[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fibYSwg2DeOgVp1kew8Rzyo2uFFI8BvZfKOVF5W6sh44":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"84cee0d2-4bc4-4c21-9dbc-3d1a73243bd5","Garante per la protezione dei dati personali (Italy) - 485\u002F2026","garante-per-la-protezione-dei-dati-personali-italy-485-2026-f6e179","Facts: typo ← Older revision Revision as of 14:42, 1 September 2026 Line 113: Line 113: When data subjects requested access to their data from the controller under [[Article 15 GDPR]], they were informed that their databases did not contain negative information or adverse events justifying the denial of energy supply. When data subjects requested access to their data from the controller under [[Article 15 GDPR]], they were informed that their databases did not contain negative information or adverse events justifying the denial of energy supply. The DPA conducted an investigation, and found that the controller provided different responses to different data subject’s depending on whether their personal data had been recorded in their system. The DPA conducted an investigation, and found that the controller provided different responses to different data subjects depending on whether their personal data had been recorded in their system. For data subjects where there was no negative information on them the controller claimed that no personal data processing had been conducted for commercial information purposes. Nevertheless, a score based on their residential address, age and place of birth was generated. For data subjects where there was no negative information on them the controller claimed that no personal data processing had been conducted for commercial information purposes. Nevertheless, a score based on their residential address, age and place of birth was generated.","The Italian Data Protection Authority (Garante) has fined Cerved Group S.p.A., a credit rating agency, €400,000 for providing inadequate responses to data subject access requests. The agency was processing personal data to assess creditworthiness for energy suppliers, leading to some individuals being denied energy supply. When data subjects requested access to their information, Cerved claimed no negative data existed, yet scores were still generated based on residential address, age, and place of birth, hindering the exercise of their rights.","Italian DPA fines Cerved Group €400K for inadequate data subject access responses.","Help Garante per la protezione dei dati personali (Italy) - 485\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 08:07, 1 September 2026 view sourceSf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators37 editsmTag: Visual edit← Older edit Latest revision as of 14:42, 1 September 2026 view source Carloc (talk | contribs)734 editsm Tag: Visual edit Line 113: Line 113: When data subjects requested access to their data from the controller under [[Article 15 GDPR]], they were informed that their databases did not contain negative information or adverse events justifying the denial of energy supply.When data subjects requested access to their data from the controller under [[Article 15 GDPR]], they were informed that their databases did not contain negative information or adverse events justifying the denial of energy supply. The DPA conducted an investigation, and found that the controller provided different responses to different data subject’s depending on whether their personal data had been recorded in their system.The DPA conducted an investigation, and found that the controller provided different responses to different data subjects depending on whether their personal data had been recorded in their system. For data subjects where there was no negative information on them the controller claimed that no personal data processing had been conducted for commercial information purposes. Nevertheless, a score based on their residential address, age and place of birth was generated.For data subjects where there was no negative information on them the controller claimed that no personal data processing had been conducted for commercial information purposes. Nevertheless, a score based on their residential address, age and place of birth was generated. Latest revision as of 14:42, 1 September 2026 Garante per la protezione dei dati personali - 485\u002F2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 12 GDPR Article 15 GDPR Article 16 GDPR Article 22(3) GDPR Article 83 GDPR Type: Complaint Outcome: Upheld Started: Decided: 07.03.2026 Published: Fine: 400000.0 EUR Parties: Cerved Group S.p.A National Case Number\u002FName: 485\u002F2026 European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA fined an Italian credit rating agency €400.000 for providing inadequate responses to data subject request, effectively preventing them from exercising their rights. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA received several complaints from data subjects concerning Cerved Group S.p.A. (the controller) an Italian credit rating agency. The controller was processing the personal data of data subjects for the purpose of verifying the creditworthiness of potential customers of two energy suppliers. As a result of the risk profiles attributed to them, data subjects were declined the supply of energy. When data subjects requested access to their data from the controller under Article 15 GDPR, they were informed that their databases did not contain negative information or adverse events justifying the denial of energy supply. The DPA conducted an investigation, and found that the controller provided different responses to different data subjects depending on whether their personal data had been recorded in their system. For data subjects where there was no negative information on them the controller claimed that no personal data processing had been conducted for commercial information purposes. Nevertheless, a score based on their residential address, age and place of birth was generated. For those data subjects where information was present on their databases the controller provided them with the personal data which was present. The DPA further found that the controller did not provide reference to the scores and sub-scores assigned by the controller to the data subjects. Holding The DPA held that in light of the controller inadequately responding to data subjects requests, which prevented them from accessing all the information processed for the purpose of calculating their risk profile, and to understand how the score was used in the decisions of the energy suppliers, data subjects were effectively prevented from exercising their rights. Particularly, the DPA held that the controller did not provide data subjects with all the necessary information, such as certain scores, and the logic and criteria used to calculate the scores, which prevented them from determining the lawfulness, fairness and accuracy of the data. This undermined their ability to exercise their right to rectification pursuant to Article 16 GDPR, and right to obtain human intervention, express their opinion and challenge the decision made, pursuant to Article 22(3) GDPR. In connection with sensitive nature of the information processed by the controller (residential address, age and place of birth) which relates to a data subjects creditworthiness with potentially prejudicial consequences, the controller was found in violation of Article 5(1)(a) GDPR, Article 12 GDPR and Article 15 GDPR. The DPA imposed a €400.000 fine on the controller pursuant to Article 83 GDPR taking into account, inter alia, the fact that this affected 2.094 data subjects. The DPA further ordered the controller to establish a procedure allowing data subjects to exercise their right to rectification pursuant to Article 16 GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [Web Doc. No. 10273976] Decision of July 3, 2026 Register of Decisions No. 485 of July 3, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, President; Prof. Ginevra Cerrina Feroni, Vice President; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016\u002F679 of the European Parliament and of the Council of April 27, 2016 (hereinafter the “Regulation”); HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003 (Code on Data Protection, hereinafter the “Code”), as amended by Legislative Decree No. 101 of August 10, 2018, containing “Provisions for the alignment of national legislation with the provisions of Regulation (EU) 2016\u002F679”; HAVING EXAMINED the documentation on file; HAVING CONSIDERED the observations made by the Secretary General pursuant to Art. 15 of the Data Protection Authority’s Regulation No. 1\u002F2000; RAPPORTEUR: Dr. Agostino Ghiglia; WHEREAS 1. Introduction. This Authority has received several requests concerning the processing of personal data carried out by Cerved Group S.p.A. (hereinafter also “the Company”) for the purpose of verifying the creditworthiness of potential customers of Hera Comm S.p.A. and EstEnergy S.p.A. Specifically, the complainants alleged that Hera Comm S.p.A. and EstEnergy S.p.A. refused to supply energy to them on the basis of a risk profile of the data subjects that allegedly emerged, following checks carried out by the aforementioned Companies, including through the use of commercial information services (operated by Cerved Group S.p.A.) and the consultation of credit information systems (operated by Experian Italia S.p.A.). This risk profile is generated within the Hera Group using software provided by Major 1 S.r.l., called “CGS-X.” This software allows the aforementioned energy suppliers to develop a risk profile regarding the creditworthiness of potential customers, based on an integrated indicator called the “Integrate","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_485\u002F2026&diff=52867&oldid=52855","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-09-01T14:42:31+00:00","2026-09-01T16:00:16.070654+00:00",7,[18],{"name":19,"type":20},"Cerved Group S.p.A.","vendor","d95477d7-eb04-4fad-a2dc-be1428040ce7",{"id":21,"icon":23,"name":24,"slug":25},null,"Privacy Fines","privacy-fines",[27,32,37,42],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":38},{"id":39,"icon":23,"name":40,"slug":41},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",{"category":43},{"id":21,"icon":23,"name":24,"slug":25},[]]