Article content
In briefShow moreShow lessOn 7 December 2023, the Court of Justice of the European Union clarified that an automatically calculated credit score can fall within the GDPR rules on automated individual decision-making.
- On 7 December 2023, the Court of Justice of the European Union clarified that an automatically calculated credit score can fall within the GDPR rules on automated individual decision-making.
- SCHUFA, a German credit information agency, calculated probability values about individuals' ability to meet future payment commitments.
- CJEU interpretation is highly relevant to Norway's EEA-applied GDPR, while application to a Norwegian case remains for Norwegian authorities and courts.
What happened
On 7 December 2023, the Court of Justice of the European Union clarified that an automatically calculated credit score can fall within the GDPR rules on automated individual decision-making. This is the case where a bank or another customer relies strongly on the score when establishing, carrying out or terminating a contract with an individual.
SCHUFA, a German credit information agency, calculated probability values about individuals' ability to meet future payment commitments. Its customers formally made the final decision. The Court focused on the practical effect: where the third party draws strongly on the automated score, the scoring itself may constitute automated decision-making under Article 22. Such processing is permitted only in specified circumstances and must include suitable measures protecting the individual's rights.
What this means for organisations
In related cases, the Court also considered the retention of information about discharge from remaining debts obtained from a public register. A private credit information agency could not automatically retain the information for longer than the public register. Prolonged retention could breach the GDPR, and individuals must be able to obtain full judicial review where a supervisory authority rejects their complaint.
Businesses buying scores, rankings or recommendations from external suppliers should therefore map how much the automated value determines the final outcome. A manual approval step is not necessarily meaningful human involvement if staff routinely follow the model. Controls should cover explainability, the ability to challenge an outcome, data quality, retention periods, and a route through which the individual can seek review.
The Court did not amend the GDPR; it interpreted existing provisions. The interpretation is relevant in Norway because the GDPR applies through the EEA. Its application to Norwegian credit and decision systems depends on how scores are actually used in each process.
Sources
Court of Justice of the European Union: “Press Release 186/23: SCHUFA credit scoring,” 7 December 2023.
Court of Justice of the European Union: “Judgment in Case C-634/21, SCHUFA Holding (Scoring),” 7 December 2023.
For discussion
Which decisions, defaults or supplier dependencies in our organisation should we examine first in light of this development?








