Civil Law And Algorithmic Credit Scoring Disputes In Europe

Civil Law and Algorithmic Credit Scoring Disputes in Europe

1. Introduction

Algorithmic credit scoring means using automated statistical or AI-based systems to assess the creditworthiness, financial reliability or probability that an individual will repay a debt.

A typical process is:

Personal/financial data → algorithmic profiling → probability calculation → credit score → lender decision → loan/credit/service consequence

Examples include automated decisions concerning:

  • bank loans;
  • mortgages;
  • credit cards;
  • consumer credit;
  • telecommunications contracts;
  • insurance-related financial services;
  • rental or housing applications;
  • electricity or other essential services where creditworthiness is assessed.

European law treats these systems as particularly sensitive because a score can affect access to financial resources and essential services. The EU AI Act specifically classifies AI systems used to evaluate the creditworthiness or credit score of natural persons as high-risk AI systems, subject to the conditions of the Regulation.

The most important modern cases are SCHUFA (C-634/21) and Dun & Bradstreet Austria (C-203/22).

2. Main Sources of European Law

Algorithmic credit scoring can simultaneously involve:

  1. GDPR
  2. EU AI Act
  3. EU Charter of Fundamental Rights
  4. Consumer-credit legislation
  5. Anti-discrimination law
  6. Contract law
  7. Tort/delict law
  8. National banking and financial regulation
  9. National procedural and administrative law

The central legal questions are:

  • Was the data lawfully collected?
  • Is the information accurate?
  • Was profiling used?
  • Was the decision genuinely automated?
  • Can the person obtain meaningful information about the scoring logic?
  • Was the score discriminatory?
  • Was there meaningful human intervention?
  • Can the individual challenge the decision?
  • Has the person suffered legally compensable damage?

3. What Is an Algorithmic Credit Score?

A credit-scoring system may calculate a probability such as:

“Probability of default = 8.4%.”

It may use information such as:

  • repayment history;
  • outstanding debts;
  • income;
  • employment information;
  • existing credit;
  • previous defaults;
  • public-register information;
  • address information;
  • financial behaviour;
  • statistical correlations.

The algorithm then converts these factors into a score.

For example:

Data

↓

Feature extraction

↓

Statistical/AI model

↓

Probability of repayment

↓

Credit score

↓

Loan approval/refusal

The legal problem often arises at the final two stages.

4. GDPR Article 22 — Automated Decision-Making

Article 22 GDPR is central.

It concerns decisions based solely on automated processing, including profiling, which produce legal effects or similarly significant effects on an individual.

Credit refusal can potentially constitute a sufficiently significant consequence.

The key issue is therefore:

Did the algorithm merely assist a human decision-maker, or did it effectively determine the outcome?

That distinction became particularly important in SCHUFA.

5. Case 1 — SCHUFA Holding (Scoring), C-634/21

Court: CJEU
Judgment: 7 December 2023

This is the leading European case on automated credit scoring.

SCHUFA calculated a probability value concerning an individual's ability to meet future payment obligations. Third parties, including banks, could use that score when deciding whether to provide credit.

The CJEU considered Article 22 GDPR and held that the automated establishment of such a probability value can itself constitute automated decision-making where the third party draws strongly on that score for its decision.

Importance

The legal analysis cannot necessarily stop at:

“The bank technically made the final decision.”

If the bank effectively treats the algorithmic score as determinative, Article 22 may apply.

Example

SCHUFA score = low

↓

Bank automatically refuses loan

↓

Bank employee formally signs refusal.

Calling the final signature “human decision-making” does not necessarily eliminate the relevance of Article 22.

Principle

The practical effect of the scoring system matters, not merely who formally presses the final button.

6. Case 2 — Dun & Bradstreet Austria, C-203/22

Court: CJEU
Judgment: 27 February 2025

This is the second major modern credit-scoring authority.

An Austrian mobile operator refused a customer a contract because of insufficient creditworthiness. The assessment had been carried out automatically by Dun & Bradstreet Austria. The underlying contract involved only a €10 monthly payment.

The CJEU interpreted GDPR Article 15(1)(h) concerning access to meaningful information about the logic involved in automated decision-making.

The Court held that the explanation must allow the person to understand and challenge the automated decision.

Important point

The individual is not necessarily entitled simply to receive the source code.

Instead, the explanation must be sufficiently meaningful to enable the person to understand the decision-making process and challenge its correctness.

Example

A company cannot simply state:

“Your score was 31.”

A meaningful explanation may need to address relevant factors and their role sufficiently for the individual to understand and contest the result.

Trade secrets

The CJEU also addressed trade-secret concerns.

If the controller claims that information contains:

  • trade secrets; or
  • protected third-party personal data,

the information can be submitted to the competent supervisory authority or court, which must balance the competing interests.

Principle

Algorithmic secrecy cannot automatically prevent effective scrutiny of a significant automated credit decision.

7. Case 3 — Österreichische Post, C-300/21

Court: CJEU
Judgment: 4 May 2023

This case did not concern traditional bank credit scoring. However, it is highly relevant to the damages aspect of algorithmic profiling.

Österreichische Post used an algorithm to analyse demographic information and infer political affinities of individuals. The claimant alleged distress, loss of confidence and a feeling of exposure.

The CJEU held:

  • a mere GDPR infringement does not automatically create a right to compensation;
  • actual damage must be established;
  • however, non-material damage does not have to exceed a particular minimum seriousness threshold imposed by national law. 

Relevance to credit scoring

Suppose an individual proves:

unlawful credit profiling.

That does not automatically mean:

automatic damages.

The claimant must establish the damage required under Article 82 GDPR.

Principle

GDPR violation + legally recognised damage + causal connection = potential compensation.

8. Case 4 — RW v Österreichische Post, C-154/21

Court: CJEU
Judgment: 12 January 2023

This case concerned the data subject's right of access to information concerning recipients of personal data under GDPR Article 15.

The Court examined the circumstances in which an individual can obtain information about the actual recipients of personal data rather than merely broad categories of recipients.

Relevance to credit scoring

Credit scores can be distributed among:

  • credit-reference agencies;
  • banks;
  • lenders;
  • insurers;
  • telecommunications companies;
  • other businesses.

A person challenging a score may therefore need to know where their data went and who received it.

Principle

Transparency concerning the circulation of personal data is an important part of effective data-subject rights.

9. Case 5 — Google Spain, C-131/12

Court: CJEU
Judgment: 13 May 2014

Google Spain concerned the treatment of personal information by search engines and the circumstances in which individuals could request removal of search results.

Although not a credit-scoring case, it establishes important principles concerning:

  • personal data;
  • relevance;
  • accuracy;
  • passage of time;
  • individual rights against continued dissemination of information.

Credit-scoring relevance

Imagine:

old financial difficulty → database record → algorithmic score → present-day credit refusal.

A credit-scoring system may continue relying on historical information long after its relevance has diminished.

The legal question can therefore become:

Is the underlying information still accurate, relevant and lawfully usable for the present credit assessment?

10. Case 6 — Breyer v Germany, C-582/14

Court: CJEU
Judgment: 19 October 2016

Breyer concerned dynamic IP addresses and the concept of personal data.

The CJEU recognised that information can constitute personal data even where the identifier does not itself directly reveal the person's identity, provided the person can reasonably be identified through additional information.

Relevance to credit scoring

Modern scoring systems may use:

  • digital identifiers;
  • device information;
  • online behaviour;
  • location;
  • digital footprints.

The fact that an algorithm uses an indirect identifier does not automatically mean that data-protection law is irrelevant.

Principle

Indirectly identifiable information can still constitute personal data.

11. Case 7 — Nowak v Data Protection Commissioner, C-434/16

Court: CJEU
Judgment: 20 December 2017

The CJEU interpreted the concept of “personal data” broadly.

The case concerned examination answers and examiner comments.

The Court held that information can qualify as personal data where it relates to an identifiable individual.

Credit-scoring relevance

An algorithm may generate:

  • internal assessments;
  • behavioural classifications;
  • risk indicators;
  • predictive evaluations.

The fact that a score is generated by an algorithm rather than directly supplied by the person does not necessarily take it outside the concept of personal data.

Principle

Derived or evaluative information concerning an identifiable person can fall within data-protection protection.

12. Case 8 — SCHUFA Holding, C-26/22 and C-64/22

Court: CJEU
Judgment: 7 December 2023

These joined cases concerned the retention of information concerning the granting of a discharge from remaining debts.

The CJEU examined the storage of such information by credit-information agencies and the relationship between the retention period and GDPR requirements. The Court found the prolonged retention at issue incompatible with the GDPR in the circumstances considered.

Importance

Credit scoring is not concerned only with:

“What data may be collected?”

It also concerns:

“How long can the information continue to influence a person's financial profile?”

Principle

Historical financial information cannot necessarily be retained and used indefinitely merely because it is available.

13. EU AI Act and Credit Scoring

The AI Act significantly strengthens the legal framework.

Article 6 and Annex III classify AI systems used to evaluate the creditworthiness or credit score of natural persons as high-risk systems, because these decisions can determine access to financial resources or essential services such as housing, electricity and telecommunications.

The Regulation recognises the risk of:

  • discrimination;
  • historical bias;
  • financial exclusion;
  • adverse fundamental-rights effects.

Importantly, the AI Act provides that an Annex III system performing profiling of natural persons remains high-risk even where certain other exemptions might otherwise apply.

14. AI Act Requirements Relevant to Credit Scoring

High-risk AI systems are subject to requirements concerning matters such as:

  • risk management;
  • data governance;
  • technical documentation;
  • record keeping;
  • transparency;
  • human oversight;
  • accuracy;
  • robustness;
  • cybersecurity.

Article 15 requires appropriate levels of accuracy, robustness and cybersecurity throughout the system's lifecycle.

This is highly relevant to credit scoring.

A system that systematically produces inaccurate scores may create:

  • regulatory problems;
  • discrimination risks;
  • contractual disputes;
  • data-protection claims;
  • civil damages claims.

15. Accuracy of Credit Data

Accuracy is one of the most important civil-law issues.

Consider:

Database incorrectly records a €5,000 unpaid debt.

The algorithm reads the record.

↓

Credit score decreases.

↓

Mortgage application rejected.

↓

Person suffers financial loss.

The dispute can potentially involve:

  1. inaccurate personal data;
  2. unlawful profiling;
  3. defective automated decision-making;
  4. lender's decision;
  5. causation;
  6. financial damage.

This makes data provenance extremely important.

16. Algorithmic Bias and Discrimination

Credit scoring can create discrimination even where the algorithm does not expressly use a protected characteristic.

For example:

Postal code → socioeconomic correlation → algorithmic risk score

or:

Employment history → gender-related statistical correlation → lower score

or:

Historical repayment data → discriminatory historical pattern → reproduced algorithmically

The AI Act itself recognises that creditworthiness systems can perpetuate historical discrimination based on characteristics such as racial or ethnic origin, gender, disability, age or sexual orientation.

The legal question is therefore not merely:

“Does the algorithm contain a race variable?”

It may also be:

“Do apparently neutral variables operate as discriminatory proxies?”

17. Proxy Discrimination

Suppose the algorithm does not ask:

“What is the applicant's ethnicity?”

But uses:

  • neighbourhood;
  • language;
  • purchasing patterns;
  • employment sector;
  • education;
  • family structure.

If these variables systematically correlate with a protected characteristic, the system may generate disparate outcomes.

The legal assessment depends on the applicable anti-discrimination regime and factual evidence.

18. Explainability

After Dun & Bradstreet Austria, explainability is a central issue.

An individual should be able to understand enough about the decision to challenge it.

A useful distinction is:

Source-code transparency

Providing the actual programming code.

Decision transparency

Explaining why the particular individual received the result.

European law does not simply equate the two.

For civil litigation, decision-level explanation is often more practically important.

19. Human Intervention

A lender may argue:

“The algorithm only makes a recommendation. A human makes the final decision.”

That statement must be examined factually.

Questions include:

  • Did the human independently assess the application?
  • Could the employee override the score?
  • Did the employee have authority to override it?
  • Was the employee trained to question the model?
  • How often were algorithmic recommendations overturned?
  • Was the human decision effectively predetermined?

This issue is particularly important following SCHUFA.

The central question is:

Was human involvement genuinely independent or merely formal?

20. Right to Challenge the Score

A practical dispute can involve:

Step 1

Request access to personal data.

Step 2

Identify the data used in the assessment.

Step 3

Check accuracy.

Step 4

Request meaningful information about automated processing.

Step 5

Challenge the automated decision where Article 22 applies.

Step 6

Request human intervention where applicable.

Step 7

Challenge the underlying credit decision.

Step 8

Seek compensation where legally available and damage can be established.

21. Trade Secrets and Algorithmic Transparency

Credit-scoring companies may argue:

“Our scoring model is commercially confidential.”

That can be legitimate.

But Dun & Bradstreet Austria makes clear that trade-secret concerns do not automatically end the inquiry.

Where protected information is involved, a supervisory authority or court can examine the information and balance:

  • individual's rights;
  • trade secrets;
  • third-party rights. 

Therefore:

Trade secret ≠ complete immunity from scrutiny.

22. Civil-Law Liability

Algorithmic credit-scoring disputes can produce several possible civil causes of action.

A. Contractual liability

For example:

  • wrongful refusal under a contractual relationship;
  • breach of contractual obligations;
  • failure to process an application according to agreed terms.

B. Tort/delict liability

Potentially based on:

  • unlawful interference;
  • negligence;
  • infringement of personality rights;
  • unlawful processing.

C. GDPR compensation

Article 82 GDPR provides a specific compensation framework where its requirements are met.

D. Consumer protection

Potentially involving:

  • unfair practices;
  • misleading information;
  • unfair contractual terms;
  • inadequate transparency.

23. Causation

Causation is often difficult.

Suppose:

Algorithm gives applicant a low score.

Then:

Bank refuses loan.

Then:

Applicant loses €100,000 property opportunity.

The claimant may need to establish:

algorithmic error → low score → refusal → actual loss.

But suppose the bank had another independent reason for refusal.

Then the causal chain becomes more complicated.

Therefore evidence should establish whether the score was:

  • decisive;
  • influential;
  • one of several factors;
  • merely advisory.

24. Damages

Potential damages may include, depending on national law and applicable legal basis:

Material damage

  • lost financial opportunity;
  • additional borrowing costs;
  • increased interest;
  • transaction costs;
  • other proven economic loss.

Non-material damage

Potentially:

  • distress;
  • loss of control over personal data;
  • reputational harm;
  • other recognised non-material injury.

But Österreichische Post establishes an important qualification:

A GDPR infringement by itself does not automatically create compensation.

There must be compensable damage caused by the infringement.

25. Credit-Reference Agency vs Bank

A credit dispute can involve several defendants.

Credit-reference agency

Produces the score.

Bank

Uses the score.

Data supplier

Provides underlying information.

Technology provider

Develops the AI model.

Employer/landlord/telecom provider

May use the score for another transaction.

The legal responsibility of each actor depends on its specific role.

26. Data Controller and Processor Issues

A complicated structure may look like:

Consumer

↓

Credit-information agency

↓

AI vendor

↓

Bank

↓

Credit decision

The parties' GDPR roles must be analysed carefully.

Questions include:

  • Who determines the purpose?
  • Who determines the means?
  • Who supplies data?
  • Who controls the scoring model?
  • Who makes the final decision?
  • Who is responsible for correcting inaccurate data?

27. Automated Fraud Detection vs Creditworthiness

The AI Act distinguishes certain systems used for fraud detection and prudential purposes from the specific high-risk creditworthiness category.

Therefore:

fraud detection ≠ ordinary consumer credit scoring.

The exact intended purpose and regulatory classification matter.

A system may perform multiple functions, requiring a careful classification analysis under the AI Act.

28. Essential Services

The AI Act's treatment of creditworthiness is particularly significant because credit assessments can affect more than conventional loans.

The Regulation specifically recognises potential consequences for access to:

  • housing;
  • electricity;
  • telecommunications;
  • financial resources.

Thus, a technically “private” scoring system can have major social consequences.

29. Evidence in Credit-Scoring Litigation

Important evidence includes:

  • credit report;
  • underlying database records;
  • score history;
  • scoring methodology;
  • model documentation;
  • input variables;
  • data sources;
  • correction history;
  • automated-decision logs;
  • human-review records;
  • lender's decision;
  • correspondence;
  • internal policies;
  • risk assessments;
  • AI compliance documentation;
  • discrimination testing;
  • validation results.

Dun & Bradstreet Austria makes meaningful access to the logic underlying automated profiling particularly significant.

30. Expert Evidence

Expert evidence may be required to establish:

  • statistical accuracy;
  • model performance;
  • error rates;
  • discriminatory effects;
  • proxy variables;
  • causal contribution;
  • model validation;
  • data quality;
  • whether human intervention was meaningful.

Experts may include:

  • data scientists;
  • statisticians;
  • AI specialists;
  • economists;
  • financial-risk experts;
  • forensic technology experts.

31. Proportionality

Credit scoring must also be assessed against proportionality.

The relevant questions may include:

Legitimate purpose

Why is the score necessary?

Suitability

Does it actually predict repayment risk?

Necessity

Could the same purpose be achieved using less intrusive data?

Proportionality

Are the consequences for the individual justified?

This is particularly important when very large datasets are used to make relatively small financial decisions.

32. Data Minimisation

Suppose a €500 consumer-credit application uses:

  • full online browsing history;
  • social-media activity;
  • location history;
  • contacts;
  • purchasing history;
  • health information.

The legal question becomes:

Are all these categories genuinely necessary and lawfully usable for the stated credit-assessment purpose?

The fact that an algorithm can technically use information does not establish that it should legally use it.

33. Historical Debt Information

Historical debt is particularly important.

Suppose:

Person experienced insolvency ten years ago.

Later:

Debt discharged.

But the old information continues to depress the person's score.

The SCHUFA discharge cases show the importance of examining the retention period and continuing use of historical financial information.

The legal analysis may involve:

  • accuracy;
  • storage limitation;
  • purpose limitation;
  • legitimate interests;
  • relevance;
  • proportionality.

34. Algorithmic Credit Scoring and Privacy

Credit scoring can create a detailed economic profile of a person.

That profile may reveal:

  • financial vulnerability;
  • spending patterns;
  • debt;
  • family circumstances;
  • employment;
  • residential history.

Consequently, credit scoring is not simply a financial issue.

It can also become a privacy and personality-rights issue.

35. Contractual Terms

Banks may include terms stating that:

“Credit approval is subject to internal risk assessment.”

Such terms do not necessarily settle GDPR or AI-law questions.

Contractual autonomy remains subject to:

  • mandatory consumer law;
  • GDPR;
  • anti-discrimination law;
  • applicable financial regulation;
  • AI Act requirements.

36. Regulatory and Civil Remedies

Possible remedies include:

Data-protection remedies

  • access;
  • rectification;
  • erasure where applicable;
  • restriction;
  • objection where applicable;
  • challenge to automated decision-making.

Civil remedies

  • damages;
  • injunction;
  • declaration;
  • contractual remedies.

Regulatory remedies

  • supervisory authority investigation;
  • corrective orders;
  • administrative penalties.

Credit remedies

  • reassessment;
  • correction of credit record;
  • reconsideration of application.

37. Relationship Between GDPR and AI Act

GDPRAI Act
Protects personal dataRegulates AI systems
ProfilingHigh-risk AI classification
Article 22 automated decisionsAI governance requirements
AccuracyData-protection + AI accuracy obligations
TransparencyMeaningful information + AI transparency
Data-subject rightsProvider/deployer obligations
CompensationNational/GDPR damages framework
Supervisory enforcementAI regulatory enforcement

The two regimes can therefore operate simultaneously.

38. Practical Legal Test

A European court or regulator examining an algorithmic credit-scoring dispute can work through:

1. What is the system?

Traditional statistical model, machine learning, generative AI, hybrid?

2. What is its purpose?

Creditworthiness, fraud detection, pricing, marketing or something else?

3. What data are used?

Financial and/or non-financial information?

4. Is profiling involved?

Does the system create a predictive profile?

5. Is the system high-risk under the AI Act?

Creditworthiness AI for natural persons is specifically addressed in Annex III.

6. Was the decision solely automated?

If yes, Article 22 GDPR becomes central.

7. Was the score effectively determinative?

SCHUFA is particularly important.

8. Can the person understand the logic?

Dun & Bradstreet Austria is central.

9. Is the underlying information accurate?

Check source data and historical records.

10. Is there discrimination?

Examine direct and proxy effects.

11. Was there damage?

Material or non-material.

12. Can causation be established?

Connect the unlawful processing/scoring to the actual loss.

39. Comparison of Major Cases

CaseMain legal issueImportance for credit scoring
SCHUFA, C-634/21Automated scoring and Article 22⭐ Core authority
Dun & Bradstreet Austria, C-203/22Explanation of automated scoring⭐ Core authority
Österreichische Post, C-300/21GDPR damagesCompensation
SCHUFA, C-26/22 & C-64/22Retention of debt-discharge informationHistorical data
RW, C-154/21Access to data recipientsData transparency
Nowak, C-434/16Meaning of personal dataDerived/evaluative information
Google Spain, C-131/12Relevance and continued availability of personal dataHistorical information
Breyer, C-582/14Indirect identifiersDigital profiling

40. Six Cases to Memorise

For examination purposes, these six are particularly useful:

1. SCHUFA Holding (Scoring), C-634/21

Automated credit scoring + Article 22 GDPR.

2. Dun & Bradstreet Austria, C-203/22

Meaningful explanation of automated credit assessment.

3. Österreichische Post, C-300/21

GDPR infringement alone does not automatically create compensation.

4. SCHUFA Holding, C-26/22 & C-64/22

Limits on prolonged retention of debt-discharge information.

5. RW v Österreichische Post, C-154/21

Access to information concerning recipients of personal data.

6. Nowak, C-434/16

Broad concept of personal data, including evaluative information.

41. Key Legal Principles

  1. Credit scoring can constitute automated decision-making under Article 22 GDPR.
  2. The practical influence of a score matters, not simply the formal identity of the final decision-maker. 
  3. Individuals can have a right to meaningful information concerning the logic behind automated credit assessments. 
  4. Trade secrets do not automatically defeat effective judicial or regulatory scrutiny. 
  5. Creditworthiness AI for natural persons is specifically treated as high-risk under the AI Act. 
  6. Accuracy and reliability of the underlying data are fundamental.
  7. Historical financial information cannot necessarily remain influential indefinitely. 
  8. Indirect or inferred information can still constitute personal data.
  9. Algorithmic discrimination can arise through apparently neutral proxy variables.
  10. A GDPR infringement alone does not automatically establish a damages claim. 
  11. Causation between the scoring error and the claimant's actual loss must be established.
  12. Human review should be assessed for its actual, rather than merely formal, role.

42. Exam-Ready Conclusion

Algorithmic credit scoring in Europe is governed by a combination of GDPR, the EU AI Act, fundamental-rights principles, consumer law and national civil-liability rules.

The most important authority is SCHUFA Holding (C-634/21), which establishes that automated calculation of a probability concerning a person's ability to meet payment obligations can fall within Article 22 GDPR where the score is effectively relied upon for the subsequent decision.

Dun & Bradstreet Austria (C-203/22) develops the transparency dimension by requiring meaningful information capable of enabling the person to understand and challenge the automated decision.

The AI Act adds another major layer by expressly classifying AI used to evaluate the creditworthiness or credit score of natural persons as high-risk, reflecting the potential effects on financial resources, housing and essential services.

The overall legal framework can therefore be expressed as:

Data collection → data accuracy → profiling → algorithmic scoring → automated decision → explanation/human review → discrimination and proportionality → actual damage → causation → civil/regulatory remedy.

The central civil-law issue is ultimately not whether an algorithm was used, but whether the scoring system was lawfully designed and operated, whether the resulting decision complied with European data-protection and AI requirements, and whether any proven unlawfulness caused legally compensable harm to the individual.

LEAVE A COMMENT