Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

From Svedka to Anthropic, Brands Are Making Bold Plays With AI in Super Bowl Ads

Accel doubles down on Fibr AI as agents turn static websites into one-to-one experiences

SNAK Venture Partners raises $50 million in capital to support vertical acquisitions

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Benchmark raises $225 million in dedicated funds to double Cerebras

    7 February 2026

    How artificial intelligence is helping to solve the labor issue in treating rare diseases

    6 February 2026

    Amazon and Google are winning the AI ​​capital race — but what’s the prize?

    6 February 2026

    AWS revenue continues to grow as cloud demand remains high

    5 February 2026

    Sam Altman tested Claude’s Super Bowl commercials brilliantly

    5 February 2026
  • Apps

    EU says TikTok must disable ‘addictive’ features like infinite scrolling, fix recommendation engine

    7 February 2026

    Here’s how Roblox’s age controls work

    6 February 2026

    Meta is testing a standalone app for its AI-generated ‘Vibes’ videos

    6 February 2026

    Reddit sees AI search as the next big opportunity

    5 February 2026

    Tinder looks to AI to help fight dating app ‘fatigue’ and burnout

    5 February 2026
  • Crypto

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025
  • Fintech

    Stripe Alumni Raise €30M Series A for Duna, Backed by Stripe and Adyen Executives

    5 February 2026

    Fintech CEO and Forbes 30 Under 30 alum indicted for alleged fraud

    3 February 2026

    How Sequoia-backed Ethos went public while rivals lagged behind

    30 January 2026

    5 days left for TechCrunch Disrupt 2026 +1 pass with 50%

    26 January 2026

    50% off +1 ends | TechCrunch

    23 January 2026
  • Hardware

    Kindle Scribe Colorsoft is an expensive but beautiful color e-ink tablet with AI features

    6 February 2026

    Ring brings “Search Party” feature for finding lost dogs to non-Ring camera owners

    2 February 2026

    India offers zero taxes till 2047 to attract global AI workloads

    1 February 2026

    Microsoft won’t stop buying AI chips from Nvidia, AMD even after its own is released, says Nadella

    30 January 2026

    The iPhone just had its best quarter ever

    30 January 2026
  • Media & Entertainment

    From Svedka to Anthropic, Brands Are Making Bold Plays With AI in Super Bowl Ads

    7 February 2026

    “Industry” Season 4 captures tech fraud better than any show on TV right now

    7 February 2026

    Spotify’s new feature lets you explore the story behind the song you’re listening to

    6 February 2026

    The Washington Post retreats from Silicon Valley when it matters most

    6 February 2026

    Spotify is in the business of selling books and adding new audiobook features

    5 February 2026
  • Security

    Senator, who has repeatedly warned of secret US government surveillance, raises new alarm over ‘CIA activities’

    7 February 2026

    Substack confirms that the data breach affects users’ email addresses and phone numbers

    6 February 2026

    One of Europe’s biggest universities was offline for days after the cyber attack

    6 February 2026

    Cyber ​​tech giant Conduent’s hot air balloon data breach affects millions more Americans

    5 February 2026

    Hackers Release Personal Information Stolen During Harvard, UPenn Data Breach

    5 February 2026
  • Startups

    Accel doubles down on Fibr AI as agents turn static websites into one-to-one experiences

    7 February 2026

    ElevenLabs Raises $500M From Sequoia At $11B Valuation

    7 February 2026

    Fundamental raises $255 million in Series A with a new approach to big data analytics

    6 February 2026

    a16z VC wants founders to stop stressing about crazy ARR numbers

    6 February 2026

    Lunar Energy raises $232 million to develop home batteries that support the grid

    5 February 2026
  • Transportation

    Prince Andrew’s adviser suggested Jeffrey Epstein invest in EV startups like Lucid Motors

    7 February 2026

    Apeiron Labs Takes $9.5M to Flood Oceans with Autonomous Underwater Robots

    5 February 2026

    Uber appoints new CFO as its AV plans accelerate

    5 February 2026

    Skyryse lands another $300 million to make flying, even helicopters, simple and safe

    4 February 2026

    China is leading the fight against hidden car door handles

    3 February 2026
  • Venture

    SNAK Venture Partners raises $50 million in capital to support vertical acquisitions

    7 February 2026

    Reddit says it’s looking for more acquisitions in adtech and elsewhere

    7 February 2026

    Secondary sales are shifting from founders’ windfalls to employee retention tools

    6 February 2026

    Sapiom Raises $15M to Help AI Agents Buy Their Own Tech Tools

    6 February 2026

    What a16z actually funds (and what it ignores) when it comes to AI infra

    5 February 2026
  • Recommended Essentials
TechTost
You are at:Home»Fintech»Credit rating agencies face restrictions after landmark EU data protection ruling
Fintech

Credit rating agencies face restrictions after landmark EU data protection ruling

techtost.comBy techtost.com8 December 202306 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Credit Rating Agencies Face Restrictions After Landmark Eu Data Protection
Share
Facebook Twitter LinkedIn Pinterest Email

Credit rating agencies operating in the European Union may face tighter restrictions under the bloc’s privacy laws following a ruling issued today by the Court of Justice of the European Communities (CJEU). The referral relates to complaints made against the practices of a German credit rating agency, called Sufabut it could have wider implications for credit reporting agencies operating in the area where the General Data Protection Regulation (GDPR) applies.

A complaint that the CJEU examined focused on a case of “prolonged” data retention by the credit reporting company of information on the granting of discharge of outstanding debts held in the German public insolvency register for only six months. However, a code of conduct for German credit bureaus allows a three-year retention period for their own databases. And the Hesse Data Protection Authority had rejected the complaint about data retention. also seeking to support the local court could not review its decision. The CJEU disagreed.

“The Court considers it contrary to the GDPR for private entities to retain such data for longer than the public insolvency register,” he wrote in a press release for case C-634/21 (plus joined cases C-26/ 22 and C-64/22). “Discharge of remaining debts is intended to enable the data subject to re-enter economic life and is therefore of existential importance to that individual. This information is still used as a negative factor when assessing the creditworthiness of the data subject. In this case, the German legislator provided for the storage of data for six months. It therefore considers that, at the end of the semester, the rights and interests of the data subject prevail over those of the public to access that information.”

“To the extent that the retention of the data is unlawful, as is the case after six months, the data subject has the right to request the deletion of the data and the organization is obliged to delete the data as soon as possible,” the court added.

The CJEU also ruled on a second complaint that seems rather existential for credit rating agencies – as it questions whether Schufa can automatically issue credit scores, given that the GDPR provides protection for individuals subject to solely automated decisions with legal or significant implications for that’s all. So, in effect, they may need to get people’s express consent to rate them.

The Court ruled that Schufa’s credit rating should be regarded as an “automated individual decision”, which its press release notes is “prohibited in principle by the GDPR, to the extent that Schufa’s customers, such as banks, attribute to it decisive role in the granting of credits”.

If this type of credit assessment is the basis for a bank’s decision to, for example, refuse an individual loan, the practice risks breaching EU data protection rules.

Although in this particular case it will be up to the Wiesbaden Administrative Court to assess whether the German Federal Data Protection Act contains a valid exception to the prohibition under the GDPR. And, if so, to check whether the general conditions set out by the GDPR for data processing are met — such as ensuring that individuals know their right to object and request (and receive) human intervention, and are in position to provide meaningful information about the credit score rationale upon request.

“Judicial review” of APD decisions

In another important ruling, the CJEU also made it clear that national courts must be able to exercise what its PR calls “full review” on any legally binding decision of a data protection authority.

Privacy rights group noybwhich has had multiple run-ins with the DPAs over their inability to act on (let alone enforce) complaints, used it as particularly important – calling it “full judicial review” of the DPAs.

“The decision of the CJEU massively increased the pressure on the APD. In some EU member states, including Germany, they have so far assumed that a GDPR complaint by data subjects is simply a kind of “report”. In practice, this means that despite an annual budget of 100 million euros, German DPAs have rejected many complaints with strange justifications and that GDPR violations have not been pursued. In countries such as Ireland, over 99% of complaints were not processed and in France, victims were denied any right to participate in the process regarding their own rights. Some APRs, such as the Hessian authority in this case, have also held that courts are prohibited from reviewing their decisions in detail,” he wrote in a press release responding to the ruling.

“The CJEU has now put an end to this approach. It has been held that Article 77 of the GDPR is designed as a mechanism to effectively protect the rights and interests of data subjects. In addition, the court ruled that Article 78 of the GDPR allows national courts to conduct a full review of DPO decisions. This includes assessing whether the authorities have acted within the limits of their discretion.’

Higher GDPR fines on the way?

The two landmark rulings follow another ruling handed down yesterday by the CJEU (also through, in part, another referral case in Germany), which legal experts suggest could lead to significantly higher penalties for GDPR violations as it reduces requirements for the imposition of fines on legal entities.

Thus, while, in this case (C-807/21), the Court held that unlawful conduct is necessary for a fine to be imposed — that is, that the breach of the GDPR must have been committed “intentionally or negligently” — judges also said that, when the controller is a legal person, it is not necessary that the violation has been committed by its management body, nor is it necessary for that body to be aware of this violation.

They further stipulated that the calculation of any fine requires the supervisory authority to take as a basis the definition of ‘undertaking’ under competition law’ (aka, according to the PR Court, that ‘the maximum amount of the fine must be calculated on the basis of a percentage of the total global annual turnover of the business concerned, taken as a whole, in the previous financial year’ — or, basically, that the revenue of an entire group of companies can be used to calculate a GDPR penalty for an infringement committed by a single unit of this group).

Jan Spittka, a partner at law firm Clyde & Co., predicted that tougher GDPR fines could follow. “The general framework of the decision will make it easier for EU Member States’ data protection supervisory authorities to sanction legal entities and is also likely to lead to significantly higher fines on average,” he suggested in a statement.

“Under this standard, only a detailed and tightly controlled data protection compliance system can put a legal entity in a position to argue that it was unaware of its unlawful conduct in relation to breaches of the GDPR committed by an employee,” he said . “Furthermore, a legal entity can be exonerated if representatives or employees act completely outside the scope of their job description, e.g. when using personal data for private purposes”.

agencies cjeu credit score credit data data protection face judicial review gdpr landmark protection rating restrictions ruling schufa cjeu
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCambium Closes $19M Series A to Develop Advanced Biomaterials for Next-Gen Hardware
Next Article Bitcoin Continues to Rise, Block Launches Hardware Wallet, Robinhood Expands to EU, and VCs May See Some Relief Soon
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Substack confirms that the data breach affects users’ email addresses and phone numbers

6 February 2026

Fundamental raises $255 million in Series A with a new approach to big data analytics

6 February 2026

Cyber ​​tech giant Conduent’s hot air balloon data breach affects millions more Americans

5 February 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

From Svedka to Anthropic, Brands Are Making Bold Plays With AI in Super Bowl Ads

7 February 2026

Accel doubles down on Fibr AI as agents turn static websites into one-to-one experiences

7 February 2026

SNAK Venture Partners raises $50 million in capital to support vertical acquisitions

7 February 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Stripe Alumni Raise €30M Series A for Duna, Backed by Stripe and Adyen Executives

5 February 2026

Fintech CEO and Forbes 30 Under 30 alum indicted for alleged fraud

3 February 2026

How Sequoia-backed Ethos went public while rivals lagged behind

30 January 2026
Startups

Accel doubles down on Fibr AI as agents turn static websites into one-to-one experiences

ElevenLabs Raises $500M From Sequoia At $11B Valuation

Fundamental raises $255 million in Series A with a new approach to big data analytics

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.