Data Protection HubCase Law

CJEU, judgment of 27 February 2025, C-203/22, Dun & Bradstreet Austria

Scope of the right of access to the logic involved in an automated decision under Article 15(1)(h) GDPR; explanation of the procedure and principles instead of disclosure of the algorithm; in camera proceedings where trade secrets stand in the way.

1. Overview

A customer was refused the conclusion of a mobile phone contract because an automated creditworthiness assessment carried out by the company Dun & Bradstreet Austria produced a negative result. The customer requested information about the logic of the automated decision. The referring court asked the CJEU how far the right of access under Article 15(1)(h) GDPR extends where a person is subject to automated decision-making, including profiling.

2. Headnotes

The controller must explain the procedure and the principles applied in such a way that the data subject is able to understand which of his or her personal data were used, and in what manner, in the automated decision-making (para. 66).

Neither the mere communication of complex mathematical formulas nor a full description of every step of the procedure is sufficient. What is required is an intelligible explanation geared to the individual case that enables the data subject to verify whether the data used are accurate and were processed lawfully.

Where trade secrets or the rights of third parties stand in the way of the information being provided, the controller is not entirely released from the obligation. It must transmit the protected information to the competent supervisory authority or the competent court, which will weigh the competing interests against each other and determine the scope of the right of access (para. 76).

3. Significance

The decision gives concrete shape to the rights to information and of access in the case of automated individual decision-making. It resolves the tension between the right to meaningful information and the protection of trade secrets, in principle, in favor of data protection, without establishing a general obligation to disclose the algorithm. The full text is available via InfoCuria.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn