Law note · Germany
GDPR Article 22 and BDSG Sections 31 and 37, Automated Decisions and Credit Scoring in Germany
General Data Protection Regulation (GDPR) Articles 12 to 23 apply, including Article 22 rights against solely automated decision-making. BDSG Section 31 supplements this for credit-reporting and scoring agencies specifically.
The CJEU's SCHUFA ruling, Case C-634/21 (OQ v Land Hessen, judgment 7 December 2023), held that automated credit-score generation used determinatively by a third party such as a bank constitutes a decision based solely on automated processing within Article 22(1), which cast doubt on BDSG Section 31's compatibility with the narrow exceptions in Article 22(2)(b). No subsequent German court ruling resolving the Wiesbaden Administrative Court's remand from that reference was found in this research.
What it asks of an app
- Honor a person's request to access, rectify, erase, restrict, port, or object to processing of their personal data within one month of receipt, as required by General Data Protection Regulation (GDPR) Articles 12 to 23.
- Provide a meaningful human review before finalizing any decision based solely on automated processing that produces legal or similarly significant effects for a person in Germany, including a credit score generated for a third party's determinative use, under GDPR Article 22 and BDSG Section 31.
When LexLint raises it
Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions
Primary source: Official Journal text, EUR-Lex, Regulation (EU) 2016/679
BDSG §§31, 37; CJEU C-634/21