CJEU SCHUFA Ruling Reaches AI Credit Scoring | TLY

AI Regulation Tracker  /  Courts and enforcement

The CJEU Ruling That Made a Credit Score an Automated Decision

A landmark from December 7, 2023, that still sets the rules for AI scoring in Europe. In Case C-634/21 (SCHUFA Holding), the Court of Justice of the European Union delivered its first interpretation of Article 22 of the GDPR and held that building an automated credit score is itself a solely automated decision when a lender draws strongly on it. That put the Article 22 duty on the scoring agency, not just the lender who acts on the number.

The Leveraged Years AI Regulation News

Let me start with what the case was actually about, because the facts are simple and they matter. A German consumer was refused credit after SCHUFA, the largest credit information agency in Germany, produced a score about her. She asked SCHUFA to tell her the logic behind the score and to erase certain data. SCHUFA said it only supplied the score to lenders and that the lending decision was made by the bank, so the real decision, and any Article 22 questions, sat with the bank, not with SCHUFA. The Administrative Court of Wiesbaden was not sure that was right and sent the question to Luxembourg. The issue was narrow but consequential. When an agency computes a score and a bank almost always follows it, who is making the automated decision the GDPR regulates?

What the Court actually held

The Court of Justice answered that the scoring agency is. In the operative part of the judgment, it ruled that "the automated establishment, by a credit information agency, of a probability value based on personal data relating to a person and concerning his or her ability to meet payment commitments in the future constitutes 'automated individual decision-making' within the meaning of that provision, where a third party, to which that probability value is transmitted, draws strongly on that probability value to establish, implement or terminate a contractual relationship with that person." That is the whole ruling in one sentence, and every word in it does work.

Two pieces are worth slowing down on. First, the Court treated the concept of a decision under Article 22 as broad enough to reach the score itself, not just the final yes or no on the loan. The reasoning was practical. On the facts before the referring court, an insufficient score led, in almost all cases, to the bank refusing the loan. When the number effectively determines the outcome, the Court was unwilling to say the number is not a decision merely because a human at the bank formally clicks the button. Second, the Court was candid that a narrower reading would leave a gap in protection. If the score fell outside Article 22, a data subject could be shut out of credit by an automated calculation while no one who actually built that calculation owed them the Article 22 safeguards. The Court declined to accept that outcome.

Why placing the duty on the agency is the whole point

Before this ruling, a scoring vendor could say what SCHUFA said: we do not make decisions, we sell inputs. After it, that defense is gone in Europe wherever a customer draws strongly on the output. Once the establishment of the score is an automated individual decision, Article 22 attaches to the agency. Article 22 as a rule prohibits solely automated decisions that produce legal effects or similarly significant effects on a person, unless one of the narrow gateways applies, contractual necessity, explicit consent, or authorization under EU or member state law, and even then the controller must provide safeguards, including the right to obtain human intervention, to express a point of view, and to contest the decision. So the agency that generates a heavily relied-on score has to find a lawful basis under Article 22 and stand up those safeguards. It cannot point downstream to the lender and walk away.

Read the status precisely: binding, and older than the headlines suggest

I want to be exact about two things so no one overstates this. It is binding. A preliminary ruling of the Court of Justice is not soft guidance or a regulator's opinion, it is an authoritative interpretation of the GDPR that every national court and supervisory authority in the EU and EEA must follow. And it is not new. It was handed down on December 7, 2023. I am covering it now because it is evergreen, not because it just broke. It is the foundational Article 22 precedent, the case that later European automated-decision decisions cite and extend, and if you are building or buying scoring systems that touch European data subjects, it is the one you have to know cold. Treat any newer EU automated-decision development as a descendant of this ruling, because that is what it is.

What this means for US firms

Here is the part US operators tend to miss. This is a European judgment, but it binds US behavior through the GDPR's territorial reach. If a US credit-scoring firm, ad-tech platform, insurtech underwriter, or lender processes the personal data of people in the EU or EEA to build or apply automated scores, the GDPR applies, and this ruling tells you how Article 22 reads for scoring. The lesson is that you cannot escape the automated-decision rules by selling a score as a mere input and letting a customer press the button. If your customers draw strongly on your output, the regulator and the courts may treat you as the one making the automated decision, with all the Article 22 duties that follow. Practically, three moves matter. Know whether any of your scored subjects sit in the EU or EEA. Identify a lawful Article 22 basis for the scoring you do, rather than assuming the duty lives with whoever acts on the score. And build the human-review and contestability machinery Article 22 requires, because the theory that you are a neutral data vendor is exactly the theory the Court rejected here.

For attorneys advising these firms, this is the case to anchor an automated-decision compliance memo on, and the one to raise when a client insists their scoring product is not a decision. It is also the reference point for reading the newer EU automated-decision rulings, which sharpen the transparency and reasoning obligations but sit squarely on the foundation this judgment laid.

Questions professionals are asking

What did the SCHUFA ruling actually decide?

The CJEU held that when a credit information agency automatically generates a probability value about a person's ability to meet future payments, and a lender draws strongly on that value to grant or refuse credit, the generation of the score is itself an automated individual decision under Article 22 GDPR. The compliance duty therefore attaches to the scoring agency, not only to the lender.

Is this binding, and when was it decided?

It is binding. A preliminary ruling of the Court of Justice authoritatively interprets EU law and binds every national court and supervisory authority in the EU and EEA. It was decided on December 7, 2023, in Case C-634/21, and it remains the foundational Article 22 precedent that later automated-decision rulings build on.

Why does it matter that the duty falls on the agency?

Because it closes the "we only supply an input" defense. Once building the score is treated as the automated decision, Article 22 attaches to the agency that builds it, which as a rule prohibits solely automated decisions with significant effects unless a lawful gateway applies and safeguards, including human review and the right to contest, are in place. The agency cannot point downstream to the lender and walk away.

Does this reach US companies?

Yes, through the GDPR's territorial scope. A US credit-scoring, ad-tech, insurtech, or lending firm that processes the personal data of people in the EU or EEA to build or apply automated scores is subject to the GDPR, and this ruling tells it how Article 22 reads for scoring. Selling the score as a neutral input does not avoid the automated-decision rules if customers draw strongly on it.

What should firms and their attorneys do about it?

Determine whether any scored subjects are in the EU or EEA, identify a lawful Article 22 basis for the scoring itself rather than assuming the duty sits with whoever acts on the score, and build the human-intervention and contestability safeguards Article 22 requires. Attorneys should anchor automated-decision compliance advice on this case and treat newer EU automated-decision rulings as extensions of it.

RELATED BRIEFINGS

Browse the full AI Regulation News tracker

Informational analysis for working professionals, not legal advice. Confirm how Article 22 GDPR and this ruling apply to your situation with qualified data protection counsel in the relevant jurisdiction.