[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$frJ2GkBEW0yRNMun2vaL5vwt3ktjzmJs6EdTKWSXcm7Y":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"c3068d32-e8b7-4577-841d-7a97dd700197","cerved-group-fined-400k-for-failing-to-honor-gdpr-data-subject-rights","3f0f6f3f-ec90-418f-a290-962d37e5ce3c","Cerved Group Fined €400K for Failing to Honor GDPR Data Subject Rights","Cerved Group S.p.A. violated GDPR by failing to adequately respond to data subject access requests, withholding critical information such as credit scores and the algorithmic logic behind them. This opacity left individuals unable to understand or challenge decisions that materially impacted their lives, including denials of energy supply. Automated decision-making systems that affect individuals must provide meaningful explanations to comply with GDPR Articles 13, 14, and 22. The case highlights that data controllers in the credit and commercial information sector bear heightened obligations when profiling individuals, and inadequate transparency can trigger significant regulatory penalties.","**Immediate actions:**\n- Audit all existing data subject request (DSR) workflows to ensure responses include scores, profiling logic, and the basis for automated decisions.\n- Establish a dedicated DSR response team with defined SLAs aligned to GDPR's one-month response requirement.\n\n**Long-term improvements:**\n- Implement a formal explainability framework for all automated scoring and profiling models, documenting the logic in plain language accessible to data subjects.\n- Conduct annual GDPR compliance reviews specifically targeting Articles 13, 14, 15, and 22 obligations for any automated decision-making processes.\n- Embed Data Protection by Design principles into new product development to ensure transparency mechanisms are built in from the start.\n\n**Detection & oversight measures:**\n- Deploy a centralized DSR tracking system with automated escalation alerts to prevent missed or incomplete responses.\n- Schedule periodic internal audits and DPO-led assessments to identify gaps in data subject rights fulfillment before regulatory review.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 13 – Information to be provided where personal data are collected","GDPR Article 14 – Information where personal data have not been obtained from the data subject","GDPR Article 15 – Right of access by the data subject","GDPR Article 22 – Automated individual decision-making, including profiling","GDPR Article 83(4) – Administrative fines","NIST Privacy Framework PR.PO-P6 (Policies for data subject rights)","NIST SP 800-53 IP-1 (Consent), IP-2 (Individual Access)","CIS Control 3 – Data Protection","ISO\u002FIEC 27701:2019 – Privacy Information Management (Section 7.3 Data Subject Rights)","ITIL Service Management – Request Fulfilment Process","published","2026-09-01T10:22:48.499299+00:00","2026-09-01T10:22:48.392+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_485\u002F2026&diff=52853&oldid=0","garante-per-la-protezione-dei-dati-personali-italy-485-2026-3c41d1","Garante per la protezione dei dati personali (Italy) - 485\u002F2026",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]