Data Protection HubCase Law

CJEU, judgment of 7 December 2023, C-634/21, SCHUFA Holding (Scoring)

Automated decisions and profiling under Article 22 GDPR; limits of Member State implementation under Article 22(2)(b) GDPR; the balancing of interests must not be pre-empted.

1 Overview

A consumer had a credit application refused on the basis of a SCHUFA score. Relying on Article 15 GDPR, he sought information about the logic involved in the procedure and the erasure of the data. The German Administrative Court of Wiesbaden (VG Wiesbaden) referred questions to the CJEU on the interpretation of Article 22 GDPR, in particular whether the establishment of the score by the credit information agency constitutes an automated decision.

2 Headnotes

The establishment by a credit information agency of an automated probability value concerning a person's ability to service a loan constitutes an "automated individual decision" within the meaning of Article 22(1) GDPR where the subsequent conduct of a third party (here, the bank) depends decisively on that value (paras. 48 et seq.).

Article 22(1) GDPR lays down a prohibition in principle; the data subject may invoke the unlawfulness of the processing without having to rely on a specific exception (para. 52).

Member States may, it is true, adopt special rules under Article 22(2)(b) GDPR. In doing so, however, they may not definitively pre-empt the outcome of the balancing of interests under Article 6(1)(f) GDPR (para. 70).

3 Significance

The decision shows the limits of relying on Article 6(1)(f) GDPR in the field of automated decisions. Article 6(1)(f) is not a "law" within the meaning of Article 22(2)(b) GDPR and therefore does not authorize automated individual decision-making. By contrast, processing that takes the form of profiling but does not lead to an automated decision within the meaning of Article 22 GDPR can in principle be assessed under point (f).

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn