Regulatory Watch  /  Austria  /  Enforcement
Low impactEnforcementDecided

Austrian DPA orders credit agency CRIF to disclose scoring logic after GDPR complaint

The Austrian Data Protection Authority ruled that CRIF's credit assessment constitutes profiling under the GDPR and must disclose that the creditworthiness score was calculated only from address, gender, name and date of birth. CRIF must also explain the scoring logic to the consumer concerned and cannot rely on legitimate interests under Article 6(1)(f). The agency ordered CRIF to redesign its credit reports to allow data subjects to explain the scores.

Why it matters: The decision reinforces GDPR transparency obligations for credit scoring agencies.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Data voodoo: credit ranking agency CRIF creates credit rating out of thin air
noyb · primary source · Aug 4, 2021
Data voodoo: credit ranking agency CRIF creates credit rating out of thin air
noyb · Aug 4, 2021
Details
JurisdictionAustria
RegulatorAustrian Data Protection Authority
LawGeneral Data Protection Regulation
StatusDecided
PublishedAugust 4, 2021
Effectivenot stated
OrganisationsCRIF
Topicsprofiling, automated decision making, transparency, privacy, access, ai governance
Datapersonal