Italian Data Protection Authority (Garante) · 3 July 2026
Hera Comm S.p.A.
Non-compliance with general data processing principles
- Regulator
- Italian Data Protection Authority (Garante)
- Decided
- 3 July 2026
- Country
- Italy
- Sector
- Transportation and Energy
- Regulator’s reference
- Not recorded
- Fino case number
- 2026/IT/094
What happened
The Italian DPA has imposed a fine of EUR 5,800,000 on Hera Comm S.p.A. Hera Comm is the Hera Group's main energy retailer, selling electricity and gas nationwide. The controller assessed the creditworthiness of prospective customers using a credit score (CGS-X) supplied by an external provider, which combined scores and sub-scores drawn from a credit reference agency and a commercial information provider. The controller received and retained far more scoring data than the single value it used to accept or refuse applications, set no retention period for it, and unlawfully repurposed it to refine the group's creditworthiness model. It also failed to respond adequately to data subject requests, telling applicants that it did not know which elements produced the score or how it was calculated and referring them to the external providers, although the investigation established that the scores and sub-scores were in its systems. The controller further shared customer arrears data with another sales company in the group without informing data subjects, and the instructions given to the group parent acting as processor did not cover that activity. The data sharing was placed on a lawful footing by a joint-controllership agreement in August 2024. The conduct affected around one million people and led in most complaint cases to refusal of an energy supply contract.
Summary from the CMS Enforcement Tracker, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 12Transparent information, communication and modalities for the exercise of the rights of the data subjectRead →
- Art. 13Information to be provided where personal data are collected from the data subjectRead →
- Art. 14Information to be provided where personal data have not been obtained from the data subjectRead →
- Art. 15Right of access by the data subjectRead →
- Art. 28ProcessorRead →
- Data principles
- Data subject rights
- Processor obligations
- Transparency
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/IT/094.