Showing posts with label transparency. Show all posts
Showing posts with label transparency. Show all posts

Tuesday, 14 April 2026

Fairness of indexing benchmarks in variable rate loans C -471/24

In a recent judgment delivered on 12 February 2026  in C-471/24 J.J.  v PKO BP S.A., the CJEU delivered further important interpretation on matters affecting loan contracts in variable rates. 

In this Polish case the consumer concluded a mortgage loan contract with variable rate of interest, which was calculated on the basis, first, of the WIBOR 6M benchmark, an interest rate benchmark, within the meaning of Article 3(1)(22) of Regulation 2016/1011, the value of which was set at 1.79% on the date of conclusion of that agreement, and, secondly, of a fixed margin of 1.85%, the applicable rate being adjusted to reflect changes in that index on a six-monthly basis.

As the consumer alleged the unfairness of the term, this gave new opportunities to the CJEU to interpret Directive 1993/13/EC on Unfair Contract Terms.

With the first question, the CJEU was asked whether the term setting out the variable rate of interest can be assessed for its fairness under Article 1(2), given the influence of Regulation 2016/1011, which would qualify a term as one that reflects ‘mandatory statutory or regulatory provisions’.  First, the CJEU importantly noted that although Article 1(2) relates to statutory or regulatory provisions of Member States and not EU law, as stated Recital 13 of the Directive the  'the provisions contained in acts adopted by the EU legislature in the form of regulations must be treated, in that regard, in the same way as the statutory and regulatory provisions of the Member States, in view of the effects of those regulations as laid down in the second paragraph of Article 288 TFEU, where such provisions of EU law seek, in the same way, to determine in a mandatory or supplementary manner the rights and obligations of the parties to certain contracts. The rationale for the exclusion established in Article 1(2) of Directive 93/13, …is, in principle, legitimate to presume that the national legislature struck a balance between all those rights and obligations, a balance which the EU legislature intended to preserve ... also applies where those rights and obligations are determined directly by the EU legislature itself.' (paras 73 and 74).

In answering the first question, the CJEU confirmed its earlier ruling in C-176/23 (see our report here), that '[a]rticle 1(2) must be interpreted as meaning that the exception provided for therein does not cover a term in a mortgage loan agreement stipulating a variable interest rate based on a benchmark, within the meaning of Regulation 2016/1011, and a fixed margin, where the statutory or regulatory provisions applicable to such a term merely establish a general framework for the setting of the interest rate for such contracts, while leaving it open to the seller or supplier to determine the contractual benchmark or the fixed margin which may be added to the value of that index'

The second question related to whether a term in a mortgage loan agreement with a variable rate of interest based on a benchmark could be the main subject matter and, as such, exempted from the scrutiny of fairness based on Article 4(2).   According to Article 4(2) the assessment of the unfair nature of the terms may relate neither to the definition of the main subject matter of the contract nor to the adequacy of the price and remuneration, on the one hand, as against the services or goods supplied in exchange, on the other hand, in so far as those terms are in plain, intelligible language. The question, therefore, here was the interpretation of the meaning of plain and intelligible in this context; whether where a mortgage loan agreement contains a term stipulating a variable interest rate based on a benchmark, within the meaning of Regulation 2016/1011, the transparency requirement arising from that provision imposes on the creditor certain specific obligations to provide information as regards the methodology of that index. The claimant alleged that the bank did not provide reliable, intelligible and complete information concerning the risk associated with the application of a variable interest rate and the mechanism for determining the WIBOR 6M benchmark, in particular as regards the influence that the banks providing the input data which was used to set that benchmark; the banks participating in setting the benchmark, including PKO, could exert influence on the benchmark; the input data did not come from transactions actually carried out on the Polish interbank market, but of price offers made on that market, which conferred discretion on the contributors to the benchmark.

The CJEU reiterated its previous position that in this context the transparency requirement must be understood as requiring an average consumer, who is reasonably well-informed and reasonably observant and circumspect, is in a position to understand the specific functioning of the method used for calculating that rate and thus evaluate, on the basis of clear, intelligible criteria, the potentially significant economic consequences of such a term on his or her financial obligations (para 86). Moreover, compliance with the requirement of transparency must be assessed in light of all relevant facts, including not only the terms contained in the agreement concerned but also the promotional material and information provided by the lender during the negotiation  (para 87). Therefore, ‘[a]ccount should also be taken of the fact that the main elements relating to the calculation of a contractual reference index are easily accessible, on account of their publication, on condition that, in the light of the publicly available and accessible information and the information provided, as the case may be, by the lender, an average consumer, who is reasonably well informed and reasonably observant and circumspect, was in a position to understand the specific functioning of the method used for calculating the variable interest rate, in particular in so far as it involves a reference index, and thus to assess, on the basis of clear, intelligible criteria, the potentially significant economic consequences of such a term on his or her financial obligations (para. 88).

Moreover, in order to assess whether a term in a loan agreement which falls within the scope of Article 4(2) satisfies the requirement of transparency imposed by that provision, it is appropriate to take into consideration all the provisions of EU law laying down obligations relating to information for consumers which may be applicable to the agreement concerned. The CJEU then examined information duties in Directive 2014/17/EC and Regulation 2016/1011, and concluded that these read together, lay down precise obligations to provide information to consumers as regards, first the terms of mortgage loan agreements setting a variable interest rate referring to a benchmark covered by that regulation and, second, the benchmarks, and that those obligations are divided between the creditors and the administrators of those benchmarks (para 101). The CJEU concluded that ‘the transparency requirement arising from Article 4(2) does not impose on the creditor certain specific obligations to provide information as regards the methodology of that benchmark. The fact that the creditor has complied with all the obligations to provide information imposed on it by Directive 2014/17 in respect of such a term and, if it has provided additional information, has not provided any information giving a distorted picture of that benchmark is such as to establish that that creditor has satisfied that requirement of transparency as regards that term.’

The third question called for interpretation of Article 3(1) in this context, according to which a contractual term which has not been individually negotiated is to be regarded as unfair if, contrary to the requirement of good faith, it causes a significant imbalance in the parties’ rights and obligations arising under the contract, to the detriment of the consumer. The question here was whether the very way the benchmark is determined renders the term substantively unfair. The claimant argued that the way the benchmark is determined allows PKO to influence the benchmark and, in turn, the borrower's interest payable. The banks thus afford themselves a ‘hidden margin’ (para 107).

The CJEU noted that Regulation 2016/1011 contains a set of detailed provisions on benchmarks, including the provision of input data, in particular as regards the nature of those data and their reliability, and the use of those benchmarks. Consequently, ‘the use, in a mortgage loan agreement, of a benchmark which, at the time that agreement is concluded, may be regarded as complying with the requirements of the framework established by Regulation 2016/1011, in particular as regards its methodology, in the light of the control provided for by that regulation, cannot, in principle, be, in itself, such as to create, to the detriment of the consumer, a significant imbalance in the parties’ rights and obligations, notwithstanding the fact that the creditor is one of the banks which provide the input data used by the administrator of that index to determine its successive values’ (para. 129).

The answer to the third question is that Article 3(1) must be interpreted as meaning that, 'the lack of information on the part of the consumer concerning certain specific features of the contractual benchmark, in particular the fact that its methodology provides for the use of input data which does not necessarily correspond to actual transactions and the fact that the creditor is one of the banks contributing to the determination of that index' - those specific features themselves are not such as to render that term unfair, provided that that index could be regarded as consistent with that regulation at the time of the conclusion of that contract.

Wednesday, 25 February 2026

Commission opens official DSA investigation into SHEIN

 While the announced Digital Fairness Act proposal remains so far at the announcement stage, the last few months have brought to light the DSA's potential - if yet to be tested - to contribute to consumer protection beyond content moderation practices. In this sense, it particularly interesting that this month the European Commission has announced an official investigation into Shein's practices concerning several potential violations, namely:

- potential failure to limit the sale of illegal products, "including content which could constitute child sexual abuse material, such as child-like sex dolls";

- potential failure to monitor systemic risks linked to addictive design "including giving consumers points or rewards for engagement", and adequacy measures that Shein has in place in order to mitigate negative effects on "users' wellbeing and consumer protection"; and 

- potential failure to achieve sufficient transparency of the recommender systems in the platform. 

The press release does not provide a detailed legal basis for the specific elements, so we did this for you. 

First, illegal content. Under the DSA, platforms do not have to actively monitor for the presence of illegal content (article 6), but they have have several obligations that are triggered once a notice is filed (article 16 para 4,5,6), and they are assumed to be legally aware of the illegal content once a valid notice has been filed (art 16 para 3). The commission has previously asked Shein to provide information about how they manage their notice & action systems to counter illegal content and the investigation is meant to obtain further insight. 

"Maximum points on a daily basis at Shein"
"rewards for engagement" from couponfollow.com
Second, as concerns the systemic risks, the Commission's framing seems to leverage the understanding of "risk" (assessment, art 34 and mitigation, art 35) referred to in recitals 81 and 83, namely that of addictive features of a platform's design or exploitation of weaknesses, in particular when it comes to children. The gamification mechanisms mentioned in the investigation announcement may structurally encourage consumers to over-spend or just spend more time in the app that normal usage would require. 

Finally, the Commission wants to know more about how Shein informs consumers about the criteria according to which product presentation is organised and selection is ranked. According to art 27 DSA, this information can be provided in the platforms T&Cs *but* "when several options are available" users must be given the a directly and easily accessible option to choose among these alternatives. The Commission here also indicates that users should be provided with *at least one easily accessible option that is not based on profiling* for each recommender system. This requirement does not follow directly from the DSA but seems in line with the requirements for consent under the GDPR (as it seems unlikely that a webshop would be able to rely on a different legal basis for the profiling). 

We do not know how long this investigation will take - the press release makes it clear that the Commission doesn't want to commit to a specific timeline. Of course, the outcome in this file may have broader implications for DSA enforcement and consumer protection, so we will be following (and sharing) any developments with great interest!

Tuesday, 2 September 2025

Key GDPR Fines in Mid-2025: Luka (Replika), TikTok, and ING Bank Śląski

This post discusses three recent decisions of Data Protection Authorities imposing fines for GDPR infringements on Luka Inc., TikTok, and ING Bank Śląski. While most of our analyses usually focus on judgments of the Court of Justice of the European Union, in this case we turn to decisions of national authorities. Such decisions tend to attract significant attention, either because of the seriousness of the violations or the high amounts of the penalties, which makes them a frequent subject of debate. The three cases selected meet these criteria and, moreover, were issued within the past few months. They are also directly relevant to consumers, as they highlight risks that many of us face in everyday life when using apps or online services where personal data may be mishandled.
 
 
Luka Inc. 

On 10 April 2025, the Italian Data Protection Authority (Garante per la protezione dei dati personali) issued a decision against Luka Inc., the U.S. company behind the Replika chatbot. Replika is marketed as an AI “companion” designed to boost users’ mood and wellbeing, and can be set up as a friend, mentor, therapist or even a romantic partner. But according to the Garante, the way Luka handled users’ personal data fell far short of what the GDPR requires.

The investigation showed that Replika’s privacy policy did not clearly identify the legal ground for the many different ways in which users’ data were processed – for example, data used for running the chatbot versus data used for developing the large language model behind it. Instead of specifying purposes and corresponding legal bases, the policy only gave vague, generic statements like: “We care about the protection and confidentiality of your data. We therefore only process your data to the extent that: It is necessary to provide the Replika services you are requesting, you have given your consent to the processing, or we are otherwise authorized to do so under the data protection laws” (btw – doesn’t that sound familiar from many privacy policies?). This lack of granularity made it impossible for users to understand how their data were really being used, in breach of Articles 5(1)(a) and 6 GDPR.

What’s more, the privacy notice was only available in English, even though the service was offered in Italy. It also failed to explain key points required under GDPR: what kinds of data were collected, how long they were stored, whether data were transferred outside the EU, and for what purpose. Some statements were even misleading, for instance, suggesting that personal data might be transferred to the U.S., while the company later claimed no such transfers took place. Such gaps and contradictions meant that users could not make informed choices about their data.

However, the most troubling finding was that the Garante concluded Luka had failed to implement effective safeguards for children. Although the service was formally intended for adults, it lacked genuine age-verification mechanisms. Registration required only a name, email address, and gender, which allowed minors to create accounts. Even when users declared they were under 18, no technical barrier prevented them from accessing the platform. In practice, this meant that children could be exposed to age-inappropriate content, including sexually explicit material. Moreover, even after updates to the privacy policy, technical testing showed that under-18 users could still bypass the age restriction simply by editing their profile. 
 
For these violations, the Garante imposed an administrative fine of EUR 5,000,000, representing half of the maximum amount available under Article 83(5) GDPR.
 
 
TikTok Technology Limited
 
Another significant decision was issued by the Irish Data Protection Commission (DPC) in May 2025 against TikTok Technology Limited. Although the full text of the decision has not yet been published, the official press release provides insight into the reasons for the sanction.
 
The inquiry examined both the lawfulness of TikTok’s transfers of European users’ personal data to China and the adequacy of the company’s transparency regarding those transfers. The DPC concluded that TikTok had infringed the GDPR in two key respects.
 
First, the Commission found that TikTok’s transfers of user data to China violated Article 46(1) GDPR. The company failed to verify, guarantee, and demonstrate that personal data of European users – remotely accessed by staff in China – was afforded a level of protection essentially equivalent to that required within the EU. TikTok’s own assessments of Chinese law highlighted serious divergences from EU standards, particularly risks under the Anti-Terrorism Law, the Counter-Espionage Law, and the National Intelligence Law. Nevertheless, the company did not adequately address these risks or ensure that its contractual safeguards were effective.
 
Second, the DPC held that TikTok had not complied with the information duties set out in Article 13(1)(f) GDPR. Earlier versions of its privacy policy (in force between July 2020 and December 2022) failed to identify the countries involved in data transfers and did not explain the nature of the processing – for instance, that personnel in China could remotely access data stored in Singapore and the United States. This lack of clarity prevented users from understanding who could access their data and under what conditions.
 
The decision imposed not only administrative fines but also corrective measures. TikTok was given six months to bring its practices into compliance, failing which data transfers to China would have to be suspended altogether. The total fine amounted to EUR 530,000,000, comprising EUR 485,000,000 for the unlawful transfers and EUR 45,000,000 for the lack of transparency.
 
 
ING Bank Śląski
 
The third discussed decision was delivered on 23 July 2025 by the Polish Data Protection Authority (UODO) against ING Bank Śląski S.A., which was fined PLN 18,416,400 (around EUR 4,000,000). The case revolved around the bank’s widespread practice of copying and scanning ID cards of both existing and potential clients, even in situations where such a step was not required by law. The bank introduced this practice after the amendment of Polish anti-money laundering provisions, interpreting them as justifying the systematic copying of IDs.
 
The investigation revealed that between April 2019 and September 2020 the bank systematically scanned ID documents not only during customer onboarding, but also in contexts where no anti-money laundering (AML) obligations applied – for example, when a customer filed a complaint about an ATM. In practice, the bank’s internal procedures made the delivery of services conditional on handing over a scanned ID, leaving consumers with no real choice.
 
As emphasized in the decision, both AML law and the GDPR require banks to conduct a risk-based assessment and determine, case by case, whether copying an ID is genuinely necessary. ING failed to perform such assessments. Instead, it adopted blanket rules requiring ID copies in numerous situations, regardless of whether AML obligations applied. As a result, the bank processed extensive amounts of sensitive identifying information without a valid legal basis under Article 6 GDPR. Although no specific harm was demonstrated, the decision underscores that ID cards contain a wide range of personal data – including full name, date of birth, parents’ names, unique national ID number (PESEL), photograph, and document series. Taken together, these data significantly increase the risk of identity theft or fraudulent loans. Given that ING had millions of individual and corporate clients during the period in question, the potential consequences of such unnecessary data collection were substantial.

Monday, 30 June 2025

On the Transparency Requirements of Arrangement Fees – CJEU in Justa v Banco Bilbao Vizcaya Argentaria SA (Case C-39/24)

Consolidating Caixabank SA (C‑224/19) and CaixaBank SA (C‑565/21) in Case C-39/2024 of 30 April 2025, the Court of Justice (CJEU) ruled on the transparency of arrangement fees and further clarified the threshold for meeting its requirements. 

Facts of the case

In November 2005, Just and Banco Bilbao Vizcaya Argentaria concluded a loan agreement secured by a mortgage. According to the contract, upon signing the agreement, Justa had to pay an arrangement fee equal to 0.25% of the capital loan. Justa brought an action before the Court of First Instance of Ceuta against Banco Bilbao seeking a declaration that the term establishing the arrangement fee was unfair. 

Question referred

The Court of First Instance of Ceuta referred two questions, one of which is admissible. The second, regarding the application of Directive 2014/17/EU is inapplicable ratione temporis.

By the admissible question, the referring court is asking whether Article 4(2) of Directive 93/13/EEC on Unfair Terms in Consumer Contracts (hereinafter, UCTD) must be interpreted as precluding the case law of the Tribunal Supremo (Supreme Court) which considers the term imposing an arrangement fee to remunerate services ‘connected with the examination, granting or processing of the mortgage loan’, to be transparent without the term specifying the services supplied in exchange for the fee or the time needed to perform them (para 28). 

Ruling

First, the CJEU observes that a term establishing an arrangement fee cannot be considered as pertaining to the main subject matter of the contract. The essential obligations of a credit contract are in fact that the lender ‘undertakes (…) to make available to the borrower a certain sum of money and that the latter undertakes (…) to repay that sum’ (para 31). With this, the CJEU further consolidates its ruling in Caixabank and Banco Bilbao Vizcaya Argentaria (C-224/19 and C-259/19, EU:C:2020:578, para 64). 

Irrespective, Article 5 of the UCTD imposes the same requirement for transparency for contractual terms in writing, which, as per that provision, must ‘always’ be written in plain and intelligible language. As already noted in 2023 in Caixabank (Loan arrangement fees), C-565/21, the requirement for transparency of Article 4(2) has the same scope as the requirement laid down in Article 5. Therefore, the question of the referring court must be reformulated with reference to Article 5 instead of Article 4(2). 

The CJEU holds that the requirement should not be understood as only demanding that the terms are formally and grammatically intelligible. The transparency of the terms must be understood broadly, in light of the provision’s rationale that is to protect consumers’ weaker position vis-à-vis businesses (see also Caixabank (Loan arrangement fees), C-565/21, EU:C:2023:212, para 30). The consumer must be able to understand what ‘economic consequences’ derive for her or him from the term (para 38, emphasis added) and the ‘nature of the services’ she or he receives (para 39, emphasis added). 

The national court will be in charge of determining whether the financial institution has provided sufficient information for her or him to understand the content and functioning of the term (para 40). The court will thus assess the transparency of the terms, taking into consideration ‘all the relevant factual elements’, which include also the advertising that the bank makes of the particular agreement (para 41; see also Caixabank (Loan arrangement fees), C-565/21, EU:C:2023:212, para 40). 

To summarise, the transparency requirement is intended to ensure that the consumer can assess the financial consequences of the term. Crucially, the requirement does not entail that the bank must detail the nature of the services supplied or the number of hours devoted to offering those services (para 44). 

The Court concludes that, like in the case at hand, where the legislation defines the term imposing the arrangement fee as remuneration for services connected with the examination, granting or processing of the mortgage loan, it is not necessary that the term includes ‘a detailed description of the nature of those services or an indication of the time devoted to their performance’ (para 47). 

It is however necessary that ‘the consumer has indeed been placed in a position to assess the economic consequence for him or her, to understand the nature of the services (…) and to ascertain that there is no overlap between the various costs provided for in the contract or between the services for which those costs are paid’ (para 47).

The national case law of the Supreme Court is thus not precluded by Article 5 of the UCTD

Wednesday, 5 March 2025

Artificial intelligence in financial services - new report by Finance Watch

Today, Finance Watch, a non-profit association dedicated to reforming finance in the interest of European citizens, published a new report: 'Artificial intelligence in finance: how to trust a black box?' authored by its Chief Economist Thierry Philipponnat.

As AI-powered systems increasingly drive financial decision-making in areas such as creditworthiness assessments, insurance pricing and investment products, the report asserts that the core principles of financial regulation accountability, responsibility, and transparency are being tested.

Against this backdrop, the report identifies several critical concerns: 

  • Lack of transparency: AI models operate as “black boxes”, generating outputs without clear explanations of their reasoning, making human oversight and intervention impossible.
  • Consumer protection under threat: In retail finance, the deployment of AI could lead to opaque creditworthiness assessments (see for an example here), pricing discrimination, discriminatory lending, and misleading financial advice. 
  • Supervisors face AI challenges: Supervisors tasked with enforcing regulation face challenges in keeping pace with financial institutions' deployment of AI and delivering on their mandates.
  • Market stability is at risk: Increasingly dependent on third-party AI providers, financial institutions face operational risks from unregulated external systems and concentration risks, where a handful of dominant AI firms control critical models and infrastructure, creating systemic vulnerabilities. 

As a response, the report urges a reassessment of the financial regulation framework: 

  1. Expand the scope of the AI Act to cover all financial services
  2. Establish a clear liability regime that holds providers of AI-powered services accountable for damages caused by an output of an AI system
  3. Conduct a regulatory gap analysis to ensure all AI-driven financial activities are adequately regulated.

Tuesday, 4 March 2025

Credit reference agencies, consumer profiling and the GDPR: the CJEU in C-203/22

On February 27, 2025, the CJEU delivered an important judgment on the interpretation of Article 15(1)(h) and Article 22 of Regulation (EU) 2016/679 on General Data Protection (GDPR) in C-203/22 CK Magistrat der Stadt Wien v Dun & Bradstreet Austria GmbH.

The facts

The mobile phone operator refused CK’s request to conclude or extend the mobile telephone contract for a monthly payment of a mere EUR 10. The refusal was justified with CK not passing a creditworthiness check with the credit reference agency D & B, which carried out an automated assessment. Unsurprisingly, CK was unhappy with the decision; her credit score was good. She brought the matter to the Austrian data protection authority and, with this, started a long way to the preliminary reference, going through various instances and avenues for protection.  

The referring court raised several questions, which the CJEU grouped into essentially two questions:

The first question

Must Article 15(1)(h) be interpreted as meaning that, in the case of automated decision-making, including profiling, within the meaning of Article 22(1), the data subject may require the controller to provide, ‘meaningful information about the logic involved’ in the decision making, which would mean an exhaustive explanation of the procedure and principles actually applied in using personal data to obtain a specific result, in this case, a creditworthiness assessment.  

According to Article 15 (h), the data subject has the right to obtain from the controller confirmation as to whether his/her personal data is being processed, information on the use of automated decision-making where applicable, including profiling, referred to in Article 22(1) and (4), and meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.

Article 22 provides that the data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, and that certain data enlisted in Article 9(1) GDPR such as racial or ethnic origin, religious beliefs cannot be considered in data processing.

Profiling, in this context, means automated processing of personal data, consisting of using personal data to analyse or predict the consumer's economic situation.

In its analysis, the CJEU first turned to a literal interpretation of the wording of Article 15 (h) and concluded that the concept of ‘meaningful information’ under that provision may have various meanings in different language versions of GDPR, which should be taken to be complementary to each other. In addition, the ‘logic involved’ in automated decision-making, which constitutes the subject matter of ‘meaningful information’ is capable of covering a wide range of ‘logics’ concerning the use of personal data and other data with a view to obtaining a specific result by automated means. The CJEU held, that the provision covers all relevant information concerning the procedure and principles relating to the use, by automated means, of personal data with a view to obtaining a specific result.

The CJEU next turned to contextual analysis of the concept of ‘meaningful information about the logic involved’, within the meaning of Article 15(1)(h). In this analysis the CJEU looked at the  Guidelines on automated individual decision-making and profiling for the purposes of Regulation 2016/679 and other provisions of the GDPR providing information duties of data controllers. The CJEU concluded that information duties relate to all relevant information that should be provided in clear, concise, transparent, intelligible and easily accessible form, using plain and clear language

Finally, the CJEU looked at the purpose of the provision, asserting that the purpose of the data subject’s right to obtain the information provided for in Article 15(1)(h) is to enable him or her to effectively exercise the rights conferred on him or her by Article 22(3), namely, the right to express his or her point of view and to contest the relevant decision. This, in turn, requires the right to obtain an explanation of the decision.

The CJEU then concluded that under Article 15(1)(h) the right to obtain ‘meaningful information about the logic involved’ in automated decision-making must be understood as a right to an explanation of the procedure and principles actually applied in order to use, by automated means, the personal data of the data subject with a view to obtaining a specific result, such as a credit profile. In order to enable the data subject to effectively exercise the rights conferred on him/her by the GDPR and, in particular, Article 22(3), that explanation must be provided by means of relevant information in a concise, transparent, intelligible and easily accessible form. Notably, the court further provided guidance on what is considered to be ‘meaningful information about the logic involved’ in automated decision-making. The procedures and principles actually applied must be explained in such a way that the data subject can understand which of his/her personal data have been used in the automated decision-making and the extent to which a variation in the personal data taken into account would have led to a different result. The requirements of Article 15(h) cannot be met by the mere communication of a complex mathematical formula, such as an algorithm, or by the detailed description of all the steps in automated decision-making since neither of those would constitute a sufficiently concise and intelligible explanation.

Second legal question

Another important contribution of the present judgment is the consideration of the relationship between Article 15(1)(h) and Directive 2016/943 on trade secrets, given that D&B argued that the logic of their automated decision-making, including what information is considered in which way, is a trade secret and should, therefore, not be disclosed.  

The CJEU highlighted that the protection of personal data is not an absolute right. Restrictions are possible of the scope of the obligations and rights provided for in, inter alia, Article 15 of the GDPR, but only when such a restriction respects the essence of the fundamental rights and freedoms and is a necessary and proportionate to safeguard the protection of the rights and freedoms of others. However, the result of any consideration on the limits of the protection of personal rights should not be a refusal to provide all information to the data subject.

The CJEU concluded that Article 15(1)(h) must be interpreted as meaning that, where the controller takes the view that the information to be provided to the data subject is a trade secrets, within the meaning of point 1 of Article 2 of Directive 2016/943, that controller is required to provide the allegedly protected information to the competent supervisory authority or court, which must balance the rights and interests at issue with a view to determining the extent of the data subject’s right of access provided for in Article 15 of the GDPR.

Our analysis

This decision is significant in addressing the long-standing problem of the lack of transparency in automated decision-making by credit reference agencies,  an important problem in the EU. Given that in most countries we have access to our credit reports we can know what data is considered in their decision making in producing a credit score and a credit report, however, credit reference agencies have refused disclosing the way this data is processed, the logic behind their decision making, in what way and to what extent various data is considered (weighted) in their decision making.  Although based on this decision, consumers are still not entitled to get hold of that information directly, but a first step has been made by mandating disclosure to the relevant authority who then makes a decision on whether or not to disclose it to the consumer, balancing the rights and interests of the two parties. This and other judgments of the CJEU (see C-634/21 SCHUFA Holding) may be gradually bringing transparency into this traditionally very untransparent area.

As credit reference agencies nowadays use artificial intelligence for automated decision-making, the judgment is relevant for advancing transparency considerations of AI systems.

Finally, given that the judgment tackles the operation of credit reference agencies, which are frequently used by creditors to assess the affordability of loan applications, it is relevant for responsible lending rules in Directive 2023/2225 on consumer credit (CCD2), which in Article 18 refers to creditworthiness assessment based on automated processing of personal data. 

Friday, 21 February 2025

Sanctions for Not Providing Essential Information in Credit Contracts - CJEU in Lexitor II (Case C-472/23)

Foto von Towfiqu barbhuiya auf Unsplash
The case concerned a debt collection agency (Lexitor), acting as an assignee of the rights of a consumer who had concluded a consumer credit agreement with a bank for an amount of approx. 9.000 EUR. In addition, the consumer was required to pay capital interest (approx. 4.500 EUR) and a commission fee (approx. EUR 1.100), whereas the Annual Percentage Rate of Charge (APRC) was specified at 11.18%. Lexitor argued that, since the APRC was partly calculated on the basis of unfair contract terms, the bank had failed to provide the correct APRC in the agreement. Consequently, Lexitor sought to recover the total sum of interest and costs as a sanction prescribed under national law. 

The first question was whether the creditor had failed to fulfil its obligation to provide the APRC in the credit agreement where the APRC was overstated due to certain contract terms being declared unfair. The Court emphasised that, although the actual APRC would indeed be overstated if calculated with reference to non-binding unfair contract terms, Article 19(3) of the Consumer Contract Directive (CCD; Directive 2008/48 on credit agreements for consumers) requires that the APRC be calculated based on the assumption that the credit agreement is to remain valid for the period agreed and that the creditor and the consumer will fulfil their obligations under the terms and by the dates specified in the credit agreement (para 34). Consequently, where the APRC is determined in accordance with the mathematical formula set out in Annex I to the directive - incorporating the total cost of credit to the consumer, including costs payable under the contract’s terms - the creditor does not infringe its obligation to provide the APRC in the credit agreement. This remains the case even if some of the terms on which the APRC was calculated are subsequently declared unfair and therefore not binding on the consumer (para 35).

The Court also addressed the question of whether listing various circumstances under which charges connected with the performance of the credit agreement may increase, without enabling the consumer to determine whether those circumstances have arisen, constitutes a breach of the creditor’s information obligation under the CCD. The Court referred to its established case law, holding that the terms of the credit agreement must be drafted transparently so that an average consumer can foresee, on the basis of clear and intelligible criteria, the changes that may be made to such charges (paras 41–44). Applying this principle to the contract terms in question, the Court concluded that where a credit agreement enumerates specific circumstances justifying an increase in charges without enabling the average consumer to ascertain whether those circumstances have materialised and their effect on the charges, this constitutes an infringement of the creditor’s obligation to provide information (paras 45–47).

Finally, the Court considered whether Article 23 CCD precludes national legislation that, in cases of infringement of the creditor’s obligation to provide information under Article 10(2) CCD, imposes a uniform penalty depriving the creditor of its right to interest and charges, irrespective of the seriousness of the infringement or its effect on the consumer’s decision. The primary concern was whether such a sanction would be proportional (para 51). Drawing upon its previous case law, the Court reaffirmed that Article 10(2) CCD sets out essential information that consumers must receive to assess the extent of their liability. A breach of this obligation may be sanctioned under national law by the forfeiture of the creditor’s entitlement to interest and charges (paras 53–54). The Court then turned to the specific circumstances of the case. Since the obligation to provide the APRC had not been infringed (first question), it focused instead on the conditions under which costs related to the performance of the agreement (such as commission fees) could be changed, considering this equally vital information under the CCD due to its impact on consumers’ financial obligations (para 55). The Court emphasised that the principle of proportionality does not preclude a Member State from imposing a uniform penalty depriving the creditor of its right to interest and charges for breaches of information obligations under Article 10(2) CCD, including those relating to the calculation of charges connected with contract performance, even where the gravity of the infringement may vary (para 57).

A Short Comment

The Court’s answers to the second and third questions are not surprising. It confirmed that the average consumer standard has been employed to assess the transparency of contract clauses under the CCD framework, as seen previously in BMW Bank, and has been extensively applied in consumer credit case law since Kásler. The response to the third question reaffirms that the information contained in a credit agreement (Article 10(2) CCD) is essential for the consumer to make an informed decision; consequently, failure to comply with this obligation may trigger sanctions under national law. The Court appears to have linked the proportionality of the sanction to the essential nature of the information provided.

The Court’s reasoning in relation to the first question, however, may be called into question. A literal interpretation of Article 19(3) CCD does not address the unfairness of terms used by the creditor but instead focuses on two distinct elements: first, that the APRC’s calculation is based on the assumption that the credit agreement remains valid for the agreed period; and second, that both parties will fulfil their respective obligations under the agreement. The unfairness of certain contract terms, on the other hand, means that they are null and void ab initio under Article 6(1) of the Unfair Contract Terms Directive, with the consequence that no obligations arise from them.

The first part of Article 19(3) CCD assumes the continued validity of the credit agreement. However, since finding the terms at issue null and void is unlikely to render the agreement invalid - as they do not appear to be essential to the contractual obligation (see Profi Credit Polska III, paras 68–70), although this must be verified under national law - this part of Article 19(3) CCD would not apply here. The same reasoning extends to the second part of Article 19(3) CCD: if obligations based on unfair terms do not exist ab initio, there is no obligation to fulfil on the side of any of the party.

It is also unclear how concluding that the APRC’s calculation, when partially based on unfair contract terms - leading to an overstatement of the APRC - does not infringe the information obligation under Article 10(2)(g) CCD, would contribute to achieving a high level of consumer protection. This raises at least three concerns.

First, in such cases, creditors would not face additional disincentives against using unfair terms in credit agreements. This appears inconsistent with Recital 20 of the CCD Preamble (“Creditors’ actual knowledge of the costs should be assessed objectively, taking into account the requirements of professional diligence”), which suggests that creditors could reasonably be expected to know when they are using unfair terms.

Second, since the APRC was overstated, it is unclear how the average consumer could accurately determine - not merely approximate - the extent to which the stipulated APRC would affect their future rights and obligations under the credit agreement. This appears to contradict the Court’s reasoning in its response to the second question, where the transparency of information is deemed crucial for consumer decision-making.

Third, it also seems to conflict with the Court’s reasoning in Pereničová and Perenič, here it held that an incorrect APRC constitutes false information regarding the total cost of credit and the price under Article 6(1)(d) of the Unfair Commercial Practices Directive (UCPD), as it causes or is likely to cause the average consumer to make a transactional decision they would not have otherwise taken (para 41). However, the Court may have drawn a distinction between cases where the actual APRC is lower than that stipulated in the contract (Lexitor II) and those where it is higher (Pereničová and Perenič), as well as between the transparency requirements under the CCD and those under the UCPD. Yet, these distinctions are not explicitly addressed in the commented judgment. Further clarification from the Court on this point would be necessary to provide much-needed clarity.

Wednesday, 5 June 2024

Transparency about online payments even if they are conditional - CJEU in Conny (C-400/22)

Last week, on May 30, the CJEU gave its judgment in the Conny case (C-400/22) elaborating on the requirement from Article 8 of the Consumer Rights Directive to clearly label an online obligation to pay on a website on a relevant button with the words 'order with obligation to pay' (or an equivalent of this).

Photo by Alice Pasqual on Unsplash
The facts of this case are interesting as it was a trader that tried to argue that the lack of clear wording on a website about an order with an obligation to pay should lead to the voidness of the concluded contract. The contract in case was a lease contract, concluded between a landlord and a tenant. Pursuant to German law, this lease contract had a ceiling on the rent that consumers had to pay and if this ceiling was exceeded, consumers could claim reimbursement of overpayments. Conny - a debt collection company - offered to collect the rent overpayments as an assignee of consumers rights. The contract between Conny and consumers was concluded online, via its website. Consumers had to approve T&Cs and click on a button to place the order, which button was not labelled with the required wording. The reason given for this was that the payment was conditional on Conny successfully securing the debt collection. Only at that time consumer would have had to pay a third of the annual rent saved, pursuant to T&Cs. The landlord used the lack of the proper labelling on Conny's website as an argument that the assignment of consumer rights was void and, that therefore, Conny could not have been successful in claiming repayment of rent from the landlord. 

Order with an obligation to pay - whether payment is conditional or unconditional

The CJEU clarifies, as expected, that the trader's obligation to transparently inform consumers concluding a contract through its website about an obligation to pay, just before a consumer binds themselves to this payment, does not change if the payment is dependent on satisfying a subsequent condition (para 56). This allows the consumer to explicitly acknowledge his consent to be bound by an online order with an obligation to pay (paras 43, 50). The CJEU points to the lack of distinction in the CRD between conditional and unconditional payments, as well as the duty to inform placed on traders when an order 'implies' an obligation to pay (paras 46-47). A different interpretation would have led to traders being able to explicitly inform consumers about their obligation to pay not at the ordering process, when consumers may still avoid the order and the subsequent payment obligation, but only at a time when the payment becomes due (para 52). Traders could then circumvent their duty to inform by placing in their T&Cs an objective condition, fulfilment of which would be required to lead to a payment obligation (para 53).

Sanction of voidability

An important clarification follows in paras 54-55 of the judgment. The CJEU emphasises the CRD's wording, which only states that a consumer is not bound by the contract in case the above-mentioned trader's duty has been breached. This does not need to indicate that a contract is void, but rather that a consumer has an opportunity to avoid it. This would make a significant difference in cases such as the one referred to the CJEU, when it is a trader who is trying to use an infringement of consumer protection rules as a 'weapon' against, ultimately, a consumer.

Tuesday, 2 April 2024

How the CJEU's ruling in C-604/22 may transform online advertising: a closer look at the IAB Europe case

In March, the CJEU issued a ruling (Case C-604/22 IAB Europe) that has sparked a lot of discussion. The ruling addresses certain practices related to online advertising in Europe, particularly the collection of personal data for the purpose of behavioural advertising.

Facts of the case

The Interactive Advertising Bureau Europe (IAB Europe) is a non-profit association that represents digital advertising and marketing businesses at the European level. IAB Europe's members include companies that generate significant revenue by selling advertising space on websites or applications. Several years ago the association developed the Transparency & Consent Framework (TCF) to promote General Data Protection Regulation (GDPR) compliance when using the OpenRTB protocol (a popular system used for "real-time bidding", which means it quickly and automatically auctions off user information to buy and sell ad space on the internet). The TCF consists of guidelines, technical specifications, instructions, protocols, and contractual obligations. The framework is designed to ensure that when users access a website or application containing advertising space, technology businesses representing thousands of advertisers can instantly bid for that space using algorithms to display targeted advertising tailored to the individual's profile.
Image by "storyset" (Freepik)

The TCF was presented as a solution to bring the auction system into compliance with GDPR (para. 21, 22). However, before displaying targeted advertisements, the user's prior consent must be obtained. When a user visits a website or application, a Consent Management Platform (CMP) appears in a pop-up window. The CMP enables users to give their consent to collect and process their personal data for pre-defined purposes, such as marketing or advertising, or to object to various types of data processing or sharing of data based on legitimate interests claimed by providers, as per Article 6(1f) of the GDPR. The personal data relates to the user's location, age, search history, and recent purchase history (para. 24). In other words - the TCF facilitates the capture of user preferences through the CMP. And these preferences are coded and stored in a "TC string" (which is a combination of letters and characters), and then shared with organizations participating in the OpenRTB system, indicating what the user has consented/ objected to. The CMP places a cookie on the user's device, and when combined with the TC string, the IP address of the user can identify the author of the preferences. Thus the TCF plays a crucial role in the architecture of the OpenRTB system as it is the expression of users' preferences regarding potential vendors and various processing purposes, including the offering of tailor-made advertisements (para. 25, 26).

Since 2019, the TCF model has faced numerous complaints to the Belgian Data Protection Authority (DPA) regarding its GDPR compliance. IAB Europe was criticized for providing users with information through the CMP interface that was too generic and vague, preventing users from fully understanding the nature and scope of data processing and thereby maintaining control over their personal data. Furthermore, IAB Europe was accused of failing to fulfil certain obligations of a data controller, including ensuring the lawfulness of processing, accountability, security, and adhering to data protection privacy by design and by default rules (more details about the proceedings can be found on the DPA's website). Consequently, the DPA concluded that IAB Europe did not meet its GDPR obligations and imposed an administrative fine of €250,000. Additionally, it mandated corrective actions to align the TCF with GDPR standards. 

IAB Europe disagreed with the decision and challenged it before the Belgian court. According to IAB Europe, it should not be considered a data controller for recording the consent signal, objection, and preferences of individual users through a TC string. Thus the association should not be obliged to follow data controllers' obligations under GDPR. IAB Europe also disagreed with the DPA's finding that the TC string is personal data within the meaning of Article 4(1) of the GDPR. Specifically, IAB Europe argued that only the other participants in the TCF could combine the TC String with an IP address to convert it into personal data, that the TC String is not specific to a user and that IAB Europe cannot access the data processed in that context by its members (para. 28).

CJ's ruling


The Court has confirmed the key aspects of the DPA’s decision, emphasizing, among other things that:


1. the TC String holds information that pertains to an identifiable user and, thus, qualifies as personal data under Article 4(1) of the GDPR. Even if it doesn't contain any direct factors that allow the data subject to be identified, it does contain the preferences of a specific user relating to their consent to data processing. This information is considered to be related to a natural person (para. 43). If the information in a TC String is linked to an identifier, such as the IP address of the device, it could be possible to create a profile of that user and identify a particular person (para. 44). The fact that IAB Europe cannot combine the TC String with the IP address of a user's device and doesn't have direct access to the data processed by its members is irrelevant. As the Court stated, IAB Europe can require its members to provide it with the necessary information to identify the users whose data is being processed in a TC String (para. 48). This means that IAB Europe has reasonable means to identify a particular natural person from a TC String (para. 49).

2. IAB Europe, together with its members, is considered a 'joint controller' when it determines the purposes and ways of data processing. Why? According to the Court, the TCF framework aims to ensure that the processing of personal data by certain operators that participate in the online auctioning of advertising space complies with the GDPR. Consequently, it aims to promote and allow the sale and purchase of advertising space on the Internet by such operators. It means that IAB Europe has control over the personal data processing operations for its own purposes and, jointly with its members, determines the purposes of such operations (para. 62-64). Moreover, the TCF contains technical specifications relating to the processing of the TC String, such as how CMPs need to collect users' preferences, how such preferences must be processed to generate a TC String, etc. (para. 66). If any of IAB's members do not comply with the TCF rules, IAB Europe may adopt a non-compliance and suspension decision, which could result in the exclusion of that member from the TCF (para. 65). Therefore, the Court concluded that IAB Europe also determines the means of data processing operations jointly with its members (para. 68), so it meets the criteria of a data controller under Article 4(7) of the GDPR. However, this should not automatically make IAB Europe responsible for the subsequent processing of personal data carried out by operators and third parties based on information about the users' preferences recorded in a TC String (para. 74-76).

What could be the consequences of the ruling? 

The Court confirmed that the IAB Europe, due to the role and significant influence it has over the processing of data by its members for the purposes of creating user profiles and targeting them with personalized advertising, should be held responsible for how this process is organized. And it is organized in a way that is hardly transparent to users. While it is up to the national court to ultimately examine the compatibility of the Belgian DPA's decision, it can be expected that the court will affirm the main conclusions of the Belgian authority's decision. 

It appears unlikely that the CJ's ruling will lead to the elimination of the intrusive pop-ups on many websites, which often rely on dark patterns and manipulative techniques to coerce consent for data processing for marketing purposes. Nevertheless, the advertising industry should place a greater emphasis on enhancing transparency and providing users with more control over their personal data. This could include the development of more user-friendly and informative consent mechanisms, making it easier for users to understand what they are consenting to and how to exercise their rights over their data. The ruling is also expected to impose further restrictions on behavioural advertising practices, particularly those dependent on real-time bidding and the widespread sharing of personal data without explicit, informed consent from users. 

Thursday, 21 September 2023

Alternative terms on performance, average consumers... tune in to CJEU in mBank (C-139/22)

Claudio Schwarz on Unsplash
Today the CJEU decided another case on unfairness in mortgage loan agreements with an index-link to Swiss francs - in the Polish mBank case (C-139/22). The first part of the judgment is Poland-specific, as it refers to the validity and effect of a national register of unlawful terms, which Poland happens to have. This issue has already been considered in the previous Biuro case (see our comment on case C-119/15 here). The Court now reiterated that as long as the register is transparent, kept up to date, and the traders have an opportunity to question the applicability of the register in their particular case, national courts could benefit from such registers (paras 41-43). Hence, contested terms could be declared by national courts as unfair if their content has previously  been registered as unfair, provided that the court warns parties to the proceeding about this and gives the trader the opportunity to challenge this finding (para 45). 

The second question was more interesting: What happens if the mortgage loan contract contains a term that is likely to be unfair, however, it also contains another term, which allows consumers to disregard the unfair term and follow a different path for contractual performance? In this case, the contract included a term that obliged consumers to reimburse a loan index-linked to Swiss francs 'exclusively in the national currency as converted according to a rate of exchange freely determined by the bank' (para 52). This term was previously determined as unfair by Polish courts. However, the contract also included a term that allowed consumers instead to reimburse the bank directly in Swiss francs. This would allow consumers to choose where to obtain Swiss francs from, avoiding the conversion rates set by mBank. According to the bank, consumers could have then avoided the detrimental effect of the first term, which, again pursuant to the bank. would not lead to unfairness. The Court rightly rejects this argumentation. Contrarily, it emphasises that a contract containing such a mechanism - two alternative terms referring to the same obligation, one of which is unfair and one of which is lawful - per definition should be considered unfair (para 55). The trader could be seen as counting on consumers' 'lack of information, failure to pay due attention or a lack of understanding', which would lead them to re-pay the loan in the way set out by the detrimental, unfair term, with the other term then only providing a mechanism to avoid liability by the trader (para 55).

Interestingly, the Court makes the above-finding fully aware of the average consumer standard that applies to the interpretation of the UCTD provisions. On its basis, we could expect that reasonably well-informed and circumspect consumers, who are to read and attempt to understand the contract and its consequences, should recognise the better of the two options for re-payment. And yet... the Court does not think so.

The average consumer is mentioned by the Court when giving the answer to the third question: Does the fact that one of the borrowers worked for the bank exclude them from the scope of protection of the UCTD? The answer is: No. As the concluded contract does not pertain to the employment relationship, the sole fact that it is concluded with the employer does not mean that it could change its non-commercial purpose (para 69). Further, even if the consumer in this case had insights into exchange rates of mBank, which were not available to consumers not working for this bank, this did not mean that their 'more specialised' knowledge should exclude them from the scope of protection of the UCTD. The CJEU reminds that we refer to the objective benchmark of an average consumer and their knowledge. Thus neither less nor more consumer knowledge in a given case will matter (para 66).

Monday, 31 July 2023

Average consumers not expected to conduct legal research - CJEU in Banco Santander (C-265/22)

 Patrick Tomasso on Unsplash
On July 13th, the CJEU issued a judgment further clarifying the principle of transparency under the Unfair Contract Terms Directive in variable-rate mortgage loan contracts, in the case Banco Santander (C-265/22). In such contracts the interest rate is variable with time, here: a new rate was to be determined every year for the following 12 months.  

In the Spanish case referred to the CJEU, consumers' interest rate was calculated with reference to the Mortgage Loan Reference Indices (IRPH). Consumers claimed that they were not informed as to the full impact of having such a reference rate, with relevant information either missing from the mortgage loan agreement or not being properly communicated to them. Whilst the Unfair Commercial Practices Directive was not yet applicable at the time the mortgage loan contract was concluded (2006), the Court could not consider whether the bank engaged in a misleading commercial practice. It was, however, able to assess that the UCTD may have been infringed if the bank's practice did not allow for applying to the IRPH a negative margin, in order to align the interest rate with the market rate.

The CJEU reiterates the main points on transparency from the Andriciuc and Others judgment (see our comment): Consumers require sufficient information to take prudent and well-informed decisions; mainly average consumers need to be able to estimate the total cost of the loan (para 53). This translates into an obligation, when variable-rate mortgage loan contracts are concluded, for average consumers to understand: the specific functioning of the method used for calculating that rate (para 55). This requires consumers to have easy access to the main elements relating to the calculation of the reference index (para 56). The national court in the given case needs to check whether the information provided in the agreement (with the index being published by the Bank of Spain and having been described in Annex VIII to the agreement) was sufficient for average consumers to become aware of the method of calculation of the variable interest rate (paras 57-58). Further, the national court should consider whether the lack of information in the loan agreement on a non-binding circular issued by the Bank of Spain could have been detrimental to the average consumer's ability to estimate the total loan cost. This in light of the circular stressing its significance for credit institutions (para 59). The CJEU seems to imply in para 60 that it would go to far to expect average consumers to conduct legal research, that is to try to find other documents of the Bank of Spain that could be applicable to the variable-rate mortgage loans, which have not been referenced in the agreement.

Whilst the CJEU reiterates the finding from the order in Gómez del Moral Guasch that the lack of transparency of a term does not render it, in itself, unfair, it would weigh in on the unfairness test (para 66). Further, the national court, when estimating whether the contract term introduces significant imbalance between parties' rights and obligations, has to look at what rules would apply in the absence of the agreement and assess to what extent the contractual provisions put the consumer at a detriment (Banco Primus - see our comment). With variable-rate mortgage loans this means comparing the interest rate to the statutory interest rate and the interest rates applied on the market at the date of conclusion of the agreement at issue... for a loan of a comparable sum and term (para 65).

UPDATED:

Readers interested in finding out more about the intricacies of the financial indexes used in Spain for calculating variable-rates in mortgage loan contracts, the legal value of circulars issued by the Bank of Spain, and the possible misconstruction of Spanish law by the CJEU - please check the comment of Prof. Ernesto Suárez from ESADE and UPF Law Schools in Spain.