To ensure the best browsing experience, please enable JavaScript in your web browser. Without it, many website features are inaccessible.


Total Tests:
485,773,462
737,046
130,956

BBVA Italia Fined €5.5M For Ignoring Customer’s Privacy Request

September 15, 2026

Read also: Telia fined for accidentally deleting data; a payment processor fined 12M over fraudulent payment processing; and more.

Views: 755 Read Time: 4 min.

BBVA Italia Fined €5.5M For Ignoring Customer’s Privacy Request

BBVA Italia fined €5.5M for ignoring the customer’s privacy request

Italian data protection authority Garante has issued a series of fines targeting several entities for various data protection violations.

In particular, Banco Bilbao Italia (BBVA) was fined more than €5.5 million for sending promotional messages to a customer after they had clearly said “no.” The messages continued for seven months because of a technical problem between the bank’s systems. The regulator said that recording a customer’s refusal is not enough and that the bank must make sure the decision is respected across all its systems. BBVA was also ordered to improve its technical and organizational procedures for handling customers’ privacy requests.

The watchdog has also fined the University Health Authority of Central Friuli (ASUFC) in Udine €24,000 because hospital staff could access employees’ medical records without being involved in their treatment. The system lacked proper access controls and alerts. ASUFC was ordered to improve security and monitoring.

ASIS Trento, the public special agency that manages and maintains sports facilities for the Municipality of Trento, was penalized €8,000 for using cameras in locker rooms to prevent theft. The cameras violated privacy rules because locker rooms are areas where people have a high expectation of privacy, the regulator said. ASIS removed the cameras, improved notices, and reduced data retention.

Last but not least, Emilia-Romagna Regional Employment Agency was fined €30,000 for publishing the names of people registered with employment centers during a hospital recruitment process. The publication could reveal sensitive personal information. The authority said the agency should have used anonymization instead of publishing personal data online.

Grindr settles UK privacy lawsuit for £26 million

LGBTQ+ dating app Grindr has agreed to pay £26 million (€30.3 million) to settle a UK lawsuit over allegations that it shared sensitive user information, including HIV status, with advertisers.

The lawsuit was filed in April 2024 on behalf of about 12,000 UK users. The alleged data-sharing took place before 2020, when Grindr was owned by Chinese company Kunlun.

Under the settlement, Grindr will pay £13 million (~€15.2 million) by the end of December 2026 and another £13 million by the end of March 2027.

Grindr has denied the allegations and said the settlement does not include an admission of liability. The company said it has significantly changed its privacy practices since 2020 and remains committed to protecting users' data.

Tech consultancy Extia fined €300,000 for GDPR violations

France’s data protection authority, the Commission nationale de l’informatique et des libertés (CNIL), has fined IT and engineering consultancy Extia €300,000 for failing to properly handle individuals’ requests to have their personal data deleted under the European Union’s General Data Protection Regulation (GDPR).

The CNIL investigation followed several complaints in 2024 from former Extia employees and job applicants who reported difficulties exercising their “right to be forgotten” under Article 17 of the GDPR.

The authority found that Extia received 265 erasure requests in 2024, primarily from job candidates and former employees. More than three-quarters of the requests were either not processed or were not handled satisfactorily, according to the CNIL.

Extia argued that many requests involved candidates whose personal data had already been automatically deleted. However, the CNIL said that even if information was deleted, the company is still required to inform people about the result of their requests.

The authority found Extia in breach of Article 17 for failing to adequately process data deletion requests and Article 12 for failing to communicate the results to data subjects.

The CNIL noted that Extia introduced corrective measures, including deleting the relevant data and informing affected individuals of the action taken. Despite the measures, the authority imposed the €300,000 fine over the company’s previous failures to comply with GDPR requirements.

ImmuniWeb Newsletter

Get Cybercrime Weekly, invitations to our events and webinars in your inbox:


Private and Confidential Your data will stay private and confidential

Swedish telecom operator Telia fined SEK 1M after accidentally deleting data

Major Swedish multinational telecommunications operator Telia has been fined SEK 1 million (around €88,600) by the Swedish Post and Telecom Agency (PTS) after the company inadvertently deleted data stored for law enforcement purposes. The incident resulted from a software error, which caused stored data to be deleted earlier than it was supposed to be.

The data was kept for law enforcement purposes and should have been stored for ten months. However, after a software update, some data was deleted after just ten days.

As a result, around 100 questions from law enforcement agencies may have received incorrect answers. Telia may have said that it had no subscriber linked to a specific IP address, even though one may have existed, the regulator noted.

The error was discovered about ten months later, and Telia reported the incident to the PTS. The authority said the incident created a risk of harm, although there is no evidence that actual harm occurred. Nevertheless, the agency decided that Telia must pay a penalty of SEK 1 million.

ImmuniWeb can help you to prevent data breaches and meet regulatory requirements.

A payment processor fined 12M over fraudulent payment processing

The US Federal Trade Commission (FTC) has taken action against payment processor Humboldt Merchant Services, accusing the company of knowingly processing payments for more than 1,000 shady merchants linked to fraudulent businesses.

Under a proposed order, Humboldt will pay $12 million in consumer redress and will be permanently barred from processing payments for certain high-risk merchants. According to the FTC, Humboldt opened accounts for shell companies despite signs that they were being used to support unauthorized billing scams and other fraud.

The FTC also alleges that many of the accounts had extremely high chargeback rates. In some cases, Humboldt allegedly moved transactions to a lower-risk bank identification number to increase the chances that payments would be approved.

The proposed order would prohibit Humboldt from processing payments for straw companies, merchants flagged for fraud or excessive chargebacks, businesses that have faced law enforcement action, and certain high-risk e-commerce companies. The company would also be banned from helping merchants provide false information or evade fraud and risk monitoring systems.

Separately, the authority fined global payment processor Nuvei $4.85 million for processing payments for businesses involved in fraudulent activities, including tech-support scams. The proposed order prohibits Nuvei from providing payment services to anyone selling tech support products or services through telemarketing or deceptive pop-up messages claiming that a computer or other device has security or performance problems.

Nuvei is also banned from using false or misleading information to obtain merchant accounts or payment-processing services, as well as from using tactics like load balancing to evade fraud or risk-monitoring systems used by banks and credit card networks.

As part of the settlement, Nuvei is required to provide money for consumer refunds and strengthen its screening and monitoring of merchants to help prevent fraudulent businesses from using its payment services.

What’s next:

Talk to an Expert