[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fEajODQc-onmfpz8L2rmJQFKm7FNb7U3XO_tbpN_EFfg":3},{"article":4,"iocs":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":28,"category":29,"article_tags":33},"2133ad00-9c49-42d2-9a58-46e45dab6e3e","Garante per la protezione dei dati personali (Italy) - 483\u002F2026","garante-per-la-protezione-dei-dati-personali-italy-483-2026-a9ec5c","Created page with \"{{DPAdecisionBOX |Jurisdiction=Italy |DPA-BG-Color= |DPAlogo=LogoIT.png |DPA_Abbrevation=Garante per la protezione dei dati personali |DPA_With_Country=Garante per la protezione dei dati personali (Italy) |Case_Number_Name=483\u002F2026 |ECLI= |Original_Source_Name_1=GPDP |Original_Source_Link_1=https:\u002F\u002Fwww.garanteprivacy.it\u002Fweb\u002Fguest\u002Fhome\u002Fdocweb\u002F-\u002Fdocweb-display\u002Fdocweb\u002F10273926 |Original_Source_Language_1=Italian |Original_Source_Language__Code_1=IT |Original_Source_Na...\" Show changes","The Italian DPA has fined Hera Comm S.p.A., an energy supplier, €5.8 million for multiple GDPR violations. The company unlawfully processed creditworthiness data, failed to adequately inform customers about automated decision-making, unlawfully shared debt data within its group, and retained credit data for an excessive ten-year period without proper justification.","Italy's Garante fines Hera Comm €5.8M for GDPR violations related to credit scoring.","Help Garante per la protezione dei dati personali (Italy) - 483\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 11:20, 28 July 2026 view source Ds (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators227 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 11:20, 28 July 2026 Garante per la protezione dei dati personali - 483\u002F2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 13 GDPR Article 14 GDPR Article 28 GDPR Article 12 GDPR Article 15 GDPR Article 5(1)(e) GDPR Article 5(1)(b) GDPR Article 5(1)(d) GDPR Type: Complaint Outcome: Upheld Started: Decided: 03.07.2026 Published: Fine: 5800000.0 EUR Parties: Hera Comm S.p.A. National Case Number\u002FName: 483\u002F2026 European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Italian Original Source: GPDP (in IT) Initial Contributor: ds The DPA fined an energy supplier €5,800,000 for failing to provide creditworthiness scores and explain how they were calculated, unlawfully sharing debt data within its group, retaining credit data for ten years without adequate justification and reusing it for an incompatible purpose. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts Several data subjects lodged complaints with the Italian DPA (Garante) after Hera Comm S.p.A., an energy supplier (the controller), declined to conclude electricity or gas contracts with them because its checks had resulted in a negative risk assessment. The controller had used a credit-check procedure to assess the creditworthiness of prospective customers before entering into such contracts. The credit-check procedure consisted of an internal and an external assessment. During the internal assessment, Hera S.p.A. (processor A) checked whether the prospective customer had outstanding debts towards the controller or EstEnergy S.p.A., another energy supplier within the same corporate group. The assessment returned an OK or KO result. The controller’s privacy notice stated that customer data could be disclosed to other companies within the Hera Group and to third parties contractually linked to the Group. Where the internal assessment returned an OK result, an external assessment was carried out using software called “CGS-X”, provided by Major 1 S.r.l. (processor B). Through the software, databases operated by Experian Italia S.p.A. (the credit-information provider) and Cerved Group S.p.A. (the commercial-information provider) were consulted. The software combined the scores supplied by the two external data providers to generate an integrated creditworthiness score, which was transmitted to systems operated by processor A. Those systems applied the criteria established under the controller’s group credit policy and returned a final OK or KO result. The data subjects alleged that the refusal of their applications resulted from the external creditworthiness assessment. When they subsequently contacted the two external data providers, the providers stated that their systems did not contain negative information or adverse events concerning them. The data subjects then submitted access requests to the controller. The controller replied that their risk profiles were based on automated scoring using information obtained from external databases and directed them to the two external data providers for further details. The replies did not identify the CGS-X score and did not explain the logic or criteria used in the assessment. At the time of the inspection, the controller had not set a specific retention period for the external-assessment data and instead applied a general ten-year period used for accounting documentation. It also reused credit-check data, including information from external providers and previous debts, for analyses aimed at refining its group’s rating system. Between 2022 and March 2024, this processing concerned 1,003,657 individuals. During the proceedings, the controller and the other energy supplier entered into a joint-controller arrangement under Article 26 GDPR concerning the internal assessment and updated the relevant privacy information. Under that arrangement, the two joint controllers also undertook to appoint processor A for the processing carried out as part of the internal assessment. The controller subsequently adopted a five-year retention period for creditworthiness data and discontinued the analyses concerning the refinement of the rating system. Holding The DPA considered that the information provided by the controller did not describe the intra-group sharing and use of data concerning previous debts with sufficient specificity. It found that the general references to disclosures within the corporate group did not provide information about the processing operations connected with the internal assessment. The DPA also found that the instructions provided to processor A did not cover the processing of information concerning debts owed by customers to the other energy supplier. It therefore found infringements of Article 5(1)(a) GDPR, Article 13 GDPR, Article 14 GDPR and Article 28 GDPR. The DPA noted that, under the joint-controller arrangement, the internal assessment was carried out jointly by the two energy suppliers on the basis of Article 6(1)(f) GDPR. However, it found that the processing carried out before the conclusion of that arrangement was unlawful. The DPA also found that the responses to the access requests did not meet the requirements of Article 12 GDPR and Article 15 GDPR. It noted that the access requests had been submitted to the controller which was required to provide all personal data and information relating to the processing. It pointed out additionally that the information to be provided should include the integrated score, the contributing scores, and meaningful information about the logic and criteria applied. Moreover, referring to the CJEU’s judgment in Case C-203\u002F22, the DPA stated that the requirement to provide meaningful information about the logic involved could not be satisfied merely by disclosing a complex mathematical formula or by providing a detailed description of every stage of the automated process. It emphasized that the controller was required to describe the procedure and principles actually applied in a concise and understandable manner, enabling the data subject to understand which personal data were used and how they contributed to the result. The DPA considered that the information provided did not enable the data subjects fully to assess the lawfulness of the processing or the accuracy of the data used. It also limited their ability to request rectification, obtain human intervention, express their views and contest the decision. The DPA further found that the application of a general ten-year retention period to the credit-check data had not been sufficiently justified in relation to the purpose of assessing a specific contractual application. The controller had not demonstrated the necessity of retaining the scores and related reports for that period. The DPA concluded that the controller violated Article 5(1)(e) GDPR. Furthermore, the DPA considered that the use of data obtained from the credit-information provider and the commercial-information provider for analyses concerning the refinement of the controller’s group rating model pursued a further purpose incompatible with the original purpose for which those data had been collected. It also found that retaining and subsequently reusing data obtained from the two external providers created a risk that the information would no longer be up to date. It therefore found infringements of Article 5(1)(b) GDPR and Article 5(1)(d) GDPR. The DPA imposed a fine of €5,800,000. It also ordered the controller to define a","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_483\u002F2026&diff=52512&oldid=0","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-07-28T11:20:28+00:00","2026-07-28T12:00:17.578823+00:00",8,[18,21,23,25],{"name":19,"type":20},"Hera Comm S.p.A.","vendor",{"name":22,"type":20},"Experian Italia S.p.A.",{"name":24,"type":20},"Cerved Group S.p.A.",{"name":26,"type":27},"CGS-X","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":28,"icon":30,"name":31,"slug":32},null,"Policy","policy",[34,39,44,46],{"category":35},{"id":36,"icon":30,"name":37,"slug":38},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":40},{"id":41,"icon":30,"name":42,"slug":43},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":45},{"id":28,"icon":30,"name":31,"slug":32},{"category":47},{"id":48,"icon":30,"name":49,"slug":50},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]