Editorial explainer · official source (Italian DPA)medium
The Garante, Experian and the system that scores you
On 3 July 2026 Italy's data protection authority, the Garante, ordered Experian Italia S.p.A. to pay 120,000 euros, in a decision touching bedrock principles: lawfulness and transparency, data minimisation, privacy by design. At its centre is a Credit Information System — one of those databases where people's payment history ends up and from which a judgement on their reliability comes out. An explainer on what the decision says and why it concerns anyone who has ever applied for financing.
A score that decides, and the data behind it
When a person applies for financing, often it is not an officer who decides first but a system. Credit Information Systems — in Italy, SIC — gather payment history and return a reliability profile that banks and lenders consult before saying yes or no. Experian Italia S.p.A. runs one of these systems. It is a delicate role: whoever holds that data is not keeping just any archive, but the material used to judge people's financial lives.
The Garante's decision of 3 July 2026 lands precisely on this ground. The authority ordered Experian Italia to pay 120,000 euros under Article 83 of the GDPR and imposed corrective measures. It is not the figure that makes the case interesting — in the landscape of European fines it is modest — but the principles it invokes.
Transparency, minimisation, "by design"
The principles at the centre of the decision are the ones often cited and less often applied. The lawfulness, fairness and transparency of Article 5(1)(a): the person being assessed must be able to know and verify how their data is processed and — the Garante notes, in line with the European Board's guidance — have the tools to know the lawfulness and accuracy of that processing. The minimisation of point (c): process the data that is needed, no more. And the privacy by design and by default of Article 25: data protection is not an accessory added at the end, but a requirement to build into the system from the design stage.
During the proceeding the company adopted some measures: it updated its privacy notice in January 2025 to combine — its own words, cited in the file — completeness and intelligibility, and it put in place a specific data-retention policy. The Garante took these into account. That detail matters: cooperation and voluntary corrections affect the outcome, but do not erase a violation that has already occurred.
Why it concerns even those outside credit
This case can be read two ways. The narrow one: a company handling credit data was fined for how it processed it. The more useful one: it is a reminder of what three principles every data controller must respect mean in concrete terms. When a system decides something about a person, that person has the right to understand and to verify; the data collected must be what is necessary; and protection must be designed into the system, not stuck on afterwards.
Honesty imposes a limit: here we summarise the core of the decision — subject, amount, articles, context — not the entire legal reasoning, which sits in the full text published by the Garante and is the source to read for the details. But the message it yields needs no footnotes. Where data is used to give people a score, transparency and restraint are not courtesies: they are obligations, and the Garante enforces them.