GDPR and the CCD2 Directive: Data Protection in Consumer Creditworthiness Assessment

Post navigation

Last updated: 28.08.2026

GDPR and CCD2 Directive: Data Protection in Consumer Creditworthiness Assessment

Directive (EU) 2023/2225 (CCD2), the new EU Consumer Credit Directive, will apply from 20 November 2026. It is the first act of EU financial market law to write data protection rules directly into the credit process within the consumer credit market: it determines which categories of personal data must not be used in the creditworthiness assessment, which sources are excluded, and what a consumer may demand when a credit decision has been generated by an algorithm.

For creditors, credit intermediaries, buy-now-pay-later (BNPL) providers and providers of crowdfunding credit services, CCD2 is not merely a consumer protection and conduct-of-business project, but a data protection project as well.

This guide forms part of our GDPR in FinTech series and covers the interface of CCD2, the GDPR, the AI Act and the case law of the Court of Justice. It is addressed to management boards and to the legal and compliance teams of entities granting consumer credit.

From this article you will learn:

  • which data must not be used in the creditworthiness assessment;
  • what changes for automated decisions;
  • how to prepare your documentation before 20 November 2026.

The topic matters also because the Polish implementing act has not yet been adopted, while the obligations arising from the GDPR and from the Court’s case law apply regardless of the state of the national legislative process. Consulting a lawyer is advisable in particular before deploying a scoring model and when a consumer challenges a credit refusal.


Key Information on CCD2 and Consumer Credit

Issue Key point
Who is affected Creditors (banks, non-bank lending institutions), credit intermediaries, BNPL providers, providers of crowdfunding credit services, and the technology vendors building or operating scoring models for them
Key regulations CCD2 (Directive (EU) 2023/2225) read together with the GDPR, the AI Act, the Mortgage Credit Directive, the EBA Guidelines on loan origination and monitoring (EBA/GL/2020/06) and national AML legislation
Key dates Entry into force 19 November 2023; transposition deadline 20 November 2025; application from 20 November 2026. Some Member States, including Poland, remain in default
Highest-risk areas Excluded data categories and sources, automated decisions and the right to an explanation, entries in credit databases and their accuracy, retention of assessment documentation, training models on customer data
Supervision Triple supervision: financial supervision (KNF), data protection supervision (UODO) and the President of UOKiK, active for years in consumer credit matters; plus civil disputes and, increasingly, group actions

How the Consumer Credit Directive Changes Data Protection in Creditworthiness Assessment

Article 18(1) CCD2 requires a thorough assessment of the consumer’s creditworthiness, carried out in the consumer’s interest and in order to prevent irresponsible lending and over-indebtedness.

Article 18(3) then settles the data question. The assessment is to be based on relevant and accurate information on the consumer’s income and expenses and other financial and economic circumstances, necessary and proportionate to the nature, duration, value and risks of the credit.

That information may include:

  • evidence of income or other sources of repayment;
  • data on financial assets and liabilities;
  • information on other commitments.

It is subject to appropriate verification, where necessary by reference to independently verifiable documentation.

This graphic contrasts permitted credit assessment practices, such as using verified financial data proportionate to the specific loan, against strictly prohibited ones. Excluded practices include the use of sensitive health data (even with consent), social media information, and applying a single universal data template for all products.

Two exclusions follow from the provision, both imposing stricter requirements than the GDPR standard.

First, the information used does not include the special categories of data referred to in Article 9(1) GDPR, such as health data, genetic and biometric data, or information on political opinions, religious beliefs or sexual orientation.

This is an unconditional exclusion. Unlike the GDPR, which permits the processing of special category data where one of the conditions of Article 9(2) is met, CCD2 provides for no exception. The consumer’s explicit consent does not legalise such processing. Recital 55 expressly cites health data, including oncological data, as an example.

Second, social networks are not to be regarded as an external source within the meaning of the Directive.

The way Article 18(3) is constructed has practical consequences. It is an exclusion based on the criterion of the source, not on the type of data. This raises a practical question: what if the same signals reach the creditor indirectly, through a data broker, an alternative data provider or a device intelligence vendor?

A literal reading would leave that route open. We advise against relying on it.

The purpose identified in the Directive’s recitals concerns the impossibility of verifying such information and the fact that it often stands in for characteristics unrelated to the ability to repay. That purpose does not change with the channel of acquisition.

Independently of CCD2, such a practice would also be caught by the principles of fairness, accuracy and data minimisation under Article 5(1)(a), (c) and (d) GDPR.

A third, systemic observation is that Article 18(3) is in essence a sectoral restatement of the minimisation principle. Necessity and proportionality are assessed against the nature, duration, value and risk of the specific credit.

A PLN 500 loan and an unsecured EUR 90,000 credit cannot lawfully be assessed on the same data set.

A creditor applying a single maximum data template across its whole product range will struggle to defend that practice before any of the supervisory authorities.

In practice, this means preparing separate, narrower data scopes for individual products:

  • for a short-term loan, confirmation of income and a basic history of liabilities will usually suffice;
  • for a high-value credit, it is justified to draw on the full picture of assets, expenses and existing commitments.

Legal Basis for Consumer Credit Data Processing in Poland: From Legitimate Interests to Legal Obligation

Under CCD1, many creditors documented the creditworthiness assessment as necessary for the performance of a contract or as resting on legitimate interests.

CCD2 changes that analysis, because the assessment becomes a mandatory statutory step. The natural basis for the core of the assessment therefore becomes compliance with a legal obligation under Article 6(1)(c) GDPR.

That conclusion carries a condition that is easy to overlook.

Article 6(3) GDPR requires the legal obligation to be laid down in Union law or in the law of the Member State to which the controller is subject. CCD2 is a directive, not a regulation, so the obligation crystallises only upon transposition.

Where transposition is delayed, the legal basis on which the creditor would wish to rely does not yet exist.

In Poland the implementing act has not yet been adopted, and we estimate its entry into force at fourth quarter of 2026. Creditors operating in such markets should maintain and document their existing legal bases until the national act enters into force and should not rebuild the record of processing activities in advance.

Everything beyond the statutory core of the assessment requires a separate legal basis, determined individually for each processing purpose.

This applies, in particular, to:

  • fraud detection;
  • portfolio monitoring;
  • model development and validation;
  • marketing.

These are distinct purposes, usually resting on legitimate interests and therefore requiring a documented balancing test.

The EDPB Guidelines 1/2024 on Article 6(1)(f) and the CJEU’s judgment in Case C-621/22 Koninklijke Nederlandse Lawn Tennisbond confirm the direction of travel: a commercial interest can be legitimate, but three conditions must be satisfied cumulatively and demonstrated:

  1. the existence of a legitimate interest;
  2. the necessity of the processing for its pursuit;
  3. the precedence of that interest over the interests and rights of the data subject.

Generalities will not do.

If customer data are used to train or recalibrate a scoring model, that is a further purpose, requiring a compatibility test under Article 6(4) GDPR and appropriate safeguards where the processing is genuinely statistical in nature.


Automated Credit Decisions under the EU Consumer Credit Directive and GDPR

The Court of Justice remodelled this area even before CCD2’s transposition.

In its judgment of 7 December 2023 in Case C-634/21 SCHUFA Holding (Scoring), the Court held that the automated establishment of a probability value concerning a person’s ability to meet payment commitments can itself constitute an automated decision within the meaning of Article 22(1) GDPR, where a third party relies on that value to a significant degree in deciding whether to establish, perform or terminate a contractual relationship.

The compliance burden therefore does not rest on the creditor alone. The credit reference agency or scoring vendor may itself be a controller bound by Article 22 GDPR.

For creditors using external scoring, this changes:

  • contract negotiations;
  • the allocation of responsibility;
  • the map of controller roles.

In practice, the contract with a credit reference agency should state expressly:

  • who responds to a consumer’s request for an explanation of the score;
  • who documents the human review;
  • within what time the parties pass each other the information needed to reply.

Article 18(8) CCD2 adds a sectoral layer that is, in one important respect, broader than Article 22 GDPR.

Where the creditworthiness assessment involves automated processing of personal data, the consumer has the right to request and obtain human intervention on the part of the creditor, including the right to:

  • obtain a clear and comprehensible explanation of the assessment;
  • express their own point of view;
  • request a review of the assessment;
  • request a review of the decision on granting the credit.

The consumer must be informed of that right.

Article 18(9) adds the obligation to inform the consumer without delay of a refusal and, where applicable, to direct the consumer to debt advisory services.

This graphic outlines the specific rights granted to consumers when algorithms evaluate their creditworthiness under CCD2. It highlights their right to receive a clear explanation, express their views, and demand human intervention for both the assessment and the final credit decision.

Article 22 GDPR vs Article 18(8) CCD2

The key difference is:

  • Article 22 GDPR is triggered only where a decision is based solely on automated processing;
  • Article 18(8) CCD2 is triggered as soon as the assessment merely involves automated processing.

A creditor keeping a human in the loop may therefore remain outside Article 22 and yet be subject to the full CCD2 regime.

Conversely, CCD2 extends the right of review to the credit decision itself, not only to the underlying assessment. Designing the process to the GDPR standard alone will therefore leave a gap from 20 November 2026.

As to the content of the explanation, the point of reference is now the judgment of 27 February 2025 in Case C-203/22 Dun & Bradstreet Austria.

Meaningful information about the logic involved means a description of the procedure and principles actually applied, sufficient for the data subject to understand:

  • which of their data were used;
  • how those data were used;
  • how the processing affected the result.

The complexity of the model does not relieve the controller of that duty. Disclosure of the algorithm or the formula is not what the provision requires.

If the controller considers the information to be covered by a trade secret, it cannot simply refuse. It must provide the material to the competent supervisory authority or court, which will balance the competing interests in the individual case. Recital 55 CCD2 points in the same direction, referring to the main variables, the logic and the risks.

In practice, this argues for two levels of explanation:

  1. a standing description of the model’s purpose, its main families of variables and its effects, published in the privacy notice;
  2. an individual layer based on reason codes indicating which factors determined the particular result.

The human review route should be a documented procedure with a process owner, a deadline and an audit trail, not a mailbox.

Typical problems we see in practice include:

  • no designated person responsible for the process;
  • responses prepared by sales teams with no access to the model’s logic;
  • response times measured in weeks, which cannot be defended before a supervisory authority.

Credit Scoring, Proxy Variables and Discrimination under CCD2 and the AI Act in Poland

Two Finnish cases concerning the same creditor show why the selection of variables is today a legal issue, not merely a modelling one.

The Finnish equality body found that a credit refusal generated by a scoring system using gender, native language, age and place of residence, without an individual assessment of solvency, constituted prohibited discrimination.

The Finnish data protection authority then ordered the same company to correct its practices, finding that:

  • a categorical upper age limit in creditworthiness assessment is impermissible;
  • the complainant must be given information on the logic of the automated decision-making;
  • the role of that logic in the credit decision and its consequences must be explained.

We cite foreign authorities’ decisions deliberately. The GDPR is applied uniformly across the Union, and Polish authorities and courts regularly draw on the practice of other Member States, so the same arguments may surface in proceedings before UODO or the KNF.

CCD2 reinforces this direction through Article 6, which requires the non-discriminatory treatment of consumers applying for credit.

The AI Act adds a third layer: AI systems used to assess the creditworthiness of natural persons or to establish their credit score are high-risk systems.

This entails obligations relating to:

  • data governance and bias examination;
  • technical documentation;
  • event logging;
  • human oversight;
  • transparency.

Recital 56 CCD2 acknowledges that classification, and the EBA’s 2025 mapping expressly places Articles 6, 18(8) and 18(9) CCD2 alongside the AI Act requirements and the Guidelines on loan origination and monitoring.

The practical consequence is that a variable inventory and a documented proxy analysis become standard evidence rather than merely good practice.

In an inspection or a dispute, it is the creditor that will have to show it examined whether the model’s variables stand in for protected characteristics. The very absence of such an analysis can itself become a compliance issue.


Consumer Credit Databases: Data Accuracy and Credit Reporting Risks

Article 19 CCD2 governs database access and requires that creditors and providers of crowdfunding credit services have access to the relevant databases on non-discriminatory terms, including cross-border.

The data protection risk lies on the other side of that access, and that is where supervisory practice across the Union is concentrated.

The fines imposed in the Union share a common denominator: inaccurate or outdated data made their way into registers, and the persons concerned were not informed.

The Spanish data protection authority fined the credit reference agency Equifax EUR 1,000,000 and ordered the deletion of the entire database because the data gathered in it were unreliable and the persons entered had not been informed of the processing.

In another case, the same authority fined a debt purchaser EUR 200,000 for entering into a register a debt it knew had been discharged in insolvency proceedings two years earlier.

Before every entry into a credit register, verify that the debt still exists and in what amount. The reporting process must also include properly informing the consumer in advance.

The recommendation is simple: before every entry, verify that the debt still exists and in what amount, and ensure that the entry process includes properly informing the consumer.

The Court of Justice moved in the same direction in Joined Cases C-26/22 and C-64/22 SCHUFA Holding, holding that a credit reference agency may not retain data on a discharge from remaining debts for longer than the retention period of the public insolvency register.

The second area of fines is obstruction of the consumer’s access to their own data.

The Dutch data protection authority imposed a fine of EUR 830,000 on the national credit register because the register charged a fee for digital access to the data and allowed only one free paper copy per year.

Access to one’s own credit history must be free and easy.

The decision has been challenged, but the authorities’ expectation is clear: obstacles to accessing one’s own credit history are treated as a serious infringement precisely because a negative entry determines access to credit.

For creditors, the practical conclusion is that reporting to a credit register is a self-standing processing operation with a significant impact on the consumer’s situation.

The process should address:

  • the accuracy of reporting;
  • prompt correction of inaccurate data;
  • passing corrections on to the register and onward recipients;
  • retention rules aligned with the underlying obligation;
  • prior notice to the consumer before a negative entry where national law requires it.

In brief

Correct practice:

  • verify the existence and amount of the debt before entry;
  • notify the consumer in advance where required by law;
  • promptly pass corrections to the register and onward recipients;
  • provide free and easy access to the consumer’s data.

Practice risking sanction:

  • entering a non-existent or discharged debt;
  • failing to inform the consumer;
  • retaining data longer than the source register;
  • imposing fees or other barriers to accessing one’s own data.

Credit Documentation and Data Retention: CCD2 and AML Requirements in Poland

Article 18(4) CCD2 requires the creditor to establish procedures for the assessment and to document and maintain them together with the information used.

This creates an evidential retention need which must be reconciled with the storage limitation principle.

The cleanest solution is to treat the CCD2 documentation duty as a separate processing purpose, with its own retention period and its own access controls.

It should be kept apart from AML customer due diligence documentation, which in Polish law and in most Member States carries a five-year minimum counted from the end of the relationship.

Merging the two sets produces the worst outcome: excessive retention of credit data and difficulty in showing why a particular record is still being held.

The graphic explains how to navigate the conflicting data retention rules of CCD2 and Anti-Money Laundering (AML) regulations. It advises treating CCD2 documentation as a distinct processing purpose with its own retention rules to avoid the severe compliance risks associated with merging the datasets.

Our guide to personal data breach obligations describes the analogous problem of reconciling several sectoral regimes in a single internal process.

In brief

  • Creditworthiness assessment documentation – Article 18(4) CCD2: separate processing purpose, own retention period and own access controls.
  • AML customer due diligence documentation: as a rule, five years from the end of the client relationship.
  • Merging both sets in one archive: risk of excessive retention and difficulty in demonstrating why a particular record is still maintained.

How to Prepare Consumer Credit Products for CCD2 Before 20 November 2026

This graphic provides a comprehensive compliance checklist for financial institutions adapting to CCD2 and GDPR rules. It covers actionable steps such as data cleansing, updating DPIAs, revising vendor contracts, and implementing documented human review procedures.

  • Build a variable inventory for every scoring and affordability model, assigning to each variable its source, its legal basis and its proximity to a legally protected characteristic.
  • Unconditionally remove special category data from the assessment and examine alternative data sources for social network provenance.
  • Update the record of processing activities and refresh the balancing tests for fraud detection, monitoring, model development and marketing.
  • Carry out or refresh the DPIA for automated creditworthiness assessment; it is high-risk processing within the meaning of Article 35 GDPR and a high-risk AI use case.
  • Rebuild contracts with vendors and credit reference agencies in the light of the SCHUFA judgment: establish who is the controller of the scoring and on whom the Article 22 GDPR obligations rest.
  • Build a two-level explanation system and a documented human review procedure satisfying Article 18(8) CCD2, not merely Article 22 GDPR.
  • Implement refusal notifications in line with Article 18(9), including referral to debt advisory services where appropriate.
  • Review reporting to credit registers for accuracy, the passing on of corrections, and retention periods.
  • Monitor national transposition and do not change legal bases before the implementing act enters into force.

Practical Example: Legal Risks in a Consumer Credit Scoring Model

A consumer creditor entering the Polish market took over a scoring model configured by its group. The model drew on an alternative data source that included signals derived from publicly visible social media activity, applied a rigid upper age limit, and generated automatic refusals with a template message and no review route.

The legal risk was threefold: an assessment based on an excluded data source and on a rigid age criterion, an automated refusal with no possibility of human intervention, and a refusal notification devoid of any informational content.

As part of our support, the variable set was rebuilt and the social media-derived signals removed, a proxy analysis was documented, the rigid age limit was replaced with an affordability-based assessment, and reason-code explanations were added together with a logged human review route.

As a result, the risks were removed without any material loss of model performance.


How we can help

We support creditors, buy-now-pay-later (BNPL) providers and crowdfunding service providers in the following areas:

  • we carry out CCD2 readiness reviews for creditors, BNPL providers and providers of crowdfunding credit services, covering data protection alongside the conduct-of-business requirements;
  • we audit variables in scoring and affordability models and prepare a documented proxy and bias analysis;
  • we carry out DPIAs and balancing tests for automated creditworthiness assessment and fraud detection monitoring;
  • we design and defend decision-explanation and human review procedures under Article 18(8) CCD2 and Article 22 GDPR;
  • we negotiate and draft contracts with credit reference agencies, scoring vendors and alternative data providers, including allocating controller roles after the SCHUFA judgment;
  • we review reporting to credit registers and correction processes, and prepare responses to consumer complaints and authorities’ enquiries;
  • we analyse AI Act compliance gaps for high-risk creditworthiness assessment systems, consistently with the EBA Guidelines;
  • we represent clients before the KNF and UODO and in disputes over negative credit decisions.

Contact us

If you are launching or developing a consumer credit product in Poland, our team will review your creditworthiness assessment against CCD2 and the GDPR, audit the variables and sources behind your scoring model, and prepare the documentation needed before both the KNF and UODO.

We regularly support creditors from the UK, the US and the EU entering the Polish market across the full regulatory spectrum: GDPR, CCD2, PSD2/PSD3, MiCA, DORA, NIS2, the AI Act and AML.


FAQ: Consumer Credit Directive, GDPR and Automated Credit Decisions in Poland

FAQ: Consumer Credit Directive, GDPR and Automated Credit Decisions in Poland

Can a consumer consent to the use of health data in the creditworthiness assessment?

No. Article 18(3) CCD2 excludes the special categories of data under Article 9(1) GDPR from the assessment without exception. The conditions of Article 9(2) GDPR, including explicit consent, do not reopen that route for this purpose. Health data may remain relevant elsewhere, for example in the context of payment protection insurance, but not in the assessment itself.

Does a human approving the model’s result satisfy Article 18(8) CCD2?

Only where the intervention is real. The reviewer must have the competence and the information to change the outcome, and the consumer must be able to obtain an explanation, express their point of view and request a review of both the assessment and the credit decision. Clicking a confirmation on a screen showing nothing but the score is unlikely to satisfy either CCD2 or Article 22 GDPR.

We only buy a score from an agency. Are we still at risk?

Yes, and so is the agency. After the judgment in C-634/21 SCHUFA, the mere generation of a score can constitute an automated decision where the creditor relies on it to a significant degree. The creditor remains responsible for the assessment and for the CCD2 rights, and the agency may have its own obligations under Article 22 GDPR. Contracts should reflect that division rather than assume a simple processor relationship.

What applies if a Member State fails to transpose CCD2 by 20 November 2026?

The relationship between the creditor and the consumer continues to be governed by the provisions transposing CCD1, because a directive cannot of itself impose obligations on a private party. National courts are, however, obliged to interpret national law, so far as possible, in conformity with CCD2, and the Member State may incur liability in damages towards consumers for the failure to transpose. Creditors should prepare for the CCD2 standard while applying the legal framework actually in force.

When will the Polish act implementing CCD2 enter into force?

The act has not yet been adopted. On the basis of the current state of the legislative work, we estimate its entry into force at fourth quarter of 2026. Until then, the provisions transposing CCD1 apply, and the obligations arising directly from the GDPR and from the case law of the Court of Justice remain unchanged.

Expert team leader D&P Legal Jacek Szczytko
check full info of team member: Jacek Szczytko