Back to Feed
PolicyJul 28, 2026

Garante per la protezione dei dati personali (Italy) - 483/2026

Italian DPA finds GDPR violations in data retention and processing practices.

Summary

The Italian Data Protection Authority (Garante per la protezione dei dati personali) has found multiple GDPR infringements by an energy supplier. The company failed to set specific retention periods for external assessment data, reusing credit check data for rating system refinement, and inadequately informed data subjects about intra-group data sharing. The DPA also noted issues with responses to access requests and instructions given to a processor.

Full text

Help Garante per la protezione dei dati personali (Italy) - 483/2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 11:20, 28 July 2026 view sourceDs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators227 edits Tag: Decisions [1.0] Latest revision as of 11:23, 28 July 2026 view source Ds (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators227 editsm Tag: Visual edit Line 133: Line 133: At the time of the inspection, the controller had not set a specific retention period for the external-assessment data and instead applied a general ten-year period used for accounting documentation. It also reused credit-check data, including information from external providers and previous debts, for analyses aimed at refining its group’s rating system. Between 2022 and March 2024, this processing concerned 1,003,657 individuals.At the time of the inspection, the controller had not set a specific retention period for the external-assessment data and instead applied a general ten-year period used for accounting documentation. It also reused credit-check data, including information from external providers and previous debts, for analyses aimed at refining its group’s rating system. Between 2022 and March 2024, this processing concerned 1,003,657 individuals. During the proceedings, the controller and the other energy supplier entered into a joint-controller arrangement under [[Article 26 GDPR|Article 26 GDPR]] concerning the internal assessment and updated the relevant privacy information. Under that arrangement, the two joint controllers also undertook to appoint processor A for the processing carried out as part of the internal assessment. The controller subsequently adopted a five-year retention period for creditworthiness data and discontinued the analyses concerning the refinement of the rating system.During the proceedings, the controller and the other energy supplier entered into a joint-controller arrangement under [[Article 26 GDPR]] concerning the internal assessment and updated the relevant privacy information. Under that arrangement, the two joint controllers also undertook to appoint processor A for the processing carried out as part of the internal assessment. The controller subsequently adopted a five-year retention period for creditworthiness data and discontinued the analyses concerning the refinement of the rating system. === Holding ====== Holding === The DPA considered that the information provided by the controller did not describe the intra-group sharing and use of data concerning previous debts with sufficient specificity. It found that the general references to disclosures within the corporate group did not provide information about the processing operations connected with the internal assessment. The DPA also found that the instructions provided to processor A did not cover the processing of information concerning debts owed by customers to the other energy supplier. It therefore found infringements of [[Article 5 GDPR|Article 5(1)(a) GDPR]], [[Article 13 GDPR|Article 13 GDPR]], [[Article 14 GDPR|Article 14 GDPR]] and [[Article 28 GDPR|Article 28 GDPR]].The DPA considered that the information provided by the controller did not describe the intra-group sharing and use of data concerning previous debts with sufficient specificity. It found that the general references to disclosures within the corporate group did not provide information about the processing operations connected with the internal assessment. The DPA also found that the instructions provided to processor A did not cover the processing of information concerning debts owed by customers to the other energy supplier. It therefore found infringements of [[Article 5 GDPR|Article 5(1)(a) GDPR]], [[Article 13 GDPR]], [[Article 14 GDPR]] and [[Article 28 GDPR]]. The DPA noted that, under the joint-controller arrangement, the internal assessment was carried out jointly by the two energy suppliers on the basis of [[Article 6 GDPR|Article 6(1)(f) GDPR]]. However, it found that the processing carried out before the conclusion of that arrangement was unlawful.The DPA noted that, under the joint-controller arrangement, the internal assessment was carried out jointly by the two energy suppliers on the basis of [[Article 6 GDPR|Article 6(1)(f) GDPR]]. However, it found that the processing carried out before the conclusion of that arrangement was unlawful. The DPA also found that the responses to the access requests did not meet the requirements of [[Article 12 GDPR|Article 12 GDPR]] and [[Article 15 GDPR|Article 15 GDPR]]. It noted that the access requests had been submitted to the controller which was required to provide all personal data and information relating to the processing. It pointed out additionally that the information to be provided should include the integrated score, the contributing scores, and meaningful information about the logic and criteria applied.The DPA also found that the responses to the access requests did not meet the requirements of [[Article 12 GDPR]] and [[Article 15 GDPR]]. It noted that the access requests had been submitted to the controller which was required to provide all personal data and information relating to the processing. It pointed out additionally that the information to be provided should include the integrated score, the contributing scores, and meaningful information about the logic and criteria applied. Moreover, referring to the CJEU’s judgment in Case C-203/22, the DPA stated that the requirement to provide meaningful information about the logic involved could not be satisfied merely by disclosing a complex mathematical formula or by providing a detailed description of every stage of the automated process. It emphasized that the controller was required to describe the procedure and principles actually applied in a concise and understandable manner, enabling the data subject to understand which personal data were used and how they contributed to the result.Moreover, referring to the CJEU’s judgment in [https://infocuria.curia.europa.eu/tabs/affair?lang=de&sort=AFF_NUM-DESC&searchTerm=%2522C%252D203%252F22%2522&publishedId=C-203%2F22 Case C-203/22 (Dun & Bradstreet Austria)], the DPA stated that the requirement to provide meaningful information about the logic involved could not be satisfied merely by disclosing a complex mathematical formula or by providing a detailed description of every stage of the automated process. It emphasized that the controller was required to describe the procedure and principles actually applied in a concise and understandable manner, enabling the data subject to understand which personal data were used and how they contributed to the result. The DPA considered that the information provided did not enable the data subjects fully to assess the lawfulness of the processing or the accuracy of the data used. It also limited their ability to request rectification, obtain human intervention, express their views and contest the decision.The DPA considered that the information provided did not enable the data subjects fully to assess the lawfulness of the processing or the accuracy of the data used. It also limited their ability to request rectification, obtain human intervention, express their views and contest the decision. Latest revision as of 11:23, 28 July 2026 Garante per la protezione dei dati personali - 483/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 13 GDPR Article 14 GDPR Article 28 GDPR Article 12 GDPR Article 15 GDPR Article 5(1)(e) GDPR Article 5(1)(b) GDPR Article 5(1)(d) GDPR Type: Complaint Outcome: Upheld Started: Decided: 03.07.2026 Published: Fine: 5800000.0 EUR Parties: Hera Comm S.p.A. National Case Number/Name: 483/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s):

Entities

Dun & Bradstreet Austria (product)GDPR (technology)