Back to Feed
Privacy FinesJul 29, 2026

Garante per la protezione dei dati personali (Italy) - 484/2026

Italian DPA fines energy supplier €1.4M for unlawful profiling and data misuse.

Summary

Italy's Garante per la protezione dei dati personali has fined EstEnergy S.p.A. €1.4 million for violating GDPR. The energy supplier unlawfully profiled potential customers, provided incomplete responses to data access requests, and reused credit data for incompatible purposes. The DPA found multiple infringements, including lack of transparency, inadequate access responses, and improper data retention and reuse.

Full text

Help Garante per la protezione dei dati personali (Italy) - 484/2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 08:46, 29 July 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators226 edits Tag: Decisions [1.0] Latest revision as of 09:08, 29 July 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators226 editsTag: Visual edit (One intermediate revision by the same user not shown)Line 128: Line 128: }}}} The Italian DPA fined an energy supplier €1.4 million for unlawfully profiling potential customers, providing incomplete access responses and reusing credit data for incompatible purposes.The DPA fined an energy supplier €1.4 million for unlawfully profiling potential customers, providing incomplete access responses and reusing credit data for incompatible purposes. == English Summary ==== English Summary == Line 135: Line 135: EstEnergy S.p.A. (hereinafter, the controller) is an Italian energy company supplying natural gas, electricity and related services. Before entering into contracts, the controller assessed the creditworthiness of potential customers through an internal and an external credit check.EstEnergy S.p.A. (hereinafter, the controller) is an Italian energy company supplying natural gas, electricity and related services. Before entering into contracts, the controller assessed the creditworthiness of potential customers through an internal and an external credit check. The internal assessment involved verifying whether potential customers had outstanding debts not only with the controller but also with Hera Comm S.p.A. The assessment was conducted on behalf of the controller by Hera S.p.A. (hereinafter, the processor), which returned an “OK” or “KO” result.The internal assessment involved verifying whether potential customers had outstanding debts not only with the controller but also with Hera Comm S.p.A (hereinafter, the corporate group). The assessment was conducted on behalf of the controller by Hera S.p.A. (hereinafter, the processor), which returned an “OK” or “KO” result. Where the internal assessment returned an “OK”, the controller conducted an external assessment using credit information supplied by Experian Italia S.p.A. and commercial information provided by Cerved Group S.p.A. This information was combined using the “CGS-X” software provided by Major 1 S.r.l. (hereinafter, the software provider and processor). The software generated an integrated creditworthiness score and several underlying sub-scores. On the basis of the result, the controller could refuse to enter into an energy supply contract.Where the internal assessment returned an “OK”, the controller conducted an external assessment using credit information supplied by Experian Italia S.p.A. and commercial information provided by Cerved Group S.p.A. This information was combined using the “CGS-X” software provided by Major 1 S.r.l. (hereinafter, the software provider and processor). The software generated an integrated creditworthiness score and several underlying sub-scores. On the basis of the result, the controller could refuse to enter into an energy supply contract. Line 141: Line 141: The DPA received several complaints from data subjects whose requests for energy supply had been rejected on the basis of their risk profiles. However, when the data subjects contacted the credit and commercial information providers, they were informed that the relevant databases did not contain negative information or adverse events concerning them.The DPA received several complaints from data subjects whose requests for energy supply had been rejected on the basis of their risk profiles. However, when the data subjects contacted the credit and commercial information providers, they were informed that the relevant databases did not contain negative information or adverse events concerning them. The data subjects also submitted access requests under [[Article 15 GDPR|Article 15 GDPR]]. Although the controller responded within the applicable time limits, it did not provide the CGS-X score, the underlying sub-scores or meaningful information about the logic and criteria used to calculate the profiles. Instead, the controller referred the data subjects to the credit and commercial information providers.The data subjects also submitted access requests under [[Article 15 GDPR]]. Although the controller responded within the applicable time limits, it did not provide the CGS-X score, the underlying sub-scores or meaningful information about the logic and criteria used to calculate the profiles. Instead, the controller referred the data subjects to the credit and commercial information providers. Following the complaints, the DPA consolidated the proceedings and initiated an ex officio investigation. It conducted inspections at the premises of the processor, the software provider and processor, and the credit and commercial information providers.Following the complaints, the DPA consolidated the proceedings and initiated an ex officio investigation. It conducted inspections at the premises of the processor, the software provider and processor, and the credit and commercial information providers. The investigation also established that the controller retained the information obtained through the credit checks. Through the processor, the controller subsequently analysed this information to potentially refine the Hera Group’s customer rating system. Between 2022 and March 2024, this processing concerned more than one million data subjects.The investigation also established that the controller retained the information obtained through the credit checks. Through the processor, the controller subsequently analysed this information to potentially refine the corporate group’s customer rating system. Between 2022 and March 2024, this processing concerned more than one million data subjects. === Holding === The DPA held that the controller’s creditworthiness assessment infringed [[Article 5 GDPR|Articles 5(1)(a)]], [[Article 5 GDPR|(b)]], [[Article 5 GDPR|(d)]] and [[Article 5 GDPR|(e)]], [[Article 12 GDPR|12]], [[Article 13 GDPR|13]], [[Article 14 GDPR|14]], [[Article 15 GDPR|15]] and [[Article 28 GDPR|28 GDPR]]. First, the controller failed to provide transparent information about the internal assessment of customers’ previous debts and the sharing of such information within the corporate group. The instructions given to the processor also did not adequately cover these processing operations. The DPA therefore found violations of [[Article 5 GDPR|Articles 5(1)(a)]], [[Article 13 GDPR|13]], [[Article 14 GDPR|14]] and [[Article 28 GDPR|28 GDPR]]. === Holding ===Second, the controller provided incomplete responses to access requests. It did not disclose the CGS-X score, the underlying sub-scores or meaningful information on the logic and criteria used to generate the creditworthiness profile. Referring the data subjects to the credit and commercial information providers did not discharge the controller’s obligations under [[Article 12 GDPR|Articles 12]] and [[Article 15 GDPR|15 GDPR]]. The DPA held that the controller’s creditworthiness assessment infringed Articles 5(1)(a), (b), (d) and (e), 12, 13, 14, 15 and 28 GDPR. First, the controller failed to provide transparent information about the internal assessment of customers’ previous debts and the sharing of such information within the Hera Group. The instructions given to the processor also did not adequately cover these processing operations. The DPA therefore found violations of Articles 5(1)(a), 13, 14 and 28 GDPR. Second, the controller provided incomplete responses to access requests. It did not disclose the CGS-X score, the underlying sub-scores or meaningful information on the logic and criteria used to generate the creditworthiness profile. Referring the data subjec

Entities

EstEnergy S.p.A. (vendor)Hera S.p.A. (vendor)Experian Italia S.p.A. (vendor)Cerved Group S.p.A. (vendor)CGS-X (product)Major 1 S.r.l. (vendor)