Personal data and credit agencies (§ 28a BDSG)

Last updated:
29.06.2020
Credit agencies are privately organized companies that collect information on the creditworthiness, solvency, and economic activities of individuals and businesses. This information is stored and shared upon request with other companies looking to assess potential financial risks in business transactions.
Personal data and credit agencies (§ 28a BDSG)
Key Takeaways
  • Credit agencies collect and share information regarding creditworthiness and solvency.
  • Section 28a of the former Federal Data Protection Act (BDSG-alt) governs the transmission of data to credit agencies under specific conditions.
  • Key requirements: due date, payment reminder, court judgment, or express acknowledgment of debt.
  • Changes to transmitted data must be reported within one month.
  • The GDPR and the new Federal Data Protection Act (BDSG-neu) establish general legal bases for data transmission, with a focus on legitimate interests.

Credit agencies are privately organized companies that collect information on the creditworthiness, solvency, and economic activities of individuals and businesses. This information is stored and, upon request, shared with other companies that need to assess financial risks in business transactions. Common names in this context include SCHUFA, Bürgel, Creditreform, and others. Under current legislation, Section 28a of the former Federal Data Protection Act (BDSG-alt) provides the legal framework for data transmission by these agencies. This balances the data protection rights of the individuals concerned with the information and disclosure interests of other market participants. The EU General Data Protection Regulation (GDPR) addresses these areas in a more general manner than the highly specific provisions of Section 28a BDSG-alt.

Data transmission under Section 28a BDSG-alt

Section 28a BDSG-alt makes the transmission of data to credit agencies subject to various conditions. In this context, the transmission of personal data is only permitted if the owed service has not been rendered despite being due, the transmission is necessary to protect the legitimate interests of the requesting party, and

  • there is a final judgment or a judgment declared provisionally enforceable regarding the claim, or an enforcement order pursuant to Section 794 of the German Code of Civil Procedure (ZPO).

or

  • the claim has been established in accordance with Section 178 of the Insolvency Code (InSO) and was not contested by the debtor during the verification hearing.

or

  • the individual concerned has expressly acknowledged the claim.

or

  • in the case of overdue claims, at least two written reminders have been sent after the due date, a period of four weeks has elapsed between the first reminder and the data transmission, the individual concerned was informed of the potential data transmission at the time of the first reminder, and the individual concerned has not contested the claim.

or

  • for contracts that can be terminated without notice due to payment arrears, provided the affected party has been informed of the impending transmission in advance.

Under Section 28a (2) of the former Federal Data Protection Act (BDSG-alt), credit institutions are permitted to transmit personal data to credit agencies for the purpose of establishing, properly executing, or terminating a contractual relationship involving banking transactions. This right to transmit data does not apply if the affected party's interest in excluding the transmission clearly outweighs the credit agency's interest in obtaining the information. The affected party must be informed of the transmission before a contract is concluded.

It is important to note that any subsequent changes to data transmitted under Section 28a BDSG-alt must be reported by the responsible entity to the relevant credit agency within one month of becoming aware of them. This applies as long as the originally transmitted data remains stored by the credit agency. Conversely, the credit agency must notify the responsible entity when the originally transmitted data is deleted.

Section 28a BDSG-alt is supplemented by the subsequent Sections 28b and 29 BDSG-alt. These two provisions specifically address data transmission within the banking sector and the practice of credit scoring.

Changes to the legal framework for credit agencies under the GDPR/new BDSG

The EU General Data Protection Regulation (GDPR), in conjunction with the new BDSG, also makes the transmission of data to credit agencies subject to a legal basis for processing. However, credit agencies are no longer treated under specific rules; instead, they are subject to the general legal bases for processing under the GDPR, specifically Article 6(1)(a), (b), and (f). In addition to consent and data transmission within the scope of pre-contractual relationships, the balancing of legitimate interests against the interests of the affected party continues to play a key role.

Data transmission to credit agencies – a complex legal situation

The transmission of personal data to credit agencies has frequently led to legal disputes in the past, as the storage and sharing of such data can have significant financial consequences for the individuals involved. The full scope of the regulations under Section 28a BDSG-alt is not always fully understood by all companies. With the introduction of the EU GDPR, ensuring legal compliance as a company will not become any easier.

For this reason, let the team at Proliance provide you with expert support regarding the transmission of personal data to credit agencies. Among other services, Proliance provides external data protection officers to assist you in developing appropriate concepts for data transmission. We are also available to provide further consulting and support services. We would be happy to provide you with more information.

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in