Garante per la protezione dei dati personali (Italy) - 483/2026

From GDPRhub
Garante per la protezione dei dati personali - 483/2026
Authority: Garante per la protezione dei dati personali (Italy)
Jurisdiction: Italy
Relevant Law: Article 5(1)(a) GDPR
Article 13 GDPR
Article 14 GDPR
Article 28 GDPR
Article 12 GDPR
Article 15 GDPR
Article 5(1)(e) GDPR
Article 5(1)(b) GDPR
Article 5(1)(d) GDPR
Type: Complaint
Outcome: Upheld
Started:
Decided: 03.07.2026
Published:
Fine: 5800000.0 EUR
Parties: Hera Comm S.p.A.
National Case Number/Name: 483/2026
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): Italian
Original Source: GPDP (in IT)
Initial Contributor: ds

The DPA fined an energy supplier €5,800,000 for failing to provide data subjects with their creditworthiness scores and an explanation on how they were calculated and used when deciding whether a contract with the data subject should be concluded. Further, the DPA held that debt data was unlawfully shared and used within the controller’s group.

English Summary

Facts

Several data subjects lodged complaints with the Italian DPA (Garante) after Hera Comm S.p.A., an energy supplier (the controller), declined to conclude electricity or gas contracts with them because its checks had resulted in a negative risk assessment. The controller had used a credit-check procedure to assess the creditworthiness of prospective customers before entering into such contracts.

The credit-check procedure consisted of an internal and an external assessment. During the internal assessment, Hera S.p.A. (processor A) checked whether the prospective customer had outstanding debts towards the controller or EstEnergy S.p.A., another energy supplier within the same corporate group. The assessment returned an OK or KO result. The controller’s privacy notice stated that customer data could be disclosed to other companies within the Hera Group and to third parties contractually linked to the Group.

Where the internal assessment returned an OK result, an external assessment was carried out using software called “CGS-X”, provided by Major 1 S.r.l. (processor B). Through the software, databases operated by Experian Italia S.p.A. (the credit-information provider) and Cerved Group S.p.A. (the commercial-information provider) were consulted. The software combined the scores supplied by the two external data providers to generate an integrated creditworthiness score, which was transmitted to systems operated by processor A. Those systems applied the criteria established under the controller’s group credit policy and returned a final OK or KO result.

The data subjects alleged that the refusal of their applications resulted from the external creditworthiness assessment. When they subsequently contacted the two external data providers, the providers stated that their systems did not contain negative information or adverse events concerning them.

The data subjects then submitted access requests to the controller. The controller replied that their risk profiles were based on automated scoring using information obtained from external databases and directed them to the two external data providers for further details. The replies did not identify the CGS-X score and did not explain the logic or criteria used in the assessment.

At the time of the inspection, the controller had not set a specific retention period for the external-assessment data and instead applied a general ten-year period used for accounting documentation. It also reused credit-check data, including information from external providers and previous debts, for analyses aimed at refining its group’s rating system. Between 2022 and March 2024, this processing concerned 1,003,657 individuals.

During the proceedings, the controller and the other energy supplier entered into a joint-controller arrangement under Article 26 GDPR concerning the internal assessment and updated the relevant privacy information. Under that arrangement, the two joint controllers also undertook to appoint processor A for the processing carried out as part of the internal assessment. The controller subsequently adopted a five-year retention period for creditworthiness data and discontinued the analyses concerning the refinement of the rating system.


Holding

The DPA considered that the information provided by the controller did not describe the intra-group sharing and use of data concerning previous debts with sufficient specificity. It found that the general references to disclosures within the corporate group did not provide information about the processing operations connected with the internal assessment. The DPA also found that the instructions provided to processor A did not cover the processing of information concerning debts owed by customers to the other energy supplier. It therefore found infringements of Article 5(1)(a) GDPR, Article 13 GDPR, Article 14 GDPR and Article 28 GDPR.

The DPA noted that, under the joint-controller arrangement, the internal assessment was carried out jointly by the two energy suppliers on the basis of Article 6(1)(f) GDPR. However, it found that the processing carried out before the conclusion of that arrangement was unlawful.

The DPA also found that the responses to the access requests did not meet the requirements of Article 12 GDPR and Article 15 GDPR. It noted that the access requests had been submitted to the controller which was required to provide all personal data and information relating to the processing. It pointed out additionally that the information to be provided should include the integrated score, the contributing scores, and meaningful information about the logic and criteria applied.

Moreover, referring to the CJEU’s judgment in Case C-203/22 (Dun & Bradstreet Austria), the DPA stated that the requirement to provide meaningful information about the logic involved could not be satisfied merely by disclosing a complex mathematical formula or by providing a detailed description of every stage of the automated process. It emphasized that the controller was required to describe the procedure and principles actually applied in a concise and understandable manner, enabling the data subject to understand which personal data were used and how they contributed to the result.

The DPA considered that the information provided did not enable the data subjects fully to assess the lawfulness of the processing or the accuracy of the data used. It also limited their ability to request rectification, obtain human intervention, express their views and contest the decision.

The DPA further found that the application of a general ten-year retention period to the credit-check data had not been sufficiently justified in relation to the purpose of assessing a specific contractual application. The controller had not demonstrated the necessity of retaining the scores and related reports for that period. The DPA concluded that the controller violated Article 5(1)(e) GDPR.

Furthermore, the DPA considered that the use of data obtained from the credit-information provider and the commercial-information provider for analyses concerning the refinement of the controller’s group rating model pursued a further purpose incompatible with the original purpose for which those data had been collected. It also found that retaining and subsequently reusing data obtained from the two external providers created a risk that the information would no longer be up to date. It therefore found infringements of Article 5(1)(b) GDPR and Article 5(1)(d) GDPR.

The DPA imposed a fine of €5,800,000. It also ordered the controller to define a new response template for access requests, including the relevant scores and meaningful information about the logic and criteria applied, and to provide the revised response to the complainants. The controller was further required to establish a procedure enabling data subjects to request the rectification of inaccurate or incomplete data, obtain human intervention, express their views and contest the decision.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details.

[Web Doc. No. 10273926]

Decision of July 3, 2026

Register of Decisions
No. 483 of July 3, 2026

THE DATA PROTECTION AUTHORITY

AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General;

HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter the “Regulation”);

HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003 (Code on Data Protection, hereinafter the “Code”), as amended by Legislative Decree No. 101 of August 10, 2018, containing “Provisions for the alignment of national legislation with the provisions of Regulation (EU) 2016/679”;

HAVING EXAMINED the documentation on file;

HAVING CONSIDERED the observations made by the Secretary General pursuant to Art. 15 of the Data Protection Authority’s Regulation No. 1/2000;

RAPPORTEUR: Prof. Pasquale Stanzione;

WHEREAS

1. Introduction.

This Authority has received several complaints concerning the processing of personal data carried out by Hera Comm S.p.A. for the purpose of verifying the creditworthiness of potential customers.

Specifically, the complainants alleged that Hera Comm S.p.A. refused to supply energy to them on the basis of a risk profile of the data subjects that allegedly emerged, following checks carried out by the aforementioned companies, including through the consultation of credit information systems (operated by Experian Italia S.p.A.) and the use of commercial information services (operated by Cerved Group S.p.A.). 

This assessment is carried out within the Hera Group using software provided by Major 1 S.r.l., called “CGS-X.” 

This software enables the aforementioned energy suppliers to identify a risk profile regarding the reliability of potential customers, based on an integrated indicator called the “Integrated Utilities Score” (hereinafter also referred to as the “CGS-X Score”). 

The petitioners pointed out in this regard that, although the denial of energy supply was the result of their being assigned a summary score (hereinafter also “score”) indicating low reliability—derived from a search of the databases managed by Cerved Group S.p.A. and Experian Italia S.p.A., these companies, when questioned on the matter, stated that their systems contained no negative information and/or adverse events regarding the aforementioned data subjects.

All of this is in response to the access requests submitted by the aforementioned individuals to Cerved Group S.p.A. and Experian Italia S.p.A., pursuant to Art. 15 of the Regulation (see request by Mr. XX dated March 1, 2023, the request filed by Mr. XX on June 29, 2023, the request filed by Mr. XX on June 14, 2024, the request filed by Mr. XX on July 15, 2024, and the request filed by Ms. XX on September 13, 2024).

With regard to the foregoing, it should be noted that the Authority, in view of the numerous requests received, first decided to consolidate the individual proceedings referred to above in order to conduct a comprehensive examination of the underlying issues and subsequently initiated, on its own initiative, pursuant to Article 21 of the Data Protection Authority’s Regulation No. 1/2019, an investigation aimed at assessing, as a whole, the methods and processing purposes carried out by Hera Comm S.p.A. in connection with the service provided by Major 1 S.r.l. and known as “CGS-X.”

In this context, several on-site inspections were conducted at Hera S.p.A. on March 18, 19, and 20, 2024; at Major 1 S.r.l., on April 15 and 16, 2024; at Cerved Group S.p.A. on April 16, 2024; and at Experian Italia S.p.A. on June 13 and 14, 2024. 
Subsequently, given the particular complexity of the investigation and in order to gather further information regarding the processing of the aforementioned data, additional on-site inspections were conducted at Major 1 S.r.l., on October 15 and 16, 2024, and at Cerved Group S.p.A. on October 16, 2024.

2. The Investigation.

As part of the proceedings, with regard to the issues highlighted in the introduction, the following findings emerged.

2.1. The Credit Check Process.

Hera S.p.A., “through its Credit Management function, establishes the ‘customer acceptance rules’ in terms of credit risk, providing services related to customer creditworthiness to the following companies operating in the energy sales sector: Hera Comm S.p.A. (…) [and] EstEnergy S.p.A.” (see Hera S.p.A.’s statement of March 18, 2024, p. 2). 
Hera S.p.A., in fact, “with a view to serving its subsidiaries, oversees the IT implementations related to credit management systems and carries out the various operational activities aimed at achieving shared objectives” (see Hera S.p.A. memorandum dated April 19, 2024, p. 1).

In particular, “in order to limit the credit risk associated with activities carried out on the free market, the Hera Group, (..), has adopted a Credit Policy and implemented a system for verifying and assessing the solvency and creditworthiness of parties applying to participate in one of the open-market offers (hereinafter, “Credit Check”). The Credit Check involves an internal assessment, consisting of verifying any delinquencies [past and current within the Hera Group’s energy sales companies] on the part of the customer (hereinafter, “Internal Assessment”), and an external assessment, which consists of obtaining, from entities authorized to conduct commercial credit reporting activities [and from the SICs], a summary “score”    —which may also be based on statistical information—regarding the customer’s creditworthiness (hereinafter, “External Assessment”)” (see Hera Comm S.p.A. note dated July 30, 2024, p. 2).

The customer creditworthiness assessment is carried out by Hera S.p.A. pursuant to the “Agreement for the Management of Administrative, Financial, and Control Activities,” signed on July 18, 2013, by Hera Comm S.p.A. and Hera S.p.A., and the related “Addendum” dated July 3, 2023. To this end, “Hera S.p.A. is appointed as the processor” (see Hera S.p.A. minutes of March 18, 2024, p. 2 and Annex 2).

This activity is carried out in accordance with a procedure titled “Rules for Private Customer Origination,” “prepared by Hera S.p.A.,” and “in effect as of May 2017, the date the Credit [Check] system became operational” (see Hera S.p.A. minutes of March 18, 2024, p. 2 and Annex 3; see also Hera S.p.A. minutes of March 19, 2024, p. 2). 

On April 15, 2024, the latter company also adopted a “document titled ‘ATF TK 1054336C – Bad Payer Rule Verification – Origination’; a document describing the “functional and technical logic used in the bad payer rule (origination system)” (see Hera S.p.A.’s note dated April 19, 2024, p. 1 and Attachment 1). 

The aforementioned procedure provides that, “where a potential customer in the open market requests the activation of a service with a Group company, the CRM (..) makes a call to SAP,” a system “used by Hera Group companies to manage a range of services, including billing and debt collection” (see Hera S.p.A.’s minutes of March 18, 2024, p. 3). 

Through this system, Hera S.p.A. “checks, based on the potential customer’s personal data (first name, last name, tax ID, and business partner), for any prior delinquencies, returning an ‘OK’ or ‘KO’ result. (…) The query, conducted online and in real time, concerns active, uncontested arrears relating solely to the energy sector in the deregulated market. Specifically, the amount of arrears that triggers a ‘KO’ result is [determined in the following cases]:

- at least one invoice overdue by more than 60 days with an amount exceeding €100;
- at least one installment overdue by more than 30 days with an amount exceeding €50;§
- receivables in the legal department’s management queue (e.g., terminated contracts subject to out-of-court collection with an amount exceeding €50)” (see Hera S.p.A. minutes of March 18, 2024, p. 3).

If “the internal checks result in an ‘OK,’ the external databases of Cerved Group S.p.A. and Experian Italia S.p.A. are also queried [via software provided by Major 1 S.r.l. and called “CGS-X”]. 

These “queries have been conducted [on behalf of Hera Comm S.p.A.] since 2021.” All of this “is based on a contractual package that requires the customer [i.e., Hera Comm S.p.A.] to sign three separate documents (..) with Cerved Group S.p.A., Experian Italia S.p.A., and Major 1 S.r.l., respectively.” 

The energy provider acts as an independent controller, designating Major 1 S.r.l.  —which acts as a technology outsourcing provider, supplying the license to use the “CGS-X” software—as the processor pursuant to Art. 28 of the Regulation (see Hera S.p.A.’s minutes of March 18, 2024, p. 3, and the minutes of Major 1 S.r.l. dated April 15, 2024, p. 3). 

If “the outcome of the internal checks results in a ‘KO,’ no further external checks are conducted” (see the minutes of Hera S.p.A. dated March 18, 2024, p. 3). 
The aforementioned “CGS-X” software enables Hera Comm S.p.A. to develop a risk profile regarding the creditworthiness of potential customers based on the integrated “CGS-X Score” indicator.

The latter is the result of combining the assessment indicators known as “ESX Score” (provided by Experian Italia S.p.A.) and “Retail Utilities Score” (provided by Cerved Group S.p.A.). 

More specifically, using the potential customer’s tax identification number, the “information systems of Cerved and Experian” are queried to retrieve the “Score Retail Utilities” from Cerved Group S.p.A.  and the “ESX Score” from Experian Italia S.p.A., together with the related sub-scores.” In response to this query, “Major 1 prepares an XML file containing the customer’s rating, (..), which is then transferred to Hera Spa’s systems.” This “is analyzed by SAP, which returns an OK/KO to the [Hera Comm S.p.A.] CRM based on acceptance thresholds set by Hera Spa’s [Credit] Policy (..). The query in SAP is generated from scratch for each new request to verify a potential customer’s creditworthiness and is valid only on the day it is made” (see Hera S.p.A. minutes of March 18, 2024, p. 4, and Major 1 S.r.l. minutes of April 15, 2024, p. 3). 

The XML format “is unique and contains a variety of information,” as indicated below:

A) “CGS-X Score for Individuals” — represented by a score “[OMISSIS], customized for each individual customer,” as well as an indicator “called class value [OMISSIS]”;

B) “SIC Details” — this is the response provided by Experian’s information systems and consists of the following items:

1) “Experian score” — a granular value corresponding to a reliability range (the so-called Experian index);
2) “[OMISSIS]”—[OMISSIS];
3) “Experian Index”—this is a value related to the credit risk profile [OMISSIS]”;

C) “Retail Score Info” — this refers to information pertaining to the so-called [Retail Utilities] Score provided by Cerved, which consists of several items:
1) “Information on Adverse Events” — [OMISSIS];
2) “Score class” – “[OMISSIS] score”;
3) “Score class before override” – a tool “for verification and reclassification in determining the class, [OMISSIS]”;
4) “Score value” – “a granular value corresponding to various ranges [OMISSIS]” (see the minutes of Major 1 S.r.l. dated April 16, 2024, pp. 2–4, and the minutes of Hera S.p.A. dated March 18, 2024, p. 4). 

In turn, the “Retail Utilities Score” is “the result of processing various sub-scores, which are also included in the XML file.” These are the following items:

A) “Subscore [OMISSIS]” — “a risk score applicable only to individuals, based on the personal information of the data subject (specifically, residence/place of birth and age) [OMISSIS]”;

B) “Subscore [OMISSIS]”;

C) “Subscore [OMISSIS]”—this is “a value reflecting the risk level of the data subject’s area of residence [OMISSIS]”;

D) “Subscore P4” – this is “the score [OMISSIS]” (see the minutes of Major 1 S.r.l. dated April 16, 2024, pp. 3–4).

On this point, it was clarified that, of all the information listed above and contained in the XML file, “Hera S.p.A. uses only that which refers to the so-called ‘class value’ [relating to the CGS-X Score for individuals bearing] [OMISSIS], automatically assigning a KO in the event of a rating greater than or equal to [OMISSIS]” (see Hera S.p.A.’s minutes of March 18, 2024, p. 4). 

It was also represented that the additional information contained in the XML schema is not used “for the purpose of verifying customer reliability,” but is nevertheless retained “for any future activities, including the improvement of the rating system” (see Hera S.p.A. minutes of March 18, 2024, p. 4). 

Inspections conducted at Hera S.p.A. revealed that “Credit Check data [conducted on behalf of Hera Comm S.p.A.] are retained in both cases of a positive outcome (OK) and a negative outcome (KO)” (see Hera S.p.A. minutes of March 18, 2024, pp. 4 and 5).

In particular, “the log of queries to external databases lists all the data contained in the various fields, including the Class Value and Experian Score assessments,” and “a total of approximately 700,000 queries are made per year” (see Hera S.p.A. minutes of March 18, 2024, pp. 4 and 5). 

More specifically, it was stated that in the years 2022, 2023, and 2024 (up to March 18, 2024), 1,003,657 individuals were subject to queries as part of the External Assessment phase of the Credit Check (Exhibit 3 of the Hera S.p.A. minutes of March 19, 2024).

Finally, a representative stated that, as of the date of the inspections, “a [group-wide] data retention policy [on the matter] had not been adopted (..) but that it [was] in the process of being defined” (see minutes of Hera S.p.A. dated March 18, 2024, p. 5).

This policy, in particular, “with specific reference to storage periods for the SAP system, (…) provided for a 10-year period from the date of recording of the last accounting document, where ‘accounting document’ means any document—including those of a non-tax nature—stored in SAP (for example, query reports from external databases)” (see Hera S.p.A. minutes of March 18, 2024, p. 5 and Annex 8).

2.2. Procedures for responding to data subject rights requests.

With regard to requests submitted by data subjects pursuant to Article 15 of the Regulation, although the Company responded within the time limits set forth in Article 12 of the Regulation, in its responses it limited itself to referring solely to the identification of a risk profile for the data subjects. 

In particular, data subjects were generally informed that the profile in question was the result of assessments conducted by Hera Comm S.p.A., based on evaluations involving the use of “indicators or scores derived through the use of automated scoring techniques or systems relating to (..) data” (see Hera Comm S.p.A.’s notes dated August 17, 2022, August 29, 2023, and August 25, 2023). 

The Company informed the data subjects that the aforementioned assessments were “the result of checks carried out, among other things, by consulting systems containing information from public sources (managed by Cerved) and credit information systems (managed by Experian)”; such consultation “yielded a summary score” (see Hera Comm S.p.A.’s notice dated August 25, 2023; see also the Company’s notices dated August 17, 2022, and August 29, 2023). 

In these responses, Hera Comm S.p.A. clarified that it was not aware of all the detailed elements pertaining to the aforementioned score and therefore invited data subjects to contact Cerved Group S.p.A. and Experian Italia S.p.A. directly for further information on the matter (see Hera Comm S.p.A.’s notes dated August 17, 2022, August 29, 2023, and August 25, 2023).

During the investigations, it was further ascertained that, in none of the cases subject to complaint, did the aforementioned findings refer to the “CGS-X Score” and the related sub-scores assigned to the data subject.

This was the case even though it emerged that Hera S.p.A.’s systems contained the queries made to Major 1 S.r.l. regarding the tax identification numbers of the complainants, as well as the XML files of the responses sent by Major 1 S.r.l. to Hera S.p.A. 

Likewise, it was established that the Company systematically retains data pertaining to the queries and the aforementioned files regarding potential customers data subjects of credit checks (see Hera S.p.A.’s report dated March 19, 2024, pp. 1, 3, and 4, and Attachments Nos. 1 and 10; see also Hera S.p.A.’s minutes of March 20, 2024, pp. 1 and 3, and Attachments Nos. 1 and 7).

2.3. The refinement of the Hera Group’s customer rating service.

The information contained in the aforementioned XML file referring to the “CGS-X Score”—other than the “class value” (see above)—“is not currently used [by Hera Comm S.p.A.] to assess customer creditworthiness” (see Hera S.p.A. minutes of March 20, 2024, p. 2). 
In fact, this information “is stored and used to conduct an analysis currently underway aimed at potentially refining the rating service provided to group companies” (see Hera S.p.A.’s minutes of March 19, 2024, p. 3). 

This activity includes “the analysis of data relating to customer creditworthiness and the risk profiles of the customer base” and is carried out by Hera S.p.A. “in its capacity as processor, in the name and on behalf of the energy sales companies Hera Comm (..) and EstEnergy” within a specific department of Hera S.p.A. called “Credit Management” (see minutes of Hera S.p.A. dated March 20, 2024, p. 2).

The data analyzed by the aforementioned department pertains to “all requests for contract establishment—concerning both electricity and gas—relating to individual customers (..) for which an external assessment was conducted by consulting the database of Cerved Group S.p.A.” and that of Experian Italia S.p.A. (see Hera S.p.A. note dated April 19, 2024, p. 2). 

These analyses—for which the legend of the relevant fields has been obtained (see Annex No. 2 to Hera S.p.A.’s note dated April 19, 2024)— “are performed by Hera S.p.A. approximately once a month using constantly updated data” (see Hera S.p.A.’s minutes of March 20, 2024, p. 2). 

The aforementioned “data, which reside on SAP SFCM, are [stored in a], (..), group data warehouse, into which data relating to the so-called customer account statement are also fed” (see Hera S.p.A. minutes of March 20, 2024, p. 2). 

This data is also analyzed using specific data analysis applications or through the use of Excel (see Hera S.p.A. minutes of March 20, p. 2). All of this is done with a view toward “a possible refinement of the Hera Group’s customer rating service” (see Hera S.p.A. minutes of March 20, 2024, p. 2). 

By way of example, Hera S.p.A. had a representative who stated that, with reference to the year 2022, the activity described above involved “approximately 500,000 queries regarding individual customers made by Hera S.p.A. to external databases in 2022” (see Hera S.p.A.’s minutes of March 20, 2024, p. 2). 

It was also established that the data processing activity described above began in 2022 and that, in total, during the years 2022, 2023, and 2024 (through March 18), it involved 1,003,657 individuals (Annex 3 of the Hera S.p.A. minutes of March 19, 2024). 

In particular, during the inspections, the auditors examined “a sample report of the analysis conducted on customers who entered the origination process in 2022, with account statement data updated as of today, which shows outstanding and past-due credit balances for various types of account activation (transfer, switch, first activation…) and by risk class (class value, with values 1–6)” (see Hera S.p.A. minutes of March 20, 2024, p. 2).

3. The notification pursuant to Article 166, paragraph 5, of the Code.

Following the allegation of violations under Articles 5(1)(a), 12, and 15 of the Regulation, sent to Hera Comm S.p.A. by notice dated July 14, 2025, the Company, by letter dated October 10, 2025, submitted its defense briefs, which were further supplemented during the hearing on May 20, 2026, and by a subsequent letter dated May 29, 2026.

In the aforementioned briefs, Hera Comm S.p.A. made the following representations:

a) regarding the allegation concerning the unlawfulness of the processing of potential customers’ data in the context of the so-called “Internal Assessment of Past Delinquencies,” “a joint controller agreement was signed between Hera Comm and EstEnergy, pursuant to Art. 26 of the Regulation”. This was done with the aim of jointly sharing, storing, and processing the personal data collected by the companies for the purpose of verifying the creditworthiness of customers in the free market segment for electricity and natural gas. This processing is designed to safeguard the financial stability of the Hera Group and minimize exposure to the risk of insolvency by acquiring customers who are financially sound and creditworthy. In conclusion, this activity represents “an essential safeguard aimed at ensuring the reliability of supplies and the economic sustainability of sales operations in the free market” (see note dated October 10, 2025, p. 3). Following the signing of the aforementioned joint-controller agreement, “the relevant notices provided to customers have been updated to ensure full transparency regarding data processing,” including with regard to the new structure of shared roles and accountability (see note dated October 10, 2025, p. 4; see also the note dated May 29, 2026, pp. 1–2);

b) regarding the alleged violation concerning the inadequate responses provided to data subjects who had exercised their right of access pursuant to Article 15 of the Regulation, the Company, “not being aware of all the evidence taken into account to produce [the CGS-X score] nor, much less, the logic behind the processing and production of the assessment itself, made available to the data subject all the information in its possession for which it could provide an explanation.” In particular, “rather than providing incomplete information or information that might have given the impression of being inaccurate, the Company deemed it more protective to simply invite the data subject to contact the external providers, while also providing all relevant contact channels for that purpose.” Although the Company had access to the “CGS-X Score” and its related sub-scores, “the information contained therein was neither intelligible nor useful for the purpose of drafting the response to be sent to the data subject.” Hera Comm S.p.A. also had a representative who stated that, as of today, it no longer uses the “CGS-X” service provided by Major 1 S.r.l., having adopted, with regard to external assessment activities, a “new system that provides only the summary score and no longer the analytical sub-scores.” Furthermore, new “response templates, (..) enhanced with additional elements aimed at ensuring a more complete representation of the information processed and at strengthening transparency toward customers” have been prepared (see note dated October 10, 2025, pp. 5–8 and Annex 3);

c) regarding the retention periods for customer data in connection with external assessment activities, which were deemed non-compliant with the storage limitation principle, the Company “has developed and progressively implemented a specific data retention policy for credit data, which defines specific periods of storage and automated procedures for erasure upon the expiration of the established periods, in full compliance with Article 5, paragraph 1, letter e) of the GDPR” (see note dated October 10, 2025, p. 8, and note dated May 29, 2026, pp. 2–3, and Annex 1);

d) regarding the alleged unlawfulness of the analysis of customers’ personal data collected as part of the Credit Check, aimed at refining the Hera Group’s customer rating assessment system, it was stated that “the purpose of the processing (..) was statistical in nature, and the reports generated were intended solely to provide management with a basis for evaluating potential revisions to the scoring parameters.” On this point, Hera Comm S.p.A. emphasized that, to date, this activity has had no “effect [on] individual contract processing cases (..) since the analyses did not affect the outcome of individual cases, nor were they used to determine automated decisions” (see note dated October 10, 2025, p. 9). 

Finally, regarding the factors to be taken into account for the purpose of determining the amount of any penalty—among those identified in Article 83(2) of the Regulation—the Company stated that “the ‘credit check’ activity,” which is the subject of the proceedings, concerns only a portion of the processing of customers’ personal data carried out by Hera Comm S.p.A.; this is because the aforementioned activity is “carried out solely with respect to residential customers requesting the activation of electricity and gas supply contracts in the free market, as well as with respect to customers requesting the activation of contracts under the gas vulnerability protection program”  (see note dated May 29, 2026, p. 4). 

The Company also highlighted that, in order to ensure full compliance of the processing activities in question with the Regulation, it has adopted certain measures, including organizational ones, such as “bringing responses to requests for clarification regarding the failure to enter into contracts under the oversight of the privacy department” (note dated May 29, 2026, p. 3). 

Finally, it was noted that, during the preliminary investigation, Hera Comm S.p.A. promptly and proactively “abandoned the project related to the refinement of the customer rating assessment system” (see note dated May 29, 2026, p. 2).

Moreover, this project “never saw the light of day because the suspension of activities occurred during a preparatory phase prior to its launch” and “therefore, no actual infringement of the data subject rights ever occurred (…), since the analyses did not affect the outcome of individual cases, nor were they used to determine automated decisions” (see note of May 29, 2026, pp. 2–3, and see note of October 10, 2025, p. 9).

4. The Authority’s Assessments.

First of all, it should be noted that, unless the act constitutes a more serious offense, anyone who, in proceedings before the Data Protection Authority, falsely declares or attests to facts or circumstances, or produces false records or documents, is liable under Art. 168 of the Code, “False Statements to the Data Protection Authority and Interruption of the Performance of the Authority’s Duties or Exercise of Its Powers.” 
In light of the evidence gathered during the preliminary investigation described above, as well as the subsequent assessments conducted, the following violations by Hera Comm S.p.A. have been identified.

4.1. The Unlawfulness of Customer Data Processing for the Purpose of Verifying Any Past Delinquencies (so-called “Internal Assessment”)

First, reference is made to the policy—known as “Credit Check”—which introduces, at the group level, a system for verifying the creditworthiness and reliability of individuals intending to sign up for electricity and/or natural gas service on the open market. 

This policy “is uniform across all group companies operating in the free energy market sector and (…) provides that, when a potential customer in the free market requests the activation of a service with a group company,” a “verification is first conducted, based on the personal data (..) of the potential customer, to determine whether there are any past payment arrears” (see Hera S.p.A. minutes of March 18, 2024, p. 3). 

More specifically, Hera Comm S.p.A., in accordance with this procedure, conducts—in response to requests from its potential customers— the so-called “Internal Assessment,” which consists of verifying whether the potential customer has any outstanding arrears related to energy supply contracts in the open market, including those established with other Group companies.

Specifically, this activity is carried out by Hera S.p.A., on behalf of Hera Comm S.p.A., pursuant to the “Agreement for the Management of Administrative, Financial, and Control Activities,” signed on July 18, 2013, by the Companies, and the related “Addendum” dated July 3, 2023. 

Hera S.p.A., in fact, carries out “on a centralized basis within the Group (..) the activity of assessing customers’ creditworthiness.” To this end, Hera Comm S.p.A. has appointed Hera S.p.A. as the processor pursuant to Article 28 of the Regulation (see Hera S.p.A. minutes of March 18, 2024, p. 2 and Annex 2).

On this point, it has emerged in particular that, in carrying out the aforementioned assessment, Hera Comm S.p.A. takes into account not only the potential customer’s delinquencies recorded in its own systems but also information regarding any additional past delinquencies the customer may have had with EstEnergy S.p.A. 

Upon completion of this check, Hera S.p.A. provides a response of “OK” in the event of a positive outcome, or “KO” in the event of a negative outcome (see Hera S.p.A.’s report dated March 18, 2024, p. 3, and Hera S.p.A.’s note dated April 19, 2024, p. 1). 

The activity described above, carried out through the processor Hera S.p.A., therefore effectively involves the sharing of customer data among Group companies operating as energy suppliers; This sharing pertains to personal information regarding customers’ past delinquencies, as identified by the procedure titled “Rules for Private Customer Onboarding” (such as, for example, unpaid invoices, overdue installments under a repayment plan, debts referred for legal collection), as well as information regarding the summary “OK/KO” assessments pertaining to individual data subjects (see Annex 3 of the Hera S.p.A. minutes dated March 18, 2024). 

With regard to this specific data processing activity, Hera Comm S.p.A. failed to inform the data subjects in accordance with Articles 13 and 14 of the Regulation. 

The privacy notice provided by the Company at the time the customer signed the contract does not, in fact, contain any information regarding the aforementioned activity or the aforementioned categories of personal data (see the attachment titled “Plico Famiglie HC-January 2023” in the Hera Comm S.p.A. notice dated March 21, 2025).

Furthermore, the privacy notice merely states in general terms that “[customers’] personal data may be disclosed to companies of the Hera Group and/or to third parties contractually linked to the Group companies,” without making any specific reference to the transfer of the aforementioned data between Hera Comm S.p.A. and EstEnergy S.p.A. carried out for the purpose of internal evaluation (see the attachment titled “HC Household Package—January 2023” in the Hera Comm S.p.A. notice dated March 21, 2025). 

In light of the above, it is clear that the information provided to data subjects by Hera Comm S.p.A. is inadequate, as it contains no information regarding the processing operations related to the Company’s internal customer assessment activities. All of this constitutes a violation of Article 5(1)(a), as well as Articles 13 and 14 of the Regulation.

It should also be noted that, with respect to the aforementioned activity, the instructions provided by Hera Comm S.p.A., pursuant to Art. 28 of the Regulation, to the processor Hera S.p.A., do not include the processing operations consisting of verifying past delinquencies of customers related to EstEnergy S.p.A. 

In fact, within the designation document pursuant to Article 28 of the Regulation signed on July 3, 2023, by Hera Comm S.p.A. and Hera S.p.A., no reference was found to the mandate to process, as part of the pursuit of the aforementioned specific purposes, information pertaining to EstEnergy S.p.A.’s customers. 

The aforementioned designation agreement is in fact limited to providing that Hera S.p.A. performs, on behalf of Hera Comm S.p.A., services related to the activity of “In-depth support for the analysis of the origination of [its own] Customer Base” (see Annex 2 “Addendum” to the “Contract for the Management of Administrative, Financial, and Control Activities,” from the minutes of March 18, 2024). Consequently, Hera Comm S.p.A. has violated Article 28 of the Regulation.

Without prejudice to the foregoing, it is also acknowledged that the Joint Controller Agreement between Hera Comm S.p.A. and EstEnergy S.p.A., pursuant to Article 26 of the Regulation, under the terms described in paragraph 3, subparagraph a) of this decision, as well as the resulting update to the customer disclosure templates pursuant to Article 13 of the Regulation.

More specifically, it is noted that the aforementioned Agreement defines the respective levels of accountability regarding the processing of data pertaining to the internal verification of customer creditworthiness.

This internal audit is carried out jointly by Hera Comm S.p.A. and EstEnergy S.p.A. pursuant to Article 6, para 1, subparagraph (f) of the Regulation, to pursue the legitimate interests of the Companies, given the need to ensure the financial soundness of the Companies themselves, as well as that of the Hera Group as a whole, and to minimize exposure to the risk of non-payment by customers (see, in this regard, Recital 47 of the Regulation).

In this regard, the reasonable expectations of the data subjects with respect to the processing in question are also taken into account, given that it involves exclusively companies belonging to the same group and is at the same time limited solely to the pre-contractual phase, as well as restricted to the specific sector of energy and gas supply in the liberalized market (see, in this regard, European Data Protection Board, “Guidelines 1/2024 on the processing of personal data based on article 6(1)(f) of the GDPR,” adopted on October 8, 2024, paragraphs 31–60).

Finally, it should also be noted that, under the aforementioned Joint Controller Agreement, Hera Comm S.p.A., together with EstEnergy S.p.A., undertakes to designate Hera S.p.A., in relation to the performance of operations connected with the so-called Internal Assessment, as the processor pursuant to Article 28 of the Regulation (see Article 8 of the aforementioned Agreement). 

In light of the foregoing, the processing of customer data carried out by Hera Comm S.p.A. up to the date of signing the aforementioned Joint Controller Agreement for the purpose of verifying any past delinquencies within the scope of the so-called Internal Assessment, is unlawful as it violates Articles 5(1)(a), 13, 14, and 28 of the Regulation.

4.2. Violations regarding the exercise of rights and the principle of storage limitation.

Based on the evidence gathered during the preliminary investigation as well as subsequent assessments, it has been established that Hera Comm S.p.A. provided inadequate and incomplete responses to requests to exercise rights pursuant to Articles 15–22 of the Regulation submitted by the data subjects. 

In fact, these responses merely contained a reference to the identification of a risk profile for the data subjects, without providing either the “CGS-X Score” or the related sub-scores assigned to the data subject, nor any information regarding the logic used to develop said profile. “CGS-X Score” and the related sub-scores assigned to the data subject, nor any information on the logic used to develop said profile. 

More specifically, in all the responses subject to the complaint, Hera Comm S.p.A. stated that it was unaware of the detailed elements pertaining to the “CGS-X Score.” In particular, asserting that it was unaware of “all the evidence taken into account to produce the [aforementioned] integrated assessment, nor, much less, the logic used to process and produce the assessment itself,” it invited the data subjects to contact Cerved Group S.p.A. and to Experian Italia S.p.A. in order to obtain further information on the matter (see note dated October 10, 2025, p. 5).

All of this occurred even though the information in question was, in fact—as ascertained during the on-site inspections—present in the data controller’s systems (see supra, para. 2.2 of this notice of violation). 
In this regard, it should be noted that, in light of the current regulatory framework governing data protection with respect to the exercise of data subject rights, pursuant to Article 15(1) of the Regulation, “the data subject has the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, to obtain access to the personal data and [certain] information” specified in that provision.

The recipient of the request made pursuant to Article 15 of the Regulation is therefore the controller—in this case, Hera Comm S.p.A.—to whom the request was submitted; the data controller is, in fact, required, pursuant to Article 12(3) of the Regulation, to provide the data subject with all personal information subject to such processing.

It follows, therefore, that the Company’s argument on this point, as set forth in paragraph 3(b) of this decision, cannot be accepted, since the obligation outlined above—pursuant to Articles 12 and 15 of the Regulation—rests first and foremost with the Company itself, as the controller in question.

It is also worth noting that the right of access under Article 15 of the Regulation is primarily conceived as a tool designed, in general terms, the data subject to exercise “control” over the personal data concerning him or her, ensuring that the data subject is fully aware of the information being processed and the actual methods of such processing. 

The purpose of the right of access is therefore primarily to disclose “what” data and “how” it has been processed by the controller in order to provide the data subject with the means to “know and verify the lawfulness and accuracy of the processing” concerning them (see Recital 63 of the Regulation; European Data Protection Board, “Guideline 1/2022 on the Data Subject Rights—Right of Access,” op. cit., paragraphs 10–13). 

Pursuant to Article 15 of the Regulation, therefore, the data controller, when responding to a request for access, may not limit itself to providing “a general description of the data [or] a mere reference to the categories of data processed,” nor may it omit information in its possession that relates to the data subject; on the contrary, the controller is required to provide access to “all the information referred to in Article 15” pertaining to the data subject and actually subject to processing.

Such information “must be complete, accurate, and up-to-date, reflecting as far as possible the status of the data processing at the time the request was received” and must be provided “in a concise, transparent, intelligible, and easily accessible form” to the data subject (see European Data Protection Board, “Guideline 1/2022 on the Rights of Data Subjects—Right of Access,” op. cit., para. 34; Article 12(1) of the Regulation). 

It should also be noted that, in the case at hand, the specific context (processing aimed at generating a score regarding customer reliability), which underlies the requests to exercise the right of access submitted by the data subjects, requires particular attention on the part of the controller, including with regard to the obligation to provide “meaningful information on the logic used, as well as [on] the significance and [on] the anticipated consequences of such processing for the data subject” (Art. 15(1)(h) of the Regulation). 

With regard to the aforementioned provision, the Court of Justice of the European Union has recently provided useful practical guidance—both substantively, regarding the type of information that the data subject may require from the controller, and formally, regarding the manner in which such information must be provided by the controller (see CJEU judgement of February 27, 2025, C-203/22). 

In particular, in clarifying the phrase “meaningful information on the logic used,” the Court specified that this refers to “any relevant information concerning the procedure and principles of the automated processing of personal data for the purpose of achieving a specific result” (see para. 58, CJEU judgement No. C-203/22, cited above).

It follows, therefore, that the data subjects, in the case at hand, have the right to be fully informed of all the elements comprising the assessment of their creditworthiness, including those taken into account by the data controller for the purpose of assigning the score, as well as the calculation criteria used (see, in this regard, Order of the Court of Cassation No. 14381 of May 25, 2021). 

With regard to the manner in which the aforementioned information must be provided, the Court of Justice of the European Union has reaffirmed the data controller’s obligation to provide it “in a concise, transparent, intelligible, and easily accessible form, using plain and clear language”; all in compliance with the principle of transparency set forth in Article 12(1) of the Regulation. Therefore, “neither the mere communication of a complex mathematical formula, such as an algorithm, nor a detailed description of all the stages of automated decision-making can satisfy these requirements, since neither of these methods would constitute a sufficiently concise and comprehensible explanation” (paragraphs 58–59, CJEU judgement No. C-203/22, cited above). 

Overall, the requirement to provide “meaningful information on the logic used,” pursuant to Article 15(1)(h) of the Regulation, thus amounts to an obligation on the part of the controller to “describe the procedure and the principles actually applied in such a way that the data subject can understand which of [his or her] personal data have been used and how (...), without the complexity of the operations to be carried out in the context of the automated decision-making process exempting the controller from its duty to explain” (para. 61, CJEU Judgement No. C-203/22, cited above).

In light of the foregoing, it follows that Hera Comm S.p.A., in the cases at hand, acted in violation of Articles 12 and 15 of the Regulation, given that it did not provide the data subjects with any information regarding the “CGS-X Score,” on the basis of which the request to activate energy supply was denied, nor regarding the additional scores (so-called “sub-scores”) that contributed to generating the aforementioned “CGS-X Score.” Furthermore, the Company did not inform the applicants of the logic and criteria applied to the calculation system underlying the development of the credit risk profile. 

This, therefore, effectively prevented the applicants from accessing the types of personal information actually used for this purpose, as well as from understanding how such information was used. 

The inadequacy of the responses provided by Hera Comm S.p.A. therefore did not enable the data subject to ascertain the lawfulness and fairness of the processing, nor the accuracy of the data used in the context in question, thereby compromising the data subject’s ability to exercise, where applicable, the right to rectification in the event of inaccurate and/or incomplete data (see Art. 16 of the Regulation), as well as the right to “obtain human intervention from the controller, [to] express their opinion and contest the decision” taken against them by the controller (see Art. 22(3) of the Regulation).

All of this—given the particularly sensitive nature of the information processed by Hera Comm S.p.A. in the case at hand, as it pertains to customers’ creditworthiness—carries the risk of adverse consequences for the fundamental rights and freedoms of the data subjects (such as, for example, as occurred in the cases under review, the refusal to enter into an energy supply contract). 
It should also be noted that, due to the Company’s conduct, the data subjects incurred additional costs and delays, given the burden of having to submit further requests pursuant to Article 15 of the Regulation, including to Cerved Group S.p.A. and Experian Italia S.p.A., in order to obtain information that was, in fact, fully available to Hera Comm S.p.A.

On this point, while taking note of the new response templates adopted by the Company in cases where supply is denied based on its customer acceptance policies, as set forth in Annex 3 of the note dated October 10, 2025, it should be noted that even these templates do not yet contain all the elements required by Article 15 of the Regulation, as specified above.

In light of the foregoing, Hera Comm S.p.A. is therefore found to be in violation of Articles 12 and 15 of the Regulation. 

Finally, it is noted that, with regard to the processing of customers’ personal data collected as part of the aforementioned external assessment, additional violations were identified concerning the storage periods for the data of the aforementioned data subjects.

Specifically, on this point, it has been established that Hera Comm S.p.A., at the time of the on-site inspections, did not have specific storage periods regarding the storage of customer data collected for the purpose of the External Assessment and that, within the data retention policy—which was still being finalized at the time—a ten-year storage period, generically applicable to accounting documentation, had been identified for such personal data (see Annex 8 of the minutes of March 18, 2024). 

In this regard, it should be noted that Article 5(1)(e) of the Regulation provides that personal data must be retained in a form that permits identification of the data subject for no longer than is necessary to fulfill the processing purpose.

The storage principle, in fact, imposes on the controller the obligation to assess the duration of processing in necessary correlation with the specific purposes established in advance at the time of collection; this is to “ensure that the retention period for personal data is limited to the minimum necessary” (see Recital 39 of the Regulation). 

This is, in fact, the controller’s obligation to ensure an “appropriate” duration of processing, which, otherwise, could extend beyond the achievement of the specific processing purposes, thereby affecting the principles of lawfulness, fairness, and transparency (Article 5 of the Regulation).

With regard to the data processing in question, it should therefore be noted, first and foremost, that at the time of the inspection, Hera Comm S.p.A. had not established specific periods of storage. 

It is also noted that, although a data retention policy was in the process of being adopted at the time, the Company did not specifically indicate in that policy the reasons for applying the ten-year storage period—generally required for accounting records—to such processing, nor was the compliance of this provision with what is strictly necessary to achieve the processing purpose duly justified. 

It follows that Hera Comm S.p.A. acted in violation of Article 5(1)(e) of the Regulation. 

On this point, however, it is acknowledged that in February 2026, the Company adopted an updated version of its Data Retention Policy (the so-called “Data Retention Policy”), in which a specific five-year storage period was established for personal data processed for the purpose of verifying customers’ creditworthiness (see Annex 1 of the note dated May 29, 2026, p. 2).

4.3. The Unlawfulness of the Processing Carried Out as Part of the Group’s Efforts to Refine Its Customer Rating System.

Following the inspection findings, it also emerged that Hera Comm S.p.A., through Hera S.p.A., which has been designated as the processor, conducts an analysis of customers’ personal data acquired as part of the Credit Check; all with the aim of refining the Hera Group’s customer credit rating assessment system (see Hera S.p.A.’s report of March 20, 2024, p. 2). 

More specifically, this activity consists of “monitoring the risk profile of the Group’s credit portfolio through the analysis of both internal and external credit and financial data,” aimed at defining the “rules for assessing the customer’s risk profile and monitoring their effectiveness” (see Annex 4 of the Hera S.p.A. minutes of March 20, 2024).  

To this end, since 2022, the Company has been retaining information regarding “all requests for contract establishment—concerning both electricity and gas—relating to individual customers (..) for which an external assessment was conducted by consulting the database of Cerved Group S.p.A. [and Experian Italia S.p.A.]” (see Hera S.p.A.’s note dated April 19, 2024, p. 2). 

This refers to the information obtained by Hera Comm S.p.A. as part of the external assessment process and contained in the XML file containing the customer’s rating; specifically, this information pertains to data relating to the “CGS-X Score,” “SIC Details,” and “Retail Score Info,” as well as the sub-scores included in the aforementioned items (see, in greater detail, para 2.1. above). 

Also subject to the aforementioned analysis are customers’ personal data—relating to past delinquencies—collected by the Company for the purposes of the internal assessment (see Hera S.p.A.’s minutes of March 20, 2024, p. 2; see also Annex 2 of the Hera S.p.A. note dated April 19, 2024, and Annex 8 of the Hera S.p.A. minutes dated March 20, 2024). 

With regard to the processing of the personal information described above, which Hera Comm S.p.A. obtains from Experian Italia S.p.A. and Cerved Group S.p.A., the following points should be highlighted.

First, it should be noted that the processing of data provided by Experian Italia S.p.A., within the framework of the Credit Information System (known as SIC), is lawfully carried out, provided that the specific regulatory provisions governing the sector are complied with (see Art. 6-bis of Law No. 148 of September 14, 2011; Art. 30-ter of Legislative Decree No. 141/2010; see also Law No. 124/2017), as well as the provisions of the Code of Conduct for information systems managed by private entities regarding consumer credit, creditworthiness, and timely payments (hereinafter the “SIC Code of Conduct,” adopted by resolution of the Data Protection Authority on October 6, 2022, and available on the Authority’s website under web document No. 9818201). 

The SIC Code of Conduct establishes adequate safeguards to protect the rights of data subjects and sets forth specific rules of conduct that industry operators are required to follow in order to demonstrate that the processing complies with the Regulation (see Recital 77 and Articles 24(3), para 3), 32(para 3), and 28(para 5) of the Regulation). 

On this point, the legislature has intervened on several occasions to grant access to the data contained in the aforementioned SICs to various parties, including—currently, pursuant to Article 6-bis, of Decree-Law 138/2011 and Art. 30-ter of Legislative Decree 141/2010, “including entities authorized to sell electricity and natural gas to end customers pursuant to applicable law.” 

Pursuant to the aforementioned provisions, “such entities (so-called “accessors”) (..) are authorized to consult the personal data contained in the SICs, entering into specific agreements for this purpose with one or more SIC operators” (see, in this regard, points 5 and 6 of the “Preamble” to the aforementioned SIC Code of Conduct). 

In accordance with this provision, on November 3, 2021, Hera Comm S.p.A. and Experian Italia S.p.A. signed the agreement titled “General Terms and Conditions” (see Annex 6 and related attachments to the minutes of Hera S.p.A. dated March 19, 2024, and Annex 5 to the minutes of Hera S.p.A. dated March 18, 2024).

In light of the foregoing, Hera Comm S.p.A., as the data recipient, may process the information obtained from the SIC “exclusively for purposes related to the assessment, assumption, or management of credit risk, [as well as] for the assessment of the creditworthiness and payment punctuality [of the potential customer]” who has requested to establish a contractual relationship with the Company (see Art 3, Art 8, paragraph 1, and Art 18, paragraph 1, of the SIC Code of Conduct).

More broadly, the aforementioned agreement of November 3, 2021, provides that Hera Comm S.p.A., as a member “of one of the categories of entities referred to in paragraph 5 of Article 30-ter of Legislative Decree No. 141 of August 13, 2010, No. 141, (..) may (..) have access to the SIC Experian system with the right to consult the data contained therein within the limits of the Permitted Purposes and in accordance with the terms and conditions set forth in these Special Conditions, the General Conditions, and the SIC Code of Conduct” (see Articles 1.2 and 6.1 of “Annex 1 to the General Terms and Conditions – Special Terms and Conditions”).

In this regard, it is worth noting that all parties accessing the SICs must comply with the principle of purpose limitation, which consists of credit protection and the mitigation of related risk, by virtue of which the consultation of a data subject’s personal data may take place only if strictly related to the processing of a request aimed at establishing a relationship with said data subject. 

Therefore, the processing of data obtained from the SICs is unlawful if carried out for additional purposes or, in any case, not specifically related to a request by a potential customer to enter into a contract with the participant/accessor (see, among others, the decision of the Data Protection Authority dated July 31, 2002, web doc. no. 30000; ruling dated May 4, 2002, web doc. no. 1302311; Decision of May 4, 2006, web doc. no. 1302373).

With specific reference to the case at hand, in light of the principles set forth above, it follows that the processing operations of data acquired from Experian Italia S.p.A., carried out by Hera Comm S.p.A. for the purpose of refining the customer credit rating system, are conducted in violation of Article 5(1)(b) of the Regulation. 

This is because—contrary to what the Company asserted in accordance with paragraph 3(d) of this decision—such processing is aimed at pursuing an additional purpose that is incompatible with the original purpose underlying the collection of the aforementioned personal data.  

Similar considerations apply to the processing carried out by Hera Comm S.p.A. concerning the commercial information it obtained from Cerved Group S.p.A.

On this point, it should be noted that commercial information activities are carried out subject to a specific prefectural license issued pursuant to Art. 134 of the Consolidated Law on Public Security (Royal Decree No. 773/1931, as amended and supplemented), and that such activity is governed by specific provisions that define its characteristics and methods of operation(see Ministerial Decree No. 269 of December 1, 2010, and Ministerial Decree No. 56 of February 25, 2015, as well as Royal Decree No. 773/1931).

Within this regulatory framework, the processing of personal data in question must be carried out in accordance with the Code of Conduct for the Processing of Personal Data in the Field of Commercial Information (hereinafter the “Code of Conduct for Commercial Information”), adopted by the Data Protection Authority by resolution dated April 29, 2021 (available on the Authority’s website as Web Doc. No. 9586215). 

The Code of Conduct provides that commercial information shall be provided to clients for the purpose of conducting “checks on the economic, financial, and asset situation of the data subjects, as well as on their soundness, solvency, and reliability,” with the purpose of establishing and managing relationships—including pre-contractual ones—with the data subjects and providing them with goods, services, and performance (see Articles 2, paragraph 2, letter c), and 6 of the Code of Conduct on Commercial Information).

All of this is based on specific agreements entered into with commercial information service providers, such as the one signed, in the case at hand, on November 3, 2021, by Hera S.p.A., in the name and on behalf of Hera Comm S.p.A., and by Cerved Group S.p.A. (see Annex 4, “Contract for the Provision of Commercial Information Services,” of the minutes of Hera S.p.A. dated March 18, 2024); a contract that, specifically, concerns the provision of a service aimed at “the implementation and rollout of scorecards for the onboarding of new customers” (see also the Preamble to the “Financial Terms—Access to Cerved & Experian Services During the Evaluation Phase Through the Adoption of Integrated Models for the Retail and Business Segments,” in the minutes of Hera S.p.A. dated March 18, 2024, Appendix 4).  

This agreement, in accordance with the provisions of the Code of Conduct for Commercial Information, stipulates that “all personal data [collected] during the term of the Contract shall be processed by each of the Parties solely for the purposes specified in the Contract and in a manner necessary for the performance thereof, as well as to comply with any legal obligations, EU regulations, and/or requirements of the Data Protection Authority” (see Art. 23.1 of the “Contract for the Provision of Commercial Information Services,” from the minutes of Hera S.p.A. dated March 18, 2024, Annex 4).

It follows, therefore, that the personal information acquired, in this specific case, by Hera Comm S.p.A., from Cerved Group S.p.A., may not be processed for additional purposes that are incompatible with those identified in the Agreement and in the aforementioned Code of Conduct for Commercial Information, which are aimed at assessing the reliability of a potential customer for the purpose of deciding whether or not to accept their request to establish a contractual relationship. 

The processing carried out by the Company with respect to the aforementioned personal data is therefore unlawful pursuant to Article 5(1)(b) of the Regulation.

Finally, it should also be noted that the overall customer data processing operations carried out by Hera Comm S.p.A. in the present case involve long-term storage of information obtained from Experian Italia S.p.A. and Cerved Group S.p.A. for subsequent processing aimed at refining the Hera Group’s customer rating assessment system.

In the case at hand, the storage of processed data for possible (re)use creates the risk that, over time, the data originally collected from the databases managed by Experian Italia S.p.A. and Cerved Group S.p.A., and subsequently retained by Hera Comm S.p.A., may change and therefore no longer be up to date. 

This is because data processing for commercial information purposes and that related to the management of a SIC —both of which, moreover, are carried out by companies specialized in these fields and, in the case of commercial information, specifically authorized by a prefectural license—are governed by specific regulatory and ethical provisions aimed at ensuring, among other things, the accuracy of the data made available to clients.

The processing carried out by Hera Comm S.p.A. in the manner described above therefore also constitutes a violation of the principle of accuracy set forth in Art. 5, para. 1, letter d) of the Regulation. 

It should also be noted that the processing of outdated data, as defined in this paragraph—given the specific nature of the aforementioned information (pertaining to the creditworthiness of the data subjects) and its impact on the decisions made by the Company regarding its customers— could result in adverse consequences for the fundamental rights and freedoms of the data subjects. 

Finally, it should be noted that the processing activity described above has been carried out since 2022 and that, in the years 2022, 2023, and 2024 (through March 18), it involved 1,003,657 individuals (Annex 3 of the Hera S.p.A. minutes dated March 19, 2024). 

Taking all of the above recitals into account, Hera Comm S.p.A. is therefore found to have violated Article 5, para 1, subparagraphs (a), (b), and (d) of the Regulation.

5. Conclusions: Declaration that the processing is unlawful. Corrective measures pursuant to Art. 58(2) of the Regulation.

In light of the overall findings, the Authority considers that the statements, documentation, and explanations provided by the controller during the investigation do not sufficiently address the objections notified by the Office in thenotice initiating the proceedings and are therefore insufficient to warrant the dismissal of this proceeding, as none of the cases provided for in Art. 11 of the Data Protection Authority’s Regulation No. 1/2019 apply.

The processing of personal data carried out by Hera Comm S.p.A., which is the subject of this decision, was therefore conducted in violation of Article 5(1)(a), (b), (d), and (e); as well as Articles 12, 13, 14, 15, and 28 of the Regulation. 

With regard to the exercise of the corrective powers referred to in Article 58, para 2, of the Regulation, it is first noted that Hera Comm S.p.A., during the proceedings, voluntarily adopted certain initial measures aimed at bringing the processing of customer data into compliance with the Regulation, in accordance with the regulatory framework described above. 

Specific reference is made to the adoption of the Joint Controller Agreement dated August 1, 2024; the update, effective February 2026, of the so-called “Data Retention Policy”; as well as the cessation of all processing activities carried out through the analysis of customers’ personal data collected as part of the Credit Check, for the purpose of refining the Hera Group’s customer rating assessment system (see above, paragraphs 3(d), 4.1. and 4.2. of this decision). 

Notwithstanding the foregoing, in light of the additional critical issues identified with respect to the controller, as detailed in this decision, it is deemed necessary to order the controller, pursuant to Article 58(2)(c) and (d) of the Regulation, to implement the following corrective measures:

a) the development of a new template for responding to requests for access, pursuant to Art 15 of the Regulation, containing all information relating to the “CGS-X Score” and its additional sub-scores, as well as the logic and criteria applied to the system for calculating said score;

b) transmission of the aforementioned response template pursuant to Art. 15 of the Regulation also to Messrs. XX, XX, Mr. XX, XX, and XX;

c) adoption of a procedure designed to ensure that the data subject can fully exercise the right to rectification pursuant to Article 16 of the Regulation, with respect to inaccurate and/or incomplete personal data processed for the purpose of verifying customer reliability. This procedure must take into account the obligation, set forth in Article 22(3) of the Regulation, to implement appropriate measures to protect the rights, freedoms, and legitimate interests of data subjects; specifically through the right “to obtain human intervention by the controller, [to] express one’s opinion, and to contest the decision” made by the controller (see Article 22(3) of the Regulation). 

Finally, it should be noted that the violations, as established in the reasoning section, cannot in any way be considered “minor” within the meaning of Recital 148 of the Regulation; given the multiple violations alleged and the number of data subjects involved, as well as the additional factors explained in greater detail in paragraph 6 of this decision.

6. Injunction Order.

The Data Protection Authority, pursuant to Article 58, para 2, subparagraph (i) of the Regulation and Article 166 of the Code, has the power to impose an administrative fine provided for in Article 83 of the Regulation, by issuing an injunction order (Article 18. Law No. 689 of November 24, 1981), in relation to the processing of personal data carried out by Hera Comm S.p.A., which has been found to be unlawful, as set forth herein. 

The violation of the provisions referred to above entails the application of the administrative fine provided for in Art. 83, para. 4, subpara. (a), and para. 5, subpara. (a) and (b), of the Regulation.

Having determined that Art. 83(3) of the Regulation must be applied, which provides that “if, in relation to the same processing operation or to related processing operations, a controller […] intentionally or negligently infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the most serious violation,” the total amount of the fine is calculated so as not to exceed the maximum penalty provided for in Art. 83(5) of the Regulation.

With regard to the factors listed in Art. 83(2) of the Regulation for the purposes of imposing the administrative fine and determining its amount, and taking into account that the fine must be “in each individual case effective, proportionate, and dissuasive” (Article 83(1) of the Regulation), it is noted that, in the case at hand, the following circumstances were taken into account:

- the significant severity of the violation (Article 83(2)(a) of the Regulation), in relation to its nature (concerning non-compliance with the general principles of lawfulness, fairness, and transparency, as well as those of purpose limitation, accuracy, and storage limitation), the manner in which it occurred (the multiple instances of unlawful conduct repeated over time), and its duration (approximately 2 years). Also considered relevant for this purpose are the context of the processing, as well as the high number of data subjects involved and the type of harm they suffered. All of this, given that: the operations in question were carried out for the purpose of developing a risk profile regarding the reliability of potential customers in terms of timely payments; the unlawful conduct affected approximately 1 million data subjects; the established violations resulted, in most cases, to the detriment of the data subjects, in the refusal to enter into an energy and/or gas supply contract;

- the negligent nature of the conduct and the significant degree of accountability of the controller regarding the technical and organizational measures implemented (Articles 83, para 2, subparagraphs (b) and (d) of the Regulation). All of this, with particular regard to the lack and inadequacy—in the specific context at hand—of the measures and processes implemented by the Company concerning compliance with obligations related to the exercise of data subject rights. With regard to the subjective element, consideration is given to the fact that, concerning the processing activities carried out by Hera Comm S.p.A. aimed at verifying customer reliability, the Company failed to correctly identify the processing purposes related to refining the Hera Group’s customer rating assessment system, nor the roles—with respect to personal data protection regulations—to be assigned to the companies involved in the internal assessment activity;

- the fact that there are no previous relevant violations committed by the controller or previous measures referred to in Art 58 of the Regulation concerning the same subject matter (Article 83(2)(e) and (i) of the Regulation). On this point, it should be noted that Measure No. 440, dated July 17, 2024, adopted against Hera Comm S.p.A., was not taken into account for this purpose; this is due to the fact that the preliminary investigation pertaining to this decision was conducted concurrently with the one that led to the adoption of the aforementioned measure;

- in favor of the violator, account is taken of the fact that the Company has complied with the requirements set forth by the Authority in Measure No. 440, referred to above (Art. 83(2)(i) of the Regulation);

- the adoption by the data controller of measures designed to mitigate or eliminate the consequences of the violation (Articles 83, para 2, subparagraph c) of the Regulation). In this regard, the fact that Hera Comm S.p.A. voluntarily adopted, once it became aware of the violation, certain initial measures to mitigate the effects of the unlawful processing—albeit measures that were only partially effective in reducing the risks—should be viewed favorably;

- the fact that the Company actively cooperated with the Authority during the proceedings (Article 83(2)(f) of the Regulation);

- the nature of the information subject to the breach (Article 83(2)(g) of the Regulation), which, although not classified as special categories of data, is nonetheless considered sensitive as it reflects the reliability of customers’ timely payments; this also taking into account the potential economic and social consequences that may arise for the data subjects as a result of the unlawful processing of their data;

- other mitigating factors (Article 83(2)(k) of the Regulation), such as the adoption of certain organizational measures, as well as the fact that the processing operations related to the aforementioned violations concern only a portion of the Company’s customer base. All of this is described in greater detail in para 3 of this decision.

It is further considered that, in the present case, the following factors are relevant in light of the aforementioned principles of effectiveness, proportionality, and deterrence that the Authority must adhere to when determining the amount of the fine (Art. 83(1) of the Regulation): the economic circumstances of the offender, determined on the basis of the Company’s turnover as reported in the financial statements for the year 2024 (the most recent available). 

In light of the above factors and the assessments made, it is deemed appropriate, in this case, to impose on Hera Comm S.p.A. an administrative fine in the amount of 5,800,000.00 euros (five million eight hundred thousand/00). 

In this context, it is also considered that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, this chapter containing the injunction order must be published on the Data Protection Authority’s website.

This is in light of the specific nature of the data subject to the processing at issue—as it pertains to the data subject’s creditworthiness—as well as the nature of the violations found, which affected the general principles of processing, in particular the principle of transparency and the obligations regarding the exercise of the data subject rights. 

Finally, it is considered that the conditions set forth in Art. 17 of the Data Protection Authority’s Regulation No. 1/2019 are met.

NOW THEREFORE, THE DATA PROTECTION AUTHORITY

- declares, pursuant to Article 57(1)(f) of the Regulation, that the processing carried out by Hera Comm S.p.A., with its registered office in Imola, VAT No. 02221101203, as set forth in the reasoning, for the violation of Article 5(1)(a), (b), (d), and (e); as well as Articles 12, 13, 14, and 15, and Article 28 of the Regulation

- orders, pursuant to Article 58(2)(c) and (d) of the Regulation, the aforementioned Company to comply, within six months from the date of notification of this decision, the requirements set forth in para 5 of this decision, while at the same time requiring the company to provide, within the aforementioned deadline, an adequately documented response pursuant to Art 157 of the Code; failure to provide such a response may result in the imposition of the administrative fine provided for in Article 83, para 5, subparagraph e) of the Regulation;

ORDERS

pursuant to Article 58, para 2, subparagraph (i) of the Regulation, that Hera Comm S.p.A. pay the sum of 5,800,000.00 euros (five million eight hundred thousand/00) as an administrative fine for the violations set forth in this order;

ORDERS

pursuant to Article 58, para 2, subparagraph (i) of the Regulation, that the same Company pay the aforementioned sum of 5,800,000.00 euros (five million eight hundred thousand/00), as an administrative fine for the violations set forth in this order, in accordance with the procedures outlined in the attachment, within thirty days of the service of this order, failing which the necessary enforcement measures will be taken pursuant to Art. 27 of Law No. 689/1981.

It is noted that, pursuant to Article 166, paragraph 8 of the Code, the offender retains the right to settle the dispute by paying an amount equal to half of the imposed penalty within the time limit set forth in Article 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, set for filing an appeal as indicated below;

ORDERS

- pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, the publication of the injunction order on the Data Protection Authority’s website;
- pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Authority’s Regulation No. 1/2019, the publication of this order on the Authority’s website;

- Pursuant to Article 17 of the Authority’s Regulation No. 1/2019, the recording of the violations and the measures adopted in accordance with Article 58(2) of the Regulation in the Authority’s internal register provided for under Article 57(1)(u) of the Regulation.

Pursuant to Article 78 of Regulation (EU) 2016/679, as well as Article 152 of the Code and Article 10 of Legislative Decree No. 150 of September 1, 2011, an appeal against this decision may be filed with the ordinary courts by filing a petition with the ordinary court of the location specified in the aforementioned Art 10, within thirty days from the date of notification of the decision, or within sixty days if the appellant resides abroad.

Rome, July 3, 2026

 

THE CHAIRMAN
Stanzione

THE RAPPORTEUR
Stanzione

THE SECRETARY GENERAL
Montuori

 

 

 

[Web Doc. No. 10273926]

Decision of July 3, 2026

Register of Decisions
No. 483 of July 3, 2026

THE DATA PROTECTION AUTHORITY

AT today’s meeting, attended by Prof. Pasquale Stanzione, President; Prof. Ginevra Cerrina Feroni, Vice President; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General;

HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter the “Regulation”);

HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003 (Code on Data Protection, hereinafter the “Code”), as amended by Legislative Decree No. 101 of August 10, 2018, containing “Provisions for the alignment of national legislation with the provisions of Regulation (EU) 2016/679”;

HAVING EXAMINED the documentation on file;

HAVING CONSIDERED the observations made by the Secretary General pursuant to Art. 15 of the Data Protection Authority’s Regulation No. 1/2000;

RAPPORTEUR: Prof. Pasquale Stanzione;

WHEREAS

1. Introduction.

This Authority has received several complaints concerning the processing of personal data carried out by Hera Comm S.p.A. for the purpose of verifying the creditworthiness of potential customers.

Specifically, the complainants alleged that Hera Comm S.p.A. refused to supply energy to them on the basis of a risk profile of the data subjects that allegedly emerged, following checks carried out by the aforementioned companies, including through the consultation of credit information systems (operated by Experian Italia S.p.A.) and the use of commercial information services (operated by Cerved Group S.p.A.). 

This assessment is carried out within the Hera Group using software provided by Major 1 S.r.l., called “CGS-X.” 

This software enables the aforementioned energy suppliers to identify a risk profile regarding the creditworthiness of potential customers, based on an integrated indicator called the “Integrated Utilities Score” (hereinafter also referred to as the “CGS-X Score”). 

The petitioners pointed out in this regard that, although the denial of energy supply was the result of their being assigned a summary score (hereinafter also “score”) indicating low reliability—derived from a search of the databases managed by Cerved Group S.p.A. and Experian Italia S.p.A., these companies, when questioned on the matter, stated that their systems contained no negative information and/or adverse events regarding the aforementioned data subjects.

All of this is in response to the access requests submitted by the aforementioned individuals to Cerved Group S.p.A. and Experian Italia S.p.A., pursuant to Article 15 of the Regulation (see the request by Mr. XX dated March 1, 2023, the request filed by Mr. XX on June 29, 2023, the request filed by Mr. XX on June 14, 2024, the request filed by Mr. XX on July 15, 2024, and the request filed by Ms. XX on September 13, 2024).

With regard to the foregoing, it should be noted that the Authority, in view of the numerous requests received, first decided to consolidate the individual proceedings referred to above in order to conduct a comprehensive examination of the underlying issues and subsequently initiated, on its own initiative, pursuant to Article 21 of the Data Protection Authority’s Regulation No. 1/2019, an investigation aimed at assessing, as a whole, the methods and processing purposes carried out by Hera Comm S.p.A. in connection with the service provided by Major 1 S.r.l. and known as “CGS-X.”

In this context, several on-site inspections were conducted at Hera S.p.A. on March 18, 19, and 20, 2024; at Major 1 S.r.l., on April 15 and 16, 2024; at Cerved Group S.p.A. on April 16, 2024; and at Experian Italia S.p.A. on June 13 and 14, 2024. 
Subsequently, given the particular complexity of the investigation and in order to gather further information regarding the processing of the aforementioned data, additional on-site inspections were conducted at Major 1 S.r.l., on October 15 and 16, 2024, and at Cerved Group S.p.A. on October 16, 2024.

2. The Investigation.

As part of the proceedings, with regard to the issues highlighted in the introduction, the following findings emerged.

2.1. The Credit Check Process.

Hera S.p.A., “through its Credit Management function, establishes the ‘customer acceptance rules’ in terms of credit risk, providing services related to customer creditworthiness to the following companies operating in the energy sales sector: Hera Comm S.p.A. (…) [and] EstEnergy S.p.A.” (see Hera S.p.A.’s statement of March 18, 2024, p. 2). 
Hera S.p.A., in fact, “with a view to serving its subsidiaries, oversees the IT implementations related to credit management systems and carries out the various operational activities aimed at achieving shared objectives” (see Hera S.p.A. memorandum dated April 19, 2024, p. 1).

In particular, “in order to limit the credit risk associated with activities carried out on the free market, the Hera Group, (..), has adopted a Credit Policy and implemented a system for verifying and assessing the solvency and creditworthiness of parties applying to participate in one of the open-market offers (hereinafter, “Credit Check”). The Credit Check involves an internal assessment, consisting of verifying any delinquencies [past and current within the Hera Group’s energy sales companies] on the part of the customer (hereinafter, “Internal Assessment”), and an external assessment, which consists of obtaining, from entities authorized to conduct commercial credit reporting activities [and from the SICs], a summary “score”    —which may also be based on statistical information—regarding the customer’s creditworthiness (hereinafter, “External Assessment”)” (see Hera Comm S.p.A. note dated July 30, 2024, p. 2). 

Hera S.p.A. conducts customer creditworthiness checks pursuant to the “Agreement for the Management of Administrative, Financial, and Control Activities,” signed on July 18, 2013, by Hera Comm S.p.A. and Hera S.p.A., and the related “Addendum” dated July 3, 2023. To this end, “Hera S.p.A. is appointed as the processor” (see Hera S.p.A. minutes of March 18, 2024, p. 2 and Annex 2).

This activity is carried out in accordance with a procedure titled “Rules for Private Customer Origination,” “prepared by Hera S.p.A.,” and “in effect as of May 2017, the date the Credit [Check] system became operational” (see Hera S.p.A. minutes of March 18, 2024, p. 2 and Annex 3; see also Hera S.p.A. minutes of March 19, 2024, p. 2). 

On April 15, 2024, the latter company also adopted a “document titled ‘ATF TK 1054336C – Verification of the ‘BAD PAYER’ Rule – origination”; a document that describes the “functional and technical logic used in the bad payer rule (origination system)” (see Hera S.p.A.’s note dated April 19, 2024, p. 1 and Annex 1). 

The aforementioned procedure stipulates that, “if a potential customer in the free market requests the activation of a service with a group company, the CRM (..) makes a call to SAP,” a system “used by Hera Group companies to manage a range of services, including billing and debt collection” (see Hera S.p.A.’s minutes of March 18, 2024, p. 3). 

Through this system, Hera S.p.A. “checks, based on the potential customer’s personal data (first name, last name, tax ID, and business partner), for any prior delinquencies, returning an ‘OK’ or ‘KO’ result. (…) The query, conducted online and in real time, concerns active, uncontested arrears relating solely to the energy sector in the deregulated market. Specifically, the amount of arrears that triggers a ‘KO’ result is [determined in the following cases]:

- at least one invoice overdue by more than 60 days with an amount exceeding €100;
- at least one installment overdue by more than 30 days with an amount exceeding €50;§
- receivables in the legal department’s management process (e.g., terminated contracts subject to out-of-court collection with an amount exceeding €50)” (see Hera S.p.A. minutes of March 18, 2024, p. 3).

If “the internal checks result in an ‘OK,’ external databases of Cerved Group S.p.A. and Experian Italia S.p.A. are also queried [via software provided by Major 1 S.r.l. and named “CGS-X”]. 

These “queries have been conducted [on behalf of Hera Comm S.p.A.] since 2021.” All of this “is based on a contractual package that requires the client [i.e., Hera Comm S.p.A.] to sign three separate documents (..) with Cerved Group S.p.A., Experian Italia S.p.A., and Major 1 S.r.l., respectively.” 

The energy provider acts as an independent controller, designating Major 1 S.r.l.  —which acts as a technology outsourcing provider, supplying the license to use the “CGS-X” software—as the processor pursuant to Art. 28 of the Regulation (see Hera S.p.A.’s minutes of March 18, 2024, p. 3, and the minutes of Major 1 S.r.l. dated April 15, 2024, p. 3). 

If “the outcome of the internal checks results in a ‘KO,’ no further external checks are conducted” (see the minutes of Hera S.p.A. dated March 18, 2024, p. 3). 
The aforementioned “CGS-X” software enables Hera Comm S.p.A. to develop a risk profile regarding the creditworthiness of potential customers based on the integrated “CGS-X Score” indicator.

The latter is the result of combining the assessment indicators known as “ESX Score” (provided by Experian Italia S.p.A.) and “Retail Utilities Score” (provided by Cerved Group S.p.A.). 

More specifically, using the potential customer’s tax ID number, “the information systems of Cerved and Experian, retrieving the ‘Score Retail Utilities’ from Cerved Group S.p.A. and the ‘Score ESX’ from Experian Italia S.p.A., along with the corresponding sub-scores.” Following this query, “Major 1 prepares an XML file containing the customer’s rating, (..), which is then transferred to Hera Spa’s systems.” This “is analyzed by SAP, which returns an OK/KO to the CRM [of Hera Comm S.p.A.] based on acceptance thresholds set by Hera Spa’s [Credit] Policy (..). The query in SAP is generated from scratch for each new request to verify a potential customer’s creditworthiness and is valid only on the day it is made” (see Hera S.p.A. minutes of March 18, 2024, p. 4, and Major 1 S.r.l. minutes of April 15, 2024, p. 3). 

The XML format “is unique and contains a variety of information,” as indicated below:

A) “CGS-X Score for Individuals” — represented by a score “[OMISSIS], customized for each individual customer,” as well as an indicator “called class value [OMISSIS]”;

B) “SIC Details” — this is the response provided by Experian’s information systems and consists of the following items:

1) “Experian score” — a granular value corresponding to a reliability range (the so-called Experian index);
2) “[OMISSIS]”—[OMISSIS];
3) “Experian Index”—this is a value related to the credit risk profile [OMISSIS]”;

C) “Retail Score Info”—this refers to information regarding the so-called [Retail Utilities] provided by Cerved, which consists of several items:
1) “Information on adverse events” –  [OMISSIS];
2) “Score class” – “score  [OMISSIS]”;
3) “Score class before override” — a tool “for verification and reclassification in determining the class, [OMISSIS]”;
4) “Score value” — “a granular value corresponding to various ranges [OMISSIS]” (see the minutes of Major 1 S.r.l. dated April 16, 2024, pp. 2–4, and the minutes of Hera S.p.A. dated March 18, 2024, p. 4). 

In turn, the “Retail Utilities Score” is “the result of processing various sub-scores, which are also included in the XML file.” These are the following items:

A) “Subscore [OMISSIS]” — “a risk score applicable only to individuals, based on the personal information of the data subject (specifically residence/place of birth and age) [OMISSIS]”;

B) “Subscore [OMISSIS]”;

C) “Subscore [OMISSIS]” – this is “a value reflecting the risk associated with the data subject’s area of residence [OMISSIS]”;

D) “Subscore P4” – this is “the score [OMISSIS]” (see the minutes of Major 1 S.r.l. dated April 16, 2024, pp. 3–4).

On this point, it was clarified that, of all the information listed above and contained in the XML file, “Hera S.p.A. uses only that which refers to the so-called ‘class value’ [relating to the CGS-X score for individuals bearing] [OMISSIS], automatically assigning a KO in the event of a rating greater than or equal to [OMISSIS]” (see Hera S.p.A. minutes of March 18, 2024, p. 4). 

It was also represented that the additional information contained in the XML schema is not used “for the purpose of verifying customer reliability,” but is nevertheless retained “for any future activities, including the improvement of the rating system” (see Hera S.p.A. minutes of March 18, 2024, p. 4). 

The on-site inspections conducted at Hera S.p.A. revealed that “the Credit Check data [conducted on behalf of Hera Comm S.p.A.] are retained both in the case of a positive result (OK) and in the case of a negative result (KO)” (see Hera S.p.A. minutes of March 18, 2024, pp. 4 and 5).

In particular, “the log of queries to external databases lists all the data contained in the various fields, including the Class Value and Experian Score assessments,” and “a total of approximately 700,000 queries are made per year” (see Hera S.p.A. minutes of March 18, 2024, pp. 4 and 5). 

More specifically, it was stated that in the years 2022, 2023, and 2024 (up to March 18, 2024), 1,003,657 individuals were subject to queries as part of the External Assessment phase of Credit Check (Exhibit 3 of the Hera S.p.A. minutes of March 19, 2024).

Finally, a representative stated that, as of the date of the inspections, “a [group-wide] data retention policy [on the matter] had not been adopted (..) but that it [was] in the process of being defined” (see minutes of Hera S.p.A. dated March 18, 2024, p. 5).

This policy, in particular, “with specific reference to storage periods for the SAP system, (…) provided for a 10-year period from the date of recording of the last accounting document, where ‘accounting document’ means any document—including those of a non-tax nature—stored in SAP (for example, query reports from external databases)” (see Hera S.p.A. minutes of March 18, 2024, p. 5 and Annex 8).

2.2. Procedures for responding to data subject rights requests.

With regard to requests submitted by data subjects pursuant to Article 15 of the Regulation, although the Company responded within the time limits set forth in Article 12 of the Regulation, in its responses it limited itself to referring solely to the identification of a risk profile for the data subjects. 

In particular, data subjects were generally informed that the profile in question was the result of assessments conducted by Hera Comm S.p.A., based on evaluations involving the use of “indicators or scores derived through the use of automated scoring techniques or systems relating to (..) data” (see Hera Comm S.p.A.’s notes dated August 17, 2022, August 29, 2023, and August 25, 2023). 

The Company informed the data subjects that the aforementioned assessments were “the result of checks carried out, in part, by consulting systems containing information from public sources (managed by Cerved) and credit information systems (managed by Experian)”; such consultation “yielded a summary score” (see Hera Comm S.p.A.’s notice dated August 25, 2023; see also the Company’s notices dated August 17, 2022, and August 29, 2023). 

In these responses, Hera Comm S.p.A. clarified that it was not aware of all the detailed elements pertaining to the aforementioned score and therefore invited data subjects to contact Cerved Group S.p.A. and Experian Italia S.p.A. directly for further information on the matter (see Hera Comm S.p.A.’s notes dated August 17, 2022, August 29, 2023, and August 25, 2023). 

During the investigation, it was further established that, in none of the cases subject to complaint, did the aforementioned findings refer to the “CGS-X Score” and the related sub-scores assigned to the data subject.

This was the case even though it emerged that Hera S.p.A.’s systems contained the queries sent to Major 1 S.r.l. regarding the taxpayers’ identification numbers of the complainants, as well as the XML files of the responses sent by Major 1 S.r.l. to Hera S.p.A. 

Likewise, it was established that the Company systematically retains data pertaining to the queries and the aforementioned files regarding potential customers data subjects of credit checks (see Hera S.p.A.’s report dated March 19, 2024, pp. 1, 3, and 4, and Attachments Nos. 1 and 10; see also Hera S.p.A.’s minutes of March 20, 2024, pp. 1 and 3, and Attachments Nos. 1 and 7).

2.3. The refinement of the Hera Group’s customer rating service.

The information contained in the aforementioned XML file referring to the “CGS-X Score”—other than the “class value” (see above)—“is not currently used [by Hera Comm S.p.A.] to assess customer creditworthiness” (see Hera S.p.A. minutes of March 20, 2024, p. 2). 
In fact, this information “is stored and used to conduct an analysis currently underway aimed at potentially refining the rating service provided to group companies” (see Hera S.p.A.’s minutes of March 19, 2024, p. 3). 

This activity includes “the analysis of data relating to customer creditworthiness and the risk profiles of the customer base” and is carried out by Hera S.p.A. “in its capacity as processor, in the name and on behalf of the energy sales companies Hera Comm (..) and EstEnergy” within a specific department of Hera S.p.A. called “Credit Management” (see minutes of Hera S.p.A. dated March 20, 2024, p. 2).

The data analyzed by the aforementioned department pertains to “all requests for contract establishment—concerning both electricity and gas—relating to individual customers (..) for which an external assessment was conducted by consulting the database of Cerved Group S.p.A.” and that of Experian Italia S.p.A. (see Hera S.p.A. note dated April 19, 2024, p. 2). 

These analyses—for which the legend of the relevant fields has been obtained (see Annex No. 2 to Hera S.p.A.’s note dated April 19, 2024)— “are performed by Hera S.p.A. approximately once a month using constantly updated data” (see Hera S.p.A.’s minutes of March 20, 2024, p. 2). 

The aforementioned “data, which reside on SAP SFCM, are [stored in a], (..), group data warehouse, into which data relating to the so-called customer account statement are also fed” (see Hera S.p.A. minutes of March 20, 2024, p. 2). 

This data is also analyzed using specific data analysis applications or through the use of Excel (see Hera S.p.A. minutes of March 20, p. 2). All of this is done with a view toward “a possible refinement of the Hera Group’s customer rating service” (see Hera S.p.A. minutes of March 20, 2024, p. 2). 

By way of example, Hera S.p.A. had a representative who stated that, with reference to the year 2022, the activity described above involved “approximately 500,000 queries regarding individual customers made by Hera S.p.A. to external databases in 2022” (see Hera S.p.A.’s minutes of March 20, 2024, p. 2). 

It was also established that the data processing activity described above began in 2022 and that, in total, during the years 2022, 2023, and 2024 (through March 18), it involved 1,003,657 individuals (Annex 3 of the Hera S.p.A. minutes of March 19, 2024).

In particular, during the inspections, “a sample report of the analysis conducted—relating to customers who entered the origination process in 2022, with account statement data updated as of today—was examined. This report details outstanding and past-due credit balances for various types of account activation (transfer, switch, first activation…) and by risk class (class value, with values 1–6)” (see Hera S.p.A. minutes of March 20, 2024, p. 2).

3. The notification pursuant to Article 166, paragraph 5, of the Code.

Following the allegation of violations under Articles 5(1)(a), 12, and 15 of the Regulation, sent to Hera Comm S.p.A. by notice dated July 14, 2025, the Company, by letter dated October 10, 2025, submitted its defense briefs, which were further supplemented during the hearing on May 20, 2026, and by a subsequent letter dated May 29, 2026.

In the aforementioned briefs, Hera Comm S.p.A. made the following representations:

a) regarding the allegation concerning the unlawfulness of processing the data of potential customers as part of the activities related to the so-called “Internal Assessment of Past Delinquencies,” “a joint controller agreement was signed between Hera Comm and EstEnergy, pursuant to Art. 26 of the Regulation”. This was done with the aim of jointly sharing, storing, and processing the personal data collected by the companies for the purpose of verifying the creditworthiness of customers in the free market segment for electricity and natural gas. This processing is designed to safeguard the financial stability of the Hera Group and minimize exposure to the risk of insolvency by acquiring customers who are financially sound and creditworthy. In conclusion, this activity represents “an essential safeguard aimed at ensuring the reliability of supplies and the economic sustainability of sales operations in the free market” (see note dated October 10, 2025, p. 3). Following the signing of the aforementioned joint-controller agreement, “the relevant notices provided to customers have been updated to ensure full transparency regarding data processing,” including with regard to the new structure of shared roles and accountability (see note dated October 10, 2025, p. 4; see also the note dated May 29, 2026, pp. 1–2);

b) regarding the alleged violation concerning the inadequate responses provided to data subjects who had exercised their right of access pursuant to Article 15 of the Regulation, the Company, “not being aware of all the evidence taken into account to produce [the CGS-X score] nor, much less, the logic behind the processing and production of the assessment itself, made available to the data subject all the information in its possession for which it could provide an explanation.” In particular, “rather than providing incomplete information or information that might have given the impression of being inaccurate, it deemed it more protective to simply invite the data subject to contact the external providers, while also providing all relevant contact channels for that purpose.” Although the Company had access to the “CGS-X Score” and its related sub-scores, “the information contained therein was neither intelligible nor useful for the purpose of drafting the response to be sent to the data subject.” Hera Comm S.p.A. also had a representative who stated that, as of today, it no longer uses the “CGS-X” service provided by Major 1 S.r.l., having adopted, with regard to external assessment activities, a “new system that provides only the summary score and no longer the analytical sub-scores.” Furthermore, new “response templates, (..) enhanced with additional elements aimed at ensuring a more complete representation of the information processed and at strengthening transparency toward customers” have been prepared (see note dated October 10, 2025, pp. 5–8 and Annex 3);

c) regarding the retention periods for customer data in connection with external assessment activities, which were deemed non-compliant with the storage limitation principle, the Company “has developed and progressively implemented a specific data retention policy for credit data, which defines specific periods of storage and automated procedures for erasure upon the expiration of the established periods, in full compliance with Article 5, paragraph 1, letter e) of the GDPR” (see note dated October 10, 2025, p. 8, and note dated May 29, 2026, pp. 2–3, and Annex 1);

d) regarding the alleged unlawfulness of the analysis of customers’ personal data collected as part of the Credit Check, aimed at refining the Hera Group’s customer rating assessment system, it was stated that “the purpose of the processing (..) was statistical in nature, and the reports produced were intended solely to provide management with a basis for evaluating potential revisions to the scoring parameters.” On this point, Hera Comm S.p.A. emphasized that, to date, this activity has had no “effect [on] individual contract processing cases (..) since the analyses did not affect the outcome of individual cases, nor were they used to determine automated decisions” (see note dated October 10, 2025, p. 9). 

Finally, regarding the factors to be taken into account for the purpose of determining the amount of any penalty—among those identified in Article 83(2) of the Regulation—the Company stated that “the ‘credit check’ activity,” which is the subject of the proceedings, concerns only a portion of the processing of customers’ personal data carried out by Hera Comm S.p.A.; this is because the aforementioned activity is “carried out solely with respect to residential customers requesting the activation of electricity and gas supply contracts in the free market, as well as with respect to customers requesting the activation of contracts under the gas vulnerability protection program”  (see note dated May 29, 2026, p. 4). 

The Company also highlighted that, in order to ensure full compliance of the processing in question with the Regulation, it has adopted certain measures, including organizational ones, such as “bringing responses to requests for clarification regarding the failure to enter into contracts under the oversight of the privacy department” (note dated May 29, 2026, p. 3). 

Finally, it was noted that, during the preliminary investigation, Hera Comm S.p.A. promptly and proactively “abandoned the project related to the refinement of the customer rating assessment system” (see note dated May 29, 2026, p. 2). 

Moreover, this project “never saw the light of day because operations were suspended during a preparatory phase prior to its launch” and “therefore, no actual infringement of the data subject rights ever occurred (…), since the analyses did not affect the outcome of individual cases, nor were they used to determine automated decisions” (see note of May 29, 2026, pp. 2–3, and note of October 10, 2025, p. 9).

4. The Authority’s Assessments.

First of all, it should be noted that, unless the act constitutes a more serious offense, anyone who, in proceedings before the Data Protection Authority, falsely declares or attests to information or circumstances, or produces false records or documents, is liable under Art. 168 of the Code, “False Statements to the Data Protection Authority and Interruption of the Performance of the Authority’s Duties or the Exercise of Its Powers.” 
In light of the evidence gathered during the preliminary investigation described above, as well as the subsequent assessments conducted, the following violations by Hera Comm S.p.A. have been identified.

4.1. The Unlawfulness of Customer Data Processing for the Purpose of Verifying Any Past Delinquencies (so-called “Internal Assessment”)

First, reference is made to the policy—known as “Credit Check”—which introduces, at the group level, a system for verifying the solvency and creditworthiness of individuals intending to subscribe to electricity and/or natural gas service offers in the open market. 

This policy “is uniform across all group companies operating in the free energy market sector and (…) provides that, where a potential customer in the free market requests the activation of a service with a group company,” a “verification is first conducted, based on the personal data (..) of the potential customer, to determine whether there are any past payment arrears” (see Hera S.p.A. minutes of March 18, 2024, p. 3). 

More specifically, Hera Comm S.p.A., in accordance with this procedure, conducts—in response to requests made by its potential customers— the so-called “Internal Assessment,” which consists of verifying whether the potential customer has any outstanding arrears related to energy supply contracts in the open market, including those established with other Group companies.

Specifically, this activity is carried out by Hera S.p.A., on behalf of Hera Comm S.p.A., pursuant to the “Agreement for the Management of Administrative, Financial, and Control Activities,” signed on July 18, 2013, by the Companies, and the related “Addendum” dated July 3, 2023. 

Hera S.p.A., in fact, carries out “on a centralized basis within the Group (..) the activity of assessing customers’ creditworthiness.” To this end, Hera Comm S.p.A. has appointed Hera S.p.A. as the processor pursuant to Art. 28 of the Regulation (see Hera S.p.A. minutes of March 18, 2024, p. 2 and Annex 2).

On this point, it has emerged in particular that, in carrying out the aforementioned assessment, Hera Comm S.p.A. takes into account not only the potential customer’s delinquencies recorded in its own systems but also information regarding any additional past delinquencies the customer may have had with EstEnergy S.p.A. 

Upon completion of this check, Hera S.p.A. provides a response of “OK” in the event of a positive outcome, or “KO” in the event of a negative outcome (see Hera S.p.A.’s report dated March 18, 2024, p. 3, and Hera S.p.A.’s note dated April 19, 2024, p. 1).

The activity described above, carried out through the processor Hera S.p.A., therefore effectively involves the sharing of customer data among Group companies operating as energy suppliers; such sharing concerns personal information regarding customers’ past delinquencies, as identified by the procedure titled “Rules for Private Customer Origination” (such as, for example, unpaid invoices, overdue installments under a repayment plan, debts referred for legal collection), as well as information regarding the summary “OK/KO” assessments pertaining to individual data subjects (see Annex 3 of the Hera S.p.A. minutes dated March 18, 2024). 

With regard to this specific data processing activity, Hera Comm S.p.A. failed to inform the data subjects in accordance with Articles 13 and 14 of the Regulation. 

The privacy notice provided by the Company at the time the customer signed the contract does not, in fact, contain any information regarding the aforementioned activity or the aforementioned categories of personal data (see the attachment titled “Plico Famiglie HC-January 2023” in the Hera Comm S.p.A. notice dated March 21, 2025).

Furthermore, the privacy notice merely states in general terms that “[customers’] personal data may be disclosed to companies of the Hera Group and/or to third parties contractually linked to the Group companies,” without making any specific reference to the transfer of the aforementioned data between Hera Comm S.p.A. and EstEnergy S.p.A. carried out for the purpose of internal evaluation (see the attachment titled “HC Household Package—January 2023” in the Hera Comm S.p.A. notice dated March 21, 2025). 

In light of the above, it is clear that the information provided to data subjects by Hera Comm S.p.A. is inadequate, as it contains no information regarding the processing operations related to the Company’s internal customer assessment activities. All of this constitutes a violation of Article 5(1)(a), as well as Articles 13 and 14 of the Regulation.

It should also be noted that, with respect to the aforementioned activity, the instructions provided by Hera Comm S.p.A., pursuant to Art. 28 of the Regulation, to the processor Hera S.p.A., do not include the processing operations consisting of verifying past delinquencies of customers related to EstEnergy S.p.A. 

In fact, within the designation document pursuant to Article 28 of the Regulation signed on July 3, 2023, by Hera Comm S.p.A. and Hera S.p.A., no reference was found to the mandate to process, as part of the pursuit of the aforementioned specific purposes, information pertaining to EstEnergy S.p.A.’s customers. 

The aforementioned designation agreement is in fact limited to providing that Hera S.p.A. performs, on behalf of Hera Comm S.p.A., services related to the activity of “In-depth support for the analysis of the origination of [its own] Customer Base” (see Annex 2 “Addendum” to the “Contract for the Management of Administrative, Financial, and Control Activities,” from the minutes of March 18, 2024). Consequently, Hera Comm S.p.A. has violated Article 28 of the Regulation.

Without prejudice to the foregoing, it is also acknowledged that the Joint Controller Agreement between Hera Comm S.p.A. and EstEnergy S.p.A., pursuant to Article 26 of the Regulation, under the terms described in paragraph 3, subparagraph a) of this decision, as well as the resulting update to the customer disclosure templates pursuant to Article 13 of the Regulation.

More specifically, it is noted that the aforementioned Agreement defines the respective levels of accountability regarding the processing of data pertaining to the internal verification of customer creditworthiness.

This internal audit is carried out jointly by Hera Comm S.p.A. and EstEnergy S.p.A. pursuant to Article 6, para 1, subparagraph (f) of the Regulation, to pursue the legitimate interests of the Companies, given the need to ensure the protection of their financial soundness, as well as that of the Hera Group as a whole, and to minimize exposure to the risk of non-payment by customers (see, in this regard, Recital 47 of the Regulation).

In this regard, the reasonable expectations of the data subjects with respect to the processing in question are also taken into account, given that it involves exclusively companies belonging to the same group and is, at the same time, limited solely to the pre-contractual phase, as well as restricted to the specific sector of energy and gas supply in the liberalized market (see, in this regard, European Data Protection Board, “Guidelines 1/2024 on the Processing of Personal Data Based on Article 6(1)(f) of the GDPR,” adopted on October 8, 2024, paragraphs 31–60).

Finally, it should also be noted that, under the aforementioned Joint Controller Agreement, Hera Comm S.p.A., together with EstEnergy S.p.A., undertakes to designate Hera S.p.A., in relation to the performance of operations connected with the so-called Internal Assessment, as the processor pursuant to Article 28 of the Regulation (see Article 8 of the aforementioned Agreement). 

In light of the foregoing, the processing of customer data carried out by Hera Comm S.p.A., up to the date of signing the aforementioned Joint Controller Agreement for the purpose of verifying any past delinquencies within the scope of the so-called Internal Assessment, is unlawful as it violates Articles 5(1)(a), 13, 14, and 28 of the Regulation.

4.2. Violations regarding the exercise of rights and the principle of storage limitation.

Based on the evidence gathered during the preliminary investigation as well as subsequent assessments, it has been established that Hera Comm S.p.A. provided inadequate and incomplete responses to requests to exercise rights pursuant to Articles 15–22 of the Regulation submitted by the data subjects. 

In fact, these responses merely contained a reference to the identification of a risk profile for the data subjects, without providing either the “CGS-X Score” and the related sub-scores assigned to the data subject, nor any information on the logic used to develop said profile. 

More specifically, in all the responses subject to the complaint, Hera Comm S.p.A. stated that it was unaware of the detailed elements pertaining to the “CGS-X Score.” In particular, asserting that it was unaware of “all the evidence taken into account to produce the [aforementioned] integrated assessment, nor, much less, the logic used to process and produce the assessment itself,” it invited the data subjects to contact Cerved Group S.p.A. and Experian Italia S.p.A. directly for further information on the matter (see note dated October 10, 2025, p. 5). 

All of this, even though the information in question was, in fact—as ascertained during the on-site inspections—present in the data controller’s systems (see above, para 2.2 of this notice of violation). 
In this regard, it should be noted that, in light of the current regulatory framework governing data protection with respect to the exercise of data subject rights, pursuant to Article 15(1) of the Regulation, “the data subject has the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, to obtain access to the personal data and [certain] information” specified in that provision.

The recipient of the request made pursuant to Article 15 of the Regulation is therefore the controller—in this case, Hera Comm S.p.A.—to whom the request was submitted; the data controller is, in fact, required, pursuant to Article 12(3) of the Regulation, to provide the data subject with all personal information subject to such processing.

It follows, therefore, that the Company’s argument on this point, as set forth in paragraph 3(b) of this decision, cannot be accepted, since the obligation outlined above—pursuant to Articles 12 and 15 of the Regulation—rests first and foremost with the Company itself, as the controller in question.

It is also worth noting that the right of access under Article 15 of the Regulation is primarily conceived as a tool designed, in general terms, the data subject to exercise “control” over the personal data concerning him or her, ensuring that the data subject is fully aware of the information being processed and the actual methods of such processing. 

The purpose of the right of access is therefore primarily to disclose “what” data and “how” it has been processed by the controller in order to provide the data subject with the means to “know and verify the lawfulness and accuracy of the processing” concerning them (see Recital 63 of the Regulation; European Data Protection Board, “Guideline 1/2022 on the Data Subject Rights—Right of Access,” op. cit., paragraphs 10–13). 

Pursuant to Article 15 of the Regulation, therefore, the data controller, when responding to a request for access, may not limit itself to providing “a general description of the data [or] a mere reference to the categories of data processed,” nor may it omit information in its possession that relates to the data subject; on the contrary, the controller is required to provide access to “all the information referred to in Article 15” pertaining to the data subject and actually subject to processing.

Such information “must be complete, accurate, and up-to-date, reflecting as far as possible the status of the data processing at the time the request was received” and must be provided “in a concise, transparent, intelligible, and easily accessible form” to the data subject (see European Data Protection Board, “Guidelines 1/2022 on the Rights of Data Subjects—Right of Access,” op. cit., para. 34; Article 12(1) of the Regulation).

It should also be noted that, in the case at hand, the specific context (processing aimed at calculating a score regarding customer reliability), underlying the requests to exercise the right of access submitted by the data subjects, requires particular attention on the part of the controller, including with regard to the obligation to provide “meaningful information on the logic used, as well as [on] the significance and [on] the anticipated consequences of such processing for the data subject” (Article 15, para 1, subparagraph (h) of the Regulation). 

With regard to the aforementioned provision, the Court of Justice of the European Union has recently provided useful practical guidance—both substantively, regarding the type of information that the data subject may require from the controller, and formally, regarding the manner in which such information must be provided by the controller (see CJEU judgement of February 27, 2025, C-203/22). 

In particular, in clarifying the phrase “meaningful information on the logic used,” the Court specified that this refers to “any relevant information concerning the procedure and principles of the automated processing of personal data for the purpose of achieving a specific result” (see para. 58, CJEU judgement No. C-203/22, cited above).

It follows, therefore, that the data subjects, in the case at hand, have the right to be fully informed of all the elements comprising the assessment of their creditworthiness, including those taken into account by the data controller for the purpose of assigning the score, as well as the calculation criteria used (see, in this regard, Order of the Court of Cassation No. 14381 of May 25, 2021). 

With regard to the manner in which the aforementioned information must be provided, the Court of Justice of the European Union has reaffirmed the data controller’s obligation to provide it “in a concise, transparent, intelligible, and easily accessible form, using plain and clear language”; all in compliance with the principle of transparency set forth in Article 12(1) of the Regulation. Therefore, “neither the mere communication of a complex mathematical formula, such as an algorithm, nor a detailed description of all the stages of automated decision-making can satisfy these requirements, since neither of these methods would constitute a sufficiently concise and comprehensible explanation” (paragraphs 58–59, CJEU Judgement No. C-203/22, cited above). 

Overall, the requirement to provide “meaningful information on the logic used,” pursuant to Article 15(1)(h) of the Regulation, thus amounts to an obligation on the part of the controller to “describe the procedure and the principles actually applied in such a way that the data subject can understand which of [his or her] personal data have been used and how (...), without the complexity of the operations to be carried out in the context of the automated decision-making process exempting the controller from its duty to explain” (para. 61, CJEU Judgement No. C-203/22, cited above).

In light of the foregoing, it follows that Hera Comm S.p.A., in the cases at hand, acted in violation of Articles 12 and 15 of the Regulation, given that it did not provide the data subjects with any information regarding the “CGS-X Score,” on the basis of which the request to activate energy supply was denied, nor regarding the additional scores (so-called “sub-scores”) that contributed to generating the aforementioned “CGS-X Score.” Furthermore, the Company did not inform the applicants of the logic and criteria applied to the calculation system underlying the development of the credit risk profile. 

This, therefore, effectively prevented the applicants from accessing the types of personal information actually used for this purpose, as well as from understanding how such information was used. 

The inadequacy of the responses provided by Hera Comm S.p.A. therefore did not enable the data subject to ascertain the lawfulness and fairness of the processing, nor the accuracy of the data used in the context in question, thereby compromising the data subject’s ability to exercise, where applicable, the right to rectification in the event of inaccurate and/or incomplete data (see Art. 16 of the Regulation), as well as the right to “obtain human intervention from the controller, [to] express their opinion and contest the decision” taken against them by the controller (see Art. 22(3) of the Regulation).

All of this—given the particularly sensitive nature of the information processed by Hera Comm S.p.A. in the case at hand, as it pertains to customers’ creditworthiness—carries the risk of adverse consequences on the fundamental rights and freedoms of the data subjects (such as, for example, as occurred in the cases under review, the refusal to enter into an energy supply contract). 
It should also be noted that, due to the Company’s conduct, the data subjects incurred additional costs and delays, given the burden of having to submit further requests pursuant to Art. 15 of the Regulation, including to Cerved Group S.p.A. and Experian Italia S.p.A., in order to obtain information that was, in fact, fully available to Hera Comm S.p.A.

On this point, while taking note of the new response templates adopted by the Company in cases where supply is denied based on its customer acceptance policies, as set forth in Annex 3 of the note dated October 10, 2025, it should be noted that even these templates do not yet contain all the elements required by Art 15 of the Regulation, as specified above.

In light of the foregoing, Hera Comm S.p.A. is therefore found to be in violation of Articles 12 and 15 of the Regulation. 

Finally, it is noted that, with regard to the processing of customers’ personal data collected as part of the aforementioned external assessment, additional violations were identified concerning the storage periods for the data of the aforementioned data subjects.

Specifically, on this point, it has been established that Hera Comm S.p.A., at the time of the on-site inspections, did not have specific timeframes regarding the storage of customer data collected for the purposes of the External Assessment and that, within the data retention policy—which was still being drafted at the time—a ten-year storage period, generically applicable to accounting documentation, had been identified for such personal data (see Annex 8 of the minutes of March 18, 2024). 

In this regard, it should be noted that Article 5(1)(e) of the Regulation provides that personal data must be retained in a form that permits identification of the data subject for no longer than is necessary to fulfill the processing purpose. 

The data storage principle, in fact, requires the controller to assess the duration of the processing in light of the specific purposes established in advance at the time of collection; this is to “ensure that the period of storage for personal data is limited to the minimum necessary” (see Recital 39 of the Regulation). 

This is, in fact, the controller’s obligation to ensure an “appropriate” duration of processing, which, otherwise, could extend beyond the achievement of the specific processing purposes, thereby affecting the principles of lawfulness, fairness, and transparency (Art. 5 of the Regulation).

With regard to the data processing in question, it should therefore be noted, first and foremost, that at the time of the inspection, Hera Comm S.p.A. had not established specific periods of storage. 

It is also noted that, although a data retention policy was in the process of being adopted at the time, the Company did not specifically indicate in that policy the reasons for applying the ten-year storage period—generally required for accounting records—to such processing, nor was the compliance of this provision with what is strictly necessary to achieve the processing purpose duly justified. 

It follows that Hera Comm S.p.A. acted in violation of Article 5(1)(e) of the Regulation. 

On this point, however, it is acknowledged that in February 2026, the Company adopted an updated version of its Data Retention Policy (the so-called “Data Retention Policy”), in which a specific five-year storage period was established for personal data processed for the purpose of verifying customers’ creditworthiness (see Annex 1 of the note dated May 29, 2026, p. 2).

4.3. The Unlawfulness of the Processing Carried Out as Part of the Group’s Efforts to Refine Its Customer Rating Assessment System.

Following the inspection findings, it also emerged that Hera Comm S.p.A., through Hera S.p.A., which has been designated as the processor, conducts an analysis of customers’ personal data acquired as part of the Credit Check; all with the aim of refining the Hera Group’s customer credit rating assessment system (see Hera S.p.A.’s report of March 20, 2024, p. 2). 

More specifically, this activity consists of “monitoring the risk profile of the Group’s credit portfolio through the analysis of both internal and external credit and financial data,” aimed at defining the “rules for assessing the customer’s risk profile and monitoring their effectiveness” (see Annex 4 of the Hera S.p.A. minutes of March 20, 2024).  

To this end, since 2022, the Company has been retaining information regarding “all requests for contract establishment—concerning both electricity and gas—relating to individual customers (..) for which an external assessment was conducted by consulting the database of Cerved Group S.p.A. [and Experian Italia S.p.A.]” (see Hera S.p.A.’s note dated April 19, 2024, p. 2). 

This refers to the information obtained by Hera Comm S.p.A. as part of the external assessment process and contained in the XML file containing the customer’s rating; specifically, this information pertains to data relating to the “CGS-X Score,” “SIC Details,” and “Retail Score Info,” as well as the sub-scores included in the aforementioned items (see, in greater detail, para 2.1. above). 

Also subject to the aforementioned analysis are customers’ personal data—relating to past delinquencies—collected by the Company for the purposes of the internal assessment (see Hera S.p.A.’s minutes of March 20, 2024, p. 2; see also Annex 2 of the Hera S.p.A. note dated April 19, 2024, and Annex 8 of the Hera S.p.A. minutes dated March 20, 2024).

With regard to the processing of the personal information described above, which Hera Comm S.p.A. obtains from Experian Italia S.p.A. and Cerved Group S.p.A., the following points should be highlighted.

First, it should be noted that the processing of data provided by Experian Italia S.p.A., within the framework of the Credit Information System (so-called SIC), is lawfully carried out, provided that the specific regulatory provisions of the sector are complied with (see Art. 6-bis of Law No. 148 of September 14, 2011; Art. 30-ter of Legislative Decree No. 141/2010; see also Law No. 124/2017), as well as the provisions of the Code of Conduct for information systems managed by private entities regarding consumer credit, creditworthiness, and timely payments (hereinafter the “SIC Code of Conduct,” adopted by resolution of the Data Protection Authority on October 6, 2022, and available on the Authority’s website as Web Doc. No. 9818201). 

The SIC Code of Conduct establishes adequate safeguards to protect the rights of data subjects and sets forth specific rules of conduct that industry operators are required to follow in order to demonstrate that the processing complies with the Regulation (see Recital 77 and Articles 24(3), para 3), 32(para 3), and 28(para 5) of the Regulation). 

On this point, the legislature has intervened on several occasions to grant access to the data contained in the aforementioned SICs to various parties, including, currently, pursuant to article 6-bis, of Decree-Law 138/2011 and Art. 30-ter of Legislative Decree 141/2010, “including entities authorized to sell electricity and natural gas to end customers pursuant to applicable law.” 

Pursuant to the aforementioned provisions, “such entities (so-called “accessors”) (..) are authorized to consult the personal data contained in the SICs, entering into specific agreements for this purpose with one or more SIC operators” (see, in this regard, points 5 and 6 of the “Preamble” to the aforementioned SIC Code of Conduct). 

In accordance with this provision, on November 3, 2021, Hera Comm S.p.A. and Experian Italia S.p.A. signed the agreement titled “General Terms and Conditions” (see Annex 6 and related attachments to the minutes of Hera S.p.A. dated March 19, 2024, and Annex 5 to the minutes of Hera S.p.A. dated March 18, 2024).

In light of the foregoing, Hera Comm S.p.A., as the data recipient, may process the information obtained from the SIC “exclusively for purposes related to the assessment, assumption, or management of credit risk, [as well as] for the assessment of the creditworthiness and payment punctuality [of the potential customer]” who has requested to establish a contractual relationship with the Company (see Article 3, Article 8, paragraph 1, and Article 18, paragraph 1, of the SIC Code of Conduct).

More broadly, the aforementioned agreement of November 3, 2021, provides that Hera Comm S.p.A., as it belongs “to one of the categories of entities referred to in paragraph 5 of Article 30-ter of Legislative Decree No. 141 of August 13, 2010, No. 141, (..) may (..) have access to the SIC Experian system with the right to consult the data contained therein within the limits of the Permitted Purposes and in accordance with the terms and conditions set forth in these Special Conditions, the General Conditions, and the SIC Code of Conduct” (see Articles 1.2 and 6.1 of “Annex 1 to the General Terms and Conditions – Special Terms and Conditions”).

In this regard, it is worth noting that all parties accessing the SICs must comply with the principle of purpose limitation, which consists of credit protection and the mitigation of related risk, by virtue of which the consultation of a data subject’s personal data may take place only if strictly related to the processing of a request aimed at establishing a relationship with said data subject. 

Therefore, the processing of data obtained from the SICs is unlawful if carried out for additional purposes or, in any case, not specifically linked to a request by a potential customer to enter into a contract with the participant/accessor (see, among others, the ruling of the Data Protection Authority dated July 31, 2002, web doc. no. 30000; ruling dated May 4, 2002, web doc. no. 1302311; Decision of May 4, 2006, web doc. no. 1302373).

With specific reference to the case at hand, in light of the principles set forth above, it follows that the processing operations of data acquired from Experian Italia S.p.A., carried out by Hera Comm S.p.A. for the purpose of refining the customer rating assessment system, are conducted in violation of Article 5(1)(b) of the Regulation. 

This is because—contrary to what the Company asserted in accordance with paragraph 3(d) of this decision—such processing is aimed at pursuing an additional purpose that is incompatible with the original purpose underlying the collection of the aforementioned personal data.  

Similar considerations apply to the processing carried out by Hera Comm S.p.A. concerning the commercial information it obtained from Cerved Group S.p.A.

On this point, it should be noted that commercial information activities are carried out subject to a specific prefectural license issued pursuant to Art. 134 of the Consolidated Law on Public Security (Royal Decree No. 773/1931, as amended and supplemented), and that such activity is governed by specific provisions that define its characteristics and methods of operation(see Ministerial Decree No. 269 of December 1, 2010, and Ministerial Decree No. 56 of February 25, 2015, as well as Royal Decree No. 773/1931).

Within this regulatory framework, the processing of personal data in question must be carried out in accordance with the Code of Conduct for the Processing of Personal Data in the Field of Commercial Information (hereinafter the “Code of Conduct for Commercial Information”), adopted by the Data Protection Authority by resolution dated April 29, 2021 (available on the Authority’s website as Web Doc. No. 9586215). 

The Code of Conduct provides that commercial information shall be provided to clients for the purpose of conducting “assessments of the economic, financial, and asset situation of the data subjects, as well as their soundness, solvency, and reliability,” for the purpose of establishing and managing relationships—including pre-contractual ones—with the data subjects and providing them with goods, services, and other benefits (see Articles 2, paragraph 2, letter c), and 6 of the Code of Conduct on Commercial Information). 

All of this is based on specific agreements entered into with commercial information service providers, such as the one signed, in the case at hand, on November 3, 2021, by Hera S.p.A., in the name and on behalf of Hera Comm S.p.A., and by Cerved Group S.p.A. (see Annex 4, “Contract for the Provision of Commercial Information Services,” of the minutes of Hera S.p.A. dated March 18, 2024); a contract that, specifically, concerns the provision of a service aimed at “the implementation and rollout of scorecards for the onboarding of new customers” (see also the Preamble to the “Financial Terms—Access to Cerved & Experian Services During the Evaluation Phase Through the Adoption of Integrated Models for the Retail and Business Segments,” in the minutes of Hera S.p.A. dated March 18, 2024, Appendix 4).  

This agreement, in accordance with the provisions of the Code of Conduct for Commercial Information, stipulates that “all personal data [collected] during the term of the Contract shall be processed by each of the Parties solely for the purposes specified in the Contract and in a manner necessary for the performance thereof, as well as to comply with any legal obligations, EU regulations, and/or requirements of the Data Protection Authority” (see Art. 23.1 of the “Contract for the Provision of Commercial Information Services,” from the minutes of Hera S.p.A. dated March 18, 2024, Annex 4).

It follows, therefore, that the personal information acquired, in this specific case, by Hera Comm S.p.A., from Cerved Group S.p.A., cannot be processed for additional purposes that are incompatible with those identified in the Agreement and in the aforementioned Code of Conduct for Commercial Information, which are aimed at assessing the reliability of a potential customer for the purpose of deciding whether or not to accept their request to establish a contractual relationship. 

The processing carried out by the Company with respect to the aforementioned personal data is therefore unlawful pursuant to Article 5(1)(b) of the Regulation.

Finally, it should also be noted that the overall customer data processing operations carried out by Hera Comm S.p.A. in the present case involve the long-term storage of information obtained from Experian Italia S.p.A. and Cerved Group S.p.A. for subsequent processing aimed at refining the Hera Group’s customer rating assessment system.

In the case at hand, the storage of processed data for possible (re)use creates the risk that, over time, the data originally collected from the databases managed by Experian Italia S.p.A. and Cerved Group S.p.A., and subsequently retained by Hera Comm S.p.A., may change and therefore no longer be up to date. 

This is because data processing for commercial information purposes and that related to the management of a SIC —both of which, moreover, are carried out by companies specialized in these fields and, in the case of commercial information, specifically authorized by a prefectural license—are governed by specific regulatory and ethical provisions aimed at ensuring, among other things, the accuracy of the data made available to clients.

The processing carried out by Hera Comm S.p.A. in the manner described above therefore also constitutes a violation of the principle of accuracy set forth in Art. 5, para. 1, subparagraph d) of the Regulation. 

It should also be noted that the processing of outdated data, as defined in this paragraph—given the specific nature of the aforementioned information (pertaining to the creditworthiness of the data subjects) and its impact on the decisions made by the Company regarding its customers— could result in adverse consequences for the fundamental rights and freedoms of the data subjects. 

Finally, it should be noted that the processing activity described above has been carried out since 2022 and that, in the years 2022, 2023, and 2024 (through March 18), it involved 1,003,657 individuals (Annex 3 of the Hera S.p.A. minutes dated March 19, 2024).

Taking all of the above recitals into account, Hera Comm S.p.A. is therefore found to have violated Article 5(1)(a), (b), and (d) of the Regulation.

5. Conclusions: Declaration that the processing was unlawful. Corrective measures pursuant to Art. 58(2) of the Regulation.

In light of the overall findings, the Authority considers that the statements, documentation, and explanations provided by the controller during the investigation do not sufficiently address the objections notified by the Office in thenotice initiating the proceedings and are therefore insufficient to warrant the dismissal of this proceeding, as none of the cases provided for in Art. 11 of the Data Protection Authority’s Regulation No. 1/2019 apply.

The processing of personal data carried out by Hera Comm S.p.A., which is the subject of this decision, was therefore conducted in violation of Article 5(1)(a), (b), (d), and (e); as well as Articles 12, 13, 14, 15, and 28 of the Regulation. 

With regard to the exercise of the corrective powers referred to in Article 58, para 2, of the Regulation, it is first noted that Hera Comm S.p.A., during the proceedings, voluntarily adopted certain initial measures aimed at bringing the processing of customer data into compliance with the Regulation, in accordance with the regulatory framework described above. 

Specific reference is made to the adoption of the Joint Controller Agreement dated August 1, 2024; the update, effective February 2026, of the so-called “Data Retention Policy”; as well as the cessation of all processing activities carried out through the analysis of customers’ personal data collected as part of the Credit Check, for the purpose of refining the Hera Group’s customer rating assessment system (see above, paragraphs 3(d), 4.1. and 4.2. of this decision). 

Notwithstanding the foregoing, in light of the additional critical issues identified with respect to the controller, as detailed in this decision, it is deemed necessary to order the controller, pursuant to Article 58(2)(c) and (d) of the Regulation, to implement the following corrective measures:

a) the development of a new template for responding to requests for access, pursuant to Art 15 of the Regulation, containing all information relating to the “CGS-X Score” and the additional sub-scores, as well as the logic and criteria applied to the system for calculating said score;

b) transmission of the aforementioned response template pursuant to Article 15 of the Regulation also to Messrs. XX, XX, Mr. XX, XX, and XX;

c) adoption of a procedure designed to ensure that the data subject can fully exercise the right to rectification pursuant to Article 16 of the Regulation, with respect to inaccurate and/or incomplete personal data processed for the purpose of verifying customer reliability. This procedure must take into account the obligation, set forth in Article 22(3) of the Regulation, to implement appropriate measures to protect the rights, freedoms, and legitimate interests of data subjects; specifically through the right “to obtain human intervention by the controller, [to] express one’s opinion, and to contest the decision” made by the controller (see Article 22(3) of the Regulation). 

Finally, it should be noted that the violations, as established in the reasoning section, cannot in any way be considered “minor” within the meaning of Recital 148 of the Regulation; given the multiple violations alleged and the number of data subjects involved, as well as the additional factors explained in greater detail in paragraph 6 of this decision.

6. Injunction Order.

The Data Protection Authority, pursuant to Article 58, para 2, subparagraph (i) of the Regulation and Article 166 of the Code, has the power to impose an administrative fine as provided for in Article 83 of the Regulation, by issuing an injunction order (Article 18. Law No. 689 of November 24, 1981), in relation to the processing of personal data carried out by Hera Comm S.p.A., which has been found to be unlawful, as set forth herein. 

The violation of the provisions referred to above entails the application of the administrative fine provided for in Art. 83, para. 4, subparagraph (a), and para. 5, subparagraphs (a) and (b), of the Regulation.

Having determined that Article 83(3) of the Regulation must be applied, which provides that “if, in relation to the same processing operation or to related processing operations, a controller […] intentionally or negligently infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the most serious violation,” the total amount of the fine is calculated so as not to exceed the maximum penalty provided for in Art. 83(5) of the Regulation.

With regard to the factors listed in Article 83(2) of the Regulation for the purposes of imposing the administrative fine and determining its amount, and taking into account that the fine must be “in each individual case effective, proportionate, and dissuasive” (Article 83(1) of the Regulation), it is noted that, in the case at hand, the following circumstances were taken into account:

- the significant severity of the violation (Article 83(2)(a) of the Regulation), in relation to its nature (concerning non-compliance with the general principles of lawfulness, fairness, and transparency, as well as those of purpose limitation, accuracy, and storage limitation), the manner in which it occurred (the multiple instances of unlawful conduct repeated over time), and its duration (approximately 2 years). Also considered relevant for this purpose are the context of the processing, as well as the large number of data subjects involved and the type of harm they suffered.  All of this, given that: the disputed transactions were carried out for the purpose of developing a risk profile regarding the reliability of potential customers in terms of timely payments; the unlawful conduct affected approximately 1 million data subjects; the violations found resulted, in most cases, to the detriment of the data subjects, in the refusal to enter into an energy and/or gas supply contract;

- the negligent nature of the conduct and the significant instance of accountability on the part of the controller with regard to the technical and organizational measures implemented (Articles 83(2)(b) and (d) of the Regulation). All of this, with particular regard to the lack and inadequacy—in the specific context at hand—of the measures and processes implemented by the Company concerning compliance with obligations related to the exercise of data subject rights. With regard to the subjective element, consideration is given to the fact that, concerning the processing activities carried out by Hera Comm S.p.A. aimed at verifying customer reliability, the Company failed to correctly identify the processing purposes related to refining the Hera Group’s customer rating assessment system, nor the roles—with respect to personal data protection regulations—to be assigned to the companies involved in the internal assessment activity;

- the fact that there are no previous relevant violations committed by the controller or previous measures referred to in Article 58 of the Regulation concerning the same subject matter (Article 83(2)(e) and (i) of the Regulation). On this point, it should be noted that Measure No. 440, dated July 17, 2024, adopted against Hera Comm S.p.A., was not taken into account for this purpose; this is due to the fact that the preliminary investigation pertaining to this decision was conducted concurrently with the one that led to the adoption of the aforementioned measure;

- in favor of the violator, account is taken of the fact that the Company has complied with the requirements set forth by the Authority in Measure No. 440, referred to above (Art 83(2)(i) of the Regulation);

- the adoption by the data controller of measures designed to mitigate or eliminate the consequences of the violation (Art. 83(2)(c) of the Regulation). In this regard, the fact that Hera Comm S.p.A. voluntarily adopted, upon becoming aware of the violation, certain initial measures to mitigate the effects of the unlawful processing—albeit measures that were only partially effective in reducing the risks—should be viewed favorably;

- the fact that the Company actively cooperated with the Authority during the proceedings (Articles 83(2)(f) of the Regulation);

- the nature of the information subject to the breach (Article 83(2)(g) of the Regulation), which, although not classified as special categories of data, is nonetheless considered sensitive as it reflects the reliability of customers’ payment timeliness; this also taking into account the potential economic and social consequences that may arise for the data subjects as a result of the unlawful processing;

- other mitigating factors (Article 83(2)(k) of the Regulation), such as the adoption of certain organizational measures, as well as the fact that the processing operations related to the aforementioned violations concern only a portion of the Company’s customer base. All of this is described in greater detail in para 3 of this decision.

It is further considered that, in the present case, the following factors are relevant in light of the aforementioned principles of effectiveness, proportionality, and deterrence to which the Authority must adhere when determining the amount of the fine (Art. 83(1) of the Regulation): the economic circumstances of the offender, determined on the basis of the Company’s turnover as reported in the financial statements for the year 2024 (the most recent available). 

In light of the above factors and the assessments made, it is deemed appropriate, in this case, to impose on Hera Comm S.p.A. an administrative fine in the amount of 5,800,000.00 euros (five million eight hundred thousand/00).

In this context, it is also deemed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Authority’s Regulation No. 1/2019, this section containing the injunction order must be published on the Data Protection Authority’s website.

This is in light of the specific nature of the data subject to the processing at issue—as it pertains to the data subject’s creditworthiness—as well as the nature of the violations found, which affected the general principles of processing, in particular the principle of transparency and the obligations regarding the exercise of the data subject rights. 

Finally, it is considered that the conditions set forth in Art. 17 of the Data Protection Authority’s Regulation No. 1/2019 are met.

NOW THEREFORE, THE DATA PROTECTION AUTHORITY

- declares, pursuant to Article 57(1)(f) of the Regulation, that the processing carried out by Hera Comm S.p.A., with its registered office in Imola, VAT No. 02221101203, as set forth in the reasoning, for the violation of Article 5(1)(a), (b), (d), and (e); as well as Articles 12, 13, 14, and 15 and Article 28 of the Regulation

- orders, pursuant to Article 58(2)(c) and (d) of the Regulation, the aforementioned company to comply, within six months from the date of notification of this decision, the requirements set forth in para 5 of this decision, while at the same time requiring the company to provide, within the aforementioned deadline, an adequately documented response pursuant to Article 157 of the Code; failure to provide such a response may result in the imposition of the administrative fine provided for in Article 83, para 5, letter e) of the Regulation;

ORDERS

pursuant to Article 58, para 2, subparagraph (i) of the Regulation, that Hera Comm S.p.A. pay the sum of 5,800,000.00 euros (five million eight hundred thousand/00) as an administrative fine for the violations set forth in this order;

ORDERS

pursuant to Article 58, para 2, subparagraph (i) of the Regulation, that the same Company pay the aforementioned sum of 5,800,000.00 euros (five million eight hundred thousand/00), as an administrative fine for the violations set forth in this order, in accordance with the procedures outlined in the attachment, within thirty days of the service of this order, failing which the necessary enforcement measures will be taken pursuant to Art. 27 of Law No. 689/1981.

It is noted that, pursuant to Article 166, paragraph 8 of the Code, the offender retains the right to settle the dispute by paying an amount equal to half of the imposed penalty within the time limit set forth in Article 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, set for filing an appeal as indicated below;

ORDERS

- pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, the publication of the injunction order on the Data Protection Authority’s website;
- pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Authority’s Regulation No. 1/2019, the publication of this order on the Authority’s website;

- Pursuant to Article 17 of the Authority’s Regulation No. 1/2019, the recording of the violations and the measures adopted in accordance with Article 58(2) of the Regulation in the Authority’s internal register provided for in Article 57(1)(u) of the Regulation.

Pursuant to Article 78 of Regulation (EU) 2016/679, as well as Article 152 of the Code and Article 10 of Legislative Decree No. 150 of September 1, 2011, an appeal against this decision may be filed with the ordinary courts by submitting a petition to the ordinary court of the location specified in the aforementioned Art 10, within thirty days from the date of notification of the decision, or within sixty days if the appellant resides abroad.

Rome, July 3, 2026

 

THE PRESIDENT
Stanzione

THE RAPPORTEUR
Stanzione

THE SECRETARY GENERAL
Montuori