[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAKKl4b4JYwW8TLPp9yWjtnHTSV4Rq6KodQnHNeTPwik":3},{"article":4,"iocs":53},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":30,"category":31,"article_tags":35},"8a81b995-dac3-4687-82ce-cf8c2bceaf9a","Garante per la protezione dei dati personali (Italy) - 483\u002F2026","garante-per-la-protezione-dei-dati-personali-italy-483-2026-8d6555","Amendments to short summary ← Older revision Revision as of 08:11, 29 July 2026 Line 116: Line 116: }} }} The DPA fined an energy supplier €5,800,000 for failing to provide creditworthiness scores and explain how they were calculated, unlawfully sharing debt data within its group, retaining credit data for ten years without adequate justification and reusing it for an incompatible purpose. The DPA fined an energy supplier €5,800,000 for failing to provide data subjects with their creditworthiness scores and an explanation on how they were calculated and used when deciding whether a contract with the data subject should be concluded. Further, the DPA held that debt data was unlawfully shared and used within the controller’s group. == English Summary == == English Summary ==","Italy's Garante per la protezione dei dati personali has fined energy supplier Hera Comm S.p.A. €5.8 million for multiple GDPR violations. The company failed to provide customers with their creditworthiness scores and explanations, unlawfully shared debt data within its group, and retained credit data for ten years without justification.","Italy's Garante fines energy supplier €5.8M for GDPR violations.","Help Garante per la protezione dei dati personali (Italy) - 483\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 11:23, 28 July 2026 view sourceDs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators240 editsm Tag: Visual edit← Older edit Latest revision as of 08:11, 29 July 2026 view source Ds (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators240 editsm Tag: Visual edit Line 116: Line 116: }}}} The DPA fined an energy supplier €5,800,000 for failing to provide creditworthiness scores and explain how they were calculated, unlawfully sharing debt data within its group, retaining credit data for ten years without adequate justification and reusing it for an incompatible purpose.The DPA fined an energy supplier €5,800,000 for failing to provide data subjects with their creditworthiness scores and an explanation on how they were calculated and used when deciding whether a contract with the data subject should be concluded. Further, the DPA held that debt data was unlawfully shared and used within the controller’s group. == English Summary ==== English Summary == Latest revision as of 08:11, 29 July 2026 Garante per la protezione dei dati personali - 483\u002F2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 13 GDPR Article 14 GDPR Article 28 GDPR Article 12 GDPR Article 15 GDPR Article 5(1)(e) GDPR Article 5(1)(b) GDPR Article 5(1)(d) GDPR Type: Complaint Outcome: Upheld Started: Decided: 03.07.2026 Published: Fine: 5800000.0 EUR Parties: Hera Comm S.p.A. National Case Number\u002FName: 483\u002F2026 European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Italian Original Source: GPDP (in IT) Initial Contributor: ds The DPA fined an energy supplier €5,800,000 for failing to provide data subjects with their creditworthiness scores and an explanation on how they were calculated and used when deciding whether a contract with the data subject should be concluded. Further, the DPA held that debt data was unlawfully shared and used within the controller’s group. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts Several data subjects lodged complaints with the Italian DPA (Garante) after Hera Comm S.p.A., an energy supplier (the controller), declined to conclude electricity or gas contracts with them because its checks had resulted in a negative risk assessment. The controller had used a credit-check procedure to assess the creditworthiness of prospective customers before entering into such contracts. The credit-check procedure consisted of an internal and an external assessment. During the internal assessment, Hera S.p.A. (processor A) checked whether the prospective customer had outstanding debts towards the controller or EstEnergy S.p.A., another energy supplier within the same corporate group. The assessment returned an OK or KO result. The controller’s privacy notice stated that customer data could be disclosed to other companies within the Hera Group and to third parties contractually linked to the Group. Where the internal assessment returned an OK result, an external assessment was carried out using software called “CGS-X”, provided by Major 1 S.r.l. (processor B). Through the software, databases operated by Experian Italia S.p.A. (the credit-information provider) and Cerved Group S.p.A. (the commercial-information provider) were consulted. The software combined the scores supplied by the two external data providers to generate an integrated creditworthiness score, which was transmitted to systems operated by processor A. Those systems applied the criteria established under the controller’s group credit policy and returned a final OK or KO result. The data subjects alleged that the refusal of their applications resulted from the external creditworthiness assessment. When they subsequently contacted the two external data providers, the providers stated that their systems did not contain negative information or adverse events concerning them. The data subjects then submitted access requests to the controller. The controller replied that their risk profiles were based on automated scoring using information obtained from external databases and directed them to the two external data providers for further details. The replies did not identify the CGS-X score and did not explain the logic or criteria used in the assessment. At the time of the inspection, the controller had not set a specific retention period for the external-assessment data and instead applied a general ten-year period used for accounting documentation. It also reused credit-check data, including information from external providers and previous debts, for analyses aimed at refining its group’s rating system. Between 2022 and March 2024, this processing concerned 1,003,657 individuals. During the proceedings, the controller and the other energy supplier entered into a joint-controller arrangement under Article 26 GDPR concerning the internal assessment and updated the relevant privacy information. Under that arrangement, the two joint controllers also undertook to appoint processor A for the processing carried out as part of the internal assessment. The controller subsequently adopted a five-year retention period for creditworthiness data and discontinued the analyses concerning the refinement of the rating system. Holding The DPA considered that the information provided by the controller did not describe the intra-group sharing and use of data concerning previous debts with sufficient specificity. It found that the general references to disclosures within the corporate group did not provide information about the processing operations connected with the internal assessment. The DPA also found that the instructions provided to processor A did not cover the processing of information concerning debts owed by customers to the other energy supplier. It therefore found infringements of Article 5(1)(a) GDPR, Article 13 GDPR, Article 14 GDPR and Article 28 GDPR. The DPA noted that, under the joint-controller arrangement, the internal assessment was carried out jointly by the two energy suppliers on the basis of Article 6(1)(f) GDPR. However, it found that the processing carried out before the conclusion of that arrangement was unlawful. The DPA also found that the responses to the access requests did not meet the requirements of Article 12 GDPR and Article 15 GDPR. It noted that the access requests had been submitted to the controller which was required to provide all personal data and information relating to the processing. It pointed out additionally that the information to be provided should include the integrated score, the contributing scores, and meaningful information about the logic and criteria applied. Moreover, referring to the CJEU’s judgment in Case C-203\u002F22 (Dun & Bradstreet Austria), the DPA stated that the requirement to provide meaningful information about the logic involved could not be satisfied merely by disclosing a complex mathematical formula or by providing a detailed description of every stage of the automated process. It emphasized that the controller was required to describe the procedure and principles actually applied in a concise and understandable manner, enabling the data subject to understand which personal data were used and how they contributed to the result. The DPA considered that the information provided did not enable the data subjects fully to assess the lawfulness of the processing or the accuracy of the data used. It also limited their ability to request rectification, obtain human intervention, express their views and contest the decision. The DPA further found that the application of a general ten-year retention period to the credit-chec","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_483\u002F2026&diff=52533&oldid=52513","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-07-29T08:11:31+00:00","2026-07-29T10:00:47.245529+00:00",7,[18,21,23,25,28],{"name":19,"type":20},"Hera Comm S.p.A.","vendor",{"name":22,"type":20},"Experian Italia S.p.A.",{"name":24,"type":20},"Cerved Group S.p.A.",{"name":26,"type":27},"CGS-X","product",{"name":29,"type":20},"Major 1 S.r.l.","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":30,"icon":32,"name":33,"slug":34},null,"Policy","policy",[36,41,46,48],{"category":37},{"id":38,"icon":32,"name":39,"slug":40},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":42},{"id":43,"icon":32,"name":44,"slug":45},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":47},{"id":30,"icon":32,"name":33,"slug":34},{"category":49},{"id":50,"icon":32,"name":51,"slug":52},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]