[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAagILSEuknVhTfRgamyEYObQTG9lQQ0JvrO_-t8JAlE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"e4721237-8130-4686-b486-abc14e4a639f","italian-dpa-fines-energy-supplier-58m-for-widespread-gdpr-data-handling-failures","2133ad00-9c49-42d2-9a58-46e45dab6e3e","Italian DPA Fines Energy Supplier €5.8M for Widespread GDPR Data Handling Failures","Hera Comm S.p.A. committed multiple, compounding GDPR violations by unlawfully processing creditworthiness data, failing to properly inform customers about automated decision-making, sharing debt data within its corporate group without legal basis, and retaining credit data for an unjustified ten-year period. These failures indicate a systemic lack of data governance — including absent or inadequate data retention policies, incomplete transparency notices, and insufficient controls over intra-group data sharing. This case underscores that GDPR compliance is not a one-time checkbox but requires ongoing operational discipline across the entire data lifecycle. The €5.8 million fine demonstrates that regulators will pursue organisations that treat personal data — especially sensitive financial data — as an unconstrained business asset rather than a protected right.","**Immediate actions:**\n- Audit all personal data processing activities to verify a documented lawful basis exists for each, particularly for creditworthiness and automated decision-making.\n- Review and update customer-facing privacy notices to include clear, specific disclosures about automated decision-making and its logic, significance, and consequences.\n\n**Data Governance & Retention:**\n- Define and enforce documented data retention schedules for all personal data categories, with mandatory review and deletion workflows when retention periods expire.\n- Establish clear intra-group data sharing agreements with explicit legal bases (e.g., legitimate interest assessments or consent) before any personal data is transferred between group entities.\n\n**Long-term improvements:**\n- Implement a Data Protection Impact Assessment (DPIA) process for all automated decision-making and profiling activities involving personal data.\n- Appoint or empower a Data Protection Officer (DPO) with sufficient authority to conduct periodic compliance audits and report directly to senior leadership.\n- Build a continuous compliance monitoring programme that includes regular reviews of data flows, third-party sharing, and retention adherence against GDPR obligations.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5 (Principles of data processing, including storage limitation and purpose limitation)","GDPR Article 6 (Lawfulness of processing)","GDPR Article 13 & 14 (Transparency and information obligations)","GDPR Article 22 (Automated individual decision-making, including profiling)","GDPR Article 35 (Data Protection Impact Assessment)","NIST Privacy Framework PR.DS-P1 (Data processing policies)","NIST SP 800-53 IP-1 (Consent and Privacy Policy)","CIS Control 3 (Data Protection — data classification and retention)","ISO\u002FIEC 27701 (Privacy Information Management System)","ITIL Service Design — Information Security Management (data handling policies)","published","2026-07-28T12:21:07.15325+00:00","2026-07-28T12:21:07.064+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_483\u002F2026&diff=52512&oldid=0","garante-per-la-protezione-dei-dati-personali-italy-483-2026-a9ec5c","Garante per la protezione dei dati personali (Italy) - 483\u002F2026",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]