AI-based credit scoring at the intersection of GDPR and AI Act: lessons from the SCHUFA judgment
摘要
This paper examines the implications of the Court of Justice of the European Union’s SCHUFA judgment for the lawfulness of AI-based credit scoring under the GDPR and explores its interaction with the EU AI Act. It analyses how the Court’s broad interpretation of Art. 22 GDPR extends the scope of automated individual decision-making to credit scoring and shifts responsibility toward credit reference agencies as the decision-maker. Additionally, the paper discusses AI-based credit scoring as a high-risk AI system under the AI Act, outlining the resulting dual compliance requirements, role distribution and the challenges at the intersection of the GDPR and the AI Act.