Back to all lessons
Awareness Lessons
2 months ago

EstEnergy Fined €1.4M for Unlawful Customer Profiling and GDPR Violations

EstEnergy S.p.A. violated GDPR by unlawfully profiling over one million individuals using credit data collected for one purpose and repurposed for incompatible creditworthiness assessments — a clear breach of the principle of purpose limitation under Article 5(1)(b). The company compounded the violation by providing incomplete responses to data subject access requests, undermining individuals' fundamental rights to transparency and control over their personal data. This case illustrates how organizations frequently treat data governance as a back-office concern rather than a core compliance obligation, exposing themselves to significant regulatory and reputational risk. The €1.4 million fine underscores that supervisory authorities are actively scrutinizing secondary data use and data subject rights fulfillment, not just security breaches.

Tactical Insight

Immediate actions

  • Audit all existing customer datasets to verify that data is only being used for the specific, documented purpose for which it was originally collected.
  • Establish a formal Data Subject Access Request (DSAR) process with defined SLAs, response templates, and completeness checklists to ensure fully compliant responses.

Long-term improvements

  • Implement a data inventory and classification program that maps every personal data element to its lawful basis, retention period, and permitted use cases.
  • Embed Privacy by Design principles into all new product and marketing initiatives, requiring a Data Protection Impact Assessment (DPIA) before any new profiling activity is launched.
  • Appoint or empower a Data Protection Officer (DPO) with sufficient authority and resources to enforce purpose limitation and data minimization across business units.

Detection & monitoring measures

  • Deploy data lineage and access logging tools to detect when personal data is accessed or processed outside its defined purpose boundary.
  • Conduct periodic internal GDPR compliance audits focused specifically on secondary data use, credit data handling, and data subject rights fulfillment rates.