Civil Law And Algorithmic Credit Scoring Discrimination Litigation In Europe

Civil Law and Algorithmic Credit Scoring Discrimination Litigation in Europe

1. Introduction

Algorithmic credit scoring is the use of mathematical, statistical or machine-learning systems to estimate a person's creditworthiness or likelihood of repaying a financial obligation.

A typical system may analyse:

repayment history;

outstanding debts;

income;

employment information;

previous defaults;

financial transactions;

address or geographical information;

age;

existing credit relationships;

public records;

information obtained from credit-reference agencies;

other behavioural or inferred characteristics.

The system then produces a score or probability, for example:

"Probability of repayment: 87%."

Banks, insurers, lenders, fintech companies and other businesses may use that score when deciding whether to:

grant credit;

refuse credit;

determine interest rates;

determine credit limits;

require additional security;

terminate or modify a contractual relationship.

The European legal problem arises when the algorithm is inaccurate, opaque, discriminatory, unlawful or effectively determines the person's access to credit.

The most important modern European authority is SCHUFA, C-634/21, where the CJEU held that an automated credit score can itself fall within GDPR Article 22 where a third party relies strongly on it in deciding whether to establish, implement or terminate a contractual relationship. (EUR-Lex)

A second major authority is Dun & Bradstreet Austria, C-203/22, decided in 2025, which substantially develops the right to meaningful information about the logic involved in automated credit scoring. (EUR-Lex)

2. Important Legal Qualification

There are still relatively few European appellate judgments involving the precise factual combination of:

AI/algorithmic credit score + discriminatory outcome + civil damages claim.

Consequently, European legal analysis must combine:

direct credit-scoring cases;

GDPR automated-decision cases;

discrimination jurisprudence;

data-access cases;

fundamental-rights jurisprudence;

national civil and banking law.

Therefore, some of the cases below are direct authorities, while others are closely related authorities that establish principles applicable to algorithmic credit discrimination.

3. Meaning of Algorithmic Credit Scoring

A simplified model is:

Personal data

↓

Credit-reference database

↓

Statistical/AI model

↓

Probability calculation

↓

Credit score

↓

Bank/financial institution

↓

Loan decision

The legal difficulty is that discrimination can enter at almost every stage.

4. Where Algorithmic Bias Can Enter

A. Training-data bias

If historical lending decisions were discriminatory, the algorithm may learn those patterns.

For example:

Historically, people from a particular neighbourhood received fewer loans.

An algorithm trained on that history might learn:

"Applicants from that area = higher risk."

That can reproduce historical discrimination without explicitly using race or another protected characteristic.

B. Proxy discrimination

An algorithm may not directly use:

race, ethnic origin, religion or nationality.

But it may use:

postcode;

language;

occupation;

education;

purchasing patterns;

geographical location.

These may operate as proxies for protected characteristics.

C. Gender discrimination

An algorithm may discover statistical differences between men and women and incorporate them into risk assessment.

The fact that a variable has statistical predictive value does not automatically make its use legally permissible.

The CJEU's insurance discrimination jurisprudence demonstrates this principle.

D. Socioeconomic discrimination

Variables such as:

income;

employment status;

housing status;

geographical location;

can produce socioeconomic disparities.

Whether such disparities amount to unlawful discrimination depends upon the applicable legal framework.

E. Data-quality discrimination

An applicant may have:

an incorrectly recorded debt;

a debt belonging to another person;

an outdated default;

an incorrectly linked identity;

duplicate records.

A mathematically sophisticated algorithm can still produce an unlawful result if its underlying data are wrong.

5. Case 1 — SCHUFA Holding (Scoring), C-634/21

Court: CJEU, First Chamber
Date: 7 December 2023

This is the leading European case on algorithmic credit scoring.

SCHUFA calculated creditworthiness scores using mathematical and statistical procedures. The score attempted to predict whether a person would meet future payment obligations.

The score was provided to third parties such as banks.

The CJEU examined whether the automated generation of such a score could itself constitute automated individual decision-making under Article 22 GDPR. (EUR-Lex)

Decision

The CJEU held that where:

a credit information agency automatically establishes a probability value;

the value concerns a person's ability to meet future payment obligations; and

a third party draws strongly on that value when deciding whether to establish, implement or terminate a contractual relationship,

the establishment of the score constitutes automated individual decision-making for Article 22 purposes. (EUR-Lex)

The Court noted that an insufficient score led, in the circumstances referred to it, to loan refusal in almost all cases. (EUR-Lex)

Importance

This is crucial because a company cannot necessarily avoid Article 22 simply by saying:

"We only calculate the score; the bank makes the final decision."

If the bank strongly relies on the score, the scoring process itself can become legally significant.

Relevance to discrimination

It creates a powerful starting point for litigation where a discriminatory score materially determines access to credit.

6. Article 22 GDPR

SCHUFA makes Article 22 particularly important.

The provision establishes a general right not to be subject to a decision based solely on automated processing, including profiling, where that decision produces legal effects or similarly significant effects, subject to the Regulation's exceptions.

The CJEU described Article 22(1) as establishing a prohibition in principle, with exceptions governed by Article 22(2). (EUR-Lex)

Relevant exceptions include circumstances involving:

contractual necessity;

EU or Member State law with suitable safeguards;

explicit consent.

Where the relevant exception applies, additional safeguards may be required.

7. Why SCHUFA Is Important for Civil Litigation

Consider:

Applicant → credit score 42 → bank refuses mortgage → applicant alleges discriminatory postcode variable.

The applicant could potentially investigate:

What data produced the score?

Was the data accurate?

Which variables were used?

Did the bank rely strongly on the score?

Was automated decision-making involved?

Was a lawful Article 22 exception applicable?

Was there meaningful human intervention?

Was the result discriminatory?

Was damage caused?

Thus, SCHUFA transforms the credit score from a supposedly internal statistical calculation into an object of legal scrutiny.

8. Case 2 — Dun & Bradstreet Austria, C-203/22

Court: CJEU, First Chamber
Date: 27 February 2025

This is the most important follow-up authority.

The case concerned:

automated creditworthiness assessment;

scoring;

profiling;

Article 15(1)(h) GDPR;

meaningful information about the logic involved;

verification of accuracy;

trade secrets;

personal data concerning third parties.

(EUR-Lex)

Central issue

The applicant wanted meaningful information about how the scoring system generated the result.

The question was essentially:

How much information must a data controller provide to enable an individual to understand an automated credit decision?

Importance

The CJEU examined the requirement to provide meaningful information about the logic involved in automated decision-making. (EUR-Lex)

This is highly relevant to discrimination claims.

A claimant cannot effectively challenge algorithmic discrimination if the only information supplied is:

"Your score is 421."

The claimant may need enough information to understand the relevant factors and methodology so that the result can be meaningfully contested.

9. Trade Secrets Are Not a Complete Answer

Credit-scoring companies may argue:

"Our algorithm is commercially confidential."

Dun & Bradstreet demonstrates the importance of balancing trade-secret interests against the individual's GDPR rights.

This does not mean that every line of source code must automatically be disclosed.

Rather, the legal system must ensure that confidentiality does not make the individual's rights practically meaningless.

This is especially important where the claimant alleges:

"The algorithm discriminated against me."

Without meaningful information, proving that claim can be extremely difficult.

10. Case 3 — SCHUFA, C-26/22 and C-64/22

Court: CJEU
Date: 7 December 2023

These joined cases concerned SCHUFA and the storage of information concerning the discharge of remaining debts.

The cases are different from SCHUFA Scoring, C-634/21, but they are highly relevant to credit information.

The CJEU considered the interaction between:

storage of personal data;

creditworthiness information;

data protection;

retention periods;

legitimate interests.

The Court's subsequent jurisprudence has referred to this case when discussing requirements applicable to national legal bases under GDPR Article 22. (EUR-Lex)

Relevance

Credit scoring is only as reliable as the information retained in the credit database.

If an old insolvency or debt record remains available after it should no longer be retained, the resulting score may be distorted.

That can produce:

outdated data → lower score → loan refusal → economic harm.

11. Case 4 — Association belge des consommateurs Test-Achats, C-236/09

Court: CJEU Grand Chamber
Date: 1 March 2011

This case did not concern AI credit scoring. It concerned gender discrimination in insurance.

However, it is a highly relevant European authority for algorithmic financial discrimination.

The issue was whether sex could be used as an actuarial risk factor in insurance premiums and benefits.

The CJEU held that the use of sex as a risk factor in insurance contracts could not continue under the challenged derogation indefinitely and declared the relevant provision invalid with effect from 21 December 2012. (Infocuria)

Importance for algorithms

Suppose an AI system determines:

"Women historically have a different statistical risk."

The fact that a characteristic has statistical predictive value does not automatically settle the legal question.

Principle

Statistical accuracy and legal equality are separate questions.

An algorithm can be statistically predictive and nevertheless use a legally impermissible discriminatory factor.

12. Case 5 — Nowak v Data Protection Commissioner, C-434/16

Court: CJEU
Date: 20 December 2017

This case concerned examination answers and examiner comments under EU data-protection law.

The CJEU adopted a broad understanding of personal data and recognised that information can be personal data where it relates to an identifiable individual. (Infocuria)

Relevance to credit scoring

A person's:

credit score;

risk classification;

probability value;

profile;

algorithmic assessment;

can raise important personal-data questions.

If an algorithm generates a profile concerning an identifiable person, the fact that the profile is machine-generated does not make it legally irrelevant.

Practical importance

A claimant may therefore ask:

"What personal data concerning me were used to generate this credit profile?"

This is an important foundation for subsequent discrimination or accuracy claims.

13. Case 6 — Breyer v Bundesrepublik Deutschland, C-582/14

Court: CJEU
Date: 19 October 2016

The CJEU considered whether dynamic IP addresses could constitute personal data where the website operator had legal means that could potentially enable identification.

The judgment is important for the broader principle that personal data analysis must be considered in its actual legal and technological context.

Relevance to credit algorithms

Credit-scoring systems frequently combine information from multiple sources.

A data item may appear harmless in isolation but become highly revealing when combined with other information.

For example:

postcode + employment + transaction data + debt history

can create a highly specific profile.

Therefore, algorithmic credit assessment cannot be assessed simply by looking at each data field separately.

14. Case 7 — Wirtschaftsakademie Schleswig-Holstein, C-210/16

Court: CJEU
Date: 5 June 2018

The case concerned Facebook fan pages and responsibility for processing personal data.

The CJEU examined joint responsibility in circumstances where an organisation participated in determining purposes and means of processing through the operation of a fan page.

Relevance to credit scoring

Credit scoring may involve several actors:

Applicant

↓

Credit-reference agency

↓

Data broker

↓

Fintech

↓

Bank

↓

AI provider

The question can become:

Who is responsible for the relevant processing?

The answer matters for:

access rights;

correction;

objections;

accountability;

remedies.

15. Case 8 — Österreichische Post, C-300/21

Court: CJEU
Date: 4 May 2023

Österreichische Post used an algorithm to analyse demographic information and predict political affinities.

Although the case was not a credit-scoring case, it is highly relevant to algorithmic profiling and damages.

The CJEU addressed compensation under Article 82 GDPR.

It established that a GDPR infringement alone does not automatically establish entitlement to compensation; the claimant must establish:

an infringement;

damage; and

a causal relationship between the infringement and the damage.

The Court also rejected a requirement that non-material damage must exceed some additional seriousness threshold merely to qualify for compensation.

Relevance to credit scoring

Suppose:

unlawful profiling → discriminatory score → loan refusal.

The claimant would still need to establish the relevant elements of a compensation claim under the applicable legal basis.

This makes evidence and causation extremely important.

16. Consolidated Case-Law Table

CaseMain legal principleCredit-scoring relevance
SCHUFA, C-634/21Automated scoring can itself constitute Article 22 automated decision-makingCore authority
Dun & Bradstreet, C-203/22Meaningful information about automated scoring logicTransparency and challenge
SCHUFA, C-26/22 & C-64/22Retention of credit-related personal dataAccuracy and historical data
Test-Achats, C-236/09Statistical risk factors can raise equality issuesAlgorithmic discrimination
Nowak, C-434/16Broad concept of personal dataCredit profiles and scores
Breyer, C-582/14Contextual approach to personal dataData aggregation
Wirtschaftsakademie, C-210/16Responsibility for personal-data processingMultiple actors in scoring
Österreichische Post, C-300/21GDPR compensation requires infringement, damage and causationDamages claims

17. What Constitutes Algorithmic Credit Discrimination?

A useful distinction is:

Direct discrimination

The algorithm explicitly uses a protected characteristic.

Example:

"Reduce credit limit because applicant is female."

Indirect discrimination

The algorithm uses apparently neutral criteria that disproportionately disadvantage a protected group.

Example:

postcode → disadvantage to a particular ethnic community.

The legality of such a result depends upon the applicable equality legislation and whether the differential treatment is legally justified.

Proxy discrimination

The algorithm does not directly use:

ethnicity.

Instead it uses:

postcode + language + purchasing behaviour.

Those variables may nevertheless correlate strongly with ethnicity.

Intersectional discrimination

The model may produce different effects based on combinations of characteristics.

Example:

age + gender + employment status.

This is particularly difficult to identify using conventional statistical testing.

18. Credit Score and Protected Characteristics

Potentially sensitive characteristics can include:

sex;

racial or ethnic origin;

religion;

disability;

age;

nationality;

other characteristics protected under applicable European or national law.

The fact that an algorithm discovers a correlation does not automatically make use of that correlation lawful.

19. The Proxy Problem

Consider:

A = postcode.

The algorithm does not use:

B = ethnicity.

But suppose postcode A strongly correlates with ethnicity B.

The model may therefore reproduce a discriminatory effect without ever being explicitly programmed to discriminate.

This creates a fundamental problem:

"We did not use race" is not necessarily sufficient to demonstrate that the system is non-discriminatory.

A proper assessment may need to consider outcomes and proxy variables.

20. Accuracy and Discrimination Are Different

This distinction is extremely important.

Accuracy question

Does the algorithm predict default correctly?

Equality question

Does the algorithm treat legally protected groups lawfully?

An algorithm could be:

highly accurate but discriminatory;

less accurate but not discriminatory;

both inaccurate and discriminatory;

accurate and compliant.

Therefore:

High predictive performance does not automatically establish legal compliance.

21. Data Accuracy

Suppose a person's credit file incorrectly states:

"Unpaid €20,000 debt."

The algorithm correctly processes the data.

It produces:

Score = 220.

The algorithm itself may be technically accurate.

But the underlying information is wrong.

Therefore:

Correct calculation + incorrect data = potentially incorrect legal outcome.

This is why data accuracy is a fundamental issue in algorithmic credit litigation.

22. Historical Data

Old information can distort present credit decisions.

Example:

Default from 15 years ago → algorithm continues treating person as high risk.

Questions include:

Was retention lawful?

Is the information still relevant?

Has the debt been discharged?

Has the information been corrected?

Should it still influence the score?

The SCHUFA data-retention cases are therefore particularly relevant to credit information systems.

23. Right of Access

A person may need access to relevant information in order to challenge:

inaccurate data;

discriminatory variables;

unlawful profiling;

automated decision-making.

But access rights do not necessarily mean unrestricted access to:

source code;

proprietary software;

every piece of third-party personal data.

The legal issue is how to provide meaningful information while respecting legitimate confidentiality interests.

24. Explanation of the Score

An inadequate explanation:

"Your score is low."

A more useful explanation might identify:

the principal categories of data;

significant factors;

relevant adverse information;

the role of automated processing;

how the score affected the decision;

available correction or appeal mechanisms.

Dun & Bradstreet is especially important because it addresses the requirement for meaningful information about the logic involved in automated profiling. (EUR-Lex)

25. Human Intervention

A bank may argue:

"A human employee reviewed the application."

That fact alone does not necessarily settle the issue.

The real questions include:

Did the employee have genuine authority?

Could the employee depart from the score?

Did the employee examine the underlying evidence?

Was the review merely formal?

Did the employee have sufficient information to identify algorithmic errors?

This is particularly important following SCHUFA.

26. Human Rubber-Stamping

Consider:

Algorithm: Reject.

Employee: "Approved by system."

If the human reviewer has no practical ability to reconsider the recommendation, the supposed human decision may provide limited protection.

A meaningful review should involve genuine evaluation.

27. Trade Secrets

Credit-scoring companies often argue that their scoring models are proprietary.

This creates a legal conflict:

Business confidentiality

versus

individual's ability to challenge automated processing.

Dun & Bradstreet is particularly significant because the CJEU examined this interaction between meaningful information and trade-secret protection. (EUR-Lex)

28. Civil Liability

An algorithmic credit-scoring dispute may potentially generate several different forms of civil claim.

A. Contractual claim

Example:

Bank wrongly applies contractual credit criteria.

B. Tort/delict claim

Example:

Negligent processing causes financial damage.

C. GDPR claim

Example:

Unlawful profiling or inaccurate personal-data processing.

D. Discrimination claim

Example:

Applicant was treated less favourably on a protected ground.

E. Consumer claim

Example:

Unfair contractual term or inadequate information.

The applicable cause of action depends upon the country and factual circumstances.

29. Damages

Potential losses include:

Direct economic loss

additional borrowing costs;

loan refusal;

lost financing opportunity.

Consequential economic loss

lost business investment;

inability to purchase property;

lost commercial opportunity.

Non-material harm

distress;

reputational consequences;

loss of control over personal data.

The claimant must satisfy the applicable legal requirements for the relevant remedy.

Österreichische Post is important concerning GDPR compensation and the need to establish damage and causation.

30. Causation

Causation may be complicated.

Suppose:

Algorithmic score = low → bank rejects loan.

But the bank also considered:

income;

existing debt;

collateral;

employment.

The claimant must determine:

Did the algorithm actually cause the rejection?

This is exactly why SCHUFA focuses on whether the recipient draws strongly on the score.

(EUR-Lex)

31. Evidence in Algorithmic Credit Litigation

Important evidence may include:

credit report;

score;

adverse entries;

algorithmic explanation;

internal bank records;

loan-decision records;

model documentation;

validation reports;

audit reports;

statistical testing;

comparable applicant outcomes;

correspondence with the lender;

expert evidence.

32. Statistical Evidence of Discrimination

A claimant may compare:

Group A approval rate = 70%

Group B approval rate = 45%

But a disparity alone does not automatically establish unlawful discrimination.

The court may examine:

whether the groups are similarly situated;

the variables involved;

legitimate risk factors;

statistical significance;

alternative explanations;

whether the criterion is justified;

whether a less discriminatory method exists.

33. The Problem of Correlation

AI systems identify correlations.

For example:

Variable X correlates with default.

But:

correlation ≠ causation.

And:

statistical correlation ≠ legal justification.

A variable may improve predictive accuracy while creating legally unacceptable discrimination.

34. Fairness Metrics

Technical audits may examine:

Demographic parity

Are approval rates similar?

Equal opportunity

Are qualified applicants treated similarly?

Equalised odds

Are error rates comparable?

False-positive rates

Are certain groups wrongly classified as high risk more frequently?

False-negative rates

Are certain groups wrongly classified as low risk?

However, technical fairness metrics do not themselves determine the legal outcome.

They are evidence for legal analysis, not substitutes for it.

35. GDPR Data Minimisation

A lender should not assume:

"If data improves prediction, we may automatically collect it."

GDPR principles concerning:

purpose limitation;

data minimisation;

accuracy;

lawfulness;

transparency;

remain relevant.

A sophisticated model does not eliminate these requirements.

36. Sensitive Personal Data

Algorithmic credit systems may encounter sensitive information.

For example:

health;

disability;

religion;

ethnicity.

If such information is processed, stricter GDPR requirements may arise.

The legal issue is particularly serious where sensitive characteristics are not directly collected but are inferred from other data.

37. Inferred Characteristics

Suppose an algorithm predicts:

"Applicant probably belongs to Group X."

Even if the person never disclosed that characteristic, the algorithm may have created an inference about them.

That can raise:

data-protection;

discrimination;

transparency;

fairness concerns.

38. Automated Decision vs Human Decision

The key distinction is:

Model A

Algorithm produces score → bank automatically refuses.

This is the clearest automated-decision scenario.

Model B

Algorithm produces score → bank employee independently investigates → employee decides.

This raises different Article 22 questions, particularly concerning whether the final decision was genuinely automated.

Model C

Algorithm produces score → employee formally approves automatically.

This may raise difficult questions about whether human intervention was genuinely meaningful.

SCHUFA makes this distinction particularly important. (EUR-Lex)

39. Role of Credit-Reference Agencies

There may be two separate decision-makers:

Credit-reference agency

Creates the score.

Bank

Uses the score.

The claimant therefore needs to determine:

Which entity is responsible for which processing operation?

The Wirtschaftsakademie jurisprudence is relevant to questions of responsibility where multiple entities participate in determining purposes and means of processing.

40. Platform/Firm as Data Controller

A bank or fintech company may be a controller for processing undertaken for credit decisions.

A credit-reference agency may have separate controller responsibilities.

A technology provider may have a different role depending on the contractual and factual arrangement.

The classification matters because it determines:

legal obligations;

transparency;

access rights;

security;

accountability;

potential liability.

41. Algorithmic Credit Discrimination and Consumer Law

Credit applicants may also benefit from consumer-protection rules concerning:

transparency;

unfair terms;

information duties;

responsible lending;

contractual fairness.

However, consumer law does not replace GDPR or equality law.

Several legal regimes can operate simultaneously.

42. Fundamental Rights

Algorithmic credit scoring can engage:

EU Charter Article 7

Respect for private and family life.

Article 8

Protection of personal data.

Article 21

Non-discrimination.

Article 47

Effective judicial remedy and fair trial.

These rights become particularly important where algorithmic decisions significantly affect economic participation.

43. European Civil-Law Approach

The European approach can therefore be understood as five connected layers:

Layer 1 — Data

Was the information lawful and accurate?

Layer 2 — Algorithm

Was the scoring system lawful and appropriately designed?

Layer 3 — Equality

Did the system produce prohibited discrimination?

Layer 4 — Decision

How strongly did the lender rely on the score?

Layer 5 — Remedy

Can the individual challenge the result and recover legally recognised damage?

44. Hypothetical Example

Suppose a European bank uses an AI model called CreditAI.

It considers:

income;

employment;

debt;

postcode;

spending patterns;

previous repayment history.

Applicant A:

Score = 780 → loan approved.

Applicant B:

Score = 510 → loan refused.

Applicant B discovers that postcode has a significant effect on the score.

The postcode corresponds strongly with a particular ethnic community.

Possible legal questions

Is postcode a legitimate credit-risk variable?

Does it operate as a proxy for ethnic origin?

Is the resulting disparity discriminatory?

Was the score generated solely through automated processing?

Did the bank strongly rely on it?

What data generated the score?

Were those data accurate?

Can the applicant obtain meaningful information about the logic?

Did the bank conduct a genuine human review?

What financial loss resulted from the refusal?

This is the type of dispute in which SCHUFA + Dun & Bradstreet + equality law + GDPR can intersect.

45. Burden of Proof

Algorithmic discrimination is often difficult to prove because the relevant information is controlled by:

banks;

credit-reference agencies;

technology vendors.

A claimant may therefore require:

disclosure;

data-access rights;

expert analysis;

statistical evidence;

judicial orders;

regulatory investigation.

The practical importance of meaningful information about the algorithm is therefore substantial.

46. Algorithmic Audit

A proper credit-scoring audit should examine:

Data

source;

accuracy;

age;

relevance.

Model

variables;

weights;

methodology;

training data.

Performance

overall accuracy;

error rates.

Equality

group outcomes;

proxy variables;

disparate effects.

Governance

human review;

documentation;

audit trails;

model changes.

47. Model Drift

A model can become less reliable over time.

Economic circumstances change.

For example:

Model trained using 2018–2022 data → deployed in 2026.

Economic conditions may be different.

A model may therefore produce systematically different results after deployment.

This creates questions about:

continuous monitoring;

validation;

updating;

discrimination testing.

48. Liability for Third-Party AI Vendors

Suppose:

Bank buys credit model from FinTech Company X.

The algorithm discriminates against applicants.

There may be two separate legal relationships:

Applicant → Bank

Challenge to the credit decision.

Bank → Technology company

Contractual claim concerning defective software, warranties, indemnification or other contractual obligations.

The vendor contract should ideally address:

model accuracy;

regulatory compliance;

bias testing;

audit rights;

data protection;

cybersecurity;

update obligations;

liability allocation.

49. Remedies

Possible remedies can include:

1. Correction

Correct inaccurate credit information.

2. Recalculation

Generate a new score using corrected information.

3. Human reassessment

Have the credit application reconsidered.

4. Access

Provide relevant information about processing.

5. Injunction

Prevent unlawful processing where legally available.

6. Compensation

Where the legal requirements are satisfied.

7. Regulatory enforcement

A data-protection or other competent authority may investigate.

8. Judicial remedy

The individual may challenge relevant decisions before the competent court.

50. Key Distinction: Wrong Score vs Discriminatory Score

These should be separately analysed.

Wrong score

The underlying information is inaccurate.

Example:

False default record.

Discriminatory score

The data may be accurate, but the system treats similarly situated persons differently on an unlawful basis.

Example:

Protected characteristic or unjustified proxy materially affects the outcome.

A single case can involve both.

51. Important Legal Questions for Courts

A court hearing an algorithmic credit-discrimination case may need to determine:

Who created the score?

What data were used?

Was the data accurate?

What variables were material?

Was profiling involved?

Was the decision solely automated?

Did the lender strongly rely on the score?

Was human intervention meaningful?

Was a protected characteristic involved?

Did proxy discrimination occur?

Was the processing lawful?

Was sufficient information provided?

Was the claimant harmed?

Did the algorithm cause the harm?

What remedy is appropriate?

52. Most Important Legal Principles from the Cases

Principle 1 — Scoring itself can be legally significant

SCHUFA C-634/21 makes clear that automated credit scoring can constitute automated individual decision-making when a third party strongly relies on the score. (EUR-Lex)

Principle 2 — Explanation matters

Dun & Bradstreet C-203/22 develops the right to meaningful information concerning the logic involved in automated profiling. (EUR-Lex)

Principle 3 — Statistical usefulness does not automatically defeat equality

Test-Achats C-236/09 illustrates that statistical risk differences can still be subject to equality requirements. (Infocuria)

Principle 4 — Algorithmic profiles can involve personal data

Nowak C-434/16 supports a broad understanding of personal data.

Principle 5 — Data accuracy is fundamental

Wrong information can produce a wrong score even if the algorithm itself operates correctly.

Principle 6 — Damage and causation matter

Österreichische Post C-300/21 demonstrates the importance of establishing infringement, damage and causation for GDPR compensation.

53. Consolidated Legal Framework

IssueMain legal concern
Incorrect credit recordGDPR accuracy
Automated scoreGDPR Article 22
ProfilingGDPR
DiscriminationEquality law / EU Charter
Proxy variablesIndirect discrimination
Lack of explanationGDPR transparency/access
Trade secretsConfidentiality vs meaningful access
Loan refusalContract/consumer law
Financial lossCivil/GDPR damages
Human reviewGenuine intervention
Multiple data providersController responsibility
Historical dataRetention and accuracy
Sensitive dataSpecial GDPR safeguards
Algorithmic biasEquality + data governance
Regulatory oversightGDPR and financial regulation

54. Short Exam Answer

Algorithmic credit-scoring discrimination in Europe concerns the use of automated statistical or AI systems to evaluate a person's creditworthiness where the resulting assessment may inaccurately or discriminatorily affect access to financial services.

The leading authority is SCHUFA Holding, C-634/21, where the CJEU held that automated creation of a creditworthiness probability constitutes automated individual decision-making under Article 22 GDPR when a third party strongly relies on the score in establishing, implementing or terminating a contractual relationship. (EUR-Lex)

Dun & Bradstreet Austria, C-203/22 is important for the right to meaningful information about the logic involved in automated scoring and for challenging the accuracy of algorithmic results. (EUR-Lex)

Other relevant authorities include SCHUFA C-26/22 and C-64/22, concerning retention of credit-related personal information; Test-Achats C-236/09, concerning statistical risk factors and equality; Nowak C-434/16, concerning personal data; Breyer C-582/14, concerning identification and personal data; Wirtschaftsakademie C-210/16, concerning responsibility for processing; and Österreichische Post C-300/21, concerning GDPR compensation.

The central European principle is:

A credit algorithm cannot be treated as legally neutral merely because it operates mathematically. Its data, variables, profiling process, discriminatory effects, degree of influence over the credit decision, transparency and consequences must all be capable of legal scrutiny.

55. Ultra-Short Revision

Remember these keywords:

Credit scoring → Profiling → GDPR Article 22 → SCHUFA → Automated decision → Strong reliance → Human intervention → Explainability → Dun & Bradstreet → Personal data → Accuracy → Proxy discrimination → Equal treatment → Test-Achats → Data retention → Controller → Causation → Damages → Effective remedy.

Six essential cases

SCHUFA, C-634/21 — automated credit scoring.

Dun & Bradstreet, C-203/22 — explanation of scoring logic.

SCHUFA, C-26/22 & C-64/22 — credit-data retention.

Test-Achats, C-236/09 — statistical risk and discrimination.

Nowak, C-434/16 — personal data.

Österreichische Post, C-300/21 — GDPR damages and causation.

Core formula:

Accurate Data + Lawful Processing + Non-Discriminatory Model + Meaningful Explanation + Genuine Human Review + Effective Remedy = Legally Defensible Credit Scoring.

LEAVE A COMMENT