[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_M2e4sGjvAlvhL8xONll50EHFqWC1Te4x9uXZDyzYL8":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"605f929a-b17c-4012-876d-65748acd1baf","Garante per la protezione dei dati personali (Italy) - 10273659","garante-per-la-protezione-dei-dati-personali-italy-10273659-da05da","← Older revision Revision as of 09:03, 1 September 2026 (One intermediate revision by the same user not shown) Line 28: Line 28: |Date_Published= |Date_Published= |Year= |Year= |Fine=120000.0 |Fine=120.000 |Currency=EUR |Currency=EUR Line 106: Line 106: === Facts === === Facts === The DPA received several complaints from data subjects concerning Experian Italia S.p.A (the controller) an Italian credit information system. The controller was processing the personal data of data subjects for the purpose of verifying the creditworthiness of potential customers of two energy suppliers. As a result of the risk profiles attributed to them, data subjects were declined the supply of energy. The DPA received several complaints from data subjects concerning Experian Italia S.p.A (the controller) an Italian credit information system. The controller was processing the personal data of data subjects for the purpose of verifying the creditworthiness of potential customers of two energy suppliers. As a result of the risk profiles attributed to them, data subjects were declined the supply of energy. When data subjects requested access from the controller to their data under [[Article 15 GDPR|Article 15 GDPR]], they were informed that their databases did not contain negative information or adverse events which would justify the denial of energy supply. When data subjects requested access from the controller to their data under [[Article 15 GDPR]], they were informed that their databases did not contain negative information or adverse events which would justify the denial of energy supply. The DPA conducted an investigation, and found that the controller transmits, to the processor, a file which was initially designed to include extensive details about variables used to calculate the scores, and only later limited to the information necessary to calculate the score. The DPA conducted an investigation, and found that the controller transmits, to the processor, a file which was initially designed to include extensive details about variables used to calculate the scores, and only later limited to the information necessary to calculate the score. Further, the DPA found that the controller limited its responses to data subjects, only to the personal data present in the credit information system, and did not provide reference to the generated score and sub-scores assigned to them. The DPA further established that even when a data subject was not present in the credit information system, a score was nevertheless assigned to them. Further, the DPA found that the controller limited its responses to data subjects, only to the personal data present in the credit information system, and did not provide reference to the generated score and sub-scores assigned to them. The DPA further established that even when a data subject was not present in the credit information system, a score was nevertheless assigned to them. The controller claimed that unless the requests by the data subjects pertained specifically to the scores, their response, providing the data present in the credit information system, was adequate. The controller further emphasised that, as a result of strengthening their internal procedures they implemented a layered approach within which only upon request by the data subject, would the controller provide them with more detail and comprehensible information. The controller claimed that unless the requests by the data subjects pertained specifically to the scores, their response, providing the data present in the credit information system, was adequate. The controller further emphasised that, as a result of strengthening their internal procedures they implemented a layered approach within which only upon request by the data subject, would the controller provide them with more detail and comprehensible information. === Holding === Firstly, the DPA held that the responses provided by the controller to the data subjects were inadequate and incomplete, as they did not provide any information as to information pertaining to the score, details about the criteria used to determine the score, nor the method used to generate the score. Similarly, the DPA emphasised that in implementing a layered approach the controller further limited the right of access to data subjects, and added no value to their new procedures. Thus, the DPA found the controller in violation of [[Article 12 GDPR]] and [[Article 15 GDPR]], as the controller failed in its response to respond in a way which helps the data subject understand what and how their personal data was used. Additionally, the DPA held that the use of the new internal procedure and persistent inadequate responses, prevented data subjects from determining the lawfulness, fairness and accuracy of the data violating [[Articles 5(1)(a) GDPR|Article 5(1)(a) GDPR]]. This undermined their ability to exercise their right to rectification pursuant to [[Article 16 GDPR]], and right to obtain human intervention, express their opinion and challenge the decision made, pursuant to [[Article 22 GDPR|Article 22(3) GDPR]]. The DPA found the controller in violation of the principle of data minimisation pursuant to [[Article 5 GDPR|Article (5)(1)(c) GDPR]]. This was based on the the fact that the controller failed to implement adequate technical and organisational measures specific to identifying the procedures which define the methods whereby the data necessary to generate the scores are transmitted. Furthermore, the DPA held that the controller failed to implement default settings ensuring only the necessary data is processed for the generation of the score. Finally, the DPA found a violation of privacy by design and default in accordance with [[Article 25 GDPR]] as the controller used a file format not designed specifically for the utilities sector, failing to ensure adequate and effective data protection by design and default. === Holding === The DPA imposed a fine of €120.000 pursuant to [[Article 83 GDPR]] taking into account, inter alia, the fact that this affected 561 data subjects. The DPA further ordered the controller revise their internal procedures to include the logic and criteria used, to ensure data subject can fully exercise their rights. Firstly, the DPA held that the responses provided by the controller to the data subjects were inadequate and incomplete, as they did not provide any information as to information pertaining to the score, details about the criteria used to determine the score, nor the method used to generate the score. Secondly, the DPA emphasised that in implementing a layered approach the controller limited the right of access to data subjects, and added no value to their new procedures. Thus, the DPA found the controller in violation of Articles 5(1)(a), 12 and 15 GDPR, as the controller failed to describe the score generating method procedure and principles in a way which helps the data subject understand what and how their personal data was used. Similarly, the DPA held that the use of the new internal procedure and persistent inadequate responses, prevented data subjects from determining the lawfulness, fairness and accuracy of the data. This undermined their ability to exercise their right to rectification pursuant to [[Article 16 GDPR|Article 16 GDPR]], and right to obtain human intervention, express their opinion and challenge the decision made, pursuant to Article 22(3). The DPA found the controller in violation of the principle of data minimisation pursuant to Article (5)(1)(c) GDPR. This was based on the the fact that the controller failed to implement adequate technical and organisational measures specific to identifying the procedures which define the methods whereby the data necessary to generate the scores are transmitted. Furthermore, the DPA held that the controller failed to implement default settings ensuring compliance with data minimisation, that is, that only the necessary data is processed. Finally, the DPA found a violation of privacy by design and default in accordance with [[Article 25 GDPR|Article 25 GDPR]]. Particularly, as the controller used a file format not designed specifically for the utilities sector, allowing for the transmission of more information than required for the purposes of processing such data. The DPA imposed a fine of €120.000 pursuant to [[Article 83 GDPR|Article 83 GDPR]] taking into account, inter alia, the fact that this affected 2.094 data subjects. The DPA further ordered the controller revise their internal procedures to include the logic and criteria used, to ensure data subject can fully exercise their rights. == Comment == == Comment ==","The Italian Data Protection Authority (Garante) has fined Experian Italia S.p.A. €120,000 for violating GDPR. The company processed personal data for creditworthiness checks, leading to energy supply denials for some individuals. The DPA found Experian's responses to data access requests were inadequate, failing to provide details about score generation and criteria. Violations included inadequate access rights, data minimization, and privacy by design.","Experian Italia fined €120,000 by Italian DPA for GDPR violations.","Help Garante per la protezione dei dati personali (Italy) - 10273659: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 08:50, 1 September 2026 view sourceSf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators37 edits Tag: Decisions [1.0] Latest revision as of 09:03, 1 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators37 editsmTag: Visual edit (One intermediate revision by the same user not shown)Line 28: Line 28: |Date_Published=|Date_Published= |Year=|Year= |Fine=120000.0|Fine=120.000 |Currency=EUR|Currency=EUR Line 106: Line 106: === Facts ====== Facts === The DPA received several complaints from data subjects concerning Experian Italia S.p.A (the controller) an Italian credit information system. The controller was processing the personal data of data subjects for the purpose of verifying the creditworthiness of potential customers of two energy suppliers. As a result of the risk profiles attributed to them, data subjects were declined the supply of energy.The DPA received several complaints from data subjects concerning Experian Italia S.p.A (the controller) an Italian credit information system. The controller was processing the personal data of data subjects for the purpose of verifying the creditworthiness of potential customers of two energy suppliers. As a result of the risk profiles attributed to them, data subjects were declined the supply of energy. When data subjects requested access from the controller to their data under [[Article 15 GDPR|Article 15 GDPR]], they were informed that their databases did not contain negative information or adverse events which would justify the denial of energy supply. When data subjects requested access from the controller to their data under [[Article 15 GDPR]], they were informed that their databases did not contain negative information or adverse events which would justify the denial of energy supply. The DPA conducted an investigation, and found that the controller transmits, to the processor, a file which was initially designed to include extensive details about variables used to calculate the scores, and only later limited to the information necessary to calculate the score.The DPA conducted an investigation, and found that the controller transmits, to the processor, a file which was initially designed to include extensive details about variables used to calculate the scores, and only later limited to the information necessary to calculate the score. Further, the DPA found that the controller limited its responses to data subjects, only to the personal data present in the credit information system, and did not provide reference to the generated score and sub-scores assigned to them. The DPA further established that even when a data subject was not present in the credit information system, a score was nevertheless assigned to them.Further, the DPA found that the controller limited its responses to data subjects, only to the personal data present in the credit information system, and did not provide reference to the generated score and sub-scores assigned to them. The DPA further established that even when a data subject was not present in the credit information system, a score was nevertheless assigned to them. The controller claimed that unless the requests by the data subjects pertained specifically to the scores, their response, providing the data present in the credit information system, was adequate. The controller further emphasised that, as a result of strengthening their internal procedures they implemented a layered approach within which only upon request by the data subject, would the controller provide them with more detail and comprehensible information.The controller claimed that unless the requests by the data subjects pertained specifically to the scores, their response, providing the data present in the credit information system, was adequate. The controller further emphasised that, as a result of strengthening their internal procedures they implemented a layered approach within which only upon request by the data subject, would the controller provide them with more detail and comprehensible information. === Holding === Firstly, the DPA held that the responses provided by the controller to the data subjects were inadequate and incomplete, as they did not provide any information as to information pertaining to the score, details about the criteria used to determine the score, nor the method used to generate the score. Similarly, the DPA emphasised that in implementing a layered approach the controller further limited the right of access to data subjects, and added no value to their new procedures. Thus, the DPA found the controller in violation of [[Article 12 GDPR]] and [[Article 15 GDPR]], as the controller failed in its response to respond in a way which helps the data subject understand what and how their personal data was used. Additionally, the DPA held that the use of the new internal procedure and persistent inadequate responses, prevented data subjects from determining the lawfulness, fairness and accuracy of the data violating [[Articles 5(1)(a) GDPR|Article 5(1)(a) GDPR]]. This undermined their ability to exercise their right to rectification pursuant to [[Article 16 GDPR]], and right to obtain human intervention, express their opinion and challenge the decision made, pursuant to [[Article 22 GDPR|Article 22(3) GDPR]]. The DPA found the controller in violation of the principle of data minimisation pursuant to [[Article 5 GDPR|Article (5)(1)(c) GDPR]]. This was based on the the fact that the controller failed to implement adequate technical and organisational measures specific to identifying the procedures which define the methods whereby the data necessary to generate the scores are transmitted. Furthermore, the DPA held that the controller failed to implement default settings ensuring only the necessary data is processed for the generation of the score. Finally, the DPA found a violation of privacy by design and default in accordance with [[Article 25 GDPR]] as the controller used a file format not designed specifically for the utilities sector, failing to ensure adequate and effective data protection by design and default. === Holding ===The DPA imposed a fine of €120.000 pursuant to [[Article 83 GDPR]] taking into account, inter alia, the fact that this affected 561 data subjects. The DPA further ordered the controller revise their internal procedures to include the logic and criteria used, to ensure data subject can fully exercise their rights. Firstly, the DPA held that the responses provided by the controller to the data subjects were inadequate and incomplete, as they did not provide any information as to information pertaining to the score, details about the criteria used to determine the score, nor the method used to generate the score. Secondly, the DPA emphasised that in implementing a layered approach the controller limited the right of access to data subjects, and added no value to their new procedures. Thus, the DPA found the controller in violation of Articles 5(1)(a), 12 and 15 GDPR, as the controller failed to describe the score generating method procedure and principles in a way which helps the data subject understand what and how their personal data was used. Similarly, the DPA held that the use of the new internal procedure and persistent inadequate responses, prevented data subjects from determining the lawfulness, fairness and accuracy of the data. This undermined their ability to exercise their right to rectification pursuant to [[Article 16 GDPR|Article 16 GDPR]], and right to obtain human intervention, express their opinion and challenge the decision made, pursuant to Article 22(3). The DPA found the controller in violation of the principle of data minimisation pursuant to Article (5)(1)(c)","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10273659&diff=52858&oldid=52856","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-09-01T09:03:54+00:00","2026-09-01T10:00:17.937531+00:00",7,[18],{"name":19,"type":20},"Experian","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,32,37,39],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":38},{"id":21,"icon":23,"name":24,"slug":25},{"category":40},{"id":41,"icon":23,"name":42,"slug":43},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]