In short
Twenty-four months: past payment incidents should not be used beyond that. Six months: how long the data of a non-client who was refused may be kept. The score can be requested through access, together with what makes it understandable. Trade secrecy may limit the answer, not turn it into a blanket refusal.
There is no right to credit, there is a duty to explain
The CNIL starts where a lawyer would: freedom of contract under article 1101 of the civil code. Nobody is obliged to grant a loan. But before granting it there is an obligation to assess creditworthiness, and that assessment processes personal data.
Lenders may use artificial intelligence or statistical models. The CNIL writes that those tools «are subject to the GDPR: they must be transparent, limit bias and not lead to discrimination», and that in every case the institution remains responsible for the decision and must be able to explain the main criteria used and the consequences of the process for the person's situation.
The three numbers
- Twenty-four months: the CNIL recommends not using past payment incidents beyond that period, save particular circumstances.
- Six months: a non-client who is refused may have the application data kept for six months, to handle a later application faster.
- Beyond that, only for litigation: for the applicable limitation period, until proceedings end, and under strict confidentiality.
On incidents the CNIL adds two conditions that are easily forgotten. Only those meeting objective criteria, defined in advance, may be used. And the context must be taken into account: whether they were disputed, whether they were settled, whether a court ruled. An incident set aside by a final decision can no longer enter the assessment.
The score is requested under Article 15
The data subject may ask to know their score, and the information must come with what makes it understandable — for example the minimum and maximum marks required to obtain the credit. The CNIL is explicit: it cannot be a repetition of what was already communicated before the assessment; it must be precise and personalised.
The right of access is not absolute and trade secrecy may stand against part of the answer. But «that refusal must not be global and absolute»: the institution must endeavour to grant the request and respond as far as possible, providing as many elements as it can.
What to look at in a client who scores
The cut-off used to discard past incidents, and whether it is written down anywhere. The advance list of incident types that may be used: if it does not exist, the objective criteria do not either. The procedure for answering a request for access to the score, and who decides what trade secrecy covers. And the credits that are not called credits — instalments, deferred payment, store cards with a revolving line, overdrafts: these are credit and can trigger the assessment.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free