[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fz7WQfP5lNad6BiBrVKkQ3a2t1xcHKQClYsoguX3VYvQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"33cd0d48-a679-45e4-9e95-fb2ad2bf0b65","experian-italia-fined-120k-for-gdpr-violations-in-credit-scoring-data-practices","605f929a-b17c-4012-876d-65748acd1baf","Experian Italia Fined €120K for GDPR Violations in Credit Scoring Data Practices","Experian Italia failed to uphold core GDPR principles when processing personal data for creditworthiness assessments, resulting in real-world harm — energy supply denials — for affected individuals. The company could not adequately respond to data subject access requests, failing to explain how credit scores were generated or what criteria were applied, a fundamental transparency obligation under GDPR. Violations of data minimization and privacy by design principles indicate that data protection was not embedded into the system's architecture from the outset. This case underscores that automated decision-making processes must be explainable, auditable, and rights-respecting — not just functionally effective.","**Immediate actions:**\n- Establish a documented, timely process for responding to data subject access requests (DSARs) that includes score logic and criteria explanations.\n- Audit all personal data processing activities to ensure only the minimum necessary data is collected and retained.\n\n**Privacy by Design improvements:**\n- Embed data minimization and purpose limitation requirements into system design specifications before development begins.\n- Conduct Data Protection Impact Assessments (DPIAs) for any automated decision-making or profiling systems that produce significant effects on individuals.\n- Document and version-control the criteria and algorithms used in credit scoring to support transparency and auditability.\n\n**Governance & Compliance measures:**\n- Train staff responsible for DSAR handling on GDPR obligations, including Articles 13–15 and Article 22 on automated decision-making.\n- Assign a qualified Data Protection Officer (DPO) with authority to review and challenge data processing designs prior to deployment.\n- Schedule regular third-party GDPR compliance audits focusing on profiling, scoring, and automated decision-making workflows.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5 – Principles of data processing (minimization, accuracy, purpose limitation)","GDPR Article 13 & 14 – Information obligations","GDPR Article 15 – Right of access by the data subject","GDPR Article 22 – Automated individual decision-making, including profiling","GDPR Article 25 – Data protection by design and by default","NIST Privacy Framework PR.DS-P4 – Data processing transparency","NIST SP 800-53 RA-3 – Risk Assessment","CIS Control 3 – Data Protection","ISO\u002FIEC 29101 – Privacy architecture framework","ITIL Service Design – Privacy and data management considerations","published","2026-09-01T10:21:11.574687+00:00","2026-09-01T10:21:11.51+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10273659&diff=52858&oldid=52856","garante-per-la-protezione-dei-dati-personali-italy-10273659-da05da","Garante per la protezione dei dati personali (Italy) - 10273659",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]