Back to all lessons
Awareness Lessons
2 months ago

Italian DPA Fines Energy Supplier €5.8M for Widespread GDPR Data Handling Failures

Hera Comm S.p.A. committed multiple, compounding GDPR violations by unlawfully processing creditworthiness data, failing to properly inform customers about automated decision-making, sharing debt data within its corporate group without legal basis, and retaining credit data for an unjustified ten-year period. These failures indicate a systemic lack of data governance — including absent or inadequate data retention policies, incomplete transparency notices, and insufficient controls over intra-group data sharing. This case underscores that GDPR compliance is not a one-time checkbox but requires ongoing operational discipline across the entire data lifecycle. The €5.8 million fine demonstrates that regulators will pursue organisations that treat personal data — especially sensitive financial data — as an unconstrained business asset rather than a protected right.

Tactical Insight

Immediate actions

  • Audit all personal data processing activities to verify a documented lawful basis exists for each, particularly for creditworthiness and automated decision-making.
  • Review and update customer-facing privacy notices to include clear, specific disclosures about automated decision-making and its logic, significance, and consequences.

Data Governance & Retention

  • Define and enforce documented data retention schedules for all personal data categories, with mandatory review and deletion workflows when retention periods expire.
  • Establish clear intra-group data sharing agreements with explicit legal bases (e.g., legitimate interest assessments or consent) before any personal data is transferred between group entities.

Long-term improvements

  • Implement a Data Protection Impact Assessment (DPIA) process for all automated decision-making and profiling activities involving personal data.
  • Appoint or empower a Data Protection Officer (DPO) with sufficient authority to conduct periodic compliance audits and report directly to senior leadership.
  • Build a continuous compliance monitoring programme that includes regular reviews of data flows, third-party sharing, and retention adherence against GDPR obligations.