Law / Germany

GDPR Article 22 and BDSG Sections 31 and 37, Automated Decisions and Credit Scoring in Germany

Regulation (EU) 2016/679, Art. 22; Bundesdatenschutzgesetz (BDSG) §§31, 37

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018.

A data subject rights rule binding public and private bodies.

As of 24 August 2026.

What it requires

  • Honor a person's request to access, rectify, erase, restrict, port, or object to processing of their personal data within one month of receipt, as required by General Data Protection Regulation (GDPR) Articles 12 to 23.
  • Provide a meaningful human review before finalizing any decision based solely on automated processing that produces legal or similarly significant effects for a person in Germany, including a credit score generated for a third party's determinative use, under GDPR Article 22 and BDSG Section 31.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

General Data Protection Regulation (GDPR) Articles 12 to 23 apply, including Article 22 rights against solely automated decision-making. BDSG Section 31 supplements this for credit-reporting and scoring agencies specifically.

The CJEU's SCHUFA ruling, Case C-634/21 (OQ v Land Hessen, judgment 7 December 2023), held that automated credit-score generation used determinatively by a third party such as a bank constitutes a decision based solely on automated processing within Article 22(1), which cast doubt on BDSG Section 31's compatibility with the narrow exceptions in Article 22(2)(b). No subsequent German court ruling resolving the Wiesbaden Administrative Court's remand from that reference is identified.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions

Read the law

Official Journal text, EUR-Lex, Regulation (EU) 2016/679
BDSG §§31, 37; CJEU C-634/21

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app