Regulatory Watch  /  Austria  /  Enforcement
Moderate impactEnforcementFiled

noyb files GDPR complaint against CRIF over arbitrary credit score

noyb.eu lodged a GDPR complaint with the Austrian Data Protection Authority against credit rating agency CRIF for assigning a credit score of 446 despite claiming no personal data was stored. The score caused an electricity supplier to refuse a contract with the consumer. The complaint cites violations of data accuracy and lack of transparency in automated decision‑making.

Why it matters: The case highlights GDPR enforcement on opaque credit scoring that can deny essential services.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Credit Scoring: Negative credit rating generated without data
noyb · primary source · Aug 4, 2020
Credit Scoring: Negative credit rating generated without data
noyb · Aug 4, 2020
Details
JurisdictionAustria
RegulatorAustrian Data Protection Authority
LawGeneral Data Protection Regulation
StatusFiled
PublishedAugust 4, 2020
Effectivenot stated
Penaltypotential fine of up to €20million
OrganisationsCRIF, noyb.eu
Topicsautomated decision making, profiling, algorithmic discrimination, transparency, access, privacy
Datapersonal