What happened
The judgment records that a woman in Austria was refused the conclusion or extension of a mobile telephone contract requiring a monthly payment of 10 euros. An automated assessment of her creditworthiness had found her financial standing insufficient.
The judgment records that she sought meaningful information about the logic involved in the profiling of her personal data, under Article 15(1)(h) of the GDPR in the context of automated decision-making including profiling within Article 22(1). The agency argued that, because of a protected trade secret, it did not have to provide information beyond what it had already supplied.
The Austrian data protection authority ordered it to provide meaningful information about the logic involved. On 23 October 2019 the Federal Administrative Court found the agency had infringed Article 15(1)(h) by failing to provide that information, or at least sufficient reasons why it could not.
The judgment records that no further information followed. Her enforcement application to the City Council of Vienna, as the enforcing authority, was rejected on the basis that the agency was considered to have met its disclosure obligation.
The Administrative Court in Vienna referred the question of what the provision actually requires. The Court of Justice of the European Union gave judgment on 27 February 2025 in Case C-203/22.
What an auditable version would have shown
It was reported that the Court found that giving someone an algorithm or a complicated mathematical formula would not, by itself, provide the meaningful explanation required under the GDPR.
The person affected needs to be given information that allows them to understand how their personal data was used and how the automated assessment reached its result. That information also needs to be clear enough for them to understand and challenge the decision if they believe it is wrong.
The Court did not prescribe a particular record or tell organisations exactly what information they must store. It did, however, find that the explanation must relate to the procedure and principles actually applied to the person’s data in reaching the specific result.
For an organisation using automated decision-making, keeping a clear record of that process would make it possible to provide that explanation later without having to reconstruct the decision from incomplete information.
Where the gap was
The Court also addressed the trade secret point. Where the controller says the information contains a trade secret or another person’s data, it must provide that information to the competent supervisory authority or court, which weighs the rights and interests at issue and determines the scope of access. Paragraph 4(6) of the Austrian Data Protection Act excluded the right of access as a rule where disclosure could compromise a business or trade secret, with no case by case balancing, and the Court held that incompatible with the GDPR.
A ConductRecord keeps the inputs used about a person, the steps applied and the result, so that an explanation can be produced from the record rather than reconstructed later. A ConstraintGate is designed to check a standing rule before an automated result is relied on.
These are Headlights designs. Neither decides whether a person is creditworthy.
What governance should have looked like
It was reported that the Court did not require companies to publish their algorithms or disclose trade secrets directly to the person affected. It found that trade secrecy could not simply be used to prevent access to information about an automated decision.
Where information is genuinely commercially sensitive, it can be provided to the relevant regulator or court so that the competing rights can be considered.
Good governance would therefore start before the automated system is used. An organisation should keep enough information about each decision to explain what personal data was used, how it was used and how the system arrived at its result. If someone later challenges the decision, there should already be a clear record to work from.
Failure Pattern: It was reported that a woman was unable to obtain a meaningful explanation of an automated credit assessment that resulted in her being refused a mobile phone contract, with the credit agency relying on trade secrecy when further information was sought.
Governance Principle: Organisations using automated systems to make decisions about people should keep enough information to explain how an individual decision was reached in terms the person can understand and challenge.
The reference implementation of ConstraintGate and ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed and free to install. The repository is public now.
Sources
- Case C-203/22, Dun & Bradstreet Austria, judgment of 27 February 2025, ECLI:EU:C:2025:117 (Court of Justice of the European Union, via EUR-Lex)
- Full text of the judgment, including the operative part and the paragraphs on trade secrets (dpcuria)