Rotten Company

BBVA EUR 5 million GDPR fine for transparency and consent failures

Company: Banco Bilbao Vizcaya Argentaria, S.A.

Summary

Spain's Data Protection Agency fined Banco Bilbao Vizcaya Argentaria in December 2020 for GDPR infringements concerning transparency and consent. The AEPD found that BBVA used imprecise privacy-policy terminology, provided insufficient information regarding categories of personal data processed and failed to obtain valid consent in connection with promotional communications. The total sanction was EUR 5 million under proceeding PS/00070/2019. Source: https://www.aepd.es/ and https://cedpo.eu/1985-2/