TL;DR for the DPO
Three decisions of 3/7/2026 on the same chain: those providing the score (Experian, Cerved) and those using it to decide whether to activate a supply contract (Hera Comm). Recurring breaches: Arts. 5, 12, 13, 14, 15 and 28 GDPR, plus privacy by design and by default. For Experian the aggravating factors are gravity (transparency, rights, minimisation), repeated conduct and duration: about two and a half years.
The three points that matter
- Responsibility cannot be delegated to the score provider: the company using the credit check to decide on a contract is the controller of that processing. It must inform the individual, state the logic of the assessment and honour the right of access, even when data comes from an external provider.
- Article 28 is the weak link: relationships between controller and scoring provider must be governed by contracts that actually describe the processing, not by generic clauses. In the Hera Comm case the Art. 28 breach is charged alongside the principle-based ones.
- Privacy by design and by default (Art. 25) becomes a standalone charge: fixing it afterwards is not enough, the system had to be built with protective settings. The same line seen in the AgID and Character.AI decisions.
What to do now, in practice
For clients assessing their own customers (utilities, telcos, rental, leasing, e-commerce with deferred payment): 1) check the notice clearly states that an assessment is carried out and on what data; 2) map the flow to the scoring provider in the Art. 30 register and review the Art. 28 agreement; 3) prepare a response procedure for access requests covering the score and its logic; 4) document privacy-by-design choices, including default settings.
Why it matters for your clients
Credit checking is one of those activities almost nobody records in the register, because it feels like 'a commercial verification'. Three decisions in one day say otherwise: it is processing in its own right, with information duties and rights to guarantee. For a DPO it is a concrete audit opportunity on a process clients often do not realise they run.
Official source:Italian Data Protection Authority - decisions of 3 July 2026, doc. nos. 10273659 (Experian Italia), 10273926 (Hera Comm), 10273976 (Cerved)Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free