Back to Feed
PolicyJul 29, 2026

Garante per la protezione dei dati personali (Italy) - 484/2026

Italian DPA fines EstEnergy €1.4M for unlawful profiling and data reuse.

Summary

The Italian Data Protection Authority (Garante) has fined EstEnergy S.p.A. €1.4 million for violating GDPR. The company unlawfully profiled potential customers by improperly assessing creditworthiness, reusing credit data for incompatible purposes, and providing incomplete responses to data access requests. The investigation revealed that EstEnergy retained and analyzed credit information, impacting over a million individuals.

Full text

Help Garante per la protezione dei dati personali (Italy) - 484/2026: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 08:46, 29 July 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators226 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 08:46, 29 July 2026 Garante per la protezione dei dati personali - 484/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 5(1)(b) GDPR Article 5(1)(d) GDPR Article 5(1)(e) GDPR Article 13 GDPR Article 14 GDPR Article 15 GDPR Article 28 GDPR Type: Investigation Outcome: Violation Found Started: Decided: 03.07.2026 Published: 03.07.2026 Fine: 1400000.0 EUR Parties: EstEnergy S.p.A. Experian italia S.p.A. Cerved Group S.p.A. Major 1 S.r.l. Hera S.p.A. National Case Number/Name: 484/2026 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Italian Original Source: GDPD (in IT) Initial Contributor: bms The Italian DPA fined an energy supplier €1.4 million for unlawfully profiling potential customers, providing incomplete access responses and reusing credit data for incompatible purposes. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts EstEnergy S.p.A. (hereinafter, the controller) is an Italian energy company supplying natural gas, electricity and related services. Before entering into contracts, the controller assessed the creditworthiness of potential customers through an internal and an external credit check. The internal assessment involved verifying whether potential customers had outstanding debts not only with the controller but also with Hera Comm S.p.A. The assessment was conducted on behalf of the controller by Hera S.p.A. (hereinafter, the processor), which returned an “OK” or “KO” result. Where the internal assessment returned an “OK”, the controller conducted an external assessment using credit information supplied by Experian Italia S.p.A. and commercial information provided by Cerved Group S.p.A. This information was combined using the “CGS-X” software provided by Major 1 S.r.l. (hereinafter, the software provider and processor). The software generated an integrated creditworthiness score and several underlying sub-scores. On the basis of the result, the controller could refuse to enter into an energy supply contract. The DPA received several complaints from data subjects whose requests for energy supply had been rejected on the basis of their risk profiles. However, when the data subjects contacted the credit and commercial information providers, they were informed that the relevant databases did not contain negative information or adverse events concerning them. The data subjects also submitted access requests under Article 15 GDPR. Although the controller responded within the applicable time limits, it did not provide the CGS-X score, the underlying sub-scores or meaningful information about the logic and criteria used to calculate the profiles. Instead, the controller referred the data subjects to the credit and commercial information providers. Following the complaints, the DPA consolidated the proceedings and initiated an ex officio investigation. It conducted inspections at the premises of the processor, the software provider and processor, and the credit and commercial information providers. The investigation also established that the controller retained the information obtained through the credit checks. Through the processor, the controller subsequently analysed this information to potentially refine the Hera Group’s customer rating system. Between 2022 and March 2024, this processing concerned more than one million data subjects. Holding The DPA held that the controller’s creditworthiness assessment infringed Articles 5(1)(a), (b), (d) and (e), 12, 13, 14, 15 and 28 GDPR. First, the controller failed to provide transparent information about the internal assessment of customers’ previous debts and the sharing of such information within the Hera Group. The instructions given to the processor also did not adequately cover these processing operations. The DPA therefore found violations of Articles 5(1)(a), 13, 14 and 28 GDPR. Second, the controller provided incomplete responses to access requests. It did not disclose the CGS-X score, the underlying sub-scores or meaningful information on the logic and criteria used to generate the creditworthiness profile. Referring the data subjects to the credit and commercial information providers did not discharge the controller’s obligations under Articles 12 and 15 GDPR. Third, the controller had not established a justified retention period for the data collected during the external assessment. Applying a general ten-year retention period for accounting records was not shown to be necessary for the creditworthiness assessment, in violation of Article 5(1)(e) GDPR. The DPA also found that reusing credit and commercial information to refine the Hera Group’s rating system was incompatible with the original purpose for which the data had been collected. Since the retained information could become outdated, this processing also violated the purpose limitation and accuracy principles under Articles 5(1)(b) and (d) GDPR. The DPA ordered the controller to adopt a compliant access-response template, provide the relevant information to the data subjects involved and establish procedures enabling rectification, human intervention and the possibility to challenge decisions. The controller had six months to demonstrate compliance. Finally, the DPA imposed a €1,400,000 fine, taking into account the seriousness and scale of the infringements, the impact on approximately one million data subjects and the risk of refusal of essential energy services. It also considered the controller’s cooperation, lack of previous relevant infringements and remedial measures as mitigating factors. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. Retrieved from "https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_484/2026&oldid=52536" Categories: Garante per la protezione dei dati personali (Italy)ItalyArticle 5(1)(a) GDPRArticle 5(1)(b) GDPRArticle 5(1)(d) GDPRArticle 5(1)(e) GDPRArticle 13 GDPRArticle 14 GDPRArticle 15 GDPRArticle 28 GDPR2026Italian This page was last edited on 29 July 2026, at 08:46. Content is available under Creative Commons Attribution-NonCommercial-ShareAlike unless otherwise noted. Privacy policy About GDPRhub Disclaimers

Entities

EstEnergy S.p.A. (vendor)Experian Italia S.p.A. (vendor)Cerved Group S.p.A. (vendor)Major 1 S.r.l. (vendor)Hera S.p.A. (vendor)