All news
Regulation August 19, 2026 6 min

The score they refuse your credit with can be requested, and it has to be explained

The CNIL sets out what a lender must be able to tell someone it turns down: the main criteria, the consequences, and the score together with the values that make it intelligible. Trade secrecy limits the answer, it does not cancel it

In short

Twenty-four months: past payment incidents should not be used beyond that. Six months: how long the data of a non-client who was refused may be kept. The score can be requested through access, together with what makes it understandable. Trade secrecy may limit the answer, not turn it into a blanket refusal.

There is no right to credit, there is a duty to explain

The CNIL starts where a lawyer would: freedom of contract under article 1101 of the civil code. Nobody is obliged to grant a loan. But before granting it there is an obligation to assess creditworthiness, and that assessment processes personal data.

Lenders may use artificial intelligence or statistical models. The CNIL writes that those tools «are subject to the GDPR: they must be transparent, limit bias and not lead to discrimination», and that in every case the institution remains responsible for the decision and must be able to explain the main criteria used and the consequences of the process for the person's situation.

The three numbers

  • Twenty-four months: the CNIL recommends not using past payment incidents beyond that period, save particular circumstances.
  • Six months: a non-client who is refused may have the application data kept for six months, to handle a later application faster.
  • Beyond that, only for litigation: for the applicable limitation period, until proceedings end, and under strict confidentiality.

On incidents the CNIL adds two conditions that are easily forgotten. Only those meeting objective criteria, defined in advance, may be used. And the context must be taken into account: whether they were disputed, whether they were settled, whether a court ruled. An incident set aside by a final decision can no longer enter the assessment.

The score is requested under Article 15

The data subject may ask to know their score, and the information must come with what makes it understandable — for example the minimum and maximum marks required to obtain the credit. The CNIL is explicit: it cannot be a repetition of what was already communicated before the assessment; it must be precise and personalised.

The right of access is not absolute and trade secrecy may stand against part of the answer. But «that refusal must not be global and absolute»: the institution must endeavour to grant the request and respond as far as possible, providing as many elements as it can.

What to look at in a client who scores

The cut-off used to discard past incidents, and whether it is written down anywhere. The advance list of incident types that may be used: if it does not exist, the objective criteria do not either. The procedure for answering a request for access to the score, and who decides what trade secrecy covers. And the credits that are not called credits — instalments, deferred payment, store cards with a revolving line, overdrafts: these are credit and can trigger the assessment.

Official source:CNIL — Le refus de crédit en questions (19 août 2026)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Regulation
26the article nobody signs before broadcasting

Who answers for the live stream of the under-14 match? Sweden answers the question nobody asks

On 25 August the Swedish authority published guidance on streaming youth sport. Many clubs stream children's matches online, and the guidance sets out the factors that decide what is allowed. But the part worth reading is the other one: responsibility when the municipality owns the venue and the club wants to install cameras.

Aug 25, 2026New 5 min
Regulation
2EDPB criteria and the DPIA becomes mandatory

In schools, advertising trackers are prohibited — and consent has nothing to do with it

On 24 August the CNIL published its rules for the digital workspaces used in schools. The decisive point is not the protection of minors but a principle of administrative law: the neutrality of the public education service includes commercial neutrality, so trackers used for advertising or profiling are prohibited in principle. If the tool has them, the controller must switch them off.

Aug 24, 2026New 6 min
Regulation
2documents on the same subject, with one rule apart

Same tool, same day, different rule: why trackers are not banned at university

On 24 August the CNIL published two texts on the same subject, one for schools and one for universities. Anyone who reads only the first and applies it to the second gets one specific thing wrong: in schools advertising trackers are «in principle prohibited», while in higher education the CNIL «recommends preferring» tools that do not use them. Everything else — legal basis, DPIA, processor guarantees, transfers — is the same.

Aug 24, 2026New 5 min