Cerved Group S.p.A – €400,000 Fine (Italy, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Cerved Group S.p.A faced a fine for mishandling personal data related to creditworthiness checks. This is important because it shows that businesses must be transparent and accurate when processing personal data, especially in sensitive areas like credit.
What happened
Cerved Group S.p.A was fined for inadequately responding to requests from individuals regarding their personal data used in creditworthiness assessments.
Who was affected
Individuals whose creditworthiness was assessed by Cerved Group S.p.A. were affected by the mishandling of their personal data.
What the authority found
The Italian authority found that Cerved Group S.p.A. failed to provide proper information to individuals about their personal data processing, violating GDPR requirements.
Why this matters
This ruling highlights the need for companies to be transparent and accurate in their data handling practices. Businesses must ensure they respond adequately to individuals' requests about their personal data.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The DPA received several complaints from data subjects concerning Cerved Group S.p.A. (the controller) an Italian credit rating agency. The controller was processing the personal data of data subjects for the purpose of verifying the creditworthiness of potential customers of two energy suppliers. As a result of the risk profiles attributed to them, data subjects were declined the supply of energy. When data subjects requested access to their data from the controller under Article 15 GDPR, they were informed that their databases did not contain negative information or adverse events justifying the denial of energy supply. The DPA conducted an investigation, and found that the controller provided different responses to different data subjects depending on whether their personal data had been recorded in their system. For data subjects where there was no negative information on them the controller claimed that no personal data processing had been conducted for commercial information purposes. Nevertheless, a score based on their residential address, age and place of birth was generated. For those data subjects where information was present on their databases the controller provided them with the personal data which was present. The DPA further found that the controller did not provide reference to the scores and sub-scores assigned by the controller to the data subjects. The DPA held that in light of the controller inadequately responding to data subjects requests, which prevented them from accessing all the information processed for the purpose of calculating their risk profile, and to understand how the score was used in the decisions of the energy suppliers, data subjects were effectively prevented from exercising their rights. Particularly, the DPA held that the controller did not provide data subjects with all the necessary information, such as certain scores, and the logic and criteria used to calculate the scores, which prevented them from determining the law
Related Enforcement Actions (0)
No other enforcement actions found for Cerved Group S.p.A in IT
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
7 March 2026
Authority
Garante per la protezione dei dati personali
Fine Amount
€400,000
GDPRhub ID
gdprhub-10236About this data
Cite as: Cookie Fines. Cerved Group S.p.A - Italy (2026). Retrieved from cookiefines.eu
Last updated: