The Italian authority sanctions Hera Comm S.p.A. for data processing violations related to customer creditworthiness checks
Facts and context
The Italian data protection authority (Garante) today published a sanction decision against Hera Comm S.p.A. (including the imposition of a fine of €5,800,000) for breaches related to its practices of verifying the creditworthiness of potential customers and managing the rights of data subjects.
The case originated from several complaints by individuals who were denied energy supply based on a negative risk profile, even though the consulted credit reporting companies had no adverse information about them.
Grounds for the decision
The investigation revealed that the company used a two-step creditworthiness verification process. A first internal assessment consisted of checking payment defaults within Hera group companies. If positive, an external assessment was launched via software called "CGS-X," which combined scores from two external providers (Experian Italia S.p.A. and Cerved Group S.p.A.) to generate an integrated composite score. The authority identified several violations:
- Breaches of the principles of fairness and transparency (Article 5(1)(a) of the GDPR) and information obligations (Articles 13 and 14 of the GDPR): The authority found that the internal payment default verification procedure involved data communication between different group companies (Hera Comm S.p.A. and EstEnergy S.p.A.) without the data subjects being specifically informed. The information provided was too generic and did not describe this specific purpose, thus violating the transparency requirement.
- Violation of the controller's obligations (Article 28 of the GDPR): The act of appointing the parent company, Hera S.p.A., as processor did not specifically cover the processing of customer data from EstEnergy S.p.A. on behalf of Hera Comm S.p.A. The documented instructions were therefore incomplete regarding the processing operations actually carried out.
- Non-compliance with the right of access and modalities of exercising rights (Articles 12 and 15 of the GDPR): Responses to access requests were incomplete and misleading. The company referred complainants to credit agencies, claiming not to know the details of the scoring, while it held the detailed results (the "CGS-X Score" and its sub-scores). The authority recalls, citing recital 63 of the GDPR and the case law of the Court of Justice of the European Union (case C-203/22), that the controller must provide full access to data, including meaningful information about the logic used for scoring, to allow the data subject to verify the lawfulness and accuracy of the processing.
- Violation of the principle of storage limitation (Article 5(1)(e) of the GDPR): The company had not defined a specific retention period for data collected during creditworthiness verification. Applying by default a 10-year period, provided for accounting documents, was deemed excessive and not compliant with the purpose of the processing, which is punctual and pre-contractual.
- Breaches of the principles of purpose limitation and accuracy (Article 5(1)(b) and (d) of the GDPR): The authority considered the reuse of creditworthiness data (including detailed sub-scores) for a subsequent purpose of "refining the scoring system" unlawful. This processing, which concerned 1,003,657 individuals, is incompatible with the initial and limited purpose of evaluating a specific contract request. Moreover, retaining this data for future analyses violates the accuracy principle, as creditworthiness information may become outdated, leading to a risk of processing inaccurate data.
Authority's decision
Consequently, the authority imposed a fine of €5,800,000 on Hera Comm S.p.A.
Furthermore, the authority ordered the company to define a new response model to access requests, to communicate it to complainants, and to adopt a procedure ensuring the exercise of the right to rectification and the right to obtain human intervention to challenge automated decisions.
Lessons learned
This decision confirms that:
- Creditworthiness data obtained from credit information systems or credit reporting agencies may only be processed for the strict purpose of evaluating a specific request and cannot be reused for subsequent purposes, such as improving scoring models.
- The controller cannot discharge its obligation to respond to an access request by referring the data subject to the original data sources; it must provide access to all data in its possession, including derived scores and information on the calculation logic.
- A generic mention in a privacy policy about data sharing with "group companies" is insufficient; the information must specify the specific purposes for which such sharing occurs, notably if it concerns verifying past payment defaults within the group.
- The data retention period must be defined strictly in accordance with the purpose of the processing; applying a general legal retention period (such as for accounting) to data processed for a punctual and pre-contractual purpose is non-compliant.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire