enforcement action IT enforcement 8/10
Government · Garante per la protezione dei dati personali

The Italian Data Protection Authority (Garante) sanctioned Hera Comm Spa and EstEnergy Spa for a total of €7.72 million. The fines were imposed because the companies denied contracts based on a scoring system, and the Garante affirmed the right of individuals to be informed about the score that led to the denial, emphasizing transparency in automated decision-making affecting consumers.

Action required

Companies using automated scoring for contract decisions must ensure transparency by providing individuals with access to the underlying score when a contract is denied.

Binding status

binding

Governing body

Garante per la Protezione dei Dati Personali

Direction

restrictive

Innovation impact

constraining

Enforcement details

Agency

Garante per la Protezione dei Dati Personali

Penalty

7,720,000

Compliance requirements

Required disclosures

  • Disclosure of the automated score used to deny a contract

Transparency requirements

  • Right to knowledge of score in automated decision-making

AI technologies

predictive analytics

Affected industries

energy

Affected roles

compliance officergeneral counselcto

"Sì alla conoscenza dello score alla base del contratto negato"

Enriched 2026-07-22

Stay informed

Get daily intelligence briefs on this and related regulatory developments.

Start 14-day trial