The Italian authority sanctions Cerved Group S.p.A. for breaches related to the right of access and transparency in the processing of reliability scoring data
Facts and context
The Italian data protection authority (Garante per la protezione dei dati personali - GPDP) has today published a sanction decision against Cerved Group S.p.A. (including the imposition of a €400,000 fine) for breaches related to the exercise of the right of access by data subjects to their risk profiling data.
The case originated from several complaints by individuals who were denied energy supply by Hera Comm S.p.A. and EstEnergy S.p.A. based on a negative risk profile generated by a system using the company's data.
Grounds for the decision
The investigation revealed that energy suppliers used software querying Cerved Group S.p.A.'s databases to obtain a score called "Score de Détail Services Publics" ("Score Retail Utilities"). This score, combined with other information, determined the granting or refusal of the contract. When complainants exercised their right of access with Cerved Group S.p.A., the company responded that no negative information was present in its systems, never mentioning the existence, value, or composition of the score which had indeed been calculated and transmitted to the energy suppliers. The authority found the following breaches:
- Obligation to provide full access to data and transparent information (Articles 12 and 15 of the GDPR): The authority judged the company's responses to access requests as inadequate and incomplete. Relying on the case law of the Court of Justice of the European Union (judgment C-634/21 of 7 December 2023), it considered that the calculation of a payment probability score constitutes automated decision-making within the meaning of Article 22 of the GDPR when a third party's decision depends decisively on it. Consequently, under Article 15(1)(h) of the GDPR, data subjects had the right to obtain not only confirmation that their data were processed but also "meaningful information about the logic involved" in the score. However, the company failed to communicate the score itself, its components (including sub-scores based on socio-demographic data such as area of residence or age), and the calculation criteria, thus depriving individuals of the possibility to understand the processing and verify its accuracy. The authority noted that even the response templates corrected during the procedure remained incomplete.
- Obligation to process data lawfully, fairly, and transparently (Article 5(1)(a) of the GDPR): The failure to provide full and intelligible access constitutes a violation of the transparency principle. By not providing all processed information, the company prevented data subjects from "knowing and verifying the lawfulness and accuracy of the processing," as required by Recital 63 of the GDPR. This opacity resulted in depriving individuals of the possibility to effectively exercise other rights, such as the right to rectification or the right to challenge the automated decision.
Authority's decision
Consequently, the authority imposed a fine of €400,000 on Cerved Group S.p.A.
Furthermore, the authority ordered the company to implement, within six months, a procedure ensuring the full exercise of the right to rectification (Article 16 of the GDPR) for inaccurate or incomplete data related to the assigned score, especially when it is based on socio-demographic data.
Lessons learned
This decision reminds that:
- The calculation of a credit score that decisively influences a third party's decision (e.g., for contract conclusion) qualifies as automated decision-making under Article 22 of the GDPR, even if the score provider is not the final decision-maker.
- The right of access (Article 15 of the GDPR) regarding scoring processing implies providing the data subject not only with the final result (the score) but also its different components (sub-scores) and meaningful information about the calculation logic.
- The explanation of the logic underlying a score must be sufficiently clear to allow the data subject to understand how their personal data were used and the weight of different variables in the final result.
- A controller cannot invoke internal technical or organizational silos to justify an incomplete response to an access request; they are required to provide all personal data processed concerning the individual.
- The scope of an investigation may extend beyond the initial complainants to assess the overall compliance of a system, and the number of data subjects affected by the violation may include all individuals subjected to the same unlawful processing during the examined period.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire