483/2026
Several data subjects lodged complaints with the Italian DPA (Garante) after Hera Comm S.p.A., an energy supplier (the controller), declined to conclude electricity or gas contracts with them because its checks had resulted in a negative risk assessment. The controller had used a credit-check procedure to assess the creditworthiness of prospective customers before entering into such contracts. The credit-check procedure consisted of an internal and an external assessment. During the internal assessment, Hera S.p.A. (processor A) checked whether the prospective customer had outstanding debts towards the controller or EstEnergy S.p.A., another energy supplier within the same corporate group. The assessment returned an OK or KO result. The controller’s privacy notice stated that customer data could be disclosed to other companies within the Hera Group and to third parties contractually linked to the Group. Where the internal assessment returned an OK result, an external assessment was carried out using software called “CGS-X”, provided by Major 1 S.r.l. (processor B). Through the software, databases operated by Experian Italia S.p.A. (the credit-information provider) and Cerved Group S.p.A. (the commercial-information provider) were consulted. The software combined the scores supplied by the two external data providers to generate an integrated creditworthiness score, which was transmitted to systems operated by processor A. Those systems applied the criteria established under the controller’s group credit policy and returned a final OK or KO result. The data subjects alleged that the refusal of their applications resulted from the external creditworthiness assessment. When they subsequently contacted the two external data providers, the providers stated that their systems did not contain negative information or adverse events concerning them. The data subjects then submitted access requests to the controller. The controller replied that their risk profiles were based on automated scoring using information obtained from external databases and directed them to the two external data providers for further details. The replies did not identify the CGS-X score and did not explain the logic or criteria used in the assessment. At the time of the inspection, the controller had not set a specific retention period for the external-assessment data and instead applied a general ten-year period used for accounting documentation. It also reused credit-check data, including information from external providers and previous debts, for analyses aimed at refining its group’s rating system. Between 2022 and March 2024, this processing concerned 1,003,657 individuals. During the proceedings, the controller and the other energy supplier entered into a joint-controller arrangement under Article 26 GDPR concerning the internal assessment and updated the relevant privacy information. Under that arrangement, the two joint controllers also undertook to appoint processor A for the processing carried out as part of the internal assessment. The controller subsequently adopted a five-year retention period for creditworthiness data and discontinued the analyses concerning the refinement of the rating system. Holding — The DPA considered that the information provided by the controller did not describe the intra-group sharing and use of data concerning previous debts with sufficient specificity. It found that the general references to disclosures within the corporate group did not provide information about the processing operations connected with the internal assessment. The DPA also found that the instructions provided to processor A did not cover the processing of information concerning debts owed by customers to the other energy supplier. It therefore found infringements of Article 5(1)(a) GDPR, Article 13 GDPR, Article 14 GDPR and Article 28 GDPR. The DPA noted that, under the joint-controller arrangement, the internal assessment was carried out jointly by the two energy suppliers on the basis of Article 6(1)(f) GDPR. However, it found that the processing carried out before the conclusion of that arrangement was unlawful. The DPA also found that the responses to the access requests did not meet the requirements of Article 12 GDPR and Article 15 GDPR. It noted that the access requests had been submitted to the controller which was required to provide all personal data and information relating to the processing. It pointed out additionally that the information to be provided should include the integrated score, the contributing scores, and meaningful information about the logic and criteria applied. Moreover, referring to the CJEU’s judgment in Case C-203/22 (Dun & Bradstreet Austria), the DPA stated that the requirement to provide meaningful information about the logic involved could not be satisfied merely by disclosing a complex mathematical formula or by providing a detailed description of every stage of the automated process. It emphasized that the controller was required to describe the procedure and principles actually applied in a concise and understandable manner, enabling the data subject to understand which personal data were used and how they contributed to the result. The DPA considered that the information provided did not enable the data subjects fully to assess the lawfulness of the processing or the accuracy of the data used. It also limited their ability to request rectification, obtain human intervention, express their views and contest the decision. The DPA further found that the application of a general ten-year retention period to the credit-check data had not been sufficiently justified in relation to the purpose of assessing a specific contractual application. The controller had not demonstrated the necessity of retaining the scores and related reports for that period. The DPA concluded that the controller violated Article 5(1)(e) GDPR. Furthermore, the DPA considered that the use of data obtained from the credit-information provider and the commercial-information provider for analyses concerning the refinement of the controller’s group rating model pursued a further purpose incompatible with the original purpose for which those data had been collected. It also found that retaining and subsequently reusing data obtained from the two external providers created a risk that the information would no longer be up to date. It therefore found infringements of Article 5(1)(b) GDPR and Article 5(1)(d) GDPR. The DPA imposed a fine of €5,800,000. It also ordered the controller to define a new response template for access requests, including the relevant scores and meaningful information about the logic and criteria applied, and to provide the revised response to the complainants. The controller was further required to establish a procedure enabling data subjects to request the rectification of inaccurate or incomplete data, obtain human intervention, express their views and contest the decision.
How it connects
Related across sources
Full text 80 findings
[Web Doc. No. 10273926] Decision of July 3, 2026 Register of Decisions No. 483 of July 3, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter the “Regulation”); HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003 (Code on Data Protection, hereinafter the “Code”), as amended by Legislative Decree No. 101 of August 10, 2018, containing “Provisions for the alignment of national legislation with the provisions of Regulation (EU) 2016/679”; HAVING EXAMINED the documentation on file; HAVING CONSIDERED the observations made by the Secretary General pursuant to Art. 15 of the Data Protection Authority’s Regulation No.
1/2000; RAPPORTEUR: Prof. Pasquale Stanzione; WHEREAS 1. Introduction. A. for the purpose of verifying the creditworthiness of potential customers. A. ). ” This software enables the aforementioned energy suppliers to identify a risk profile regarding the reliability of potential customers, based on an integrated indicator called the “Integrated Utilities Score” (hereinafter also referred to as the “CGS-X Score”). A. , these companies, when questioned on the matter, stated that their systems contained no negative information and/or adverse events regarding the aforementioned data subjects. A. , pursuant to Art. 15 of the Regulation (see request by Mr. XX dated March 1, 2023, the request filed by Mr. XX on June 29, 2023, the request filed by Mr. XX on June 14, 2024, the request filed by Mr. XX on July 15, 2024, and the request filed by Ms. XX on September 13, 2024). With regard to the foregoing, it should be noted that the Authority, in view of the numerous requests received, first decided to consolidate the individual proceedings referred to above in order to conduct a comprehensive examination of the underlying issues and subsequently initiated, on its own initiative, pursuant to Article 21 of the Data Protection Authority’s Regulation No.
A. l. A. A. A. on June 13 and 14, 2024. A. on October 16, 2024. 2. The Investigation. As part of the proceedings, with regard to the issues highlighted in the introduction, the following findings emerged. 1. The Credit Check Process. A. ’s statement of March 18, 2024, p. 2). A. memorandum dated April 19, 2024, p. 1). ), has adopted a Credit Policy and implemented a system for verifying and assessing the solvency and creditworthiness of parties applying to participate in one of the open-market offers (hereinafter, “Credit Check”). A. note dated July 30, 2024, p. 2). A. A. , and the related “Addendum” dated July 3, 2023. A. A. minutes of March 18, 2024, p. 2 and Annex 2). A. minutes of March 18, 2024, p. A. minutes of March 19, 2024, p. 2). ’s note dated April 19, 2024, p. 1 and Attachment 1). ’s minutes of March 18, 2024, p. 3). A. “checks, based on the potential customer’s personal data (first name, last name, tax ID, and business partner), for any prior delinquencies, returning an ‘OK’ or ‘KO’ result.
(…) The query, conducted online and in real time, concerns active, uncontested arrears relating solely to the energy sector in the deregulated market. A. minutes of March 18, 2024, p. 3). A. A. l. and called “CGS-X”]. l. —which acts as a technology outsourcing provider, supplying the license to use the “CGS-X” software—as the processor pursuant to Art. ’s minutes of March 18, 2024, p. l. dated April 15, 2024, p. 3). A. dated March 18, 2024, p. 3). A. to develop a risk profile regarding the creditworthiness of potential customers based on the integrated “CGS-X Score” indicator. ). A. ). A. minutes of March 18, 2024, p. l. minutes of April 15, 2024, p. 3). l. dated April 16, 2024, pp. A. dated March 18, 2024, p. 4). l. dated April 16, 2024, pp. 3–4). A. ’s minutes of March 18, 2024, p. 4). A. minutes of March 18, 2024, p. 4). A. A. minutes of March 18, 2024, pp. 4 and 5). A. minutes of March 18, 2024, pp.
4 and 5). A. minutes of March 19, 2024). A. dated March 18, 2024, p. 5). A. minutes of March 18, 2024, p. 5 and Annex 8). 2. Procedures for responding to data subject rights requests. With regard to requests submitted by data subjects pursuant to Article 15 of the Regulation, although the Company responded within the time limits set forth in Article 12 of the Regulation, in its responses it limited itself to referring solely to the identification of a risk profile for the data subjects. ’s notes dated August 17, 2022, August 29, 2023, and August 25, 2023). ’s notice dated August 25, 2023; see also the Company’s notices dated August 17, 2022, and August 29, 2023). A. A. A. ’s notes dated August 17, 2022, August 29, 2023, and August 25, 2023). During the investigations, it was further ascertained that, in none of the cases subject to complaint, did the aforementioned findings refer to the “CGS-X Score” and the related sub-scores assigned to the data subject.
l. l. A. ’s report dated March 19, 2024, pp. 1, 3, and 4, and Attachments Nos. ’s minutes of March 20, 2024, pp. 1 and 3, and Attachments Nos. 1 and 7). 3. The refinement of the Hera Group’s customer rating service. A. minutes of March 20, 2024, p. 2). ’s minutes of March 19, 2024, p. 3). A. A. A. dated March 20, 2024, p. 2). A. A. note dated April 19, 2024, p. 2). These analyses—for which the legend of the relevant fields has been obtained (see Annex No. A. ’s minutes of March 20, 2024, p. 2). A. minutes of March 20, 2024, p. 2). A. minutes of March 20, p. 2). A. minutes of March 20, 2024, p. 2). A. A. ’s minutes of March 20, 2024, p. 2). A. minutes of March 19, 2024). A. minutes of March 20, 2024, p. 2). 3. The notification pursuant to Article 166, paragraph 5, of the Code. A. by notice dated July 14, 2025, the Company, by letter dated October 10, 2025, submitted its defense briefs, which were further supplemented during the hearing on May 20, 2026, and by a subsequent letter dated May 29, 2026.
A. made the following representations: a) regarding the allegation concerning the unlawfulness of the processing of potential customers’ data in the context of the so-called “Internal Assessment of Past Delinquencies,” “a joint controller agreement was signed between Hera Comm and EstEnergy, pursuant to Art. 26 of the Regulation”. This was done with the aim of jointly sharing, storing, and processing the personal data collected by the companies for the purpose of verifying the creditworthiness of customers in the free market segment for electricity and natural gas. This processing is designed to safeguard the financial stability of the Hera Group and minimize exposure to the risk of insolvency by acquiring customers who are financially sound and creditworthy. In conclusion, this activity represents “an essential safeguard aimed at ensuring the reliability of supplies and the economic sustainability of sales operations in the free market” (see note dated October 10, 2025, p.
3). Following the signing of the aforementioned joint-controller agreement, “the relevant notices provided to customers have been updated to ensure full transparency regarding data processing,” including with regard to the new structure of shared roles and accountability (see note dated October 10, 2025, p. 4; see also the note dated May 29, 2026, pp. A. ) enhanced with additional elements aimed at ensuring a more complete representation of the information processed and at strengthening transparency toward customers” have been prepared (see note dated October 10, 2025, pp. 5–8 and Annex 3); c) regarding the retention periods for customer data in connection with external assessment activities, which were deemed non-compliant with the storage limitation principle, the Company “has developed and progressively implemented a specific data retention policy for credit data, which defines specific periods of storage and automated procedures for erasure upon the expiration of the established periods, in full compliance with Article 5, paragraph 1, letter e) of the GDPR” (see note dated October 10, 2025, p.
8, and note dated May 29, 2026, pp. A. ) since the analyses did not affect the outcome of individual cases, nor were they used to determine automated decisions” (see note dated October 10, 2025, p. 9). ; this is because the aforementioned activity is “carried out solely with respect to residential customers requesting the activation of electricity and gas supply contracts in the free market, as well as with respect to customers requesting the activation of contracts under the gas vulnerability protection program” (see note dated May 29, 2026, p. 4). The Company also highlighted that, in order to ensure full compliance of the processing activities in question with the Regulation, it has adopted certain measures, including organizational ones, such as “bringing responses to requests for clarification regarding the failure to enter into contracts under the oversight of the privacy department” (note dated May 29, 2026, p.
3). A. promptly and proactively “abandoned the project related to the refinement of the customer rating assessment system” (see note dated May 29, 2026, p. 2). Moreover, this project “never saw the light of day because the suspension of activities occurred during a preparatory phase prior to its launch” and “therefore, no actual infringement of the data subject rights ever occurred (…), since the analyses did not affect the outcome of individual cases, nor were they used to determine automated decisions” (see note of May 29, 2026, pp. 2–3, and see note of October 10, 2025, p. 9). 4. The Authority’s Assessments. First of all, it should be noted that, unless the act constitutes a more serious offense, anyone who, in proceedings before the Data Protection Authority, falsely declares or attests to facts or circumstances, or produces false records or documents, is liable under Art. A. have been identified.
1. The Unlawfulness of Customer Data Processing for the Purpose of Verifying Any Past Delinquencies (so-called “Internal Assessment”) First, reference is made to the policy—known as “Credit Check”—which introduces, at the group level, a system for verifying the creditworthiness and reliability of individuals intending to sign up for electricity and/or natural gas service on the open market. A. minutes of March 18, 2024, p. 3). , in accordance with this procedure, conducts—in response to requests from its potential customers— the so-called “Internal Assessment,” which consists of verifying whether the potential customer has any outstanding arrears related to energy supply contracts in the open market, including those established with other Group companies. , pursuant to the “Agreement for the Management of Administrative, Financial, and Control Activities,” signed on July 18, 2013, by the Companies, and the related “Addendum” dated July 3, 2023.
A. A. A. minutes of March 18, 2024, p. 2 and Annex 2). A. A. A. ’s report dated March 18, 2024, p. ’s note dated April 19, 2024, p. 1). A. minutes dated March 18, 2024). A. failed to inform the data subjects in accordance with Articles 13 and 14 of the Regulation. A. notice dated March 21, 2025). A. A. A. notice dated March 21, 2025). A. is inadequate, as it contains no information regarding the processing operations related to the Company’s internal customer assessment activities. All of this constitutes a violation of Article 5(1)(a), as well as Articles 13 and 14 of the Regulation. , pursuant to Art. A. A. ’s customers. A. , services related to the activity of “In-depth support for the analysis of the origination of [its own] Customer Base” (see Annex 2 “Addendum” to the “Contract for the Management of Administrative, Financial, and Control Activities,” from the minutes of March 18, 2024).
A. has violated Article 28 of the Regulation. A. , pursuant to Article 26 of the Regulation, under the terms described in paragraph 3, subparagraph a) of this decision, as well as the resulting update to the customer disclosure templates pursuant to Article 13 of the Regulation. More specifically, it is noted that the aforementioned Agreement defines the respective levels of accountability regarding the processing of data pertaining to the internal verification of customer creditworthiness. A. A. pursuant to Article 6, para 1, subparagraph (f) of the Regulation, to pursue the legitimate interests of the Companies, given the need to ensure the financial soundness of the Companies themselves, as well as that of the Hera Group as a whole, and to minimize exposure to the risk of non-payment by customers (see, in this regard, Recital 47 of the Regulation). In this regard, the reasonable expectations of the data subjects with respect to the processing in question are also taken into account, given that it involves exclusively companies belonging to the same group and is at the same time limited solely to the pre-contractual phase, as well as restricted to the specific sector of energy and gas supply in the liberalized market (see, in this regard, European Data Protection Board, “Guidelines 1/2024 on the processing of personal data based on article 6(1)(f) of the GDPR,” adopted on October 8, 2024, paragraphs 31–60).
, in relation to the performance of operations connected with the so-called Internal Assessment, as the processor pursuant to Article 28 of the Regulation (see Article 8 of the aforementioned Agreement). A. up to the date of signing the aforementioned Joint Controller Agreement for the purpose of verifying any past delinquencies within the scope of the so-called Internal Assessment, is unlawful as it violates Articles 5(1)(a), 13, 14, and 28 of the Regulation. 2. Violations regarding the exercise of rights and the principle of storage limitation. A. provided inadequate and incomplete responses to requests to exercise rights pursuant to Articles 15–22 of the Regulation submitted by the data subjects. In fact, these responses merely contained a reference to the identification of a risk profile for the data subjects, without providing either the “CGS-X Score” or the related sub-scores assigned to the data subject, nor any information regarding the logic used to develop said profile.
“CGS-X Score” and the related sub-scores assigned to the data subject, nor any information on the logic used to develop said profile. A. A. A. in order to obtain further information on the matter (see note dated October 10, 2025, p. 5). All of this occurred even though the information in question was, in fact—as ascertained during the on-site inspections—present in the data controller’s systems (see supra, para. 2 of this notice of violation). In this regard, it should be noted that, in light of the current regulatory framework governing data protection with respect to the exercise of data subject rights, pursuant to Article 15(1) of the Regulation, “the data subject has the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, to obtain access to the personal data and [certain] information” specified in that provision.
—to whom the request was submitted; the data controller is, in fact, required, pursuant to Article 12(3) of the Regulation, to provide the data subject with all personal information subject to such processing. It follows, therefore, that the Company’s argument on this point, as set forth in paragraph 3(b) of this decision, cannot be accepted, since the obligation outlined above—pursuant to Articles 12 and 15 of the Regulation—rests first and foremost with the Company itself, as the controller in question. It is also worth noting that the right of access under Article 15 of the Regulation is primarily conceived as a tool designed, in general terms, the data subject to exercise “control” over the personal data concerning him or her, ensuring that the data subject is fully aware of the information being processed and the actual methods of such processing. The purpose of the right of access is therefore primarily to disclose “what” data and “how” it has been processed by the controller in order to provide the data subject with the means to “know and verify the lawfulness and accuracy of the processing” concerning them (see Recital 63 of the Regulation; European Data Protection Board, “Guideline 1/2022 on the Data Subject Rights—Right of Access,” op.
, paragraphs 10–13). Pursuant to Article 15 of the Regulation, therefore, the data controller, when responding to a request for access, may not limit itself to providing “a general description of the data [or] a mere reference to the categories of data processed,” nor may it omit information in its possession that relates to the data subject; on the contrary, the controller is required to provide access to “all the information referred to in Article 15” pertaining to the data subject and actually subject to processing. Such information “must be complete, accurate, and up-to-date, reflecting as far as possible the status of the data processing at the time the request was received” and must be provided “in a concise, transparent, intelligible, and easily accessible form” to the data subject (see European Data Protection Board, “Guideline 1/2022 on the Rights of Data Subjects—Right of Access,” op.
, para. 34; Article 12(1) of the Regulation). It should also be noted that, in the case at hand, the specific context (processing aimed at generating a score regarding customer reliability), which underlies the requests to exercise the right of access submitted by the data subjects, requires particular attention on the part of the controller, including with regard to the obligation to provide “meaningful information on the logic used, as well as [on] the significance and [on] the anticipated consequences of such processing for the data subject” (Art. 15(1)(h) of the Regulation). With regard to the aforementioned provision, the Court of Justice of the European Union has recently provided useful practical guidance—both substantively, regarding the type of information that the data subject may require from the controller, and formally, regarding the manner in which such information must be provided by the controller (see CJEU judgement of February 27, 2025, C-203/22).
In particular, in clarifying the phrase “meaningful information on the logic used,” the Court specified that this refers to “any relevant information concerning the procedure and principles of the automated processing of personal data for the purpose of achieving a specific result” (see para. 58, CJEU judgement No. C-203/22, cited above). It follows, therefore, that the data subjects, in the case at hand, have the right to be fully informed of all the elements comprising the assessment of their creditworthiness, including those taken into account by the data controller for the purpose of assigning the score, as well as the calculation criteria used (see, in this regard, Order of the Court of Cassation No. 14381 of May 25, 2021). With regard to the manner in which the aforementioned information must be provided, the Court of Justice of the European Union has reaffirmed the data controller’s obligation to provide it “in a concise, transparent, intelligible, and easily accessible form, using plain and clear language”; all in compliance with the principle of transparency set forth in Article 12(1) of the Regulation.
Therefore, “neither the mere communication of a complex mathematical formula, such as an algorithm, nor a detailed description of all the stages of automated decision-making can satisfy these requirements, since neither of these methods would constitute a sufficiently concise and comprehensible explanation” (paragraphs 58–59, CJEU judgement No. C-203/22, cited above). ), without the complexity of the operations to be carried out in the context of the automated decision-making process exempting the controller from its duty to explain” (para. 61, CJEU Judgement No. C-203/22, cited above). ” Furthermore, the Company did not inform the applicants of the logic and criteria applied to the calculation system underlying the development of the credit risk profile. This, therefore, effectively prevented the applicants from accessing the types of personal information actually used for this purpose, as well as from understanding how such information was used.
A. therefore did not enable the data subject to ascertain the lawfulness and fairness of the processing, nor the accuracy of the data used in the context in question, thereby compromising the data subject’s ability to exercise, where applicable, the right to rectification in the event of inaccurate and/or incomplete data (see Art. 16 of the Regulation), as well as the right to “obtain human intervention from the controller, [to] express their opinion and contest the decision” taken against them by the controller (see Art. 22(3) of the Regulation). A. in the case at hand, as it pertains to customers’ creditworthiness—carries the risk of adverse consequences for the fundamental rights and freedoms of the data subjects (such as, for example, as occurred in the cases under review, the refusal to enter into an energy supply contract). A. A. On this point, while taking note of the new response templates adopted by the Company in cases where supply is denied based on its customer acceptance policies, as set forth in Annex 3 of the note dated October 10, 2025, it should be noted that even these templates do not yet contain all the elements required by Article 15 of the Regulation, as specified above.
A. is therefore found to be in violation of Articles 12 and 15 of the Regulation. Finally, it is noted that, with regard to the processing of customers’ personal data collected as part of the aforementioned external assessment, additional violations were identified concerning the storage periods for the data of the aforementioned data subjects. , at the time of the on-site inspections, did not have specific storage periods regarding the storage of customer data collected for the purpose of the External Assessment and that, within the data retention policy—which was still being finalized at the time—a ten-year storage period, generically applicable to accounting documentation, had been identified for such personal data (see Annex 8 of the minutes of March 18, 2024). In this regard, it should be noted that Article 5(1)(e) of the Regulation provides that personal data must be retained in a form that permits identification of the data subject for no longer than is necessary to fulfill the processing purpose.
The storage principle, in fact, imposes on the controller the obligation to assess the duration of processing in necessary correlation with the specific purposes established in advance at the time of collection; this is to “ensure that the retention period for personal data is limited to the minimum necessary” (see Recital 39 of the Regulation). This is, in fact, the controller’s obligation to ensure an “appropriate” duration of processing, which, otherwise, could extend beyond the achievement of the specific processing purposes, thereby affecting the principles of lawfulness, fairness, and transparency (Article 5 of the Regulation). A. had not established specific periods of storage. It is also noted that, although a data retention policy was in the process of being adopted at the time, the Company did not specifically indicate in that policy the reasons for applying the ten-year storage period—generally required for accounting records—to such processing, nor was the compliance of this provision with what is strictly necessary to achieve the processing purpose duly justified.
A. acted in violation of Article 5(1)(e) of the Regulation. On this point, however, it is acknowledged that in February 2026, the Company adopted an updated version of its Data Retention Policy (the so-called “Data Retention Policy”), in which a specific five-year storage period was established for personal data processed for the purpose of verifying customers’ creditworthiness (see Annex 1 of the note dated May 29, 2026, p. 2). 3. The Unlawfulness of the Processing Carried Out as Part of the Group’s Efforts to Refine Its Customer Rating System. ’s report of March 20, 2024, p. 2). A. minutes of March 20, 2024). A. ’s note dated April 19, 2024, p. 2). A. 1. above). ’s minutes of March 20, 2024, p. A. A. minutes dated March 20, 2024). A. A. , the following points should be highlighted. , within the framework of the Credit Information System (known as SIC), is lawfully carried out, provided that the specific regulatory provisions governing the sector are complied with (see Art.
6-bis of Law No. 148 of September 14, 2011; Art. 30-ter of Legislative Decree No. 141/2010; see also Law No. 124/2017), as well as the provisions of the Code of Conduct for information systems managed by private entities regarding consumer credit, creditworthiness, and timely payments (hereinafter the “SIC Code of Conduct,” adopted by resolution of the Data Protection Authority on October 6, 2022, and available on the Authority’s website under web document No. 9818201). The SIC Code of Conduct establishes adequate safeguards to protect the rights of data subjects and sets forth specific rules of conduct that industry operators are required to follow in order to demonstrate that the processing complies with the Regulation (see Recital 77 and Articles 24(3), para 3), 32(para 3), and 28(para 5) of the Regulation). On this point, the legislature has intervened on several occasions to grant access to the data contained in the aforementioned SICs to various parties, including—currently, pursuant to Article 6-bis, of Decree-Law 138/2011 and Art.
) are authorized to consult the personal data contained in the SICs, entering into specific agreements for this purpose with one or more SIC operators” (see, in this regard, points 5 and 6 of the “Preamble” to the aforementioned SIC Code of Conduct). A. A. A. A. dated March 18, 2024). , as the data recipient, may process the information obtained from the SIC “exclusively for purposes related to the assessment, assumption, or management of credit risk, [as well as] for the assessment of the creditworthiness and payment punctuality [of the potential customer]” who has requested to establish a contractual relationship with the Company (see Art 3, Art 8, paragraph 1, and Art 18, paragraph 1, of the SIC Code of Conduct). , as a member “of one of the categories of entities referred to in paragraph 5 of Article 30-ter of Legislative Decree No. 141 of August 13, 2010, No. 1 of “Annex 1 to the General Terms and Conditions – Special Terms and Conditions”).
In this regard, it is worth noting that all parties accessing the SICs must comply with the principle of purpose limitation, which consists of credit protection and the mitigation of related risk, by virtue of which the consultation of a data subject’s personal data may take place only if strictly related to the processing of a request aimed at establishing a relationship with said data subject. Therefore, the processing of data obtained from the SICs is unlawful if carried out for additional purposes or, in any case, not specifically related to a request by a potential customer to enter into a contract with the participant/accessor (see, among others, the decision of the Data Protection Authority dated July 31, 2002, web doc. no. 30000; ruling dated May 4, 2002, web doc. no. 1302311; Decision of May 4, 2006, web doc. no. 1302373). A. for the purpose of refining the customer credit rating system, are conducted in violation of Article 5(1)(b) of the Regulation.
This is because—contrary to what the Company asserted in accordance with paragraph 3(d) of this decision—such processing is aimed at pursuing an additional purpose that is incompatible with the original purpose underlying the collection of the aforementioned personal data. A. A. On this point, it should be noted that commercial information activities are carried out subject to a specific prefectural license issued pursuant to Art. 134 of the Consolidated Law on Public Security (Royal Decree No. 773/1931, as amended and supplemented), and that such activity is governed by specific provisions that define its characteristics and methods of operation(see Ministerial Decree No. 269 of December 1, 2010, and Ministerial Decree No. 56 of February 25, 2015, as well as Royal Decree No. 773/1931). Within this regulatory framework, the processing of personal data in question must be carried out in accordance with the Code of Conduct for the Processing of Personal Data in the Field of Commercial Information (hereinafter the “Code of Conduct for Commercial Information”), adopted by the Data Protection Authority by resolution dated April 29, 2021 (available on the Authority’s website as Web Doc.
No. 9586215). The Code of Conduct provides that commercial information shall be provided to clients for the purpose of conducting “checks on the economic, financial, and asset situation of the data subjects, as well as on their soundness, solvency, and reliability,” with the purpose of establishing and managing relationships—including pre-contractual ones—with the data subjects and providing them with goods, services, and performance (see Articles 2, paragraph 2, letter c), and 6 of the Code of Conduct on Commercial Information). A. A. A. dated March 18, 2024, Appendix 4). This agreement, in accordance with the provisions of the Code of Conduct for Commercial Information, stipulates that “all personal data [collected] during the term of the Contract shall be processed by each of the Parties solely for the purposes specified in the Contract and in a manner necessary for the performance thereof, as well as to comply with any legal obligations, EU regulations, and/or requirements of the Data Protection Authority” (see Art.
A. dated March 18, 2024, Annex 4). , may not be processed for additional purposes that are incompatible with those identified in the Agreement and in the aforementioned Code of Conduct for Commercial Information, which are aimed at assessing the reliability of a potential customer for the purpose of deciding whether or not to accept their request to establish a contractual relationship. The processing carried out by the Company with respect to the aforementioned personal data is therefore unlawful pursuant to Article 5(1)(b) of the Regulation. A. A. A. for subsequent processing aimed at refining the Hera Group’s customer rating assessment system. A. , may change and therefore no longer be up to date. This is because data processing for commercial information purposes and that related to the management of a SIC —both of which, moreover, are carried out by companies specialized in these fields and, in the case of commercial information, specifically authorized by a prefectural license—are governed by specific regulatory and ethical provisions aimed at ensuring, among other things, the accuracy of the data made available to clients.
A. in the manner described above therefore also constitutes a violation of the principle of accuracy set forth in Art. 5, para. 1, letter d) of the Regulation. It should also be noted that the processing of outdated data, as defined in this paragraph—given the specific nature of the aforementioned information (pertaining to the creditworthiness of the data subjects) and its impact on the decisions made by the Company regarding its customers— could result in adverse consequences for the fundamental rights and freedoms of the data subjects. A. minutes dated March 19, 2024). A. is therefore found to have violated Article 5, para 1, subparagraphs (a), (b), and (d) of the Regulation. 5. Conclusions: Declaration that the processing is unlawful. Corrective measures pursuant to Art. 58(2) of the Regulation. In light of the overall findings, the Authority considers that the statements, documentation, and explanations provided by the controller during the investigation do not sufficiently address the objections notified by the Office in thenotice initiating the proceedings and are therefore insufficient to warrant the dismissal of this proceeding, as none of the cases provided for in Art.
11 of the Data Protection Authority’s Regulation
No. 1/2019 apply. , which is the subject of this decision, was therefore conducted in violation of Article 5(1)(a), (b), (d), and (e); as well as Articles 12, 13, 14, 15, and 28 of the Regulation. , during the proceedings, voluntarily adopted certain initial measures aimed at bringing the processing of customer data into compliance with the Regulation, in accordance with the regulatory framework described above. 1. 2. of this decision). Notwithstanding the foregoing, in light of the additional critical issues identified with respect to the controller, as detailed in this decision, it is deemed necessary to order the controller, pursuant to Article 58(2)(c) and (d) of the Regulation, to implement the following corrective measures: a) the development of a new template for responding to requests for access, pursuant to Art 15 of the Regulation, containing all information relating to the “CGS-X Score” and its additional sub-scores, as well as the logic and criteria applied to the system for calculating said score; b) transmission of the aforementioned response template pursuant to Art.
15 of the Regulation also to Messrs. XX, XX, Mr. XX, XX, and XX; c) adoption of a procedure designed to ensure that the data subject can fully exercise the right to rectification pursuant to Article 16 of the Regulation, with respect to inaccurate and/or incomplete personal data processed for the purpose of verifying customer reliability. This procedure must take into account the obligation, set forth in Article 22(3) of the Regulation, to implement appropriate measures to protect the rights, freedoms, and legitimate interests of data subjects; specifically through the right “to obtain human intervention by the controller, [to] express one’s opinion, and to contest the decision” made by the controller (see Article 22(3) of the Regulation). Finally, it should be noted that the violations, as established in the reasoning section, cannot in any way be considered “minor” within the meaning of Recital 148 of the Regulation; given the multiple violations alleged and the number of data subjects involved, as well as the additional factors explained in greater detail in paragraph 6 of this decision.
6. Injunction Order. The Data Protection Authority, pursuant to Article 58, para 2, subparagraph (i) of the Regulation and Article 166 of the Code, has the power to impose an administrative fine provided for in Article 83 of the Regulation, by issuing an injunction order (Article 18. Law No. , which has been found to be unlawful, as set forth herein. The violation of the provisions referred to above entails the application of the administrative fine provided for in Art. 83, para. 4, subpara. (a), and para. 5, subpara. (a) and (b), of the Regulation. Having determined that Art. 83(3) of the Regulation must be applied, which provides that “if, in relation to the same processing operation or to related processing operations, a controller […] intentionally or negligently infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the most serious violation,” the total amount of the fine is calculated so as not to exceed the maximum penalty provided for in Art.
83(5) of the Regulation. With regard to the factors listed in Art. 83(2) of the Regulation for the purposes of imposing the administrative fine and determining its amount, and taking into account that the fine must be “in each individual case effective, proportionate, and dissuasive” (Article 83(1) of the Regulation), it is noted that, in the case at hand, the following circumstances were taken into account: - the significant severity of the violation (Article 83(2)(a) of the Regulation), in relation to its nature (concerning non-compliance with the general principles of lawfulness, fairness, and transparency, as well as those of purpose limitation, accuracy, and storage limitation), the manner in which it occurred (the multiple instances of unlawful conduct repeated over time), and its duration (approximately 2 years). Also considered relevant for this purpose are the context of the processing, as well as the high number of data subjects involved and the type of harm they suffered.
All of this, given that: the operations in question were carried out for the purpose of developing a risk profile regarding the reliability of potential customers in terms of timely payments; the unlawful conduct affected approximately 1 million data subjects; the established violations resulted, in most cases, to the detriment of the data subjects, in the refusal to enter into an energy and/or gas supply contract; - the negligent nature of the conduct and the significant degree of accountability of the controller regarding the technical and organizational measures implemented (Articles 83, para 2, subparagraphs (b) and (d) of the Regulation). All of this, with particular regard to the lack and inadequacy—in the specific context at hand—of the measures and processes implemented by the Company concerning compliance with obligations related to the exercise of data subject rights. A. aimed at verifying customer reliability, the Company failed to correctly identify the processing purposes related to refining the Hera Group’s customer rating assessment system, nor the roles—with respect to personal data protection regulations—to be assigned to the companies involved in the internal assessment activity; - the fact that there are no previous relevant violations committed by the controller or previous measures referred to in Art 58 of the Regulation concerning the same subject matter (Article 83(2)(e) and (i) of the Regulation).
On this point, it should be noted that Measure No. , was not taken into account for this purpose; this is due to the fact that the preliminary investigation pertaining to this decision was conducted concurrently with the one that led to the adoption of the aforementioned measure; - in favor of the violator, account is taken of the fact that the Company has complied with the requirements set forth by the Authority in Measure No. 440, referred to above (Art. 83(2)(i) of the Regulation); - the adoption by the data controller of measures designed to mitigate or eliminate the consequences of the violation (Articles 83, para 2, subparagraph c) of the Regulation). A. voluntarily adopted, once it became aware of the violation, certain initial measures to mitigate the effects of the unlawful processing—albeit measures that were only partially effective in reducing the risks—should be viewed favorably; - the fact that the Company actively cooperated with the Authority during the proceedings (Article 83(2)(f) of the Regulation); - the nature of the information subject to the breach (Article 83(2)(g) of the Regulation), which, although not classified as special categories of data, is nonetheless considered sensitive as it reflects the reliability of customers’ timely payments; this also taking into account the potential economic and social consequences that may arise for the data subjects as a result of the unlawful processing of their data; - other mitigating factors (Article 83(2)(k) of the Regulation), such as the adoption of certain organizational measures, as well as the fact that the processing operations related to the aforementioned violations concern only a portion of the Company’s customer base.
All of this is described in greater detail in para 3 of this decision. It is further considered that, in the present case, the following factors are relevant in light of the aforementioned principles of effectiveness, proportionality, and deterrence that the Authority must adhere to when determining the amount of the fine (Art. 83(1) of the Regulation): the economic circumstances of the offender, determined on the basis of the Company’s turnover as reported in the financial statements for the year 2024 (the most recent available). A. 00 euros (five million eight hundred thousand/00). In this context, it is also considered that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, this chapter containing the injunction order must be published on the Data Protection Authority’s website. This is in light of the specific nature of the data subject to the processing at issue—as it pertains to the data subject’s creditworthiness—as well as the nature of the violations found, which affected the general principles of processing, in particular the principle of transparency and the obligations regarding the exercise of the data subject rights.
Finally, it is considered that the conditions set forth in Art. 17 of the Data Protection Authority’s Regulation No. 1/2019 are met. , with its registered office in Imola, VAT No. A. 00 euros (five million eight hundred thousand/00), as an administrative fine for the violations set forth in this order, in accordance with the procedures outlined in the attachment, within thirty days of the service of this order, failing which the necessary enforcement measures will be taken pursuant to Art. 27 of Law No. 689/1981. It is noted that, pursuant to Article 166, paragraph 8 of the Code, the offender retains the right to settle the dispute by paying an amount equal to half of the imposed penalty within the time limit set forth in Article 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, set for filing an appeal as indicated below; ORDERS - pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No.
1/2019, the publication of the injunction order on the Data Protection Authority’s website; - pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Authority’s Regulation No. 1/2019, the publication of this order on the Authority’s website; - Pursuant to Article 17 of the Authority’s Regulation No. 1/2019, the recording of the violations and the measures adopted in accordance with Article 58(2) of the Regulation in the Authority’s internal register provided for under Article 57(1)(u) of the Regulation. Pursuant to Article 78 of Regulation (EU) 2016/679, as well as Article 152 of the Code and Article 10 of Legislative Decree No. 150 of September 1, 2011, an appeal against this decision may be filed with the ordinary courts by filing a petition with the ordinary court of the location specified in the aforementioned Art 10, within thirty days from the date of notification of the decision, or within sixty days if the appellant resides abroad.
Rome, July 3, 2026 THE CHAIRMAN Stanzione THE RAPPORTEUR Stanzione THE SECRETARY GENERAL Montuori [Web Doc. No. 10273926] Decision of July 3, 2026 Register of Decisions No. 483 of July 3, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, President; Prof. Ginevra Cerrina Feroni, Vice President; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter the “Regulation”); HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003 (Code on Data Protection, hereinafter the “Code”), as amended by Legislative Decree No. 101 of August 10, 2018, containing “Provisions for the alignment of national legislation with the provisions of Regulation (EU) 2016/679”; HAVING EXAMINED the documentation on file; HAVING CONSIDERED the observations made by the Secretary General pursuant to Art.
15 of the Data Protection Authority’s Regulation
No. 1/2000; RAPPORTEUR: Prof. Pasquale Stanzione; WHEREAS 1. Introduction. A. for the purpose of verifying the creditworthiness of potential customers. A. ). ” This software enables the aforementioned energy suppliers to identify a risk profile regarding the creditworthiness of potential customers, based on an integrated indicator called the “Integrated Utilities Score” (hereinafter also referred to as the “CGS-X Score”). A. , these companies, when questioned on the matter, stated that their systems contained no negative information and/or adverse events regarding the aforementioned data subjects. A. , pursuant to Article 15 of the Regulation (see the request by Mr. XX dated March 1, 2023, the request filed by Mr. XX on June 29, 2023, the request filed by Mr. XX on June 14, 2024, the request filed by Mr. XX on July 15, 2024, and the request filed by Ms.
XX on September 13, 2024). With regard to the foregoing, it should be noted that the Authority, in view of the numerous requests received, first decided to consolidate the individual proceedings referred to above in order to conduct a comprehensive examination of the underlying issues and subsequently initiated, on its own initiative, pursuant to Article 21 of the Data Protection Authority’s Regulation No. A. l. A. A. A. on June 13 and 14, 2024. A. on October 16, 2024. 2. The Investigation. As part of the proceedings, with regard to the issues highlighted in the introduction, the following findings emerged. 1. The Credit Check Process. A. ’s statement of March 18, 2024, p. 2). A. memorandum dated April 19, 2024, p. 1). ), has adopted a Credit Policy and implemented a system for verifying and assessing the solvency and creditworthiness of parties applying to participate in one of the open-market offers (hereinafter, “Credit Check”).
A. note dated July 30, 2024, p. 2). A. A. , and the related “Addendum” dated July 3, 2023. A. A. minutes of March 18, 2024, p. 2 and Annex 2). A. minutes of March 18, 2024, p. A. minutes of March 19, 2024, p. 2). ’s note dated April 19, 2024, p. 1 and Annex 1). ’s minutes of March 18, 2024, p. 3). A. “checks, based on the potential customer’s personal data (first name, last name, tax ID, and business partner), for any prior delinquencies, returning an ‘OK’ or ‘KO’ result. (…) The query, conducted online and in real time, concerns active, uncontested arrears relating solely to the energy sector in the deregulated market. A. minutes of March 18, 2024, p. 3). A. A. l. and named “CGS-X”]. l. —which acts as a technology outsourcing provider, supplying the license to use the “CGS-X” software—as the processor pursuant to Art. ’s minutes of March 18, 2024, p. l. dated April 15, 2024, p. 3). A. dated March 18, 2024, p.
3). A. to develop a risk profile regarding the creditworthiness of potential customers based on the integrated “CGS-X Score” indicator. ). A. ). A. minutes of March 18, 2024, p. l. minutes of April 15, 2024, p. 3). l. dated April 16, 2024, pp. A. dated March 18, 2024, p. 4). l. dated April 16, 2024, pp. 3–4). A. A. minutes of March 18, 2024, p. 4). A. minutes of March 18, 2024, p. 4). A. A. minutes of March 18, 2024, pp. 4 and 5). A. minutes of March 18, 2024, pp. 4 and 5). A. minutes of March 19, 2024). A. dated March 18, 2024, p. 5). A. minutes of March 18, 2024, p. 5 and Annex 8). 2. Procedures for responding to data subject rights requests. With regard to requests submitted by data subjects pursuant to Article 15 of the Regulation, although the Company responded within the time limits set forth in Article 12 of the Regulation, in its responses it limited itself to referring solely to the identification of a risk profile for the data subjects.
’s notes dated August 17, 2022, August 29, 2023, and August 25, 2023). ’s notice dated August 25, 2023; see also the Company’s notices dated August 17, 2022, and August 29, 2023). A. A. A. ’s notes dated August 17, 2022, August 29, 2023, and August 25, 2023). During the investigation, it was further established that, in none of the cases subject to complaint, did the aforementioned findings refer to the “CGS-X Score” and the related sub-scores assigned to the data subject. l. l. A. ’s report dated March 19, 2024, pp. 1, 3, and 4, and Attachments Nos. ’s minutes of March 20, 2024, pp. 1 and 3, and Attachments Nos. 1 and 7). 3. The refinement of the Hera Group’s customer rating service. A. minutes of March 20, 2024, p. 2). ’s minutes of March 19, 2024, p. 3). A. A. A. dated March 20, 2024, p. 2). A. A. note dated April 19, 2024, p. 2). These analyses—for which the legend of the relevant fields has been obtained (see Annex No.
A. ’s minutes of March 20, 2024, p. 2). A. minutes of March 20, 2024, p. 2). A. minutes of March 20, p. 2). A. minutes of March 20, 2024, p. 2). A. A. ’s minutes of March 20, 2024, p. 2). A. minutes of March 19, 2024). In particular, during the inspections, “a sample report of the analysis conducted—relating to customers who entered the origination process in 2022, with account statement data updated as of today—was examined. A. minutes of March 20, 2024, p. 2). 3. The notification pursuant to Article 166, paragraph 5, of the Code. A. by notice dated July 14, 2025, the Company, by letter dated October 10, 2025, submitted its defense briefs, which were further supplemented during the hearing on May 20, 2026, and by a subsequent letter dated May 29, 2026. A. made the following representations: a) regarding the allegation concerning the unlawfulness of processing the data of potential customers as part of the activities related to the so-called “Internal Assessment of Past Delinquencies,” “a joint controller agreement was signed between Hera Comm and EstEnergy, pursuant to Art.
26 of the Regulation”
This was done with the aim of jointly sharing, storing, and processing the personal data collected by the companies for the purpose of verifying the creditworthiness of customers in the free market segment for electricity and natural gas. This processing is designed to safeguard the financial stability of the Hera Group and minimize exposure to the risk of insolvency by acquiring customers who are financially sound and creditworthy. In conclusion, this activity represents “an essential safeguard aimed at ensuring the reliability of supplies and the economic sustainability of sales operations in the free market” (see note dated October 10, 2025, p. 3). Following the signing of the aforementioned joint-controller agreement, “the relevant notices provided to customers have been updated to ensure full transparency regarding data processing,” including with regard to the new structure of shared roles and accountability (see note dated October 10, 2025, p.
4; see also the note dated May 29, 2026, pp. A. ) enhanced with additional elements aimed at ensuring a more complete representation of the information processed and at strengthening transparency toward customers” have been prepared (see note dated October 10, 2025, pp. 5–8 and Annex 3); c) regarding the retention periods for customer data in connection with external assessment activities, which were deemed non-compliant with the storage limitation principle, the Company “has developed and progressively implemented a specific data retention policy for credit data, which defines specific periods of storage and automated procedures for erasure upon the expiration of the established periods, in full compliance with Article 5, paragraph 1, letter e) of the GDPR” (see note dated October 10, 2025, p. 8, and note dated May 29, 2026, pp. A. ) since the analyses did not affect the outcome of individual cases, nor were they used to determine automated decisions” (see note dated October 10, 2025, p.
9). ; this is because the aforementioned activity is “carried out solely with respect to residential customers requesting the activation of electricity and gas supply contracts in the free market, as well as with respect to customers requesting the activation of contracts under the gas vulnerability protection program” (see note dated May 29, 2026, p. 4). The Company also highlighted that, in order to ensure full compliance of the processing in question with the Regulation, it has adopted certain measures, including organizational ones, such as “bringing responses to requests for clarification regarding the failure to enter into contracts under the oversight of the privacy department” (note dated May 29, 2026, p. 3). A. promptly and proactively “abandoned the project related to the refinement of the customer rating assessment system” (see note dated May 29, 2026, p. 2). Moreover, this project “never saw the light of day because operations were suspended during a preparatory phase prior to its launch” and “therefore, no actual infringement of the data subject rights ever occurred (…), since the analyses did not affect the outcome of individual cases, nor were they used to determine automated decisions” (see note of May 29, 2026, pp.
2–3, and note of October 10, 2025, p. 9). 4. The Authority’s Assessments. First of all, it should be noted that, unless the act constitutes a more serious offense, anyone who, in proceedings before the Data Protection Authority, falsely declares or attests to information or circumstances, or produces false records or documents, is liable under Art. A. have been identified. 1. The Unlawfulness of Customer Data Processing for the Purpose of Verifying Any Past Delinquencies (so-called “Internal Assessment”) First, reference is made to the policy—known as “Credit Check”—which introduces, at the group level, a system for verifying the solvency and creditworthiness of individuals intending to subscribe to electricity and/or natural gas service offers in the open market. A. minutes of March 18, 2024, p. 3). , in accordance with this procedure, conducts—in response to requests made by its potential customers— the so-called “Internal Assessment,” which consists of verifying whether the potential customer has any outstanding arrears related to energy supply contracts in the open market, including those established with other Group companies.
, pursuant to the “Agreement for the Management of Administrative, Financial, and Control Activities,” signed on July 18, 2013, by the Companies, and the related “Addendum” dated July 3, 2023. A. A. as the processor pursuant to Art. A. minutes of March 18, 2024, p. 2 and Annex 2). A. A. A. ’s report dated March 18, 2024, p. ’s note dated April 19, 2024, p. 1). A. minutes dated March 18, 2024). A. failed to inform the data subjects in accordance with Articles 13 and 14 of the Regulation. A. notice dated March 21, 2025). A. A. A. notice dated March 21, 2025). A. is inadequate, as it contains no information regarding the processing operations related to the Company’s internal customer assessment activities. All of this constitutes a violation of Article 5(1)(a), as well as Articles 13 and 14 of the Regulation. , pursuant to Art. A. A. ’s customers. A. , services related to the activity of “In-depth support for the analysis of the origination of [its own] Customer Base” (see Annex 2 “Addendum” to the “Contract for the Management of Administrative, Financial, and Control Activities,” from the minutes of March 18, 2024).
A. has violated Article 28 of the Regulation. A. , pursuant to Article 26 of the Regulation, under the terms described in paragraph 3, subparagraph a) of this decision, as well as the resulting update to the customer disclosure templates pursuant to Article 13 of the Regulation. More specifically, it is noted that the aforementioned Agreement defines the respective levels of accountability regarding the processing of data pertaining to the internal verification of customer creditworthiness. A. A. pursuant to Article 6, para 1, subparagraph (f) of the Regulation, to pursue the legitimate interests of the Companies, given the need to ensure the protection of their financial soundness, as well as that of the Hera Group as a whole, and to minimize exposure to the risk of non-payment by customers (see, in this regard, Recital 47 of the Regulation). In this regard, the reasonable expectations of the data subjects with respect to the processing in question are also taken into account, given that it involves exclusively companies belonging to the same group and is, at the same time, limited solely to the pre-contractual phase, as well as restricted to the specific sector of energy and gas supply in the liberalized market (see, in this regard, European Data Protection Board, “Guidelines 1/2024 on the Processing of Personal Data Based on Article 6(1)(f) of the GDPR,” adopted on October 8, 2024, paragraphs 31–60).
, in relation to the performance of operations connected with the so-called Internal Assessment, as the processor pursuant to Article 28 of the Regulation (see Article 8 of the aforementioned Agreement). , up to the date of signing the aforementioned Joint Controller Agreement for the purpose of verifying any past delinquencies within the scope of the so-called Internal Assessment, is unlawful as it violates Articles 5(1)(a), 13, 14, and 28 of the Regulation. 2. Violations regarding the exercise of rights and the principle of storage limitation. A. provided inadequate and incomplete responses to requests to exercise rights pursuant to Articles 15–22 of the Regulation submitted by the data subjects. In fact, these responses merely contained a reference to the identification of a risk profile for the data subjects, without providing either the “CGS-X Score” and the related sub-scores assigned to the data subject, nor any information on the logic used to develop said profile.
A. A. A. directly for further information on the matter (see note dated October 10, 2025, p. 5). 2 of this notice of violation). In this regard, it should be noted that, in light of the current regulatory framework governing data protection with respect to the exercise of data subject rights, pursuant to Article 15(1) of the Regulation, “the data subject has the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, to obtain access to the personal data and [certain] information” specified in that provision. —to whom the request was submitted; the data controller is, in fact, required, pursuant to Article 12(3) of the Regulation, to provide the data subject with all personal information subject to such processing. It follows, therefore, that the Company’s argument on this point, as set forth in paragraph 3(b) of this decision, cannot be accepted, since the obligation outlined above—pursuant to Articles 12 and 15 of the Regulation—rests first and foremost with the Company itself, as the controller in question.
It is also worth noting that the right of access under Article 15 of the Regulation is primarily conceived as a tool designed, in general terms, the data subject to exercise “control” over the personal data concerning him or her, ensuring that the data subject is fully aware of the information being processed and the actual methods of such processing. The purpose of the right of access is therefore primarily to disclose “what” data and “how” it has been processed by the controller in order to provide the data subject with the means to “know and verify the lawfulness and accuracy of the processing” concerning them (see Recital 63 of the Regulation; European Data Protection Board, “Guideline 1/2022 on the Data Subject Rights—Right of Access,” op. , paragraphs 10–13). Pursuant to Article 15 of the Regulation, therefore, the data controller, when responding to a request for access, may not limit itself to providing “a general description of the data [or] a mere reference to the categories of data processed,” nor may it omit information in its possession that relates to the data subject; on the contrary, the controller is required to provide access to “all the information referred to in Article 15” pertaining to the data subject and actually subject to processing.
Such information “must be complete, accurate, and up-to-date, reflecting as far as possible the status of the data processing at the time the request was received” and must be provided “in a concise, transparent, intelligible, and easily accessible form” to the data subject (see European Data Protection Board, “Guidelines 1/2022 on the Rights of Data Subjects—Right of Access,” op. , para. 34; Article 12(1) of the Regulation). It should also be noted that, in the case at hand, the specific context (processing aimed at calculating a score regarding customer reliability), underlying the requests to exercise the right of access submitted by the data subjects, requires particular attention on the part of the controller, including with regard to the obligation to provide “meaningful information on the logic used, as well as [on] the significance and [on] the anticipated consequences of such processing for the data subject” (Article 15, para 1, subparagraph (h) of the Regulation).
With regard to the aforementioned provision, the Court of Justice of the European Union has recently provided useful practical guidance—both substantively, regarding the type of information that the data subject may require from the controller, and formally, regarding the manner in which such information must be provided by the controller (see CJEU judgement of February 27, 2025, C-203/22). In particular, in clarifying the phrase “meaningful information on the logic used,” the Court specified that this refers to “any relevant information concerning the procedure and principles of the automated processing of personal data for the purpose of achieving a specific result” (see para. 58, CJEU judgement No. C-203/22, cited above). It follows, therefore, that the data subjects, in the case at hand, have the right to be fully informed of all the elements comprising the assessment of their creditworthiness, including those taken into account by the data controller for the purpose of assigning the score, as well as the calculation criteria used (see, in this regard, Order of the Court of Cassation No.
14381 of May 25, 2021). With regard to the manner in which the aforementioned information must be provided, the Court of Justice of the European Union has reaffirmed the data controller’s obligation to provide it “in a concise, transparent, intelligible, and easily accessible form, using plain and clear language”; all in compliance with the principle of transparency set forth in Article 12(1) of the Regulation. Therefore, “neither the mere communication of a complex mathematical formula, such as an algorithm, nor a detailed description of all the stages of automated decision-making can satisfy these requirements, since neither of these methods would constitute a sufficiently concise and comprehensible explanation” (paragraphs 58–59, CJEU Judgement No. C-203/22, cited above). ), without the complexity of the operations to be carried out in the context of the automated decision-making process exempting the controller from its duty to explain” (para.
61, CJEU Judgement No. C-203/22, cited above). ” Furthermore, the Company did not inform the applicants of the logic and criteria applied to the calculation system underlying the development of the credit risk profile. This, therefore, effectively prevented the applicants from accessing the types of personal information actually used for this purpose, as well as from understanding how such information was used. A. therefore did not enable the data subject to ascertain the lawfulness and fairness of the processing, nor the accuracy of the data used in the context in question, thereby compromising the data subject’s ability to exercise, where applicable, the right to rectification in the event of inaccurate and/or incomplete data (see Art. 16 of the Regulation), as well as the right to “obtain human intervention from the controller, [to] express their opinion and contest the decision” taken against them by the controller (see Art.
22(3) of the Regulation). A. in the case at hand, as it pertains to customers’ creditworthiness—carries the risk of adverse consequences on the fundamental rights and freedoms of the data subjects (such as, for example, as occurred in the cases under review, the refusal to enter into an energy supply contract). It should also be noted that, due to the Company’s conduct, the data subjects incurred additional costs and delays, given the burden of having to submit further requests pursuant to Art. A. A. On this point, while taking note of the new response templates adopted by the Company in cases where supply is denied based on its customer acceptance policies, as set forth in Annex 3 of the note dated October 10, 2025, it should be noted that even these templates do not yet contain all the elements required by Art 15 of the Regulation, as specified above. A. is therefore found to be in violation of Articles 12 and 15 of the Regulation.
Finally, it is noted that, with regard to the processing of customers’ personal data collected as part of the aforementioned external assessment, additional violations were identified concerning the storage periods for the data of the aforementioned data subjects. , at the time of the on-site inspections, did not have specific timeframes regarding the storage of customer data collected for the purposes of the External Assessment and that, within the data retention policy—which was still being drafted at the time—a ten-year storage period, generically applicable to accounting documentation, had been identified for such personal data (see Annex 8 of the minutes of March 18, 2024). In this regard, it should be noted that Article 5(1)(e) of the Regulation provides that personal data must be retained in a form that permits identification of the data subject for no longer than is necessary to fulfill the processing purpose.
The data storage principle, in fact, requires the controller to assess the duration of the processing in light of the specific purposes established in advance at the time of collection; this is to “ensure that the period of storage for personal data is limited to the minimum necessary” (see Recital 39 of the Regulation). This is, in fact, the controller’s obligation to ensure an “appropriate” duration of processing, which, otherwise, could extend beyond the achievement of the specific processing purposes, thereby affecting the principles of lawfulness, fairness, and transparency (Art. 5 of the Regulation). A. had not established specific periods of storage. It is also noted that, although a data retention policy was in the process of being adopted at the time, the Company did not specifically indicate in that policy the reasons for applying the ten-year storage period—generally required for accounting records—to such processing, nor was the compliance of this provision with what is strictly necessary to achieve the processing purpose duly justified.
A. acted in violation of Article 5(1)(e) of the Regulation. On this point, however, it is acknowledged that in February 2026, the Company adopted an updated version of its Data Retention Policy (the so-called “Data Retention Policy”), in which a specific five-year storage period was established for personal data processed for the purpose of verifying customers’ creditworthiness (see Annex 1 of the note dated May 29, 2026, p. 2). 3. The Unlawfulness of the Processing Carried Out as Part of the Group’s Efforts to Refine Its Customer Rating Assessment System. ’s report of March 20, 2024, p. 2). A. minutes of March 20, 2024). A. ’s note dated April 19, 2024, p. 2). A. 1. above). ’s minutes of March 20, 2024, p. A. A. minutes dated March 20, 2024). A. A. , the following points should be highlighted. , within the framework of the Credit Information System (so-called SIC), is lawfully carried out, provided that the specific regulatory provisions of the sector are complied with (see Art.
6-bis of Law No. 148 of September 14, 2011; Art. 30-ter of Legislative Decree No. 141/2010; see also Law No. 124/2017), as well as the provisions of the Code of Conduct for information systems managed by private entities regarding consumer credit, creditworthiness, and timely payments (hereinafter the “SIC Code of Conduct,” adopted by resolution of the Data Protection Authority on October 6, 2022, and available on the Authority’s website as Web Doc. No. 9818201). The SIC Code of Conduct establishes adequate safeguards to protect the rights of data subjects and sets forth specific rules of conduct that industry operators are required to follow in order to demonstrate that the processing complies with the Regulation (see Recital 77 and Articles 24(3), para 3), 32(para 3), and 28(para 5) of the Regulation). On this point, the legislature has intervened on several occasions to grant access to the data contained in the aforementioned SICs to various parties, including, currently, pursuant to article 6-bis, of Decree-Law 138/2011 and Art.
) are authorized to consult the personal data contained in the SICs, entering into specific agreements for this purpose with one or more SIC operators” (see, in this regard, points 5 and 6 of the “Preamble” to the aforementioned SIC Code of Conduct). A. A. A. A. dated March 18, 2024). , as the data recipient, may process the information obtained from the SIC “exclusively for purposes related to the assessment, assumption, or management of credit risk, [as well as] for the assessment of the creditworthiness and payment punctuality [of the potential customer]” who has requested to establish a contractual relationship with the Company (see Article 3, Article 8, paragraph 1, and Article 18, paragraph 1, of the SIC Code of Conduct). , as it belongs “to one of the categories of entities referred to in paragraph 5 of Article 30-ter of Legislative Decree No. 141 of August 13, 2010, No. 1 of “Annex 1 to the General Terms and Conditions – Special Terms and Conditions”).
In this regard, it is worth noting that all parties accessing the SICs must comply with the principle of purpose limitation, which consists of credit protection and the mitigation of related risk, by virtue of which the consultation of a data subject’s personal data may take place only if strictly related to the processing of a request aimed at establishing a relationship with said data subject. Therefore, the processing of data obtained from the SICs is unlawful if carried out for additional purposes or, in any case, not specifically linked to a request by a potential customer to enter into a contract with the participant/accessor (see, among others, the ruling of the Data Protection Authority dated July 31, 2002, web doc. no. 30000; ruling dated May 4, 2002, web doc. no. 1302311; Decision of May 4, 2006, web doc. no. 1302373). A. for the purpose of refining the customer rating assessment system, are conducted in violation of Article 5(1)(b) of the Regulation.
This is because—contrary to what the Company asserted in accordance with paragraph 3(d) of this decision—such processing is aimed at pursuing an additional purpose that is incompatible with the original purpose underlying the collection of the aforementioned personal data. A. A. On this point, it should be noted that commercial information activities are carried out subject to a specific prefectural license issued pursuant to Art. 134 of the Consolidated Law on Public Security (Royal Decree No. 773/1931, as amended and supplemented), and that such activity is governed by specific provisions that define its characteristics and methods of operation(see Ministerial Decree No. 269 of December 1, 2010, and Ministerial Decree No. 56 of February 25, 2015, as well as Royal Decree No. 773/1931). Within this regulatory framework, the processing of personal data in question must be carried out in accordance with the Code of Conduct for the Processing of Personal Data in the Field of Commercial Information (hereinafter the “Code of Conduct for Commercial Information”), adopted by the Data Protection Authority by resolution dated April 29, 2021 (available on the Authority’s website as Web Doc.
No. 9586215). The Code of Conduct provides that commercial information shall be provided to clients for the purpose of conducting “assessments of the economic, financial, and asset situation of the data subjects, as well as their soundness, solvency, and reliability,” for the purpose of establishing and managing relationships—including pre-contractual ones—with the data subjects and providing them with goods, services, and other benefits (see Articles 2, paragraph 2, letter c), and 6 of the Code of Conduct on Commercial Information). A. A. A. dated March 18, 2024, Appendix 4). This agreement, in accordance with the provisions of the Code of Conduct for Commercial Information, stipulates that “all personal data [collected] during the term of the Contract shall be processed by each of the Parties solely for the purposes specified in the Contract and in a manner necessary for the performance thereof, as well as to comply with any legal obligations, EU regulations, and/or requirements of the Data Protection Authority” (see Art.
A. dated March 18, 2024, Annex 4). , cannot be processed for additional purposes that are incompatible with those identified in the Agreement and in the aforementioned Code of Conduct for Commercial Information, which are aimed at assessing the reliability of a potential customer for the purpose of deciding whether or not to accept their request to establish a contractual relationship. The processing carried out by the Company with respect to the aforementioned personal data is therefore unlawful pursuant to Article 5(1)(b) of the Regulation. A. A. A. for subsequent processing aimed at refining the Hera Group’s customer rating assessment system. A. , may change and therefore no longer be up to date. This is because data processing for commercial information purposes and that related to the management of a SIC —both of which, moreover, are carried out by companies specialized in these fields and, in the case of commercial information, specifically authorized by a prefectural license—are governed by specific regulatory and ethical provisions aimed at ensuring, among other things, the accuracy of the data made available to clients.
A. in the manner described above therefore also constitutes a violation of the principle of accuracy set forth in Art. 5, para. 1, subparagraph d) of the Regulation. It should also be noted that the processing of outdated data, as defined in this paragraph—given the specific nature of the aforementioned information (pertaining to the creditworthiness of the data subjects) and its impact on the decisions made by the Company regarding its customers— could result in adverse consequences for the fundamental rights and freedoms of the data subjects. A. minutes dated March 19, 2024). A. is therefore found to have violated Article 5(1)(a), (b), and (d) of the Regulation. 5. Conclusions: Declaration that the processing was unlawful. Corrective measures pursuant to Art. 58(2) of the Regulation. In light of the overall findings, the Authority considers that the statements, documentation, and explanations provided by the controller during the investigation do not sufficiently address the objections notified by the Office in thenotice initiating the proceedings and are therefore insufficient to warrant the dismissal of this proceeding, as none of the cases provided for in Art.
11 of the Data Protection Authority’s Regulation
No. 1/2019 apply. , which is the subject of this decision, was therefore conducted in violation of Article 5(1)(a), (b), (d), and (e); as well as Articles 12, 13, 14, 15, and 28 of the Regulation. , during the proceedings, voluntarily adopted certain initial measures aimed at bringing the processing of customer data into compliance with the Regulation, in accordance with the regulatory framework described above. 1. 2. of this decision). Notwithstanding the foregoing, in light of the additional critical issues identified with respect to the controller, as detailed in this decision, it is deemed necessary to order the controller, pursuant to Article 58(2)(c) and (d) of the Regulation, to implement the following corrective measures: a) the development of a new template for responding to requests for access, pursuant to Art 15 of the Regulation, containing all information relating to the “CGS-X Score” and the additional sub-scores, as well as the logic and criteria applied to the system for calculating said score; b) transmission of the aforementioned response template pursuant to Article 15 of the Regulation also to Messrs.
XX, XX, Mr. XX, XX, and XX; c) adoption of a procedure designed to ensure that the data subject can fully exercise the right to rectification pursuant to Article 16 of the Regulation, with respect to inaccurate and/or incomplete personal data processed for the purpose of verifying customer reliability. This procedure must take into account the obligation, set forth in Article 22(3) of the Regulation, to implement appropriate measures to protect the rights, freedoms, and legitimate interests of data subjects; specifically through the right “to obtain human intervention by the controller, [to] express one’s opinion, and to contest the decision” made by the controller (see Article 22(3) of the Regulation). Finally, it should be noted that the violations, as established in the reasoning section, cannot in any way be considered “minor” within the meaning of Recital 148 of the Regulation; given the multiple violations alleged and the number of data subjects involved, as well as the additional factors explained in greater detail in paragraph 6 of this decision.
6. Injunction Order. The Data Protection Authority, pursuant to Article 58, para 2, subparagraph (i) of the Regulation and Article 166 of the Code, has the power to impose an administrative fine as provided for in Article 83 of the Regulation, by issuing an injunction order (Article 18. Law No. , which has been found to be unlawful, as set forth herein. The violation of the provisions referred to above entails the application of the administrative fine provided for in Art. 83, para. 4, subparagraph (a), and para. 5, subparagraphs (a) and (b), of the Regulation. Having determined that Article 83(3) of the Regulation must be applied, which provides that “if, in relation to the same processing operation or to related processing operations, a controller […] intentionally or negligently infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the most serious violation,” the total amount of the fine is calculated so as not to exceed the maximum penalty provided for in Art.
83(5) of the Regulation. With regard to the factors listed in Article 83(2) of the Regulation for the purposes of imposing the administrative fine and determining its amount, and taking into account that the fine must be “in each individual case effective, proportionate, and dissuasive” (Article 83(1) of the Regulation), it is noted that, in the case at hand, the following circumstances were taken into account: - the significant severity of the violation (Article 83(2)(a) of the Regulation), in relation to its nature (concerning non-compliance with the general principles of lawfulness, fairness, and transparency, as well as those of purpose limitation, accuracy, and storage limitation), the manner in which it occurred (the multiple instances of unlawful conduct repeated over time), and its duration (approximately 2 years). Also considered relevant for this purpose are the context of the processing, as well as the large number of data subjects involved and the type of harm they suffered.
All of this, given that: the disputed transactions were carried out for the purpose of developing a risk profile regarding the reliability of potential customers in terms of timely payments; the unlawful conduct affected approximately 1 million data subjects; the violations found resulted, in most cases, to the detriment of the data subjects, in the refusal to enter into an energy and/or gas supply contract; - the negligent nature of the conduct and the significant instance of accountability on the part of the controller with regard to the technical and organizational measures implemented (Articles 83(2)(b) and (d) of the Regulation). All of this, with particular regard to the lack and inadequacy—in the specific context at hand—of the measures and processes implemented by the Company concerning compliance with obligations related to the exercise of data subject rights. A. aimed at verifying customer reliability, the Company failed to correctly identify the processing purposes related to refining the Hera Group’s customer rating assessment system, nor the roles—with respect to personal data protection regulations—to be assigned to the companies involved in the internal assessment activity; - the fact that there are no previous relevant violations committed by the controller or previous measures referred to in Article 58 of the Regulation concerning the same subject matter (Article 83(2)(e) and (i) of the Regulation).
On this point, it should be noted that Measure No. , was not taken into account for this purpose; this is due to the fact that the preliminary investigation pertaining to this decision was conducted concurrently with the one that led to the adoption of the aforementioned measure; - in favor of the violator, account is taken of the fact that the Company has complied with the requirements set forth by the Authority in Measure No. 440, referred to above (Art 83(2)(i) of the Regulation); - the adoption by the data controller of measures designed to mitigate or eliminate the consequences of the violation (Art. 83(2)(c) of the Regulation). A. voluntarily adopted, upon becoming aware of the violation, certain initial measures to mitigate the effects of the unlawful processing—albeit measures that were only partially effective in reducing the risks—should be viewed favorably; - the fact that the Company actively cooperated with the Authority during the proceedings (Articles 83(2)(f) of the Regulation); - the nature of the information subject to the breach (Article 83(2)(g) of the Regulation), which, although not classified as special categories of data, is nonetheless considered sensitive as it reflects the reliability of customers’ payment timeliness; this also taking into account the potential economic and social consequences that may arise for the data subjects as a result of the unlawful processing; - other mitigating factors (Article 83(2)(k) of the Regulation), such as the adoption of certain organizational measures, as well as the fact that the processing operations related to the aforementioned violations concern only a portion of the Company’s customer base.
All of this is described in greater detail in para 3 of this decision. It is further considered that, in the present case, the following factors are relevant in light of the aforementioned principles of effectiveness, proportionality, and deterrence to which the Authority must adhere when determining the amount of the fine (Art. 83(1) of the Regulation): the economic circumstances of the offender, determined on the basis of the Company’s turnover as reported in the financial statements for the year 2024 (the most recent available). A. 00 euros (five million eight hundred thousand/00). In this context, it is also deemed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Authority’s Regulation No. 1/2019, this section containing the injunction order must be published on the Data Protection Authority’s website. This is in light of the specific nature of the data subject to the processing at issue—as it pertains to the data subject’s creditworthiness—as well as the nature of the violations found, which affected the general principles of processing, in particular the principle of transparency and the obligations regarding the exercise of the data subject rights.
Finally, it is considered that the conditions set forth in Art. 17 of the Data Protection Authority’s Regulation No. 1/2019 are met. , with its registered office in Imola, VAT No. A. 00 euros (five million eight hundred thousand/00), as an administrative fine for the violations set forth in this order, in accordance with the procedures outlined in the attachment, within thirty days of the service of this order, failing which the necessary enforcement measures will be taken pursuant to Art. 27 of Law No. 689/1981. It is noted that, pursuant to Article 166, paragraph 8 of the Code, the offender retains the right to settle the dispute by paying an amount equal to half of the imposed penalty within the time limit set forth in Article 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, set for filing an appeal as indicated below; ORDERS - pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No.
1/2019, the publication of the injunction order on the Data Protection Authority’s website; - pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Authority’s Regulation No. 1/2019, the publication of this order on the Authority’s website; - Pursuant to Article 17 of the Authority’s Regulation No. 1/2019, the recording of the violations and the measures adopted in accordance with Article 58(2) of the Regulation in the Authority’s internal register provided for in Article 57(1)(u) of the Regulation. Pursuant to Article 78 of Regulation (EU) 2016/679, as well as Article 152 of the Code and Article 10 of Legislative Decree No. 150 of September 1, 2011, an appeal against this decision may be filed with the ordinary courts by submitting a petition to the ordinary court of the location specified in the aforementioned Art 10, within thirty days from the date of notification of the decision, or within sixty days if the appellant resides abroad. Rome, July 3, 2026 THE PRESIDENT Stanzione THE RAPPORTEUR Stanzione THE SECRETARY GENERAL Montuori