Cerved Fined €400K for Failing to Honor Data Subject Access Requests
Cerved Group S.p.A. violated GDPR obligations by providing inaccurate and misleading responses to data subject access requests (DSARs), claiming no negative data existed while still generating credit scores based on personal attributes such as residential address, age, and place of birth. This disconnect between what was disclosed and what was actually processed denied individuals the ability to understand, challenge, or correct decisions that directly impacted their access to essential services like energy supply. The case highlights a critical failure in data inventory transparency — organizations must have full visibility into all data processing activities, including derived or inferred scores, to respond accurately to DSARs. Regulators are increasingly scrutinizing the quality and completeness of DSAR responses, not just their timeliness, making this a high-risk compliance gap for any data controller.
Tactical Insight
Immediate actions
- Conduct a comprehensive audit of all data processing activities, including automated scoring and profiling pipelines, to ensure they are fully captured in the Record of Processing Activities (RoPA).
- Establish a mandatory DSAR response review process that cross-checks responses against all data systems, including derived scores and inferred attributes, before submission to the data subject.
Long-term improvements
- Implement a centralized data inventory and classification platform that maps personal data across all systems, including those that generate derived or inferred data points.
- Define clear internal policies distinguishing between "raw" personal data and derived outputs (e.g., credit scores), ensuring both categories are disclosed in DSAR responses as required under GDPR Article 15.
- Train data protection and customer service teams regularly on the full scope of GDPR data subject rights, including the right of access to profiling logic under Article 22.
Detection & monitoring measures
- Implement logging and audit trails for all DSAR workflows to detect inconsistencies between disclosed data and data actually held or processed.
- Schedule periodic third-party or internal audits of DSAR response quality and completeness to identify systemic gaps before regulatory review.