Italian DPA fines BBVA EUR 5 508 000 for failing to respect a customer’s objection to direct marketing

The Italian Data Protection Authority (DPA) investigated BBVA, a multinational Spanish banking group, following a complaint from a customer who continued to receive promotional communications through the bank’s mobile app despite having objected to direct marketing. BBVA explained that the customer’s choice had been correctly recorded but that a technical failure prevented synchronisation between its internal systems and the Customer Relationship Management unit responsible for sending commercial communications. Controllers must facilitate the exercise of data subject rights and cannot disregard a valid request merely because it was not submitted through a preferred channel. In particular, Customer Service provided incorrect information by telling the customer that promotional pop-up notifications in the app could not be disabled, although BBVA subsequently demonstrated that they could be stopped. The DPA ordered BBVA to adopt appropriate technical and organisational measures to facilitate the exercise of data subject rights and to ensure that requests are handled correctly and without undue delay. When determining the fine, the DPA considered that the infringement concerned one data subject, lasted seven months and involved contact data for marketing purposes.

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source