Does your Fintech comply with the GDPR?
The GDPR (Regulation (EU) 2016/679) and the LOPDGDD (Organic Law 3/2018) regulate the processing of personal data in the fintech sector. The most critical aspects are:
Credit scoring as automated decision: The CJEU confirmed in the Schufa case (C-634/21, 7 Dec 2023) that credit scoring constitutes an automated decision under Art. 22 GDPR. This means data subjects have the right not to be subject to a decision based solely on automated processing that produces legal effects or significantly affects them, unless an exception applies (contract, legal authorisation, explicit consent).
Legal bases (Art. 6 GDPR): For credit scoring, common bases are:
- Legitimate interest (Art. 6(1)(f)) — credit risk assessment
- Contract (Art. 6(1)(b)) — necessary to execute a loan contract
- Legal obligation (Art. 6(1)(c)) — anti-money laundering
Special data (Art. 9 GDPR): Financial data are not themselves special categories, but may become so if used as a proxy for health, biometrics, religion, ethnicity or other sensitive data.
LOPDGDD Art. 20: Regulates solvency and credit files, setting requirements for the processing of solvency data: accuracy, updating, retention period (6 years for negative data) and the data subject's right of access.
DPIA (Art. 35): Systematic and extensive credit scoring requires a Data Protection Impact Assessment.
- Art. 22 analysis — We assess whether your credit scoring is an automated decision and the applicable exceptions
- Legal bases — We identify the appropriate Art. 6 basis for each financial processing operation
- Financial DPIA — We carry out the Art. 35 Impact Assessment for credit scoring
- LOPDGDD Art. 20 compliance — We verify solvency and credit files
- AEPD coordination — We act before the AEPD in inspections, requests and complaints
GDPR obligations for Fintech
GDPR obligations for a fintech include:
Legal bases and transparency:
- Identify the Art. 6 legal basis for each processing operation (legitimate interest, contract, legal obligation)
- Information to the data subject (Arts. 13-14): controller identity, purposes, legal basis, recipients, transfers, rights
- Clear and accessible privacy policy
Data subject rights:
- Access, rectification, erasure, restriction, portability, objection (Arts. 15-21)
- Right not to be subject to automated decisions (Art. 22), with additional safeguards
- Right to object to legitimate interest (Art. 21(1))
Security and breaches:
- Technical and organisational measures (Art. 32): encryption, pseudonymisation, access control
- Breach notification within 72 hours (Art. 33) if there is a risk to data subjects' rights
- Communication to affected persons (Art. 34) if there is a high risk
DPIA and DPO:
- Mandatory DPIA for systematic credit scoring (Art. 35)
- Mandatory DPO if core activities consist of systematic and large-scale monitoring (Art. 37)
International transfers:
- If using cloud providers outside the EEA (AWS, GCP, Azure): SCCs, BCRs, adequacy decision or TIA
- Sub-processor assessment (Art. 28(2)-(4))
Fines: Up to €20 million or 4% of global turnover (upper level). The AEPD has fined CaixaBank €6M (2021) and BBVA €5M (2020).
Most relevant GDPR articles for Fintech
| Article | Topic | Application in fintech |
|---|---|---|
| Art. 6 | Legal bases | Legitimate interest, contract, legal obligation for scoring |
| Art. 9 | Special categories | If data reveal health, biometrics or other sensitive data |
| Art. 13-14 | Information to data subject | Privacy policy, scoring notice |
| Art. 22 | Automated decisions | Credit scoring (Schufa ruling C-634/21) |
| Art. 32 | Security | Encryption, access control, pseudonymisation |
| Art. 35 | DPIA | Systematic and extensive credit scoring |
| Art. 37 | DPO | Systematic and large-scale monitoring |
| Arts. 44-49 | Transfers | Cloud providers outside the EEA |
| LOPDGDD Art. 20 | Credit solvency | Solvency files: accuracy, 6 years, right of access |
Real enforcement cases in the financial sector
- CaixaBank, €6,000,000 (2021) — Breach of Arts. 6, 13 and 14 GDPR in data processing for profiling. Source: EDPB
- BBVA, €5,000,000 (2020) — Breach of Arts. 6 and 13 GDPR. Source: Enforcement Tracker
- CJEU Schufa judgment (C-634/21, 7 Dec 2023) — Credit scoring constitutes an automated decision under Art. 22 GDPR. Source: EUR-Lex
- AEPD — Legal report on credit information systems: AEPD
- AEPD — GDPR compliance for AI processing (2020): AEPD
- EDPB/WP29 — Guidelines on automated decisions (WP251rev.01): EDPB
GDPR compliance checklist for Fintech
- Identify all personal data processing operations
- Determine the Art. 6 legal basis for each processing operation
- Verify whether credit scoring is an automated decision (Art. 22)
- Identify an Art. 22 exception (contract, legal authorisation, explicit consent)
- Implement additional Art. 22 safeguards (human intervention, information)
- Draft a clear privacy policy (Arts. 13-14)
- Implement data subject rights mechanisms (Arts. 15-21)
- Carry out DPIA for systematic credit scoring (Art. 35)
- Designate DPO where appropriate (Art. 37)
- Implement security measures (Art. 32): encryption, access control
- Establish 72-hour breach notification procedure (Art. 33)
- Verify international transfers (Arts. 44-49) and TIA
- Comply with LOPDGDD Art. 20 (solvency files)
- Conduct periodic compliance audits
Official sources
- Regulation (EU) 2016/679 (GDPR): EUR-Lex
- LOPDGDD (Organic Law 3/2018): BOE
- Schufa judgment (C-634/21): EUR-Lex
- AEPD — Report on credit information systems: AEPD
- AEPD — GDPR compliance for AI processing: AEPD
- EDPB — Guidelines on automated decisions: EDPB
Related resources
- GDPR Hub — Resource centre on the GDPR
- GDPR Glossary — 45+ key terms with article references
- AI Act vs GDPR — Comparative table of both regulations
- GDPR Compliance Checker — Self-assess your compliance
- AI & Data Regulation Service — Integrated advisory
- AI Act for Fintech — Sectoral AI Act guide for fintech
- DPO as a Service — External Data Protection Officer
This page is general information, not legal advice. Each data processing operation must be analysed individually. Fines cited are based on public AEPD decisions.