The Austrian Data Protection Authority ruled that CRIF's credit assessment constitutes profiling under the GDPR and must disclose that the creditworthiness score was calculated only from address, gender, name and date of birth. CRIF must also explain the scoring logic to the consumer concerned and cannot rely on legitimate interests under Article 6(1)(f). The agency ordered CRIF to redesign its credit reports to allow data subjects to explain the scores.
Why it matters: The decision reinforces GDPR transparency obligations for credit scoring agencies.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.