Hera Comm Fined €5.8M for GDPR Violations Over Creditworthiness Data Misuse
Italian energy supplier Hera Comm S.p.A. committed multiple GDPR violations by failing to provide customers with their creditworthiness scores and explanations, unlawfully sharing debt data within its corporate group, and retaining credit data for ten years without legal justification. These failures violate core GDPR principles including transparency, purpose limitation, and data minimisation. The case highlights that organisations must not only secure personal data technically but also govern how it is used, shared, and retained in compliance with data subjects' rights. Excessive retention periods and undisclosed intra-group data transfers are common compliance blind spots that regulators are increasingly scrutinising, resulting in significant financial penalties.
Tactical Insight
Immediate actions
- Conduct an urgent audit of all automated profiling and scoring processes to ensure customers can access their scores and receive meaningful explanations.
- Review and halt any intra-group personal data sharing arrangements that lack a documented lawful basis under GDPR Articles 6 and 9.
Data governance & retention
- Implement a formal data retention policy with defined, justified retention periods for all personal data categories, especially financial and credit data.
- Deploy automated data lifecycle management tools to enforce deletion or anonymisation when retention periods expire.
- Maintain a comprehensive Record of Processing Activities (RoPA) that documents the legal basis, purpose, and retention schedule for every data type.
Long-term improvements
- Establish a Data Protection by Design programme so that new products and intra-group data flows undergo Privacy Impact Assessments (DPIAs) before launch.
- Train customer-facing and data management teams on GDPR transparency obligations, including the right to explanation under automated decision-making rules (Article 22).
- Appoint or empower a qualified Data Protection Officer (DPO) with authority to review and veto non-compliant data processing practices.