Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Italy’s €400,000 Credit Scoring Fine: What U.S. Companies Should Know About the Next Phase of DSAR Enforcement

By Odia Kagan on September 4, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

Table of Contents

  • 1. DSAR enforcement is changing phases:
  • 2. Automated scoring increases in significance:
  • 3. Ordinary data may not always be ordinary:

400,000 EUR fine by the Italian DPA for a credit agency Cerved Group S.p.A’s failure to provide sufficient responses to a data access requests (DSARs) provides some insight into a possible direction for the future of privacy rights enforcement, in the US as well. 

In this case, a credit reporting agency provided different answers to access requests by individuals, not providing complete information, especially where such information was not favorable. The agency also refrained from providing information about credit score information, including sub-scores and scoring logic that it had in its possession. 

Other than the significant fines, what are some practice lessons for companies, both in the EU and the US: 

Link to 1. DSAR enforcement is changing phases: 1. DSAR enforcement is changing phases:

Whereas in the past the focus of enforcement had been on failure to respond at all, or failure to respond on time. Now, the regulatory scrutiny is moving to whether the information provided is sufficient. Per Italian Garante, by not providing the individual with sufficient information, the controller is preventing the individual from exercising rights like the right to correct information, the right to delete and even the right to request human intervention for automated processing. 

All these rights are present in the US privacy laws as well. In the US, the focus from agencies like CPPA has recently been on things like data minimization and symmetry opt-out requests, however, a focus on the substance of access request responses, could be a next step as more consumers start exercising their rights. 

Link to 2. Automated scoring increases in significance: 2. Automated scoring increases in significance:

Scores, especially ones that weigh on creditworthiness, could have significant impact on individuals and should be provided to them in a way that makes it easily understandable, with a concise explanation of the criteria and the logic behind the processing. In the US this could be equally applicable to AI generated scores, especially if the AI Transparency laws, like those of California and Utah, apply. However, information relating to creditworthiness may be carved out of scope if it is subject to the Fair Credit Reporting Act (FCRA). 

Link to 3. Ordinary data may not always be ordinary: 3. Ordinary data may not always be ordinary:

Seemingly ordinary information like residential address, age and place of birth can become sensitive information and take on greater significant if they are used to calculate a score regarding degree of risk for failure to pay.  For another example of residential address potentially being sensitive see new California law AB 2624, that will establish an address confidentiality program in connection with designated immigration support services providers.  

The Garante decision highlights that as privacy enforcement become more mature, in the EU and in the US as well, regulators may start to look deeper “under the hood”; not just whether you reply to a request, but also how well. This part of access requests becomes increasingly important as companies start using AI in connection with scoring and decision-making that give rise to additional rights to individuals like increased transparency and human intervention. 

Tags: AI
  • Posted in:
    Administrative and Regulatory, Banking, Finance and Securities, Privacy and Cybersecurity
  • Blog:
    Privacy Compliance & Data Security
  • Organization:
    Fox Rothschild LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo