Editorial explainer · official source (Italian Data Protection Authority)medium
The contract refused by a score nobody explains: EUR 7.72 million from the Italian DPA
On 21 July 2026 the Italian Data Protection Authority published four decisions dated 3 July, totalling EUR 7.72 million: EUR 5.8 million against Hera Comm, EUR 1.4 million against EstEnergy, EUR 400,000 against Cerved Group and EUR 120,000 against Experian Italia. At the centre is a system that automatically decides whether to accept or refuse an electricity and gas contract on the open market, based on a score built by querying external databases around 700,000 times a year. The legal point is not that the score exists: it is that the people subject to it were never told what it was made of. And the right to know, the Authority recalls citing the Court of Justice, is satisfied neither by a formula nor by a refusal.
What happens when you apply for an electricity contract
You apply to switch on an electricity or gas supply on the open market. You fill in your details, submit them, and a refusal comes back. No useful explanation: your application was not accepted.
What happened in between, and almost nobody pictures, is that your data were sent to one or more external databases, which returned a summary judgement on your reliability as a payer. A piece of software combined those judgements into a single number and, on the basis of that number, decided.
The software is called CGS-X, supplied by Major 1 S.r.l.; the indicator it produces is the «Integrated Utilities Score», fed by Cerved's Retail Utilities Score and Experian's ESX Score, plus a series of sub-scores. The volume stated in the file: «a total of around 700,000 queries are performed each year».
We are not talking about a mortgage. We are talking about the lights.
The four decisions
On 3 July 2026 the Authority adopted four injunction orders, published on 21 July alongside a press release. The total is EUR 7.72 million.
Cerved Group is found in breach of art. 5(1)(a) and arts. 12 and 15; Experian Italia of art. 5(1)(a) and (c) and arts. 12, 15 and 25. The fines take account of economic capacity calculated on 2024 annual accounts; corrective measures must be implemented within six months.
One necessary clarification, because it touches a GDPR article that is not involved here in the way one might assume: Article 22, on automated decisions, does not appear among the provisions found to be infringed. It appears in the prescriptions, at paragraph 3, on the right to obtain human intervention. It is therefore not correct to say the companies were fined for breaching Article 22.
The core of the decision: what «explaining» means
The most important passage is not about the figures but about the content of the right of access. The Authority writes that «data subjects, in this case, have the right to full awareness of all the elements making up the assessment of their creditworthiness, including those taken into account by the controller in assigning the score, as well as the calculation criteria used».
Here the Authority invokes the Court of Justice of the European Union, judgment of 27 February 2025 in case C-203/22, which had already fenced the perimeter on both sides: «neither the mere communication of a complex mathematical formula, such as an algorithm, nor a detailed description of all the steps in an automated decision-making process can satisfy those requirements».
It is a definition with two walls. On one side, saying it is an algorithm, here is the code is not enough: that is not an explanation, it is a referral to an object the individual cannot read. On the other, recounting every step of the chain is unnecessary: nobody is asking for the maintenance manual. What must be communicated sits in between: which information was used, and by what criteria it weighed.
- 01The contract applicationdata go out to the external databases
- 02The scoreCGS-X combines the providers' scores into a single number
- 03The decisionthe contract is accepted or refused · and here the right to understand arises
In the case at hand the complaint is very practical: the answers given to people asking about their own case did not put them in a position to understand. The Authority puts it this way about one of the companies: «The inadequacy of the responses provided by Hera Comm S.p.A. therefore did not put the data subject in a position to be aware of the lawfulness and fairness of the processing».
The resulting prescription is equally concrete: the «definition of a new response template for access requests under Article 15 of the Regulation, containing all information relating to the "CGS-X Score" and the further sub-scores, as well as the logic and criteria applied in the calculation system».
Not a statement of principle: a form to be rewritten.
Why this case also concerns security people
There is a reason a credit scoring decision ends up on a cybersecurity site, and it is not simply that the two fields sit next to each other.
A system querying external databases 700,000 times a year is, technically, a continuous flow of personal data to third parties, governed by processor contracts — the Article 28 finding is exactly this. Every query is a surface: data going out, a supplier responding, a log accumulating somewhere. In a setup like this, the security question «who has access to what, for how long, and under what contract» and the data protection question are the same question in different words.
And there is a second, subtler point. An archive holding, for millions of people, a summary judgement of economic reliability is a valuable target regardless of how it was built. Data minimisation — the Article 5(1)(c) finding against Experian — is not only a legal principle: it is the security measure that reduces the damage of a breach that has not happened yet.
What you can do
If you were refused a contract, you can ask why. The right of access under Article 15 GDPR also covers the elements that determined the score and the calculation criteria, not just the list of data processed.
Do not accept «it's the system» as an answer. Per the Court of Justice and these decisions, neither pointing at the algorithm nor silence satisfies the obligation.
You can request human intervention. This is Article 22(3), invoked in the prescriptions: an automated decision producing significant effects should not remain the last word.
Ask for the upstream data to be corrected too. If the score rests on wrong information in an external database, rectification must be sought there as well: fixing the outcome without fixing the source only works once.
What we do not know
A genuine discrepancy between sources should be flagged: the press release refers to infringements «lasting around two and a half years», but the Hera Comm and EstEnergy decisions read «around 2 years». The longer period concerns Cerved and Experian. This is not a detail to be smoothed over for convenience.
The total number of people affected is not quantified: the prescriptions cite five complainants, anonymised. The sub-scores are [REDACTED] in the published text, so the exact composition of the score is not in the public domain. It is not known whether the companies will pay a reduced amount or file an objection within the statutory deadline.
Finally, a note on continuity: the EUR 120,000 decision against Experian Italia belongs to this same group of rulings and has already been covered on these pages from the angle of credit information systems. Here the angle is different — energy supply and the refused contract — and the two readings do not replace one another.