need telling apart here. A channel preference, such as an email unsubscribe link or a push toggle, applies to that channel. An objection to marketing, such as "stop sending me promotions", has to stop marketing in every channel. The BBVA customer objected to the bank's marketing in general, and the pop-ups in the app were part of it. My rule for your own settings page: read each label the way a user would. A setting called "Marketing" or "Offers and promotions" is an objection to all of it, so the email tool must honour it too. A setting called "Newsletter", or a push permission switched off on the phone, covers that one channel. When the label is unclear, treat it as general. I described the same problem for email in the post on unsubscribes that stop at one tool.

In B2B software, an objection from a customer's employee counts the same as one from a consumer, and in my reading an in-app pitch to upgrade a plan is marketing.

Can a company require objections to come through one email address?

No. BBVA argued that the customer should have written to one of the two addresses its privacy policy lists for privacy requests, including its data protection officer's, and that a request sent there would have been handled as a formal GDPR request 1.

The Garante rejected that. Article 12(2) requires a company to "facilitate the exercise of data subject rights" 2. The EDPB's guidelines on the right of access, whose rule on request channels the Garante applied here to an objection, say a person "is not required to use these specific channels and may instead send the request to an official contact point of the controller" 4. The app setting was BBVA's own standard way to object, so the customer had used exactly the route the bank gave him, and his messages to customer service only confirmed it.

Why is the fine 5.5 million euros for one person?

Because BBVA is large. The Garante rated the breach's seriousness as low: one person, seven months, contact data only, and negligence rather than intent 1. The amount follows from BBVA's size, and a small company making the same mistake would face a far smaller number.

GDPR fines for breaching people's rights are capped at 20 million euros or 4% of worldwide annual turnover, whichever is higher 2. For a bank, 4% of turnover is far above 20 million euros. The EDPB's fining guidelines, which the Garante cited, start a low-seriousness case at up to 10% of that cap 5. The Garante then credited BBVA for fixing the problem during the investigation, and counted against it the untrained customer service and an earlier breach decision from July 2025, about a late answer to a request for data 1.

For a small company the same method produces a much smaller figure: with turnover of 2 million euros or less, the guidelines let a regulator scale the starting point down to a few thousand euros, although it does not have to 5. A small company can also be ordered to fix its process, as BBVA was. I covered what else decides between a fine and a formal warning in an earlier post on the EDPB's fining guidelines.

What should a software company check?

If your product sends promotions inside the app, by push or by email, every opt-out has to reach each tool that sends the marketing it covers. A general objection has to stop all of it. Your support team has to be able to make that happen too. Otherwise one complaint from one user is enough for a regulator to open a case. I would expect support to be where this fails first: an engineer can test a sync, but nobody tests whether a support agent knows the setting exists. (Email and push marketing can also need consent in advance under the EU's separate ePrivacy rules, which this post does not cover.)

  • List every tool that can send a promotion. Include in-app message and banner tools, push services, product tours that pitch upgrades, and the email platforms. For each one, write down where it reads the user's marketing preference from.
  • Test one opt-out end to end. Switch off marketing on a test account in your app's settings, then check in the user record of each tool that setting covers that the account is now excluded. A setting that changed only in your database is the BBVA failure.
  • Treat a support message as an objection. "Stop sending me promotions", sent to support or in a chat, is an objection to marketing under Article 21. Give support a way to switch marketing off for a user, and a rule to do it the same day.
  • Check support's saved replies against the product. BBVA's customer service said the pop-ups could not be switched off. If your support team answers questions about notifications, make sure their answers match the real settings.
  • Wire the opt-out into a new sending tool before it goes live. A newly added tool usually starts with its own opt-out list, empty. It is also a new recipient of personal data that your privacy policy, and in B2B your sub-processor list, may need to name. Lawcel, a compliance tool that reads pull requests and reports how each change affects your legal documents, can flag that part; the opt-out sync is still your team's work.
  • Reply to the person. Article 12(3) requires you to tell someone what you did with their request "without undue delay", and within one month at the latest 2. A short confirmation that marketing is off, in every channel it reached, meets it.

FAQ

The Italian regulator treated them as such in the BBVA case: promotional pop-ups inside the app were the marketing the customer objected to, and continuing them broke Article 21.
You can offer a dedicated address, but you cannot ignore an objection made through your app settings or your support team. The regulator rejected that exact argument from BBVA.
At once. Article 21(3) says the data "shall no longer be processed" for marketing after an objection, with no grace period. The one-month limit in Article 12(3) is for telling the person what you did.
Probably not. Under the EDPB's method a low-seriousness case starts at up to 2 million euros, and for turnover of 2 million euros or less a regulator may cut that to about 8,000 euros at most. The cut is optional.

References

  1. Garante per la protezione dei dati personali, Provvedimento n. 613 del 3 settembre 2026, Banco Bilbao Vizcaya Argentaria, S.A., succursale italiana (doc. web n. 10291895) - accessed 10 Oct 2026
  2. Regulation (EU) 2016/679 (General Data Protection Regulation) - accessed 10 Oct 2026
  3. EDPB, Italian DPA fines BBVA EUR 5 508 000 for failing to respect a customer's objection to direct marketing, 9 October 2026 - accessed 10 Oct 2026
  4. EDPB, Guidelines 01/2022 on data subject rights: Right of access, version 2.1, adopted 28 March 2023 - accessed 10 Oct 2026
  5. EDPB, Guidelines 04/2022 on the calculation of administrative fines under the GDPR, version 2.1, adopted 24 May 2023 - accessed 10 Oct 2026

About the author

Ulf Aslak Lai

Ulf Aslak Lai

Co-founder, Chief Technology Officer

Ulf is Co-founder and CTO at Lawcel. He leads engineering architecture for connectors, analysis pipelines, and the safeguards needed when automation touches regulated customer content.

  • Platform architecture
  • Data governance
  • ML/AI systems
GDPR

An unsubscribe must stop marketing email from every tool you use, under EU and UK law

Under EU and UK law, every marketing email must offer a free, easy way out, and an opt-out has to take effect in every tool that sends the marketing it covers: the newsletter, CRM sequences and product email. Withdrawing consent must be as easy as giving it, so if one tick put someone on several lists, one step should take them off all of them.

GDPR

Every contact you publish for GDPR data requests must be easy to use on its own

Spain's regulator fined Securitas Direct 100,000 euros for a paid 902 phone line on its camera signs, even though its privacy policy listed a free email address. It judged each route for data requests on its own. For a software product, a deletion route behind a login can fail the same test, and a request sent to support@ counts from the day it arrives.

GDPR

A GDPR fix counts for more if you made it before you heard from the regulator

The date you repaired a GDPR problem decides how much the repair is worth to you. One made before you learned an authority was investigating counts for more than the same work done afterwards. Not knowing the rule is negligence either way, and doing what the law already requires earns no credit. New draft guidelines from the European Data Protection Board set out how.

GDPR

Does your new feature need a DPIA? Decide before you ship, and write the answer down.

A data protection impact assessment (DPIA) is mandatory under GDPR Article 35 where processing is likely to result in a high risk to people, and it belongs before that processing starts. Guidance from the EU's regulators gives nine criteria and says meeting two usually requires one. Your national regulator also publishes a mandatory list of its own. If a feature needs none, record why.