[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_lngoXTlVFtOvcCeTiod7EAsN2XA4zRZhBARld-Wj9o":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":43},"beeeac74-4a62-485f-a02c-1d8f7bd875ee","cerved-fined-400k-for-failing-to-honor-data-subject-rights-under-gdpr","91ca9c11-5cd4-4c85-b37c-77134660724a","Cerved Fined €400K for Failing to Honor Data Subject Rights Under GDPR","Cerved Group S.p.A. was fined €400,000 by Italy's data protection authority for providing incomplete responses to data subject access requests, specifically failing to disclose credit scores and the logic behind automated decisions. This directly hindered individuals' ability to challenge decisions that led to real-world consequences, such as denial of energy supply. Under GDPR Articles 13–15 and 22, organizations using automated decision-making must provide meaningful, intelligible explanations of the logic involved. This case underscores that data subject rights are not a formality — inadequate or opaque responses to such requests constitute a serious compliance failure with significant regulatory and reputational consequences.","**Immediate actions:**\n- Audit all existing data subject request (DSR) processes to ensure responses include scores, profiling logic, and the basis for automated decisions.\n- Establish a dedicated DSR response team with clear SLAs aligned to GDPR's one-month response deadline.\n\n**Long-term improvements:**\n- Implement a formal Automated Decision-Making (ADM) transparency framework that documents and communicates the logic, significance, and consequences of profiling to data subjects.\n- Conduct regular GDPR Article 22 compliance reviews for any systems involved in credit scoring, risk profiling, or other automated decisions with significant effects on individuals.\n- Integrate data subject rights workflows into CRM or case management systems to ensure completeness, traceability, and auditability of all responses.\n\n**Detection & monitoring measures:**\n- Establish internal QA checks on DSR response quality, including completeness of information provided regarding automated decision logic.\n- Monitor regulatory guidance and DPA decisions across EU member states to proactively identify compliance gaps in data subject rights handling.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 13 – Information to be provided where personal data are collected","GDPR Article 14 – Information where personal data have not been obtained from the data subject","GDPR Article 15 – Right of access by the data subject","GDPR Article 16 – Right to rectification","GDPR Article 22 – Automated individual decision-making, including profiling","GDPR Recital 71 – Profiling and automated decision-making transparency","NIST Privacy Framework PR.PO-P6 – Policies for responding to data subject requests","NIST SP 800-53 PT-6 – System of Records Notice","CIS Control 3 – Data Protection","ISO\u002FIEC 29101 – Privacy Architecture Framework","ITIL Service Operation – Request Fulfilment Process","published","2026-09-01T10:22:28.684073+00:00","2026-09-01T10:22:28.543+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_485\u002F2026&diff=52855&oldid=52853","garante-per-la-protezione-dei-dati-personali-italy-485-2026-4ed6e3","Garante per la protezione dei dati personali (Italy) - 485\u002F2026",[31,37],{"id":32,"name":33,"slug":34,"description":35,"color":36},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]