Credit scoring firms face curbs after landmark EU data protection ruling | TechCrunch (2024)

Natasha Lomas@riptari / 2 months

Credit scoring firms face curbs after landmark EU data protection ruling | TechCrunch (1)

Credit scoring companies operating in the European Union could be facing tighter curbs under the bloc’s privacy laws following a ruling issued by the Court of Justice (CJEU) today. The referral relates to complaints brought against the practices of a German credit scoring company, called Schufa, but could have wider significance for credit information agencies operating in the region where the General Data Protection Regulation (GDPR) applies.

One complaint the CJEU considered centered on a case of “prolonged” data retention by the credit referencing firm of information relating to the granting of a discharge from remaining debts which is only kept in the German public insolvency register for six months. However, a code of conduct for German credit information agencies allows a retention period of three years for their own databases. And the Hessian Data Protection Authority had dismissed the complaint about the data retention; also seeking to argue the local court could not review its decision. The CJEU disagreed.

“The Court considers that it is contrary to the GDPR for private agencies to keep such data for longer than the public insolvency register,” it wrote in a press release on case C-634/21 (plus joined cases C-26/22 and C-64/22). “The discharge from remaining debts is intended to allow the data subject to re-enter economic life and is therefore of existential importance to that person. That information is still used as a negative factor when assessing the solvency of the data subject. In this case, the German legislature has provided for data to be stored for six months. It therefore considers that, at the end of the six months, the rights and interests of the data subject take precedence over those of the public to have access to that information.”

“In so far as the retention of data is unlawful, as is the case beyond six months, the data subject has the right to have the data deleted and the agency is obliged to delete the data as soon as possible,” the court added.

The CJEU also ruled on a second complaint that looks rather existential for credit scoring companies — being as it questions whether Schufa can automatically issue credit scores, given the GDPR provides protections for individuals subject to solely automated decisions with legal or significant impacts on them. So, essentially, they may need to obtain people’s explicit consent to being credit scored.

The Court held that Schufa’s credit scoring must be regarded as an “automated individual decision,” which its press release notes is “prohibited in principle by the GDPR, in so far as Schufa’s clients, such as banks, attribute to it a determining role in the granting of credit.”

If this kind of credit scoring is the basis for a decision by a bank, for instance, to deny an individual credit the practice risks ruling foul of EU data protection rules.

Though in the specific case it will be up to the Administrative Court of Wiesbaden to assess whether the German Federal Law on data protection contains a valid exception to the prohibition in accordance with the GDPR. And, if that’s so, to check whether the general conditions laid down by the GDPR for data processing have been met — such as ensuring individuals are aware of their right to object and to ask for (and get) human intervention, as well as being able to provide meaningful information about the logic of the credit scoring on request.

“Judicial review” of DPA decisions

In another significant ruling, the CJEU also made it clear national courts must be able to exercise what its PR calls “full review” over any legally binding decision of a data protection authority.

Privacy rights group noyb, which has had multiple run-ins with DPAs over their failure to act on (let alone enforce) complaints, seized on this as especially significant — dubbing it “full judicial review” of DPAs.

“The CJEU ruling massively increased the pressure on DPAs. In some EU member states, including Germany, they have so far assumed that a GDPR complaint from data subjects is merely a kind of ‘petition.’ In practice, this has meant that despite an annual budget of €100M the German DPAs have rejected many complaints with bizarre justifications and GDPR violations have not been pursued. In countries such as Ireland, more than 99% of complaints were not processed and in France any right of those affected to participate in the procedure concerning their own rights was denied. Some DPAs, such as the Hessian authority in the present case, have also argued that the courts are prohibited from reviewing their decisions in detail,” it wrote in a press release responding to the ruling.

“The CJEU has now put an end to this approach. It has ruled that Article 77 of the GDPR is designed as a mechanism to effectively safeguard the rights and interests of data subjects. In addition, the court has ruled that the Article 78 of the GDPR allows national courts to carry out a full review of DPA decisions. This includes the assessment whether the authorities have acted within the limits of their discretion.”

Higher GDPR fines on the way too?

The pair of significant rulings follow another handed down by the CJEU yesterday (also via, in part, another Germany case referral), which legal experts suggest could result in significantly higher penalties for breaches of the GDPR as it lowers the requirements for imposing fines on legal entities.

So while, in this case (C-807/21), the Court held that wrongful conduct is necessary for a fine to be imposed — that is, that a breach of the GDPR must have been committed “intentionally or negligently” — judges also said that, where a controller is a legal person, it is not necessary for the infringement to have been committed by its management body, nor is it necessary for that body to have had knowledge of that infringement.

They further stipulated that the calculation of any fine requires the supervisory authority to take as its basis the concept of “an ‘undertaking’ under competition law” (aka, per the Court PR, that “the maximum amount of the fine must be calculated on the basis of a percentage of the total worldwide annual turnover of the undertaking concerned, taken as a whole, in the preceding business year” — or, basically, that the revenue of an entire group of companies may be used to calculate a GDPR penalty for an infringement committed by a single unit of that group).

Jan Spittka, partner at law firm Clyde & Co., predicted beefier GDPR fines could result. “The overall context of the decision will make it way easier for the data protection supervisory authorities of the EU member states to sanction legal entities and is also likely to result in significantly higher fines on average,” he suggested in a statement.

“Against the background of this standard only a detailed and strictly monitored data protection compliance system may put a legal entity in a position to argue that it was unaware of the unlawfulness of its conduct with regard to GDPR infringements committed by an employee,” he also said. “Furthermore, a legal entity may exculpate itself if representatives or employees act totally out of the scope of their job description, e.g. when misusing personal data for private purposes.”

Europe’s top court clarifies GDPR compensation and data access rights

I am an expert in data protection laws, particularly in the context of the European Union. My knowledge spans various aspects of privacy regulations, with a focus on the General Data Protection Regulation (GDPR). I can provide insights into recent legal developments and their implications on businesses operating in the EU.

In a recent ruling by the Court of Justice of the European Union (CJEU), credit scoring companies within the European Union, including the German credit scoring company Schufa, are potentially facing tighter curbs under the EU's privacy laws. The ruling is a response to complaints against Schufa's practices and could have broader significance for credit information agencies operating in the region where the GDPR applies.

One key complaint addressed by the CJEU pertains to the "prolonged" data retention by Schufa, specifically related to information about the granting of a discharge from remaining debts. The court found it contrary to the GDPR for private agencies to retain such data for longer than the public insolvency register, which has a retention period of six months. The court emphasized that the discharge from remaining debts is of existential importance to individuals, and if data retention is unlawful beyond six months, individuals have the right to request deletion.

Another crucial aspect of the ruling involves the question of whether credit scoring companies like Schufa can automatically issue credit scores without obtaining explicit consent from individuals. The GDPR provides protections for individuals subject to solely automated decisions that have legal or significant impacts on them. The CJEU ruled that Schufa's credit scoring must be regarded as an "automated individual decision," potentially requiring explicit consent from individuals.

The CJEU also clarified the role of national courts in overseeing decisions of data protection authorities (DPAs). It emphasized the need for "full review" by national courts over any legally binding decision of a DPA. This development is seen as increasing pressure on DPAs and ensuring effective safeguarding of the rights and interests of data subjects.

In addition to these rulings, the CJEU, in a separate case, indicated that higher fines for breaches of the GDPR could be on the horizon. The court suggested that the calculation of fines should be based on the concept of an "undertaking" under competition law, potentially allowing for significantly higher penalties for GDPR violations.

These legal developments underscore the evolving landscape of data protection laws in the EU, emphasizing the need for businesses to stay informed and compliant with the regulations to avoid legal consequences and protect individuals' privacy rights.

Credit scoring firms face curbs after landmark EU data protection ruling | TechCrunch (2024)
Top Articles
Latest Posts
Article information

Author: Catherine Tremblay

Last Updated:

Views: 6158

Rating: 4.7 / 5 (67 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Catherine Tremblay

Birthday: 1999-09-23

Address: Suite 461 73643 Sherril Loaf, Dickinsonland, AZ 47941-2379

Phone: +2678139151039

Job: International Administration Supervisor

Hobby: Dowsing, Snowboarding, Rowing, Beekeeping, Calligraphy, Shooting, Air sports

Introduction: My name is Catherine Tremblay, I am a precious, perfect, tasty, enthusiastic, inexpensive, vast, kind person who loves writing and wants to share my knowledge and understanding with you.