[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fzdjNpviEJRuYIadu-UOBGWGzDoriZnipmNzf878XMr0":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":43},"94491a31-00f2-40ee-9619-0df3953d1637","hera-comm-fined-58m-for-gdpr-violations-over-creditworthiness-data-misuse","8a81b995-dac3-4687-82ce-cf8c2bceaf9a","Hera Comm Fined €5.8M for GDPR Violations Over Creditworthiness Data Misuse","Italian energy supplier Hera Comm S.p.A. committed multiple GDPR violations by failing to provide customers with their creditworthiness scores and explanations, unlawfully sharing debt data within its corporate group, and retaining credit data for ten years without legal justification. These failures violate core GDPR principles including transparency, purpose limitation, and data minimisation. The case highlights that organisations must not only secure personal data technically but also govern how it is used, shared, and retained in compliance with data subjects' rights. Excessive retention periods and undisclosed intra-group data transfers are common compliance blind spots that regulators are increasingly scrutinising, resulting in significant financial penalties.","**Immediate actions:**\n- Conduct an urgent audit of all automated profiling and scoring processes to ensure customers can access their scores and receive meaningful explanations.\n- Review and halt any intra-group personal data sharing arrangements that lack a documented lawful basis under GDPR Articles 6 and 9.\n\n**Data governance & retention:**\n- Implement a formal data retention policy with defined, justified retention periods for all personal data categories, especially financial and credit data.\n- Deploy automated data lifecycle management tools to enforce deletion or anonymisation when retention periods expire.\n- Maintain a comprehensive Record of Processing Activities (RoPA) that documents the legal basis, purpose, and retention schedule for every data type.\n\n**Long-term improvements:**\n- Establish a Data Protection by Design programme so that new products and intra-group data flows undergo Privacy Impact Assessments (DPIAs) before launch.\n- Train customer-facing and data management teams on GDPR transparency obligations, including the right to explanation under automated decision-making rules (Article 22).\n- Appoint or empower a qualified Data Protection Officer (DPO) with authority to review and veto non-compliant data processing practices.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 5 – Principles of data processing (purpose limitation, data minimisation, storage limitation)","GDPR Article 6 – Lawfulness of processing","GDPR Article 13\u002F14 – Transparency and information obligations","GDPR Article 22 – Automated individual decision-making and profiling","GDPR Article 30 – Records of processing activities","GDPR Article 35 – Data Protection Impact Assessment (DPIA)","NIST Privacy Framework PR.DS-P1 – Data processing transparency","NIST SP 800-53 IP-1 – Consent \u002F IP-2 – Individual Access","CIS Control 3 – Data Protection (data classification and retention)","ISO\u002FIEC 27701 – Privacy Information Management System (PIMS)","ITIL Service Design – Information Security and Data Management policies","published","2026-07-29T10:22:39.366049+00:00","2026-07-29T10:22:39.271+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_483\u002F2026&diff=52533&oldid=52513","garante-per-la-protezione-dei-dati-personali-italy-483-2026-8d6555","Garante per la protezione dei dati personali (Italy) - 483\u002F2026",[31,37],{"id":32,"name":33,"slug":34,"description":35,"color":36},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]