EstEnergy S.p.A. – €1,400,000 Fine (Italy, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
EstEnergy S.p.A. was fined €1.4 million for mishandling personal data related to credit assessments. This case is significant because it emphasizes the need for companies to be transparent and lawful when sharing personal information within their corporate groups.
What happened
EstEnergy S.p.A. improperly shared personal data for creditworthiness assessments.
Who was affected
Individuals whose credit data was shared without proper compliance.
What the authority found
The authority found that EstEnergy did not meet GDPR requirements for data sharing and transparency.
Why this matters
This ruling serves as a reminder for companies to review their data-sharing practices and ensure they comply with GDPR rules to avoid hefty fines.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
Entities Involved
EstEnergy S.p.A. (hereinafter, the controller) is an Italian energy company supplying natural gas, electricity and related services. Before entering into contracts, the controller assessed the creditworthiness of potential customers through an internal and an external credit check. The internal assessment involved verifying whether potential customers had outstanding debts not only with the controller but also with Hera Comm S.p.A (hereinafter, the corporate group). The assessment was conducted on behalf of the controller by Hera S.p.A. (hereinafter, the processor), which returned an “OK” or “KO” result. Where the internal assessment returned an “OK”, the controller conducted an external assessment using credit information supplied by Experian Italia S.p.A. and commercial information provided by Cerved Group S.p.A. This information was combined using the “CGS-X” software provided by Major 1 S.r.l. (hereinafter, the software provider and processor). The software generated an integrated creditworthiness score and several underlying sub-scores. On the basis of the result, the controller could refuse to enter into an energy supply contract. The DPA received several complaints from data subjects whose requests for energy supply had been rejected on the basis of their risk profiles. However, when the data subjects contacted the credit and commercial information providers, they were informed that the relevant databases did not contain negative information or adverse events concerning them. The data subjects also submitted access requests under Article 15 GDPR. Although the controller responded within the applicable time limits, it did not provide the CGS-X score, the underlying sub-scores or meaningful information about the logic and criteria used to calculate the profiles. Instead, the controller referred the data subjects to the credit and commercial information providers. Following the complaints, the DPA consolidated the proceedings and initiated an ex officio investig
Related Enforcement Actions (0)
No other enforcement actions found for EstEnergy S.p.A. in IT
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
3 July 2026
Authority
Garante per la protezione dei dati personali
Fine Amount
€1,400,000
GDPRhub ID
gdprhub-10155About this data
Cite as: Cookie Fines. EstEnergy S.p.A. - Italy (2026). Retrieved from cookiefines.eu
Last updated: