On 21 July 2026, the Italian data protection authority Garante announced sanctions totalling €7.72 million across four companies involved in a single automated scoring system used to decide whether to activate a gas or electricity contract: two gas and electricity providers (€5.8 million and €1.4 million respectively), and Cerved Group S.p.A. (€400,000) and Experian Italia S.p.A. (€120,000) as credit and business-information providers.
The Garante found multiple violations of the GDPR in terms of transparency, information to data subjects, data retention and DSAR management, and ordered the companies to implement corrective measures, in particular to make processing more transparent and allow data subjects to understand how the scoring system works, how scores are attributed and, eventually, to ask for rectification of incorrect data.
The main issue was the failure to adequately explain to data subjects, upon their requests, the logics behind the credit scoring system and how the process worked.
The interesting aspect of these decisions is that the Garante investigated not only the energy suppliers, but the entire chain involved in the automated scoring process and found different violations at each level of that chain.
How the Scoring System Worked
Both energy suppliers ran a group-wide automated scoring system, assigning a reliability score to decide whether to activate a supply contract. This credit check system had two stages:
- an in-house cross-check of the applicant's payment defaults, run across both companies' customer bases, returning a simple OK/KO
- if the internal check passed, the applicant's tax code was queried against Cerved's and Experian's databases, producing the integrated score
The Transparency Failure
People who were refused a contract asked, under Art. 15 GDPR, to know how their score was calculated. The response they got was vague: the energy suppliers said the score came from external providers, and told people to contact Cerved and Experian directly, even though they already had the full score and its breakdown on file.
The Garante rejected this approach. The company that receives the access request must answer it in full, not whichever vendor supplied the underlying data.
For access requests in similar cases, the authority relies on the CJEU jurisprudence on the requirements of the “meaningful information about the logic” of the scoring system: the explanation must be concise, in plain language, and describe the actual criteria used, not just a generic reference to “an external scoring system”.
Why Art. 22 GDPR Applied to Cerved and Experian
Cerved and Experian argued they weren't responsible for the outcome, since they only supplied a score and it was the energy supplier who decided whether to activate the contract or not. The Garante rejected this approach, relying on the CJEU's SCHUFA ruling (see our previous article on this decision): a score falls under Art. 22 GDPR whenever it decisively drives someone else's decision, even if the company producing the score never itself signs or refuses the contract. Since the energy suppliers' refusals were based directly on Cerved's and Experian's scores, the Garante found that all companies were bound to the same transparency duties and therefore owed data subjects a proper explanation of the logic behind the score.
Corrective Measures
The Garante ordered several corrective measures across all four companies. The main one was to update Art. 15 response templates to include the score, all sub-scores (the individual risk indicators, such as those based on age or place of residence, that feed into the overall score), and the logic used, in the very first response.
Building a GDPR-Compliant Credit-Scoring Process
These decisions address practical lessons for anyone who wants to implement a credit scoring process:
- Treat any third-party score that decisively drives a contract decision as falling under Art. 22, regardless of which company in the chain makes the final call.
- Whoever receives the access request must answer it in full, even if the underlying data comes from a vendor.
- Map every company involved in producing the score, not just the one that signs the contract.
- Set retention periods and processing purposes based on the actual purpose of the data, not convenience or a generic default.
This is, once again, a reminder of how important it is to involve your DPO or privacy counsel whenever automated decision-making is part of the picture, especially when several different companies are involved in producing the outcome.
No comments