195 incidents on record · 2026 Headlights Incident reports by Ellie Harris · Melbourne
11 new this week Library last updated 12 September 2026
← The incident library
HD-INC-184
Credit reference · Austria · 2025 · An automated assessment that determined an outcome for a person, with no explanation of the logic the person could understand

EU court rules automated credit decisions must be explained in a way people can understand

By Ellie Harris · Filed Refusal of the contract and the request for information preceded the reference; the Federal Administrative Court decision is dated 23 October 2019 and the reference was received by the Court on 16 March 2022

Alleged: Dun & Bradstreet Austria GmbH developed or deployed the AI system implicated in this incident. Details are drawn from public reports; parties are presumed innocent of any wrongdoing not established by an official finding.

EU court rules automated credit decisions must be explained in a way people can understand

What happened

The judgment records that a woman in Austria was refused the conclusion or extension of a mobile telephone contract requiring a monthly payment of 10 euros. An automated assessment of her creditworthiness had found her financial standing insufficient.

The judgment records that she sought meaningful information about the logic involved in the profiling of her personal data, under Article 15(1)(h) of the GDPR in the context of automated decision-making including profiling within Article 22(1). The agency argued that, because of a protected trade secret, it did not have to provide information beyond what it had already supplied.

The Austrian data protection authority ordered it to provide meaningful information about the logic involved. On 23 October 2019 the Federal Administrative Court found the agency had infringed Article 15(1)(h) by failing to provide that information, or at least sufficient reasons why it could not.

The judgment records that no further information followed. Her enforcement application to the City Council of Vienna, as the enforcing authority, was rejected on the basis that the agency was considered to have met its disclosure obligation.

The Administrative Court in Vienna referred the question of what the provision actually requires. The Court of Justice of the European Union gave judgment on 27 February 2025 in Case C-203/22.

What an auditable version would have shown

It was reported that the Court found that giving someone an algorithm or a complicated mathematical formula would not, by itself, provide the meaningful explanation required under the GDPR.

The person affected needs to be given information that allows them to understand how their personal data was used and how the automated assessment reached its result. That information also needs to be clear enough for them to understand and challenge the decision if they believe it is wrong.

The Court did not prescribe a particular record or tell organisations exactly what information they must store. It did, however, find that the explanation must relate to the procedure and principles actually applied to the person’s data in reaching the specific result.

For an organisation using automated decision-making, keeping a clear record of that process would make it possible to provide that explanation later without having to reconstruct the decision from incomplete information.

Where the gap was

The Court also addressed the trade secret point. Where the controller says the information contains a trade secret or another person’s data, it must provide that information to the competent supervisory authority or court, which weighs the rights and interests at issue and determines the scope of access. Paragraph 4(6) of the Austrian Data Protection Act excluded the right of access as a rule where disclosure could compromise a business or trade secret, with no case by case balancing, and the Court held that incompatible with the GDPR.

A ConductRecord keeps the inputs used about a person, the steps applied and the result, so that an explanation can be produced from the record rather than reconstructed later. A ConstraintGate is designed to check a standing rule before an automated result is relied on.

These are Headlights designs. Neither decides whether a person is creditworthy.

What governance should have looked like

It was reported that the Court did not require companies to publish their algorithms or disclose trade secrets directly to the person affected. It found that trade secrecy could not simply be used to prevent access to information about an automated decision.

Where information is genuinely commercially sensitive, it can be provided to the relevant regulator or court so that the competing rights can be considered.

Good governance would therefore start before the automated system is used. An organisation should keep enough information about each decision to explain what personal data was used, how it was used and how the system arrived at its result. If someone later challenges the decision, there should already be a clear record to work from.

Failure Pattern: It was reported that a woman was unable to obtain a meaningful explanation of an automated credit assessment that resulted in her being refused a mobile phone contract, with the credit agency relying on trade secrecy when further information was sought.

Governance Principle: Organisations using automated systems to make decisions about people should keep enough information to explain how an individual decision was reached in terms the person can understand and challenge.

The reference implementation of ConstraintGate and ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed and free to install. The repository is public now.

Sources

The mailing list

Fresh incident reports every week. One email to match.

We add new incidents to the library regularly, and send a single short email each week with what's new. The library stays free and open; this is just how you keep up with it.

No tracking. Unsubscribe in one click.

The record

An auditable system would have produced a signed, tamper-evident record the moment this happened: what the system did, the version that did it, the basis it acted on, and the action taken, and Dun & Bradstreet Austria GmbH could have produced it on demand.

This is the record the system as deployed did not produce in a signed, auditable form.

What this teaches
Capture what happened when it happens
What the system did, the version that did it, the basis it acted on, and the action taken, recorded at the moment, not reconstructed after.
Sign it, so no one has to trust the record-keeper
A tamper-evident entry. Edit it later and the signature breaks. The record does not ask for the benefit of the doubt.
Make it verifiable by anyone
A court, a regulator, a customer's lawyer can check the record themselves, without taking the company, or us, at our word.

Headlights summarises publicly reported AI incidents. All summaries are independently written, attributed to their original sources, and intended for research and educational purposes. Allegations are identified as such until established through official findings.

Last reviewed September 2026. This report is based on the sources listed above and reflects information available at the time of review; later developments may not be captured. Where a person is described as charged with or alleged to have done something, that allegation is unproven unless a conviction or a court or regulatory finding is stated. Headlights publishes journalism and commentary, not legal advice.

Want to write back?

Direct to my inbox.

ellie@useheadlights.com →