The Italian authority sanctions EstEnergy S.p.A. for violations related to the processing of personal data in the context of customer creditworthiness assessment

The Italian data protection authority sanctioned an energy provider for the unlawful use of creditworthiness data to improve its evaluation models and for failures regarding transparency and data subject rights.

Facts and context

The Italian data protection authority (Garantor for the protection of personal data - GPDP) today published a sanction decision against EstEnergy S.p.A. (including the imposition of a fine of €1,400,000) for breaches related to its system for assessing the creditworthiness of potential customers, notably the use of such data for incompatible purposes and non-compliance with data subject rights.

The procedure was initiated following several complaints from individuals who were denied energy supply based on a negative risk score, even though the commercial credit reporting companies consulted indicated they held no negative information about them.

Grounds for the decision

The authority found several GDPR violations against the company, which used a credit assessment system based on an internal evaluation (search for unpaid debts within the group) and an external evaluation (consultation of credit information systems and commercial credit reporting providers).

  • Obligation of lawfulness, fairness and transparency (Article 5(1)(a) of the GDPR) and information (Articles 13 and 14 of the GDPR): The processing carried out within the internal evaluation was unlawful. EstEnergy shared data on its customers' unpaid debts with another group company, Hera Comm S.p.A., without properly informing the data subjects. The information provided was limited to a generic mention of data sharing with group companies, which did not allow individuals to understand that their possible unpaid debts would be shared and used to assess their creditworthiness for future contracts. This lack of transparency rendered the processing unfair and unlawful.
  • Obligation of purpose limitation (Article 5(1)(b) of the GDPR) and accuracy (Article 5(1)(d) of the GDPR): The company used the data collected for creditworthiness assessment (scores, sub-scores, credit information) for a secondary and incompatible purpose: improving its risk assessment system for the entire group. The authority considered that data obtained from credit information systems (such as Experian) and commercial credit reporting providers (such as Cerved), whose processing is governed by specific codes of conduct, can only be used for the initial and specific purpose of evaluating a contract application. Their retention and reuse to refine statistical models constitute a violation of the purpose limitation principle. Moreover, this prolonged retention creates a risk of processing outdated data, violating the accuracy principle.
  • Obligations regarding the exercise of rights (Article 12 and 15 of the GDPR): The responses provided to individuals exercising their right of access were inadequate and incomplete. The company limited itself to indicating that a risk profile had been detected, without communicating the assigned score, the sub-scores composing it, nor information on the logic used for the calculation, inviting individuals to contact the external data providers directly. The authority recalls, citing recital 63 of the GDPR and the case law of the Court of Justice of the European Union (case C-203/22), that the controller must provide access to all personal data it holds and meaningful information on the logic used, to allow the data subject to verify the lawfulness and accuracy of the processing.
  • Obligation of storage limitation (Article 5(1)(e) of the GDPR): EstEnergy did not have a specific retention period for data collected in the context of creditworthiness assessment. The application of a general ten-year period, provided for accounting documents, was deemed non-compliant with the storage limitation principle, as it was not justified by the purpose of the processing, namely a pre-contractual assessment.
  • Obligations related to the processor (Article 28 of the GDPR): The subcontracting contract with the parent company, Hera S.p.A., which carried out the internal evaluation, was incomplete. It did not include clear and specific instructions regarding the verification of unpaid debts with other group companies, constituting a violation of the controller's obligations in its relationships with its processors.

Authority's decision

Consequently, the authority imposed a fine of €1,400,000 on EstEnergy S.p.A.

Furthermore, the authority ordered the company to define a new response model to access requests, apply it retroactively to the complainants, and adopt a procedure ensuring the exercise of the right to rectification as well as the right to obtain human intervention to challenge automated decisions.

Lessons learned

This decision reminds that:

  • Sharing data on unpaid debts between different legal entities of the same group must be based on a solid legal basis, such as a joint responsibility agreement, and be subject to specific and transparent information to the data subjects.
  • In the case of automated decision-making, the right of access implies providing the data subject not only with the final decision but also with all intermediate data and scores used, as well as an intelligible explanation of the calculation logic.
  • Data obtained from credit information systems or commercial credit reporting providers to assess a specific application cannot be reused for incompatible purposes, such as training or improving internal scoring models.
  • The retention period for data collected for a pre-contractual assessment must be specifically defined according to this purpose and cannot be aligned with longer legal retention periods provided for other types of documents (e.g., accounting).

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire