10266250
Holding
The DPA identified a contradictory classification of the controller and the processor, and thus subsequent obligations. The contract presented by the processor declared the parties as independent controllers. Nonetheless, in 2018, the processor accepted to be a processor under Article 28 GDPR. According to the DPA, the contractual relationship was not properly understood by the processor, and correspondingly the GDPR obligations which follow. Firstly, the DPA held that in absence of demonstrating an appropriate legal basis, the promotional contact made by the processor violated Articles 5, 6 and 7 GDPR. Furthermore, the DPA held that the failure by the processor to adopt adequate measures to handle data subject requests concerning the exercise of their rights, and the inadequate response to the request submitted by the data subject, violated Articles 12, 13, 14, 15 and 22 GDPR. Lastly, the DPA found the processor to be in violation of its processor duties in light of its appointment in 2018 under Article 28 GDPR, as it did not diligently assess the arrangement with the controller, and lacked the prior written authorisation for engaging a sub-processor. The DPA imposed an administrative fine of €15,300 on the processor, and ordered it to adopt appropriate measures to ensure that any further engagement of sub-processors complies with the GDPR.
From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓
Facts — The data subject received unsolicited promotional phone calls and a email containing contractual information from Green Partner (the processor), despite the data subject's phone number being registered with the Public-Opt-Out Registry. The processor failed to respond to the data subjects request to exercise his rights. The data subject had also sought compensation from the processor. The processor dismissed the request with regard to its content and origin due to being subject to repeated fraudulent emails which aimed at soliciting undue payments. On 13 October 2025 the data subject submitted a complaint with the Italian DPA. In the course of the procedure by the DPA, the processor first denied responsibility for the promotional contact made to the data subject, the DPA found that the caller ID number was not registered in the Register of Communications and Postal Operators (‘ROC’). After further questions by the DPA, the processor claimed that the phone call was a mere clerical error made by an agent of the sub-processor (Vanille Service S.r.l.s.) it had engaged in the entry of the phone number. The processor claimed to process data on behalf of Sorgenia (the controller). The controller emphasised that the processor was never authorised to use telemarketing to conduct sales, violating their contractual agreement. The controller denied having any contractual relationship with the sub-processor as they never authorised the use of a sub-processor pursuant to Article 28 GDPR.
Full text 11 findings
Machine translation of the decision, via GDPRhub — not the official text. Read the original
[Web Doc. No. 10281706] Decision of June 18, 2026 Register of Decisions No. 472 of June 18, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter the “Regulation”); HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003 (Code on Data Protection, hereinafter the “Code”), as amended by Legislative Decree No. 101 of August 10, 2018, containing “Provisions for the alignment of national legislation with the provisions of Regulation (EU) 2016/679”; HAVING EXAMINED the documentation on file; HAVING CONSIDERED the observations made by the Secretary General pursuant to Article 15 of the Data Protection Authority’s Regulation No. 1/2000; RAPPORTEUR: Dr. Agostino Ghiglia; PREAMBLE
The complaints brought to the Authority’s attention. This Authority has received several complaints alleging that energy supply contracts were activated in the names of deceased individuals during periods following their deaths, as well as the occurrence, with respect to the aforementioned supply arrangements, of multiple switches to different energy companies operating in the free market. In addition, a complaint was received, submitted by Mr. XX, regarding the inadequate response provided by Acquirente Unico S.p.A., to the request to exercise rights submitted by the data subject on July 21, 2025, regarding the failure to update his personal data, which had been erroneously associated with a PDR not attributable to the complainant.
The Preliminary Investigation. The preliminary investigation was initially launched in response to the complaint filed by XX regarding the unlawful processing of the personal data of XX, who died on March 19, 2018. Specifically, the complaint alleged that Servizio Elettrico Nazionale S.p.A. had activated an electricity service in the name of the deceased, covering consumption for the years 2023 and 2024. In this regard, a request for information was therefore sent to the aforementioned company (see note dated July 11, 2024, ref. no. 85584/24), to which the company responded with a note dated September 30, 2024. In light of the statements made by Servizio Elettrico Nazionale S.p.A., a request for information was also sent to Acquirente Unico S.p.A. (hereinafter also “AU”), as the operator of the Integrated Information System (SII) (see letter dated November 5, 2024; ref. no. 129941/24; see the response from Acquirente Unico S.p.A. dated December 4, 2024), and, subsequently, to Acea Energia S.p.A. in its capacity as a dispatch user; Recital 1: Given that the latter had initially arranged to activate an energy supply on the open market at the POD assigned to XX (see note dated March 24, 2025; ref. no. 38941/25; see Acea Energia S.p.A.’s response dated April 22, 2025). On July 1, 2025, an inspection was also ordered against Acquirente Unico S.p.A. Subsequently, additional information was obtained through supplementary documentation submitted by the latter on July 1, 2025, thereby resolving the reservations raised during the inspection. Following the aforementioned on-site inspection and based on the findings thereof, it became necessary to initiate, ex officio, pursuant to Art. 21 of the Data Protection Authority’s Regulation No. 1/2019, to initiate a preliminary investigation aimed at assessing, as a whole, the methods and processing purposes carried out by Acquirente Unico S.p.A. in its capacity as operator of the SII and, more specifically, of the Official Central Registry (hereinafter also “RCU”). With this in mind, the proceedings concerning the complaint filed by XX were first consolidated with other complaints of a similar nature submitted by Mr. XX (see complaint of April 8, 2025), by Messrs. XX and XX (see complaint of June 25, 2025), and Ms. XX (see complaint of October 6, 2025), as well as with the complaint of August 26, 2025, filed by Mr. XX, as it concerned grievances similar to those in the aforementioned cases. This was done in order to conduct a comprehensive review of the underlying issues. Subsequently, a further request for information was sent to Acquirente Unico S.p.A. (see note dated October 31, 2025, ref. no. 144814/25), to which the Company responded on November 20, 2025. During the proceedings described above, with regard to the issues highlighted in the introduction, the following facts emerged. Acquirente Unico S.p.A. is a public company responsible for managing the Integrated Information System (SII) “based on a database of electricity and gas consumption points and the identifying information of end customers, established by Art. 1-bis of Law 129/2010” (see the Company’s note dated December 4, 2024, p. 2). The activities “carried out by the SII and the procedures for managing information flows through [the SII] are governed by law and by the resolutions of the Regulatory Authority for Energy, Networks, and the Environment (ARERA). These regulations require energy operators to register with the SII and to transmit (and update) the data necessary to enable the activities entrusted to it. The aforementioned operators (..) are responsible for the accuracy of the information exchanged” (see the Company’s note dated December 4, 2024, p. 2). Ownership of the data processed through the SII “belongs to: a) each legal entity that participates in the SII and implements it through information flows (User), limited to the information in its possession; b) to AU with regard to the information collected in the Official Central Registry (RCU), the case filing system, and other databases contained within the central infrastructure” (see Company note dated December 4, 2024, p. 2). Among “the responsibilities of SII Users is that of ensuring the fairness and truthfulness of the data within their purview that they provide, as provided for in Articles 6 and 17.8 of the SII Regulations” (see Company note dated December 4, 2024, p. 2). With regard to the entry of customer-related data into the SII, AU has stated that, in the event of a new supply activation or a switch (switching) of the same, the SII receives “communications pertaining to the supply (..) from the operators involved in each case, having the sole task of managing the information flows relating to the electricity and natural gas markets provided by the various market operators (..) and without any accountability for the accuracy of such information, accountability that rests solely and exclusively with the party providing the information” (see the Company’s note of December 4, 2024, p. 4). With regard to the requests submitted to the Authority, it emerged that, in the names of Messrs. XX, XX, XX, and XX, during periods following their respective deaths, various energy supply contracts were registered, each of which was subsequently subject to multiple switching operations involving different energy companies, with an average of approximately 2–3 supplier changes per year (see minutes of July 1, 2025, p. 3, and the communication from Acquirente Unico S.p.A. dated November 20, 2025, pp. 2–9). With regard to the report submitted by Mr. XX, it emerged that, prior to the application dated July 21, 2025, which is the subject of the dispute, he had already submitted (specifically, on June 23 and December 1, 2023) several requests to exercise his right to rectification regarding the same complaint concerning the erroneous association of his data with a PDR not attributable to him (see Attachment 2 of the AU note dated August 1, 2025). In all three instances, Acquirente Unico S.p.A. replied that it could not proceed with updating the inaccurate data, on the grounds that “only the Operator/Supplier is responsible for updating or performing an erasure of the data reported in the SII, and it is solely to the latter that [one must] turn” for this purpose (see Annex 2 of the AU note dated August 1, 2025; see also AU’s note in response to the complainant dated August 20, 2025). It was not until October 1, 2025, following an investigation by this Authority, that the Company took steps to correct the inaccurate information regarding Mr. XX, requesting the energy suppliers involved in this case, “each within the scope of their respective responsibilities, to regularize [the complainant’s] status and correct the [relevant] personal data” (see AU’s note in response to Mr. XX, dated October 1, 2025, p. 1). It was also found that, within the Official Central Registry, at the SII, as of August 1, 2025, there were approximately 11,711 customers over the age of 100 associated with 25,713 active energy supply contracts (see the Company’s note dated August 1, 2025, Annex 1— “Centennials”). With regard to the measures implemented by AU, in compliance with the accountability principle of the Regulation, to ensure the accuracy of customers’ personal data contained in the Official Central Registry, The representative of the Company stated that “it is not authorized by ARERA to conduct periodic checks aimed at identifying potentially inaccurate data (e.g., utility accounts associated with tax identification numbers of people over 100 years old; multiple activations in the name of the same individual and at the same supply address; etc.). This is because it is not AU’s responsibility to ensure the accuracy of the data in the aforementioned registry; this obligation falls, by regulation, exclusively on the operator, (..) while AU is [only] responsible for certifying the consistency of such data” (see minutes of July 1, 2025, pp. 3 and 5). Acquirente Unico S.p.A., in fact, has “no authority to modify the data contained in the RCU; such modifications may be made only by Users authorized to enter such information (in this case, the energy suppliers)” (see minutes of July 1, 2025, p. 4). Similarly, the Company cannot, in cases similar to those reported by the petitioners, notify energy suppliers of the existence of active PODs/PDRs in the name of a deceased individual, in order to invite them to verify the accuracy of their customers’ data and, if necessary, update such data within the RCU. This activity “is not among the tasks specifically assigned to AU; in fact, the SII does not provide for direct communication flows whereby AU modifies end-customer records with respect to energy suppliers” (see minutes of July 1, 2025, p. 4). For these reasons, Acquirente Unico S.p.A., in the cases in question, once it had taken note of the fact that the aforementioned energy supply contracts were in the names of deceased individuals, “did not conduct a check to verify the presence, within the SII, of any additional active supply contracts in the name of [the aforementioned data subjects]; this in light of the fact that, although it was aware of the deaths of the latter, it had not received any specific request from the entitled parties to cancel the relevant supply contracts, a revocation that would have allowed it to take the necessary actions (notifying the operator to correct the data)” (see minutes of July 1, 2025, p. 3). Finally, with regard, more generally, to the operating procedures adopted by Acquirente Unico S.p.A. when responding to requests for data correction submitted by data subjects (Articles 12 and 16 of the Regulation), the Company stated that it typically responds that “it cannot intervene directly on the RCU,” while simultaneously inviting “the data subject to first contact the relevant energy supplier” (see minutes of July 1, 2025, p. 4). On this point, it also reiterated that “since 2018, the Company has received fewer than 10 requests for correction regarding SII data pursuant to the GDPR, to which it responded in accordance with the terms indicated above” (see minutes of July 1, 2025, p. 4). More specifically, Acquirente Unico S.p.A. provided eight responses pursuant to Articles 12 and 15 of the Regulation, concerning seven data subjects (see the Company’s communication of August 1, 2025, Annex 2 – “Requests for Rectification and Responses”).
Notification of Violations and Defenses. By notice dated February 27, 2026, the Office, based on the documentation in the case file and the evidence gathered during the preliminary investigation, notified Acquirente Unico S.p.A. of the initiation of proceedings for the adoption of corrective and punitive measures regarding the alleged violations of Article 5, para 1, subparagraph d) and para 2, as well as Articles 12, 16, 24, and 28 of the Regulation; in accordance with the provisions of Article 166, paragraph 5, of the Code. In this regard, the Company, by notice dated March 28, 2026, submitted its defense briefs, which were further supplemented during the hearing on May 27, 2026. In this regard, with respect to the allegations, Acquirente Unico S.p.A. argued as follows: a) regarding the alleged violation of the principles of accuracy and accountability, the Company highlighted the limitations—in terms of powers and responsibilities—imposed on Acquirente Unico S.p.A. under sector-specific regulations. In fact, the Company “operates within the scope of activities [strictly] defined by the Regulatory Authority for Energy, Networks, and the Environment (hereinafter, “ARERA”),” a scope that, to date, in no way provides for either the implementation of measures aimed at verifying the accuracy of customer data contained in the RCU, nor operations to update or correct such data at the request of the individual data subjects concerned. This is due to the fact that “AU is assigned only the task of certifying the information communicated to it by the operators. This activity (..) stems from the nature of the SII itself, which does not manage either contracts or other documentation that would enable it to verify the fairness of the data.” It follows that if Acquirente Unico S.p.A. “were to independently correct the data” or were to “activate alert systems” and/or other measures of a similar nature, it “would violate [the aforementioned regulations and, more specifically,] the SII Regulation” (see the Company’s note dated March 28, 2026, pp. 3, 9–11, 13); b) with regard to the allegations concerning the violation of Articles 12, 16, and 28 of the Regulation, the Company pointed out that, although it was unable to update customers’ inaccurate personal data for the reasons stated above, “AU has always been cooperative with the data subjects, indicating the entity responsible for the correction to which [the data subjects] could easily refer.” The responses provided by Acquirente Unico S.p.A. in response to requests to exercise the right under Article 16 of the Regulation must be interpreted in this light: these responses were “clearly intended to indicate to the end customer the quickest way to obtain data rectification,” with a view to “guiding the data subject toward the fastest resolution path” (see the Company’s note dated March 28, 2026, pp. 14–15). In particular, with specific reference to the alleged violation of Article 28 of the Regulation, the Company clarified that, in the cases under investigation, the response provided by AU, although not in line with the instructions issued by the data controller, nevertheless effectively led to the updating of the aforementioned information by the designated individual, thereby enabling the data subjects to receive the social benefits to which they were entitled (see minutes of the hearing of May 27, 2026); c) with regard to the additional factors for assessment pursuant to Article 83, para 2 of the Regulation, the Company first stated that, in response to the notice of violation issued by the Data Protection Authority, it had initiated a review of its “response procedures [pursuant to Art. 12 of the Regulation], with the aim of informing all authorized personnel of the Data Protection Authority’s interpretation regarding the obligation to forward any requests for correction to the operators who enter the relevant data into the SII.” This process also addressed cases in which AU acts as a processor on behalf of ARERA. The Company further announced its intention to “have a third-party, independent entity conduct a general audit [regarding personal data protection] of the entire data management structure” processed by the Company in its capacity as data controller. Finally, it noted that it had launched “a specific training session for designated staff aimed at better clarifying the procedures for responding pursuant to Article 12 of the Regulation” (see the Company’s note of March 28, 2026, p. 19 and the minutes of the hearing of May 27, 2026); d) regarding the revenue reported in the 2024 financial statements, it emphasized that this figure does not reflect the Company’s actual economic capacity and that it cannot be equated with that of other private economic operators. Acquirente Unico S.p.A., in fact, does not operate as a for-profit commercial enterprise in a competitive market, but rather as an entity established by express provision of law to carry out tasks in the public interest as specifically set forth by sector-specific regulations (see the Company’s statement of March 28, 2026, pp. 18–19). Finally, the Company has declared itself “fully willing to initiate, with ARERA and, hopefully, with the support of the Data Protection Authority, a specific dialogue regarding the introduction into the SII Regulations, in accordance with the procedure set forth in paragraphs 6 and following of Art 2 of Annex A to Resolution 201, provisions governing the verification of utility accounts and the obligations to correct data in the RCU in light of requests submitted by end customers” (see the Company’s note of March 28, 2026, p. 14). With this in mind, it has already launched an internal review aimed at identifying some initial proposals to be submitted to the aforementioned Authorities, intended to include the “definition, in agreement with ARERA and the Data Protection Authority, of a cooperation procedure for managing requests, in compliance with the primary legislation governing the SII; the conduct of coordinated moral suasion efforts with ARERA to ensure that operators comply with their obligations regarding data entry and prompt responses to requests for corrections; the preparation of a report on requests for correction on a bimonthly or quarterly basis to be sent to ARERA and the Data Protection Authority for their respective areas of jurisdiction” (see minutes of the hearing of May 27, 2026).
Dialogue with ARERA. Following receipt of the defense briefs submitted by Acquirente Unico S.p.A. and in light of their content as described above, the Authority initiated an initial dialogue with ARERA, aimed at obtaining, from the latter, useful information for analyzing the regulatory framework underlying the role and tasks entrusted to Acquirente Unico S.p.A. as operator of the SII (and, within it, the RCU). A request was also made to the aforementioned Authority to identify what measures it could take to ensure full compliance with data protection regulations in the context in question (see the Data Protection Authority’s note dated March 30, 2026). In this regard, ARERA, in a letter dated May 14, 2026, provided some preliminary guidance regarding the relevant regulations pertaining to the case in question and agreed on the advisability of initiating a dialogue with the Data Protection Authority in order to resolve some of the critical issues that have emerged in the context of the proceedings under review. With regard to sector-specific regulations, and specifically concerning the role played by Acquirente Unico S.p.A. in relation to the information contained in the SII and, in particular, in the Official Central Register, ARERA clarified the latter’s role as a “certifier”—that is, an entity responsible for verifying the information in the SII “of a purely technical nature (for example, the type and number of characters entered in fields such as tax ID and POD/PDR) and not pertaining to the accuracy” of such information (see ARERA note of May 14, 2026, p. 3). This is because, under the current regulatory framework, the SII operator has not been granted “the power to unilaterally modify the data; at most, an obligation [on the part of the SII operator] to take action to report discrepancies in the information entered into the SII to the Authority and/or to the operators who entered that data” into the system (see ARERA note of May 14, 2026, p. 5). ARERA therefore concurred with the interpretation of the primary and secondary legislation pertaining to the energy sector provided by Acquirente Unico S.p.A. in its defense briefs; this applies both to “the assertion (…) regarding the scope of the SII operator’s role as a mere manager of information flows pertaining to the electricity and gas markets provided by market operators, without any accountability for the accuracy of such information,” and with regard to the assertion that the obligation to enter accurate data into the system “would fall solely and exclusively on the entity providing the information (i.e., the energy suppliers and distributors involved in each case)” (see ARERA note of May 14, 2026, p. 5). Notwithstanding the foregoing, ARERA also emphasized, in light of the various critical issues highlighted by the Data Protection Authority regarding the accuracy of customers’ personal data contained in the RCU, the advisability of evaluating—including through the discussions already underway with the Data Protection Authority—a regulatory intervention aimed both “at introducing measures to hold commercial operators more accountable” and at “proposing an amendment to the SII Regulation” designed to bring the regulatory framework into compliance with data protection laws. Furthermore, with specific reference to the issues that have arisen regarding AU’s response to requests by end customers to exercise their rights, it was stated that the data subjects’ need for rectification “could be met by providing that AU, whenever it receives a request from an end customer to correct the data contained in the RCU, process such request in its capacity as the Energy and Environment Consumer Help Desk (...), and forward the request to update the RCU directly to the relevant commercial operator in light of the correction request received” (see ARERA note of May 14, 2026, p. 6).
The outcome of the preliminary investigation and the Department’s assessments regarding the unlawfulness of the processing of customers’ personal data contained in the Official Central Registry. First and foremost, it should be noted that, unless the act constitutes a more serious offense, anyone who, in proceedings before the Data Protection Authority, falsely declares or attests to facts or circumstances, or produces false documents or records, is liable pursuant to Art. 168 of the Code, “False Statements to the Data Protection Authority and Interruption of the Performance of the Authority’s Duties or the Exercise of Its Powers.” That said, in light of the evidence gathered during the preliminary investigation described above and the subsequent assessments conducted by this Department, the violations detailed below have been identified with respect to Acquirente Unico S.p.A.; These relate to the processing of customers’ personal data carried out by Acquirente Unico S.p.A., in its capacity as data controller, in the performance of its duties as administrator of the Official Central Registry, as well as to certain conduct engaged in by it as processor pursuant to Art. 28 of the Regulation.
The Official Central Registry and Acquirente Unico’s status as data controller with respect to the personal data of end customers contained therein. It should be noted at the outset that, for the purposes of this decision, it is necessary to take into account the specific context underlying the processing activities carried out in the present case, as they are performed within the SII and, more specifically, within the Official Central Registry established therein. In this regard, it is worth recalling that the aforementioned Registry constitutes the national database of identifying information for so-called end customers—that is, the owners of an electricity withdrawal point (POD) and a natural gas redelivery point (PDR)—as well as data pertaining to the management of SII processes (see Art. 1-bis, paragraph 1 of Law No. 129/2010). The RCU thus forms the basis for information flows among the various energy market operators (primarily distributors and suppliers) and for the various processes necessary for the operation, throughout the country, of the entire sector in question (from the activation of a supply to the transfer of that supply to another customer; from switching to a new provider in the open market to the assignment of customers to the Services of Last Resort; from the activation of the Vulnerability Service to the automatic disbursement of social bonuses; etc.). The management of the aforementioned Registry is entrusted by law to Acquirente Unico S.p.A., which is also designated as the controller for the personal data contained therein (see the SII Regulation, adopted pursuant to Art. 2.6 of Annex A to ARERA Resolution No. ARG/com 201/10). More specifically, the SII Operating Regulations (hereinafter “SII Regulations”) stipulate that responsibility for processing the information in the RCU lies with: each User (e.g., energy supplier and/or distributor), limited to the information in its possession; Acquirente Unico S.p.A., in its capacity as SII Operator, with respect to the information collected therein. It should be noted that this responsibility “passes from the User to the Operator, or vice versa depending on the direction of the exchange flow, upon submission of the data at the Data Delivery Point” (Articles 5.5 and 17.2 of the SII Regulation). It is also expressly provided that “the User is responsible for the accuracy and truthfulness of the data communicated to the Operator” and that “the Operator is responsible for the consistency and updating of the RCU (…), with respect to the information received from Users, [as well as] for the correct sequence of Media Updates in relation to the managed processes” (Art. 17.8 of the SII Regulation). Acquirente Unico S.p.A., in its capacity as Operator, is also assigned specific tasks and primary accountability regarding the information it processes. It is, in fact, responsible for ensuring: - “the processing of information relating to end customers collected in the RCU, (..) in accordance with Regulation (EU) No. 2016/679” (see Art. 5.5 of the SII Regulations); - “the security, confidentiality, and integrity of the information both in communications with Users and in the SII databases,” including the RCU (see Art. 5.3 of the SII Regulation); - “the enforceability against third parties of the data entered in the Official Central Registry, the verification and control of the data provided by Users in communications to the SII, (..) the storage and archiving of the information and communications” contained therein (see Art. 5.3 of the SII Regulation). Finally, the aforementioned SII Regulations stipulate that “in the event that the Operator detects an error in the personal data received or in the content of the RCU, [it is required to promptly notify] the data subjects of the information necessary for the required corrections” (Art. 17.10 of the SII Regulations). In light of the aforementioned duties and accountability, the role of Acquirente Unico S.p.A. is clearly evident as the data controller of the end customers’ personal information contained in the Official Central Registry; a controller responsible for ensuring compliance with data protection regulations. It is also worth noting, in this regard, that the Company operates within a stringent regulatory framework, with activities, scope, and operating procedures strictly governed by law and public regulation. In particular, the tasks assigned by ARERA to Acquirente Unico S.p.A.—as a mere “certifier” of SII data, in accordance with sector regulations—do not appear to allow it to fully comply with the obligations imposed by EU Regulation No. 2016/679 to the controller. Specifically, reference is made to the absence—repeatedly emphasized by the Company during the proceedings—of a clear allocation of powers and responsibilities aimed at ensuring, including from an accountability perspective, the accuracy of the personal data processed within the RCU (see para 3(a) of this decision). All this is considered in light of the fact that the sector-specific regulations have limited themselves to conferring upon that entity, with respect to the RCU, “the sole task of managing the information flows pertaining to the electricity and gas markets provided by market operators, (…) with no accountability [having been assigned to the Operator] for the accuracy of such information; accountability that rests solely and exclusively with the entity providing the information [namely, the energy suppliers and distributors involved in each case]” (see paragraphs 2 and 3 of this decision). This is true even though, at the same time, the aforementioned legislation, with regard to matters pertaining to data protection, has granted Acquirente Unico S.p.A. the status of data controller for customer data processed within the RCU (see Art. 17 of the SII Regulation), a role that is not compatible with the functions of a mere “certifier” of the information entered by Users into the SII. It should also be noted that, through the RCU, Acquirente Unico S.p.A., in accordance with sector-specific regulations, carries out a distinct and far more extensive processing of personal data than that performed by individual energy suppliers participating in the SII. In fact, the end customer’s personal data—once entered by the User into the SII—is linked to other personal information pertaining to that same data subject present in the RCU, as well as, at a later stage, to information that will be provided by other Users over time, creating a set of information capable of representing the end customer’s “energy history.” On this point, it is worth noting that the Official Central Registry contains a wide range of personal information about the end customer, such as: the number of other active or terminated supply contracts associated with the same tax identification number; the number of switches made in the past, relating to the POD/PDR being entered; the data subject’s eligibility for the social bonus; the consumption recorded for the aforementioned customer; etc. It follows that the RCU Operator possesses a complex and comprehensive set of personal data, over which it assumes full and independent control, with all the resulting obligations in terms of compliance with EU Regulation No. 2016/679; first and foremost, with regard to the procedure under consideration, those concerning compliance with the principles of accuracy and accountability, as well as the provisions regarding the exercise of data subject rights. In the context of the processing carried out through the SII (and more specifically, within the RCU), there therefore appears to be a need for regulatory action which, taking into account the much broader scope the RCU has assumed over time, as a result of the various regulatory provisions that have accumulated over the years, provides Acquirente Unico S.p.A. with the necessary tools to fully carry out its role as the controller for the customer data contained therein.
Violation of the Principle of Accuracy. Based on the overall checks conducted during the present investigation, it emerged that the aforementioned Registry contained inaccurate and outdated personal data of end customers, with particular reference to information regarding electricity and gas supply contracts concluded after the customers’ deaths. Specifically, with regard to the complaints filed with the Data Protection Authority, it was first established that the personal data of Messrs. XX, XX, XX, and XX, regarding the flow of information at the SII concerning the activation—in their names and during periods following their deaths—of various energy supply contracts; Each of these supply contracts was subsequently subject to multiple switching operations involving different energy companies, with an average of approximately 2–3 supplier changes per year. More specifically, these involved: 10 energy supply contracts in the name of Mr. XX; three of which were still active as of the date of the inspection on July 1, 2025 (see report of July 1, 2025, p. 3); 6 contracts in the name of Ms. XX (erroneously listed in the RCU as XX and as XX; see the notice from Acquirente Unico S.p.A. dated November 20, 2025, pp. 2–5); 4 supply agreements, in the name of Ms. XX, one of which was still active as of November 20, 2025 (see the notice from Acquirente Unico S.p.A. dated November 20, 2025, pp. 6–9); 1 supply relationship, registered in the name of Mr. XX (erroneously listed in the RCU as XX; see the communication from Acquirente Unico S.p.A. dated November 20, 2025, p. 6). It was also found that, as of August 1, 2025, the Official Central Registry at the SII contained approximately 11,711 customers over the age of 100, to whom 25,713 active energy supply contracts were associated (see the Company’s note dated August 1, 2025, Annex 1— “Centenarians”); among these, for example, there are 184 people aged 110 and as many as 74 aged 114 It should also be noted that, as of now, in most cases, these customers are associated with multiple active supply contracts (in some instances, up to 17 different contracts). Finally, with regard to Mr. XX’s complaint, it emerged that the erroneous association of his data with a PDR not pertaining to him persisted for approximately two years, namely from the complainant’s submission on June 23, 2023, of the first request for rectification pursuant to Article 16 of the Regulation, until October 1, 2025, the date on which Acquirente Unico S.p.A., following the Data Protection Authority’s intervention, requested the cooperation of the energy suppliers involved in this case to update his status (see AU’s response to Mr. XX dated October 1, 2025). Each of the aforementioned transactions involved the processing by Acquirente Unico S.p.A. of inaccurate and outdated personal data of end customers within the RCU; which constitutes a violation of Article 5(1)(d) of the Regulation (the so-called principle of accuracy). On this point, it should be noted that the principle of accuracy requires the data controller to carry out periodic verification of the processed data by implementing, on the one hand, technical and organizational processes capable of ensuring the accuracy and timeliness of such data, and, on the other hand, by adopting operational practices suitable for enabling timely and precise corrective action regarding inaccurate information. It is also worth noting that Article 5 of the Regulation must be read in conjunction with the principle of accountability (Art 5(2) and Art 24 of the Regulation). Pursuant to the aforementioned provisions, in fact, the controller is the entity to which “overall accountability” for the processing is attributed; consequently, the controller bears the burden of implementing an organizational and management system characterized by concrete, effective, and verifiable data protection measures (see also Recital 74 of the Regulation); this is achieved not only through the proper and timely fulfillment of the obligations imposed by the Regulation (privacy notice; record of processing activities; appointment of a data protection officer where required; etc.), but also through the implementation of organizational procedures and practices designed to bring the relevant processing operations into compliance with the applicable regulations (e.g., processes for the proper management of data subject to processing; data retention policies; procedures for handling requests to exercise rights and complaints; etc.; see Article 29 Working Party, WP 173 of July 13, 2010—Opinion 3/2010 on the principle of accountability, pp. 11–12). The implementation of the principle of accountability with regard to the principle of accuracy imposes on the data controller, first and foremost, the obligation to adopt appropriate technical and organizational measures to ensure the lawfulness, fairness, and up-to-date nature of the data processed in the RCU. This is true even when considering the specific context at hand, in which the controller operates within the limits permitted by current regulatory provisions (see recitals 4 and 5.1 of this decision). This is to be achieved, first and foremost, through preventive procedures designed to ensure the consistency and accuracy of the information entered into the system. In this regard, the data controller should conduct periodic ex post checks as measures designed to identify indicators of anomalies, with a view to prompting further, targeted investigations by the data controller. This refers, for example, to the implementation of checks on the consistency of data in the system, including the triggering of alerts for various anomalies (such as: the upload to the SII of an anomalous number of PODs/PDRs registered to the same individual; an excessive number of switching events occurring in close succession with respect to the same supply/delivery point; the recurrence of the same contact information—such as email addresses or phone numbers—across multiple PODs/PDRs; etc.). The adoption of such systems should also be accompanied by the implementation of procedures that allow Acquirente Unico S.p.A. to actively engage with SII Users (in particular, energy suppliers); this—as also recognized by ARERA itself (see note of May 14, 2026)—in order to facilitate the updating of personal data contained in the RCU in accordance with the requirements of Article 5, para 1, subparagraph d) of the Regulation. The absence of the above-mentioned measures or, in any case, of other technical and organizational measures equally suitable for ensuring the consistency and accuracy of the personal data processed in the RCU—a circumstance ascertained, as highlighted above, during the inspection— has therefore resulted, on the part of Acquirente Unico S.p.A., not only in the aforementioned violation of Article 5, para 1, subparagraph d) of the Regulation, but also in a violation of Article 5, para 2, and Article 24 of the Regulation. With regard to the aforementioned allegations, it is necessary to take into account the findings that emerged following discussions with ARERA concerning the current regulatory framework (see paragraphs 4 and 5.1 of this decision). In this regard, based on an examination of all the documentation obtained, it is considered appropriate to accept the arguments put forward by the Company aimed at excluding its accountability for the failure to adopt the measures outlined above; this is because Acquirente Unico S.p.A. acted in good faith and strictly adhered to the instructions and procedures specifically set forth in the sector’s regulations (see, among many others, Civil Cassation, Section II, No. 20219 of July 31, 2018; see also Civil Cassation, Section II, Judgement No. 6051 of March 6, 2025). In this regard, and with particular reference to whether the error committed by the Company was excusable, it is significant that ARERA confirmed, in the aforementioned note dated May 14, 2026, the interpretation, followed by AU, of the aforementioned regulator’s resolutions concerning the duties and powers assigned to Acquirente Unico S.p.A. as operator of the SII and the RCU; resolutions which, therefore, constitute a positive factor—unrelated to the perpetrator of the violation—capable of leading the Company to believe that its conduct was lawful. Having duly set forth the foregoing, with regard to the violations of the principles of accuracy and accountability as alleged in the Authority’s notification of February 27, 2026, it is noted, therefore, that, with respect to the specific conduct referred to in these proceedings, the conditions for adopting the measures provided for in Article 58 of the Regulation do not exist. Accordingly, limited to this specific aspect, the request made by Acquirente Unico S.p.A. to dismiss the allegation regarding these specific instances of violation is granted (see para 3, subparagraph a) of this decision). At the same time, given the broader scope that the Official Central Registry has assumed to date, it is deemed necessary to reiterate the aforementioned need, in the near future, for regulatory action aimed at bringing the current sector-specific regulatory framework into compliance with data protection legislation. In this regard, the Authority therefore takes note of the initiation of a collaborative effort between the Authority and ARERA aimed at addressing the systemic issues highlighted above.
Violations concerning the exercise of data subject rights. Personal data protection legislation requires the data controller, in accordance with the principle of accountability, to establish an organized system for managing requests submitted pursuant to Articles 15–22 of the Regulation, by identifying specific and adequate instructions to be provided to designated staff (such as, for example, the obligation to monitor the dedicated email account; instructions clarifying the deadlines to be met; guidelines for identifying cases where deadlines may be extended; etc.) and providing them with response templates (e.g., request for rectification; extension of deadlines with justification; etc.) and operational procedures for handling various scenarios (e.g., instructions on the actions to be taken in the event of a follow-up request; etc.). All of this is intended to ensure that adequate and effective measures are adopted to fulfill the data controller’s broader duty to facilitate the exercise of the rights set forth in Articles 15–22 of the Regulation (see Article 12, para 2, and Recital 59 of the Regulation); this also applies, with specific reference to the cases in question, to the obligation to ensure the rectification of inaccurate or outdated data concerning the data subject (Art. 5(1)(d) of the Regulation). With regard to the manner in which Acquirente Unico S.p.A. responded to requests to exercise the right to rectification, submitted by data subjects pursuant to Article 16 of the Regulation, it emerged that, in all cases examined by the Authority, responded to the requests received by stating that it could not update the inaccurate information of end customers and by inviting the latter to resubmit their requests to other, different controllers (see the Company’s communication of August 1, 2025, Annex 2 – “Requests for Rectification and Responses”). This was the case both when Acquirente Unico S.p.A. acted as the controller (see the requests submitted by Messrs. XX, XX, XX, XX, and XX), and in cases where it has served in the distinct role of processor pursuant to Art. 28 of the Regulation (see the requests from Messrs. XX and XX). In particular, it should be noted that in all the cases referred to above in which Acquirente Unico S.p.A. acted as the data controller, the latter should instead have taken active steps to ensure that inaccurate customer information was updated, including, where necessary, liaising with the relevant energy suppliers as data subjects on a case-by-case basis to conduct the necessary verifications. In response to a request to exercise the right to rectification of personal data contained in the RCU, the data controller, in fact, cannot—as was evident in the cases under review—simply instruct the data subject to contact the energy supplier, but is obligated to take action (including, if necessary, through the aforementioned supplier) to promptly carry out the necessary verifications and, where appropriate, update the inaccurate data, also in order to comply with the provisions of Art. 19 of the Regulation. All of this must be done ex officio if the conditions are met; in this regard, with reference to the case of Mr. XX, Acquirente Unico S.p.A., after becoming aware (through the request for information sent by this Office) of Mr. XX’s death in connection with a POD associated with him, it should have independently verified whether there were any other transactions containing inaccurate data regarding the aforementioned data subject and taken steps to update the RCU accordingly and notify the relevant supplier. This action, in addition to ensuring that AU’s processing complies with the principle of accountability, is necessary to guarantee—in accordance with Art 5, para 1, subparagraph d) of the Regulation—the consistency and accuracy of the information contained in the Official Central Register. The conduct adopted by the data controller in all the cases listed above (refusal to correct the data and referral to the relevant supplier) constituted a violation of Articles 12 and 16 of the Regulation and, in fact, resulted in the continued unlawful processing of inaccurate data pertaining to the aforementioned complainants within the aforementioned RCU. On this point, it is not possible to accept the argument put forward by Acquirente Unico S.p.A. regarding its technical inability to independently modify the customer records in the SII (see para 3, subparagraph b) of this decision). It should be noted, in fact, that in any case, the aforementioned data controller, in accordance with the regulatory obligation to facilitate the exercise of data subjects’ rights (Article 12 of the Regulation), should at the very least have complied with requests to update inaccurate data pertaining to data subjects by reporting the inconsistency to the relevant suppliers on a case-by-case basis and simultaneously requesting that they verify and make the necessary changes to the system. Moreover, this is an activity that Acquirente Unico S.p.A. has already demonstrated it is capable of performing, as, following the launch of the Data Protection Authority’s investigation into Mr. XX’s complaint, it intervened by requesting the relevant suppliers to ensure the timely update of the aforementioned customer’s data in the RCU. Furthermore, ARERA itself has represented that, although under current regulations “Acquirente Unico S.p.A. is not granted the authority to unilaterally modify the data [in the SII], there remains (..) the obligation [on Acquirente Unico S.p.A.] (…) to take action to report discrepancies in the data entered into the SII to the Authority and/or to the operators who entered that data” (see ARERA note dated May 14, 2026, pp. 4–5). With specific reference, however, to the processing of data pertaining to Mr. XX and Ms. XX, in which AU acted as a data processor pursuant to Article 28 of the Regulation, it is noted that AU should have acted in accordance with the specific instructions provided by the data controller through the designation agreement signed for that purpose (see Annex 2—“ARERA Agreement,” attached to AU’s note of November 20, 2025). In fact, within the aforementioned “ARERA Agreement,” the data controller correctly provided the instructions required by Art. 28, para. 3 of the Regulation, imposing, among other things, the obligation on AU to “promptly notify the data controller, within 3 business days, regarding any requests from data subjects that may be received by the data processor, by sending a copy of the requests received to the email address indicated in the ‘communications’ article, and to cooperate in order to ensure that data subjects can fully exercise all rights provided for by applicable law” (see Art. 5, paragraph 14 of the ARERA Agreement, cited above). Contrary to what was therefore expressly requested by the data controller, Acquirente Unico S.p.A. failed to comply with these operational guidelines, omitting to involve the controller and limiting itself, in the response provided to data subjects, to pointing out that the controller was unable to correct the inaccurate personal information; thereby inviting them to submit a specific request for rectification to INPS or to the data subject’s water utility. For these reasons, therefore, it is considered that AU’s conduct in this case constituted a violation of Article 28(3)(a) and (e) of the Regulation.
Conclusions: Declaration that the processing is unlawful. Corrective measures pursuant to Art. 58(2) of the Regulation. In light of the overall findings, the Authority considers that the statements, documentation, and explanations provided by the controller during the investigation do not sufficiently address the objections notified by the Office in thenotice of initiation of proceedings and are therefore insufficient to warrant the dismissal of this proceeding, especially since none of the cases provided for in Art. 11 of the Data Protection Authority’s Regulation No. 1/2019 apply. The processing of customers’ personal data carried out by Acquirente Unico S.p.A., in the context of activities related to the management of the Official Central Registry, is in fact unlawful, under the terms set forth above, as it was carried out in violation of Articles 12, 16, and 28 of the Regulation. The violation affected seven data subjects and lasted for approximately four years; more specifically, from May 25, 2021 (the date of the access request submitted by Mr. XX) to November 20, 2025 (the date of the last response provided by the Company to the Data Protection Authority). The violation of the provisions referred to above entails the imposition of the administrative sanction provided for in Art. 83, para. 4, subpara. (a), and para. 5, subpara. (b), of the Regulation. With regard to the exercise of the corrective powers referred to in Art. 58, para 2, of the Regulation, it should be noted that—although, due to the need to revise the sector’s regulatory framework as previously highlighted, it was decided to dismiss the allegations raised against Acquirente Unico S.p.A. regarding the principles of accuracy and accountability—the RCU continues to process inaccurate and outdated information concerning the personal data of Messrs. XX, XX, XX, XX, and XX. With regard to the personal data of the aforementioned data subjects, it is therefore necessary to order the correction of such data pending the completion of ARERA’s review of the aforementioned legal framework. It is therefore deemed necessary to order the controller, pursuant to Article 58(2)(d) of the Regulation, to take the following corrective measures: a) with regard to the requests at issue in this proceeding, to correct the inaccurate personal data of Messrs. XX, XX, XX, XX, and XX through consultation with the respective service providers involved. For this purpose, it will be necessary to maintain adequate documentation (e.g., through a system entry) of the fact that the service was erroneously activated in the name of a deceased individual (with respect to Messrs. XX, XX, XX, and XX) or due to a case of homonymy (with respect to Mr. XX); b) with reference to the policy adopted by the Company for the purposes of complying with Articles 15–22 of the Regulation, adopt a specific Section regarding the rectification of inaccurate data processed within the RCU that, while taking into account the various scenarios that could be the subject of a request under Art. 16 of the Regulation (e.g., unsolicited service; service in the name of a deceased individual; failure to update the customer’s personal information or contact details; incorrect POD/PDR address; etc.), establishes specific procedures to enable the updating of the aforementioned personal data—where appropriate, through the involvement of the data subjects—and provides detailed instructions to the designated operators, as well as the measures necessary to implement the provisions of Article 19 of the Regulation. Finally, with regard to the data of the 11,711 customers over the age of 100 who are active service holders within the RCU, it is acknowledged that the aforementioned discussions with ARERA have begun, aimed at evaluating the steps to be taken to ensure full compliance with data protection regulations in the context at hand.
Adoption of the injunction ordering the imposition of an administrative fine and ancillary penalties (Articles 58(2)(i) and 83 of the Regulation; Article 166(7) of the Code). The Data Protection Authority, pursuant to Art 58, para 2, subparagraph i) of the Regulation and Article 166 of the Code, has the power to impose an administrative fine provided for in Article 83 of the Regulation, through the adoption of an injunction order (Article 18. Law No. 689 of November 24, 1981), in connection with the processing of personal data carried out by Acquirente Unico S.p.A., which has been found to be unlawful, as set forth above. Having determined that paragraph 3 of Article 83 of the Regulation must be applied, which provides that “if, in relation to the same processing or related processing operations, a controller […] intentionally or negligently violates several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the most serious infringement,” the total amount of the fine is calculated so as not to exceed the maximum amount provided for in Art. 83(5) of the Regulation. With regard to the factors listed in Article 83(2) of the Regulation for the purposes of imposing the administrative fine and determining its amount, and taking into account that the fine must be “in each individual case effective, proportionate, and dissuasive” (Article 83(1) of the Regulation), it is noted that, in the case at hand, the following circumstances were taken into account. With specific regard to the nature, gravity, and duration of the violations, whether they were intentional or negligent, as well as the categories of personal data involved (Articles 83(2)(a), (b), and (g) of the Regulation), the following were noted: the significant severity of the violations (Articles 83(2)(a) and (g) of the Regulation), in relation to their nature (concerning non-compliance with the principles governing the exercise of rights), the manner (the multiple instances of unlawful conduct repeated over time), and the duration of the violations (approximately four years). The nature, context, and processing purpose, as well as the type of harm suffered by the data subjects involved, were considered relevant for this purpose. All of this, given that: the operations in question were carried out by Acquirente Unico S.p.A. as part of the management of the Official Central Registry—that is, the national database containing identifying information on energy market customers; the data protection issues identified relate to the processes and policies implemented by the controller at the time of processing, highlighting a systemic inadequacy in the procedures for responding to requests by data subjects to exercise their data subject rights. On the other hand, factors in favor of the violator include the fact that the processing was carried out for the performance of tasks in the public interest, the non-sensitive nature of the personal data processed in the cases in question, and the small number of data subjects involved; the negligent nature of the violation (Art. 83, para 2, subparagraph b) of the Regulation), given that the conduct was carried out under the Company’s mistaken belief that, in light of sector-specific regulations governing energy law, it did not have the authority to correct inaccurate personal data within the RCU. In light of these circumstances, it is considered that, in the present case, the level of severity of the violations committed by the controller is moderate (Guidelines 4/2022 on the calculation of administrative fines under the GDPR, adopted by the Committee on May 23, 2023, paragraph 60). With regard to the additional factors identified in Article 83(2) of the Regulation, the following indicators were also taken into account: the significant instance of accountability of the controller with regard to the technical and organizational measures implemented (Articles 83(2)(d) of the Regulation); specifically, with regard to the inadequacy of the procedures implemented by Acquirente Unico S.p.A. to address, in accordance with the Regulation, requests for rectification submitted by data subjects. Factors considered in favor of the violator include the unique structure of the technical processes specific to the SII and the operational practices in use within the SII by its Users; the fact that there are no previous violations committed by the controller or previous measures pursuant to Article 58 of the Regulation concerning the same subject matter (Article 83(2)(e) and (i) of the Regulation). On this point, it should be noted that Measure No. 764 of December 18, 2025 (web doc. No. 10210454) was not taken into account for this purpose, given that the investigations pertaining to this decision were conducted concurrently with those that led to the adoption of the aforementioned measure against Acquirente Unico S.p.A.; the adoption by the data controller of certain measures designed to mitigate or eliminate the consequences of the violation (Art. 83(2)(c) of the Regulation). In this regard, the initiatives undertaken by Acquirente Unico S.p.A. to facilitate the exercise of Mr. XX’s right to rectification of his data should be viewed favorably; however, since these measures were directed exclusively at a single data subject, they were only partially effective in reducing the harmful consequences of the violation; the fact that the Company actively cooperated with the Authority during the proceedings (Art 83(2)(f) of the Regulation); other mitigating factors (Article 83(2)(k) of the Regulation): consideration was also given, in favor of the offender, to the initiatives recently undertaken by the Company to strengthen its level of compliance with the Regulation, as described in para 3, subparagraph (c) of this decision, as well as the in-depth analysis conducted internally by AU with a view to identifying some initial proposals to be submitted to the Data Protection Authority and ARERA, as set forth in para 3 of this decision. It is further considered that, in the present case, given the aforementioned principles of effectiveness, proportionality, and deterrence to which the Authority must adhere in determining the amount of the penalty (Articles 83, para 1, of the Regulation), the legal nature of Acquirente Unico S.p.A. as a wholly publicly owned in-house company (see para 3(d) of this decision). In light of the above factors and the assessments made, it is deemed appropriate, in the present case, to impose on Acquirente Unico S.p.A. an administrative penalty consisting of the payment of a sum equal to 90,000.00 euros (ninety thousand/00). In this context, it is also considered that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, this chapter containing the injunction order must be published on the Data Protection Authority’s website. This is in light of the nature of the violations found, which concerned the procedures used by the Company to respond to requests to exercise the data subject rights. In this regard, account is taken of the impact that these practices have had on the rights of end customers, given that they effectively prevented the latter from obtaining, from Acquirente Unico S.p.A., the rectification of their personal data. Also relevant in this regard is the broad scope of the unlawful conduct, as it pertains to processing operations carried out for the management of a public database of national significance, which forms the basis for information flows among the various energy market operators and the various processes necessary for the functioning, throughout the territory, of the entire relevant sector. Finally, it is considered that the conditions set forth in Art. 17 of the Data Protection Authority’s Regulation No. 1/2019 are met. GIVEN THE FOREGOING, THE DATA PROTECTION AUTHORITY a) pursuant to Articles 57(1)(a) and (f) and 83 of the Regulation, finds that the processing carried out by Acquirente Unico S.p.A., with headquarters in Rome, VAT No. 05877611003, as set forth in the reasoning, for violating Articles 12, 16, and 28 of the Regulation; b) pursuant to Article 58(2)(d) of the Regulation, orders the aforementioned company to comply, within 9 months from the date of notification of this decision, with the requirements set forth in para 6 of this decision, while at the same time requiring the company to provide, within the aforementioned deadline, an adequately documented response pursuant to Art 157 of the Code; failure to provide such a response may result in the imposition of the administrative fine provided for in Article 83, para 5, subparagraph e) of the Regulation; ORDERS pursuant to Article 58, para 2, subparagraph (i) of the Regulation, Acquirente Unico S.p.A. is ordered to pay the sum of 90,000.00 euros (ninety thousand/00) as an administrative fine for the violations indicated in this order. THEREFORE ORDERS Acquirente Unico S.p.A. to pay the aforementioned sum of 90,000.00 euros (ninety thousand/00), in accordance with the procedures set forth in the attachment, within thirty days of the service of this order, failing which the necessary enforcement measures will be taken pursuant to Art. 27 of Law No. 689/1981. It is noted that, pursuant to Article 166, paragraph 8, of the Code, the offender retains the right to settle the dispute by paying —always in accordance with the procedures set forth in the attachment—of an amount equal to half of the imposed penalty within the time limit specified in Art. 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, provided for the filing of an appeal as indicated below. ORDERS - pursuant to Article 17 of the Data Protection Authority’s Regulation No. 1/2019, that the violations and the measures adopted in accordance with Article 58, para 2, of the Regulation be recorded in the Authority’s internal register provided for in Article 57, para 1, letter u), of the Regulation; - pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Data Protection Authority’s Regulation No. 1/2019, the publication of this order on the Authority’s website; - Pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, the publication of the injunction order on the Data Protection Authority’s website. Pursuant to Article 78 of the Regulation, as well as Article 152 of the Code and Article 10 of Legislative Decree No. 150/2011, an appeal against this order may be filed with the ordinary courts by submitting a petition to the ordinary court of the jurisdiction specified in Art 10, within thirty days from the date of notification of the order, or within sixty days if the appellant resides abroad. Rome, June 18, 2026 THE CHAIRMAN Stanzione THE RAPPORTEUR Ghiglia THE SECRETARY GENERAL Montuori [Web Doc. No. 10281706] Decision of June 18, 2026 Register of Decisions No. 472 of June 18, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter the “Regulation”); HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003 (Code on Data Protection, hereinafter the “Code”), as amended by Legislative Decree No. 101 of August 10, 2018, containing “Provisions for the alignment of national legislation with the provisions of Regulation (EU) 2016/679”; HAVING EXAMINED the documentation on file; HAVING CONSIDERED the observations made by the Secretary General pursuant to Art. 15 of the Data Protection Authority’s Regulation No. 1/2000; RAPPORTEUR: Dr. Agostino Ghiglia; PREAMBLE 1 The complaints brought to the Authority’s attention. This Authority has received several complaints alleging that energy supply contracts were activated in the names of deceased individuals during periods following their deaths, as well as the occurrence, with respect to the aforementioned supply arrangements, of multiple switches to different energy companies operating in the free market. In addition, a complaint was received, submitted by Mr. XX, regarding the inadequate response provided by Acquirente Unico S.p.A., to the request to exercise rights submitted by the data subject on July 21, 2025, regarding the failure to update his personal data, which had been erroneously associated with a PDR not attributable to the complainant. 2 The Preliminary Investigation. The preliminary investigation was initially launched in response to the complaint filed by XX regarding the unlawful processing of the personal data of XX, who died on March 19, 2018. Specifically, the complaint alleged that Servizio Elettrico Nazionale S.p.A. had activated an electricity service in the name of the deceased, covering consumption for the years 2023 and 2024. In this regard, a request for information was therefore sent to the aforementioned company (see note dated July 11, 2024, ref. no. 85584/24), to which the company responded with a note dated September 30, 2024. In light of the statements made by Servizio Elettrico Nazionale S.p.A., a request for information was also sent to Acquirente Unico S.p.A. (hereinafter also “AU”), as the operator of the Integrated Information System (SII) (see letter dated November 5, 2024; ref. no. 129941/24; see the response from Acquirente Unico S.p.A. dated December 4, 2024), and, subsequently, to Acea Energia S.p.A. in its capacity as a dispatch user; Recital 1: Given that the latter had initially arranged to activate an energy supply on the open market at the POD assigned to XX (see note dated March 24, 2025; ref. no. 38941/25; see Acea Energia S.p.A.’s response dated April 22, 2025). On July 1, 2025, an inspection was also ordered against Acquirente Unico S.p.A. Subsequently, additional information was obtained through supplementary documentation submitted by the latter on August 1, 2025, thereby resolving the reservations raised during the inspection. Following the aforementioned on-site inspection and based on the findings thereof, it became necessary to initiate, ex officio, pursuant to Article 21 of the Data Protection Authority’s Regulation No. 1/2019, to initiate a preliminary investigation aimed at assessing, as a whole, the methods and processing purposes carried out by Acquirente Unico S.p.A. in its capacity as operator of the SII and, more specifically, of the Official Central Registry (hereinafter also “RCU”). With this in mind, the proceedings concerning the complaint filed by XX were first consolidated with other complaints of a similar nature submitted by Mr. XX (see complaint of April 8, 2025), by Messrs. XX and XX (see complaint of June 25, 2025), and Ms. XX (see complaint of October 6, 2025), as well as with the complaint of August 26, 2025, filed by Mr. XX, as it concerned grievances similar to those in the aforementioned cases. This was done in order to conduct a comprehensive review of the underlying issues. Subsequently, a further request for information was sent to Acquirente Unico S.p.A. (see note dated October 31, 2025, ref. no. 144814/25), to which the Company responded on November 20, 2025. During the proceedings described above, with regard to the issues highlighted in the introduction, the following facts emerged. Acquirente Unico S.p.A. is a public company responsible for managing the Integrated Information System (SII) “based on a database of electricity and gas consumption points and the identifying information of end customers, established by Art. 1-bis of Law 129/2010” (see the Company’s note dated December 4, 2024, p. 2). The activities “carried out by the SII and the procedures for managing information flows through [the SII] are governed by law and by the resolutions of the Regulatory Authority for Energy, Networks, and the Environment (ARERA). These regulations require energy operators to register with the SII and to transmit (and update) the data necessary to enable the activities entrusted to it. The aforementioned operators (..) are responsible for the accuracy of the information exchanged” (see the Company’s note dated December 4, 2024, p. 2). Ownership of the data processed through the SII “belongs to: a) each legal entity that participates in the SII and implements it through information flows (User), limited to the information in its possession; b) to AU with regard to the information collected in the Official Central Registry (RCU), the case filing system, and other databases contained within the central infrastructure” (see Company note dated December 4, 2024, p. 2). “Among the accountability responsibilities of SII Users is that of ensuring the fairness and truthfulness of the data within their purview that they provide, as required by Articles 6 and 17.8 of the SII Regulations” (see the Company’s note dated December 4, 2024, p. 2). With regard to the entry of customer-related data into the SII, AU has stated that, in the event of a new supply activation or a switch (switching) of the supply, the SII receives “communications pertaining to the supply (..) from the operators involved in each case, having the sole task of managing the information flows relating to the electricity and natural gas markets provided by the various market operators (..) and without any accountability for the accuracy of such information, accountability that rests solely and exclusively with the party providing the information” (see the Company’s note of December 4, 2024, p. 4). With regard to the requests submitted to the Authority, it emerged that, in the names of Messrs. XX, XX, XX, and XX, during periods following their respective deaths, various energy supply contracts were registered, each of which was subsequently subject to multiple switching operations involving different energy companies, with an average of approximately 2–3 supplier changes per year (see minutes of July 1, 2025, p. 3, and the communication from Acquirente Unico S.p.A. dated November 20, 2025, pp. 2–9). With regard to the report submitted by Mr. XX, it emerged that, prior to the application of July 21, 2025, which is the subject of the dispute, he had already submitted (specifically, on June 23 and December 1, 2023) several requests to exercise his right to rectification regarding the same complaint concerning the erroneous association of his data with a PDR not attributable to him (see Attachment 2 of the AU note dated August 1, 2025). In all three instances, Acquirente Unico S.p.A. replied that it could not proceed with updating the inaccurate data, on the grounds that “only the Operator/Supplier is responsible for updating or performing erasure of the data reported in the SII, and it is solely to the latter that [one must] turn” for this purpose (see Annex 2 of the AU note dated August 1, 2025; see also AU’s note in response to the complainant dated August 20, 2025). It was not until October 1, 2025, following an investigation by this Authority, that the Company took steps to correct the inaccurate information regarding Mr. XX, requesting the energy suppliers involved in this case, “each within the scope of their respective responsibilities, to regularize [the complainant’s] status and correct the [relevant] personal data” (see AU’s note in response to Mr. XX, dated October 1, 2025, p. 1). It was also found that, within the Official Central Registry, at the SII, as of August 1, 2025, there were approximately 11,711 customers over the age of 100 associated with 25,713 active energy supply contracts (see the Company’s note dated August 1, 2025, Annex 1— “Centennials”). With regard to the measures implemented by AU, in compliance with the accountability principle of the Regulation, to ensure the accuracy of customers’ personal data contained in the Official Central Registry, The representative of the Company stated that “it is not authorized by ARERA to conduct periodic checks aimed at identifying potentially inaccurate data (e.g., utility accounts associated with tax identification numbers of people over 100 years old; multiple activations in the name of the same individual and at the same supply address; etc.). This is because it is not AU’s responsibility to ensure the accuracy of the data in the aforementioned registry; this obligation falls, by regulation, exclusively to the operator, (..) while AU is responsible [only] for certifying the consistency of such data” (see minutes of July 1, 2025, pp. 3 and 5). Acquirente Unico S.p.A., in fact, has “no authority to modify the data contained within the RCU; such modifications may be made solely by Users authorized to enter such information (in this case, the energy suppliers)” (see minutes of July 1, 2025, p. 4). Likewise, the Company cannot, in cases similar to those reported by the petitioners, notify energy suppliers of the existence of active PODs/PDRs in the name of a deceased individual, in order to invite them to verify the accuracy of their customers’ data and update it within the RCU as necessary. This activity “is not among the tasks specifically assigned to AU; in fact, the SII does not provide for direct communication flows whereby AU modifies end-customer records with respect to energy suppliers” (see minutes of July 1, 2025, p. 4). For these reasons, Acquirente Unico S.p.A., in the cases in question, once it had taken note of the fact that the aforementioned energy supply contracts were in the names of deceased individuals, “did not conduct a check to verify the presence, within the SII, of any additional active supply contracts in the name of [the aforementioned data subjects]; this in light of the fact that, although it was aware of the deaths of the latter, it had not received any specific request from the entitled parties to cancel the relevant supply contracts, a revocation that would have allowed it to take the necessary actions (notifying the operator to correct the data)” (see minutes of July 1, 2025, p. 3). Finally, with regard, more generally, to the operating procedures adopted by Acquirente Unico S.p.A. when responding to requests for data correction submitted by data subjects (Articles 12 and 16 of the Regulation), the Company stated that it typically responds that “it cannot intervene directly on the RCU,” while simultaneously inviting “the data subject to first contact the relevant energy supplier” (see minutes of July 1, 2025, p. 4). On this point, it also reiterated that “since 2018, the Company has received fewer than 10 requests for correction regarding SII data pursuant to the GDPR, to which it responded in accordance with the terms indicated above” (see minutes of July 1, 2025, p. 4). More specifically, Acquirente Unico S.p.A. provided eight responses pursuant to Articles 12 and 15 of the Regulation, concerning seven data subjects (see the Company’s communication of August 1, 2025, Annex 2 – “Requests for Rectification and Responses”). 3 Notification of Violations and Defenses. By notice dated February 27, 2026, the Office, based on the documentation in the case file and the evidence gathered during the preliminary investigation, notified Acquirente Unico S.p.A. of the initiation of proceedings for the adoption of corrective and punitive measures regarding the alleged violations of Article 5, para 1, subparagraph d) and para 2, as well as Articles 12, 16, 24, and 28 of the Regulation; in accordance with the provisions of Article 166, paragraph 5, of the Code. In this regard, the Company, by notice dated March 28, 2026, submitted its defense briefs, which were further supplemented during the hearing on May 27, 2026. In this regard, with respect to the allegations, Acquirente Unico S.p.A. argued as follows: a) regarding the alleged violation of the principles of accuracy and accountability, the Company highlighted the limitations—in terms of powers and responsibilities—imposed on Acquirente Unico S.p.A. under sector-specific regulations. In fact, the Company “operates within the scope of activities [strictly] defined by the Regulatory Authority for Energy, Networks, and the Environment (hereinafter “ARERA”),” a scope that, to date, in no way provides for either the implementation of measures aimed at verifying the accuracy of customer data contained in the RCU, nor operations to update or correct such data at the request of the individual data subjects concerned. This is due to the fact that “AU is assigned only the task of certifying the information communicated to it by the operators. This activity (..) stems from the nature of the SII itself, which does not manage either contracts or other documentation that would enable it to verify the fairness of the data.” It follows that if Acquirente Unico S.p.A. “were to independently correct the data” or were to “activate alert systems” and/or other measures of a similar nature, it “would violate [the aforementioned regulations and, more specifically,] the SII Regulation” (see the Company’s note dated March 28, 2026, pp. 3, 9–11, 13); b) with regard to the allegations concerning the violation of Articles 12, 16, and 28 of the Regulation, the Company pointed out that, although it was unable to update customers’ inaccurate personal data for the reasons stated above, “AU has always been cooperative with the data subjects, identifying the entity responsible for the correction to which [the data subjects] could easily turn.” The responses provided by Acquirente Unico S.p.A. in response to requests to exercise the right under Article 16 of the Regulation must be interpreted in this light: these responses were “clearly intended to indicate to the end customer the quickest way to obtain data rectification,” with a view to “guiding the data subject toward the fastest resolution path” (see the Company’s note dated March 28, 2026, pp. 14–15). In particular, with specific reference to the alleged violation of Article 28 of the Regulation, the Company clarified that, in the cases under investigation, the response provided by AU, although not in line with the instructions issued by the data controller, nevertheless effectively led to the updating of the aforementioned information by the designated individual, thereby enabling the data subjects to receive the social benefits to which they were entitled (see minutes of the hearing of May 27, 2026); c) with regard to the additional factors for assessment pursuant to Article 83, para 2 of the Regulation, the Company first stated that, in response to the notice of violation issued by the Data Protection Authority, it had initiated a review of its “response procedures [pursuant to Article 12 of the Regulation], with the aim of informing all authorized personnel of the Data Protection Authority’s interpretation regarding the obligation to forward any requests for correction to the operators who enter the relevant data into the SII.” This process also addressed cases in which AU acts as a processor on behalf of ARERA. The Company further announced its intention to “have a third-party, independent entity conduct a general audit [regarding personal data protection] of the entire data management structure” processed by the Company in its capacity as data controller. Finally, it noted that it had launched “a specific training session for designated staff aimed at better clarifying the procedures for responding pursuant to Article 12 of the Regulation” (see the Company’s note dated March 28, 2026, p. 19 and the minutes of the hearing of May 27, 2026); d) regarding the revenue reported in the 2024 financial statements, it emphasized that this figure does not reflect the Company’s actual economic capacity and that it cannot be equated with that of other private economic operators. Acquirente Unico S.p.A., in fact, does not operate as a for-profit commercial enterprise in a competitive market, but rather as an entity established by express provision of law to carry out tasks in the public interest as specifically set forth by sector-specific regulations (see the Company’s note dated March 28, 2026, pp. 18–19). Finally, the Company stated that it is “fully willing to initiate, together with ARERA and, hopefully, with the support of the Data Protection Authority, a specific dialogue regarding the introduction into the SII Regulations, in accordance with the procedure set forth in paragraphs 6 and following of Art 2 of Annex A to Resolution 201, provisions governing the verification of utility accounts and the obligations to correct data in the RCU in light of requests submitted by end customers” (see the Company’s note of March 28, 2026, p. 14). With this in mind, it has already launched an internal review aimed at identifying some initial proposals to be submitted to the aforementioned Authorities, intended to include the “definition, in agreement with ARERA and the Data Protection Authority, of a cooperation procedure for managing requests, in compliance with the primary legislation governing the SII; the conduct of coordinated moral suasion efforts with ARERA to ensure that operators comply with their obligations regarding data entry and prompt responses to requests for corrections; the preparation of a report on requests for correction on a bimonthly or quarterly basis to be sent to ARERA and the Data Protection Authority for their respective areas of jurisdiction” (see minutes of the hearing of May 27, 2026). 4 Dialogue with ARERA. Following receipt of the defense briefs submitted by Acquirente Unico S.p.A. and in light of their content as described above, the Authority initiated an initial dialogue with ARERA, aimed at obtaining, from the latter, useful information for analyzing the regulatory framework underlying the role and tasks entrusted to Acquirente Unico S.p.A. as operator of the SII (and, within it, the RCU). A request was also made to the aforementioned Authority to identify what measures it could take to ensure full compliance with data protection regulations in the context in question (see the Data Protection Authority’s note of March 30, 2026). In this regard, ARERA, in a note dated May 14, 2026, provided some preliminary guidance regarding the relevant regulations pertaining to the case in question and agreed on the advisability of initiating a dialogue with the Data Protection Authority in order to resolve some of the critical issues that have emerged in the context of the proceedings under review. With regard to sector-specific regulations, concerning the role assumed by Acquirente Unico S.p.A. in relation to the information contained in the SII and, in particular, in the Official Central Register, ARERA clarified the latter’s role as a “certifier”—that is, an entity responsible for verifying the information in the SII “of a purely technical nature (for example, the type and number of characters entered in fields such as tax ID and POD/PDR) and not pertaining to the accuracy” of such information (see ARERA note of May 14, 2026, p. 3). This is because, under the current regulatory framework, the SII operator has not been granted “the power to unilaterally modify the data; at most, an obligation [on the part of the SII operator] to take steps to report any discrepancies in the information entered into the SII to the Authority and/or to the operators who entered that data” into the system (see ARERA note dated May 14, 2026, p. 5). ARERA therefore concurred with the interpretation of the primary and secondary legislation pertaining to the energy sector provided by Acquirente Unico S.p.A. in its defense briefs; this applies both to “the assertion (…) regarding the scope of the SII operator’s role as a mere manager of information flows pertaining to the electricity and gas markets provided by market operators, without any accountability for the accuracy of such information,” and with regard to the assertion that the obligation to enter accurate data into the system “would fall solely and exclusively on the entity providing the information (i.e., the energy suppliers and distributors involved in each case)” (see ARERA note of May 14, 2026, p. 5). Notwithstanding the foregoing, ARERA also emphasized, in light of the various critical issues highlighted by the Data Protection Authority regarding the accuracy of customers’ personal data contained in the RCU, the advisability of evaluating—including through the discussions already underway with the Data Protection Authority—a direct regulatory intervention aimed both “at introducing measures to hold commercial operators more accountable” and at “proposing an amendment to the SII Regulation” designed to bring the regulatory framework into compliance with data protection laws. Furthermore, with specific reference to the issues that have arisen regarding AU’s response to requests by end customers to exercise their rights, it was stated that the data subjects’ need for rectification “could be met by providing that AU, whenever it receives a request from an end customer to correct the data contained in the RCU, process such request in its capacity as the Energy and Environment Consumer Help Desk (...), and forward the request to update the RCU directly to the relevant commercial operator in light of the correction request received” (see ARERA note of May 14, 2026, p. 6). 5 The outcome of the preliminary investigation and the Department’s assessments regarding the unlawfulness of the processing of customers’ personal data contained in the Official Central Registry. First and foremost, it should be noted that, unless the act constitutes a more serious offense, anyone who, in proceedings before the Data Protection Authority, falsely declares or attests to facts or circumstances, or produces false documents or records, is liable pursuant to Art. 168 of the Code, “False Statements to the Data Protection Authority and Interruption of the Performance of the Authority’s Duties or Exercise of Its Powers.” That said, in light of the evidence gathered during the preliminary investigation described above and the subsequent assessments conducted by this Department, the following violations have been identified with respect to Acquirente Unico S.p.A., as detailed below; These relate to the processing of customers’ personal data carried out by Acquirente Unico S.p.A., in its capacity as data controller, in the performance of its duties as administrator of the Official Central Registry, as well as to certain actions undertaken in its capacity as processor pursuant to Article 28 of the Regulation. 5.1 The Official Central Registry and Acquirente Unico’s status as data controller with respect to the personal data of end customers contained therein. It should be noted at the outset that, for the purposes of this decision, it is necessary to take into account the specific context underlying the processing activities carried out in the present case, as they are performed within the SII and, more specifically, within the Official Central Registry established therein. In this regard, it is worth recalling that the aforementioned Registry constitutes the national database of identifying information for so-called end customers—that is, the owners of an electricity withdrawal point (POD) and a natural gas redelivery point (PDR)—as well as data pertaining to the management of SII processes (see Art. 1-bis, paragraph 1, of Law No. 129/2010). The RCU thus forms the basis for information flows among the various energy market operators (primarily distributors and suppliers) and for the various processes necessary for the operation, throughout the country, of the entire sector in question (from the activation of a supply to the transfer of that supply to another customer; from switching to a new provider in the open market to the assignment of customers to the Services of Last Resort; from the activation of the Vulnerability Service to the automatic disbursement of social bonuses; etc.). The management of the aforementioned Registry is entrusted by law to Acquirente Unico S.p.A., which is also designated as the controller for the personal data contained therein (see the SII Regulation, adopted pursuant to Art. 2.6 of Annex A to ARERA Resolution No. ARG/com 201/10). More specifically, the SII Operating Regulations (hereinafter “SII Regulations”) stipulate that responsibility for processing the information in the RCU lies with: each User (e.g., energy supplier and/or distributor), limited to the information in its possession; Acquirente Unico S.p.A., in its capacity as SII Operator, with respect to the information collected therein. It should be noted that this responsibility “passes from the User to the Operator, or vice versa depending on the direction of the exchange flow, from the moment the data is submitted to the Data Delivery Point” (Articles 5.5 and 17.2 of the SII Regulations). It is also expressly provided that “the User is responsible for the fairness and truthfulness of the data communicated to the Operator” and that “the Operator is responsible for the consistency and updating of the RCU (…), with respect to the information received from Users, [as well as] for the correct sequence of updates in relation to the managed processes” (Art. 17.8 of the SII Regulation). Acquirente Unico S.p.A., in its capacity as Operator, is also assigned specific tasks and primary accountability regarding the information it processes. It is, in fact, responsible for ensuring: - “the processing of information relating to end customers collected in the RCU, (..) in accordance with Regulation (EU) No. 2016/679” (see Art. 5.5 of the SII Regulations); - “the security, confidentiality, and integrity of the information both in communications with Users and in the SII databases,” including the RCU (see Art. 5.3 of the SII Regulation); - “the enforceability against third parties of the data entered in the Official Central Registry, the verification and control of the data provided by Users in communications to the SII, (..) the storage and archiving of the information and communications” contained therein (see Art. 5.3 of the SII Regulation). Finally, the aforementioned SII Regulation stipulates that “if the Operator detects an error in the personal data received or in the content of the RCU, [it is required to promptly provide] the data subjects with the information necessary to make the required corrections” (Art. 17.10 of the SII Regulation). In light of the aforementioned duties and accountability, the role of Acquirente Unico S.p.A. is clearly evident as the data controller of the end customers’ personal information contained in the Official Central Registry; a controller responsible for ensuring compliance with data protection regulations. It is also worth noting, in this regard, that the Company operates within a stringent regulatory framework, with activities, scope, and operating procedures strictly governed by law and public regulation. In particular, the tasks assigned by ARERA to Acquirente Unico S.p.A.—as a mere “certifier” of SII data, in accordance with sector regulations—do not appear to allow it to fully comply with the obligations imposed by EU Regulation No. 2016/679 to the controller. Specifically, reference is made to the absence—repeatedly emphasized by the Company during the proceedings—of a clear allocation of powers and responsibilities aimed at ensuring, including from an accountability perspective, the accuracy of the personal data processed within the RCU (see para 3(a) of this decision). All this is considered in light of the fact that the sector-specific regulations have limited themselves to conferring upon that entity, with respect to the RCU, “the sole task of managing the information flows pertaining to the electricity and gas markets provided by market operators, (…) with no accountability [having been assigned to the Operator] for the accuracy of such information; accountability that rests solely and exclusively on the entity providing the information [namely, the energy suppliers and distributors involved in each case]” (see paragraphs 2 and 3 of this decision). This is the case even though, at the same time, the aforementioned legislation, with regard to aspects pertaining to data protection, has attributed to Acquirente Unico S.p.A. the status of data controller for customer data processed within the RCU (see Art. 17 of the SII Regulation), a role that is not compatible with the functions of a mere “certifier” of the information entered by Users into the SII. It should also be noted that, through the RCU, Acquirente Unico S.p.A., in accordance with sector-specific regulations, carries out a distinct and far more extensive processing of personal data than that performed by individual energy operators participating in the SII. In fact, the end customer’s personal data—once entered by the User into the SII—is linked to other personal information pertaining to that same data subject present in the RCU, as well as, at a later stage, to information that will be provided by other Users over time, creating a set of information capable of representing the end customer’s “energy history.” On this point, it is worth noting that the Official Central Registry contains a wide range of personal information about the end customer, such as: the number of other active or terminated supply contracts associated with the same tax ID number; the number of switches made in the past, relating to the POD/PDR being entered; whether the data subject belongs to categories eligible for the social bonus; the consumption recorded for the aforementioned customer; etc. It follows that the RCU Operator possesses a complex and comprehensive set of personal data, over which it assumes full and independent control, with all the resulting obligations in terms of compliance with EU Regulation No. 2016/679; first and foremost, with regard to the procedure under consideration, those concerning compliance with the principles of accuracy and accountability, as well as the provisions regarding the exercise of data subject rights. In the context of the processing carried out through the SII (and more specifically, within the RCU), there therefore appears to be a need for regulatory action which, taking into account the much broader scope the RCU has assumed over time, as a result of the various regulatory provisions that have accumulated over the years, provides Acquirente Unico S.p.A. with the necessary tools to fully carry out its role as the controller for the customer data contained therein. 5.2 Violation of the principle of accuracy. Based on the overall checks conducted during the present investigation, it emerged that the aforementioned Registry contained inaccurate and outdated personal data of end customers, with particular reference to information regarding electricity and gas supply contracts concluded after the customers’ deaths. Specifically, with regard to the complaints filed with the Data Protection Authority, it was first established that the personal data of Messrs. XX, XX, XX, and XX, regarding the flow of information at the SII concerning the activation—in their names and during periods following their deaths—of various energy supply contracts; Each of these supply contracts was subsequently subject to multiple switching operations involving different energy companies, with an average of approximately 2–3 supplier changes per year. More specifically, these involved: 10 energy supply contracts in the name of Mr. XX; three of which were still active as of the date of the inspection on July 1, 2025 (see inspection report of July 1, 2025, p. 3); 6 contracts in the name of Ms. XX (erroneously listed in the RCU as XX and as XX; see the notice from Acquirente Unico S.p.A. dated November 20, 2025, pp. 2–5); 4 supply agreements, in the name of Ms. XX, one of which was still active as of November 20, 2025 (see the notice from Acquirente Unico S.p.A. dated November 20, 2025, pp. 6–9); 1 supply relationship, registered in the name of Mr. XX (erroneously listed in the RCU as XX; see the communication from Acquirente Unico S.p.A. dated November 20, 2025, p. 6). It was also found that, as of August 1, 2025, the Official Central Registry at the SII contained approximately 11,711 customers over the age of 100, to whom 25,713 active energy supply contracts were associated (see the Company’s note dated August 1, 2025, Annex 1— “Centenarians”); among these, for example, there are 184 people aged 110 and as many as 74 aged 114 It should also be noted that, as of now, in most cases, these customers are associated with multiple active supply contracts (in some instances, up to 17 different contracts). Finally, with regard to Mr. XX’s complaint, it emerged that the erroneous association of his data with a PDR not pertaining to him persisted for approximately two years, namely from the complainant’s submission on June 23, 2023, of the first request for rectification pursuant to Article 16 of the Regulation, until October 1, 2025, the date on which Acquirente Unico S.p.A., following the Data Protection Authority’s intervention, requested the cooperation of the energy suppliers involved in this case to update his status (see AU’s response to Mr. XX dated October 1, 2025). Each of the aforementioned transactions involved the processing by Acquirente Unico S.p.A. of inaccurate and outdated personal data of end customers within the RCU; which constitutes a violation of Article 5(1)(d) of the Regulation (the so-called principle of accuracy). On this point, it should be noted that the principle of accuracy requires the data controller to carry out periodic verification of the processed data by implementing, on the one hand, technical and organizational processes capable of ensuring the accuracy and timeliness of such data, and, on the other hand, by adopting operational practices suitable for enabling timely and precise corrective action regarding inaccurate information. It is also worth noting that Article 5 of the Regulation must be read in conjunction with the principle of accountability (Art 5(2) and Art 24 of the Regulation). Pursuant to the aforementioned provisions, in fact, the controller is the entity to which “overall accountability” for the processing is attributed; consequently, the controller bears the burden of implementing an organizational and management system characterized by concrete, effective, and verifiable data protection measures (see also Recital 74 of the Regulation); this is achieved not only through the proper and timely fulfillment of the obligations imposed by the Regulation (privacy notice; record of processing activities; appointment of a data protection officer where required; etc.), but also through the implementation of organizational procedures and practices designed to bring the relevant processing operations into compliance with the applicable regulations (e.g., processes for the proper management of data subject to processing; data retention policies; procedures for handling requests to exercise rights and complaints; etc.; see Article 29 Working Party, WP 173 of July 13, 2010—Opinion 3/2010 on the principle of accountability, pp. 11–12). The implementation of the principle of accountability with regard to the principle of accuracy imposes on the data controller, first and foremost, the obligation to adopt appropriate technical and organizational measures to ensure the lawfulness, fairness, and up-to-date nature of the data processed in the RCU. This is true even when considering the specific context at hand, in which the controller operates within the limits permitted by current regulatory provisions (see recitals 4 and 5.1 of this decision). This is to be achieved, first and foremost, through preventive procedures designed to ensure the consistency and appropriateness of the information entered into the system. In this regard, the data controller should conduct periodic ex post checks as measures designed to identify indicators of anomalies, with a view to prompting further, targeted investigations by the data controller. This refers, for example, to the provision for consistency checks on data in the system with regard to the inclusion of alerts triggered by various anomalies (such as: the upload to the SII of an abnormal number of PODs/PDRs registered to the same individual; an excessive number of switching events occurring in close succession with respect to the same supply/delivery point; the recurrence of the same contact information—such as email addresses or phone numbers—across multiple PODs/PDRs; etc.). The adoption of such systems should also be accompanied by the implementation of procedures that allow Acquirente Unico S.p.A. to actively engage with SII Users (in particular, energy suppliers); this—as also recognized by ARERA itself (see note of May 14, 2026)—in order to facilitate the updating of personal data in the RCU in accordance with the requirements of Article 5, para 1, subparagraph d) of the Regulation. The absence of the above-mentioned measures or, in any case, of other technical and organizational measures equally suitable for ensuring the consistency and accuracy of the personal data processed in the RCU—a circumstance ascertained, as highlighted above, during the inspection— has therefore resulted, on the part of Acquirente Unico S.p.A., not only in the aforementioned violation of Article 5, para 1, subparagraph d) of the Regulation, but also in a violation of Article 5, para 2, and Article 24 of the Regulation. With regard to the aforementioned allegations, it is necessary to take into account the findings that emerged following discussions with ARERA concerning the current regulatory framework (see paragraphs 4 and 5.1 of this decision). In this regard, based on an examination of all the documentation obtained, it is considered appropriate to accept the arguments put forward by the Company aimed at excluding its accountability with respect to the failure to adopt the measures outlined above; this is because Acquirente Unico S.p.A. acted in good faith and strictly adhered to the instructions and procedures specifically set forth in the sector’s regulations (see, among many others, Civil Cassation, Section II, No. 20219 of July 31, 2018; see also Civil Cassation, Section II, Judgement No. 6051 of March 6, 2025). Of particular relevance in this regard, with respect to the excusability of the error committed by the Company, is the fact that ARERA confirmed, in the aforementioned note dated May 14, 2026, the interpretation, followed by AU, of the aforementioned regulator’s resolutions concerning the duties and powers assigned to Acquirente Unico S.p.A. as operator of the SII and the RCU; resolutions which, therefore, constitute a positive factor, unrelated to the perpetrator of the violation, capable of leading the latter to believe that its conduct was lawful. Having duly set forth the foregoing, with regard to the violations of the principles of accuracy and accountability as alleged in the Authority’s notification of February 27, 2026, it is noted, therefore, that, with respect to the specific conduct referred to in these proceedings, the conditions for adopting the measures provided for in Art 58 of the Regulation do not exist. Accordingly, limited to this specific aspect, the request made by Acquirente Unico S.p.A. to dismiss the allegation regarding these specific instances of violation is granted (see para 3, subparagraph a) of this decision). At the same time, given the broader scope that the Official Central Registry has assumed to date, it is deemed necessary to reiterate the aforementioned need, in the near future, for regulatory action aimed at bringing the current sector-specific regulatory framework into compliance with data protection legislation. In this regard, the Authority therefore takes note of the initiation of a collaborative effort between the Authority and ARERA aimed at addressing the systemic issues highlighted above. 5.3 Violations concerning the exercise of data subject rights. Data protection legislation requires the data controller, in accordance with the principle of accountability, to establish an organized system for managing requests submitted pursuant to Articles 15–22 of the Regulation, by identifying specific and adequate instructions to be provided to designated staff (such as, for example, the obligation to monitor the dedicated email account; instructions clarifying the deadlines to be met; guidelines for identifying cases where deadlines may be extended; etc.) and providing them with response templates (e.g., request for rectification; extension of deadlines with justification; etc.) and operational procedures for handling various scenarios (e.g., instructions on the actions to be taken in the event of a follow-up request; etc.). All of this is intended to ensure that adequate and effective measures are adopted to fulfill the data controller’s broader duty to facilitate the exercise of the rights set forth in Articles 15–22 of the Regulation (see Article 12, para 2, and Recital 59 of the Regulation); this also applies, with specific reference to the cases in question, to the obligation to ensure the rectification of inaccurate or outdated data concerning the data subject (Art. 5(1)(d) of the Regulation). With regard to the manner in which Acquirente Unico S.p.A. responded to requests to exercise the right to rectification, submitted by data subjects pursuant to Article 16 of the Regulation, it emerged that, in all cases examined by the Authority, responded to the requests received by stating that it could not update the inaccurate information of end customers and by inviting the latter to resubmit their requests to other, different controllers (see the Company’s communication of August 1, 2025, Annex 2 – “Requests for Rectification and Responses”). This was the case both when Acquirente Unico S.p.A. acted as the controller (see the requests submitted by Messrs. XX, XX, XX, XX, and XX), and in cases where it has served in the distinct role of processor pursuant to Art. 28 of the Regulation (see the requests from Messrs. XX and XX). In particular, it should be noted that in all the cases referred to above in which Acquirente Unico S.p.A. acted as the data controller, the latter should instead have taken active steps to ensure that inaccurate customer information was updated, including, where necessary, liaising with the relevant energy suppliers on a case-by-case basis to conduct the necessary verifications. In response to a request to exercise the right to rectification of personal data contained in the RCU, the data controller, in fact, cannot—as was evident in the cases under review—simply invite the data subject to contact the energy supplier, but is obligated to take action (including, if necessary, through the aforementioned supplier) to promptly carry out the necessary verifications and, where appropriate, update the inaccurate data, also in order to comply with the provisions of Article 19 of the Regulation. All of this must be done ex officio if the conditions are met; in this regard, with reference to the case of Mr. XX, Acquirente Unico S.p.A., after becoming aware (through the request for information sent by this Office) of Mr. XX’s death in connection with a POD associated with him, it should have independently verified whether there were any other transactions containing inaccurate data regarding the aforementioned data subject and taken steps to update the RCU accordingly and notify the relevant supplier in this regard. This action, in addition to ensuring that AU’s processing complies with the principle of accountability, is necessary to guarantee—in accordance with Article 5, para 1, subparagraph d) of the Regulation—the consistency and accuracy of the information contained in the Official Central Register. The conduct adopted by the data controller in all the cases listed above (refusal to correct the data and referral to the relevant supplier) constituted a violation of Articles 12 and 16 of the Regulation and, in fact, resulted in the continued unlawful processing of inaccurate data pertaining to the aforementioned complainants within the aforementioned RCU. On this point, it is not possible to accept the argument put forward by Acquirente Unico S.p.A. regarding its technical inability to independently modify the customer records in the SII (see para 3, subparagraph b) of this decision). It should be noted, in fact, that in any case, the aforementioned data controller, in accordance with the regulatory obligation to facilitate the exercise of data subjects’ rights (Article 12 of the Regulation), should at the very least have complied with requests to update inaccurate data concerning data subjects by reporting the inconsistency to the relevant suppliers and simultaneously requesting that they verify and make the necessary changes to the system. Moreover, this is an activity that Acquirente Unico S.p.A. has already demonstrated it is capable of performing, as, following the launch of the Data Protection Authority’s investigation into Mr. XX’s complaint, it intervened by requesting the relevant suppliers to ensure the timely update of the aforementioned customer’s data in the RCU. Furthermore, ARERA itself has represented that, although under current regulations “Acquirente Unico S.p.A. is not granted the authority to unilaterally modify the data [in the SII], there remains (..) the obligation [on Acquirente Unico S.p.A.] (…) to take action to report discrepancies in the data entered into the SII to the Authority and/or to the operators who entered that data” (see ARERA note of May 14, 2026, pp. 4–5). With specific reference, however, to the processing of data pertaining to Mr. XX and Ms. XX, in which AU acted as a data processor pursuant to Art. 28 of the Regulation, it is noted that AU should have proceeded in accordance with the specific instructions provided by the data controller through the designation document signed for that purpose (see Annex 2—“ARERA Agreement,” attached to AU’s note of November 20, 2025). In fact, within the aforementioned “ARERA Agreement,” the data controller correctly provided the instructions required by Article 28, para 3 of the Regulation, imposing, among other things, the obligation on AU to “promptly notify the data controller, within 3 business days, regarding any requests from data subjects that may be received by the data processor, by sending a copy of the requests received to the email address indicated in the ‘Communications’ article, and to cooperate in order to ensure that data subjects can fully exercise all rights provided for by applicable law” (see Art. 5, paragraph 14 of the ARERA Agreement, cited above). Contrary to what was therefore expressly requested by the data controller, Acquirente Unico S.p.A. failed to comply with these operational guidelines, omitting to involve the controller and limiting itself, in the response provided to data subjects, to pointing out that the controller was unable to correct the inaccurate personal information; thereby inviting them to submit a specific request for rectification to INPS or to the data subject’s water utility. For these reasons, therefore, it is considered that AU’s conduct in this case constituted a violation of Article 28(3)(a) and (e) of the Regulation. 6 Conclusions: Declaration that the processing is unlawful. Corrective measures pursuant to Art. 58(2) of the Regulation. In light of the overall findings, the Authority considers that the statements, documentation, and explanations provided by the controller during the investigation do not sufficiently address the objections notified by the Office in thenotice of initiation of proceedings and are therefore insufficient to warrant the dismissal of this proceeding, especially since none of the cases provided for in Art. 11 of the Data Protection Authority’s Regulation No. 1/2019 apply. The processing of customers’ personal data carried out by Acquirente Unico S.p.A., in the context of activities related to the management of the Official Central Registry, is in fact unlawful, under the terms set forth above, as it was carried out in violation of Articles 12, 16, and 28 of the Regulation. The unlawfulness affected seven data subjects and continued for approximately four years; more specifically, from May 25, 2021 (the date of the access request submitted by Mr. XX) to November 20, 2025 (the date of the last response provided by the Company to the Data Protection Authority). The violation of the provisions referred to above entails the application of the administrative sanction provided for in Art. 83, para. 4, subpara. (a), and para. 5, subpara. (b), of the Regulation. With regard to the exercise of the corrective powers referred to in Art. 58, para 2, of the Regulation, it should be noted that—although, due to the need to revise the sector’s regulatory framework as previously highlighted, it was decided to dismiss the allegations raised against Acquirente Unico S.p.A. regarding the principles of accuracy and accountability—the RCU continues to process inaccurate and outdated information concerning the personal data of Messrs. XX, XX, XX, XX, and XX. With regard to the personal data of the aforementioned data subjects, it is therefore necessary to order the correction of such data pending the completion of ARERA’s review of the aforementioned legal framework. It is therefore deemed necessary to order the controller, pursuant to Article 58(2)(d) of the Regulation, to take the following corrective measures: a) with regard to the requests at issue in this proceeding, to correct the inaccurate personal data of Messrs. XX, XX, XX, XX, and XX through consultation with the respective service providers involved. For this purpose, it will be necessary to maintain adequate documentation (e.g., through a system entry) of the fact that the service was erroneously activated in the name of a deceased individual (with respect to Messrs. XX, XX, XX, and XX) or due to a case of homonymy (with respect to Mr. XX); b) with reference to the policy adopted by the Company for the purposes of complying with Articles 15–22 of the Regulation, adopt a specific Section regarding the rectification of inaccurate data processed within the RCU that, while taking into account the various scenarios that could be the subject of a request under Art. 16 of the Regulation (e.g., unsolicited service; service in the name of a deceased individual; failure to update the customer’s personal information or contact details; incorrect POD/PDR address; etc.), establishes specific procedures to enable the updating of the aforementioned personal data—where appropriate, through the involvement of the data subjects—and provides detailed instructions to the designated operators, as well as the measures necessary to implement the provisions of Article 19 of the Regulation. Finally, with regard to the data of the 11,711 customers over the age of 100 who are active service holders within the RCU, it is acknowledged that the aforementioned discussions with ARERA have begun, aimed at evaluating the steps to be taken to ensure full compliance with data protection regulations in the context at hand. 7 Adoption of the injunction ordering the imposition of an administrative fine and ancillary penalties (Articles 58(2)(i) and 83 of the Regulation; Article 166(7) of the Code). The Data Protection Authority, pursuant to Art 58, para 2, subparagraph i) of the Regulation and Article 166 of the Code, has the power to impose an administrative fine provided for in Article 83 of the Regulation, through the adoption of an injunction order (Article 18. Law No. 689 of November 24, 1981), in connection with the processing of personal data carried out by Acquirente Unico S.p.A., which has been found to be unlawful, as set forth above. Having determined that paragraph 3 of Art 83 of the Regulation must be applied, which provides that “if, in relation to the same processing or related processing operations, a controller […] intentionally or negligently violates several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the most serious infringement,” the total amount of the fine is calculated so as not to exceed the maximum penalty provided for in Art. 83(5) of the Regulation. With regard to the factors listed in Article 83(2) of the Regulation for the purposes of imposing the administrative fine and determining its amount, and taking into account that the fine must be “in each individual case effective, proportionate, and dissuasive” (Article 83(1) of the Regulation), it is noted that, in the case at hand, the following circumstances were taken into account. With specific regard to the nature, gravity, and duration of the violations, whether they were intentional or negligent, as well as the categories of data involved (Articles 83(2)(a), (b), and (g) of the Regulation), the following were noted: the significant severity of the violations (Articles 83(2)(a) and (g) of the Regulation), in relation to their nature (concerning non-compliance with the principles governing the exercise of rights), the manner (the multiple instances of unlawful conduct repeated over time), and the duration of the violations (approximately four years). The nature, context, and processing purpose, as well as the type of harm suffered by the data subjects involved, were considered relevant for this purpose. All of this, given that: the operations in question were carried out by Acquirente Unico S.p.A. as part of the management of the Official Central Registry—that is, the national database containing identifying information on energy market customers; the data protection issues identified relate to the processes and policies implemented by the controller at the time of processing, highlighting a systemic inadequacy in the procedures for responding to requests by data subjects to exercise their data subject rights. On the other hand, factors in favor of the violator include the fact that the processing was carried out for the pursuit of tasks in the public interest, the non-sensitive nature of the personal data processed in the cases in question, as well as the small number of data subjects involved; the negligent nature of the violation (Art. 83, para 2, subparagraph b) of the Regulation), given that the conduct was carried out under the Company’s mistaken belief that, in light of sector-specific regulations governing energy law, it did not have the authority to correct inaccurate personal data within the RCU. In light of these circumstances, it is considered that, in the present case, the level of severity of the violations committed by the controller is moderate (Guidelines 4/2022 on the calculation of administrative fines under the GDPR, adopted by the Committee on May 23, 2023, paragraph 60). With regard to the additional factors identified in Article 83(2) of the Regulation, the following indicators were also taken into account: the significant instance of accountability of the data controller with regard to the technical and organizational measures implemented (Articles 83(2)(d) of the Regulation); specifically, with regard to the inadequacy of the procedures implemented by Acquirente Unico S.p.A. to address, in accordance with the Regulation, requests for rectification submitted by data subjects. Factors considered in favor of the violator include the unique structure of the technical processes specific to the SII and the operational practices in use within the SII by its Users; the fact that there are no previous violations committed by the controller or previous measures pursuant to Article 58 of the Regulation concerning the same subject matter (Article 83(2)(e) and (i) of the Regulation). On this point, it should be noted that Measure No. 764 of December 18, 2025 (web doc. No. 10210454) was not taken into account for this purpose, given that the investigations pertaining to this decision were conducted concurrently with those that led to the adoption of the aforementioned measure against Acquirente Unico S.p.A.; the adoption by the data controller of certain measures designed to mitigate or eliminate the consequences of the violation (Art. 83(2)(c) of the Regulation). In this regard, the initiatives taken by Acquirente Unico S.p.A. to facilitate the exercise of Mr. XX’s right to rectification of his data should be viewed favorably; however, since these measures were directed exclusively at a single data subject, they were only partially effective in reducing the harmful consequences of the violation; the fact that the Company actively cooperated with the Authority during the proceedings (Art. 83(2)(f) of the Regulation); other mitigating factors (Article 83(2)(k) of the Regulation): consideration was also given, in favor of the offender, to the initiatives recently undertaken by the Company to strengthen its level of compliance with the Regulation, as described in para 3, subparagraph (c) of this decision, as well as the in-depth analysis conducted internally by AU with a view to identifying some initial proposals to be submitted to the Data Protection Authority and ARERA, as detailed in para 3 of this decision. It is also considered that, in the case at hand, the following is relevant in light of the aforementioned principles of effectiveness, proportionality, and deterrence, which the Authority must observe when determining the amount of the penalty (Art. 83(1) of the Regulation), the legal nature of Acquirente Unico S.p.A., as a wholly publicly owned in-house company (see para 3(d) of this decision). In light of the above factors and the assessments made, it is deemed appropriate, in the present case, to impose on Acquirente Unico S.p.A. an administrative penalty consisting of the payment of a sum equal to 90,000.00 euros (ninety thousand/00). In this context, it is also deemed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Authority’s Regulation No. 1/2019, this section containing the injunction order must be published on the Data Protection Authority’s website. This is in light of the nature of the violations found, which concerned the procedures used by the Company to respond to requests to exercise the data subject rights. In this regard, account is taken of the impact that these practices have had on the rights of end customers, given that they effectively prevented the latter from obtaining, from Acquirente Unico S.p.A., the rectification of their personal data. Also relevant in this regard is the broad scope of the unlawful conduct, as it pertains to processing operations carried out for the management of a public database of national significance, which forms the basis for information flows among the various operators in the energy market and for the various processes necessary for the functioning, throughout the territory, of the entire relevant sector. Finally, it is considered that the conditions set forth in Art. 17 of the Data Protection Authority’s Regulation No. 1/2019 are met. GIVEN THE FOREGOING, THE DATA PROTECTION AUTHORITY a) pursuant to Articles 57(1)(a) and (f) and 83 of the Regulation, finds that the processing carried out by Acquirente Unico S.p.A., with headquarters in Rome, VAT No. 05877611003, as set forth in the reasoning, for violating Articles 12, 16, and 28 of the Regulation; b) pursuant to Article 58(2)(d) of the Regulation, orders the aforementioned company to comply, within 9 months from the date of notification of this decision, with the requirements set forth in para 6 of this decision, while at the same time requiring the company to provide, within the aforementioned deadline, an adequately documented response pursuant to Art 157 of the Code; failure to provide such a response may result in the imposition of the administrative fine provided for in Article 83, para 5, subparagraph e) of the Regulation; ORDERS pursuant to Article 58, para 2, subparagraph i) of the Regulation, Acquirente Unico S.p.A. is ordered to pay the sum of 90,000.00 euros (ninety thousand/00) as an administrative fine for the violations set forth in this order. THEREFORE ORDERS Acquirente Unico S.p.A. to pay the aforementioned sum of 90,000.00 euros (ninety thousand/00), in accordance with the procedures set forth in the attachment, within thirty days of the service of this order, failing which the necessary enforcement measures will be taken pursuant to Art. 27 of Law No. 689/1981. It is noted that, pursuant to Article 166, paragraph 8 of the Code, the offender retains the right to settle the dispute by paying —always in accordance with the procedures set forth in the attachment—of an amount equal to half of the penalty imposed within the time limit specified in Art. 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, provided for the filing of an appeal as indicated below. ORDERS - pursuant to Article 17 of the Data Protection Authority’s Regulation No. 1/2019, that the violations and the measures adopted in accordance with Article 58, para 2, of the Regulation be recorded in the Authority’s internal register provided for in Article 57, para 1, letter u), of the Regulation; - pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Data Protection Authority’s Regulation No. 1/2019, the publication of this order on the Authority’s website; - Pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, the publication of the injunction order on the Data Protection Authority’s website. Pursuant to Article 78 of the Regulation, as well as Article 152 of the Code and Article 10 of Legislative Decree No. 150/2011, an appeal against this order may be filed with the ordinary courts by submitting a petition to the ordinary court of the jurisdiction specified in Art 10, within thirty days from the date of notification of the order, or within sixty days if the appellant resides abroad. Rome, June 18, 2026 THE PRESIDENT Stanzione THE RAPPORTEUR Ghiglia THE SECRETARY GENERAL Montuori