GDPR · Fintech

GDPR for Fintech: Credit Scoring, Art. 22 and AEPD Fines

The CJEU confirmed in the Schufa case (2023) that credit scoring is an automated decision under Art. 22 GDPR. Learn the legal bases, AEPD fines in the financial sector and LOPDGDD Art. 20.

Does your Fintech comply with the GDPR?

The GDPR (Regulation (EU) 2016/679) and the LOPDGDD (Organic Law 3/2018) regulate the processing of personal data in the fintech sector. The most critical aspects are:

Credit scoring as automated decision: The CJEU confirmed in the Schufa case (C-634/21, 7 Dec 2023) that credit scoring constitutes an automated decision under Art. 22 GDPR. This means data subjects have the right not to be subject to a decision based solely on automated processing that produces legal effects or significantly affects them, unless an exception applies (contract, legal authorisation, explicit consent).

Legal bases (Art. 6 GDPR): For credit scoring, common bases are:

  • Legitimate interest (Art. 6(1)(f)) — credit risk assessment
  • Contract (Art. 6(1)(b)) — necessary to execute a loan contract
  • Legal obligation (Art. 6(1)(c)) — anti-money laundering

Special data (Art. 9 GDPR): Financial data are not themselves special categories, but may become so if used as a proxy for health, biometrics, religion, ethnicity or other sensitive data.

LOPDGDD Art. 20: Regulates solvency and credit files, setting requirements for the processing of solvency data: accuracy, updating, retention period (6 years for negative data) and the data subject's right of access.

DPIA (Art. 35): Systematic and extensive credit scoring requires a Data Protection Impact Assessment.

  • Art. 22 analysis — We assess whether your credit scoring is an automated decision and the applicable exceptions
  • Legal bases — We identify the appropriate Art. 6 basis for each financial processing operation
  • Financial DPIA — We carry out the Art. 35 Impact Assessment for credit scoring
  • LOPDGDD Art. 20 compliance — We verify solvency and credit files
  • AEPD coordination — We act before the AEPD in inspections, requests and complaints

GDPR obligations for Fintech

GDPR obligations for a fintech include:

Legal bases and transparency:

  • Identify the Art. 6 legal basis for each processing operation (legitimate interest, contract, legal obligation)
  • Information to the data subject (Arts. 13-14): controller identity, purposes, legal basis, recipients, transfers, rights
  • Clear and accessible privacy policy

Data subject rights:

  • Access, rectification, erasure, restriction, portability, objection (Arts. 15-21)
  • Right not to be subject to automated decisions (Art. 22), with additional safeguards
  • Right to object to legitimate interest (Art. 21(1))

Security and breaches:

  • Technical and organisational measures (Art. 32): encryption, pseudonymisation, access control
  • Breach notification within 72 hours (Art. 33) if there is a risk to data subjects' rights
  • Communication to affected persons (Art. 34) if there is a high risk

DPIA and DPO:

  • Mandatory DPIA for systematic credit scoring (Art. 35)
  • Mandatory DPO if core activities consist of systematic and large-scale monitoring (Art. 37)

International transfers:

  • If using cloud providers outside the EEA (AWS, GCP, Azure): SCCs, BCRs, adequacy decision or TIA
  • Sub-processor assessment (Art. 28(2)-(4))

Fines: Up to €20 million or 4% of global turnover (upper level). The AEPD has fined CaixaBank €6M (2021) and BBVA €5M (2020).

Most relevant GDPR articles for Fintech

ArticleTopicApplication in fintech
Art. 6Legal basesLegitimate interest, contract, legal obligation for scoring
Art. 9Special categoriesIf data reveal health, biometrics or other sensitive data
Art. 13-14Information to data subjectPrivacy policy, scoring notice
Art. 22Automated decisionsCredit scoring (Schufa ruling C-634/21)
Art. 32SecurityEncryption, access control, pseudonymisation
Art. 35DPIASystematic and extensive credit scoring
Art. 37DPOSystematic and large-scale monitoring
Arts. 44-49TransfersCloud providers outside the EEA
LOPDGDD Art. 20Credit solvencySolvency files: accuracy, 6 years, right of access

Real enforcement cases in the financial sector

  • CaixaBank, €6,000,000 (2021) — Breach of Arts. 6, 13 and 14 GDPR in data processing for profiling. Source: EDPB
  • BBVA, €5,000,000 (2020) — Breach of Arts. 6 and 13 GDPR. Source: Enforcement Tracker
  • CJEU Schufa judgment (C-634/21, 7 Dec 2023) — Credit scoring constitutes an automated decision under Art. 22 GDPR. Source: EUR-Lex
  • AEPD — Legal report on credit information systems: AEPD
  • AEPD — GDPR compliance for AI processing (2020): AEPD
  • EDPB/WP29 — Guidelines on automated decisions (WP251rev.01): EDPB

GDPR compliance checklist for Fintech

  • Identify all personal data processing operations
  • Determine the Art. 6 legal basis for each processing operation
  • Verify whether credit scoring is an automated decision (Art. 22)
  • Identify an Art. 22 exception (contract, legal authorisation, explicit consent)
  • Implement additional Art. 22 safeguards (human intervention, information)
  • Draft a clear privacy policy (Arts. 13-14)
  • Implement data subject rights mechanisms (Arts. 15-21)
  • Carry out DPIA for systematic credit scoring (Art. 35)
  • Designate DPO where appropriate (Art. 37)
  • Implement security measures (Art. 32): encryption, access control
  • Establish 72-hour breach notification procedure (Art. 33)
  • Verify international transfers (Arts. 44-49) and TIA
  • Comply with LOPDGDD Art. 20 (solvency files)
  • Conduct periodic compliance audits

Official sources

  • Regulation (EU) 2016/679 (GDPR): EUR-Lex
  • LOPDGDD (Organic Law 3/2018): BOE
  • Schufa judgment (C-634/21): EUR-Lex
  • AEPD — Report on credit information systems: AEPD
  • AEPD — GDPR compliance for AI processing: AEPD
  • EDPB — Guidelines on automated decisions: EDPB

This page is general information, not legal advice. Each data processing operation must be analysed individually. Fines cited are based on public AEPD decisions.

Featured Services

Frequently Asked Questions

Is credit scoring an automated decision under Art. 22 GDPR?

Yes. The CJEU confirmed in the Schufa case (C-634/21, 7 December 2023) that credit scoring constitutes an automated decision under Art. 22 GDPR. This means data subjects have the right not to be subject to a decision based solely on automated processing that produces legal effects or significantly affects them, unless an exception applies: necessary for a contract, legal authorisation, or explicit consent, with additional safeguards.

Which Art. 6 legal basis applies to credit scoring?

Common bases are: legitimate interest (Art. 6(1)(f)) for credit risk assessment; contract (Art. 6(1)(b)) when scoring is necessary to execute a loan contract; legal obligation (Art. 6(1)(c)) for anti-money laundering. The choice depends on the context. The AEPD has published a legal report on credit information systems clarifying the use of Art. 6(1)(f).

What does LOPDGDD Art. 20 say about credit solvency?

LOPDGDD Art. 20 regulates solvency and credit files. It establishes: (1) data must be accurate and up to date; (2) negative data may be retained for 6 years; (3) the data subject has the right of access to their solvency data; (4) solvency data may only be processed for credit assessment purposes. The AEPD supervises compliance with this article.

When is the DPIA mandatory in fintech?

The DPIA (Art. 35 GDPR) is mandatory for high-risk processing, including: systematic and extensive evaluation of personal aspects (credit scoring), large-scale processing of special categories of data, and systematic large-scale monitoring. In fintech, systematic and extensive credit scoring requires a DPIA. It must document the risk analysis, mitigation measures and residual assessment.

What fines has the AEPD imposed in the financial sector?

The AEPD has imposed significant fines in the financial sector: CaixaBank, €6,000,000 (2021) for breach of Arts. 6, 13 and 14 GDPR in data processing for profiling; BBVA, €5,000,000 (2020) for breach of Arts. 6 and 13 GDPR. These fines illustrate the AEPD's active supervision in the sector and the importance of compliance with legal bases and transparency.

Are financial data special categories under Art. 9 GDPR?

Not per se. Financial data (income, expenses, balance, credit history) are not special categories under Art. 9 GDPR. However, they may become special categories if used as a proxy for sensitive data: if financial data reveal information about health, biometrics, religion, ethnicity or other special data, Art. 9 applies and a specific legal basis is required (explicit consent, etc.).

How are international transfers made in fintech?

If your fintech uses cloud providers outside the EEA (AWS, GCP, Azure), it must comply with international transfer rules (Arts. 44-49): adequacy decision (EU-US Framework 2023), Standard Contractual Clauses (SCCs 2021), Binding Corporate Rules (BCRs), or codes of conduct/certifications. In addition, a Transfer Impact Assessment (TIA) must be carried out to verify that the country offers an essentially equivalent level of protection (EDPB Recommendations 01/2020).

Which authority supervises the GDPR in fintech in Spain?

The AEPD (Spanish Data Protection Agency) is the competent supervisory authority in Spain. At European level, the EDPB (European Data Protection Board) coordinates enforcement between Member States through the one-stop-shop mechanism (Art. 56). The AEPD has published a legal report on credit information systems and guidance on GDPR compliance for AI processing.

Contact

If you want to talk about intellectual property protection, AI and data regulation, startup formation or international expansion, write us a few lines and schedule a conversation with the team.

A2 Estudio Legal
María de Molina, 41
28006 Madrid · Spain

Tel: +34 913 451 406
Email: info@a2estudiolegal.com

Tell us briefly about your project, development stage and target countries. We will respond with the next steps to start working together.

Let's talk
Contact us