Four companies fined a total of 7.72 million euro because an automated system decided, on the basis of a reliability score, whether or not to activate an electricity and gas supply; and the customers who were turned down could not find out how that score had been built. In its press release of 21 July 2026 the Italian Data Protection Authority (Garante) made public the decisions of 3 July against Hera Comm, EstEnergy, Cerved Group and Experian Italia, and set out a clear principle: anyone refused a service on the strength of automated scoring has the right to understand its logic.
A score that opens or closes access to the contract
The investigations began with reports from citizens who had been denied supply on the basis of a negative reliability score, without being given clear information on the criteria and the logic used to assign it. Hera Comm and EstEnergy, suppliers of electricity and gas, ran a system that gave prospective customers a score to decide whether to proceed with the contract. The Garante found numerous and serious breaches concerning transparency, information to data subjects, data retention and the handling of requests to exercise rights, and imposed 5.8 million euro on Hera Comm and 1.4 million euro on EstEnergy. What is being sanctioned is not the computing power but the opacity: a score that has a concrete effect on a person’s life, namely access to an essential good, cannot remain a closed box.
The logic behind the score, and the right to reach it
Alongside the fines, the Authority ordered corrective measures: more transparent procedures allowing data subjects to understand how the scoring system works, to obtain complete information on the scores assigned and to request rectification of inaccurate data used in the assessments. This is the core of the rules on automated decisions: where a determination that significantly affects a person is based solely on automated processing, the controller must make the underlying logic intelligible, under Articles 13, 15 and 22 of the GDPR. The point deserves attention because private scoring of economic reliability remains a matter of data protection law, whereas social scoring by public bodies falls instead under the AI Act’s prohibition: two separate tracks that converge on the same requirement, whoever judges a citizen with a number must be able to explain it.
Those who supply the data are answerable too: Cerved and Experian
In the same proceeding the Garante also adopted two decisions against Cerved Group, fined 400,000 euro, and Experian Italia, fined 120,000 euro, both involved in supplying the data processed by the scoring system. For each the Authority found serious breaches of the GDPR, including one concerning the data subjects’ right of access; for Experian, also an infringement of the data minimisation principle, having processed data that were not necessary to compute the score. Responsibility, then, does not stop with those who use the score: it runs back to those who feed the model with data, and the compliance chain has to be reconstructed in full, as the shifting perimeter of the very notion of personal data shows.
What is left on the table
In setting the fines the Garante took into account the economic capacity of the companies, the gravity of the breaches, which lasted for about two and a half years, the large number of people involved and the harm suffered by data subjects. For the four companies the immediate outcome is twofold: to pay and, above all, to rewrite procedures and notices so that the customer can understand the score, reach it and correct its premises. For the sector the message is broader: an algorithm that filters access to an essential service must be explainable, the data feeding it must be accurate and reduced to what is necessary, and transparency is not a formal box to tick but the condition for that decision to be lawful. It is one of the areas the Authority’s 2026 inspection plan keeps under watch, and anyone processing reliability profiles would do well to reread their models now.




