Italy algorithmic accountability

Italy's Garante Fines Hera Comm €5.8M for a Secret Credit Score That Used Neighborhood Poverty Data to Deny Energy Contracts

Italy fined two energy suppliers €7.2M for a hidden algorithm that used census poverty data to deny gas and power to over 1 million people.

Italy's Energy-Scoring Fines, July 2026 People of Internet Research · Italy €5.8M Hera Comm fine Largest of four penalties for the … €7.72M Total fines, four firms Combined penalty across Hera Comm,… 1M+ People scored, 2022–2024 Applicants evaluated by the algori… €120K Experian Italia fine Penalized for incomplete disclosur… peopleofinternet.com
Italy's Energy-Scoring Fines, July 202… People of Internet Research · Italy €5.8M Hera Comm fine €7.72M Total fines, four firms 1M+ People scored, 2022–2024 €120K Experian Italia fine peopleofinternet.com

Key Takeaways

A score nobody could see, deciding whether you get power

On July 3, 2026, Italy's data protection authority, the Garante per la protezione dei dati personali, issued four enforcement orders against Hera Comm S.p.A., EstEnergy S.p.A., Cerved Group S.p.A., and Experian Italia S.p.A. — announced July 21 — for running an opaque credit-scoring pipeline that denied gas and electricity contracts to more than one million people between 2022 and March 2024. Hera Comm was fined €5.8 million, EstEnergy €1.4 million, Cerved €400,000, and Experian €120,000: €7.72 million in total.

The mechanism, built on a scoring engine called "CGS-X" supplied by software vendor Major 1 S.r.l., assigned each prospective customer a score from 0 to 100 across eight reliability classes. Anyone landing in class 6 or above was automatically rejected — no manual review, no explanation, no way to contest it. The inputs included prior payment defaults with Hera, external credit histories pulled from Cerved and Experian's "Score ESX," and — most strikingly — statistical risk indices tied to the applicant's residential area, built from census-level "neighborhood degradation" indicators. Personal attributes like age, birthplace, and property holdings fed the model too.

The case for scoring — and where it broke down

Energy suppliers have a real and legitimate problem: unpaid bills. Automated credit assessment is standard practice across utilities, banking, and insurance precisely because manually underwriting every applicant doesn't scale, and a supplier that can't screen for default risk passes the cost of bad debt onto paying customers through higher tariffs. GDPR itself doesn't ban automated scoring — Article 22 permits it when necessary for a contract, provided there are adequate safeguards. If Hera and EstEnergy had simply run a transparent, well-documented model with a clear appeals path, this would be unremarkable risk management, not a scandal.

What the Garante actually found was different in kind, not degree. The authority's ruling on Hera Comm (Provvedimento 10273926) documents that when customers exercised their GDPR Article 15 right of access and asked why they'd been denied, Hera's responses omitted the actual score, the sub-scores, and the calculation logic — precisely the information Article 15(1)(h) requires for any automated decision with legal effect. The companion order against Experian (Provvedimento 10273659) found the same pattern on the data-supply side: roughly 561 documented cases where individuals got incomplete answers lacking the "Score ESX" or its constituent "E5-35" sub-score, even after Experian revised its response templates. This isn't a proportionality dispute about how much scoring should be allowed — it's a finding that two rounds of correction still didn't produce a legible answer to "why was I denied electricity."

Why the geographic variable is the harder problem

The transparency failure is fixable with better paperwork. The neighborhood-degradation variable is a design choice, and a more troubling one. Feeding a credit model census data about the poverty level of an applicant's residential area is a proxy for penalizing people for living in low-income neighborhoods — the same statistical logic that produced redlining disputes in US mortgage and insurance markets for decades. For a discretionary product like a personal loan, that's already legally fraught. For gas and electricity — services every EU member state treats as essential, with dedicated protections for vulnerable consumers — building geography-as-destiny into an auto-reject algorithm is qualitatively worse than the transparency gap, because no amount of disclosure fixes a variable that's doing indirect proxy discrimination by design.

The Garante's finding wasn't that scoring itself is illegal — it was that Hera retained scoring data to refine its own model beyond the original contract-approval purpose, compounding an opacity problem into a data-minimization one (Article 5 GDPR).

The proportionate fix, and the one to avoid

The remedy the Garante actually imposed is instructive: not a ban on scoring, but a mandate — six months from notification — to make scores accessible to consumers, disclose the logic behind them, and let people correct inaccurate inputs. That's the right calibration. Italy already has form here: the Garante's 2025 telemarketing enforcement and earlier action against Eni Gas e Luce (€11.5 million, 2019) show a regulator willing to escalate fines but consistently stopping short of banning the underlying automated practice.

The risk for policymakers watching this case — in Brussels as the EU AI Act's high-risk classification rules for "access to essential services" come into fuller effect, and in other capitals drafting their own algorithmic-accountability rules — is overcorrecting into a presumption that any automated eligibility scoring for utilities is inherently suspect. That would raise costs for the compliant majority of applicants to punish a design flaw that transparency and a ban on geographic proxy variables would have already fixed. The actual lesson of Hera Comm is narrower and more useful: automated decisions with real-world stakes need an explainable basis and a contestable outcome, and models trained on proxies for poverty or place will eventually produce discriminatory results whether or not anyone intended them to. Regulators should keep enforcing that standard — and resist the temptation to legislate against automation itself.

Sources & Citations

  1. Garante Privacy — Provvedimento 3 luglio 2026 (Hera Comm)
  2. Garante Privacy — Provvedimento 3 luglio 2026 (Experian Italia)
  3. il Salvagente: 'Luce e gas negati da un algoritmo'
  4. iSimply: scoring clienti e sanzioni Garante
  5. GDPR.eu: Italy fines Eni Gas e Luce €11.5M