Privacy

Credit scoring firms face curbs after landmark EU data protection ruling

Comment

An image of a close up gavel in front of code, concept of justice and lawsuit
Image Credits: Aitor Diago (opens in a new window) / Getty Images

Credit scoring companies operating in the European Union could be facing tighter curbs under the bloc’s privacy laws following a ruling issued by the Court of Justice (CJEU) today. The referral relates to complaints brought against the practices of a German credit scoring company, called Schufa, but could have wider significance for credit information agencies operating in the region where the General Data Protection Regulation (GDPR) applies.

One complaint the CJEU considered centered on a case of “prolonged” data retention by the credit referencing firm of information relating to the granting of a discharge from remaining debts which is only kept in the German public insolvency register for six months. However, a code of conduct for German credit information agencies allows a retention period of three years for their own databases. And the Hessian Data Protection Authority had dismissed the complaint about the data retention; also seeking to argue the local court could not review its decision. The CJEU disagreed.

“The Court considers that it is contrary to the GDPR for private agencies to keep such data for longer than the public insolvency register,” it wrote in a press release on case C-634/21 (plus joined cases C-26/22 and C-64/22). “The discharge from remaining debts is intended to allow the data subject to re-enter economic life and is therefore of existential importance to that person. That information is still used as a negative factor when assessing the solvency of the data subject. In this case, the German legislature has provided for data to be stored for six months. It therefore considers that, at the end of the six months, the rights and interests of the data subject take precedence over those of the public to have access to that information.”

“In so far as the retention of data is unlawful, as is the case beyond six months, the data subject has the right to have the data deleted and the agency is obliged to delete the data as soon as possible,” the court added.

The CJEU also ruled on a second complaint that looks rather existential for credit scoring companies — being as it questions whether Schufa can automatically issue credit scores, given the GDPR provides protections for individuals subject to solely automated decisions with legal or significant impacts on them. So, essentially, they may need to obtain people’s explicit consent to being credit scored.

The Court held that Schufa’s credit scoring must be regarded as an “automated individual decision,” which its press release notes is “prohibited in principle by the GDPR, in so far as Schufa’s clients, such as banks, attribute to it a determining role in the granting of credit.”

If this kind of credit scoring is the basis for a decision by a bank, for instance, to deny an individual credit the practice risks ruling foul of EU data protection rules.

Though in the specific case it will be up to the Administrative Court of Wiesbaden to assess whether the German Federal Law on data protection contains a valid exception to the prohibition in accordance with the GDPR. And, if that’s so, to check whether the general conditions laid down by the GDPR for data processing have been met — such as ensuring individuals are aware of their right to object and to ask for (and get) human intervention, as well as being able to provide meaningful information about the logic of the credit scoring on request.

“Judicial review” of DPA decisions

In another significant ruling, the CJEU also made it clear national courts must be able to exercise what its PR calls “full review” over any legally binding decision of a data protection authority.

Privacy rights group noyb, which has had multiple run-ins with DPAs over their failure to act on (let alone enforce) complaints, seized on this as especially significant — dubbing it “full judicial review” of DPAs.

“The CJEU ruling massively increased the pressure on DPAs. In some EU member states, including Germany, they have so far assumed that a GDPR complaint from data subjects is merely a kind of ‘petition.’ In practice, this has meant that despite an annual budget of €100M the German DPAs have rejected many complaints with bizarre justifications and GDPR violations have not been pursued. In countries such as Ireland, more than 99% of complaints were not processed and in France any right of those affected to participate in the procedure concerning their own rights was denied. Some DPAs, such as the Hessian authority in the present case, have also argued that the courts are prohibited from reviewing their decisions in detail,” it wrote in a press release responding to the ruling.

“The CJEU has now put an end to this approach. It has ruled that Article 77 of the GDPR is designed as a mechanism to effectively safeguard the rights and interests of data subjects. In addition, the court has ruled that the Article 78 of the GDPR allows national courts to carry out a full review of DPA decisions. This includes the assessment whether the authorities have acted within the limits of their discretion.”

Higher GDPR fines on the way too?

The pair of significant rulings follow another handed down by the CJEU yesterday (also via, in part, another Germany case referral), which legal experts suggest could result in significantly higher penalties for breaches of the GDPR as it lowers the requirements for imposing fines on legal entities.

So while, in this case (C-807/21), the Court held that wrongful conduct is necessary for a fine to be imposed — that is, that a breach of the GDPR must have been committed “intentionally or negligently” — judges also said that, where a controller is a legal person, it is not necessary for the infringement to have been committed by its management body, nor is it necessary for that body to have had knowledge of that infringement.

They further stipulated that the calculation of any fine requires the supervisory authority to take as its basis the concept of “an ‘undertaking’ under competition law” (aka, per the Court PR, that “the maximum amount of the fine must be calculated on the basis of a percentage of the total worldwide annual turnover of the undertaking concerned, taken as a whole, in the preceding business year” — or, basically, that the revenue of an entire group of companies may be used to calculate a GDPR penalty for an infringement committed by a single unit of that group).

Jan Spittka, partner at law firm Clyde & Co., predicted beefier GDPR fines could result. “The overall context of the decision will make it way easier for the data protection supervisory authorities of the EU member states to sanction legal entities and is also likely to result in significantly higher fines on average,” he suggested in a statement.

“Against the background of this standard only a detailed and strictly monitored data protection compliance system may put a legal entity in a position to argue that it was unaware of the unlawfulness of its conduct with regard to GDPR infringements committed by an employee,” he also said. “Furthermore, a legal entity may exculpate itself if representatives or employees act totally out of the scope of their job description, e.g. when misusing personal data for private purposes.”

Europe’s top court clarifies GDPR compensation and data access rights

More TechCrunch

For years, Sammy Faycurry has been hearing from his dietician mom and sister about how poorly many Americans eat and their struggles with delivering nutritional counseling. Although nearly half of…

Dietitian startup Fay has been booming from Ozempic patients and emerges from stealth with $25M from General Catalyst, Forerunner

Apple is bringing new accessibility features to iPads and iPhones, designed to cater to a diverse range of user needs.

Apple announces new accessibility features for iPhone and iPad users

TechCrunch Disrupt, our flagship startup event held annually in San Francisco, is back on October 28-30 — and you can expect a bustling crowd of thousands of startup enthusiasts. Exciting…

Startup Blueprint: TC Disrupt 2024 Builders Stage agenda sneak peek!

Mike Krieger, one of the co-founders of Instagram and, more recently, the co-founder of personalized news app Artifact (which TechCrunch corporate parent Yahoo recently acquired), is joining Anthropic as the…

Anthropic hires Instagram co-founder as head of product

Seven orgs so far have signed on to standardize the way data is collected and shared.

Venture orgs form alliance to standardize data collection

As cloud adoption continues to surge toward the $1 trillion mark in annual spend, we’re seeing a wave of enterprise startups gaining traction with customers and investors for tools to…

Alkira connects with $100M for a solution that connects your clouds

Charging has long been the Achilles’ heel of electric vehicles. One startup thinks it has a better way for apartment dwelling EV drivers to charge overnight.

Orange Charger thinks a $750 outlet will solve EV charging for apartment dwellers

So did investors laugh them out of the room when they explained how they wanted to replace Quickbooks? Kind of.

Embedded accounting startup Layer secures $2.3M toward goal of replacing Quickbooks

While an increasing number of companies are investing in AI, many are struggling to get AI-powered projects into production — much less delivering meaningful ROI. The challenges are many. But…

Weka raises $140M as the AI boom bolsters data platforms

PayHOA, a previously bootstrapped Kentucky-based startup that offers software for self-managed homeowner associations (HOAs), is an example of how real-world problems can translate into opportunity. It just raised a $27.5…

Meet PayHOA, a profitable and once-bootstrapped SaaS startup that just landed a $27.5M Series A

Restaurant365, which offers a restaurant management suite, has raised a hot $175M from ICONIQ Growth, KKR and L Catterton.

Restaurant365 orders in $175M at $1B+ valuation to supersize its food service software stack 

Venture firm Shilling has launched a €50M fund to support growth-stage startups in its own portfolio and to invest in startups everywhere else. 

Portuguese VC firm Shilling launches €50M opportunity fund to back growth-stage startups

Chang She, previously the VP of engineering at Tubi and a Cloudera veteran, has years of experience building data tooling and infrastructure. But when She began working in the AI…

LanceDB, which counts Midjourney as a customer, is building databases for multimodal AI

Trawa simplifies energy purchasing and management for SMEs by leveraging an AI-powered platform and downstream data from customers. 

Berlin-based trawa raises €10M to use AI to make buying renewable energy easier for SMEs

Lydia is splitting itself into two apps — Lydia for P2P payments and Sumeria for those looking for a mobile-first bank account.

Lydia, the French payments app with 8 million users, launches mobile banking app Sumeria

Cargo ships docking at a commercial port incur costs called “disbursements” and “port call expenses.” This might be port dues, towage, and pilotage fees. It’s a complex patchwork and all…

Shipping logistics startup Harbor Lab raises $16M Series A led by Atomico

AWS has confirmed its European “sovereign cloud” will go live by the end of 2025, enabling greater data residency for the region.

AWS confirms will launch European ‘sovereign cloud’ in Germany by 2025, plans €7.8B investment over 15 years

Go Digit, an Indian insurance startup, has raised $141 million from investors including Goldman Sachs, ADIA, and Morgan Stanley as part of its IPO.

Indian insurance startup Go Digit raises $141M from anchor investors ahead of IPO

Peakbridge intends to invest in between 16 and 20 companies, investing around $10 million in each company. It has made eight investments so far.

Food VC Peakbridge has new $187M fund to transform future of food, like lab-made cocoa

For over six decades, the nonprofit has been active in the financial services sector.

Accion’s new $152.5M fund will back financial institutions serving small businesses globally

Meta’s newest social network, Threads, is starting its own fact-checking program after piggybacking on Instagram and Facebook’s network for a few months.

Threads finally starts its own fact-checking program

Looking Glass makes trippy-looking mixed-reality screens where things look 3D without the need of special glasses. Today it launches a pair of new displays, including a 16-inch mode that runs…

Looking Glass launches new 3D displays

OpenAI co-founder and chief scientist Ilya Sutskever has left the company. Replacing Sutskever is Jakub Pachocki, OpenAI’s director of research.

Ilya Sutskever, OpenAI co-founder and longtime chief scientist, departs

Intuitive Machines made history when it became the first private company to land a spacecraft on the moon, so it makes sense to adapt that tech for Mars.

Intuitive Machines wants to help NASA return samples from Mars

As Google revamps itself for the AI era, offering AI overviews within its search results, the company is introducing a new way to filter for just text-based links. With the…

Google adds ‘Web’ search filter for showing old-school text links as AI rolls out

Blue Origin’s New Shepard rocket will take a crew to suborbital space for the first time in nearly two years later this month, the company announced on Tuesday.  The NS-25…

Blue Origin to resume crewed New Shepard launches on May 19

This will enable developers to use the on-device model to power their own AI features.

Google is building its Gemini Nano AI model into Chrome on the desktop

It ran 110 minutes, but Google managed to reference AI a whopping 121 times during Google I/O 2024 (by its own count). CEO Sundar Pichai referenced the figure to wrap…

Google mentioned ‘AI’ 120+ times during its I/O keynote

Firebase Genkit is an open source framework that enables developers to quickly build AI into new and existing applications.

Google launches Firebase Genkit, a new open source framework for building AI-powered apps

In the coming months, Google says it will open up the Gemini Nano model to more developers.

Patreon and Grammarly are already experimenting with Gemini Nano, says Google