The CNIL has published a new recommendation on the use of personal data in the assessment of the creditworthiness of credit applicants. The document, adopted following a public consultation launched in May 2025, aims to provide financial operators with an updated framework for complying with the GDPR and French national data protection law, the Loi Informatique et Libertés, in the context of processing activities related to the granting of credit (octroi de crédit).
The recommendation focuses in particular on processing operations carried out to assess the applicant’s ability to meet their obligations and repay the loan. The CNIL recalls the need to limit the data processed to what is relevant and strictly necessary, including where previous contractual defaults or information from internal and external sources are taken into account.
Particular attention is paid to scoring tools, which are often partially or fully automated and, in some cases, based on artificial intelligence systems. In light of the case law of the Court of Justice of the European Union, in particular in Cases C-634/21 and C-203/22, the CNIL emphasises that scoring may amount to automated decision-making where it plays a decisive role in the granting of credit, thereby requiring data subjects to be provided with clear and intelligible information on the functioning of the decision-making mechanism.
The recommendation therefore strengthens the obligations of transparency, accountability and human oversight, while also recalling the need to assess whether a DPIA should be carried out, to correctly identify the applicable legal bases for processing, to limit retention periods and to ensure appropriate security measures. The CNIL has also published an operational checklist to help operators verify the compliance of their creditworthiness assessment processes.
The publication is significant beyond the French market, as it provides guidance that is relevant across the EU in light of the GDPR and confirms the growing attention of European supervisory authorities to the use of algorithms, scoring and automated systems in financial services, particularly where such tools affect access to credit and the rights of data subjects.