# Garante per la protezione dei dati personali (Italy) - 485/2026

- Type: Enforcement
- Source: Garante per la protezione dei dati personali (Italy)
- Date: 2026-03-07
- Original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_485/2026
- Canonical: https://overview.legal/posts/353642

## Summary

Facts — The DPA received several complaints from data subjects concerning Cerved Group S.p.A. (the controller) an Italian credit rating agency. The controller was processing the personal data of data subjects for the purpose of verifying the creditworthiness of potential customers of two energy suppliers. As a result of the risk profiles attributed to them, data subjects were declined the supply of energy. When data subjects requested access to their data from the controller under Article 15 GDPR, they were informed that their databases did not contain negative information or adverse events justifying the denial of energy supply. The DPA conducted an investigation, and found that the controller provided different responses to different data subjects depending on whether their personal data had been recorded in their system. For data subjects where there was no negative information on them the controller claimed that no personal data processing had been conducted for commercial information purposes. Nevertheless, a score based on their residential address, age and place of birth was generated. For those data subjects where information was present on their databases the controller provided them with the personal data which was present. The DPA further found that the controller did not provide reference to the scores and sub-scores assigned by the controller to the data subjects. Holding — The DPA held that in light of the controller inadequately responding to data subjects requests, which prevented them from accessing all the information processed for the purpose of calculating their risk profile, and to understand how the score was used in the decisions of the energy suppliers, data subjects were effectively prevented from exercising their rights. Particularly, the DPA held that the controller did not provide data subjects with all the necessary information, such as certain scores, and the logic and criteria used to calculate the scores, which prevented them from determining the lawfulness, fairness and accuracy of the data. This undermined their ability to exercise their right to rectification pursuant to Article 16 GDPR, and right to obtain human intervention, express their opinion and challenge the decision made, pursuant to Article 22(3) GDPR. In connection with sensitive nature of the information processed by the controller (residential address, age and place of birth) which relates to a data subjects creditworthiness with potentially prejudicial consequences, the controller was found in violation of Article 5(1)(a) GDPR, Article 12 GDPR and Article 15 GDPR. The DPA imposed a €400,000 fine on the controller pursuant to Article 83 GDPR taking into account, inter alia, the fact that this affected 2.094 data subjects. The DPA further ordered the controller to establish a procedure allowing data subjects to exercise their right to rectification pursuant to Article 16 GDPR.

## Full text

[Web Doc. No. 10273976] Decision of July 3, 2026 Register of Decisions No. 485 of July 3, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, President; Prof. Ginevra Cerrina Feroni, Vice President; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter the “Regulation”); HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003 (Code on Data Protection, hereinafter the “Code”), as amended by Legislative Decree No. 101 of August 10, 2018, containing “Provisions for the alignment of national legislation with the provisions of Regulation (EU) 2016/679”; HAVING EXAMINED the documentation on file; HAVING CONSIDERED the observations made by the Secretary General pursuant to Art. 15 of the Data Protection Authority’s Regulation No. 1/2000; RAPPORTEUR: Dr. Agostino Ghiglia; WHEREAS 1. Introduction. This Authority has received several requests concerning the processing of personal data carried out by Cerved Group S.p.A. (hereinafter also “the Company”) for the purpose of verifying the creditworthiness of potential customers of Hera Comm S.p.A. and EstEnergy S.p.A. Specifically, the complainants alleged that Hera Comm S.p.A. and EstEnergy S.p.A. refused to supply energy to them on the basis of a risk profile of the data subjects that allegedly emerged, following checks carried out by the aforementioned Companies, including through the use of commercial information services (operated by Cerved Group S.p.A.) and the consultation of credit information systems (operated by Experian Italia S.p.A.). This risk profile is generated within the Hera Group using software provided by Major 1 S.r.l., called “CGS-X.” This software allows the aforementioned energy suppliers to develop a risk profile regarding the creditworthiness of potential customers, based on an integrated indicator called the “Integrated Utilities Score” (hereinafter also referred to as the “CGS-X Score”). The latter is the result of combining two assessment indicators: one called “ESX Score” (provided by Experian Italia S.p.A.) and one called “Retail Utilities Score” (provided by Cerved Group S.p.A.). In this regard, the petitioners pointed out that, although the refusal to supply energy was the result of their being assigned a composite score indicating low creditworthiness—derived from a search of the databases managed by Cerved Group S.p.A. and Experian Italia S.p.A., these companies—which were specifically questioned on this point through requests for access pursuant to Art 15 of the Regulation—had stated that their systems contained no negative information and/or adverse events concerning the aforementioned data subjects that would justify a negative assessment. With regard to the foregoing, it should be noted that the Authority, in view of the numerous requests received, first decided to consolidate the individual proceedings referred to above in order to conduct a comprehensive examination of the underlying issues and subsequently initiated, on its own initiative, pursuant to Article 21 of the Data Protection Authority’s Regulation No. 1/2019, an investigation aimed at assessing, as a whole, the methods and processing purposes carried out by Cerved Group S.p.A. in connection with the service provided by Major 1 S.r.l. and known as “CGS-X.” In this regard, several on-site inspections were conducted at Hera S.p.A. on March 18, 19, and 20, 2024; at Major 1 S.r.l., on April 15 and 16, 2024; at Cerved Group S.p.A. on April 16, 2024; and at Experian Italia S.p.A. on June 13 and 14, 2024. Subsequently, given the particular complexity of the investigation and in order to gather further information regarding the processing of the aforementioned data, additional on-site inspections were conducted at Major 1 S.r.l., on October 15 and 16, 2024, and at Cerved Group S.p.A., on October 16, 2024. 2. The Preliminary Investigation. The preliminary investigation concerning Cerved Group S.p.A. took into account not only the findings of the aforementioned inspections but also additional information provided in the supplementary documentation submitted by the Company, on May 10 and October 31, 2024, to address the reservations raised during the on-site inspections, as well as the communication dated April 4, 2025, received in response to the Authority’s request for information dated March 7, 2025. As part of the investigation, with regard to the issues highlighted in the introduction, the following findings emerged. 2.1. The results of the on-site inspections. The “CGS-X” software is distributed “based on a contractual package that requires the customer [i.e., the energy supplier] to sign three separate contractual documents with Cerved Group S.p.A., Experian Italia S.p.A., and Major 1 S.r.l.” (see Major 1 S.r.l.’s statement of April 15, 2024, p. 3). Once enrolled in the service, the energy supplier enters the data of its potential customers into the “CGS-X” software, acting as an independent controller and, at the same time, appointing Major 1 S.r.l. as the processor, pursuant to Art. 28 of the Regulation. The latter acts as a technology service provider, supplying the license to use the “CGS-X” software and, in this context, in response to a query made by the energy provider, consults the commercial information systems managed by Cerved Group S.p.A. and credit information systems, which are managed by Experian Italia S.p.A. According to the findings of the inspection at Major 1 S.r.l., “access to the information systems of Cerved and Experian is carried out by Major 1 S.r.l., in the name and on behalf of the client [energy supplier] (..) and constitutes a transfer of data between independent controllers of processing (between Experian/Cerved and the client)” (see Major 1 S.r.l. inspection report dated April 15, 2024, p. 3). From an operational standpoint, “the operation of the aforementioned software requires that the client [energy provider] perform a query (..) with a specific call based on the tax ID number [of the data subject]” (see minutes of Major 1 S.r.l. dated April 15, 2024, p. 2). The system “queries the information systems of Cerved and Experian using those same tax identification numbers,” retrieving the “Retail Utilities Score” from Cerved Group S.p.A. and the “ESX Score” from Experian Italia S.p.A., along with the related sub-scores (see minutes of Major 1 S.r.l. dated April 15, 2024, p. 3). This information “is processed by Major 1’s software in order to obtain (..), in response to the aforementioned queries, (..) an integrated score (known as the CGS-X Score) relating to the assessment of the data subjects’ ‘reliability’; a score that is the result of combining, (..), the scores obtained from the Experian (SIC) and Cerved (commercial information) databases” (see minutes of Major 1 S.r.l. dated April 15, 2024, pp. 2–3). More specifically, with regard to the processing carried out by Cerved Group S.p.A. for the purpose of calculating the “Retail Utilities Score,” it was verified that the latter consists of the following items, all of which are present in the XML schema: ‒ “Information on adverse events”: [OMISSIS]” (see minutes of Major 1 S.r.l. dated April 16, 2024, p. 3); ‒ “Score class”: “score [OMISSIS]” (see minutes of Major 1 S.r.l. dated April 16, 2024, p. 3); ‒ “Score class before override”: a tool “for control and reclassification in determining the class, [OMISSIS]” (see minutes of Major 1 S.r.l. dated April 16, 2024, p. 3; see also note from Major 1 S.r.l. dated May 10, 2024, p. 1). In turn, the “Retail Utilities Score” is “the result of processing various sub-scores, which are also present in the XML file.” These are the following items: ‒ “Sub-score [OMISSIS]”: “a risk score concerning only natural persons, based on the personal information of the data subject (specifically, residence/place of birth and age) [OMISSIS]” (see minutes of Major 1 S.r.l. dated April 16, 2024, p. 3); ‒ “Sub-score [OMISSIS]” (see minutes of Major 1 S.r.l. dated April 16, 2024, p. 3); ‒ “Sub-score [OMISSIS]”: this is “a value reflecting the risk level of the data subject’s area of residence [OMISSIS]” (see minutes of Major 1 S.r.l. dated April 16, 2024, pp. 3–4); ‒ “Sub-score P4”: “score [OMISSIS]” (see minutes of Major 1 S.r.l. dated April 16, 2024, p. 4). With regard to the requests submitted by the data subjects pursuant to Article 15 of the Regulation, the Company provided different responses depending on whether their personal information was recorded (or not) in its systems. In particular, Cerved Group S.p.A. clarified that “where no Cerved customer has ever submitted a request on behalf of [the aforementioned data subjects] or where no data [relating to them] has ever been collected from the sources used by Cerved to provide commercial information services,” there is no record in its database (see the Company’s minutes of October 16, 2024, p. 3). In such cases (see responses provided: on August 5, 2022, to Mr. XX; on March 25, 2024, to Mr. XX; on September 19, 2023, to Mr. XX; on May 21, 2024, to Mr. XX), the Company therefore responded to the requests for access pursuant to Article 15 of the Regulation, stating that there was no negative information regarding these individuals in its systems and that, likewise, no processing of personal data concerning them had been carried out for commercial information purposes. Nevertheless, a “Retail Utilities Score” had been generated for them, a result based primarily on the degree of risk associated with the data subject in relation to their residential address (so-called Sub-score [OMISSIS]), as well as their age and place of birth (so-called Sub-score [OMISSIS]). In other cases (see responses provided: on October 4, 2022, to Mr. XX, and on May 31, 2023, to Ms. XX), where personal information pertaining to the applicant had been identified, the Company sent the applicant an informational report containing the personal data present in the Cerved Group S.p.A. database (e.g., management positions and/or qualifications; equity interests in companies; etc.). The aforementioned document also included a score, [OMISSIS], corresponding to a risk profile of “zero—no adverse events.” It was also established that, in none of the cases subject to complaint, did the response provided by the Company include any references to the “Retail Utilities Score” or the related sub-scores assigned to the data subjects. All of this, even though it emerged that Cerved Group S.p.A.’s systems contained records of queries made by Major 1 S.r.l. regarding the tax identification numbers of all complainants, including those listed above for whom a negative response had been provided, as well as the corresponding responses sent by Cerved Group S.p.A.’s systems, which contained the “Retail Utilities Score” and the related sub-scores pertaining to the latter (see the Company’s minutes of April 16, 2024, p. 2 and Attachment 2; see also the Company’s minutes of October 16, 2024, p. 4 and Annex 7). On this point, Cerved Group S.p.A. represented that the office responsible for responding to requests pursuant to Articles 15–22 of the Regulation (referred to as the “Complaints Office”), did not provide any information regarding the aforementioned scores because it “had no technical means to independently and directly verify whether, with respect to a specific data subject, the aforementioned information was available”; all this despite the fact that such information had been “previously compiled in response to requests from authorized clients” (see the Company’s note of May 10, 2024, pp. 2 and 3). It also pointed out that such “information is not normally included in the informational documents made available to the majority of customers (..) since it may also change even within short time frames” (see the Company’s note dated May 10, 2024, pp. 2 and 3). Therefore, with regard to the requests for access submitted, it emerged that—as expressly stated by the Company—Cerved Group S.p.A. responded to the data subjects “without including, for the reasons outlined above, data concerning the value of the Retail Utilities Score and the related sub-scores, since the Office was not immediately able to directly access this additional information, which had been specifically processed and sent” to the requesting energy suppliers (see the Company’s note dated May 10, 2024, p. 3). 2.2. Measures Adopted by the Company Following the Inspection Findings. Following the Office’s findings, Cerved Group S.p.A. implemented—initially on a provisional basis, starting in May 2024, and definitively as of August 2024—– measures designed to enable the Complaints Office, “in the event of access requests to exercise the right of access to personal data, to immediately and directly verify the presence of personal data relating also to the ‘Retail Utilities Score’ and related sub-scores, where processed and sent to customers (…) and to communicate such data to the data subjects through a representation that makes it easily understandable, with a concise explanation of the criteria and [the] logic behind the processing” (Company note dated May 10, 2024, p. 3; see also Annex 1 to the Company note dated October 31, 2024). All of this shall be achieved through: - the adoption of a system capable of “tracking the existence, under a specific record, of a query submitted to Cerved [by Major S.r.l.], including in response to requests for information made by customers [energy suppliers] regarding the use of the CGS-X software” (see Company minutes of October 16, 2024, p. 4); - the implementation of a “tool for use by the team dedicated to responding to requests for the exercise of rights, designed to allow the team to interface with the system (..) containing the logs regarding the queries made by Major1 (..) and received from Cerved, regarding the customer’s use of the CGS-X software” (see Company minutes of October 16, 2024, p. 4). The Company “therefore created a dashboard, available to the Complaints Office, through which, using specific filters (..), the queries related to the “Retail Utilities Score,” made by Major 1 on behalf of customers using the CGS-X software. (..) In this way, it is possible to provide a comprehensive response to the data subject, which also takes into account, in a relatively short time, the assessments (“Retail Utilities Score” and related sub-scores) pertaining to the data subjects” (see Company minutes of October 16, 2024, p. 4 and Annex 1 of the Company’s note dated October 31, 2024). At the same time, the Company has prepared a new template for responding to requests under Article 15 of the Regulation from data subjects, which is processed within the “CGS-X” software, aimed at enabling them to “better understand the key elements used to calculate the Retail Utilities Score” (see the Company’s minutes of October 16, 2024, p. 3). In this regard, it was determined that, pending the final adoption of the new response procedures, the Company nevertheless sent an interim response to certain complainants (specifically, to Ms. XX on August 5, 2024, and to Ms. XX, on September 23, 2024) an interim response containing preliminary information regarding the data provided by Cerved Group S.p.A. to Hera Comm S.p.A. as part of the services rendered to the latter (see Annex 2 to the Company’s minutes of October 16, 2024; see the Company’s note of April 4, 2025, p. 1). All of this is subject to conducting “the specific technical investigations necessary to verify the existence of additional (..) personal data transmitted to [aforementioned] Hera,” in order to provide a definitive response (see Attachment 2 to the Company’s minutes of October 16, 2024; see the Company’s note of April 4, 2025, p. 1). Effective October 15, 2024, the system described above became fully operational, and Cerved Group S.p.A. provided the petitioners with a response based on the newly adopted model (see the Company’s note dated October 31, 2024, and the Company’s note dated April 4, 2025, p. 1). More specifically, with regard to this latest new model (see Attachments Nos. 1, 4.2, and 5.2 of the Company’s note dated October 31, 2024; see Attachments Nos. 3a, 3b_1, 3b_2, 3b_3, and 4 of the Company’s notice dated April 4, 2025), it emerged that the data controller, with respect to the requests submitted by Messrs. XX, XX, XX, XX, XX, XX, and XX, had nevertheless provided an incomplete response, as it lacked the sub-scores labeled “Sub-score [OMISSIS]” and “Sub-score [OMISSIS],” as well as any explanation regarding the logic underlying their determination. Finally, it was found that the Company, during the period from May 2022 to October 2024, received “approximately 50 requests to exercise the rights [pursuant to Articles 15–22 of the Regulation] per month from Hera Comm/EstEnergy customers” for a total of 2,094 requests (see the Company’s minutes of October 16, 2024, p. 4 and Annex 6). 3. The notification pursuant to Article 166, paragraph 5, of the Code. Following the allegation of violations under Articles 5(1)(a), 12, and 15 of the Regulation, sent to Cerved Group S.p.A. by notice dated July 16, 2025, the Company, by letter dated September 15, 2025, submitted its defense briefs, which were further supplemented during the hearing on May 11, 2026, as well as through a communication dated May 25, 2026. In the aforementioned briefs, the Company made the following representations: - regarding the allegation concerning the inadequacy of the response provided by Cerved Group S.p.A. to the data subjects, in that it lacked information regarding the “Retail Utilities Score,” the additional sub-scores, as well as the logic and criteria applied to the calculation system, the aforementioned “Retail Utilities Score,” as processed and transmitted by Cerved, does not constitute, (..) an independent automated decision-making process,” pursuant to Art. 22 of the Regulation. Rather, it is “a mere partial indicator of customer reliability (...) made available to clients of third parties—such as, in the case at hand, Hera Comm S.p.A. and EstEnergy S.p.A.—so that they may use it with full autonomy and in accordance with their own internal assessment and decision-making criteria.” More specifically, the Company believes it has fulfilled all disclosure obligations toward data subjects. On the one hand, in fact, “the provision of the ‘Retail Utilities Score’ constitutes, in and of itself, a correct and sufficient representation of the assessment result and the criteria underlying the calculation, without any further obligation to provide the sub-scores.” This is taking into account that the sub-scores “cannot be classified as additional information independent of the ‘Retail Utilities Score,’ but rather represent the internal structure of the assessment system, (..) which enables the determination of the ‘Retail Utilities Score.’” Furthermore, “Cerved was in no way obligated to provide clarifications regarding the internal logic and decision-making criteria adopted by the energy suppliers,” given that the latter are the “only parties who have effectively assumed—with full evaluative and discretionary autonomy—the decision regarding whether or not to activate the supply” (see the Company’s note dated September 15, 2025, pp. 4–5; see also the minutes of the hearing on May 11, 2026, pp. 1–2); - with specific reference to the complaint filed by Mr. XX on July 15, 2024, it notes a procedural issue in that the Authority did not issue, to the account holder, an invitation to exercise the right to notify the complainant and the Office of any voluntary compliance, as provided for in Article 15, paragraph 1, of the Data Protection Authority’s Internal Regulations No. 1/2019; all of this “despite the fact that the complaint concerned exclusively the exercise of the right of access with respect to the Company” (see note of September 15, 2025, p. 3); - regarding the number of data subjects affected by the breach, this figure does not correspond to the “2,094 data subjects who submitted requests to Cerved during the period from May 2022 to October 2024,” as indicated in the notice of initiation pursuant to Article 166, paragraph 5, of the Code, but must be attributed “exclusively to the 8 individuals whose requests formed the basis of the proceedings” (see note dated September 15, 2025, pp. 2 and 6; see also the minutes of the hearing of May 11, 2026, p. 3). Furthermore, with regard to the factors to be taken into account for the purpose of determining the amount of any penalty—among those identified in Art. 83(2) of the Regulation—the Company stated that, with respect to the revenue relevant to the case at hand, “over the past three fiscal years, Cerved’s provision of the Retail Utilities Score as part of the broader service known as ‘CGS-X’ has had only a marginal impact on Cerved’s revenue” (see the Company’s note dated September 15, September 2025, p. 9; see supplementary note of 25 May 2026). The Company also emphasized the significant efforts it has made, following the initiation of proceedings by the Data Protection Authority, to further bring its activities into compliance with data protection regulations. To this end, beginning in September 2025, it drafted an additional template for responding to requests for access pursuant to Article 15 of the Regulation “which includes the sub-scores named ‘Sub-score [OMISSIS]’ and ‘Sub-score [OMISSIS]’, and [provides] further guidance regarding the logic underlying their definition.” The latter was sent to the data subjects “to further supplement what had already been communicated previously” (see the Company’s note of September 15, 2025, p. 8; see also the minutes of the hearing of May 11, 2026, p. 3). Finally, Cerved Group S.p.A. emphasized, pursuant to and for the purposes of Article 166, paragraph 7, of the Code, that it has “consistently produced and disseminated, through its corporate website (in the ‘News & Educational’ Section), numerous articles aimed at informing users and raising their awareness of the risks associated with the processing of personal data and digital threats” (see the Company’s note dated September 15, 2025, p. 9). 4. The Authority’s Assessments. First of all, it should be noted that, unless the act constitutes a more serious offense, anyone who, in proceedings before the Data Protection Authority, falsely declares or attests to facts or circumstances, or produces false documents or records, shall be liable pursuant to Art. 168 of the Code, “False statements to the Data Protection Authority and obstruction of the Authority’s duties or exercise of its powers.” In light of the evidence gathered during the preliminary investigation described above, it has been established that Cerved Group S.p.A. provided inadequate and incomplete responses to the requests submitted by data subjects to exercise their rights under Articles 15–22 of the Regulation. This pertains specifically to the processing of personal data carried out by Cerved Group S.p.A. for the purpose of providing the “CGS-X” service. Having duly stated the foregoing, it should be noted at the outset that, for the purposes of addressing the issues covered by this decision, it is necessary to take into account the specific context underlying the processing activities carried out in the cases at hand. 4.1. The processing of personal data for commercial information purposes and Judgement C-634/21 of the Court of Justice of the European Union of December 7, 2023. In its judgement of December 7, 2023, in Case No. C-634/21, the Court of Justice of the European Union (hereinafter “the Court”) ruled on the interpretation of Article 22 of the Regulation, with regard to the processing of personal data for commercial information purposes. In that judgment, the Court clarified that the applicability of the aforementioned provision is subject to the fulfillment of three cumulative conditions related to the existence of a “decision,” that such a decision is “based solely on automated processing, including profiling,” and that it produces “legal effects [concerning the data subject],” or “significantly affects the data subject in a similar manner” (see para. 43, CJEU Judgement, C-634/21, cited above). The Court observed, in particular, that the concept of “decision,” within the meaning of Article 22(1) of the Regulation, may encompass various acts, including those which, although they do not have direct legal effects on the data subject, nonetheless have a significant and analogous impact on the data subject (see, to that effect, also Recital 71 of the Regulation). That concept, therefore, is “broad enough to encompass the result of calculating a person’s creditworthiness in the form of a probability ratio relating to that person’s ability to meet future payment obligations.” This applies even where the result—as may be the case here—is produced by a company that provides commercial information to third parties (see para. 46, CJEU judgement, C-634/21, cited above). With regard to the additional conditions set forth in Art. 22 of the Regulation, the Court found that they were met in the specific context at hand. The ruling clarified, first of all, that the aforementioned decision is based exclusively on an automated calculation derived from the processing of the data subject’s personal data concerning the data subject’s reliability in terms of timely payments. Second, the Court noted that the result of that calculation—in the form of a probability rate—significantly affects the individual, preventing them from accessing the requested service, such as the energy supply at issue in the present case. On this point, the Court itself clarified that, in the aforementioned context, “the action of the third party to whom the probability rate is transmitted is guided ‘decisively’ by that rate” (see para. 48, CJEU judgement, C-634/21, cited above), as has become evident during the present proceedings with respect to the decisions made by Hera Comm S.p.A. and EstEnergy S.p.A. This interpretation is consistent with the rationale underlying Article 22 of the Regulation, which aims to ensure the protection of individuals’ fundamental rights and freedoms against the specific risks arising from the automated processing of personal data, including profiling (see para. 51, CJEU Judgement, C-634/21, cited above). Moreover, a restrictive interpretation of the aforementioned provision would undermine the safeguards for the data subject provided for by the Regulation, as the data subject would be unable to assert, against commercial information companies, their right of access to data concerning them, as established by Art 15(1)(h) of the Regulation (see paragraphs 61–63, Judgement of the CJEU, C-634/21, cited above). In conclusion, according to the Court, “Article 22(1) of the Regulation must be interpreted as meaning that the automated calculation, by a business information provider, of a probability score based on personal data relating to an individual and concerning that individual’s ability to meet payment obligations in the future constitutes an ‘automated individual decision-making process’ within the meaning of that provision, where the conclusion, the performance, or the termination of a contractual relationship with that individual by a third party to whom that probability score is communicated” (see para. 73, CJEU Judgement, C-634/21, cited above). It follows, therefore, that—contrary to the Company’s contention (see supra, para. 3(a) of this decision)—the processing operations carried out by Cerved Group S.p.A. in the cases at issue in this decision fall within the scope of the aforementioned judgement and, therefore, Articles 15(1)(h) and 22 of the Regulation apply to them, as explained in greater detail below (see paragraphs 4.2. and 4.3. of this decision). Finally, it should be noted that the proceedings in question concerned solely the measures adopted by Cerved Group S.p.A. to ensure proper compliance with the obligations set forth in Article 15 et seq. of the Regulation regarding the exercise of rights; all of this in light of the specific instances of non-compliance that emerged during the investigation initiated by the Authority following the submission of the requests indicated in the preamble. With regard, however, to the broader issue concerning the conditions for the lawfulness, pursuant to Article 22, para 2 of the Regulation, of the processing of the data subject’s personal data carried out by providers of commercial information services, as well as the safeguards that the controller is required to implement pursuant to Article 22, paragraphs 3 and 4 of the Regulation, the Authority reserves the right to take any appropriate action necessary to verify the existence of the aforementioned conditions (see, on this subject, also the Authority’s statement of September 11, 2025, during the hearing of the President of the Data Protection Authority regarding “Draft Law AS 1578 establishing the Annual Market and Competition Law for 2025,” web doc. no. 10166076). 4.2. Violations concerning the exercise of the right of access under Article 15 of the Regulation. First and foremost, following the preliminary investigation, it became evident that the responses provided by Cerved Group S.p.A. to requests by data subjects to exercise their rights under Articles 15–22 of the Regulation—aimed at obtaining information regarding the “Retail Utilities Score”—were inadequate. In its responses, the Company merely confirmed the presence (or absence) of the data subjects’ records in its systems and, where present, disclosed the personal data stored therein; however, without providing any indication regarding the score associated with the creditworthiness profile developed by the Company and made available to energy suppliers, nor the criteria on which that profile was based. Similarly, in these responses, no information was provided to the data subjects regarding the logic used to develop the aforementioned profile. All of this, even though the information in question was—as ascertained during the on-site inspections—still present in Cerved Group S.p.A.’s systems as of the date of receipt of the aforementioned requests (see above, para 2.1 of this decision). On this point, it is worth noting that the right of access under Article 15 of the Regulation is primarily conceived as a tool designed to allow, in general terms, the data subject to exercise “control” over their personal data and over its use by data controllers, ensuring that the individual to whom the data relates is fully aware of the information being processed and the actual methods of such processing; in accordance with the general provisions of the principle of lawfulness, fairness, and transparency (Art 5(1)(a) of the Regulation). The purpose of the right of access is therefore primarily to disclose “what” data and “how” it has been processed by the controller, in order to provide the data subject with the means to “know and verify the lawfulness and accuracy of the processing” concerning them (see Recital 63 of the Regulation; European Data Protection Board, “Guidelines 1/2022 on the Rights of Data Subjects—Right of Access,” adopted on March 28, 2023, paragraphs 10–13). Pursuant to Article 15 of the Regulation, therefore, the data controller, when responding to a request for access, may not limit itself to providing “a general description of the data [or] a mere reference to the categories of data processed,” nor may it omit information in its possession that relates to the data subject; on the contrary, the data controller is required to provide the data subject with access to “all the information referred to in Article 15” that is actually being processed. Such information, therefore, “must be complete, accurate, and up-to-date, reflecting as closely as possible the status of the data processing at the time the request was received” and must be provided “in a concise, transparent, intelligible, and easily accessible form” to the data subject (see European Data Protection Board, “Guidelines 1/2022,” op. cit., para. 34; Art. 12, para. 1 of the Regulation). It should also be noted that, in the case at hand, the specific context underlying the requests to exercise the right of access submitted by the data subjects requires particular attention on the part of the controller, including with regard to the obligation to provide “meaningful information on the logic used, as well as [on] the significance and [the] expected consequences of such processing for the data subject” (Article 15, para 1, subparagraph (h) of the Regulation). With regard to the aforementioned provision, the Court of Justice of the European Union has recently provided useful practical guidance—both substantively, regarding the type of information that the data subject may require from the controller, and formally, regarding the manner in which such information must be provided by the controller (see CJEU judgement of February 27, 2025, C-203/22). In particular, in clarifying the phrase “meaningful information on the logic used,” the Court specified that this refers to “any relevant information concerning the procedure and principles for the automated processing of personal data in order to achieve a specific result” (see para. 58, CJEU judgement, C-203/22, cit.). It follows, therefore, that the data subjects, in the case at hand, have the right to full knowledge of all the elements comprising the assessment of their creditworthiness, including those taken into account by the data controller for the purpose of assigning the score, as well as the calculation criteria used for that purpose (see, in this regard, Order of the Court of Cassation, Section I, No. 14381 of May 25, 2021). With regard, however, to the manner in which the aforementioned information must be provided, the Court of Justice of the European Union has reaffirmed the data controller’s obligation to provide it “in a concise, transparent, intelligible, and easily accessible form, using plain and clear language”; all in compliance with the principle of transparency set forth in Articles 5(1)(a) and 12(1) of the Regulation. Therefore, “neither the mere communication of a complex mathematical formula, such as an algorithm, nor a detailed description of all the stages of automated decision-making can satisfy these requirements, since neither of these methods would constitute a sufficiently concise and comprehensible explanation” (paragraphs 58–59, CJEU judgement, C-203/22, cited above). Overall, the requirement to provide “meaningful information on the logic used,” pursuant to Article 15(1)(h) of the Regulation, thus amounts to an obligation on the part of the controller to “describe the procedure and the principles actually applied in such a way that the data subject can understand which of [his or her] personal data have been used and how (...), without the complexity of the operations to be carried out in the context of the automated decision-making process exempting the controller from its duty to explain” (para. 61, CJEU judgement, C-203/22, cited above). In light of the foregoing, it follows that Cerved Group S.p.A., in the cases at hand, acted in violation of Articles 5(1)(a), para 1, 12, and 15 of the Regulation, recital 12, given that it did not provide the data subjects with any information regarding the “Retail Utilities Score” or the additional sub-scores that contributed to generating that score. Furthermore, the Company did not inform the petitioners regarding the logic and criteria applied to the calculation system underlying the development of the credit risk profile. 4.3. The feedback form pursuant to Article 15 of the Regulation, prepared following the preliminary investigation, and additional profiles. It is worth noting that the aforementioned violations also persist with regard to the feedback form that Cerved Group S.p.A. prepared (and sent to the data subjects concerned), effective October 15, 2024 (see above, para. 2.2.); this was done to provide them with more information enabling them “to better understand the essential elements used to calculate” the aforementioned score (see the Company’s minutes of October 16, 2024, p. 3). The preliminary investigation revealed that, with respect to the requests made in the cases under dispute, the Company provided—even based on the updated template—a response that was nonetheless incomplete, as it lacked the sub-scores labeled “Sub-score [OMISSIS]” and “Sub-score [OMISSIS],” as well as guidance regarding the rationale underlying their determination (see Attachments Nos. 1, 4.2, and 5.2 of the Company’s letter dated October 31, 2024; see Attachments Nos. 3a, 3b_1, 3b_2, 3b_3, and 4 to the Company’s letter dated April 4, 2025). These are sub-scores which, as already noted in para 2.1 of this decision, refer to a level of risk that varies, depending on the data subject’s age and in relation to their place of birth and residence, and regarding which no information has been provided—with reference to specific individual cases—concerning the “actual weight” of these variables in the calculation of the “Retail Utilities Score.” It follows, therefore, that even the use of the new model adopted by Cerved Group S.p.A., starting in September 2025, is capable of ensuring that data subjects’ right of access, as provided for in Articles 12 and 15 of the Regulation, is effectively satisfied with respect to the specific processing operations in question. Finally, regarding the specific objection raised by the Company concerning the procedural issue related to how the complaint filed by Mr. XX was handled (see supra, para. 3, subpar. b) of this decision), it should be noted that, in the present case, the provision requiring that the invitation to respond be forwarded to the data controller (see Article 15, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019) could not be applied. This is because, at the time the complaint was received, the Authority did not have the information pertaining to the specific processing in question and, therefore, could not determine that the response provided to the data subject by Cerved Group S.p.A. on May 21, 2024, was inadequate (see para 2.1 of this decision). Indeed, it was only after the investigation was initiated—once the Authority had gained a clear understanding of the characteristics and methods of the processing carried out for the purpose of calculating the “Retail Utilities Score”— was the Authority able to determine that the aforementioned response was inadequate and that the Company was under an obligation to comply with the complainant’s requests. 4.4. Concluding Assessments. As a result of the findings in the preceding paragraphs, it is clear that the inadequacy of the responses provided by the Company as a whole effectively prevented the data subjects who exercised their rights under the Regulation from accessing all the personal information actually processed for the purpose of calculating their risk profile, as well as to adequately understand how that profile was used for the purposes of the decisions made by Hera Comm S.p.A. and EstEnergy S.p.A. regarding them, which led to the denial of energy supply. This effectively prevented them from ascertaining the lawfulness and fairness of the processing, as well as the accuracy of the data used in the context at hand, thereby impairing their ability to exercise, where applicable, the right to rectification, in the event of inaccurate and/or incomplete data (see Article 16 of the Regulation) and, at the same time, the right to “obtain human intervention by the controller, [to] express their opinion and contest the decision” taken by the controller with respect to them (see Art. 22(3) of the Regulation). This risk arises, in particular, in the event that, even though there are “no personal records in the (..) [Company’s] database,” as established during the preliminary investigation, the data subject in question was nonetheless assigned a “Retail Utilities Score” based primarily on the degree of unreliability associated with that data subject, in relation to their residential address—the so-called Sub-score [OMISSIS], as well as on the individual’s age and place of birth, known as Sub-score [OMISSIS] (see paragraph 2.1. of this decision). All of this—given the particularly sensitive nature of the information processed by Cerved Group S.p.A. in the case at hand, as it pertains to customer creditworthiness—could have prejudicial consequences on the fundamental rights and freedoms of the data subjects (such as, for example, as occurred in the cases under review, the refusal to sign an energy supply contract). For the reasons outlined above, it is therefore determined that Cerved Group S.p.A. has violated Articles 5(1)(a), 12, and 15 of the Regulation. Finally, it is noted that the aforementioned unlawful conduct—during the period from May 2022 to October 2024—affected approximately 2,094 data subjects (see para 2.2 of this decision). In this regard, the Company’s argument—that the relevant figure in the case at hand is not 2,094 but “exclusively [that relating to] the 8 individuals whose complaints formed the basis of the proceeding”—cannot be accepted (see, supra, para 3, subparagraph c) of this decision). On this point, it is worth noting that, contrary to the Company’s assertion (see minutes of the hearing of May 11, 2026, p. 3), the scope of the proceedings in question cannot be limited exclusively to the cases of the eight data subjects who filed reports and/or complaints with the Authority. This is because the Data Protection Authority, in the exercise of its supervisory duties—and also considering the large number of requests received by the Authority at various times—has identified the need to initiate, pursuant to Art. 21 of the Data Protection Authority’s Regulation No. 1/2019, a general investigation aimed at assessing, as a whole, the methods and processing purposes carried out by Cerved Group S.p.A. in connection with the service provided by Major 1 S.r.l. and known as “CGS-X.” It should also be noted that the Company’s assertions on this point have not been substantiated in any way by Cerved Group S.p.A. through the submission of adequate supporting documentation. In order to determine the number of data subjects involved in these proceedings, the findings from the investigations conducted on October 16, 2024, must therefore be taken into account. On that occasion, the Company presented a chart showing the number of requests regarding the exercise of rights submitted by customers of Hera Comm S.p.A. and EstEnergy S.p.A. in the years 2022, 2023, and 2024, which clearly indicates the figure mentioned above, namely 2,094 (see minutes of October 16, 2024, p. 4 and related Annex No. 6). 5. Conclusions: Declaration of unlawful processing. Corrective measures pursuant to Art 58(2) of the Regulation. In light of the overall findings, the Authority considers that the statements, documentation, and explanations provided by the controller during the investigation do not sufficiently address the objections notified by the Office in thenotice initiating the proceedings and are therefore insufficient to warrant the dismissal of this proceeding, especially since none of the cases provided for in Art. 11 of the Data Protection Authority’s Regulation No. 1/2019 apply. The processing of personal data carried out by Cerved Group S.p.A., which is the subject of this decision, was therefore conducted in violation of Articles 5(1)(a), 12, and 15 of the Regulation. With regard to the exercise of the corrective powers referred to in Art. 58(2) of the Regulation, it is noted that Cerved Group S.p.A., during the proceedings, took initial steps to bring the processing of customer data into compliance with the Regulation, in accordance with the regulatory framework described above, as detailed in this decision (see above, paragraphs 2.2 and 3 of this decision). Particular reference is made to the adoption, in September 2025, of an additional new feedback form, pursuant to Art 15 of the Regulation, which includes the “Retail Utilities Score” and its related sub-scores and thus provides clearer guidance regarding the logic underlying their definition, as well as the implementation of the so-called Dashboard, a tool made available to the Company’s Complaints Office, with a view to enabling that office to provide a comprehensive response to the data subject within the terms set forth above. Notwithstanding the aforementioned actions already implemented by the Company, it is nonetheless deemed necessary, in light of the additional critical issues identified with respect to the controller, to order the controller to take a corrective measure pursuant to Article 58, para 2, subparagraph d), of the Regulation, with a view to safeguarding the data subject rights, freedoms, and legitimate interests of the data subject in accordance with Article 22, paragraph 3, of the Regulation. This measure consists of adopting a procedure designed to ensure that the data subject can fully exercise the right to rectification pursuant to Article 16 of the Regulation, in the event of the processing of inaccurate and/or incomplete data relating to the “Retail Utilities Score” assigned to the data subject. This applies, in particular, when the aforementioned score is primarily based on the degree of risk associated with the data subject, in relation to their residential address (so-called “Sub-score [OMISSIS]”), as well as their age and place of birth (so-called Sub-score [OMISSIS]). Finally, it should be noted that the violations, as established in the reasoning section, cannot in any way be considered “minor” within the meaning of Recital 148 of the Regulation; given the multiple violations alleged and the number of data subjects involved, as well as the additional factors explained in greater detail in paragraph 6 of this decision. 6. Injunction Order. The Data Protection Authority, pursuant to Art. 58, para 2, subparagraph (i) of the Regulation and Article 166 of the Code, has the power to impose an administrative fine as provided for in Article 83 of the Regulation, by issuing an injunction order (Article 18. Law No. 689 of November 24, 1981), in relation to the processing of personal data carried out by Cerved Group S.p.A., which has been found to be unlawful, as set forth herein. The violation of the provisions referred to above entails the application of the administrative fine provided for in Art. 83, para. 5, subparagraphs (a) and (b) of the Regulation. Having determined that paragraph 3 of Art 83 of the Regulation must be applied, insofar as it provides that “if, in relation to the same processing operation or to related processing operations, a controller […] infringes, intentionally or negligently, several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the most serious infringement,” the total amount of the fine is calculated so as not to exceed the maximum penalty provided for in Art. 83(5) of the Regulation. With regard to the factors listed in Article 83(2) of the Regulation for the purposes of imposing the administrative fine and determining its amount—taking into account that the fine must be “in each individual case effective, proportionate, and dissuasive” (Article 83(1) of the Regulation), it is noted that, in the case at hand, the following circumstances were taken into account: - the significant gravity of the violation (Articles 83(2)(a) and 83(para) of the Regulation), in relation to its nature (concerning non-compliance with provisions on transparency and data subject rights), the manner (the multiple instances of unlawful conduct repeated over time), and the duration of the violation (approximately 2.5 years). For this purpose, the characteristics and processing purposes are also taken into account, as well as the large number of data subjects involved and the nature of the harm they suffered. All of this, given that: the operations at issue were carried out for the purpose of developing a risk profile regarding the data subjects’ reliability in terms of timely payments, an activity that falls within the data controller’s core business; the unlawful conduct affected 2,094 data subjects; the established violations resulted, in most cases, to the detriment of the data subjects, in the refusal to enter into an energy and/or gas supply contract; - the negligent nature of the conduct and the data controller’s significant instance of accountability regarding the technical and organizational measures implemented (Articles 83, para 2, subparagraphs (b) and (d) of the Regulation). All of this, with particular regard to the lack and inadequacy of the measures and processes implemented by the Company concerning compliance with obligations related to the exercise of data subject rights, within the specific context in question. With regard to the subjective element, consideration is given to the fact that, concerning the processing activities carried out by Cerved Group S.p.A. and aimed at calculating the “Retail Utilities Score,” the company erroneously considered the provision of Art 22 of the Regulation to be inapplicable; - the fact that there are no previous relevant violations committed by the controller or previous measures referred to in Art Article 58 of the Regulation concerning the same matter (Article 83(2)(e) and (i) of the Regulation); - the adoption by the data controller of measures to mitigate or eliminate the consequences of the violation (Art. 83(2)(c) of the Regulation). In this regard, the fact that Cerved Group S.p.A. voluntarily took initial steps to mitigate the effects of the unlawful processing once it became aware of the violation should be viewed favorably; these measures, while only partially effective in reducing the risks, can nonetheless be considered reasonable; - the fact that the Company actively cooperated with the Authority during the proceedings (Article 83(2)(f) of the Regulation); - the nature of the information subject to the breach (Article 83(2)(g) of the Regulation), which, although not classified as special categories of data, is nonetheless considered sensitive as it reflects the reliability of customers’ timely payments; this also taking into account the potential economic and social consequences that may arise for the data subjects as a result of the unlawful processing of their data; - other mitigating factors (Article 83(2)(k) of the Regulation), such as, first and foremost, the Company’s implementation of communication campaigns aimed at promoting awareness of the right to personal data protection, carried out prior to the commission of the data breach through its institutional website, in the “News & Educational” section (see above, para 3 of this decision), as well as Cerved Group S.p.A.’s adherence to the “Code of Conduct for the Processing of Personal Data for Commercial Information Purposes,” approved by the Data Protection Authority pursuant to Art. 41 of the Regulation, by resolution dated April 29, 2021. It is further considered that, in the present case, the following factors are relevant in light of the aforementioned principles of effectiveness, proportionality, and deterrence to which the Authority must adhere in determining the amount of the sanction (Art. 83(1) of the Regulation): the economic circumstances of the offender, determined based on the Company’s turnover as reported in the financial statements for the year 2025 (as submitted by the Company in a letter dated May 25, 2026). In light of the above factors and the assessments made, it is deemed appropriate, in this case, to impose on Cerved Group S.p.A. an administrative penalty in the amount of 400,000.00 euros (four hundred thousand/00). In this context, it is also deemed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, this section containing the injunction order must be published on the Data Protection Authority’s website. This is in light of the specific nature of the data subject to the processing at issue—as it pertains to the data subject’s creditworthiness—as well as the nature of the violations found, which concerned the general principles of processing, in particular the principle of transparency and the obligations regarding the exercise of the data subject rights. Finally, it is considered that the conditions set forth in Art. 17 of the Data Protection Authority’s Regulation No. 1/2019 are met. GIVEN THE FOREGOING, THE DATA PROTECTION AUTHORITY a) declares, pursuant to Article 57(1)(f) of the Regulation, that the processing carried out by Cerved Group S.p.A., with its registered office in San Donato Milanese, VAT No. 08587760961, under the terms set forth in the reasoning, for the violation of Article 5(1)(a) and Articles 12 and 15 of the Regulation; b) orders, pursuant to Article 58(2)(d) of the Regulation, the aforementioned Company to comply, within six months from the date of service of this order, to the requirement set forth in para 5 of this decision, while at the same time requiring the company to provide, within the aforementioned period, an adequately documented response pursuant to Article 157 of the Code; failure to provide such a response may result in the imposition of the administrative fine provided for in Article 83, para 5, subparagraph (e) of the Regulation; ORDERS pursuant to Article 58, para 2, subparagraph (i) of the Regulation, that Cerved Group S.p.A. pay the sum of 400,000.00 (four hundred thousand/00) euros as an administrative fine for the violations set forth in this order; ORDERS pursuant to Article 58, para 2, subparagraph i) of the Regulation, that the aforementioned Company pay the aforementioned sum of 400,000.00 euros (four hundred thousand/00) as an administrative fine for the violations set forth in this order, in accordance with the procedures outlined in the attachment, within thirty days of the notification of this order, failing which the consequent enforcement measures will be adopted pursuant to Art. 27 of Law No. 689/1981. It is noted that, pursuant to Article 166, paragraph 8 of the Code, the offender retains the right to settle the dispute by paying an amount equal to half of the imposed fine within the time limit set forth in Article 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, set for filing an appeal as indicated below; ORDERS - pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, the publication of the injunction order on the Data Protection Authority’s website; - pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Authority’s Regulation No. 1/2019, the publication of this order on the Authority’s website; - Pursuant to Article 17 of the Data Protection Authority’s Regulation No. 1/2019, the recording of the violations and the measures adopted in accordance with Article 58(2) of the Regulation in the Authority’s internal register provided for by Article 57(1)(u) of the Regulation. Pursuant to Article 78 of Regulation (EU) 2016/679, as well as Articles 152 of the Code and 10 of Legislative Decree No. 150 of September 1, 2011, an appeal against this decision may be filed with the ordinary courts by submitting a petition to the ordinary court of the jurisdiction specified in the aforementioned Art 10, within thirty days from the date of notification of the decision, or within sixty days if the appellant resides abroad. Rome, July 3, 2026 THE PRESIDENT Stanzione THE RAPPORTEUR Ghiglia THE SECRETARY GENERAL Montuori [Web Doc. No. 10273976] Decision of July 3, 2026 Register of Decisions No. 485 of July 3, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair, Prof. Ginevra Cerrina Feroni, Vice Chair, Dr. Agostino Ghiglia, Member, and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter the “Regulation”); HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003 (Code on Data Protection, hereinafter the “Code”), as amended by Legislative Decree No. 101 of August 10, 2018, containing “Provisions for the alignment of national legislation with the provisions of Regulation (EU) 2016/679”; HAVING EXAMINED the documentation on file; HAVING CONSIDERED the observations made by the Secretary General pursuant to Art. 15 of the Data Protection Authority’s Regulation No. 1/2000; RAPPORTEUR: Dr. Agostino Ghiglia; WHEREAS 1. Introduction. This Authority has received several requests concerning the processing of personal data carried out by Cerved Group S.p.A. (hereinafter also referred to as the “Company”), for the purpose of verifying the creditworthiness of potential customers of Hera Comm S.p.A. and EstEnergy S.p.A. Specifically, the complainants alleged that Hera Comm S.p.A. and EstEnergy S.p.A. refused to supply energy to them based on a risk profile of the data subjects that allegedly emerged, following checks carried out by the aforementioned Companies, including through the use of commercial information services (operated by Cerved Group S.p.A.) and the consultation of credit information systems (operated by Experian Italia S.p.A.). This risk profile is developed within the Hera Group using software provided by Major 1 S.r.l., called “CGS-X.” This software enables the aforementioned energy suppliers to develop a risk profile regarding the creditworthiness of potential customers, based on an integrated indicator called “Integrated Utilities Score” (hereinafter also referred to as “CGS-X Score”). The latter is the result of combining two assessment indicators: one called “ESX Score” (provided by Experian Italia S.p.A.) and one called “Retail Utilities Score” (provided by Cerved Group S.p.A.). In this regard, the petitioners pointed out that, although the refusal to supply energy was the result of their having been assigned a composite score indicating low creditworthiness—derived from consultations of the databases managed by Cerved Group S.p.A. and Experian Italia S.p.A., these latter companies—specifically questioned on this point through requests for access pursuant to Art 15 of the Regulation—had declared that there was no negative information and/or prejudicial events within their systems concerning the aforementioned data subjects that would justify a negative assessment. With regard to the foregoing, it should be noted that the Authority, in light of the numerous requests received, first decided to consolidate the individual proceedings referred to above in order to conduct a comprehensive review of the underlying issues and subsequently initiated, on its own initiative, pursuant to Article 21 of the Data Protection Authority’s Regulation No. 1/2019, an investigation aimed at assessing, as a whole, the methods and processing purposes carried out by Cerved Group S.p.A. in connection with the service provided by Major 1 S.r.l. and known as “CGS-X.” With this in mind, several inspections were conducted: at Hera S.p.A. on March 18, 19, and 20, 2024; at Major 1 S.r.l., on April 15 and 16, 2024; at Cerved Group S.p.A. on April 16, 2024; and at Experian Italia S.p.A. on June 13 and 14, 2024. Subsequently, given the particular complexity of the investigation and in order to gather further information regarding the processing of the aforementioned data, additional on-site inspections were conducted at Major 1 S.r.l., on October 15 and 16, 2024, and at Cerved Group S.p.A. on October 16, 2024. 2. The Preliminary Investigation. The preliminary investigation concerning Cerved Group S.p.A. took into account not only the findings of the aforementioned inspections but also additional information provided in the supplementary documentation submitted by the Company on May 10 and October 31, 2024, to address the reservations raised during the on-site inspections, as well as the communication dated April 4, 2025, received in response to the Authority’s request for information dated March 7, 2025. As part of the investigation, with regard to the issues highlighted in the introduction, the following findings emerged. 2.1. The results of the on-site inspections. The “CGS-X” software is distributed “based on a contractual package that requires the customer [i.e., the energy supplier] to sign three separate contractual documents with Cerved Group S.p.A., Experian Italia S.p.A., and Major 1 S.r.l.” (see Major 1 S.r.l.’s statement of April 15, 2024, p. 3). Once enrolled in the service, the energy supplier enters the data of its potential customers into the “CGS-X” software, acting as an independent controller and, at the same time, designating Major 1 S.r.l. as the processor, pursuant to Art. 28 of the Regulation. The latter acts as a technology service provider, supplying the license to use the “CGS-X” software and, in this context, in response to a query made by the energy provider, consults the commercial information systems managed by Cerved Group S.p.A. and credit information systems, which are managed by Experian Italia S.p.A. According to the findings of the inspection at Major 1 S.r.l., “access to the information systems of Cerved and Experian is carried out by Major 1 S.r.l., in the name and on behalf of the client [energy supplier] (..) and constitutes a transfer of data between independent controllers (between Experian/Cerved and the client)” (see Major 1 S.r.l. report dated April 15, 2024, p. 3). From an operational standpoint, “the operation of the aforementioned software requires that the client [energy supplier] execute a query (..) with a specific call based on the tax ID number [of the data subject]” (see minutes of Major 1 S.r.l. dated April 15, 2024, p. 2). The system “queries the information systems of Cerved and Experian using those same tax identification numbers,” retrieving the “Retail Utilities Score” from Cerved Group S.p.A. and the “ESX Score” from Experian Italia S.p.A., along with the corresponding sub-scores (see minutes of Major 1 S.r.l. dated April 15, 2024, p. 3). This information “is processed by Major 1’s software in order to obtain (..), in response to the aforementioned queries, (..) an integrated score (the so-called CGS-X Score) relating to the assessment of the data subjects’ ‘reliability’; a score that is the result of combining, (..), the scores obtained from the Experian (SIC) and Cerved (commercial information) databases” (see minutes of Major 1 S.r.l. dated April 15, 2024, pp. 2–3). More specifically, with regard to the processing carried out by Cerved Group S.p.A. for the purpose of calculating the “Retail Utilities Score,” it was verified that the latter consists of the following items, all of which are present in the XML schema: ‒ “Information on adverse events”: [OMISSIS]” (see minutes of Major 1 S.r.l. dated April 16, 2024, p. 3); ‒ “Score class”: “score [OMISSIS]” (see minutes of Major 1 S.r.l. dated April 16, 2024, p. 3); ‒ “Score class before override”: a tool “for control and reclassification in determining the class, [OMISSIS]” (see minutes of Major 1 S.r.l. dated April 16, 2024, p. 3; see also note from Major 1 S.r.l. dated May 10, 2024, p. 1). In turn, the “Retail Utilities Score” is “the result of processing various sub-scores, which are also present in the XML file.” These are the following items: ‒ “Sub-score [OMISSIS]”: “a risk score concerning only individuals, based on the personal information of the data subject (specifically residence/place of birth and age) [OMISSIS]” (see minutes of Major 1 S.r.l. dated April 16, 2024, p. 3); ‒ “Sub-score [OMISSIS]” (see minutes of Major 1 S.r.l. dated April 16, 2024, p. 3); ‒ “Sub-score [OMISSIS]”: this is “a value reflecting the risk level of the data subject’s area of residence [OMISSIS]” (see minutes of Major 1 S.r.l. dated April 16, 2024, pp. 3–4); ‒ “Sub-score P4”: “score [OMISSIS]” (see minutes of Major 1 S.r.l. dated April 16, 2024, p. 4). With regard to the requests submitted by the data subjects pursuant to Article 15 of the Regulation, the Company provided different responses depending on whether or not the data subjects’ personal information was recorded in its systems. In particular, Cerved Group S.p.A. clarified that “where no Cerved customer has ever submitted a request on behalf of [the aforementioned data subjects] or where no data [relating to them] has ever been collected from the sources used by Cerved to provide commercial information services,” there is no record in its database (see the Company’s minutes of October 16, 2024, p. 3). In such cases (see responses provided: on August 5, 2022, to Mr. XX; on March 25, 2024, to Mr. XX; on September 19, 2023, to Mr. XX; on May 21, 2024, to Mr. XX), the Company therefore responded to the requests for access pursuant to Article 15 of the Regulation, stating that there was no negative information regarding these individuals in its systems and that, likewise, no processing of personal data concerning them had been carried out for commercial information purposes. Nevertheless, a “Retail Utilities Score” had been generated for them, which was based primarily on the degree of risk associated with the data subject in relation to their residential address (so-called Sub-score [OMISSIS]), as well as their age and place of birth (so-called Sub-score [OMISSIS]). In other cases (see responses provided: on October 4, 2022, to Mr. XX, and on May 31, 2023, to Ms. XX), where personal information pertaining to the applicant had been identified, the Company sent the applicant an informational report containing the personal data present in the Cerved Group S.p.A. database (e.g., positions and/or management roles; equity interests in companies; etc.). The aforementioned document also included a score, [OMISSIS], corresponding to a risk profile of “zero—no negative events.” It was also established that, in none of the cases subject to complaint, did the response provided by the Company contain any references to the “Retail Utilities Score” or the related sub-scores assigned to the data subjects concerned. All of this, even though it emerged that, within Cerved Group S.p.A.’s systems, records existed of the queries made by Major 1 S.r.l. regarding the tax identification numbers of all the complainants, including those mentioned above for whom a negative response had been provided, as well as the corresponding responses sent by Cerved Group S.p.A.’s systems and containing the “Retail Utilities Score” and the related sub-scores pertaining to the latter (see the Company’s minutes of April 16, 2024, p. 2 and Attachment 2; see also the Company’s minutes of October 16, 2024, p. 4 and Annex 7). On this point, Cerved Group S.p.A. represented that the office responsible for responding to requests pursuant to Articles 15–22 of the Regulation (referred to as the “Complaints Office”), did not provide any information regarding the aforementioned scores because “it had no technical means to independently and directly verify whether, with respect to a specific data subject, the aforementioned information was available”; all of this despite the fact that such information had been “previously compiled in response to requests from authorized clients” (see the Company’s note dated May 10, 2024, pp. 2 and 3). It also pointed out that such “information is not normally included in the informational documents made available to the majority of customers (..) since it is also subject to change even within short time frames” (see the Company’s note dated May 10, 2024, pp. 2 and 3). Therefore, with regard to the requests for access submitted, it emerged that—as expressly stated by the Company—Cerved Group S.p.A. responded to the data subjects “without including, for the reasons outlined above, data concerning the value of the Retail Utilities Score and the related sub-scores, since the Office was not immediately able to directly access this additional information as well, which had been specifically processed and sent” to the requesting energy suppliers (see the Company’s note dated May 10, 2024, p. 3). 2.2. Measures Adopted by the Company Following the Inspection Findings. Following the Office’s findings, Cerved Group S.p.A. implemented—initially on a provisional basis, starting in May 2024, and definitively as of August 2024—– measures designed to enable the Complaints Office, “in the event of access requests to exercise the right of access to personal data, to immediately and directly verify the presence of personal data relating also to the ‘Retail Utilities Score’ and its sub-scores, where such data have been processed and sent to customers (…) and to communicate such data to the data subjects through a presentation that makes it easily understandable, with a concise explanation of the criteria and [the] logic behind the processing” (Company’s note of May 10, 2024, p. 3; see also Annex 1 to the Company’s note of October 31, 2024). All of this through: - the adoption of a system capable of “tracking, by customer record, a query submitted to Cerved [by Major S.r.l.], including in response to requests for information made by customers [energy suppliers] regarding the use of the CGS-X software” (see Company minutes of October 16, 2024, p. 4); - the implementation of a “tool for use by the team dedicated to responding to requests to exercise rights, designed to enable the team to interface with the system (..) containing the logs regarding the queries made by Major1 (..) and received from Cerved, regarding the customer’s use of the CGS-X software” (see Company minutes of October 16, 2024, p. 4). The Company “therefore developed a dashboard, available to the Complaints Office, through which, using specific filters (..), the queries related to the “Retail Utilities Score,” made by Major 1 on behalf of customers using the CGS-X software. (..) In this way, it is possible to provide a comprehensive response to the data subject, which also takes into account, relatively quickly, the assessments (“Retail Utilities Score” and related sub-scores) pertaining to the data subjects” (see Company minutes of October 16, 2024, p. 4 and Annex 1 of the Company’s note dated October 31, 2024). At the same time, the Company has prepared a new template for responding to requests under Article 15 of the Regulation submitted by data subjects, which is processed within the “CGS-X” software, designed to enable data subjects to “better understand the key elements used to calculate the Retail Utilities Score” (see the Company’s minutes of October 16, 2024, p. 3). In this regard, it was established that, pending the final adoption of the new response procedures, the Company nevertheless sent an interim response to certain complainants (specifically to Ms. XX on August 5, 2024, and to Ms. XX, on September 23, 2024) an interim response containing preliminary information regarding the data communicated by Cerved Group S.p.A. to Hera Comm S.p.A. as part of the services provided to the latter (see Annex 2 to the Company’s minutes of October 16, 2024; see the Company’s note of April 4, 2025, p. 1). All of this is subject to conducting “the specific technical investigations necessary to verify the existence of additional (..) personal data transmitted to [aforementioned] Hera,” in order to provide a definitive response (see Annex 2 of the Company’s minutes of October 16, 2024; see the Company’s note of April 4, 2025, p. 1). Effective October 15, 2024, the system described above became fully operational, and Cerved Group S.p.A. provided the petitioners with a response based on the new model adopted (see the Company’s note dated October 31, 2024, and the Company’s note dated April 4, 2025, p. 1). More specifically, with regard to this latest new model as well (see Attachments Nos. 1, 4.2, and 5.2 of the Company’s notice dated October 31, 2024; see Attachments Nos. 3a, 3b_1, 3b_2, 3b_3, and 4 of the Company’s notice dated April 4, 2025), it emerged that the data controller, with respect to the requests made by Messrs. XX, XX, XX, XX, XX, XX, and XX, had nevertheless provided an incomplete response, as it lacked the sub-scores labeled “Sub-score [OMISSIS]” and “Sub-score [OMISSIS],” as well as explanations regarding the logic underlying their determination. Finally, it emerged that the Company, during the period from May 2022 to October 2024, received “approximately 50 requests to exercise the rights [pursuant to Articles 15–22 of the Regulation] per month from Hera Comm/EstEnergy customers,” for a total of 2,094 requests (see the Company’s minutes of October 16, 2024, p. 4 and Annex 6). 3. The notification pursuant to Article 166, paragraph 5, of the Code. Following the allegation of violations under Articles 5(1)(a), 12, and 15 of the Regulation, sent to Cerved Group S.p.A. by notice dated July 16, 2025, the Company, by letter dated September 15, 2025, submitted its defense briefs, which were further supplemented during the hearing on May 11, 2026, as well as via a communication dated May 25, 2026. In the aforementioned briefs, the Company made the following representations: - regarding the allegation concerning the inadequacy of the response provided by Cerved Group S.p.A. to the data subjects, in that it lacked information regarding the “Retail Utilities Score,” the additional sub-scores, as well as the logic and criteria applied to the calculation system, the aforementioned “Retail Utilities Score,” as processed and transmitted by Cerved, does not constitute, (..) an “autonomous automated decision-making process,” pursuant to Art. 22 of the Regulation. Rather, it is “a mere partial indicator of customer reliability (..) made available to clients of third parties—such as, in the case at hand, Hera Comm S.p.A. and EstEnergy S.p.A.—so that they may use it with full autonomy and in accordance with their own internal assessment and decision-making logic.” More specifically, the Company believes it has fulfilled all disclosure obligations toward data subjects. On the one hand, in fact, “the provision of the ‘Retail Utilities Score’ constitutes, in and of itself, a correct and sufficient representation of the assessment result and the criteria underlying the calculation, without any further obligation to provide the sub-scores.” This is taking into account that the sub-scores “cannot be classified as additional information independent of the ‘Retail Utilities Score,’ but rather represent the internal structure of the assessment system, (..) which enables the determination of the ‘Retail Utilities Score.’” Furthermore, “Cerved was in no way under an obligation to provide clarifications regarding the internal logic and decision-making criteria adopted by the energy suppliers,” given that the latter are the “only parties that have effectively assumed—with full evaluative and discretionary autonomy—the decision regarding whether or not to activate the supply” (see the Company’s note of September 15, 2025, pp. 4–5; see also the minutes of the hearing of May 11, 2026, pp. 1–2); - with specific reference to the complaint filed by Mr. XX on July 15, 2024, it notes a procedural issue in that the Authority did not issue, to the account holder, an invitation to exercise the right to notify the complainant and the Office of any voluntary compliance, as provided for in Article 15, paragraph 1, of the Data Protection Authority’s Internal Regulations No. 1/2019; all of this “despite the fact that the complaint concerned exclusively the exercise of the right of access vis-à-vis the Company” (see note of September 15, 2025, p. 3); - regarding the number of data subjects affected by the breach, this figure does not correspond to the “2,094 data subjects who submitted requests to Cerved between May 2022 and October 2024,” as indicated in the notice of initiation pursuant to Article 166, paragraph 5 of the Code, but must be attributed “exclusively to the 8 individuals whose requests formed the basis of the proceedings” (see note dated September 15, 2025, pp. 2 and 6; see also the minutes of the hearing of May 11, 2026, p. 3). Furthermore, with regard to the factors to be taken into account for the purpose of determining the amount of any penalty—among those identified in Article 83, para 2 of the Regulation—the Company stated that, with respect to the revenue relevant to the case at hand, “over the last three fiscal years, Cerved’s provision of the Retail Utilities Score as part of the broader service known as ‘CGS-X’ had a completely marginal impact on Cerved’s revenue” (see the Company’s note dated September 15, September 2025, p. 9; see supplementary notes dated May 25, 2026). The Company also highlighted the significant efforts it has made, following the initiation of proceedings by the Data Protection Authority, to further bring its activities into compliance with data protection regulations. To this end, beginning in September 2025, it drafted an additional template for responding to requests for access pursuant to Article 15 of the Regulation “which includes the sub-scores designated ‘Sub-score [OMISSIS]’ and ‘Sub-score [OMISSIS]’, and [provides] further guidance regarding the logic underlying their definition.” The latter was sent to the data subjects “to further supplement what had already been communicated previously” (see the Company’s note of September 15, 2025, p. 8; see also the minutes of the hearing of May 11, 2026, p. 3). Finally, Cerved Group S.p.A. emphasized, pursuant to and for the purposes of Article 166, paragraph 7 of the Code, that it has “consistently produced and disseminated, through its corporate website (the ‘News & Educational’ Section), numerous articles aimed at informing users and raising their awareness of the risks associated with the processing of personal data and digital threats” (see the Company’s note dated September 15, 2025, p. 9). 4. The Authority’s Assessments. First of all, it should be noted that, unless the act constitutes a more serious offense, anyone who, in proceedings before the Data Protection Authority, falsely declares or attests to facts or circumstances, or produces false documents or records, is liable pursuant to Art. 168 of the Code, “False Statements to the Data Protection Authority and Interruption of the Performance of the Authority’s Duties or the Exercise of Its Powers.” In light of the evidence gathered during the preliminary investigation described above, it has been established that Cerved Group S.p.A. provided inadequate and incomplete responses to the requests submitted by data subjects to exercise their rights under Articles 15–22 of the Regulation. This pertains specifically to the processing of personal data carried out by Cerved Group S.p.A. for the purpose of providing the “CGS-X” service. Having duly set that forth, it should first be noted that, for the purposes of addressing the issues at the heart of this decision, it is necessary to take into account the specific context underlying the processing activities carried out in the cases at hand. 4.1. The processing of personal data for commercial information purposes and Judgement C-634/21 of the Court of Justice of the European Union dated December 7, 2023. In its judgement of December 7, 2023, in Case No. C-634/21, the Court of Justice of the European Union (hereinafter “the Court”) ruled on the interpretation of Article 22 of the Regulation, with regard to the processing of personal data for commercial information purposes. In that judgment, the Court clarified that the applicability of the aforementioned provision is subject to the fulfillment of three cumulative conditions related to the existence of a “decision,” that such a decision is “based solely on automated processing, including profiling,” and that it produces “legal effects [concerning the data subject],” or “significantly affects the data subject in a similar manner” (see para. 43, CJEU Judgement, C-634/21, cited above). The Court noted in particular that the concept of “decision,” within the meaning of Article 22(1) of the Regulation, may encompass various acts, including those which, although they do not have direct legal effects on the data subject, nevertheless significantly affect the data subject in a similar manner (see, to that effect, also Recital 71 of the Regulation). That concept, therefore, is “broad enough to encompass the result of calculating a person’s creditworthiness in the form of a probability ratio relating to that person’s ability to meet future payment obligations.” This applies even where the result—as is the case here—is produced by a company that provides commercial information to third parties (see para. 46, CJEU judgement, C-634/21, cited above). With regard to the additional conditions set forth in Art. 22 of the Regulation, the Court found that they were met in the specific context at hand. The ruling clarified, first of all, that the aforementioned decision is based exclusively on an automated calculation derived from the processing of the data subject’s personal data concerning the data subject’s reliability in terms of timely payments. Second, the Court noted that the result of this calculation—expressed as a probability rate—significantly affects the individual by preventing them from accessing the requested service, such as the energy supply at issue in the present case. On this point, the Court itself clarified that, in the aforementioned context, “the action of the third party to whom the probability rate is transmitted is guided ‘decisively’ by that rate” (see para. 48, CJEU judgement, C-634/21, cited above), as has emerged during the present proceedings with respect to the decisions made by Hera Comm S.p.A. and EstEnergy S.p.A. This interpretation is consistent with the rationale underlying Article 22 of the Regulation, which aims to ensure the protection of individuals’ fundamental rights and freedoms against the specific risks arising from the automated processing of personal data, including profiling (see para. 51, CJEU Judgement, C-634/21, cited above). Moreover, a restrictive interpretation of the aforementioned provision would undermine the safeguards for the data subject provided for by the Regulation, as the data subject would be unable to assert, against commercial information companies, their right of access to data concerning them, as established by Article 15(1)(h) of the Regulation (see paragraphs 61–63, CJEU Judgement, C-634/21, cit.). In conclusion, according to the Court, “Article 22(1) of the Regulation must be interpreted as meaning that the automated calculation, by a credit reporting agency, of a probability score based on personal data relating to an individual and concerning that individual’s ability to meet payment obligations in the future constitutes an ‘automated individual decision-making process’ within the meaning of that provision, where the conclusion, the performance, or the termination of a contractual relationship with that individual by a third party to whom that probability score is disclosed” (see para. 73, CJEU Judgement, C-634/21, cited above). It follows, therefore, that, contrary to the Company’s contention (see supra, para. 3(a) of this decision), the processing operations carried out by Cerved Group S.p.A. in the cases at issue in this decision fall within the scope of the aforementioned judgement and, therefore, Articles 15(1)(h) and 22 of the Regulation apply to such processing, as explained in greater detail below (see paragraphs 4.2. and 4.3. of this decision). Finally, it should be noted that the proceedings in question concerned solely the measures adopted by Cerved Group S.p.A. to ensure proper compliance with the obligations set forth in Article 15 et seq. of the Regulation regarding the exercise of rights; all of this in light of the specific instances of non-compliance that emerged during the preliminary investigation initiated by the Authority following the submission of the requests indicated in the preamble. With regard, however, to the broader issue concerning the conditions for the lawfulness, pursuant to Art. 22, para. 2 of the Regulation, of the processing of the data subject’s personal data carried out by providers of commercial information services, as well as the safeguards that the controller is required to implement pursuant to Art. 22, paragraphs 3 and 4 of the Regulation, the Authority reserves the right to take any appropriate action aimed at verifying the existence of the aforementioned conditions (see, on this subject, also the Authority’s statement of September 11, 2025, during the hearing of the President of the Italian Data Protection Authority regarding “Draft Law AS 1578 establishing the Annual Law on the Market and Competition for 2025,” web doc. no. 10166076). 4.2. Violations concerning the exercise of the right of access under Art 15 of the Regulation. First and foremost, following the preliminary investigation, it became evident that the responses provided by Cerved Group S.p.A. to requests by data subjects to exercise their rights under Articles 15–22 of the Regulation—aimed at obtaining information regarding the “Retail Utilities Score”—were inadequate. In its responses, the Company limited itself to confirming the presence (or absence) of the data subjects’ records in its systems and, where present, to providing the personal data stored therein; however, without providing any indication regarding the score associated with the creditworthiness profile developed by the Company and made available to energy suppliers, nor the criteria on which that profile was based. Similarly, in these responses, no information was provided to the data subjects regarding the logic used to calculate the aforementioned profile. All of this occurred even though the information in question was, in fact—as ascertained during the on-site inspections—still present in Cerved Group S.p.A.’s systems as of the date of receipt of the aforementioned requests (see supra, para. 2.1. of this decision). On this point, it is worth noting that the right of access under Article 15 of the Regulation is primarily conceived as a tool intended, in general terms, the data subject to exercise “control” over their personal data and the controllers’ use thereof, ensuring that the data subject is fully aware of the information being processed and the actual methods of such processing; in accordance with the general provisions of the principle of lawfulness, fairness, and transparency (Articles 5(1)(a) and 5(2) of the Regulation). The purpose of the right of access is therefore primarily to disclose “what” data and “how” it has been processed by the controller, in order to provide the data subject with the means to “know and verify the lawfulness and accuracy of the processing” concerning them (see Recital 63 of the Regulation; European Data Protection Board, “Guidelines 1/2022 on the Rights of Data Subjects—Right of Access,” adopted on March 28, 2023, paragraphs 10–13). Pursuant to Article 15 of the Regulation, therefore, the data controller, when responding to a request for access, may not limit itself to providing “a general description of the data [or] a mere reference to the categories of personal data processed,” nor may it omit information in its possession that relates to the data subject; on the contrary, the controller is required to provide the data subject with access to “all the information referred to in Article 15” that is actually being processed. Such information, therefore, “must be complete, accurate, and up-to-date, reflecting as closely as possible the status of the data processing at the time the request was received” and must be provided “in a concise, transparent, intelligible, and easily accessible form” to the data subject (see European Data Protection Board, “Guidelines 1/2022,” op. cit., para. 34; Art. 12, para. 1 of the Regulation). It should also be noted that, in the case at hand, the specific context underlying the requests to exercise the right of access submitted by the data subjects requires particular attention on the part of the controller, including with regard to the obligation to provide “meaningful information on the logic used, as well as [on] the significance and [the] expected consequences of such processing for the data subject” (Article 15, para 1, subparagraph (h) of the Regulation). With regard to the aforementioned provision, the Court of Justice of the European Union has recently provided useful practical guidance—both substantively, regarding the type of information that the data subject may require from the controller, and formally, regarding the manner in which such information must be provided by the controller (see CJEU judgement of February 27, 2025, C-203/22). In particular, in clarifying the phrase “meaningful information regarding the logic used,” the Court specified that this refers to “any relevant information concerning the procedure and principles for the automated processing of personal data in order to achieve a specific result” (see para. 58, CJEU judgement, C-203/22, cited above). It follows, therefore, that the data subjects concerned, in the case at hand, have the right to be fully informed of all the elements that make up the assessment of their creditworthiness, including those taken into account by the data controller for the purpose of assigning the credit score, as well as the calculation criteria used for that purpose (see, in this regard, Order of the Court of Cassation, Section I, No. 14381 of May 25, 2021). With regard, however, to the manner in which the aforementioned information must be provided, the Court of Justice of the European Union has reaffirmed the data controller’s obligation to provide such information “in a concise, transparent, intelligible, and easily accessible form, using plain and clear language”; all in compliance with the principle of transparency set forth in Articles 5(1)(a) and 12(1) of the Regulation. Therefore, “neither the mere communication of a complex mathematical formula, such as an algorithm, nor a detailed description of all the stages of automated decision-making can satisfy these requirements, since neither of these methods would constitute a sufficiently concise and comprehensible explanation” (paragraphs 58–59, CJEU judgement, C-203/22, cited above). Overall, the requirement to provide “meaningful information on the logic used,” pursuant to Article 15(1)(h) of the Regulation, thus amounts to an obligation on the part of the controller to “describe the procedure and the principles actually applied in such a way that the data subject can understand which of [their] personal data have been used and how (...), without the complexity of the operations to be carried out in the context of the automated decision-making process exempting the controller from its duty to explain” (para. 61, CJEU judgement, C-203/22, cit.). In light of the foregoing, it follows that Cerved Group S.p.A., in the cases at issue, acted in violation of Articles 5(1)(a), para 1, 12, and 15 of the Regulation, Recital 12, given that it did not provide the data subjects with any information regarding the “Retail Utilities Score” or the additional sub-scores that contributed to generating that score. Furthermore, the Company did not inform the petitioners regarding the logic and criteria applied to the calculation system underlying the development of the credit risk profile. 4.3. The response template pursuant to Art. 15 of the Regulation, prepared following the preliminary investigation, and additional profiles. It is worth noting that the aforementioned violations also persist with regard to the feedback form that Cerved Group S.p.A. prepared (and sent to the data subjects), starting on October 15, 2024 (see above, para 2.2.); this was done to provide them with more information enabling them “to better understand the essential elements used to calculate” the aforementioned score (see the Company’s minutes of October 16, 2024, p. 3). The preliminary investigation revealed that, with respect to the requests made in the cases under dispute, the Company provided—even based on the updated template—a response that was nonetheless incomplete, as it lacked the sub-scores labeled “Sub-score [OMISSIS]” and “Sub-score [OMISSIS],” as well as guidance regarding the logic underlying their determination (see Attachments Nos. 1, 4.2, and 5.2 of the Company’s note dated October 31, 2024; see Attachments Nos. 3a, 3b_1, 3b_2, 3b_3, and 4 of the Company’s letter dated April 4, 2025). These are sub-scores which, as already noted in para 2.1 of this decision, refer to a risk level that varies, depending on the age of the data subject and in relation to their place of birth and residence, and regarding which no information has been provided, with reference to specific individual cases, concerning the “actual weight” of these variables in the calculation of the “Retail Utilities Score.” It follows, therefore, that even the use of the new model adopted by Cerved Group S.p.A., starting in September 2025, is capable of ensuring that data subjects’ right of access, as provided for in Articles 12 and 15 of the Regulation, is effectively satisfied with respect to the specific processing operations in question. Finally, regarding the specific objection raised by the Company concerning the procedural issue related to the handling of the complaint filed by Mr. XX (see supra, para. 3, subpara. b) of this decision), it should be noted that, in the present case, the provision requiring that the invitation to respond be forwarded to the data controller (see Article 15, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019) could not be applied. This is because, at the time the complaint was received, the Authority did not have the information pertaining to the specific processing in question and therefore could not determine that the response provided to the data subject by Cerved Group S.p.A. on May 21, 2024, was inadequate (see para 2.1 of this decision). Indeed, it was only after the investigation was initiated—once the Authority had gained a clear understanding of the characteristics and methods of the processing carried out for the purpose of calculating the “Retail Utilities Score”— was the Authority able to determine that the aforementioned response was inadequate and that the Company was under an obligation to comply with the complainant’s requests. 4.4. Concluding Assessments. As a result of the findings set forth in the preceding paragraphs, it is clear that the inadequacy of the responses provided by the Company as a whole effectively prevented the data subjects who exercised their rights under the Regulation from gaining access to all personal information actually processed for the purpose of calculating their risk profile, as well as from adequately understanding how that profile was used for the purposes of the decisions made by Hera Comm S.p.A. and EstEnergy S.p.A. regarding them, which led to the denial of energy supply. This effectively prevented them from ascertaining the lawfulness and fairness of the processing, as well as the accuracy of the data used in the context at hand, thereby impairing their ability to exercise, where applicable, the right to rectification, in the event of inaccurate and/or incomplete data (see Art. 16 of the Regulation) and, at the same time, the right to “obtain human intervention by the controller, [to] express their opinion and contest the decision” taken by the controller regarding them (see Article 22(3) of the Regulation). This risk arises, in particular, in cases where, even though there is “no personal data in the (..) [Company’s] database,” as established during the preliminary investigation, the data subject was nonetheless assigned a “Retail Utilities Score” based primarily on the degree of unreliability associated with the data subject in relation to their residential address, the so-called Sub-score [OMISSIS], as well as on their age and place of birth, the so-called Sub-score [OMISSIS] (see paragraph 2.1 of this decision). All of this—given the particularly sensitive nature of the information processed by Cerved Group S.p.A. in the case at hand, as it pertains to customer creditworthiness—could have prejudicial consequences on the fundamental rights and freedoms of the data subjects (such as, for example, as occurred in the cases in question, the refusal to sign an energy supply contract). For the reasons outlined above, it is therefore determined that Cerved Group S.p.A. has violated Articles 5(1)(a), 12, and 15 of the Regulation. Finally, it is noted that the aforementioned unlawful conduct—during the period from May 2022 to October 2024—affected approximately 2,094 data subjects (see para 2.2 of this decision). In this regard, in fact, the Company’s argument—that the relevant figure in the case at hand is not 2,094 but “exclusively [that relating to] the 8 individuals whose complaints formed the basis of the proceedings” (see, supra, para 3(c) of this decision). On this point, it is worth noting that, contrary to the Company’s assertion (see minutes of the hearing of May 11, 2026, p. 3), the scope of the proceedings in question cannot be limited exclusively to the cases of the eight data subjects who filed reports and/or complaints with the Authority. This is because the Data Protection Authority, in the exercise of its supervisory duties—and given the large number of requests received by the Authority over time—has determined the need to initiate, pursuant to Article 21 of the Data Protection Authority’s Regulation No. 1/2019, a general investigative inquiry aimed at assessing, as a whole, the methods and processing purposes carried out by Cerved Group S.p.A. in connection with the service provided by Major 1 S.r.l. and referred to as “CGS-X.” It should also be noted that the Company’s assertions on this point have not been substantiated in any way by Cerved Group S.p.A. through appropriate documentary evidence. In order to determine the number of data subjects involved in this proceeding, the findings from the investigations conducted on October 16, 2024, must therefore be taken into account. On that occasion, the Company presented a chart showing the number of requests regarding the exercise of rights submitted by customers of Hera Comm S.p.A. and EstEnergy S.p.A. in the years 2022, 2023, and 2024, which clearly indicates the figure mentioned above, namely 2,094 (see minutes of October 16, 2024, p. 4 and related Annex No. 6). 5. Conclusions: Declaration that the processing is unlawful. Corrective measures pursuant to Art. 58(2) of the Regulation. In light of the overall findings, the Authority considers that the statements, documentation, and explanations provided by the controller during the investigation do not sufficiently address the concerns raised by the Office in thenotice of initiation of proceedings, and that they are therefore insufficient to warrant the dismissal of this proceeding, especially since none of the cases provided for in Art. 11 of the Data Protection Authority’s Regulation No. 1/2019 apply. The processing of personal data carried out by Cerved Group S.p.A., which is the subject of this decision, was therefore conducted in violation of Articles 5(1)(a), 12, and 15 of the Regulation. With regard to the exercise of the corrective powers referred to in Art. 58(2) of the Regulation, it is noted that Cerved Group S.p.A., during the proceedings, took initial steps to bring the processing of customer data into compliance with the Regulation, in accordance with the regulatory framework described above, as detailed in this decision (see above, paragraphs 2.2 and 3 of this decision). Particular reference is made to the adoption, in September 2025, of an additional new feedback form, pursuant to Art. 15 of the Regulation, which includes the “Retail Utilities Score” and its related sub-scores and thus provides clearer guidance regarding the logic underlying their definition, as well as the successful implementation of the so-called Dashboard, a tool made available to the Company’s Complaints Office, with a view to enabling that department to provide a comprehensive response to the data subject within the terms set forth above. Notwithstanding the aforementioned actions already taken by the Company, it is nevertheless deemed necessary, in light of the additional critical issues identified with respect to the controller, to order the controller to implement a corrective measure pursuant to Art. 58, para 2, subparagraph d), of the Regulation, with a view to safeguarding the data subject rights, freedoms, and legitimate interests in accordance with Article 22, paragraph 3, of the Regulation. This measure consists of adopting a procedure designed to ensure that the data subject can fully exercise the right to rectification pursuant to Article 16 of the Regulation, in the event of the processing of inaccurate and/or incomplete data relating to the “Retail Utilities Score” assigned to the data subject. This applies, in particular, where the aforementioned score is primarily based on the degree of risk associated with the data subject, in relation to their residential address (so-called “Sub-score [OMISSIS]”), as well as their age and place of birth (so-called Sub-score [OMISSIS]). Finally, it should be noted that the violations, as established in the reasoning section, cannot in any way be considered “minor” within the meaning of Recital 148 of the Regulation; given the multiple violations alleged and the number of data subjects involved, as well as the additional factors explained in greater detail in paragraph 6 of this decision. 6. Injunction Order. The Data Protection Authority, pursuant to Article 58, para 2, subparagraph (i) of the Regulation and Article 166 of the Code, has the power to impose an administrative fine provided for in Article 83 of the Regulation by issuing an injunction (Article 18. Law No. 689 of November 24, 1981), in connection with the processing of personal data carried out by Cerved Group S.p.A., which has been found to be unlawful, as set forth herein. The violation of the provisions referred to above entails the application of the administrative fine provided for in Art. 83, para. 5, subparagraphs (a) and (b) of the Regulation. Having determined that paragraph 3 of Art 83 of the Regulation must be applied, insofar as it provides that “if, in relation to the same processing or related processing operations, a controller […] intentionally or negligently infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the most serious violation,” the total amount of the fine is calculated so as not to exceed the maximum amount provided for in Art. 83(5) of the Regulation. With regard to the factors listed in Art. 83(2) of the Regulation for the purposes of imposing the administrative fine and determining its amount—taking into account that the fine must be “in each individual case effective, proportionate, and dissuasive” (Article 83(1) of the Regulation), it is noted that, in the case at hand, the following circumstances were taken into account: - the significant gravity of the violation (Articles 83(2)(a) and 83(para) of the Regulation), in relation to its nature (concerning non-compliance with provisions on transparency and data subject rights), the manner (the multiple instances of unlawful conduct repeated over time), and the duration of the violation (approximately two and a half years). For this purpose, the characteristics and processing purposes are also taken into account, as well as the high number of data subjects involved and the type of harm they suffered. All of this, given that: the operations in question were carried out to develop a risk profile regarding the data subjects’ reliability in terms of timely payments, an activity that falls within the controller’s core business; the unlawful conduct affected 2,094 data subjects; the established violations resulted, in most cases, to the detriment of the data subjects, in the refusal to enter into a contract for the supply of electricity and/or gas; - the negligent nature of the conduct and the data controller’s significant instance of accountability regarding the technical and organizational measures implemented (Articles 83(2)(b) and (d) of the Regulation). All of this, with particular regard to the deficiency and inadequacy of the measures and processes implemented by the Company concerning compliance with obligations related to the exercise of data subject rights in the specific context at hand. With regard to the subjective element, consideration is given to the fact that, concerning the processing activities carried out by Cerved Group S.p.A. for the purpose of calculating the “Retail Utilities Score,” the company erroneously considered the provision of Art. 22 of the Regulation to be inapplicable; - the fact that there are no previous relevant infringements committed by the controller or previous measures referred to in Art 58 of the Regulation concerning the same subject matter (Article 83(2)(e) and (i) of the Regulation); - the data controller’s adoption of measures to mitigate or eliminate the consequences of the violation (Art. 83(2)(c) of the Regulation). In this regard, the fact that Cerved Group S.p.A. voluntarily adopted, once it became aware of the violation, certain initial measures to mitigate the effects of the unlawful processing should be viewed favorably; these measures, although only partially effective in reducing the risks, can nonetheless be considered reasonable; - the fact that the Company actively cooperated with the Authority during the proceedings (Article 83(2)(f) of the Regulation); - the nature of the information subject to the breach (Article 83(2)(g) of the Regulation), which, although not classified as special categories of data, is nonetheless considered sensitive as it reflects the reliability of customers’ timely payments; this also taking into account the potential economic and social consequences that may arise for the data subjects as a result of the unlawful processing of their data; - other mitigating factors (Article 83(2)(k) of the Regulation), such as, first and foremost, the Company’s implementation of communication campaigns aimed at raising awareness of the right to personal data protection, carried out prior to the commission of the data breach via its official website, in the “News & Educational” Section (see above, para 3 of this decision), as well as Cerved Group S.p.A.’s adherence to the “Code of Conduct for the Processing of Personal Data for Commercial Information Purposes,” approved by the Data Protection Authority pursuant to Art. 41 of the Regulation, by resolution dated April 29, 2021. It is further considered that, in the present case, the following factors are relevant in light of the aforementioned principles of effectiveness, proportionality, and deterrence to which the Authority must adhere in determining the amount of the sanction (Art. 83(1) of the Regulation): the economic circumstances of the offending party, determined on the basis of the Company’s turnover as set forth in the financial statements for the year 2025 (as submitted by the Company in a letter dated May 25, 2026). In light of the above factors and the assessments made, it is deemed appropriate, in this case, to impose on Cerved Group S.p.A. an administrative penalty in the amount of 400,000.00 euros (four hundred thousand/00). In this context, it is also deemed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, this section containing the injunction order must be published on the Data Protection Authority’s website. This is in light of the specific nature of the data subject to the processing at issue—as it pertains to the data subject’s creditworthiness—as well as the nature of the violations found, which affected the general principles of processing, in particular the principle of transparency and the obligations regarding the exercise of the data subject rights. Finally, it is considered that the conditions set forth in Article 17 of the Data Protection Authority Regulation No. 1/2019 are met. THAT BEING SAID, THE DATA PROTECTION AUTHORITY a) declares, pursuant to Article 57(1)(f) of the Regulation, that the processing carried out by Cerved Group S.p.A., with its registered office in San Donato Milanese, VAT No. 08587760961, as detailed in the grounds of this decision, to be unlawful due to a violation of Article 5(1)(a) and Articles 12 and 15 of the Regulation; b) orders, pursuant to Article 58(2)(d) of the Regulation, the aforementioned Company to comply, within six months from the date of service of this order, to the requirement set forth in para 5 of this decision, while at the same time requiring the company to provide, within the aforementioned time limit, an adequately documented response pursuant to Article 157 of the Code; failure to provide such a response may result in the imposition of the administrative fine provided for in Article 83, para 5, subparagraph (e) of the Regulation; ORDERS pursuant to Article 58, para 2, subparagraph (i) of the Regulation, that Cerved Group S.p.A. pay the sum of 400,000.00 euros (four hundred thousand/00) as an administrative fine for the violations indicated in this order; ORDERS pursuant to Article 58, para 2, subparagraph i) of the Regulation, that the same Company pay the aforementioned sum of 400,000.00 euros (four hundred thousand/00) as an administrative fine for the violations indicated in this order, in accordance with the procedures set forth in the attachment, within thirty days of notification of this order, failing which the necessary enforcement measures will be taken pursuant to Art. 27 of Law No. 689/1981. It is noted that, pursuant to Article 166, paragraph 8 of the Code, the offender retains the right to settle the dispute by paying an amount equal to half of the imposed penalty within the time limit set forth in Article 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, set for filing an appeal as indicated below; ORDERS - pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, the publication of the injunction order on the Data Protection Authority’s website; - pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Authority’s Regulation No. 1/2019, the publication of this order on the Authority’s website; - Pursuant to Article 17 of the Authority’s Regulation No. 1/2019, the recording of the violations and the measures adopted in accordance with Article 58(2) of the Regulation in the Authority’s internal register provided for in Article 57(1)(u) of the Regulation. Pursuant to Article 78 of Regulation (EU) 2016/679, as well as Article 152 of the Code and Article 10 of Legislative Decree No. 150 of September 1, 2011, an appeal against this decision may be filed with the ordinary courts by filing a petition with the ordinary court of the jurisdiction specified in the aforementioned Art 10, within thirty days from the date of notification of the decision, or within sixty days if the appellant resides abroad. Rome, July 3, 2026 THE PRESIDENT Stanzione THE RAPPORTEUR Ghiglia THE SECRETARY GENERAL Montuori

---
Generated by overview.legal · https://overview.legal/posts/353642 · 2026-09-03
