The Italian authority declares Experian Italia S.p.A.'s data processing non-compliant and imposes a €120,000 fine
Facts and context
The Italian data protection authority (GPDP) has today published a sanction decision against Experian Italia S.p.A. (including the imposition of a €120,000 fine) for breaches related to transparency, the right of access, data minimization, and data protection by design in the context of its credit scoring activities.
The case originated from several complaints by individuals who were denied energy supply based on a negative risk profile calculated by Experian, while Experian had indicated to them that it held no adverse information about them in its credit information systems.
Grounds for the decision
- Obligation of transparency and respect for the right of access (Article 5(1)(a), 12 and 15 of the GDPR): The authority found that Experian's responses to access requests were systematically incomplete. The company limited itself to communicating the data present in its credit information system, omitting to provide the credit score ("Score ESX") assigned, its components (including those based on the residence address) and especially the "useful information concerning the underlying logic" as required by Article 15(1)(h) of the GDPR. Relying on the case law of the Court of Justice of the European Union (case C-634/21), the authority qualifies this scoring as an automated decision within the meaning of Article 22 of the GDPR, and based on the European Data Protection Board's guidelines 1/2022, it rejects the argument of a "layered disclosure," which in reality hindered the exercise of the rights of the 561 data subjects concerned.
- Obligation of data minimization and data protection by design and by default (Article 5(1)(c) and 25 of the GDPR): It was demonstrated that Experian transmitted to its technological partner data unnecessary for the calculation of the final score, notably the sub-scores "D4U" and "DG3r." This practice resulted from the use of a data transmission model (XML trace) designed for the banking sector and not adapted to the energy sector. The authority concluded that the company had not implemented appropriate technical and organizational measures to ensure that, by default, only data necessary for the purpose are processed, in violation of the principles of data protection by design and by default, as well as the principle of minimization.
Authority's decision
Consequently, the authority imposed a fine of €120,000 on Experian Italia S.p.A.
Furthermore, the authority ordered the company to bring its processing into compliance within six months, notably by revising its models and procedures for responding to access requests to ensure their completeness, by establishing a procedure for rectifying scores, and by limiting the data transmitted to its partners to the strict necessary.
Lessons learned
This decision confirms / specifies / recalls that:
- The calculation of a credit score constitutes an "automated decision-making process" within the meaning of Article 22 of the GDPR as soon as it decisively influences a third party's decision to contract or not with the data subject.
- The right of access regarding a credit scoring decision implies the communication not only of the input data but also of the final score, its components, and an intelligible explanation of the calculation logic, in accordance with Article 15(1)(h) of the GDPR.
- The approach of "layered disclosure" in response to an access request cannot justify providing an initially incomplete response and is only conceivable if it brings real added value to the data subject to understand a large amount of data, without imposing additional steps on them.
- Data exchange formats between partners must be specifically designed for each processing purpose to avoid transmitting superfluous data, in direct application of the principle of data protection by design.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire