The Italian authority sanctions Banco Bilbao Vizcaya Argentaria for non-compliance with the rights of objection to commercial communications

Failure to comply with a request to object to marketing, justified by a technical internal synchronization defect, constitutes a violation of the data subject's rights, aggravated by the incorrect information provided by the customer service about the technical impossibility to comply with the request.

Facts and context

The Italian data protection authority (Garante per la protezione dei dati personali - GPDP) has today published a sanction decision against the Italian branch of Banco Bilbao Vizcaya Argentaria, S.A. for breaches related to the management of the right to object to commercial marketing.

The case originated from a complaint by a user who continued to receive commercial communications in the bank's mobile application, although he had disabled this option and expressed his objection.

Grounds for the decision

  • Obligation to respect the right to object and to facilitate the exercise of rights (Article 5(1)(a), 12 and 21 of the GDPR): The authority found that the company did not comply with the objection of the data subject, expressed both via the app settings and with customer service. The company argued that the complainant had not used the dedicated email addresses, but the authority rejected this argument relying on the European Data Protection Board (EDPB) guidelines 1/2022, which specify that a request can be addressed to an official contact point and that the controller must facilitate its exercise. The technical synchronization failure between internal systems and the customer relationship management tool, invoked by the company, does not exempt it from responsibility. The failure to provide an appropriate and timely response to the data subject was also noted.
  • Obligation to ensure lawfulness, fairness and transparency of processing (Article 5(1)(a) and 24 of the GDPR): The authority noted that the company's customer service wrongly informed the complainant that it was technically impossible to disable commercial notifications in the app, inviting him to ignore them. This information proved false, as the company subsequently made the necessary technical correction. The authority considered that this erroneous communication, resulting from inadequate organizational measures, constituted a breach of the principles of fairness and transparency, customer service being the first point of contact for data subjects.

Decision of the authority

Consequently, the authority imposed an administrative fine on Banco Bilbao Vizcaya Argentaria, S.A. (the amount is not specified in the excerpt of the decision).

Furthermore, the authority ordered the company to adopt appropriate technical and organizational measures to facilitate the exercise of data subjects' rights and to respond to their requests without undue delay and properly. The company must communicate the initiatives taken to the authority within 30 days.

Lessons learned

This decision reminds that:

  • A data subject can validly exercise their rights via any official contact point of the controller, such as a customer service, and is not required to use exclusively the dedicated channels specified in the privacy policy.
  • An internal technical defect, such as a database synchronization problem, does not constitute a valid excuse for failing to respect the exercise of a person's right to object.
  • Teams in contact with customers must be properly trained on data protection procedures, as providing inaccurate information on rights management constitutes a breach of transparency and fairness obligations.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire