CJEU Delivers Judgment on Automated Decision-Making
13th March 2025
A German credit rating agency’s use of automated decision-making led to an individual being rejected for a bank loan. The Court of Justice of the European Union (CJEU) ruled that creating a credit score by Schufa AG does count as automated decision-making and could violate the GDPR. This has implications for the use of algorithms and other technology to determine credit scores, profiles or other assessments that can have significant effects on individuals. Case C-634/21 refers.
Case Details
Schufa AG is a credit rating agency in Germany that processes the data of around 70 million individuals. One of the services they offer is providing credit scores for people in Germany. In this case, a German resident applied for a bank loan with a German bank but was denied. The bank’s decision to reject the loan application was mostly based on an automated credit score from Schufa AG.
The individual challenged this decision and demanded that Schufa AG release the information relating to the automated decision that led to the individual’s loan application being rejected. Schufa asserted that while automated decision making was used to calculate the individual’s credit score, the ultimate decision was up to the bank offering the loan. The CJEU rejected this and ruled that the creation of the credit score was subject to Article 22 of the GDPR.
What is Automated Decision Making?

Automated decision-making, or ADM, is the use of automated technology, including AI, to make decisions about individuals without any human involvement. Some ADM can be very useful and remove the need for time-consuming manual work that can be done by computer software.
However, ADM can be problematic due to its lack of transparency and human intervention, as well as the concern that a machine or computer program, which cannot be held accountable, is making decisions about individuals that could have significant impacts on their lives. Automated decision-making could be responsible for them not getting offered a job, a bank loan, a mortgage, or even more sinister effects like criminal profiling and potentially being accused of illegal activity.
Some automated decision-making software has even been accused of having biases from their data sources or the people programming the software. This is why the GDPR has specific sections about automated decision-making and an individual’s rights regarding this.
The GDPR and Automated Decision-Making
Article 15 of the GDPR gives data subjects the right to request a copy of information held on them, and states that:
“The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information:”
And Art.15(1)(h) expressly states:
“the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.”
In other words, data subjects have to be told if automated decision-making is taking place, and in certain cases, what logic is being used to make the decision. Schufa argued that they were not responsible for an automated decision as the individual’s bank made the final decision. However, the CJEU ruled that Schufa’s credit score played a determining role in whether credit was granted. Schufa should have disclosed information about its scoring process to comply with Article 15 of the GDPR, even though the final decision was made by a third party.
Article 22 of the GDPR states that:
“The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.”
Once again, the individual applying for credit should be advised of the logic behind the decision made and have the right to contest the decision and request human intervention. The CJEU ruling stipulates that Schufa and other companies need to allow individuals to challenge credit scores determined by automation and provide a meaningful explanation of how they are calculated.
Key Takeaways
Whilst this was an EU decision and the UK is not bound by the rulings of the CJEU, the outcome in this case C-634/21 broadens the definition of the word ‘decision’ within Article 22 of the EU GDPR.
UK Controllers should take notice that our courts may take a similar view that a broad interpretation of the word ‘decision’ includes decisions that are strongly influenced by automated processes. This case confirms that automated scoring that significantly influences a decision counts as an automated decision. The companies that use this technology to produce these scores cannot shift their responsibilities under the GDPR to third parties, and individuals have the right to be informed of and to challenge these decisions.
In a more recent case, C-203/22, involving an individual in Austria being denied a mobile phone contract due to an automated credit assessment, the CJEU ruled that organisations cannot withhold information about their use of ADM based on the protection of ‘trade secrets’.
Author: Mike Martin LLM
Mike is an information governance specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.
Sources
